Firewall Wizards mailing list archives
Re: Re: Firewalls breaking stuff: [Was re: fwtk]
From: Paul Robertson <proberts () patriot net>
Date: Mon, 22 Jul 2002 14:19:03 -0400 (EDT)
On Mon, 22 Jul 2002, Charles W. Swiger wrote:
Most of the firewalls sold today are "hardware" running some "software", too. Some of them are nothing more than a PC running *BSD and web-based firewall management app. Let's say the SSL device is internal: on a PCI card, or is connected via the SCSI bus. Even if the device is vulnerable, how is an attacker going to get to it?
It doesn't function well as an accelerator if it doesn't accept HTTPS connections.
[ Short of compromising and going through the HTTPS server machine, that is. ]
It *is* the HTTPS server, that's the idea{NPI].
vulnerable to compromise than any other network appliance. For instance, has anyone else had to update the firmware on their network switches for the SNMP vulerability?
Only those who turn that feature on and rely on it for operations.
- And you responded that we should get EVEN MORE COMPLEX by adding mystical unauditable devices to the configuration because...? it's better than just implementing a subset of SMTP?Are the mystical unauditable devices sold by some security vendors better?
Nothing is unauditable- it _may_ be that you may or may not have the opportunity/skills/time to perform such an audit, but that doesn't make it unauditable (we can talk all day about what's important to *you* in an audit versus what's important to *me* in an audit- that's a different question all together.)
How could I audit the VPN solution you mention below?
1. Source code review. 2. "Black box" testing. 3. Reverse engineering/disassembly. 4. Pick an Open Source solution and do #1. 5. Independent criteria such as ISO 9001[1], Common Criteria[2], ICSA Labs IPSec certification[3] either alone, or in combination with some other audit criteria. 6. A full 3rd party IT/development audit of the vendor.
People tend to want VPNs between branch offices or permanent home offices because they do take some effort to configure. People don't tend to want VPNs when going to a trade show, or reading their mail from a client site, or from some other transient location.
Most of the companies I've looked at which impement VPN connectivity are perfectly happy to have sales use if from a tradeshow, hotel or client site. Paul [1] Falls under the "not acceptable to me" category. [2] It's necessary to look closely at the protection profile to see if the critria is useful to you. [3] Obviously, ICSA Labs hosts this list, my employer owns the Labs, and therefore I might have some bias towards them. It's necessary to look at the criteria to see if it's useful to you. ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions proberts () patriot net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: FWTK and smap/smapd, (continued)
- Re: FWTK and smap/smapd Rick Murphy (Jul 17)
- Re: FWTK and smap/smapd Charles W. Swiger (Jul 17)
- Firewalls breaking stuff: [Was re: fwtk] Marcus J. Ranum (Jul 18)
- Re: Firewalls breaking stuff: [Was re: fwtk] Dominik Miklaszewski (Jul 18)
- Re: Firewalls breaking stuff: [Was re: fwtk] Charles W. Swiger (Jul 19)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Paul Robertson (Jul 19)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Marcus J. Ranum (Jul 19)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Charles Swiger (Jul 20)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Marcus J. Ranum (Jul 20)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Charles W. Swiger (Jul 22)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Paul Robertson (Jul 22)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Charles W. Swiger (Jul 22)
- Re: Re: Firewalls breaking stuff: [Was re: fwtk] Paul Robertson (Jul 22)
- Re: FWTK and smap/smapd David Lang (Jul 16)
- Re: FWTK and smap/smapd Dominik Miklaszewski (Jul 16)
- Re: FWTK and smap/smapd Paul Robertson (Jul 16)
- Re: FWTK and smap/smapd Marcus J. Ranum (Jul 16)
