Security Basics mailing list archives

Re: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618


From: Brad Mills <millsmiami () usa net>
Date: Wed, 25 Jun 2003 00:49:50 EDT

Hilal,

i am not sure if i am asking the right question within the same subject,but 
i am configuring the firewall throught the telnet connecting / from winxp 
workstation.

Is there any possibility for any internal user to use any tools that will 
haijack my telnet password - password for the firewall too!, and what are 
the measurements for securing the telnet session.
 
 This is likely a trivial task:
 
 Windows: cain
 Linux: tcpdump, + others
 
 You're better off examining ssh solutions. <opinion> Have a look at a 
Smoothwall solution and/or LTSP, putting everyone on a (linux) thin client 
<bg>.
 
 cheers, 
 /b



---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: