Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




firewall-wizards logo Firewall Wizards mailing list archives

RE: RPCs over HTTPS through the firewall
From: Gwendolynn ferch Elydyr <gwen () reptiles org>
Date: Fri, 25 Apr 2003 17:07:42 -0400 (EDT)

On Fri, 25 Apr 2003, Ben Nagy wrote:
Flippant, I know, but - sadly - it does reflect reality. It's ironic,
really, that RPC has been one of the big unix "hack me" services whereas it
is not one of the worst MS offenders. The  Web service, however, has
historically been the exact opposite. Before anyone gets all "platform
agnostic" on me, the original question regarded Outlook traffic to an
Exchange server, so excuse me for being windows centric here.

It may not have been one of the worst MS offenders, but removing or
disablying RPC on a MS box (Win2k for certain, I didn't test beyond
that, due to a limited test set) will cause it to fail in particularly
unhappy ways which are difficult to recover.

cheers!
==========================================================================
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet.  This is the defining metaphor of my life right now."

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]