Re: transfer data (securely) within an protected network via RPC/SSL/...?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello Phillip,

perhaps my question was not exact.
Which protocol/service prefered by admins to tranfered data by my
program between client and server?

Mario

On Jan 26, 5:36 pm, "Phillip Windell" <@.> wrote:
You need to explain what you consider "insecure" is an how you would determine
that it is insecure. Being secure is relative and defined by what you are
trying to be secure "from".

The fact that Blaster used RPC doesn't have any bearing at all as to if traffic
content is "secure" running over RPC. Blaster did not attack the content of the
traffic,..it attacked the machine listening on RPC.

If this is nothing but web traffic from a webserver,..just run the site on SSL
and forget it.

--
Phillip Windell [MCP, MVP, CCNA]www.wandtv.com

The views expressed are my own (as annoying as they are), and not those of my
employer or anyone else associated with me.
-----------------------------------------------------

"Mario Beutler" <mario.beut...@xxxxxxxxxx> wrote in message

news:1169824463.767430.109920@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Hello,
Our software should transfer data between clients in a LAN.

How to transfer data (securely) within an firewall protected office
network?
The admin doesn't need to change firewall or any other settings, if
possible.

Which protocol/service prefered by admins?
- RPC (but W32 Blaster Worm uses vulnerability in RPC)
- Named Pipe (but not available if file and printer sharing is
disabled)
- TCP/IP (but in general admin have to open ports firewall manually)
- SNMP
- SSL
- SSH

Any help is highly apperciated.

Mario


.



Relevant Pages

  • Re: [Full-Disclosure] DCOM RPC exploit (dcom.c)
    ... users throats is grossly _un_professional. ... allow them to do their work in a secure manner. ... > I trivialize the belief that the problem is insurmountable and that not ... I'm not worried about outside RPC attacks. ...
    (Full-Disclosure)
  • RE: Anonymous Web based printing for standard users
    ... local admin group, login and install the printeras the user, then remove ... them from the admin group. ... > which the printer is installed, either using IPP or RPC. ... > creates a local queue which requires local admin rights and with RPC it does ...
    (microsoft.public.inetserver.iis)
  • Re: You dont have permission to read
    ... then you are opening the secured database using a secure workgroup. ... generally the Admin user does not have permission to do ... > permission to read - object name". ...
    (microsoft.public.access.security)
  • Re: Linux Distribution Recomendation
    ... > Security does not depend on the admin alone. ... > secure than the level of security that the underlying software is able to ... Depends on what you mean by 'underlying'. ...
    (Security-Basics)
  • Re: Failed login attempts, anything else I can do?
    ... are the usual attemps at trying to login with various usernames (local, ... the server. ... I am wondering if there is anything else I can do to secure the ... I have changed the admin name, ...
    (microsoft.public.windows.server.sbs)