home page

copyright 1999/2005 vrl labs. - tutti i diritti riservati

home
advisories
library
links
news
review
servizi
tools
freaknet.org
dyne.org
your account

 
 

.:::.search.:::.



 

.:::.who's online.:::.

There are currently, 2 guest(s) and 0 member(s) that are online.

..::lastest advisories::..


Lynx Command Line URL CRLF Injection Vulnerability

Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability

FreeBSD Ptrace/SPIgot Insufficient Signal Verification Denial of Service Vulnerability

Dotless IP Addresses Can Cause IE to Move into Intranet Zone

Invalid RDP Data can Cause Terminal Service Failure

phpBB Allows Remote Users to Modify Default SQL Queries

CDP Vulnerability in Cisco Routers

Hi-Resolution System`s MacAdministrator Hidden Files Disclosure and Access Vulnerability

TYPSoft FTP Server STOR/RETR Denial of Service Vulnerability

Security Bug Found in ht://Dig htsearch CGI (DoS, File Exposure)

Account Management Vulnerabilities in Ipswitch IMail Server

Cisco PIX Firewall Manager Password Disclosure Vulnerability

Atomz Search Engine Cross-site Scripting Vulnerability

Security Bug Found in PostNuke (and possibly PHPNuke

Additional Details Released on the Zone Spoofing Vulnerability

Ipswitch Web Calendaring Buffer Overflow
all advisories


..:::..lastest files..:::..


DNS Flood Detector v1.0

wormulon v0.1.3

ulogd-php v0.7

FWReport v1.1.5

Netl, a Customizable Low Level Network Monitor

WinDefender 2.1.6

NTDaddy, ASP Based Administration Kit

Virge v2.07

PCX Firewall v2.7

Port Scan Attack Detector (psad) v0.9.2

NARC v0.5.1

Nimda Notifyer v1.2

IIS Worms Detector v1.1

Legion of the Bouncy Castle Java Cryptography API v1.09

Samhain 1.2.8
all files








`Govnet` Would Be Costly, Prone to Failure-Experts
posted by: valvoline on 17/10/2001 @ 8.30.30
SAN FRANCISCO - Creating an independent U.S. government computer network that is separate from the Internet would be costly and fail to create a safe haven from hack attacks and viruses, security experts said on Monday.

Last week Richard Clarke, the presidential adviser on cyberspace security, proposed that the U.S. government establish its own network-- dubbed Govnet -- that would be less vulnerable to malicious attacks amounting to a kind of ``digital Pearl Harbor`` Clarke and others have warned could cripple key systems.
While the concept is theoretically feasible, experts said it would be very difficult to execute.

``The idea is sound, to physically separate services that do not require access to the Internet or that have sensitive information,`` said Elias Levy, chief technology officer at SecurityFocus.com. ``Of course, no separation is ever 100 percent.``

For instance, Govnet would be susceptible to the same physical attacks as the Internet if its fiber optic cable were run through the same conduits the Internet uses, Levy said.

Inside the government offices, employees themselves could easily pass viruses from the public Internet to Govnet with floppy disks, unless the floppy disk drive were locked shut, experts said.

The Department of Defense is among the government agencies that already operates its own classified network separate from the Internet. Despite diligent efforts, several computers in that classified network were infected by the Love Letter computer worm last year, experts noted.

NO BULLETPROOF SYSTEM

``The thought is if we can have complete control over it will be bulletproof,`` said Jeff Wyne, vice president of marketing at security services provider Atabok Inc.

``But this is farfetched unless they assume there`s not going to be any kind of human intervention or place where someone is going to connect in through a PC,`` Wyne said.

The larger the network the harder it is to secure, said Bill Cheswick, author of a book on security and chief scientist at network management and security services provider Lumeta Corp.
Users of classified networks are prone to lax security practices because they have the perception that the network they are using is immune from security issues, said Amit Yoran, chief executive of network monitoring form RIPTech.

``They believe that because they are unplugged that they`re secure enough,`` said Yoran, who was director of vulnerability assessment for the Defense Department`s computer emergency response team in 1997 and 1998.

