RE: IDS bypassing

From: charles lindsay (frostbackeng@lycos.com)
Date: 12/30/02

  • Next message: smarkle@icsalabs.com: "RE: ICSA [WAS: Re: Intrusion Prevention]"
    To: ed3f@overminder.com
    Date: Mon, 30 Dec 2002 14:56:16 -0500
    From: "charles lindsay" <frostbackeng@lycos.com>
    
    

    Could you be more explicit as to which NAT devices support this evasion technique?

    All NAT/PAT devices I am familiar with are either complete TCP proxies, in which case they verify the checksum coming in, and then re-calculate it as it goes out, or they only implement the "quick-update" algorithm (RFC 1624 et alia). In the first case, your evil packets get dropped at the first NAT, in the second case, they always have an incorrect checksum.

    ================ On Sun 12/29/02 at 6:44 PM ========================
    ============== Ed3f [ed3f@overminder.com] spake: =====================

    >> Systems Affected
    >>
    >> NAT/PAT/load_balancing/packet_manipulation implementations
    >>
    >> Overview
    >>
    >> Multiple vendors' implementations of
    >> NAT/PAT/load_balancing/packet_manipulation
    >> calculate level 4 checksum from scratch.
    >>
    << snip>>

    _____________________________________________________________
    Get 25MB, POP3, Spam Filtering with LYCOS MAIL PLUS for $19.95/year.
    http://login.mail.lycos.com/brandPage.shtml?pageId=plus&ref=lmtplusong with anomaly detection at the higher level. <br> Withd



    Relevant Pages

    • Re: Going back to POP3 collection from SMTP
      ... Is your client aware of the disadvantages and problems with the POP3 ... > The client decided this was the best solution for SPAM filtering. ... >> yet, but make sure you configure the pop3 connector right, else you ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: Advice on ISP independant email address
      ... Purley host my website, for example, but forward ... I ask Zen to provide a POP3 mailbox, ...
      (comp.sys.acorn.networking)
    • Re: Any Pitfalls when using Gmail?
      ... Because of Gmail's inability to fix their POP3 bugs, ... As noted, if you ONLY use one e-mail client to poll for messages and you ALWAYS download the messages then their POP3 host works okay. ... Gmail demands that you use SSL when connecting to their POP3 host. ... Spam filtering has been very good but then I don't use my Gmail accounts as my primary accounts to know how often there are false positives. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: [SLE] Spamassassin - the quick and dirty how-to?
      ... On Thursday 09 October 2003 12:40 pm, Ivan Sergio Borgonovo wrote: ... rather than mess too much with KMail's filters. ... client rather than the server to handel the spam filtering. ...
      (SuSE)
    • Re: Going back to POP3 collection from SMTP
      ... The client decided this was the best solution for SPAM filtering. ... just rerun the ICW wizard. ... > yet, but make sure you configure the pop3 connector right, else you might ... > loose future mail. ...
      (microsoft.public.backoffice.smallbiz2000)