Re: What if we don't trust web Server

From: Roger Abell (MVPNoSpam_at_asu.edu)
Date: 06/11/03

  • Next message: S. Pidgorny [MVP]: "Re: What if we don't trust web Server"
    Date: Tue, 10 Jun 2003 21:30:46 -0700
    
    

    "Guogang" <nospam@no_such_domain.com> wrote in news:O5Qg#L5LDHA.704
    @tk2msftngp13.phx.gbl:

    > Hi,
    >
    > In a classic setup:
    >
    > Client----Firewall-----Web Server----Firewall----Database
    >
    > What if we don't trust web server, due to the fact that it is highly
    > exposed? If web server is compromised, user name, password can be
    easily
    > intercepted. What is the best we can do to protect from such attacks?
    >
    > Got some idea to minimize the information exposed to web server?
    >
    > Thanks,
    > Guogang
    >
    >

    If one wishes to hide in a cave, one hides and goes unseen.
    If one wants to glimpse the sun, one risks the open sky overhead.
    Because one's umbrella might break is no reason not to use it
    against sun, rain, and wind.
    The trick is knowing when the unbrella is getting weak.

    -- 
    Roger Abell
    MS MVP (Windows Security)
    

  • Next message: S. Pidgorny [MVP]: "Re: What if we don't trust web Server"

    Relevant Pages

    • Re: Itanium Madison blasts Sun, IBM in encryption specs!
      ... What is the public URL to the standard 4GB system config you are ... SunOne or the IBM WebSphere web server. ... Zeus than Sun ONE. ... There is a partitioning of VxFS in HP-UX. ...
      (comp.os.vms)
    • SN#22246 "Sun Web Server: The Essential Guide"
      ... SYSTEM NEWS FOR SUN USERS ... Detailed Guide to Sun Java System Web Server 7.0 ... comprehensive guide to the Sun Java System Web Server ...
      (comp.sys.sun.announce)
    • SN#18951 Deploying PHP5 Runtime Within Java System Web Server 7
      ... SYSTEM NEWS FOR SUN USERS ... PHP5 runtime bundled with Cool Stack 1.2, ... System Web Server 7 or Apache 2 worker MPM. ... Have a custom version of 'System News for Sun Users' delivered to you ...
      (comp.sys.sun.announce)
    • Re: Reasons for preferring Lisp, and for what
      ... "Sun ONE Active Server Pages" (formerly ChiliSoft ASP), ... for Apache and the Sun ONE web server including ...
      (comp.lang.lisp)
    • Re: What if we dont trust web Server
      ... > In a classic setup: ... > What if we don't trust web server, due to the fact that it is highly ... If web server is compromised, user name, password can be ... If one wants to glimpse the sun, one risks the open sky overhead. ...
      (microsoft.public.security)

    Loading