Re: ICMP pokes holes in firewalls...

From: by way of Lucio (hdm_at_digitaloffense.net)
Date: 09/26/03

  • Next message: emacdona_at_edmacdonald.net: "RE: CyberInsecurity: The cost of Monopoly"
    Date: Fri, 26 Sep 2003 11:54:57 +0000
    To: bugtraq@securityfocus.com
    
    

    Only if these systems are running kernel version 2.2, the 2.4 NAT system
    has been rewritten and is not vulnerable.

    On Friday 26 September 2003 04:55 am, Lucio wrote:
    > > This also applies to Linux NAT gateways.
    >
    > I'm rellay not an expert in building a firewall with a Linux box, but
    > I've tried twice and now I have two customers happy of their
    > unexpensive Linux based firewall. These firewalls offer also NAT
    > functionality to the respective LANs they protect and use iptables
    > rules with stateful inspection to filter the packets. Both customers
    > have a DNS in between the linux firewall and the ISP's router. Are they
    > vulnerable to any of those attacks?


  • Next message: emacdona_at_edmacdonald.net: "RE: CyberInsecurity: The cost of Monopoly"

    Relevant Pages

    • Re: Advice on a firewall distro
      ... but as a NAT router with only one machine (the new linux ... ZyWALL unless they were intended for one of the servers (in the DMZ of the ... linux firewall). ...
      (comp.os.linux.networking)
    • Re: newbie question
      ... am I better off to use a full install of a Linux Distro ... > a pre-packaged firewall like IPCop, ... On a NAT Router/Firewall if someone were to compromise the box, ... Another advantage of a transparent bridging firewall is that you can still ...
      (comp.security.firewalls)
    • Re: Another basic networking question.
      ... The second common case is to act as a network gateway, firewall, NAT ... Download some of the router documents that Cisco has on line ... stuff can be done in Linux and mostly the language is the ...
      (Fedora)
    • Re: Unexpected termination of http connections through nat.
      ... I had only tried on debian machines behind the firewall, and windows machines before the firewall. ... Since it loaded on the firewall and seemed to do not so behind, I thought it to be a nat issue, sorry. ... But it also won't on a linux 2.6 without the OpenBSD firewall. ...
      (comp.unix.bsd.openbsd.misc)
    • windows me machine compromised?
      ... I have a me machine sat behind a linux based hardware ... firewall that provides ... nat. ...
      (alt.computer.security)