Great Circle Associates Firewalls
(October 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: liabilities of ports >1023
From: Leland K. Neely <lkn @ s1 . gov>
Date: Thu, 29 Oct 92 7:43:30 PST
To: JMA21624%USA . decnet @ usav01 . glaxo . com (USA::JMA21624)
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <9210291414 . AA15912 @ mycroft . GreatCircle . COM>; from "USA::JMA21624" at Oct 30, 92 09:06:00 am

USA::JMA21624 writes:
> What kind of things can internal users do (inadvertantly or intentionally)
> to expose a network that allows incoming TCP packets destined for ports >1023?
> 
> Can an intruder get in without inside help (either inadvertant or intentional)?
> 

I heard a story this week.  It seemed that one site setup filters to
permit port>1023 access, excepting X and openwin, and thought they were ok.
One user decided that he "REALLY" had to have access so he reset telnet
(or rlogin, I am not sure) to listen to a port equal to his phone
extention. (eg 4532.)  This worked so well, that his buddies all had him do
the same for them.  Now, each machine listened on a different port...

Need I say more?

Lee

BTW I talked to ANS about their solution for a firewall for X.
When you don't have DES encryption at both ends, their secure system
for X isn't.  They don't like me anymore. ;-)



References:
Indexed By Date Previous: liabilities of ports >1023
From: "USA::JMA21624" <JMA21624%USA . decnet @ usav01 . glaxo . com>
Next: Re: icmp considered dangerous ?
From: Brent Chapman <brent @ GreatCircle . COM>
Indexed By Thread Previous: liabilities of ports >1023
From: "USA::JMA21624" <JMA21624%USA . decnet @ usav01 . glaxo . com>
Next: Re: liabilities of ports >1023
From: Brent Chapman <brent @ GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com