Re: Feedback solicited - best way to harden a mail/web server?
From: teddy (mouschi@cheese-head-state.rr.com)
Date: 12/30/02
- Next message: teddy: "Re: Feedback solicited - best way to harden a mail/web server?"
- Previous message: Tim Haynes: "Re: Various Questions on Dropping SYN Pkts"
- In reply to: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Next in thread: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Reply: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "teddy" <mouschi@cheese-head-state.rr.com> Date: Mon, 30 Dec 2002 17:18:12 GMT
"Jim Levie" <jim@entrophy-free.net> wrote :
> That's pretty much "security through obscurity". Changing the HTTPS port
to
> one greater than 1024 doesn't help if you happen to be running a
vulnerable
> version of Apache/OpenSSL. The vulnerabiltiy is in the application and
> changing the port just makes it a bit more difficult to find the
vulnerabilty.
> If I were trying to penetrate such a system it would take only a few
minutes
> to find the port being used for HTTPS and then I'm in if the application
is
> vulnerable.
You're forgetting something... if apache doesn't need root access and
doesn't HAVE root access, then exploiting it will simply give the attacker a
normal shell. Sure, that's bad, but at least it's another layer of crap the
kid would have to get through. and chances are, this guy's getting bitten by
a worm of some sort.
-Ted
- Next message: teddy: "Re: Feedback solicited - best way to harden a mail/web server?"
- Previous message: Tim Haynes: "Re: Various Questions on Dropping SYN Pkts"
- In reply to: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Next in thread: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Reply: Jim Levie: "Re: Feedback solicited - best way to harden a mail/web server?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|