Re: [fw-wiz] Variations of firewall ruleset bypass via FTP

From: Paul Robertson (proberts@patriot.net)
Date: 10/11/02


From: Paul Robertson <proberts@patriot.net>
To: Darren Reed <darrenr@reed.wattle.id.au>
Date: Fri Oct 11 15:38:00 2002

On Sat, 12 Oct 2002, Darren Reed wrote:

> This deserves more treatment than I have given it because I'm
> sure it is a reflection of an attitude people form when they
> have no understanding of roles and responsibilities people have,
> never mind what "software engineering" is, beyond a simple "hack
> on it" mentality.

I think you're taking it more personally than you should[1], let me see if
I can take a less inflamitory stance...

> So your reading, of my saying meaning the "someone else" to be the
> users is quite incorrect. What I said was, literally, quite correct.

I think what Mikael's concern was (and he'll pipe up if I'm wrong, I'm
sure) is that folks looking at the vuln. note will see "IPFilter- Not
vulnerable." and stop there, rather than looking for a Net- or Free-
entry. "Check the specific OS line, or your version number, or upgrade."
Might be more helpful too.

Please note I'm saying this with no direct evidence that the versions
shipping with any prior version of Net- are or aren't vulnerable- because
I think that's irrelevant to the point.

It's really about making sure people know they should upgrade, not about a
particular implementation. That's why I think it was irresponsible for
anyone else to talk about IPF's status, but if they shouldn't, then you
most certainly need to- and it should be verbose enough to ensure that
folks using IPF don't get the wrong idea.

Let's face it, most people don't run up-to-date systems, and we need to
point them to upgrades when we can. It may well be the responsibility of
the individual admin to check and read and dig for info, but since we
*know* that's going to fail more times than it doesn't (and this isn't a
shot at Net- admins, most of my evidence is based on OTHER *nix OS', I'm
just not sure the Net- folks are any different than anyone else.) We can
make it easier to encourage people to upgrade, or not, and I think a lot
of us are advocating that, nothing more.

If I were still admining NetBSD systems in production, I'd look at the IPF
entry well before I'd look at the NetBSD entry because I'd expect you to
have more complete and accurate information. Maybe that's the wrong way
to look at it, but I think that's the gist of the case Mikael proposed.

Paul
[1] Yes, that's really easy to say when you're not the person under fire.
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
proberts@patriot.net which may have no basis whatsoever in fact."
probertson@trusecure.com Director of Risk Assessment TruSecure Corporation



Relevant Pages

  • Re: Terminal Services after Migration to SBS 2003
    ... It's funny, but there are a fair number of folks that I can say "yes, I ... remember we talked about this last time we did that upgrade". ... Kit reference because at least it's a standardized ... emails I get start with "Jeff, I'm in Phase 2, Step B, Item 5 and I'm stuck. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Biblography Styles
    ... I've been doing work for the University of Chicago ... information in a bibliography entry, so I always put it in the ... or date, but if you "suppress" the author inside the reference, you ... and moved tohttp://officelabs.comand while the MS folks are probably working on improving the next version there doesn't seem to ...
    (microsoft.public.word.docmanagement)
  • VMS upgrade changed program behavior, what could cause this?
    ... I have a very puzzling problem, folks, that shakes my group's confidence in ... This averaging is done for each column, ... This is just straight addition and division, folks, nothing fancy. ... HOUR_AVERAGE ran before the upgrade last Dec. ...
    (comp.os.vms)
  • Re: A tale of two macro libraries LIB vs STARLET
    ... The point about help is we told folks they can put stuff in there we take ... >> on an upgrade to replace it. ... >> to be unique and not comflict with anything put in there. ... That's why we have the lovely Product Registry isn't it? ...
    (comp.os.vms)
  • Re: Upgrading laptop processor
    ... 50% of the folks who buy PC parts from these stores have no idea how to ... The gentleman in question has a newish notebook with a Sempron CPU... ... developing expertise and imparting it freely - encouraging consumerism by ... telling someone who wants to upgrade his laptop he must be joking. ...
    (microsoft.public.windowsxp.hardware)