Re: Cracking Servers W/O open ports: Packet Filter Firewall

From: Steven Ackerman (ackerman_steven@hotmail.com)
Date: 07/12/02


From: "Steven Ackerman" <ackerman_steven@hotmail.com>
To: security-basics@securityfocus.com
Date: Fri, 12 Jul 2002 13:08:02 -0700

Cool. Thanks for the quick reply.

And now to throw a little flame bait to all the cyber security fishes. Are,
or can, proxy based firewalls be less secure because they are running a
proxy service?

Which brings me to a question I've been wanting to ask for a long time.

If you read firewall books, docs, lists, etc, people often say that you
shouldn't run anything on your firewall box. No services, etc. So if I have
one machine running iptables and I want to run squid or an NIDS or HIDS I
should have a second machine for each "service". If I just have a home
machine is it o.k. to run that stuff on it?

My scenario is just a home machine with a dialup connection. I'd like to run
iptables, maybe squid for setup experience, nmap and maybe snort and
tripwire. Not sure if snort is just NIDS or HIDS as well. If it does HIDS
and NIDS then I would run it alone.

Thanks.

Steve

>From: "Steve Bremer" <steveb@nebcoinc.com>
>To: "Steven Ackerman" <ackerman_steven@hotmail.com>
>CC: security-basics@securityfocus.com
>Subject: Re: Cracking Servers W/O open ports: Packet Filter Firewall
>Date: Fri, 12 Jul 2002 14:20:10 -0500
>
>
>
> > solution, right?) and so they are very difficult to crack. Could you
> > please elaborate on that.
>
>Sure can. I left out a word in that sentence. I meant to say:
>
>"Machines that are used as a packet filtering firewall often fall into
>this category."
>^^^^^
>
>I say that because often times, at least in my experience, a packet
>filtering firewall is configured with no services running so that they
>become very difficult to attack.
>
>Steve Bremer
>

_________________________________________________________________
Send and receive Hotmail on your mobile device: http://mobile.msn.com



Relevant Pages

  • Re: [fw-wiz] dirty packet tricks?
    ... solve via promiscuously sucking up packets. ... restriction that your 'sideways' proxy box is it will have to be on a hub ... The firewall will have to suppress all ICMP errors to the internal network ...
    (Firewall-Wizards)
  • Re: [fw-wiz] httport 3snf
    ... >> wouldn't have gotten SSH out of my firewall. ... > Postfix SMTP server with a wildcard MX that handed the mail that wasn't ... > destined to me off to the downstream MS stuff, and an HTTP proxy server ... All it needs is a written policx "Internet access is ...
    (Firewall-Wizards)
  • Re: Kids bypassing firewall via web proxy sites
    ... We use a Sonicwall firewall, 3060, I subscribe to content fltering, ... I checked "Access to HTTP Proxy Servers" But I am still able to get to ... CyBlock, which does network proxy and filtering ...
    (comp.security.firewalls)
  • Re: Tool to find hidden web proxy server
    ... No reason the proxy has to be INSIDE your firewall. ... Cell Phones to just bypass your firewall completely. ... On Thu, 2 Sep 2004, vinay mangal wrote: ... policy for Internet access says it is through IP ...
    (Pen-Test)
  • Re: NAT is not a mechanism for securing a network.. but.. HELP!
    ... tell you a NAT router is a firewall. ... > There is this one hot chick at a major American news network, ... >proxy, and come to a chat room where her and I have been chatting, she has ... >admins at the station she works for. ...
    (comp.security.firewalls)

Quantcast