Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Secure Modem Pool
From: ari @ soscorp . com (Ari Shamash)
Date: Wed, 26 Apr 1995 10:22:06 -0400
To: FV Admin mail <fvadmin @ sgf . fv . com>
Cc: Steve England <se @ adv . sbc . sony . co . jp>, firewalls @ GreatCircle . COM
In-reply-to: <Pine . 3 . 89 . 9504251839 . A3178-0100000 @ sgf . fv . com>
References: <199504251416 . KAA02711 @ dauntless . soscorp . com> <Pine . 3 . 89 . 9504251839 . A3178-0100000 @ sgf . fv . com>

>>>>> On Tue, 25 Apr 1995 18:15:52 +0100, FV Admin mail <fvadmin @
 sgf .
 fv .
 com> said:

	FV> Well, that's just *broken*.  Either that, or it's from the
	FV> way-back days when the callee couldn't hang up on a call
	FV> if the caller stayed off hook.  Nowadays, there's no
	FV> possible reason why a callback modem wouldn't just hang up
	FV> the line itself before picking up, listening for
	FV> dial-tone, and dialing.

Regular POTS lines do not have any sort of out-of-band signaling to
determine when the phone line has actually hung up (unlike ISDN, for
example).  The only way a modem can know that it really hung up the
line is by getting a dialtone, which can be simulated.  Have you ever
pressed the on-hook button on your phone momentarily, and when you
lifted your finger the line was not hung up, and you could actually
continue the conversation?  The same thing can happen with a modem.

Of course, there are ways around this problem: Have the modem hang up
the line for a ridiculous period of time (say, on the order of a
minute or two), and then reuse the line.  But unless things are set up
this way, it opens up a security hole.

Ari Shamash
SOS Corporation


References:
Indexed By Date Previous: Re: Firewall Failure Modes
From: James Smilanich <jsmilan @ subzero . winternet . com>
Next: Re: Firewall failure modes (was Re: performance)
From: "Frank Byrum" <byrum @ vbv . dec . com>
Indexed By Thread Previous: Re: Secure Modem Pool
From: Christian Wettergren <cwe @ it . kth . se>
Next: Re: Secure Modem Pool
From: lars @ RNS . COM (Lars Poulsen)

Google
 
Search Internet Search www.greatcircle.com