Re: What does a firewall do?

From: Justins local account (justin-nntp_at_pipemedia.net)
Date: 01/20/05


Date: Thu, 20 Jan 2005 13:30:53 +0000

Nick Roberts <nick.roberts@acm.org> writes:

> All the documentation I have read says that the 'ident' service should never
> be used for authentication, and generally shouldn't be implemented at all.
> What am I missing?

It shouldn't be used for authentification, but it is used in logging.

the downside is that it allows thingsthe outside to recieve
identifiers from your system, and these are often usernames. Some
people consider this to be a dangerous information leak.

If you don't implement it, your server will reply with a port closed
message, and my server will carry on straight away.

If on the other hand, you do implement the service, and I have a query
about activity on my server, when I ask you for your input I can
advise you that your system advised me it was the httpd user that was
trying to send mail at 3:15 am, and you have a better clue where to
start looking.

-- 
Justin Murdock


Relevant Pages

  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)
  • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
    ... SYSTEM account. ... In IIS I took the virtual server that I was testing, ... Authentication premise. ... From a website perspective, I ...
    (microsoft.public.inetserver.iis.security)
  • Need help configuring Wireless Connection profile
    ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Remote Web Workplace Issues-Please help!
    ... Open the Server Management Console, ... client after Authentication" right. ... permissions, and Microsoft Windows user rights according to the KB 812614. ... Download the IIS Resource Kit tools from the following page: ...
    (microsoft.public.windows.server.sbs)
  • [REVS] NTLM HTTP Authentication is Insecure By Design
    ... in front of a web server, and that proxy server shares a single TCP ... These are attacks that make use of non-RFC HTTP requests (HTTP Request ... the authentication is associated with the ...
    (Securiteam)

Quantcast