Palisade Magazine

 
Understanding SSL VPN

July 2006

Understanding SSL VPN

by Bhaven Haria, CISA

What if you are sitting in a hotel room, hundreds of miles away from your office and you need to access the intranet portal of your company? One of the solutions is to publish this portal on the web, so that all employees can access it from anywhere. Publishing all these applications directly on the web can expose the company to multiple security risks as they become accessible to everyone on the Internet. The most common practice adopted by enterprises in such a scenario is to use a VPN. In this article, we will discuss the working of SSL VPN, its key advantages and few concerns about it.… more →

Securing Apache Web Servers

by Siddharth Anbalahan

According to Dr. Johannes Ullrich, CTO of the SANS Institute’s Internet Storm Center, "web application attacks account for a significant portion of hacking activities across the Internet." Securing web servers is an important step towards preventing some of the most common application layer attacks. Netcraft Web Server Survey, June 2006 recorded that Apache is the leading web server in the market with a market share of 61.25%. In this first part of the two part series, we will look at some of the general secure configuration settings of Apache web server.… more →

More on dodging spiders

by Shalini Gupta

In the first part of this article series, we discussed malicious use of spiders and some means to defend against them. In this article, we’ll explore other defenses such as use of onetime links, special links, turing tests and URL tokenization. We will also try to identify the most suitable solution to defend against crawling spiders.… more →

QuizQuiz: Protecting passwords against stealing

Which of these techniques helps in preventing passwords being stolen from the browser?

  1. Using SSL for the authentication pages
  2. Using salted hashing for transmitting passwords
  3. Using an intermediate page after login
  4. All of the above

more →

Search this website

 Search website

Stay Informed

Want to know when the new issues are out? Just fill in your details, we will take care of notifying you when new issues are released:




Subscribe  Unsubscribe

Write to Us

All flowers, brickbats and suggestions are welcome. You can put in yours on the feedback page.

News & Events

  • 20.02.07. Paladion conducts Operational Risk Management Conference in Dubai, Bahrain
  • 27.11.06. Paladion enables ORC achieve ISO 27001:2005
  • 10.11.06. Deloitte’s Asia Pacific Technology Fast 500 calls Paladion/Plynt one of the fastest growing technology companies.
  • 10.11.06. Paladion/Plynt ranked among the fastest growing 50 technology companies in India by Deloitte.
  • 01.08.06. Rajat speaks on the current state of security in Financial firms outsourcing to India