Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall failure modes (was Re: performance)
From: peter @ nmti . com (Peter da Silva)
Date: Tue, 25 Apr 1995 08:07:21 -0500 (CDT)
To: fc @ all . net (Dr. Frederick B. Cohen)
Cc: mjr @ tis . com, firewalls @ GreatCircle . COM
In-reply-to: <9504240117 . AA21779 @ all . net> from "Dr. Frederick B. Cohen" at Apr 23, 95 09:17:42 pm

> I have discussed.  I offer as
> evidence of the continued existence of these potential flaws, the
> eternal <defunct> processes that still exist even in modern versions of
> Unix. 

Why are these a problem? You have to store the exit status for a dead
process somewhere, and you can't reuse the process-id until the parent's
picked it up, so why *not* use an empty process structure?

> Sure - the defunct process problem, the failed logging problem that
> results from resource exhaustion, the problem with NFS pointed to above,

If you run NFS on your firewall you're already dead.

> Even when a file system cache error causes a block of the deny
> file to be read as a block of the allow file?

I have never heard of this sort of error happening on any UNIX file system,
ever.

> Yes, this sort of behavior
> has been detected under certain versions of NFS and Novell and has been
> published for some time. 

NFS is not a UNIX file system, and neither is Novell. They are network file
systems. If your firewall is depending on the security of network resources
it's not a firewall at all.

(if you really want to know why NFS isn't a UNIX file system, mail me under
 separate cover)


Follow-Ups:
References:
Indexed By Date Previous: Secure Modem Pool
From: ari @ soscorp . com (Ari Shamash)
Next: Re: Appletalk resources safe behind IP router?
From: Jas (Matthew K) <matt @ uts . EDU . AU>
Indexed By Thread Previous: Re: Firewall failure modes (was Re: performance)
From: "Simon J. Gerraty" <sjg @ zen . void . oz . au>
Next: Re: Firewall failure modes (was Re: performance)
From: David Miller <isdmill @ gatekeeper . ddp . state . me . us>

Google
 
Search Internet Search www.greatcircle.com