RE: statefull inspection FW and hackers



Statefulness doesn't help with SYN port scans -- that much is correct.

However, some attacks may depend on violating the normal state transitions
or sequencing of TCP traffic, or on scanning with other sorts of packets --
I see unsolicited SYN-ACK packets all the time. (Those are probably just
responses to spoofed SYNs, but I can't know that for certain. I'm not sure
what a scan with RST or FIN packets would reveal.)

Most of the stateful firewalls I've seen also do inspection of FTP control

traffic, so that FTP data sessions on negotiated ports can be allowed
without
leaving masses of high-numbered ports open all the time. An awful lot of
junk/noise can be filtered out by that.

David Gillett


-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx
[mailto:listbounce@xxxxxxxxxxxxxxxxx] On Behalf Of Juan B
Sent: Tuesday, August 19, 2008 10:05 PM
To: security basics
Subject: statefull inspection FW and hackers



Hi,

Can someone please explain why statefull inspection Fw helps
against hackers? I know that those FW keep track of the
sessions but I dont understand how the feature might help
against a port scan from the internet or other ways to
mitigate hackers attacks.

Thanks

Juan











Relevant Pages

  • RE: autoblocking many ssh failed logins from the same IP....
    ... Defending Against Attacks ... ports can be bombarded with login attempts using common ID/PW ... To the firewall these all look like legitimate packets. ... The simplest defense is to change the port numbers these services ...
    (freebsd-questions)
  • Re: Blocking attacks from spoofed IP addresses
    ... cause a _Self_ Denial Of Service attack. ... Defeating Denial of Service Attacks ... of our DMZ servers, and had source IPs from our public DNS servers. ... Web services are on your port 80 and/or 443, ...
    (comp.os.linux.networking)
  • RE: Specification-based Anomaly Detection
    ... >Or highly polimorph attacks, yes. ... >defines a listening application, so we can profile ... What about apps that all tunnel over a single port? ... >actionable anomaly detection result. ...
    (Focus-IDS)
  • Re: Grafting a SSH auto-drop chain onto Arnos 1.8.3-RC1
    ... > hammering my machine with multiple attacks per second. ... to block those certain places from ever touching your ssh port (if you don't ... the patchomatic-ng and add alot of neat options to iptables. ... have not seen one single ssh attack since I moved my sshd off port 22. ...
    (comp.os.linux.security)
  • RE: Hacking to Xp box
    ... restricts most of the attacks that use anonymous connections. ... nessus found port 135 139 ... Audit your website security with Acunetix Web Vulnerability Scanner: ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
    (Pen-Test)