Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Dialup Vunerability?
From: "Joseph L. Moll" <jmoll @ acquion . com>
Date: Sun, 17 Mar 1996 20:50:44 -0500
To: firewalls @ greatcircle . com

What is all this noise about putting your local net on the internet by
simply dialing up your ISP with your Windows (3.1 or 95) PC??

It is my understanding that unless you are running a piece of gateway
software on this box that you cannot hop it from the internet on to the
isolated lan.

Internet <--> ISP <--> PC <--> Isolated LAN

Suppose that PC is not running a gateway daemon...  PC is dialed up to the
ISP and is connected with an IP address of 192.0.0.1.  Internal network is
IP network 130.80.0.0 and is not connected to the internet at all.  PC has
an IP address of 130.80.250.1 on the isolated network.

Someone explain to me how a host on the Internet can attack a host on the
isolated LAN in this configuration.

Since the ISP is typically static routed or running BGP4 to one of the
Internet backbones, where would someone on the Internet even begin to get a
route to the isolated LAN?  Granted since an attacker could create a static
route from their network to the isolated network by pointing at the PC's IP
address 192.0.0.1 as a gateway, the fact that there is no dynamic routing
available may be a mute point.

I simply do not see how there is a way that this configuration can place the
isolated network in danger when the PC is simply an end-node on the network.

Please enlighten me if I am wrong,
---
Joseph (Joe) L. Moll  mailto:jmoll @
 acquion .
 com
http://www.acquion.com  phone:864-281-4108  fax:864-281-4576
Acquion, Inc.  Greenville, SC  USA -- Specialists in Electronic Commerce


Indexed By Date Previous: Re: Please unsubscribe me
From: Michael Dillon <michael @ memra . com>
Next: Re: DMZ to Internal Net Security Holes
From: bve @ vidnoe . yourtown . com (Bill Van Emburg)
Indexed By Thread Previous: Disabling NIS for Solaris 2.[45] firewall
From: Scott Barman <scott @ di2 . disclosure . com>
Next: Re: Dialup Vunerability?
From: Jonathan Larmour <jlarmour @ origin-at . co . uk>

Google
 
Search Internet Search www.greatcircle.com