Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20@xxxxxxxxxxxxxxxx
- Date: Mon, 15 Oct 2007 10:37:16 +0000 (UTC)
In article <+kq29A1$EX+C@xxxxxxxxxxxxxxxxxxxxxxxx>, Kilgallen@xxxxxxxxxxx (Larry Kilgallen) writes:
In article <feq6fs$gj5$2@xxxxxxxxxxxxxxxxx>, david20@xxxxxxxxxxxxxxxx writes:If the user is unprivileged the application they have listening on the
In article <Zzl9eeGh$$y1@xxxxxxxxxxxxxxxxxxxxxxxx>, Kilgallen@xxxxxxxxxxx (Larry Kilgallen) writes:
In article <feo3dq$sba$1@xxxxxxxxxxxxxxxxx>, david20@xxxxxxxxxxxxxxxx writes:
In article <Tf7qEQl$YxFl@xxxxxxxxxxxxxxxxxxxxxxxx>, koehler@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx (Bob Koehler) writes:
In article <fel8op$31o$1@xxxxxxxxxxxxxxxxx>, david20@xxxxxxxxxxxxxxxx writes:Only to high port numbers not to well-known ports unless he has the required
As far as I am aware the only authentication ever done with DECNET objects is
to require the incoming connection to supply the target username and password
or appropriate proxy information. This is no different from applications under
TCPIP.
This is very different. Any fool application programmer can open
an IP socket and accept connections without action by the system
admin, who might be or find someone competent to determine whether
the code is full of security holes.
privileges.
Restrictins on "well-known port numbers" only guard against impersonating
an official service.
They do nothing to prevent a security-unaware user from programming
something that violates organization security policy by using a high
port number.
Which I think is what I said in the statement above. There was another similar
posting in which I answered more fully talking about protecting high-port
numbers by the use of stateful firewalls (either on external boxes or on the
system itself).
The business about "well known ports" is a red herring. The issue we
were discussing was the ability of a random user of arbitrary motive
and competence to accept unauthenticated inbound connections.
port will be unprivileged.
What percentage of TCP/IP machines are protected against that ?
What percentage of DECnet machines are protected against that ?
I'd hope most businesses have now moved their firewalls to a default-deny
policy - I know we did (for both incoming and outgoing connections) years ago.
Most home users with more than a single machine on their network (and lots of
businesses) will be running on private addresses behind NAT which, although a
side-effect of it's real function, in effect provides a default-deny firewall
for incoming connections.
Even windows from XP service Pack 2 onwards provides a personal firewall which
by default blocks incoming connections (and for previous versions there are
a number of free third-party personal firewalls).
David Webb
Security team leader
CCSS
Middlesex University
.
- Follow-Ups:
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Bob Koehler
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Larry Kilgallen
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- References:
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Steven M. Schweda
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Rich Alderson
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Bob Koehler
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Rich Alderson
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Larry Kilgallen
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Bob Koehler
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: Bob Koehler
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- From: david20
- Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- Prev by Date: Re: SRVMISMATCH error fix available
- Next by Date: Re: SRVMISMATCH error fix available
- Previous by thread: Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- Next by thread: Re: TCPIP SMTP receiver issues (SYSTEM-F-NOLINKS)
- Index(es):
Relevant Pages
|