Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Any logs of SATAN attacks against firewalls?
From: wolfgang @ wsrcc . com (Wolfgang Rupprecht)
Organization: W S Rupprecht Computer Consulting, Fremont CA
Date: 15 Apr 1995 22:41:25 -0700
To: firewalls @ greatcircle . com
References: <Pine . 3 . 89 . 9504131242 . A1451-0100000 @ maestro . com>

sikpuppy @
 maestro .
 com (Sick Puppy) writes:
>Has anyone seen an S.. attack against a firewall?

Yes.

>If so, could you post part of the logs please?

They're boring.  The firewall used a simple three strikes and you're
out program.

A full solution would use a smarter watcher program that charaterized
an attack and then informed the firewall to update its filters.

One thing I *really* like about the current Morningstar Express
software is that one can update filters whenever some user-defined
trigger packets are received.  In the full blown firewall design one
could run tcpdump on a Unix host and have some high level pattern
matcher watch the tcpdump output.  Any suspicious activity would cause
the program to tell the firewall to raise the drawbridge with respect
to that subnet (or domain etc.).

One could also set tripwires in sendmail/ftp/finger/http etc looking
for someone trying to exploit old bugs (eg. if someone typed "debug"
at sendmail.)  The daemons themselves could then tell the firewall to
slam the door.

This of course assumes that one is willing to live with an occasional
denial of service attack.

-wolfgang
-- 
Wolfgang Rupprecht <wolfgang @
 wsrcc .
 com>  <http://www.wsrcc.com/>


References:
Indexed By Date Previous: Re: Sysco Routers Son't Do Security
From: ATM_Feel_the_Power <joe @ net99 . net>
Next: Re: Sysco Routers Son't Do Security
From: Can Baysal <baysalc @ boun . edu . tr>
Indexed By Thread Previous: Any logs of SATAN attacks against firewalls?
From: Sick Puppy <sikpuppy @ maestro . com>
Next: RE: Any logs of SATAN attacks against firewalls?
From: Shane Kinsch <shane . kinsch @ brite . com>

Google
 
Search Internet Search www.greatcircle.com