Re: Probes on Port 135 and 445 continue

From: Michael (none_at_none.com)
Date: 10/13/04

  • Next message: Barry Margolin: "Re: Probes on Port 135 and 445 continue"
    Date: Wed, 13 Oct 2004 03:46:44 GMT
    
    

    david20@alpha2.mdx.ac.uk wrote:

    > What security NAT provides is a side effect which is better achieved via a
    > proper firewall.

    I'd agree with this, partially cause NAT is operating at a low level
    compared to application-layer firewalls.

    What I wonder then is if Linksys and simple firewalls are that much
    better than NAT? Do they really scan SMTP, AIM, ICQ and other traffic?
      I'm talking $50 firewalls of course, not high-end. I just question
    how deep the inspection is on packets, and whether they MUST be used in
    conjunction with a personal firewall (or IPS) like BlackIce which
    performs inspection of ICQ and others.

    Certainly Checkpoint (or linksys SPI) is "better" than a NAT router, but
    most reverse-connect trojans should get past it. Reverse-connect has
    been all the rage since the post-Sub7 era. The threats are just
    different in 2004 than 2001. Hell, even netcat can backchannel easy.

    michael


  • Next message: Barry Margolin: "Re: Probes on Port 135 and 445 continue"

    Relevant Pages

    • Re: Linksys hardware firewall enough...?
      ... Most of us know that ROUTING is part of NAT and has ... > nothing to do with firewalls. ... firewall provides routing, NAT, and packet filtering. ... > them that the devices marketed as firewalls, that are only NAT Routers ...
      (comp.security.firewalls)
    • Re: [fw-wiz] Internet accessible screened subnet - use public orprivate IPs?
      ... >The whole reason NAT was implemented was because of a very finite number of publicly routable IP addresses. ... The first firewalls I built offered NAT (inherent in the design and then later via ... "Proxy transparency" in Gauntlet) because a lot of the early firewall customers ... re-address their network or NAT ...
      (Firewall-Wizards)
    • Re: Schaltung, um mit PT100 oder PT1000 ...... PAUSE WG. URLAUB
      ... dass es auch HW Firewalls gibt. ... obwohl die Seite ziemlich polemisch ist - ich nehme an, ... NAT ist _der_ Schutz vor aktiven Angriffen von aussen. ... Der Rest der Risiken ist dann ...
      (de.sci.electronics)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... >> one of their firewalls). ... >> But there was one claim that sounded like a serious problem for NAT ... >> device opens a port by putting it in the NAT table, ... way into the network? ...
      (comp.security.firewalls)
    • Re: pppoe, cant ping tun0, ipfnat ftp proxy "doesnt work"
      ... > But I noticed that, although you use ipnat(8), nat is also enabled in your ... especially on the way packets flow through the ... firewalls, so I dropped back and enabled in in ppp. ... Combining stateful rules and dummynet in ipfwwas interesting. ...
      (freebsd-net)