Re: an error in the NMAP docs?

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 04/05/05

  • Next message: Robert Holtz: "Re: Microsoft Software Auditing ?"
    Date: Tue, 05 Apr 2005 14:07:17 +0100
    To: Michael Herz <mherz@uwaterloo.ca>
    
    
    

    Michael Herz wrote:
    > Hi all,
    >
    > Is there an error in the NMAP docs? The --source_port section says:
    >
    > "Many naive firewall and packet filter installations make an exception in
    > their rule-set to allow DNS (53) or FTP-DATA (20) packets to come through
    > and establish a connection. Obviously this completely subverts the security
    > advantages of the firewall since intruders can just masquerade as FTP or
    > DNS by modifying their source port."
    >
    > This implies that the hole in a packet filtered machine exists if it has
    > allowed inbound DNS or FTP connections. I don't believe this is true. I
    > think the hole only exists if the machine has allowed outbound (ie client)
    > connections from the machine. For example if the machine allowed outbound
    > DNS client requests to the world, using --source_port 53 would exploit the
    > hole.

    The manual is quite correct, if you allow incoming requests from port 53
    to any random port internally to *establish a connection*. This
    represents a hole. The attacker can target any port he wishes as long as
    his source is 53. This is a common firewall misconfiguration.

    -- 
    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue
    blog: http://zeedo.blogspot.com
    site: http://www.bsrf.org.uk
    CA: www.cacert.org
    "He who hingeth aboot, getteth hee-haw" - Victor (Still Game)
    
    



  • Next message: Robert Holtz: "Re: Microsoft Software Auditing ?"

    Relevant Pages

    • Re: AS4.2/WM5/OUTLOOK2K3 suddenly not syncing, please help
      ... there is a connection EXIST between the device because I ... connection on port 26675 but on the PPC the port number keeps ... Outlook, countless times of reinstalling Activesync, removing Windows ... Firewall set to NO). ...
      (microsoft.public.pocketpc.activesync)
    • RE: FTP Window of opportunity?
      ... target on the line when in reality it was just a firewall lying to them. ... The connection connects and then immediately ... Subject: FTP Window of opportunity? ... the FTP port shows up. ...
      (Pen-Test)
    • Re: WDSC, VPN, and RPG Editing
      ... With some machines I can have a 24 hour connection, ... thru port 23 using telnet. ... iSeries server to make sure they are configured to allow the ... through the firewall. ...
      (comp.sys.ibm.as400.misc)
    • Re: Plausible reasons for http access?
      ... The word port has several meanings, ... On my home firewall, I normally have _ALL_ logging off. ... NetBIOS is a protocol meant for local use within a windoze workgroup. ... If you block the connection (or ...
      (comp.security.misc)
    • Re: Problem with AS 4.1 and USB
      ... I have as said in my first post, set in my firewall to allow both tcp/udp ... Where do find the USB to check on phone? ... > And a UDP outgoing port of. ... >>> Connection? ...
      (microsoft.public.pocketpc.activesync)