Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Firewall Wizards: Re: Provocative Query: Are firewalls obsolete in a world involving enterprise WebService SOA

Re: Provocative Query: Are firewalls obsolete in a world involving enterprise WebService SOA

From: Paul Melson <pmelson_at_gmail.com>
Date: Thu, 27 Mar 2008 15:31:17 -0400

> Back in the old days, we had similar situations and they amounted to
"block everything except
> incoming telnet" - well, of course you can do anything over telnet, just
like you can over
> these newfangled web frobozzes.

I guess I'm just questioning the relevance of a comparison between now and
then. You only have security around those protocols that you control.
That's always been true. If you only implement controls for IP, TCP, UDP,
and ICMP, then that's all you get. You don't get control over your SOAP
services or Telnet. Your router won't enforce those protocol standards and
prevent things like PPP-over-Telnet or RPC-over-SOAP. It's not a question
of obsolescence, rather a question of ignorance. And frankly, I don't think
that ignorance is that widespread. Maybe I've been out of consulting too
long.

My take on William's inquiry is that it's a strawman. He basically asked,
"Are devices that control A relevant to the security of systems that do B?"
Well, duh.

> None of this should be taken (please) as an attack on you.
> It's frustration because the ideas you're expressing are bad ideas that
many of us have fought > a long rearguard action against, knowing we'd fail
from the beginning.

You mean *epic* fail from the beginning. :-)

PaulM

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Mar 28 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]