Firewall Wizards mailing list archives

Re[2]: Web Site Hacks


From: Edward Cracknell <edward () securIT net>
Date: Thu, 4 Dec 1997 21:38:20 GMT

My mailer says Denis Gordon <denis () dcc govt nz>  wrote:
denis >Edward Cracknell <edward () securIT net> said:
denis >
denis >But the 'page' this cgi script produces would be sent back to the
denis >browser. To be activated, the user at the browser has to click it. So
denis >any connection to 'target.system.behind.firewall' would be from the
denis >browser, not from the firewall.
denis >
denis >Or have I missed something fundamental here?
denis >
denis >Denis Gordon - <denis () dcc govt nz>
denis >
denis >

No. I think I did. I haven't tried it, I was trying to think it through!

I think it would appear to come from the client. CGI-bin script
allowing, unless the script itself does something silly.
-----------------------------------------------------------------
Edward Cracknell - <edward () SecurIT net>





Current thread: