Re: Network Devices

Barrie Dempster <[email protected]> Sat, 19 Mar 2005 14:18:48 +0000
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
Biswas, Proneet wrote:
> Hi ,
>   Just picking up a thread of thought.. In the security community, we
> see this increase in the number of devices which say they are IDS/IPS or
> Layer 7 firewall stuff.. and hackers I am sure take the pains to bypass
> these devices. But as part of this forum, are there folks who actually
> figure out vulnerabilities in these devices which can potentially cause
> loss of network connectivity. Many of them use web-interfaces, why is it
> we feel confident that these webservers are secure.
> 
> Thanks.

We don't feel confident that they are secure, since they are most often 
based on common operating systems (usually a BSD). So vulnerabilities 
affecting the core OS can often be exploited on the device based on that
OS. Similarly if they have a web interface it's often based on some 
piece of existing software.


-- 
With Regards..
Barrie Dempster (zeedo) - Fortiter et Strenue

blog: http://zeedo.blogspot.com
site: http://www.bsrf.org.uk
CA: www.cacert.org

"He who hingeth aboot, getteth hee-haw" - Victor (Still Game)

_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
smime.p7s (application/x-pkcs7-signature, 3.3 KB) - not displayed