RE: Testing load balanced servers behind NAT

From: Javier Megias (jmegias@hyphop.com)
Date: 09/07/01


From: "Javier Megias" <jmegias@hyphop.com>
To: "'Andrew Koh'" <drewkoh@dingoblue.net.au>, <pen-test@securityfocus.com>
Subject: RE: Testing load balanced servers behind NAT
Date: Fri, 7 Sep 2001 13:09:08 +0200
Message-ID: <005f01c1378d$84b1b640$e100a8c0@hyphop.hh>

I'm not firewall expert, but you could use FIREWALKING(a traceroute-like
anaysis) to map hosts behind it,and to prove that a Firewall is not a *risk
free* solution in network security, like most management people think.Also
if the firewall is being used for VPN authentication, and if not is current
in security patches, you could download network topology from it.(Sorry,
don't remember the links, just the idea- maybe i'm wrong)

FIREWALK: http://www.packetfactory.net/Projects/Firewalk/firewalk-final.html

My 2 cents

-----Mensaje original-----
De: Andrew Koh [mailto:drewkoh@dingoblue.net.au]
Enviado el: jueves, 06 de septiembre de 2001 9:24
Para: pen-test@securityfocus.com
Asunto: Testing load balanced servers behind NAT

Greetings!

I'm currently doing a quick vulnerability test using nessus on some of our
machines which are load balanced behind a firewall/NAT system. As there are
a few machines distributed on the virtual IP, I was wondering if there's
anyway to make sure that when nessus connects to the virtual IP, it will
keep hitting the same server.
How would I test each server in the pool?

Also, is there any other documentation on identifying hosts behind
proxy/NAT(like FW-1), their internal IP and getting to other internal
machines which are not directly accessible from outside?

On identifying hosts:
 From what I have read so far, its possible to elicit responses by crafting
packets with missing packet fragments and invalid IP header lengths/field
values. Then you match up the TTL, TOS and DF bits from the responses to
see if its different from the firewall. (Of course you need to id the
firewall first). That's assuming the various ICMP types haven't been
filtered.

On getting internal IP:
Besides misconfigured DNS and snmp, are there any other ways to find out
internal host IP?

On routing to internal machines:
The only way I can think of is bouncing off other internal hosts which are
accessible to the Internet. How does source routing work as there are many
routers out there which filter them.

Any thoughts?

p.s. yeah, I'm trying to prove to my boss that a FW-1 solution isn't the
be-all-end-all :)

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • RE: security question
    ... You connect to the internet after your OS has booted up. ... security item is in place, only then you logon to internet right. ... By then your personal firewall would have loaded anyway. ... seconds of the network services thus reducing the window size. ...
    (Security-Basics)
  • Re: Using netmask ffffffff
    ... The most important thing these new hosts need is connection to the outside world, for internet browsing, webmail access, fetch some documents from remote sites they forgot to bring with them for the conference, etc. ... the new hosts should not be able to directly contact each-other or the majority of my internal network. ... The trouble is that even if I set-up firewall rules to filter their traffic, they can still communicate behind the firewall directly through the switch they are all connected to, as only their internet traffic will go through the firewall. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Another Newbie asking "Which Anti-Virus Sofware is the Best?"
    ... security patches for Windows, IE and OE. ... Do yourself a favor and purchase a external router/firewall since ... you wouldn't be able to browse the internet. ... a firewall is that you will have many open internet ports by default ...
    (alt.comp.anti-virus)
  • Re: my computer keeps dialing up for no reason?
    ... Dialer is a program that is often used to maliciously redirect Internet ... Windows XP users ... has integrated firewall - ... Download all the security updates - Critical updates with Express install. ...
    (microsoft.public.windowsxp.newusers)