Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Is OS Vulnerable w/ FW-1?
From: "Scott R. Myers" <srmyers @ voicenet . com>
Date: Sat, 29 Nov 1997 18:33:08 -0500
To: William Cooper <cooper @ io . com>
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <Pine . BSI . 3 . 96 . 971129031520 . 2591A-100000 @ xanadu . io . com>
References: <199711250900 . BAA01784 @ honor . greatcircle . com>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Fundamentally the firewall code embbeds itself into the TCP/IP stack 
between the MAC (Datalink) layer and the Network layer.  As a result 
OS specific and Server App specific bugs do not affect its 
reliability as a firewall.  Of course you have to trust the IP stacks 
reliability in this case but things like stealthing the firewall does 
keep anoying things like Ping of Death the like off your back.

Please note that if for some reason you are running other services on 
an fw-1 box and those services are subject to a malicious exploit it 
is feasible for someone to aquire control of the box using that 
service and thereby have the ability to reconfigure or shutdown the 
firewall.  

Hence my advice to all my clients to let a firewall be a firewall and 
nothing else. Can you run FTP,HTTP,SMTP,DNS and all that on the box.  
Sure but you leave yourself open to potential hacks at application 
layer that will lead to a hacker puting the firewall out of its 
misery.  Please note this is a problem I've observed with a number of 
products on the market and in a statement "Friends don't let Friends 
run other apps on their firewalls"!

At 03:52 AM 11/29/97 -0600, William Cooper wrote:
>Hello-
> I've heard it said that Check Point's Firewall-1 runs in such a way 
that
>the OS is not vulneralbe, or the Firewall is not subject to
>vulnerabilities that exist in the operating system itself.  I'm 
hoping
>someone could affer some pointers to information that offers a more
>detailed explanation of this and possibly addresses whether or not 
it is
>true (re:NT & unix.)  I've searched dejanews and this list's archive 
but
>still have questions. 
> 
>Thanks,
>
>- bill
>
>cooper @
 io .
 com
>
>
>
-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQA/AwUBNICmMx2j3R5oMtAxEQJVvACgnZW1cRWp780GxQYx/OyNx2kErVYAoMG8
sek0wFHHFU3ytjKU4frby+7s
=HC4D
-----END PGP SIGNATURE-----




Follow-Ups:
References:
Indexed By Date Previous: FW-1 secures the OS?
From: William Cooper <cooper @ io . com>
Next: Re: FW-1 Sec. Servers, only 10% of traffic?
From: "Scott R. Myers" <srmyers @ voicenet . com>
Indexed By Thread Previous: Is OS Vulnerable w/ FW-1?
From: William Cooper <cooper @ io . com>
Next: Re: Is OS Vulnerable w/ FW-1?
From: Steve Kruse <jsk347 @ sprynet . com>

Google
 
Search Internet Search www.greatcircle.com