View previous topic :: View next topic |
Author |
Message |
hmo
Joined: 14 Feb 2003 Posts: 81 Location: Denmark
|
Posted: Fri Jul 25, 2003 1:35 am Post subject: |
|
|
Alex!
Within RMA You specify from where connections is allowed - either all or listet IPs. Even though, You can make a active connection to RMA-port... should'nt that be impossible? I mean... if source IP is not allowed to talk to that "deamon" on an given port.. then it should'nt make the connection in the first place! Right?
This might be a small issue, but be aware when useing RMAs through Internet/Firewall's etc. - then the "deamon" should'nt be talking to anyone not specifyed in the rma.ini file.
Cheers,
Hans Mosegaard
|
|
Back to top |
|
|
KS-Soft
Joined: 03 Apr 2002 Posts: 12801 Location: USA
|
Posted: Fri Jul 25, 2003 12:45 pm Post subject: |
|
|
>if source IP is not allowed to talk to that "deamon" on an given port.. then it should'nt make the connection in the first place! Right?
RMA accepts TCP connection from anywhere. But first action it takes is checking incoming IP address. If address is not in the list, RMA drops connections.
Regards
Alex |
|
Back to top |
|
|
hmo
Joined: 14 Feb 2003 Posts: 81 Location: Denmark
|
Posted: Sat Jul 26, 2003 10:18 am Post subject: |
|
|
It's imho not safe enough! Try to do a telnet onto RMA port... even though source IP is not granted, it will stay "connected" as long as you dont do anything! (untill defined timeout value). If you plan to use RMAs through internet/firewall's, then RMA should (read: it *must*) drop connection QUICK when it sees incoming IP address is'nt allowed! Why make RMAs attractive to scans or potiential "closer look" for a hacker?
Cheers,
Hans Mosegaard
|
|
Back to top |
|
|
KS-Soft
Joined: 03 Apr 2002 Posts: 12801 Location: USA
|
Posted: Sun Jul 27, 2003 10:25 pm Post subject: |
|
|
>Try to do a telnet onto RMA port... even though source IP is not granted, it will stay "connected" as long as you dont do anything! (untill defined timeout value).
H'm, what Windows and telnet do you use? On our systems RMA drops connections from unauthorized addresses right away. It waits for data only from IP addresses that are in the list (if you use Accept connections from following addresses). Just checked..
Regards
Alex |
|
Back to top |
|
|
|