Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP Masquerading and vulnerabilities
From: Craig Brozefsky <cosmo @ ebs . net>
Date: Sun, 14 Jul 1996 17:17:42 -0500 (CDT)
To: Mike Shaver <shaver @ neon . ingenia . ca>
Cc: Peter da Silva <peter @ baileynm . com>, firewalls @ GreatCircle . COM
In-reply-to: <199607140617 . CAA20357 @ neon . ingenia . com>

On Sun, 14 Jul 1996, Mike Shaver wrote:

> > Or just block packets that are too short to hold all the options. If you try
> > and reassemble all the fragments that opens you up to a denial of service
> > attack, and there really isn't any legitimate need to have packets that
> > short.
> 
> The Linux 2.0 CONFIG_ALWAYS_DEFRAG stuff is designed to make the
> transparent proxy and NAT code more correct; otherwise, you can get
> things like PORT commands (which matter to the NAT stuff, obviously)
> split between 2 fragments.
> 
> My recommendation is that the transparent proxy stuff is better than
> the NAT stuff (Darren? =) ), but it's not quite as plug-and-play.

I have no problem setting up some proxies from the FWTK, particularly since 
the application I'm looking at would be predominantly Windows users who 
would not be using any other services except the ones which the FWTK 
already has proxies for.

Damn, now if only I could get rid of the need for NFS on my current 
network and I'de have that bastid pretty tightly secured.


Craig Brozefsky				cosmo @
 ebs .
 net
System Administrator			vox: 312-226-1675
EBS.NET					http://www.ebs.net
*****available for limited time only in this dimension****



References:
Indexed By Date Previous: Re: IP Masquerading and vulnerabilities
From: Craig Brozefsky <cosmo @ ebs . net>
Next: Re: Dirty Dogs on AOL
From: Dan Simoes <dans @ ans . net>
Indexed By Thread Previous: Re: IP Masquerading and vulnerabilities
From: Mike Shaver <shaver @ neon . ingenia . ca>
Next: Re: IP Masquerading and vulnerabilities]
From: Darren Reed <avalon @ coombs . anu . edu . au>

Google
 
Search Internet Search www.greatcircle.com