Firewall Wizards mailing list archives

Re: Web Site Hacks


From: Michael Kyle <mikek () lanl gov>
Date: Thu, 04 Dec 1997 08:13:59 -0700

Edward Cracknell wrote:

a) The ability to run cgi-bin scripts or html form processing in a way
which will create an html page as output. (Many form-based pages take
input and produce a page for output). As a result, it might be possible
to create a page that contains a URL like:

<A HREF=telnet://target.system.behi nd.firewall> Click here </A>

This would generally allow a telnet session from the web server to the
target system and the firewall rules of ONLY http allowed through would
not stop this.


The telnet still occurs on port 23 from the client that clicks on the
link,
not from the webserver.


c) Attacks made to the DNS parent of your web site (ISP) to 'point'
traffic elsewhere

trust and security are vital ... I'd control all of my name servers if
I were you.


-- 
-----------------------------------------------------------------------
Michael F. Kyle                                   PHONE: (505) 667-3230
CIC/Advanced Computing Laboratory, MS B287        FAX:   (505) 665-4939
Los Alamos, NM 87545                              EMAIL: mikek () lanl gov



Current thread: