RE: Securing webmail - changing a port necessary to ensure security?

From: Aditya, ALD [Aditya Lalit Deshmukh] (aditya.deshmukh_at_online.gateway.technolabs.net)
Date: 02/12/04

  • Next message: N407ER: "Re: Secured Linux box for Windows access"
    To: "Jennifer Fountain" <jfountain@rbinc.com>, <security-basics@securityfocus.com>
    Date: Thu, 12 Feb 2004 23:29:14 +0530
    
    

    > -----Original Message-----
    > From: Jennifer Fountain [mailto:jfountain@rbinc.com]
    > Sent: Wednesday, February 11, 2004 9:33 PM
    > To: security-basics@securityfocus.com
    > Subject: Securing webmail - changing a port necessary to ensure
    > security?
    >
    >
    > I am going back and forth on this one with a consultant on this one and
    > need an expert opinion. So, I turn to you :) When configuring webemail
    > (such as owa) that is using https, is it better to change the default
    > port (443) to an uncommon port (20000)for security reasons? Does it
    > secure it further by doing this?

    that would be security thru obscurity, will add one more layer of secure but it would be very easy to break this one

    doing someing as nmap scan would reveal this

    > Wouldn't it cause more issues than
    > anything if you try to access that site from inside an org that only
    > allows port 80/443 and 21 out?
    >

    none that i would think of.

    > Thank you in advance for any opinions you may share.
    >
    > Kind Regards,
    >
    > Jennifer Fountain
    >
    > ------------------------------------------------------------------
    > ---------
    > Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
    >
    > Protect your network with the comprehensive security solution that
    > integrates six applications for ease of use and lower TCO.
    >
    > Firewall - Virus protection - Spam protection - URL blocking - VPN
    > - Wireless security.
    >
    > Download 30-day evaluation at:
    > http://www.astaro.com/php/contact/securityfocus.php
    > ------------------------------------------------------------------
    > ----------
    >
    >
    >

    ________________________________________________________________________
    Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ----------------------------------------------------------------------------


  • Next message: N407ER: "Re: Secured Linux box for Windows access"

    Relevant Pages

    • Re: My words
      ... Internet Connection Firewall for SP1 and Windows Firewall for SP2 ... download all the security updates - Critical updates with Express ... Get into Safe Mode and password protect it. ...
      (microsoft.public.windowsxp.newusers)
    • [NEWS] Lotus Domino View ACL Bypass
      ... Lotus Domino View ACL Bypass ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A Lotus Notes database contains documents that are organized into views. ... nor are they intended to protect the documents they ...
      (Securiteam)
    • Re: BEWARE: New EULA lets MS ADMIN YOUR Systems!
      ... Microsoft and owners of content secured with Windows Media DRM to limit the ... Digital Rights Management (Security). ... You agree that in order to protect ... Microsoft may provide security related updates to the OS ...
      (microsoft.public.security)
    • Re: Front End/Back End communication
      ... I believe we should further protect the FE Exchange Server: ... the FE is located on the internal network with typical full-stack access to ... There is no such thing as security perfection. ...
      (Focus-Microsoft)
    • Re: Finally, a secure computer
      ... > security at the IBM website is compromised, ... Therefore it is extremely unlikely that any hacker ... > a tiny system served by IIS or the PWS protect himself with the same ... > ICF which does not listen on ports but only opens to responses to messages ...
      (microsoft.public.inetserver.iis.security)