Re: Linksys WRT54G and Firewall software
- From: Gerald Vogt <vogt@xxxxxxxxxxx>
- Date: Mon, 26 Mar 2007 12:54:01 +0900
Leythos wrote:
On Mon, 26 Mar 2007 02:46:22 +0000, Maximum Dog9 wrote:The XP FW/packet filter is doing the same thing as any other PFW or personal packet filter. That is to stop unsolicited inbound traffic from reaching the machine.
Not technically correct - they actually reach the machine and if there was
an exploit path it would get through.
The NAT router (a typical SOHO unit) would never let the packet make it to
the computer in the first place. Exploits at the machine would not be
reached by "unsolicited" connections.
Yes. Therefore all the malware has to do is to "open" the port on the
router. An unconfigured router with default password is an easy target.
You could even run a quick dictionary attack if you wanted as the router
won't bother repeated attempts to access the configuration interface
from the LAN.
But even if it cannot access the management interface, the router may be
configured for UPnP by default. Makes it easy to open the port.
The WRT is so popular there is even customized hacker firmware available
which gives you full control of the router and the internet connection
while the average user behind the router won't even notice as everything
so far works normal...
And if there is nothing else, simply open the port by sending frequent
UDP packets out. This allows you "unsolicited" incoming traffic through UDP.
But anyway, it still does not explain why my laptop with XP SP2 FW with
no exceptions connected to a public hotspot is any more vulnerable than
while it is connected behind a NAT router with or without the SP2 FW.
Gerald
.
- Follow-Ups:
- Re: Linksys WRT54G and Firewall software
- From: Maximum Dog9
- Re: Linksys WRT54G and Firewall software
- References:
- Linksys WRT54G and Firewall software
- From: R.User
- Re: Linksys WRT54G and Firewall software
- From: Leythos
- Re: Linksys WRT54G and Firewall software
- From: Gerald Vogt
- Re: Linksys WRT54G and Firewall software
- From: Maximum Dog9
- Re: Linksys WRT54G and Firewall software
- From: Gerald Vogt
- Re: Linksys WRT54G and Firewall software
- From: Maximum Dog9
- Re: Linksys WRT54G and Firewall software
- From: Leythos
- Linksys WRT54G and Firewall software
- Prev by Date: Re: Linksys WRT54G and Firewall software
- Next by Date: Re: Linksys WRT54G and Firewall software
- Previous by thread: Re: Linksys WRT54G and Firewall software
- Next by thread: Re: Linksys WRT54G and Firewall software
- Index(es):
Relevant Pages
|