Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Outbound Restrictions.
From: Paul Mason <masonpg @ onto . network . com>
Date: Tue, 03 Dec 96 03:00:00 CST
To: "'Firewalls '" <firewalls @ greatcircle . com>


     Just food for thought.

     I recently caught an open back door at a customers site by auditing 
outbound traffic for the internal source address. Turns out someone was 
dialing out to the internet from their PC while still connected to the 
corporate backbone ( It seems this user felt they should not have to login 
to the firewall before using the internet ). The dial out connection allowed 
someone from the outside get in to the enterprise
( IP routing is a wonderful thing ). The outbound audit triggered when this 
unwanted system then tried to leave the site though the firewall, thus 
notifying security department of the back doors existence. Talk about a 
major violation of site security policy.

     If I am not mistaken there have been several cases where firewalls were 
toppled from the inside by using this same occurrence.

                              Paul Mason
                              Systems Engineer
                              Network Systems Canada
                              paul .
 mason @
 network .
 com

     
     P.S. You can never hope to find anything unless your looking!!
          Audit, Audit, Audit.!!

On Dec 2,  5:12pm, Bill Heiser wrote:
> Subject: restricting OUTBOUND access
>
> An associate of mine is trying to convince me that it's safe
> to restrict only inbound traffic thru a firewall, but to
> allow completely unrestricted traffic outbound.  I'm looking
> for concrete examples of why this is a Bad Thing.  I guess
> I'm thinking in terms of inside users connecting to evil
> services on the outside, with the established connections
> being used to do Bad Things to inside systems.  However
> I don't have any concrete examples.    Also, since
> presumably once someone is "inside" they can do anything
> they want anyway (put stuff on a floppy, fax, etc), that
> makes a case for his argument that allowing outbound
> unrestricted access isn't so bad.  But I'm not convinced.
>
> Any feedback on what kinds of bad things can happen (by users
> on the OUTSIDE) with this kind of firewall setup would be
> appreciated.
>
> Thanks in advance,
> Bill
>
>
> --
>  Bill Heiser   heiser @
 world .
 std .
 com
>-- End of excerpt from Bill Heiser


Indexed By Date Previous: Re:
From: Zayar <zayar @ ksc . net . th>
Next: RE: [Fwd: Caution : Internet Virus]
From: Security Mail <security @ vine . net>
Indexed By Thread Previous: Re: POP3 for TIS firewall
From: Frederick M Avolio <avolio @ tis . com>
Next: Hi, dear guru.
From: Changmin Park <chang @ cosmos . kaist . ac . kr>

Google
 
Search Internet Search www.greatcircle.com