Re: [Full-Disclosure] ICMP (was: daily internet traffic report)

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 10/18/04

  • Next message: Dominic Hargreaves: "[Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities"
    To: full-disclosure@lists.netsys.com
    Date: Mon, 18 Oct 2004 11:07:47 +0100
    
    
    

    On Sun, 2004-10-17 at 16:35 -0600, James Edwards wrote:
    >
    > That is great till you want to run a server behind that firewall.
    <snip>

    If the server is behind the firewall the firewall will be aware of the
    connection passing through and will therefore regard the packets as
    legitimate.

    I agree with you though blocking ICMP isn't much towards security
    although as said before if we block everything and whitelist we are
    closer to a secure system.
    (The whitelist here being, RELATED connections)

    -- 
    Barrie Dempster (zeedo) - Fortiter et Strenue
      http://www.bsrf.org.uk
    [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Dominic Hargreaves: "[Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities"

    Relevant Pages

    • Re: CEICW fails at firewall config
      ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
      (microsoft.public.windows.server.sbs)
    • Re: Recycler security issues on IIS server
      ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
      (microsoft.public.inetserver.iis.security)
    • Re: ISA SERVER NOT STARTING
      ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
      (microsoft.public.windows.server.sbs)
    • Re: For Microsoft Partners and Customers Who Cant Download or Access
      ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
      (microsoft.public.dotnet.general)
    • RE: Is this as bad as it seems?
      ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
      (Security-Basics)