Firewall Wizards mailing list archives
Re: RE: In defense of non standard ports
From: James <jimbob.coffey () gmail com>
Date: Tue, 24 Jan 2006 23:08:53 +1100
As a postscript, when I managed a corporate firewall, I found that a number of sites and applications were trying to pass arbitrary traffic through HTTPS by just believing that it would not be examined by an application proxy more than checking the headers. Our particular firewall (Symantec SEF) actually had an HTTPS proxy and complained that the handshake was not correct and refused it.
I would have thought stunnel would make light work of SEF. How does the ssl proxying work ? Isn't the whole point of ssl that the session is encrypted end to end. Does SEF do some kind of CA trickery ? On this point of ssl tunneled connections how do the list members deal with it ? Just about any home user can get a piece of web estate and a domain name these days so how do you stop users using ssl tunnels to access resources denied by your policy ? Some ideas I have heard are traffic analysis, HIDS (which could flag the presence of stunnel, a connection to a listening port on localhost or even detect the protocol before it enters the tunnel) and even plain old enumerating goodness (ie you can go to urls' we want you to and everything else is denied) The problem with enumerating goodness is it creates a lot of work for the admin. So what do you do to stop mischievous users ? -- James _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: In defense of non standard ports Behm, Jeffrey L. (Jan 23)
- RE: RE: In defense of non standard ports Bill Royds (Jan 23)
- Re: RE: In defense of non standard ports Tobias Reckhard (Jan 24)
- Re: RE: In defense of non standard ports James (Jan 24)
- Re: RE: In defense of non standard ports ArkanoiD (Jan 24)
- Re: RE: In defense of non standard ports Chuck Swiger (Jan 24)
- Re: RE: In defense of non standard ports Marcus J. Ranum (Jan 24)
- Re: RE: In defense of non standard ports Paul D. Robertson (Jan 24)
- Re: RE: In defense of non standard ports Tim Shea (Jan 24)
- Re: RE: In defense of non standard ports Paul D. Robertson (Jan 24)
- Message not available
- RE: In defense of non standard ports Brian Loe (Jan 24)
- Message not available
- Re: RE: In defense of non standard ports Marcus J. Ranum (Jan 24)
- Re: RE: In defense of non standard ports ArkanoiD (Jan 25)
- RE: RE: In defense of non standard ports Bill Royds (Jan 23)
- RE: RE: In defense of non standard ports Bill Royds (Jan 24)