Great Circle Associates Firewalls
(June 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: intelligent/"stateful" packet filter weaknesses
From: mcr @ milkyway . com (Michael Richardson)
Organization: Milkyway Networks Corporation, Ottawa, ON
Date: 28 Jun 1995 21:04:32 -0400
To: firewalls @ greatcircle . com
Distribution: milkyway
Newsgroups: milkyway.mail.firewalls
References: <9506282219 . AA20446 @ amhux3 . amherst . edu>

In article <9506282219 .
 AA20446 @
 amhux3 .
 amherst .
 edu>,
Peter Couvares <pfcouvar @
 amhux3 .
 amherst .
 EDU> wrote:
>If, say, a UDP packet flies from internal host A through a stateful
>packet filter to external host B in such a way that the firewall
>expects a reply from machine B, what's to stop a second, malicious

  In general, UDP is a big can of worms. I would hope that
commercial packet filters would come with all UDP services 
disabled. 
 
  This kind of attack is possible with any mechanism, application
layer or packet filter, when it comes to UDP, unless you are
examining the data. 

>If not, it seems likely that someone could exploit this in order to
>circumvent the firewall--but I can't think of a specific example
>offhand.  Is it possible that there are there no common situations

  Well, if one were permitting NFS through the firewall... we
get a request a month from customers about how they can do this
kind of thing. (We reluctantly tell them)

-- 
   :!mcr!:            |     <A HREF="http://www.milkyway.com/";>Milkyway Networks Corporation</A>
   Michael Richardson |   Makers of the Black Hole firewall 
 NCF: aa714 || xx714  | +1 613 566-4574 ... mcr @
 milkyway .
 com
 Home: <A HREF="http://www.sandelman.ocunix.on.ca/People/Michael_Richardson/Bio.html";>mcr @
 sandelman .
 ocunix .
 on .
 ca</A>. PGP key available.


References:
Indexed By Date Previous: (fwd) CERT advisory regarding S/Key (fwd)
From: Ron DuFresne <dufresne @ winternet . com>
Next: Re: intelligent/"stateful" packet filter weaknesses
From: Brent @ GreatCircle . COM (Brent Chapman)
Indexed By Thread Previous: intelligent/"stateful" packet filter weaknesses
From: Peter Couvares <pfcouvar @ amhux3 . amherst . edu>
Next: Re: intelligent/"stateful" packet filter weaknesses
From: Brent @ GreatCircle . COM (Brent Chapman)

Google
 
Search Internet Search www.greatcircle.com