Re: Web Server

From:
Date: 06/04/02


Date: Mon, 03 Jun 2002 23:22:03 GMT

I thought I would hear from you FB. Did you lookup the information I gave
you? What's your opinion?

"FB" <nospam@nospam.com> wrote in message
news:3CFB3AB4.8000707@nospam.com...
> Jack Daniels wrote:
> > Is it possible to run a web server (port 80 open) behind ZAP? How
> > large a risk would be assumed on a local network?
> The risk is proportional to the web server and the modules you run. No
> packet filter (e.g. ZA) will protect your web server if you open port 80.
>
> You should take a web server that is considered almost bug free (not
> IIS) and don't use too much modules. Another option is to use a reverse
> proxy in front of your web server.
>
>



Relevant Pages

  • Buffer Overrun in Talentsofts Web+ (3) (#NISR17042002B)
    ... Name: Web+ Cookie Buffer Overflow ... Attackers can run arbitrary code as SYSTEM on the web server. ... If the server is running IIS 4 and using the Web+ ... As this has limited privileges the risk is reduced. ...
    (Bugtraq)
  • RE: Should webservers, eg. IIS 6 have anti--virus installed on them?
    ... It's part risk analysis, part cost/benefit ... You either choose to accept the risk of pushing out defs ... a/v deployment set in such a way] that I can do this. ... >>If a web server is just a web server, ...
    (Focus-Microsoft)
  • Re: What is the best way to Invoke a java application from ASP.NET
    ... Anybody accessing the web server would be able to execute the program ... >have to give the ASPNET user execute permissions). ... what kind of risk would be raised by giving the ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: assessing IIS 5.0
    ... The risk will be determined by the threat, ... asset coupled with its vulnerability. ... Is the web server in a DMZ, Honeypot, secured portion of the network? ...
    (Pen-Test)
  • Re: Web Server
    ... Jack Daniels wrote: ... > large a risk would be assumed on a local network? ... The risk is proportional to the web server and the modules you run. ...
    (comp.security.firewalls)