Firewall Wizards mailing list archives
Re: Proxy 2.0 secure?
From: tqbf () pobox com
Date: Fri, 26 Jun 1998 01:21:26 -0500 (CDT)
that should be further investigated. (Cyberguard, for instance, happily passes all fragments #2 and up through the firewall, both ways, unlogged. Sure. Filtering is done on #0 (#1 is dropped), but statefullness should enter into the equation somewhere). Many of them had trouble (or a complete
This is a security flaw, and should be reported. There are platforms that will reassemble fragment streams that don't start at offset 0, as if the first received offset was actually 0. The purpose of a firewall is to shield vulnerable hosts from their own problems. Of course, statefulness isn't the answer to the problem; proxying is. =) ----------------------------------------------------------------------------- Thomas H. Ptacek SNI Labs, Network Associates, Inc. ----------------------------------------------------------------------------- http://www.pobox.com/~tqbf "If you're so special, why aren't you dead?"
Current thread:
- RE: Proxy 2.0 secure? Stout, Bill (Jun 23)
- RE: Proxy 2.0 secure? Aleph One (Jun 24)
- <Possible follow-ups>
- RE: Proxy 2.0 secure? Grigorof, Adrian (Jun 24)
- Re: Proxy 2.0 secure? Gillian Steele (Jun 24)
- Re: Proxy 2.0 secure? tqbf (Jun 25)
- Re: Proxy 2.0 secure? Vanja Hrustic (Jun 25)
- Re: Proxy 2.0 secure? Kjell Wooding (Jun 25)
- Re: Proxy 2.0 secure? tqbf (Jun 26)
- Re: Proxy 2.0 secure? Ted Doty (Jun 25)
- Re: Proxy 2.0 secure? Mark Horn [ Net Ops ] (Jun 25)
- RE: Proxy 2.0 secure? Vanja Hrustic (Jun 25)
- RE: Proxy 2.0 secure? ark (Jun 25)
- RE: Proxy 2.0 secure? Stout, Bill (Jun 25)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
- Re: Proxy 2.0 secure? tqbf (Jun 26)
- Re: Proxy 2.0 secure? Vanja Hrustic (Jun 26)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
