Re: Webserver on a DMZ still needed?



On Sun, 3 Sep 2006 12:42:31 +0100
"Davie Elliott - Eluse" <delliott@xxxxxxxxxxx> escreveu assim:

My question is this: does the Exchange
server definatly, need to be put in the DMZ? Or should Microsoft have
patched all the vulnerabilities by now?


well.. DMZ is considered as "good security pratice", since nobody can
guarantee for the integrity of any product, mainly from these origin.
Search for 'exchange vulnerabilities' and you will learn something.

BTW.. since you MUST have a separate server to host it, why in the hell
it will increase your expenses, at all?


--

saudações,
irado furioso com tudo
Linux User 179402/FreeBSD BSD50853/FUG-BR 115
Um país que se diz democrático não pode ter voto obrigatório. Vote - 99
- NULO

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: Multi stage attacks on networks?
    ... Webserver on the DMZ is running an older version of IIS that is ... trojan is executed and attacker has full access ... to the dmz server. ... vulnerabilities to take over a particular resource. ...
    (Bugtraq)
  • RE: VM Host with guests on the Internal and DMZ networks
    ... I'm no security expert, but I've seen some security vulnerabilities with ... Sounds like an awesome way to get a VM into DMZ, ... Not sure how relevant the vulnerabilities below are to you, ... were picked up by a simple "VMWare vulnerability" Google search. ...
    (Security-Basics)