Security Basics mailing list archives
Re: Checkpoint smart defance as IPS
From: FV <mailing () beufa net>
Date: Fri, 28 May 2010 00:26:35 +0200
I know that SourceFire has just release a new appliance which can decrypt SSL trafic and analyse it through its SourceFire IPS, in inline or passive mode. Not sure about how it works, but can be something to check to resolve the problem of SSL encrypted traffic http://www.net-security.org/secworld.php?id=9308 More about : http://www.sourcefire.com/products/3D/ssl Hope this can help you ! Regards, FV ------------------------------------------------------------------- On Thu, May 27, 2010 at 22:50, <mzcohen2682 () aim com> wrote:
Hi list friends !!! I did a pentest for a client's web site and found many holes most of them because of Sql injection which can be fixed with a good practice of input validation. I also recommended installing an IPS. the client has checkpoint smart defance module installed on his FW but I guess that this module is not enough because 1. one cant write signatures 2. the clients uses SSL on his web site so the IPS cant see the attack. AM I WRONG?? I think that the client needs to buy a real IPS which can also open the encrypted traffic. which IPS you recommend for doing the task? thanks a lot, Marco ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- Re: Checkpoint smart defance as IPS, (continued)
- Message not available
- Re: Checkpoint smart defance as IPS mzcohen2682 (May 28)
- Message not available
- Re: Checkpoint smart defance as IPS Laurens Vets (May 28)
- Re: Checkpoint smart defance as IPS mzcohen2682 (May 28)
- Re: Checkpoint smart defance as IPS Laurens Vets (May 28)
- Re: Checkpoint smart defance as IPS Trevor Alexander (May 28)
- RE: Checkpoint smart defance as IPS Bretten, Andrew P (May 28)
- RE: Checkpoint smart defance as IPS Craig S. Wright (May 31)
- Re: Checkpoint smart defance as IPS Trevor Alexander (May 31)
- RE: Checkpoint smart defance as IPS Craig S. Wright (May 31)
- RE: Checkpoint smart defance as IPS Craig S. Wright (May 31)
- Re: Checkpoint smart defance as IPS mzcohen2682 (May 28)