Subject | Re: [firebird-support] Any news regarding SuperClassic and events / RemoteAuxPort? |
---|---|
Author | John vd Waeter |
Post date | 2009-01-04T13:41:55Z |
Hi Developers...
Interesting discussion!
Maybe I'm missing something: if a connection is requested from client to
port 3050 on server, and after a connection is established on I guess
some other port, there seems to be a possibility of Keep-Alive through
the same connection... Why not use this Keep-Alive-packets to inform
client of events? No need for separate event-connections and therefore
no problems with firewalls....? Or I'm missing something obvious...
Kind regards,
John
Dimitry Sibiryakov wrote:
John vd Waeter
mailto:john@...
http://www.jvdw.nl
http://www.shotinthedark.nl
Interesting discussion!
Maybe I'm missing something: if a connection is requested from client to
port 3050 on server, and after a connection is established on I guess
some other port, there seems to be a possibility of Keep-Alive through
the same connection... Why not use this Keep-Alive-packets to inform
client of events? No need for separate event-connections and therefore
no problems with firewalls....? Or I'm missing something obvious...
Kind regards,
John
Dimitry Sibiryakov wrote:
>>> 2) Add source host to white list on connect to port 3050.--
>> That looks like a huge potential security hole to me. All the hacker
>> needs to do is to connect on port 3050 and gets access to all ports on
>> server?
>
> Right. I'd say that second line protection is required to allow
> connecions only to FB listening ports. But topic starter is limited in
> money, so, probably, he don't need to care about hackers clever enough
> to find out this hole...
>
> SY, SD.
>
> ------------------------------------
>
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
>
> Visit http://www.firebirdsql.org and click the Resources item
> on the main (top) menu. Try Knowledgebase and FAQ links !
>
> Also search the knowledgebases at http://www.ibphoenix.com
>
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> Yahoo! Groups Links
>
>
>
>
>
John vd Waeter
mailto:john@...
http://www.jvdw.nl
http://www.shotinthedark.nl