Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: chroot/setuid vs type enforcement
From: Dermot Tynan <dtynan @ fws . ilo . dec . com>
Organization: Digital Firewall Engineering
Date: Wed, 29 Nov 1995 14:19:24 +0000 (GMT)
To: jeromie @ garrison . com
Cc: firewalls @ GreatCircle . COM, mjr @ iwi . com, mjr @ switchblade . iwi . com
In-reply-to: <9511290355 . AA06866 @ garrison . com> from "jeromie @ garrison . com" at Nov 28, 95 09:55:08 pm

jeromie @
 garrison .
 com wrote:
> 
> In my eyes, this means that if a proxy were to get 
> subverted, it would not take much to subvert the chroot() setuid() calls and
> gain full access over the firewall.  I would like to hear if anyone has
> comments on this issue..??

If a vagrant program subverts a proxy via buffer overruns or whatever,
with a chroot()/setuid() pair, it's not really the firewall that's in
danger.  The firewall isn't (usually) the target of an attack, it is
the first line of defense which needs to be overcome to attack the real
target (the weakling systems on the inside).  If I can install a
program on the firewall which listens to RED traffic on port, say, 8888
and redirects it to a selected port on the BLUE (inside) network, the
firewall is of no use in terms of security.  I can use this redirector
to attack internal systems.  Facilities like chroot() and setuid()
protect the firewall, and hamper efforts to determine the geography of
the internal network, but the game is still pretty much over.
						- Der
-- 
Dermot Tynan						+353 91 754608
dtynan @
 ilo .
 dec .
 com					 DTN: 822-4608

Digital Equipment International BV, Galway, Ireland


References:
Indexed By Date Previous: Re: FW: Windows NT holes and Lotus Notes holes (fwd)
From: Paul Ferguson <pferguso @ cisco . com>
Next: RE: FW: Windows NT holes and Lotus Notes holes (fwd)
From: Russ Cooper <rcooper @ the-wire . com>
Indexed By Thread Previous: Re: chroot/setuid vs type enforcement
From: "Marcus J. Ranum" <mjr @ iwi . com>
Next: Re: chroot/setuid vs type enforcement
From: Ted Stockwell <stockwel @ sctc . com>

Google
 
Search Internet Search www.greatcircle.com