SonicWALL Aventail SSL-VPN SQL Injection Vulnerability
# Code by Asheesh kumar Mani Tripathi www.2cto.com
Defect Overview:
SonicWALL Aventail SSL-VPN is prone to an SQL-injection vulnerability because the application fails to p
, the connection is obtained by the SSL Proxy server and the identity of the user is verified. Then, the SSL Proxy Server provides a connection between a remote user and various application servers. Understanding the meaning of the four key terms helps to understand how ssl vpn is implemented. Proxy, application conver
. ssl vpn users are not restricted by the way they access the internet. The ssl vpn tunnel can penetrate Firewall. However, the IPSec client must support the "NAT penetration" function to penetrate Firewall and open the UDP500 port through Firewall.
4.
, when the user enters a URL in the browser, the connection is obtained by the SSL proxy server and the user is authenticated, and the SSL proxy server provides a connection between a remote user and a variety of application servers. Mastering the meaning of four key terms helps to understand how SSL VPN is implemented
Ssl vpn Definition
The development of ssl vpn is a supplement to the existing SSL applications. It increases the access control and security level and capability of the company.
Ssl vpn
algorithm. Iana (Internet Assigned NumbersAuthority) The official port assigned to openvpn is 1194. In openvpn 2.0 and later versions, each process can manage several concurrent tunnels at the same time.Openvpn uses the features of common network protocols (TCP and UDP) to make it an ideal alternative to protocols such as IPSec, especially when the ISP (Internet Service Provider) filters certain VPN protoc
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.