|
|||||||||||
|
What constitutes authorized server access? - was Re: RPAT - Realtime Proxy Abuse Triangulation
From: Gary Flynn <flynngn(at)jmu.edu>
Date: Tue Dec 31 2002 - 08:20:58 EST >This is fundamentally flawed logic. To cite a physical-world
Or is it more complicated? Netbios doors as long as its not C$? Kazaa doors as long as its not at the root directory? What if an organization wants to make SNMP read access available for some reason. Whether for network performance information or an SNMP coffee pot status. Intent is easily provided in telnet and web sessions through common user interfaces with login banners but that is not the case for other protocols.
Maybe we need a new RFC governing "intent notification" so that all
servers offering services to a network will state whether the server is
meant
Of course, if vendors made the default for every service "public" to
promote
(Forgive the HTML mail if it comes through that way. I'm at home and wrestling with new browsers/mail clients.) >
This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Thu Jan 2 12:32:25 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:55 EDT |
||||||||||
|
|||||||||||