``In reality, what happens is that even the smallest chink in the armor causes the entire infrastructure to fall apart because these kinds of networks don`t have the kinds of security they need, (or) even minimal security practices,`` Yoran added.

USE EXISTING TECHNOLOGY

Yoran and the others recommended that instead of creating a new network from scratch, the government improve its security practices and use existing security technologies.

``We might make the best use of our dollars by taking the security products and processes and technologies which exist and using them more effectively,`` Yoran said.

A compromise, the experts said, is virtual private network technology, which enables corporations to use the Internet securely by encrypting data communications before they are sent over the public network and decrypting them at the receiving end.

But one expert pointed out that users of such technology are only as safe as the computer user at the other end is.

``VPN is a trust relationship, not a security one,`` said Alan Paller, research director of the System Administration, Networking and Security Institute.

Paller predicted that by pursuing a separate, more secure network, the government would force software companies to improve the security of software they develop.

``Think of this money as a reality check on safe networking that will force vendors to build something that is just as safe,`` Paller said.

Copyright 2001, Arizona Central. All Rights Reserved.
comments: (0) |  send this story to a friendprint a friendly page

.:::.mailing list.:::.


subscribe
unsubscribe

 
 

.:::.Login.:::.

Nickname

Password



Don't have an account yet? You can create one. As registered user you have some advantages like, comments configuration and post comments with your name.
 

..:::..news..:::..


Scans to expose Windows RPC vulnerability are increasing

Update Windows before it gets Blasted

Blaster rewrites Windows worm rules

Microsoft to hackers: Don`t publish code

Senator Backs Off Backdoors

SafeWeb ain`t all that

Hackers launch `cyber jihad` on US

Net security: An oxymoron

Microsoft Patch Yanked

Security Attacks Set to Double in 2001

`Govnet` Would Be Costly, Prone to Failure-Experts

Microsoft to Prioritize Security Bugs

XP a National Security Threat?

`Smart Card` Technology Gets Second Look

U.S. could close Gates on hackers, terrorists

Encryption: How Prevalent Is It?

bv-Control for Microsoft SQL Server Launched

The Achilles` Heel of Remote Net Mgmt

Former Federal Agent Calls Xp a Threat to National Security

`Net Routers Still Feeling Effects of Code Red, Nimda

RIAA Attempts to Influence Anti-Terrorism Bill

FBI shuts down `IRA` website

$200m WinXP media assault begins

Symantec users risk redirection to hacker sites

Anthrax-laced letter to MS license div suspected

Internet Security Revenue To Exceed $14 Billion by 2005
all news


..:::..lastest docs..:::..


Ethernet Games Sources

Ethernet Games Slides

EthernetGames DOCS

CryptoWorkshop Sources

CryptoWorkshop DOCS

CryptoWorkshop Slides

An Overview of LIDS

How to tell if your Linux box has been cracked

CRYPTO-GRAM - October 15 2001

Netfilter and iptables: Stateful firewalling for Linux

Comparing E-mail Server Virus Protection Solutions

Cryptography General Discussions and Implementations

THINKERS ANONYMOUS

The world will end tomorrow - official

Kerberos and Windows 2000
all docs


..:::..lastest reviews..:::..


NSA Security-enhanced Linux v2003081307

Sophos Delivers MailMonitor For Notes/Domino

Evidian Announces NetWall 6

DbEncrypt Flexible

LANGuard S.E.L.M.

BlackICE Defender

ftp-voyager 8.0.0.3 - Wins Again!

sygate personal firewall 4.2

FreeBSD 4.4 Released

LSM-based Security-Enhanced Linux
all reviews

.:::. webdesign & webprogramming: valv`0 (PGP KEY) .:::. co-ordinators: hellbreak (PGP KEY) & cmcsynth (PGP KEY) .:::.

All logos and trademarks in this site are property of their respective owner, all the rest © 2001/2219 VRL Team
site powered by: ALIP site creator v1.0b © 2001/2219 VRL Team