RE: Re[2]: [Full-disclosure] Personal firewalls.



Any self-respecting network administrator, (who knows what he/she is doing),
would have planned for that
And setup some kind of overideing ruleset, that will allways allow
communiction to/from it's own resources.
A.K.A, the "BLACKHOLE / IP BANNING" would be overiden for IP's & resources,
like that of it's DNS Servers.
But, that could, too, be exploited.
If Z spoofs packets using the ip of the DNS Server (the one that is not
banned because of the overide or 'never ban these ips, etc')
Would be allowed to send those packets, SYN Packet, etc, as was stated, ad
infinitum.

As, they say, no computer or server is ever, *TRULY*, secure - even with a
software or hardware firwall, or 'voodoo-like' security measures.
Digitalchaos
(just my 2 cents)
-----Original Message-----
From: full-disclosure-bounces@xxxxxxxxxxxxxxxxx
[mailto:full-disclosure-bounces@xxxxxxxxxxxxxxxxx] On Behalf Of Thierry
Zoller
Sent: Friday, January 20, 2006 5:58 PM
To: full-disclosure@xxxxxxxxxxxxxxxxx
Subject: Re[2]: [Full-disclosure] Personal firewalls.


Dear Eliah Kagan,

EK> Then Z comes along and sends a
EK> bunch of SYN packets to X, spoofed to have the source IP of Y, waits
EK> 10 minutes, and repeats ad infinitum.

Z sends spoofed packets coming from the DNS server of X even more
interesting..

--
http://secdev.zoller.lu
Thierry Zoller
Fingerprint : 5D84 BFDC CD36 A951 2C45 2E57 28B3 75DD 0AC6 F1C7

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.375 / Virus Database: 267.14.21/236 - Release Date: 1/20/2006


--
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.375 / Virus Database: 267.14.21/236 - Release Date: 1/20/2006


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: resolver latencies return in Mozilla 1.6
    ... I have watched the packets going out and I ... >> ISP's DNS server keeps rejecting. ... What's weird is that for these failing conversations my firewall doesn't seem ... Same sequential port numbers, but no ICMPs, no "ServFail" packet (whatever ...
    (comp.unix.bsd.freebsd.misc)
  • Re: problems with BT broadband connection
    ... speculation could point to DNS packets ... being lost over a dodgy wireless connection. ... improve the connection to your wireless router; ... PC's LAN interface to use 127.0.0.1 as your primary DNS server. ...
    (uk.telecom.broadband)
  • # packets for first query with personal DNS server
    ... I asked earlier about my new DNS server ... packets ). ... initial query of www.google.com. ... then it started sending packets to ...
    (comp.os.linux.networking)
  • Re: Strange msgs in syslog
    ... these because there's a rule to log packets like this. ... Do you have a DNS server running on box 192.168.10.1? ... configured to send DNS requests to 192.168.10.1? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)