Security Basics mailing list archives

Unrestricted Outbound Web Server Access Opinion


From: "Paul Guibord" <pguibord () tngtech net>
Date: Tue, 3 May 2005 08:54:57 -0400


Hello All,

Someone within our company wants our Internet facing web servers to have
unrestricted outbound access. Port 80 is the only port permitted from
the outside coming in. I need the experts opinion why we do not want to
permit this PLEASE. Two things I could think of are if the web servers
were compromised, then the hacker would have the ability offload any
data they want. Another being if they were infected with a worm they
would bring down the Internet T1 in their attempt to find other devices
to infect.

Thanks in advance for everyone's input.

Paul


Current thread: