Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Proxy firewall design.

Proxy firewall design.

From: Darren Reed <darrenr_at_cyber.com.au>
Date: Tue, 10 Mar 1998 23:14:23 +1100 (EST)

A common theme amongst proxy firewalls running on Unix is to limit the
exposure through use of chroot. How many of these segregate it further
such that (say) the smtp proxy uses /fw/smtp, ftp uses /fw/ftp, etc ?
I'm aware of chrooting used for WWW & mail, but I can't see why you
wouldn't use it for all of them. For example, FWTK 2.0 doesn't support
chroot for plug-gw or x-gw but it does for all the others. Of course,
you might even chroot to /fw first, before running any of your proxies...

Darren
Received on Mar 10 1998

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]