Great Circle Associates Firewalls
(November 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: setting up a Cisco
From: Craig Metz <cmetz @ thor . tjhsst . edu>
Date: Thu, 25 Nov 1993 20:48:12 EST
To: firewalls @ greatcircle . com
Cc: jimc @ jts . com
In-reply-to: Your message of "Thu, 25 Nov 1993 09:17:42 EST." <9311251417 . AA03687 @ lemon . jts . com>

In message <9311251417 .
 AA03687 @
 lemon .
 jts .
 com>, you write:
>I have the following concern:  The "established" keyword is supposed to
>prevent connections unless the ACK or RST bits are set.  Is it possible
>that someone can spoof/fake/munge a connection by hacking said bits?
>
>My understanding of TCP says "no", but my paranoia says "watch out!"

	The destination host of a TCP packet should either drop such a 
spoofed packet or possibly send a packet that would terminate the connection.
But there is no way to initiate and/or sustain a connection this way so that
real data could flow. There still remains the possibility of denial-of-service
type attacks that would have no particular use for return packets. I have
always wondered at the realistic possibility of such attacks in practical 
setups (if your site has a 56k line, for instance... from the standpoint of
bare IP transport and TCP without connections, is there any way you could do
this? It seems to me that only a badly designed system wouldn't be able to
handle the load, and so it would be only a matter of system bugs), but your
level of paranoia will determine your firewall needs.

	On another side note, you should figure in the human factors involved
with such a setup. I have worked at a site that used something to this effect,
and it creates a lot of headaches when novice users can't understand why they
can telnet and send mail out, but FTP won't work. On the other hand, it at
least allows some commonly used things like telnet to be run from PC- or Mac-
based clients that are easier to use than their *IX counterparts.

								-Craig



References:
Indexed By Date Previous: setting up a Cisco
From: jimc @ jts . com (Jim Carroll)
Next: Proxy tip/cu daemon
From: Ruggiero Angelo <Angelo . Ruggiero @ zh014 . ubs . ubs . ch>
Indexed By Thread Previous: setting up a Cisco
From: jimc @ jts . com (Jim Carroll)
Next: Proxy tip/cu daemon
From: Ruggiero Angelo <Angelo . Ruggiero @ zh014 . ubs . ubs . ch>

Google
 
Search Internet Search www.greatcircle.com