Re: [fw-wiz] Firewalls that generate new packets..






Marcus J. Ranum

Let's take MITM and DOS off the table. No firewall will
protect you against either of those.

I've addressed the MITM and DOS issues. I don't agree
with you, and I have presented my reasoning.

Does a router with ACL+"established" let unsolicited
RSTs through? I thought that all that got through was
SYN, unless it had an ACK. And to do an RST with
an active connection don't you need the sequence #?
That would require a MITM, right?

Yep, it will. Any firewall that does not depend on
tcp sequence #s will allow such an attack.

The hard thing I had to wrap my brain around was the
observation that between a router+ACLs combined
with the state that is held in the TCP stack of the
target, you've got exactly the same thing (and often
quite a bit better!) than a "stateful" firewall.

I respecfully disagree for all the reasons I have outlined
before.... Sum: tcp sequence #s make a difference.

--Patrick Darden
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: cisco 1600
    ... Ask your "guru" to justify his reasoning. ... installed firewal is worse than no firewall> With out a firewall, ... Network person had some trouble ...
    (comp.security.firewalls)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall.
    ... compromise a network, arp poison it, MiTM, access the firewall, ... as others have pointed out, you already have much larger problems at that point, such as the fact that your network has been totally and completely compromised from the inside in order to do the MitM in the first place... ... we're talking very significant owning of a network in order to simply get the firewall password. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall.
    ... distributed metastasis, presto... ... If you're at a point where you have access to the broadcast medium shared by the firewall -- why would you even need to setup a MitM attach against it -- you're already in. ...
    (Full-Disclosure)
  • Re: Problem with Samba and iptables
    ... Nada Lada wrote: ... >> Either way your firewall will allow incoming packets destined for the ... >> broadcast address. ... > If I'm following your reasoning, where I originally have the source as ...
    (comp.os.linux.security)
  • Re: Terayon TJ715 and XP Local Area Connections
    ... What is your reasoning behind this statement. ... > Did you turn off the firewall? ... >> Anyone know the procedure to integrate to Local Area Connections ... >> It is adding the Terayon in one Local Area Connection ...
    (microsoft.public.windowsxp.hardware)