Re: RPC over HTTP security
From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 01/27/05
- Previous message: Nick Owen: "Re: Linux boxs authentication to Cisco secure Tacacs ACS ver 3.0"
- In reply to: sf_mail_sbm_at_yahoo.com: "RPC over HTTP security"
- Next in thread: Shawn Wall: "RE: RPC over HTTP security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 27 Jan 2005 02:22:02 +0100 To: security-basics@securityfocus.com
On 2005-01-26 sf_mail_sbm@yahoo.com wrote:
> We are thinking about deploying RPC over HTTP to access email from the
> Internet
Ask yourself two questions:
1. Why does nobody in his right mind do RPC over untrusted networks?
2. How does bloating a protocol by encapsulating it in plain-text make
it any better?
Regards
Ansgar Wiechers
-- "Those who would give up liberty for a little temporary safety deserve neither liberty nor safety, and will lose both." --Benjamin Franklin
- Previous message: Nick Owen: "Re: Linux boxs authentication to Cisco secure Tacacs ACS ver 3.0"
- In reply to: sf_mail_sbm_at_yahoo.com: "RPC over HTTP security"
- Next in thread: Shawn Wall: "RE: RPC over HTTP security"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|