Great Circle Associates Firewalls
(September 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: routing..
From: Bob Stodola <stodola @ relay . fccc . edu>
Date: Fri, 25 Sep 92 04:22:49 -0400
To: hobbit @ ftp . com (*Hobbit*)
Cc: firewalls @ GreatCircle . COM
In-reply-to: Your message of "Thu, 24 Sep 92 17:54:25 EDT." <9209242154 . AA24289 @ ftp . com>

>I was just playing with a brandy-new Sun that someone had had installed in a
>very vendor-default way by some OEM [complete with + in /etc/hosts.equiv],
>and realized that if I do NOT give it a default route, but only routes to some
>of our internal nets, that the outside world will essentially never know it's
>there.  I realized that I could probably do this on several other machines
>that normally never need to talk to the outside.  [And turn off routed, of
>course.]  Now, the question is, is there something I'm missing here such that
>this isn't enough?  I'm not addressing the concept of someone blind-barraging
>the machine with packets from the outside, of course...

I think this is only a viable strategy when you have complete control over all
systems in your network.  If you have a large, rambling network, you have
to assume that any weak, accessible, system on it will give an invader a more
"trusted" status to attack other machines on the net, eventually finding
their way to the machines which you have "secured" in this fashion.

I think an important purpose of a firewall to deny access to systems on my
net which are not well-managed, either through neglect or a low level of
technical expertise.  Even if I didn't care about protecting these systems,
it helps to control what I call the "friend of my brother-in-law's friend"
attack.

-------------------------------------------------------------------------------
Robert K. Stodola                            Phone: (215) 728-3660
Manager, Research Computing Services         FAX: (215) 728-2513
The Fox Chase Cancer Center                  internet: RK_Stodola @
 fccc .
 edu
7701 Burholme Avenue              +--------------------------------------------
Philadelphia, PA  19111           | "Don't ever try to teach a pig to sing:  it
USA                               |  wastes your time and it annoys the pig."
----------------------------------+--------------------------------------------



References:
  • routing..
    From: hobbit @ ftp . com (*Hobbit*)
Indexed By Date Previous: Flames, etc. (an apology)
From: Dave Friedman <davidf @ ocf . Berkeley . EDU>
Next: Re: coversion to digest
From: packman @ tamuts . tamu . edu (Wally Strzelec)
Indexed By Thread Previous: routing..
From: hobbit @ ftp . com (*Hobbit*)
Next: Re: routing..
From: smb @ ulysses . att . com

Google
 
Search Internet Search www.greatcircle.com