Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Hey the crackers have a new twist 8-(.
From: Ian Dunkin <imd1707 @ ggr . co . uk>
Date: Tue, 29 Mar 1994 12:29:10 +0100 (BST)
To: Eric Murray <ericm @ MicroUnity . com>, Sean McLinden <sean+ @ andrew . cmu . edu>, firewalls @ GreatCircle . COM, rouilj @ terminus . cs . umb . edu
In-reply-to: <Pine . 3 . 89 . 9403271002 . A5465-0100000 @ uk0x04>

>                  the alternative being real authentication (eg
> SecurId) for every outbound connexion as well as every inbound

Actually, it occurs that in this second scenario -- a confederate of the
baddies, perhaps a disaffected employee inside your network -- even
authentication of outbound connections wouldn't help you: if this
insider is `trusted' -- allowed to make outbound connections through
(say) your telnet application gateway -- then she can if so determined
misuse this channel anyway (eg:

    connects  out via your telnet application gateway to a port on a
    collaborating remote system, which echoes back  commands  to  be
    executed  on  your  local system; user's local program -- either
    custom written, or `expect' wrapped around  an  ordinary  telnet
    client(?)  -- then acts accordingly, and echoes resulting output
    back down the line
                            
..even if she has to supply the connect authentication manually (eg
SecurId) to set the connection up.  So even things like TIS's
authentication hooks don't seem to prevent this kind of thing?

    I.

--
Ian Dunkin <imd1707 @
 ggr .
 co .
 uk>
--


Follow-Ups:
References:
Indexed By Date Previous: Re: FW: White Paper on Firewall Routers
From: "Joseph W. Stroup" <nettech @ crl . com>
Next: [no subject]
From: Jaroslaw Liszowski student WT <liszowsk @ usctoux1 . cto . us . edu . pl>
Indexed By Thread Previous: Re: Hey the crackers have a new twist 8-(.
From: Ian Dunkin <imd1707 @ ggr . co . uk>
Next: twist the crackers
From: webberr @ pictel . com (Bob Webber)

Google
 
Search Internet Search www.greatcircle.com