Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Reverse Proxy |
|---|---|
| Date: | Sat, 25 Nov 2006 10:23:10 -0500 |
1) how good is the idea to use of reverse proxy as a layer of defense while accessing a web portal .
It is a good only if you implement it properly. It certainly plays a major role in the layered-defense of the web portals.
5) What are some best known and used Revrse Proxy products apart from the well known open source one .
This mainly depends on your user base. Is this a webportal that will be accessible by anyone in the world or is limited to an enterprise.
For limited single enterprise use:
Take a look at Citrix solutions (URLs below). They have the Netscaler product which might fit you needs. It is a essentially a SSL VPN solution.
Another possible solution is to use graphical firewall. This is useful if you really want to secure the your Datastore. In a graphical firewall the content never gets transmitted to the client, instead just the pixel that represent the content get transferred. Citrix can provide this graphical firewall.
The Citrix Presentation server + HTTP server (WebPortal) + DataStore will be inside the firewall. You open only one port (ICA protocol) on the firewall that connects to the Citrix server. Publish Firefox on the Citrix server such that it can only access the web application and nothing else. Then the user outside the firewall will use the web based / java based / active X based ICA client to access the published the firefox with your web application. One key thing to note is that the user is only seeing the graphical output of the web app, so it is a lot more secure then pushing actual content out to the user's browser.
saqib http://www.full-disk-encryption.net
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Segregation of Duties related, Faheem SIDDIQUI |
|---|---|
| Next by Date: | Re: [Full-disclosure] The state of JavaScript Hacking, Martin Johns |
| Previous by Thread: | Reverse Proxy, zack_taple |
| Next by Thread: | Re: Reverse Proxy, warl0ck |
| Indexes: | [Date] [Thread] [Top] [All Lists] |