RE: [Full-Disclosure] Sidewinder G2

From: Mike Fratto (mfratto_at_nwc.com)
Date: 11/20/03

  • Next message: Ron DuFresne: "RE: [Full-Disclosure] Sidewinder G2"
    To: "'Ron DuFresne'" <dufresne@winternet.com>, "'Brent J. Nordquist'" <b-nordquist@bethel.edu>
    Date: Thu, 20 Nov 2003 12:37:41 -0500
    
    

    >So, then I have to ask here; do you or anyone
    > else know of a security incident that compromised the
    > perimiter guarded by one of these blackboxen?

    Yes, I did. Through the transparent HTTP application proxy in version 4.1,
    as I stated in an earlier email but...

    >And I'd direct
    > folks to the sec-focus vuln listings to determine how these
    > systems have faired historically say since oh, 1995 or so.

    If you not current with security software to the last two years your screwed
    anyway. A search at Cert for "Secure Computing" and "Sidewinder: yielded 6
    entries, the earliest in 2002. A search at BugTraq db at security focus
    showed 0. Hrmmmm. The consistent response at Cert was that the vuln didn't
    yield anything useful due to Type Enforement.

    The SideWinder is a proxy firewall and it has application support many of
    the common protocols like HTTP, SMTP, FTP, telnet, SQL*Net, H.323, T.120,
    etc. What you need to remember is that even if the external proxy contains a
    vulnerability doesn't mean that traffic will be passed internal hosts. You
    also have to remember the limitations if application proxies, many only deal
    with protocol headers and don't even look into the protocol payload. So
    exploits against vulnerable servers are typically stopped because 1) the
    exploit contains characters outside of the set defined by RFC822 (aka binary
    characters ASCII 128-255) or can be contained by header length enforcement
    (do you really need a HTTP host: header length greater than 50 characters?).
    The application proxy can also limit commands to a subset, which is useful,
    but makes support for using TLS within SMTP impossible. Now there are still
    ways round this type of processing like sending ASCII encoded shellcode, but
    you might also bump into those pesky line length issues.

    I have tested Sidewinder 4.1, 5.0, and G2 and for the most part it provided
    the protective functions that SecureComputing claimed. I tested G2 by trying
    to send illegal characters in the headers, overly long header lengths, and
    other manipulations none of which passed through to the internal network.

    So the real question is not "how secure sidewinder is" (or any product for
    that matter). The real question is what protective measures does the
    sidewinder provide AND how well are they implemented.

    mike

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Ron DuFresne: "RE: [Full-Disclosure] Sidewinder G2"

    Relevant Pages

    • Re: Where Should I Get the Latest SLRN?
      ... Discussions about updating the slrn ... When following-up on an article with no Newsgroups header, ... this function does not work with wide characters. ... installbin and installdirs swapped in the install ...
      (news.software.readers)
    • [REVS] CRLF Injection
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... two commonly used non-printing ASCII characters. ... additional fake log entry. ... E-mail headers, news headers and HTTP headers all have the structure "Key: ...
      (Securiteam)
    • [Full-disclosure] Re: What A Click! [Internet Explorer]
      ... > tell your windows to open .HTA files in notepad. ... > (since there are more ways to cover windows with malicious lookalikes). ... >> Using custom Microsoft Agent characters it is possible to cover any kind ... including security or download dialogs. ...
      (Full-Disclosure)
    • Re: Linksys home network problems
      ... That refers to a password of only 8 characters. ... But that compromises your security. ... What of the guest is using his laptop given by his employer "Intel"? ... Use a hotspot-type router with different security zones, ...
      (alt.internet.wireless)
    • RE: Password security
      ... hardware on each computer that is going to access the network, ... way you're making your security requirements sound, ... an array of 68 possible characters (alpha num and some easily-typed ... can be deployed across many dumb insecure computers across an insecure ...
      (FreeBSD-Security)