Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: How safe is a VPN connexion from within an internal network?

Subject: Re: How safe is a VPN connexion from within an internal network?
Date: Wed, 22 Nov 2006 16:44:40 -0800
I think what he means by disconnecting is not enabling split tunneling. So the only connections allowed are through the tunnel and then at the tunnel endpoint you can control where the user has access.
On Nov 22, 2006, at 9:56 AM, Jeffrey F. Bloss wrote:


David Jacoby wrote:

There are a few solutions for this, ive seen some VPN clients that
disconnects the client machine from the Internet once the VPN
connection is established, this will prevent the attacker to keep his
connection because the client machine only allows connection to be
sent to the remote network via the VPN client, no other connections
are allowed.

Just out of idle curiosity, how would one "disconnect the client from the Internet" when it's typically the Internet that's being used to establish the VPN tunnel? :)

I suppose a piece of software could go to great lengths trying to
prevent any and all connections that weren't VPN, but this would be a
daunting task even if we weren't adding to the mix a condition like
being compromised. Even without that I just don't see this alleged
disconnection as being all that comforting, and a cracker mucking
around in your machine for a few minutes might turn it into one of
those (false sense of) security nightmares.

--
Hand crafted on 22 November, 2006 at 12:46:49 EST using
only the finest domestic and imported ASCII.

Do not meddle in the affairs of dragons, for you
are crunchy and good with ketchup.

<Prev in Thread] Current Thread [Next in Thread>