4 ms·
Is a VPN significantly less likely to be exploitable than SSH? Yes, for a few reasons. First, a VPN provides defense in-depth -- compromising a server now req
by ankp 17y ago
Is a VPN significantly less likely to be exploitable than SSH?
Yes, for a few reasons.
First, a VPN provides defense in-depth -- compromising a server now requires finding two unpatched vulnerabilities:
* You must find a vulnerability in the VPN implementation that allows you to leverage the VPN or the VPN host to forward your traffic.
* You must then find an additional vulnerability to use against the actual secured hosts made available over the VPN connection.
There should be a firewall between the VPN entry-point and your internal networks, to limit access to unapproved services.
As a single point of entry, a VPN is also easier to secure. If all servers are inaccessible except for approved services, then a single server running an unapproved vulnerable service (or an account with a weak password or key) does not open the door to immediate external compromise.
This single entry point also allows you to offset the likelyhood of user failure (such as choosing poor passwords) by using additional two-factor authentication. RSA SecurID or PKCS#11 are often too heavyweight for using every time you want to SSH'ing into a host, but they're far more reasonable for initially connecting to the VPN.
- iuguy 17y agoNot necessarily. What about exploiting VPN clients? http://www.zerodayinitiative.com/advisories/ZDI-09-024/ http://www.zerodayinitiative.com/advisories/ZDI-09-024/ There's also the configuration to consider. Using PSK or aggressive mode for VPNs can be considered bad but are you really going to deploy a full RADIUS solution just to access a web server? Compare this to using public key based auth on SSH, I know which one I'd rather have for a web server.
- ankp 17y agoNot necessarily. What about exploiting VPN clients? IPSec is a disaster, one aspect of which is having a client daemon listening on an open port for isakmp/ike key exchange. There's also the configuration to consider. Using PSK or aggressive mode for VPNs can be considered bad but are you really going to deploy a full RADIUS solution just to access a web server? Provisionally "yes", but I'd actually use OpenVPN, wired into our existing directory infrastructure. Compare this to using public key based auth on SSH, I know which one I'd rather have for a web server. Why do you consider it a net win to reduce the entry barrier to only one exploit, one bad user password, or one misconfigured host?