Re: [fw-wiz] Phrack #60: "Java tears down the Firewall"

From: David Lang (david.lang@digitalinsight.com)
Date: 01/03/03


From: David Lang <david.lang@digitalinsight.com>
To: Mikael Olsson <mikael.olsson@clavister.com>
Date: Fri Jan  3 19:47:01 2003

Ok, this then limits the attack to the machine running the browser doesn't
it? Or are you saying that firewalls allow active FTP data connections to
terminate on a different machine then the control connection is from, I
know not all firewalls make this mistake (one more case where a good app
level firewall will win over a stateful firewall)

David Lang

On Fri, 3 Jan 2003, Mikael Olsson wrote:

> Date: Fri, 03 Jan 2003 23:07:19 +0100
> From: Mikael Olsson <mikael.olsson@clavister.com>
> To: Marcus J. Ranum <mjr@ranum.com>
> Cc: fw-wiz <firewall-wizards@honor.icsalabs.com>
> Subject: Re: [fw-wiz] Phrack #60: "Java tears down the Firewall"
>
>
> "Marcus J. Ranum" wrote:
> >
> > Mikael Olsson wrote:
> > >- The firewall automagically pokes a hole for this "data channel"
> > >- The server box is suddenly allowed to connect to this
> > > vulnerable port, through the firewall.
> >
> > Could the java app proxy to other ports internally? Seems
> > like a simple exercise for the malcoder.
>
> Ah, no, the java sandbox only allows connections back to the server
> that served the applet -- the problem is that this security model
> doesn't coexist very well together with the FTP "security model".
>
>
> --
> Mikael Olsson, Clavister AB
> Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
> Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05
> Fax: +46 (0)660 122 50 WWW: http://www.clavister.com
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@honor.icsalabs.com
> http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
>



Relevant Pages

  • Re: What is the Pattern here ?
    ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
    (comp.security.firewalls)
  • Re: Port 135
    ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
    (microsoft.public.security)
  • Re: Black Ice confesses faulty program!!!
    ... > outgoing connections or traffic except in cases where these connections ... > "dangerous/suspicious" traffic by the BlackICE program. ... > get into your machine then even a PC *without* a firewall is completely ... If you don't think "Spyware" is a problem for computer ...
    (comp.security.firewalls)
  • Re: Networking/Security Question...
    ... The router itself will be a Cisco 1721. ... >setup is very simple... ... XP sp2 having the firewall on by default. ... > # but deny established connections that don't have a dynamic rule. ...
    (freebsd-net)
  • Re: XPsp2 firewall - bug? - disables on certain networks
    ... Firewall Settings for Microsoft Windows XP with Service Pack 2" document ... Even if the DNS suffix is different, the computer can get a new policy from ... manually enter the DNS server and suffix settings for all connections. ...
    (comp.security.firewalls)