Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: RE: tunnel vs open a hole

RE: tunnel vs open a hole

From: Behm, Jeffrey L. <BehmJL_at_bvsg.com>
Date: Mon, 7 Apr 2003 15:14:50 -0500

Agreed!

This is one reason why a client I work for has implemented outbound http
proxying *with*
authentication required. While certainly not perfect, this helps keeps most
things
that require port 80 outbound to a minimum.

The biggest problem we have seen is that app developers don't understand how
to
handle a response from the proxy server that says "Hey, you tried to open a
new
connection but did not provide any credentials, so please authenticate."
Rather,
they just blindly assume its gonna work and apparently don't perform any
programming 101 error checking, and just let the app die a horrible
(but deserving :-)) death.

<pet peeve>
When will programmers begin (again) to do basic error checking?
</pet peeve>

Marcus J. Ranum spewed:
> We made a big mistake when we started building
> firewalls that
> allowed outgoing connections that were not individually
> authenticated and
> associated with a human user's request.
>
> mjr.
> ---
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Apr 07 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos