AD in the DMZ . . . OK?

From: karl (opium_at_runningriver.co.uk)
Date: 07/28/04

  • Next message: Ansgar -59cobalt- Wiechers: "Re: upgrading to IE6 on w2k servers"
    Date: Wed, 28 Jul 2004 11:49:12 +0100
    To: security-basics@securityfocus.com
    
    

    Hello

    One of the developers I work with has come up with a wild and crazy
    notion to write a .NET app that sits on a DMZ Web server but gets user
    information from the Active Directory on the other side of the firewall..

    I'm inexperienced with this, so did some research and found that this
    kind of thing is possible (plenty of articles on putting Exchange
    servers in the DMZ), but found myself wondering if this ever happens,
    i.e. do people actually have their networks set up this way? Do folk
    expose/replicate AD to the DMZ in practice?

    It's all very well that this stuff is possible, but if it's perceived as
    insecure and not implementable in the real world . . . . . . .

    Thanks for any advice . . . . .

    Karl

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Ansgar -59cobalt- Wiechers: "Re: upgrading to IE6 on w2k servers"

    Relevant Pages

    • Re: AD in the DMZ . . . OK?
      ... If I were to expose any AD domain to the DMZ, ... > Ethical Hacking at the InfoSec Institute. ... > interaction with one of our expert instructors. ... > Attend a course taught by an expert instructor with years of ...
      (Security-Basics)
    • RE: Access from DMZ Was: AD in the DMZ . . . OK?
      ... Subject: Access from DMZ Was: AD in the DMZ. ... > direct Internet connections into you secure network (even VPN ... All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: AD in the DMZ . . . OK?
      ... If the only thing needed is authentication with userid/password, ... If I were to expose any AD domain to the DMZ, ... > interaction with one of our expert instructors. ... > Attend a course taught by an expert instructor with years of ...
      (Security-Basics)
    • Access from DMZ Was: AD in the DMZ . . . OK?
      ... we have to provide some access to our internal networks either from the ... DMZ or from the internet. ... All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: AD in the DMZ . . . OK?
      ... > also an ldap server. ... DMZ to the DC, ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)