Re: RPC over HTTP security

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 02/03/05

  • Next message: John Madden: "Disk/PDA Encryption"
    To: security-basics@securityfocus.com
    Date: Thu, 03 Feb 2005 15:16:38 +0000
    
    
    

    On Tue, 2005-02-01 at 22:46 -0500, Steve wrote:
    > We ran OWA with SSL, didn't mean our server didn't get owned by a hacker.
    > Consider running a reverse proxy 'nix based box in front of your OWA box
    > which runs on IIS.
    >
    > STEVE

    And then what?

    Reverse NAT passing through a NIX box offers absolutely no security at
    all unless the NIX box has an IPS/IDS or something of that ilk setup on
    it which you could easily have on the firewall that is between the OWA
    box and the net.

    Having a NIX box in place doesn't offer any security above having a
    firewall unless the NIX box actually has something running on it.

    -- 
    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue
    blog: http://zeedo.blogspot.com
    site: http://www.bsrf.org.uk
    [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]
    
    



  • Next message: John Madden: "Disk/PDA Encryption"

    Relevant Pages

    • Re: Event 1023 POP3SVC Content Engine
      ... the pop3 account was ok. ... > A corrupt message in the users mailbox is causing this issue. ... > Steve Antonio ... >> Access to the mailbox from OWA is ok. ...
      (microsoft.public.exchange.admin)
    • Re: Red x in Message body of OWA
      ... Steve, thanks for the info but that didn't work. ... body of OWA. ... > sneaky way to try to fix it is to install the s\MIME stuff on the troubled ... > workstation (from within OWA go to Options and look down the list for s/MIME ...
      (microsoft.public.exchange.admin)
    • Re: Inetinfo.exe Dr. Watson error, causes OWA and Worldwide Web Publishing service to stop
      ... Install that one on your OWA box. ... There are some other OL2003/Exch 5.5 hotfixes also. ... "steve" wrote in message ... >>> When this happens it causes the worldwide web publishing service to ...
      (microsoft.public.exchange.admin)
    • Re: RPC over HTTP security
      ... >> your OWA box which runs on IIS. ... > Reverse NAT passing through a NIX box offers absolutely no security at ... "Those who would give up liberty for a little temporary safety ...
      (Security-Basics)
    • RE: PEWA for Exchange 2003
      ... use Microsoft desktops, so they never get a warning that their password is ... I configure OWA to inform users that they are going to expire? ... And Great Info, Steve. ... You need to use Outlook XP/2000. ...
      (microsoft.public.exchange.admin)