Re: [suse-security] Application Firewall.
Stephan Gerling wrote: Hi!
Is the SuSE Proxy Suite it too ???? Well, the SuSE Proxy Suite contains yet only an FTP Proxy, see http://proxy-suite.suse.de
What is about NNTP, SMTP, Netmeeting, Telnet.... Are there Proxy´s too ????
Hmm, what about the TIS FWTK (www.fwtk.org) or the Juniper Firewall from Obtuse (www.obtuse.com/open_source/). Imho there's a lack of (good) Application Gateways for Linux - but maybe this changes with the SuSE Proxy Suite?! :-)
What´s about Virus/Trojan or ActiveX and Script Scanning on an Firewall Gateway under Linux. Are there any tools avaible for free or only commercial Produkts ???
Commercial: Trend Micro's InterScan VirusWall (www.antivirus.com), but it does not work with SuSE 6.2 (I have reports, that it does not work with 6.3, too), because it was developed for RedHat 6.x (I hate it, if software does only run with a specific Linux distro). Well, limited to eMail Gateway, either AMaViS (GPL), IspMailGate, Scan4Virus (GPL) or H+B EDV AvGuard (commercial, imho). AMaViS can be found at http://amavis.org - but please have a look at http://www.ce.is.fh-furtwangen.de/~link/security/amavis-patch.php3 and especially http://www.unixzone.com/virus/ IspMailGate is a Perl Module, see (your local) CPAN-Archive. Scan4Virus (works only with qmail), see http://www.geocities.com/jhaar/scan4virus/ AvGate is still beta (currently 0.7, IIRC), see ftp.antivir.de/linux/ I would recommend AMaViS, but, well, I'm biased :-) You may also have a look at: http://www.ce.is.fh-furtwangen.de/~link/security/av-linux.php3 http://www.ce.is.fh-furtwangen.de/~link/security/hotlist.php3#Linux HTH best regards, Rainer Link Maintainer Mini-FAQ "Antivirus software for Linux" Member of the AMaViS Development Group -- Rainer Link, eMail: linkra@fh-furtwangen.de, WWW: http://rainer.w3.to/ Student of Communication Engineering/Computer Networking, University of Applied Sciences,Furtwangen,Germany,http://www.ce.is.fh-furtwangen.de/
[...]
What is about NNTP, SMTP, Netmeeting, Telnet.... Are there Proxy´s too ????
Hmm, what about the TIS FWTK (www.fwtk.org) or the Juniper Firewall from Obtuse (www.obtuse.com/open_source/). Imho there's a lack of (good) Application Gateways for Linux - but maybe this changes with the SuSE Proxy Suite?! :-)
What about DeleGate (http://www.delegate.org/delegate/)? I haven't tried it yet, but it seems to be a nice tool. Does anybody know more about it? Regards, Jan Hildebrandt -- jan.hildebrandt@mathema.de MATHEMA Software GmbH (http://www.mathema.de) Nägelsbachstraße 25a D-91052 Erlangen, Germany Tel: (+49)9131/8903-0 Fax: (+49)9131/8903-55
Jan Hildebrandt wrote:
Hmm, what about the TIS FWTK (www.fwtk.org) or the Juniper Firewall from Obtuse (www.obtuse.com/open_source/). Imho there's a lack of (good) Application Gateways for Linux - but maybe this changes with the SuSE Proxy Suite?! :-)
What about DeleGate (http://www.delegate.org/delegate/)? I haven't tried it yet, but it seems to be a nice tool. Does anybody know more about it?
Well, I have not used it yet, so I can not comment on it. A few months ago, DeleGate was discussed in BugTraq, see: http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-11-08&m... (or do just a search about delegate at www.securityfocus.com) best regards, Rainer Link -- Rainer Link, eMail: linkra@fh-furtwangen.de, WWW: http://rainer.w3.to/ Student of Communication Engineering/Computer Networking, University of Applied Sciences,Furtwangen,Germany,http://www.ce.is.fh-furtwangen.de/
[...]
Well, I have not used it yet, so I can not comment on it. A few months ago, DeleGate was discussed in BugTraq, see: http://www.securityfocus.com/templates/archive.pike?list=1&date99-11-08&msg> ine.LNX.4.05.9911131950140.12742-200000@nb.in-berlin.de (or do just a search about delegate at www.securityfocus.com)
Mmmh, "several hundred unchecked buffers" doesn't sound too promising :-/ but DeleGate's revision history states 1999-12-13 DeleGate/5.9.11 bug fix (buffer overflows, malformed Host generation, etc.) and this is a month after the bugtraq entry was published. Maybe DeleGate is worth a try? I'm definitely interested in it; if anyone of you has got the time to test it, would you please let the list know (or directly send me an email) about the results? Thanks a lot. Regards, Jan Hildebrandt -- jan.hildebrandt@mathema.de MATHEMA Software GmbH (http://www.mathema.de) Nägelsbachstraße 25a D-91052 Erlangen, Germany Tel: (+49)9131/8903-0 Fax: (+49)9131/8903-55
Hi,
Hmm, what about the TIS FWTK (www.fwtk.org) or the Juniper Firewall from Obtuse (www.obtuse.com/open_source/). Imho there's a lack of (good) Application Gateways for Linux - but maybe this changes with the SuSE Proxy Suite?! :-)
What about DeleGate (http://www.delegate.org/delegate/)? I haven't tried it yet, but it seems to be a nice tool. Does anybody know more about it?
Deleagte is full of bugs. So, keep hands off that proxy. Bye, Thomas -- Thomas Biege, SuSE GmbH, Schanzaeckerstr. 10, 90443 Nuernberg E@mail: thomas@suse.de Function: Security Support & Auditing "lynx -source http://www.suse.de/~thomas/thomas.pgp | pgp -fka" Key fingerprint = 09 48 F2 FD 81 F7 E7 98 6D C7 36 F1 96 6A 12 47
participants (3)
-
Jan Hildebrandt
-
Rainer Link
-
Thomas Biege