Re: General SSL Question

From: Greg Reinacker (gregnews@rassoc.com)
Date: 06/27/02


From: "Greg Reinacker" <gregnews@rassoc.com>
Date: Thu, 27 Jun 2002 10:06:07 -0600


I remember reading an article a while back (wish I could find it now) that
said something like 70% of security breaches occur behind the firewall. So
given that, if your data is extremely sensitive, I'd encrypt it.

Depending on the network configuration, it's far easier for the amateur to
effectively run a packet sniffer on an internal network than on the
internet...

--
Greg Reinacker
Reinacker & Associates, Inc.
http://www.rassoc.com
http://www.rassoc.com/gregr/weblog/
"Harry Simpson" <hssimpson@nospamphgt.net> wrote in message
news:#S044jeHCHA.2312@tkmsftngp13...
> Why would an intranet need SSL if the web app already depended on Windows
> authentication.  Should the company intranet firewall provide enough
> security for aspnet apps?
>
> Wouldn't SSL (HTTPS) really only be needed for anonymous internet
> applications??
>
> Also, If the application uses cookieless sessions, wouldn't using the
https
> absolute URLS cause the session to renew and screw up any session
> variables.....
>
> Ideas?
>
> TIA
> Harry
>
>


Relevant Pages

  • Re: user list
    ... >Easily done via a null session if you have file and print ... >your network adapter connected to the internet and you do ... >firewall or it is improperly configured. ... >> Is it possible that some external parties retrieve the ...
    (microsoft.public.win2000.security)
  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)
  • Re: XP NOT RESPONDING
    ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • RE: firewall
    ... You need to do a lot of reading about ipfw ... IPFW is the only firewall available to FBSD, ... rules do not function correctly on a DSL or cable internet ... @320 pass in quick on rl0 proto tcp from 63.70.155.0/24 to any port ...
    (freebsd-questions)