UhOh - I pissed off IT security

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Armitage

Banned
Feb 23, 2001
8,086
0
0
Ok, so we didn't get very far today. They are adamant that a dial-up modem with auto answer not be on their network - and were not very forthcoming with alternatives. About what I expected. I even offered that I would only turn the modem on when the hardware team is actively testing and calls up and asks me to turn it on. No dice.

One guy suggested that I put the modem on one system, and connect that system to the system on the network via the serial ports. That doesn't make any sense to me ... if somebody just compromised your first system via the serial port, what's to stop them from doing the same to the second system??

I proposed the following via email, but had to leave before I got a response.

Machine A
Has the modem and 1 NIC. Runs a firewall that only allows connections from Machine B and only on the NFS ports. The modem writes its files to the volume exported via NFS to Machine B

The modem software runs as a very restricted user - just enough permission to read from the serial port and write to the exported filesystem.

Machine B
2 NICS

First is conected to the corporate network - possibly configured to only allow traffic on port 80

Second is conected only to Machine A via a crossover cable or small hub/switch. Confgured to not accept any incoming connections except for the return NFS connection.

You might be able to substitute some kluge of ssh/scp instead of NFS as well.

Maybe run an antivirus on one or both - ClamAV? And ensure that all files are scanned before the webserver can touch them. Maybe run an SELinux distro to lock things down harder with ACLs and such?

What do you guys think? Is this reasonable? Does it significantly reduce the risk?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |