All of lore.kernel.org
 help / color / mirror / Atom feed
* Completely Bypassing a Firewall?!
@ 2006-01-25 14:07 Jason Noble
  2006-01-25 17:02 ` /dev/rob0
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Jason Noble @ 2006-01-25 14:07 UTC (permalink / raw)
  To: netfilter

We just heard a rumor about our rival company, that they have developed
a "system" that can completely bypass a properly-configured/locked-down
firewall (netfilter or any other).

Is this truly possible? with only external access and no software that's
already been planted inside the firewall?



^ permalink raw reply	[flat|nested] 7+ messages in thread
* RE: Completely Bypassing a Firewall?!
@ 2006-01-25 14:28 Derick Anderson
  0 siblings, 0 replies; 7+ messages in thread
From: Derick Anderson @ 2006-01-25 14:28 UTC (permalink / raw)
  To: netfilter

 

> -----Original Message-----
> From: netfilter-bounces@lists.netfilter.org 
> [mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of 
> Jason Noble
> Sent: Wednesday, January 25, 2006 9:07 AM
> To: netfilter@lists.netfilter.org
> Subject: Completely Bypassing a Firewall?!
> 
> 
> We just heard a rumor about our rival company, that they have 
> developed
> a "system" that can completely bypass a 
> properly-configured/locked-down
> firewall (netfilter or any other).
> 
> Is this truly possible? with only external access and no 
> software that's
> already been planted inside the firewall?

Depends on how you define "bypass". Can you send SMTP data through port
80? Yes. You can also "bypass" any firewall which filters on source port
but not destination port, but this isn't considered properly configured
much less locked down. Are you sure they're not talking about I[D|P]Ses?
There have been several white papers over the last few years on
bypassing those, and some people think that firewall = IPS.

Maybe this rival company has been watching too many recent movie
previews with Harrison Ford in them. If Harrison Ford works for you (and
you happen to be a bank), then I'd be worried. =)

Derick Anderson



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2006-01-29  4:31 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-25 14:07 Completely Bypassing a Firewall?! Jason Noble
2006-01-25 17:02 ` /dev/rob0
2006-01-26  3:48 ` Mark E. Donaldson
2006-01-27  8:50 ` Jimmy Hedman
2006-01-27 14:54   ` Carl-Daniel Hailfinger
2006-01-29  4:31     ` John A. Sullivan III
  -- strict thread matches above, loose matches on Subject: below --
2006-01-25 14:28 Derick Anderson

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.