[322] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: GE Break-in: via HTTPD?

daemon@ATHENA.MIT.EDU (Mr. Tom Cozzolino)
Mon Jan 16 21:14:38 1995

From: rbntjc@rohmhaas.com (Mr. Tom Cozzolino)
To: www-security@ns2.rutgers.edu
Date: Mon, 16 Jan 1995 16:32:33 +22311259 (EST)
In-Reply-To: <Pine.3.89.9501161157.A11393-0100000@tabitha.pacificu.edu> from "Jeb Weisman" at Jan 16, 95 11:44:55 am
Reply-To: www-security@ns2.rutgers.edu


Previously, Jeb Weisman wrote:
> 
> This is possible.  However, the word on the sysadmin grape vine, and at
> least one of the security lists, is that this may be more smoke and
> mirrors than other more mundane possibilities.  Specifically, improperly
> patched Sun, sniffing inside and outside the network, loose security
> procedures.  Then again, it could be httpd, but perhaps you shouldn't bet
> on it. 

As we move closer to putting up an external HTTPD server, though, the
"big boys" pay attention to silly articles like this.

Hmm.

+=================================================+
|     Thomas J. Cozzolino - Rohm and Haas Co.     |
|     Internet:    tcozz@rohmhaas.com             |
|     Phone/Fax: (215) 619-5451/1633              |
|        PGP Public Key Available                 |
|                                                 |
|         Internet Access for Everyone..          | 
|             - Isn't it Time?                    |
|                                                 |
|       Opinions expressed are my own, not        |
|   necessarily those of Rohm and Haas Company    |
+=================================================+

home help back first fref pref prev next nref lref last post