Re: can I use keep-state for icmp rules?

From: Mipam (mipam@ibb.net)
Date: 10/31/01


Date: Wed, 31 Oct 2001 14:36:33 +0100
From: Mipam <mipam@ibb.net>
To: Michael Scheidell <scheidell@fdma.com>


> > TCP
> > src_ip.src_port ----> dst_ip.dst_port
> >
> > I can send _any_ TCP packet back,
> >
> > TCP
> > src_ip.src_port <---- dst_ip.dst_port
> >
> > And it will pass provided the source and destination IP and ports all
> > line up. ipfw(8) does not consider the TCP flags, sequence number,

Bit off topic, but nowadays still a lot of so called 'best' and great
commercial firewalls still dont check the sequence number for example.
Would be good enough for udp state keeping in a way,
but not for tcp. Not to mention icmp statekeeping which still
isn't possible in many products.

Mipam.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: a couple of questions from a newbie to this group
    ... The ports that are ... the sequence is the key. ... within a certain amount of time, port X opens and runs a daemon process ... stealth candidate. ...
    (alt.computer.security)
  • Re: Best update order for a new workstation install??
    ... >>1 Gb RAM) I would like to run FreeBSD 4.8 with X windows, ... >>wonder whether my sequence of operations is correct. ... if you have a network you only need to install ... > the ports and sources on one system and share them with the rest.) ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Port-Knocking vulnerabilities?
    ... steal the relevant secrets (the password or the sequence of ports). ... will allow an attacker to learn the secret without having to compromise ... then the authentication mechanism is insecure and thus mere ...
    (Security-Basics)
  • Re: Firewall shows ports being used in sqeuence
    ... I run on XP Pro on cable with no other PCs or devices attached to the network. ... The monitor feature in the FILSECLAB firewall shows that simply to do their work, the browser and newsreader are accepting connections which come into my local ports numbered 1030, 1031, 1032, 1033, etc. ... The sequence is not precisely followed but more or less that is what is happening. ...
    (alt.computer.security)
  • Re: Port-Knocking vulnerabilities?
    ... a security mechanism as cleartext passwords. ... steal the relevant secrets (the password or the sequence of ports). ... Why doesn't that make it a substantial defence against most kinds of ...
    (Security-Basics)