gabriel rosenkoetter on 14 Feb 2004 21:04:02 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Interview Questions: System Admin


On Sat, Feb 14, 2004 at 03:20:02PM -0500, Peter Grace wrote:
> ~      - Name at least two types of server process that can be an open
> ~        mail relay but are not SMTP server processes.
> SOCKS?  Squid maybe, if you were REALLY good at configuring it?
> netcat and some scripting magic?
[...]
> What answers would you be looking for in that question?

HTTP and FTP servers were the ones I was thinking of. (If configured
to permit it--and many at least *used* to be by default--both can
be asked to make an outgoing TCP connection to an arbitrary host
and port and send user-controlled data.)

> Hell when you get right down to it, anyone could write/install
> a program on the box that could be a method of forwarding tcp
> traffic in the upper port ranges, and the sysadmin would be none
> the wiser unless they looked regularly at open/listening ports and
> noticed a lot of traffic popping up as of late..

Huh. I intended the question to refer only to services you were
running on purpose and needed, otherwise, to be running. Perhaps I
should clarify that.

> Then again, the admin in question should have some sort of firewall in
> place to stop such evildoers before they start....

That would be difficult with a well-behaved firewall that won't
touch protocols above layer 3. (It would have to be filtering
packets based on the application-layer content.)

> I actually like these questions, but I also think that they're more
> for a beginner..

Oh, that's how mine are intended as well, really. If you can't
answer (most of) these, it's really not worth my time to consider
you. You wouldn't necessarily have to be *right*, but you'd at least
have to answer in a way that told me you'd understood the question.

-- 
gabriel rosenkoetter
gr@eclipsed.net

Attachment: pgpIfmcxsbg1c.pgp
Description: PGP signature