Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: screend
From: Brent @ GreatCircle . COM (Brent Chapman)
Date: Tue, 24 Jan 1995 09:10:25 -0800
To: Dermot Tynan <dtynan @ corrib . ilo . dec . com>, Jim . Shaw @ actrix . gen . nz, mjr @ tis . com
Cc: firewalls @ GreatCircle . COM

At 02:39 1/24/95, Dermot Tynan wrote:
>'screend' will throw away source-routed packets, anyway.  As for bogus
>'src' addresses, even if they could get through, they'd never get back.

Haven't you been paying attention?  Whether the packets can get back or
not is IRRELEVANT.  There are plenty of attacks that can be carried out
simply by getting packets IN that APPEAR to come from a trusted-by-address
host, regardless of whether or not you can see the results (you don't need
to see them if you can successfully predict what they'd be, and respond as
if you'd seen them).

>In the specific case of 'screend', spoofing a source address from inside
>the firewall won't buy you anything.  'screend' would only allow it to
>talk to the 'gatekeeper' machine anyway, and you can already do that.
>It's a bastion host.

This is HIGHLY dependant on your firewall architecture, and where and how
you have screend deployed.  It may be true for your situation; it's not true
in general.


-Brent

--
Brent Chapman         | Great Circle Associates  | Call or email for info about
Brent @
 GreatCircle .
 COM | 1057 West Dana Street    | upcoming Internet Security
+1 415 962 0841       | Mountain View, CA  94041 | Firewalls Tutorial dates



Indexed By Date Previous: Re: CERT advisory
From: Phil Trubey <phil @ netpart . com>
Next: Node identification
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Indexed By Thread Previous: Re: screend
From: Dermot Tynan <dtynan @ corrib . ilo . dec . com>
Next: Re: screend
From: Dermot Tynan <dtynan @ corrib . ilo . dec . com>

Google
 
Search Internet Search www.greatcircle.com