Firewall Wizards mailing list archives

Re: Important Comments re: INtrusion Detection


From: tqbf () secnet com
Date: Sun, 15 Feb 1998 01:17:39 -0600 (CST)

The most serious problem, of course, is that there is no a priori reason
to think that the IDS's stack is bug-free.  And if you penetrate it, you've
acquired control of a machine that is by definition a perfect sniffer --
for the dark side...

Don't proxy firewalls, and intermediate systems in general, all share this
problem? Or are you saying that as well?

-----------------------------------------------------------------------------
Thomas H. Ptacek                                        Secure Networks, Inc.
-----------------------------------------------------------------------------
http://www.enteract.com/~tqbf                           "mmm... sacrilicious"



Current thread: