📄 what_are_the_risks
字号:
>From daemon@inoc.dl.nec.com Wed Dec 1 17:44:07 1993Date: Wed, 1 Dec 93 17:42:55 CSTFrom: ylee@syl.dl.nec.com (Ying-Da Lee)Message-Id: <9312012342.AA26065@florida.syl.dl.nec.com>To: socks@inoc.dl.nec.com, zz5@dswpa.dsdoe.ornl.govSubject: Re: Comparing firewall packages...Cc: ylee@syl.dl.nec.comX-Mailing-List: socks@syl.dl.nec.com (SOCKS discussion list)Status: RO>I will be working with SOCKS now. Any information would be >appreciated. I just want to know how secure SOCKS is, and what >guarantees can be made about it... Thanks.I don't know about guarantees. Should we start with 'as far as Iknow, there is no way...' and see where it ends?As far as I know, there is no way to initiate an attack into yourfirewalled internal network through SOCKS if your SOCKS server isproperly configured. For example, if your internal network is200.100.50 and you put the linedeny 0.0.0.0 0.0.0.0 200.100.50.0 255.255.255.0at the top of your sockd.conf, the SOCKS server will fend offall attempts to go through it to reach your inside hosts. Norouting tricks or IP address spoofing will make any difference.This is not to say that you are not incurring some risks byrunning SOCKS. You are, but these are the risks/vulnerabilitiesaccompanying the applications you allow to run on top of SOCKS,not with SOCKS itself. For example, doing any network communicationwithout encryption runs the risk of having your password or otherconfidential information stolen, whether you use SOCKS or not.Blindly "displaying" a postscript file can end in a disasterregardless of whether you retrieved the file through SOCKS ornot. SOCKS doesn't add more on top of these risks, but it doesn'thelp you deal with them either.Should it?It really can't if SOCKS is to remain a general purpose TCP relayerwithout delving into the specific application protocols. This accountsfor the server's high efficiency. This independence of the applicationprotocol also makes it easy to convert an application program into aSOCKS client. In addition, SOCKS probably will have a fairly easy timeaccommodating security devices in the application protocols if and whenthey are used.So, if on balance you find the security risks of existing telnet, ftp,Mosaic, etc. outweigh their usefulness to you and you are unable orunwilling to develop a more secure version, then SOCKS is not for you.If the balance tilts the other way, welcome to SOCKS.I hope that's enough for a start. Ying-Da Lee (214)518-3490 (214)518-3552 (FAX) Principal Member, Technical Staff NEC Systems Laboratory, C&C Software Technology Center / NEC USA, Corporate Network Administration Division ylee@syl.dl.nec.com************** The rest of this message was automatically appended by the socks listmail munger. To send a message to the entire list, address it to:socks@inoc.dl.nec.com. However, if you want to get off the list orchange your address, please send a message to socks-request@inoc.dl.nec.com,and NOT the entire list. Thank you.**************
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -