CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – Firewalls
Firewalls
Packet Filtering Firewall – First Generation
- Screening router
- Operates at Network and Transport Level
- Examines Source and Destination IP address
- Can deny based on ACLs
- Can specify port
You may also want to consider these CISSP resources from Amazon.com
Tags: <application level firewall, CISSP RE, CISSP reviewer, dynamic packet filtering firewall, firewalls, kernel proxy, NT kernel, packet filtering firewall, proxy server, screening router, stateful inspection firewall, TCP/IP, UDP>
CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – More Protocols
Host-to-Host Transport Layer Protocols
TCP – Transmission Control Protocol
- Connection oriented
- Sequenced packets
- Acknowledgement is sent back for received packets
- If no acknowledgement then packet is resent
- Packets are re-sequenced
- Manageable data flow is maintained
Note: TCP and UDP use dynamic port numbers greater than 1023
Tags: <Address Resolution Protocol, ARP, Bootp, Bootstrap protocol, CISSP RE, File Transfer Protocol, FTP, ICMP, Internet Control Message Protocol, Internet Protocol, Network File Sharing, NFS, RARP, Reverse Address Resolution Protocol, Simple Network Management Protocol, SNMP, TCP, TCP/IP, telnet, TFTP, Transmission Control Protocol, Trivial FTP, UDP>
Join Me On Facebook
Entry Categories
- All Other Items (1)
- Biz Mgt & Dev (8)
- Blog-keeping (1)
- Bum-A-Post (3)
- Don's eBook Report (22)
- eBooks, etc… (9)
- eCommerce / eBiz (22)
- Entrepreneurship (21)
- Geek Mail (2)
- Information Security (40)
- Information Systems (35)
- Information Technology (29)
- InfoSec Docs (11)
- Internet Docs (3)
- Internet Marketing (43)
- IT Docs (4)
- Life Happens (20)
- Project Management (25)
- Random Stuff (12)
- The Demondaynizer (4)
- The Internet (75)
- Web Design / Development (30)
- Yeah Boy! Yah Suck! (5)
-
Recent Posts
- The Art of the Start: The Time-Tested, Battle-Hardened Guide for Anyone Starting Anything (Hardcover)
- How to Use the Internet to Advertise, Promote and Market Your Business or Website with Little or No Money (Paperback)
- Head First WordPress: A Brain-Friendly Guide to Creating Your Own Custom WordPress Blog (Paperback)
- Mastering Joomla! 1.5 Extension and Framework Development: The Professional Guide to Programming Joomla! (Paperback)
- Entrepreneur’s Notebook: Practical Advice for Starting a New Business Venture (Paperback)
- Wordpress Entrepreneur: How To Setup, Customize & Use A Wordpress Website (Volume 1) (Paperback)
- Mastering Online Marketing: 12 Keys to Transform Your Website into a Sales Powerhouse (Paperback)
Follow Me on Twitter
Business Tech Press Releases- Cambium Learning Group Announces Second Quarter Earnings Call July 29, 2010
- Henry Bros. Electronics' CEO Jim Henry to Speak at the National Sports Safety and Security Conference and Exhibition July 29, 2010
- Brazil: Privalia's Success Story July 29, 2010
- InfiniteGraph 1.0 Released by Objectivity, Inc. July 29, 2010
- eBay Supports Resolution to Protect Small Internet Businesses July 29, 2010
Archives
Tags
Blog Book Building business CISSP CISSP Exam CISSP reviewer Development Dummies eBusiness Edition Engine Entrepreneurship Exam facebook From Google Guide Hardcover Information internet Joomla Maceo MAD MAC Management marketing Media Online Optimization Paperback PMP Exam Professional Project Search Secrets Security Social strategies Technology Trehb101 Tweets Twitter with Wordpress Your
Your Shopping Cart
Your cart is emptyCalendar
e-Business News from eCommerceTimes- AT&T Is Winning Its Catch-Up RaceAT&T Mobility and Apple iPhone have been successful together, but every coin has two sides. The other side has been a wireless data logjam. Could that problem finally be getting under control? AT&T has been working very hard to do just that, said Ralph de la Vega, AT&T mobility and consumer markets president and CEO, at last week's Fortune B […]
- Europe's Tender Words About FOSSThere's no denying that everyone needs a little love from time to time, but for those of us in the FOSS community, that need can be particularly acute. After all, rarely a week goes by without some affront from those we had hoped were our friends. Case in point? Dell. Imagine our surprise, then -- nay, outright joy! -- when none other than Neelie Kroes […]
- PRM: It's Not Just CRM for PartnersCRM is a complex thing. It involves understanding your customers and your own business -- two difficult things to fully grasp under any circumstances -- and then using technology to convert that understanding into a positive impact on your business. Customers, and to a lesser extent your business, are always changing. […]
- Senate Committee Hacks Away at Online Privacy ThicketThe pressure on major Web site operators and online advertisers to do a better job of protecting consumers' privacy continues to mount. On Tuesday, Senator John Kerry, D-Mass., said he plans to introduce legislation that would "give people more control over how their personal information is collected and distributed online." […]
- Why That Mountain of Leads Is a Molehill of SalesIn the struggle to grow revenues in tighter markets, most companies are pushing their marketing departments to provide greater market coverage and deliver more sales opportunities. Yet statistics reveal that an astonishing 79 percent of leads generated by corporate marketing departments are never contacted by corporate sales groups. […]
- The Beauty of a Sustainable Supply ChainThe new age of sustainability is like a three-legged stool, and over the last couple of weeks I've discussed my ideas for the first two legs, including customers and energy or transportation. The third leg involves products, and this idea takes some thinking to fully comprehend. Most of us don't think a lot about products because they are ubiquito […]
- Yahoo Japan May Succeed Where Yahoo FailedYahoo Japan has announced that it will begin a relationship with Google to power its search functions and also administer ads that appear on the site. In this deal, the company is not following in the steps of its U.S. counterpart, Yahoo, which cut a deal with Microsoft's Bing, announced last year. […]
- Citigroup Upgrades Careless iPhone Banking AppCitigroup customers who do mobile banking on an iPhone should head to the Apple App Store immediately for an upgrade. A flaw in the Citigroup mobile banking iPhone app released in March 2009 causes personal information to be saved in a hidden file on the mobile device, the banking giant revealed in a letter to customers dated July 20, a day after it released […]
- Doctoring the Customer ExperienceRetailers' worst nightmare has indeed come to bear: American consumers have permanently changed their buying habits, according to research by several firms. Gone are the days of shopping as a pastime. And, for all practical purposes, brand loyalty has just about evaporated. […]
- IBM's Next-Gen 'System of Systems' MainframeFor most systems vendors, the launch of a next-generation server platform qualifies as a pretty big deal. After all, such occasions provide vendors multiple opportunities to strut their visionary stuff, roll out a host of satisfied customers, and highlight their current/future strategies. However, some next-gen platforms are -- literally and figuratively -- […]
- AT&T Is Winning Its Catch-Up Race
From the National Vulnerability Database- CVE-2009-4960 (lanai-core) July 27, 2010Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. […]nvd@nist.gov
- CVE-2010-1577 (content_delivery_system, internet_streamer) July 27, 2010Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL. […]nvd@nist.gov
- CVE-2009-4973 (totalcalendar) July 27, 2010SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action. […]nvd@nist.gov
- CVE-2010-2703 (openview_network_node_manager) July 27, 2010Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe. […]nvd@nist.gov
- CVE-2009-4972 (simpleid) July 27, 2010Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attackers to inject arbitrary web script or HTML via the s parameter. […]nvd@nist.gov
- CVE-2010-0211 (openldap) July 27, 2010The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, […]nvd@nist.gov
- CVE-2009-4971 (vjchat) July 27, 2010SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. […]nvd@nist.gov
- CVE-2009-4958 (emo_breeder_manager) July 27, 2010SQL injection vulnerability in video.php in EMO Breader Manager allows remote attackers to execute arbitrary SQL commands via the idd parameter. […]nvd@nist.gov
- CVE-2009-4970 (t3m_affiliate) July 27, 2010SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. […]nvd@nist.gov
- CVE-2010-2529 (iputils) July 27, 2010Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafted echo response. […]nvd@nist.gov
- CVE-2009-4960 (lanai-core) July 27, 2010





