<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Proxy on Inliniac</title>
    <link>https://inliniac.net/blog/tag/proxy/</link>
    <description>Recent content in Proxy on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 24 Aug 2007 16:26:47 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/proxy/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Follow up on Sguil securtiy</title>
      <link>https://inliniac.net/blog/2007/08/24/follow-up-on-sguil-securtiy/</link>
      <pubDate>Fri, 24 Aug 2007 16:26:47 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/08/24/follow-up-on-sguil-securtiy/</guid>
      <description>&lt;p&gt;In the discussion about my post about Sguil security there have been a number of ideas and general thoughts. I&amp;rsquo;d like to write about them here to we can further discuss them. There seems to be consensus on that when a sensors is rooted, there is nothing we can do to prevent injection of bogus data as long as it isn&amp;rsquo;t malformed.&lt;/p&gt;&#xA;&lt;p&gt;Having the agent authenticate itself is a solution, but it relies on the agent credentials to remain secret. So when a webserver is rooted the attacker will have access to the credentials as they will be stored on the webserver itself. So this approach does provide an extra layer of defense but local roots aren&amp;rsquo;t uncommon, so it remains risky. It may still be worth the effort though.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
