Firewall Wizards mailing list archives

Re: Opinions on VPN?


From: Robert Graham <robert_david_graham () yahoo com>
Date: Fri, 23 Apr 1999 23:24:30 -0700 (PDT)

Has anyone considered time-disjoint attacks via VPNs?

For example, most home VPN users today use the same machine for both Internet access and corporate
access via the VPN. Now VPN vendors try to lock out normal Internet traffic while connected via
the VPN, but the user can be hacked at other times.

For example, I crack into a machine and install Back Orifice on a Win95 machine along with some
special plug-ins. As soon as the user connects to the VPN, my Back Orifice notifies me and allows
me to "bounce" through into the corporation, allowing me all the rights of the victim. 

Thoughts?

Rob.



_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



Current thread: