Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Long delays for telnet & ftp connects to firewall hosts
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Wed, 29 Nov 1995 00:18:11 +1100 (EDT)
To: mcn @ EnGarde . com (Mike Neuman)
Cc: wag @ swl . msd . ray . com, firewalls @ GreatCircle . COM
In-reply-to: <199511222057 . OAA00873 @ guardian . EnGarde . com> from "Mike Neuman" at Nov 22, 95 02:57:20 pm

In some mail from Mike Neuman, sie said:
> 
> > From: Bill Gianopoulos <wag @
 swl .
 msd .
 ray .
 com>
> 
> > Actually, the recommended action for the firewall is fake a reset of the
> > connection from the destiation host.  Any TCP/IP implementation that pays
> > attention to ICMP destination unreachable is leaving itself wide open
> > to a denial of service attack.
> 
>   I don't know if this is the right reason for faking a reset
> versus using ICMP destination unreachables. Almost any TCP
> implementation will listen to TCP RSTs regardless of the TCP 
> sequence number. As a result, it's just as easy to deny service by
> spoofing TCP packets as it is to spoof ICMP packets. (Okay, sure, you
> have to guess the client's port. Even a brute force attack with, say,
> 2000 guesses comes to only 80k of data)

Which TCP implementations are you talking about here ?

At least testing done by myself and reading the source contradicts what
you're claiming here for post 4.3BSD and even then it isn't as straight
forward as you're suggesting.

darren


References:
Indexed By Date Previous: flash.flashback.com funnies
From: jon @ london . hcsc . com (Jon Shallow)
Next: Penetration Testing
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Indexed By Thread Previous: Re: Long delays for telnet & ftp connects to firewall hosts
From: Bill Gianopoulos <wag @ swl . msd . ray . com>
Next: Re: Long delays for telnet & ftp connects to firewall hosts
From: Mike Neuman <mcn @ EnGarde . com>

Google
 
Search Internet Search www.greatcircle.com