Re: Features for a monitoring tool

From: Charles Lee (chuckx@cold-sun.com)
Date: 02/17/03


From: "Charles Lee" <chuckx@cold-sun.com>
Date: Mon, 17 Feb 2003 04:50:14 GMT

On Sun, 16 Feb 2003 22:08:28 +0000, Felinux wrote:

> Mmmm... I see. That means I'll have to rewrite lots of the stuff I
> already did. Not to mention I'll have to swap check.c and checkd.c! =)
> Seriously, I'm not that sure there is a real security gap between the
> two solutions: since both the server and the client would need to run
> 24/7, if one had a bug that could lead to a security problem regardless
> of the flawed program's role (client or server). Ok, a server is
> constantly accepting connections and is therefore inherently less secure
> than a client, but one of the two hosts HAS to act as a server.
> Therefore I don't think I can improve the client/server suite's security
> by swapping the two programs' behavior. I can only choose wich of the
> two parts will be riskier to run.

To further illustrate his point, imagine you have 20 servers (monitoring
clients) being monitored and 1 monitoring server. Like you said, the
server portion would inherently be less secure. So, if there is a
vulnerability, only the 1 monitoring server would be vulnerable. The 20
servers (monitoring clients) would (hopefully) still be safe.

--
chuckx


Relevant Pages

  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: Routing and Remote Access - Authentication Failure
    ... because the real client computer can tunel through it's local NAT router, ... travel the Intrenet, join the VPN and access the server, when this feature ... Their security system decided that the server was trying to steel ...
    (microsoft.public.windows.server.networking)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: Problems with security requirements in Windows WorkGroups.
    ... "A remote side security requirement was not fulfilled during authentication. ... small chat application between a client and a server ... When I try to use the TCP channel I get the error (with NO inner exception ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: VPN -- the next consumer "turnkey"?
    ... I'm not a security expert. ... "A Hamachi system is comprised of backend servers and end-node ... Server nodes track client's locations and provide ... services without providing Hamachi with a list of client IP's. ...
    (alt.internet.wireless)

Quantcast