Re: Kerio 2.1.5 Vulnerability

From: Alan Illeman (illemann_at_surfbest.net)
Date: 05/29/04


Date: Sat, 29 May 2004 10:19:57 -0400


"Kerodo" <kerodonospamkenny@hotmail.com> wrote in message
news:MPG.1b213e3d6d45640e98968a@news.west.cox.net...
> I'm posting this message because I believe I have found a vulnerability
> in Kerio 2.1.5 and that I should share this with other Kerio users who I
> believe are vulnerable to this exploit, even though I can't explain it
> all very well. I'll do my best.. What it boils down to is that a
> malicious person is able to get packets to any port past the firewall if
> they wish.
>
> Some time ago, I turned on logging of ICMP in Kerio and noticed that
> there was ICMP Type 3 outbound to various IP addresses, other than my
> DNS servers. I wasn't worried about Type 3 to my DNS servers since this
> appeared to be fairly safe and common, but the other destinations
> bothered me. Why would my machine be sending Type 3 to seemingly random
> IPs?

I allow [8] IN and [0] OUT (else my ISP folds my dialup connection) and
all other types are blocked IN and OUT, and logged - but no log entries
of any of the blocked types.



Relevant Pages

  • Re: Kerio 2.1.5 Vulnerability
    ... >> I'm posting this message because I believe I have found a vulnerability ... >> in Kerio 2.1.5 and that I should share this with other Kerio users who I ... >of any of the blocked types. ... and my ISP never drops my connection. ...
    (comp.security.firewalls)
  • Tiny / Kerio potential vulnerability: App masquerade
    ... Kerio potential vulnerability ... ... would grant the program access through the firewall to any remote host on ...
    (comp.security.firewalls)
  • Re: Huge security hole in Kerio 2.1.5
    ... The reason for the dissing of Kerio 4.x is that it isn't just a firewall ... They had to go and add popup blocking and other stuff in there. ... and isn't really a vulnerability. ... fragmented UDP packet that the system won't respond to anyway? ...
    (comp.security.firewalls)
  • Re: Kerio 2.1.5
    ... In my opinion, the vulnerability isn't THAT big of a deal, but I believe ... I ran Kerio 2.1.5 for a long time here. ... thru the firewall to hit specific ports, ... Please let us know if you can verify that outbound type 3 is happening ...
    (comp.security.firewalls)
  • Re: ICMP Type 3
    ... I use Kerio 2.1.5, and earthlink dialup. ... I let ICMP 3 Out to my ISP's DNS servers only. ... Just a Win2k system on cable ...
    (comp.security.firewalls)