Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
The great firewall of China
Scott Granneman, 2005-08-30

In the 1980s, I was unbeatable in Trivial Pursuit, and to this day, I still possess a love of trivia. Here's some neat facts about the Great Wall of China. Did you know...

Comments Mode:
The great firewall of China 2005-08-31
Trinidex (2 replies)
Re: The great firewall of China 2005-09-09
Anonymous
Re: The great firewall of China 2005-09-22
Anonymous
Resources for practical deployment 2005-08-31
Alex Nordstrom
The great firewall of China 2005-08-31
Art Blummer
The great firewall of China 2005-08-31
Erik Norgaard
The great firewall of China 2005-08-31
Roger Davies (1 replies)
Re: The great firewall of China 2005-09-08
transplant
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Mihai
The great firewall of China 2005-08-31
carpy
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous (1 replies)
Re: The great firewall of China 2005-09-10
Anonymous InfoSec Guy
While I appreciate your situation, and agree with most here that if any netblock from anywhere becomes a problem, it should be blocked entirely, I think you have some contributory issues that speak to the larger security problem most organizations face. How do "they" know how to target your domain controller? If you have that much information about your internal network leaking out of your perimeter, you have some additional securing to do of your own, or geographical location will have nothing to do with your server's eventual compromise.

Most best practices agree that MS DCs should not be visible _from_ the outside, and many agree that they should not be allowed direct access _to_ the outside. They are too critical to internal operations, and hardware is too cheap to host several mission critical functions on the same box if they require different levels of external access. Best practices recommend this separation of function to different boxen for this reason, among others. Same goes for your mail server if it is your primary internal mail server. Set up a proxy or a separate MTA for external mail receipt and transmit. You appear to be ripe for a zero-day pickoff of your entire internal network, and you told the whole world yourself right here.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/350/32354#32354
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous
The great firewall of China 2005-08-31
Anonymous
That's just shocking 2005-08-31
Colin
The great firewall of China 2005-08-31
JustDisGuy
The great firewall of China 2005-08-31
vonbrand
The great firewall of China 2005-09-01
Anonymous
The great firewall of China 2005-09-02
Anonymous
The great firewall of China 2005-09-03
Anonymous
The great firewall of China 2005-09-05
cto74@hotmail.com
The great firewall of China 2005-09-19
Mike Gaynes







 

Privacy Statement
Copyright 2008, SecurityFocus