Re: [fw-wiz] SANS Top Ten and Commercial Firewalls

From: Paul D. Robertson (probertsat_private)
Date: Thu Oct 03 2002 - 08:34:37 PDT

  • Next message: manatworkyes moderator: "Re: [fw-wiz] SANS Top Ten and Commercial Firewalls"

    On Thu, 3 Oct 2002, Anton A. Chuvakin wrote:
    
    > >proftpd, vsftpd, pureftpd
    > >...
    > >Postfix/Qmail
    > >...
    > 
    > Is there any evidence that helps decide whether its more secure because
    > its written better or because its used less?
    
    (A) Project history- Postfix and Qmail have held up well, proftpd erm, 
    hasn't.  I haven't followed the other two, since FTP is on my list of "Horribly 
    broken protocols I'll never support."
    
    (B) Look at the code.
    
    (C) Developer history.
    
    (D) Developer's understanding of the protocol and its weaknesses.
    
    It's worth factoring in frequency of attack as well as tool prevalence.
    
    HTH,
    
    Paul 
    -----------------------------------------------------------------------------
    Paul D. Robertson      "My statements in this message are personal opinions
    probertsat_private      which may have no basis whatsoever in fact."
    probertsonat_private Director of Risk Assessment TruSecure Corporation
    
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizardsat_private
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    



    This archive was generated by hypermail 2b30 : Thu Oct 03 2002 - 22:17:24 PDT