Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: IP Masquerading and vulnerabilities
From: Craig Brozefsky <cosmo @ ebs . net>
Date: Fri, 12 Jul 1996 19:45:56 -0500 (CDT)
To: firewalls @ GreatCircle . COM

I would like to open a discussion on attacks thru various firewall 
implementations, in particularly Linux/FreeBSD boxes with either IP
Filter or ipfirewall.c doing filtering and masquerading and then 
redirecting pors to local ports to handle some more complex proxies.  I 
have a 2.0.X Linux kernel running this now and am looking at putting 
together a system I can use as a firewall with some reliability.  here 
are some ideas of possible attacks and I would like comments ontheir 
feasability and wether they are being performed presently and if their 
are fixes:


1. Fragmenting packets so that port information is passed in second
   packet and the filter only looks at first so it lets it go thru.  I 
   know this is a possibility with various packet filtering firewalls on 
   the market now.  Linux 2.0 has an option to re-assemble all fragmented 
   packets going thru it before applying the filter which stops it.

2. A sequence number guessing attack (what kidn of sequence number 
   generators do the various OSs have?)

3. Stupid use of gets()

Stoopid configurations don't really count either 8)



Craig Brozefsky				cosmo @
 ebs .
 net
System Administrator			vox: 312-226-1675
EBS.NET					fax: 312-226-1677
Network Consulting			http://www.ebs.net



Follow-Ups:
Indexed By Date Previous: Re: Freeware
From: Don Lewis <Don . Lewis @ tsc . tdk . com>
Next: Open Market
From: mdr @ vodka . sse . att . com
Indexed By Thread Previous: CGI Security Leak !!
From: N Bhalla <bhalla @ wwonline . com>
Next: Re: IP Masquerading and vulnerabilities
From: peter @ baileynm . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com