Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How secure is xinetd's binding to specific interfaces
From: lists @ lina . inka . de (Bernd Eckenfels)
Date: Wed, 31 Jul 1996 01:52:58 +0200 (MET DST)
To: amsden+ @ andrew . cmu . edu (Zachary Roger Amsden)
Cc: gaarder @ actech . com, firewalls @ greatcircle . com
In-reply-to: <0lzcET200YUf0U=5o0 @ andrew . cmu . edu> from "Zachary Roger Amsden" at Jul 30, 96 05:52:31 pm

Hi,

> many BSD based systems, it is possible to ping an inside interface from
> the outside, even with IP forwarding turned off (so I have been told). 
> I know for a fact that Linux-2.0 and higher (and probably earlier as
> well) are not vulnerable to this.

Linux IS vulnerable to it. It will accept packets from outside on a
interface if the packet matches any of the systems addresses. Outgoing
packets however are nly recognized as local ones, if there is a route that
points to the interface. (Otherwise the packet will be send and the arp code
recognizes it and prints a: 'arp called for my own ip address'.

Since Linux has a interface based firewalling this is not realy a problem.
Geenral Firewall rules should always mask out addresses which should never
happen on a specific interface.

Greetings
Bernd
-- 
  (OO)      -- Bernd_Eckenfels @
 Wittumstrasse13 .
 76646Bruchsal .
 de --
 ( .. )  ecki @
 lina .
 {inka .
 de,ka.sub.org}  http://home.pages.de/~eckes/
  o--o     *plush*  2048/A2C51749  eckes @
 irc  +4972573817  *plush*
(O____O)       If privacy is outlawed only Outlaws have privacy


Follow-Ups:
References:
Indexed By Date Previous: Re: Re[2]: Ascend pipeline products.
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: Re[2]: Ascend pipeline products.
From: "Jim Thompson" <jim @ SmallWorks . COM>
Indexed By Thread Previous: Re: How secure is xinetd's binding to specific interfaces
From: Zachary Roger Amsden <amsden+ @ andrew . cmu . edu>
Next: Re: How secure is xinetd's binding to specific interfaces
From: gunni @ if . is (Gunnar Ingvi Thorisson)

Google
 
Search Internet Search www.greatcircle.com