Re: ICMP (Ping)

From: Jude Naidoo (jude007_at_jnaidoo.fsnet.co.uk)
Date: 09/03/03

  • Next message: Jay Woody: "Re: ICMP (Ping)"
    To: "Paul Kurczaba" <paul@myipis.com>
    Date: Wed, 3 Sep 2003 09:08:47 +0100
    
    

    Hi Paul

    Yes there are security issues.

    The aim is to make the firewall invisible to the internet. Also by allowing
    ICMP to the firewall from a totally untrusted domain, you open your firewall
    to DoS attacks, as well as the possibility of having your firewall
    compromised.

    You may want to read the following thread and find out a bit more :-)

    http://www.geocrawler.com/mail/thread.php3?subject=%5BFW1%5D+ICMP+Traffic+Security+Issues&list=98

    Thanks

    Jude

    ----- Original Message -----
    From: "Paul Kurczaba" <paul@myipis.com>
    To: <security-basics@securityfocus.com>
    Sent: Tuesday, September 02, 2003 8:19 PM
    Subject: ICMP (Ping)

    > Are there any security issues for allowing a firewall/router to respond to
    > Ping from the internet?
    >
    > -Paul Kurczaba
    >

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    technical IT security event. Modeled after the famous Black Hat event in
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    Symantec is the Diamond sponsor. Early-bird registration ends September 6.Visit us: www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: Jay Woody: "Re: ICMP (Ping)"

    Relevant Pages

    • RE: security question
      ... You connect to the internet after your OS has booted up. ... security item is in place, only then you logon to internet right. ... By then your personal firewall would have loaded anyway. ... seconds of the network services thus reducing the window size. ...
      (Security-Basics)
    • Re: Another Newbie asking "Which Anti-Virus Sofware is the Best?"
      ... security patches for Windows, IE and OE. ... Do yourself a favor and purchase a external router/firewall since ... you wouldn't be able to browse the internet. ... a firewall is that you will have many open internet ports by default ...
      (alt.comp.anti-virus)
    • Re: my computer keeps dialing up for no reason?
      ... Dialer is a program that is often used to maliciously redirect Internet ... Windows XP users ... has integrated firewall - ... Download all the security updates - Critical updates with Express install. ...
      (microsoft.public.windowsxp.newusers)
    • Re: Cant connect afte rupgrade to 6.2
      ... If your password information is not saved, verify ... If you use a firewall (like ZoneAlarm, ... Internet Security etc.), it's possible ...
      (microsoft.public.windowsxp.messenger)
    • RE: Testing load balanced servers behind NAT
      ... I'm not firewall expert, but you could use FIREWALKING(a traceroute-like ... free* solution in network security, ... is there any other documentation on identifying hosts behind ... accessible to the Internet. ...
      (Pen-Test)

    Loading