SonicWall Pro DoS?

From: Greg Smith (gsmith_at_cybercrews.com)
Date: 04/25/03

  • Next message: Albert Puigsech Galicia: "Multiple SQL injection on OpenBB forums"
    Date: 24 Apr 2003 23:04:13 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Came across an apparent problem on a SonicWall Pro running firmware
    version 6.4.0.1 ROM version 5.0.1.0 during a vulnerability assessment and
    couldn't find any other postings on this problem so fwiw.. the problem
    occurs when sending a large HTTP POST to the inside interface - may affect
    others just didn't test as the outside interface was blocked. I was able
    to confirm this problem using two separate Nessus plugins (10012 and
    10687). The behavior of the firewall suggests a buffer overflow but since
    I'm not familiar with the internals of this system it's just a guess. 15-
    20 seconds after sending the POST to the firewall the firewall goes
    through a reset cycle. This delay suggests to me a section of code that is
    being overwritten. At the very least, this is a Denial of Service problem.
    Vendor was notified of the problem.


  • Next message: Albert Puigsech Galicia: "Multiple SQL injection on OpenBB forums"

    Relevant Pages

    • Re: ftp problem
      ... > here is my whole firewall script ... > # No restrictions on Loopback Interface ... > # or from this gateway server destine for the public Internet. ... > # Allow out secure FTP, Telnet, and SCP ...
      (freebsd-questions)
    • Re: Checkpoint experiences
      ... decide they want the firewall used by the big boys...often repeated, ... The Nokia appliance IPSO, is useful if you don't want to take the ... It is no wonder that the Nokia interface is called ... > billions on training, and classes, consultants, support contracts, etc. ...
      (comp.security.firewalls)
    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... part of the same network as the LAN. ... Each interface of a firewall should be distinct from ... interfaces, so a "DMZ interface" is not a requirement. ...
      (comp.security.firewalls)
    • Proxy ARP and Routing
      ... some CPE from our ISP connected to a firewall. ... the public IPs on the physical DMZ network. ... packets to the host on the DMZ? ... on the DMZ interface. ...
      (SunManagers)
    • RE: [fw-wiz] Dynamic routing on a firewall
      ... is on this interface", rather than having to work it out manually each time. ... Obviously, if the firewall is using dynamic routing, there would be no ... >> party is in their own DMZ. ...
      (Firewall-Wizards)