Re: [Full-Disclosure] Lets discuss, Firewalls...

Valdis.Kletnieks_at_vt.edu
Date: 08/30/03

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Authorities eye MSBlaster suspect"
    To: "Mike @ Suzzal.net" <mike@suzzal.net>
    Date: Sat, 30 Aug 2003 00:53:25 -0400
    
    
    

    On Fri, 29 Aug 2003 22:33:06 CDT, "Mike @ Suzzal.net" <mike@suzzal.net> said:

    > I can surf the web from the box so it is fine.

    > Can you get to it? How?

    http://www.microsoft.com/technet/security/bulletin/MS03-032.asp

    You got IE or Outlook on that box?

    (And no, you can't whine "that's not fair, that's not what I asked" - remember that
    the bad guys aren't going to play fair either).

    Incidentally, the *entire* security benefit of NAT is that it usually
    *accidentally* acts as a firewall due to its design (the "no 1 to 1 NATing").
    It won't usually forward packets for a port it doesn't know about - which
    basically means it's acting as a firewall with a default deny policy.

    And yes, you need a firewall as well - if only to protect yourself from
    screw-ups like accidentally enabling 1-to-1 NAT (or if some 1337 haxor
    finds a way to enable it from the outside interface).

    Security in depth. Belt AND suspenders.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Authorities eye MSBlaster suspect"

    Relevant Pages

    • Re: home network behind NAT and firewall ?
      ... >> real Firewall appliance with more than 20 systems at any given time. ... >> firewall provides for the ability to assign both public (not nat) and ... that would reset the router and allow remote control - it was noted ... >> LAN inside their network and it would never have to reach the ISP's ...
      (comp.security.firewalls)
    • Re: NAT vs. True Firewalls
      ... not just mean packet filter. ... A firewall can be made up of one or more ... components that can block or filter protocol traffic between two networks. ... So a NAT can be as much part of a firewall implementation as the ...
      (comp.security.firewalls)
    • Re: 56k dial up on laptop 802.11G ?
      ... NAT is not FW software. ... > firewall is literally anything that defends your network against ... >>By comparing the way NAT functions between two networks, ... >>And I consider the FW appliance to out class the packet filtering NAT ...
      (alt.internet.wireless)
    • Re: do i need a new router
      ... Standard SBS ... > uses IPSec, NAT and port forwarding, Premium SBS includes all that plus ... I've never had a firewall or an appliance ... public connection and always tucked them ...
      (comp.security.firewalls)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... For years I have heard people claim that NAT could be circumvented ... > packet is routed. ... but the only outside network I have access to right now ... > Firewall is a term, most people use other than it was intended. ...
      (comp.security.firewalls)