All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tom <tom@lemuria.org>
To: Dean Anderson <dean@av8.com>
Cc: Colin Walters <walters@verbum.org>, selinux@tycho.nsa.gov
Subject: Re: Linuxfromscratch.org
Date: Sun, 27 Jul 2003 17:28:38 +0200	[thread overview]
Message-ID: <20030727172837.U542@lemuria.org> (raw)
In-Reply-To: <Pine.LNX.4.44.0307241434480.23576-100000@vista.av8.net>; from dean@av8.com on Thu, Jul 24, 2003 at 02:52:02PM -0400

On Thu, Jul 24, 2003 at 02:52:02PM -0400, Dean Anderson wrote:
> Regarding the "useful" damage, if the trojan accepts another pre-defined
> password, then you don't need an outbound connection to tell you the
> passwords.  However, there has been some recent discussion of using
> charactistics of packets to trigger finite state machines. One example I
> read recently of (don't remember the source), was using a FSM in a
> firewall to remotely open holes for authorized users in a manner that
> would be hard to detect with a sniffer.  Sending a certain sequence could
> communicate the port numbers and IP addresses to open.

Actually, the current state of the art is embedding arbitrary commands 
in regular traffic. Opening ports is just one possibility, and usually
unnecessary if you have what is essentially a remote shell.
I've seen working implementations of that. They use encryption and changing 
start/end patterns. You can embed your commands in HTTP requests, or
spam mail, or hidden in the IP flags of a ping series. Good luck with
the IDS.

Which goes to show that you can't have security unless the system
itself is secure. No amount of firewalling, filtering or IDS will
protect a weak system. That's why we need SELinux. (how's that for
getting back on-topic? :) )

-- 
http://web.lemuria.org/pubkey.html
pub  1024D/2D7A04F5 2002-05-16 Tom Vogt <tom@lemuria.org>
     Key fingerprint = C731 64D1 4BCF 4C20 48A4  29B2 BF01 9FA1 2D7A 04F5

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2003-07-28 14:54 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-07-22  1:42 Linuxfromscratch.org Charlie Watts
2003-07-22 20:06 ` Linuxfromscratch.org Russell Coker
2003-07-22 20:49   ` Linuxfromscratch.org Dean Anderson
2003-07-23 15:09     ` Linuxfromscratch.org Carsten P. Gehrke
2003-07-23 15:44       ` Linuxfromscratch.org Russell Coker
2003-07-23 20:01         ` Linuxfromscratch.org Dale Amon
2003-07-23 21:24         ` Linuxfromscratch.org Dean Anderson
2003-07-23 19:34       ` Linuxfromscratch.org karlm
2003-07-23 22:08         ` Linuxfromscratch.org Dean Anderson
2003-07-24 14:06           ` Linuxfromscratch.org Dale Amon
2003-07-24 14:16           ` Linuxfromscratch.org Dale Amon
2003-07-24 14:18             ` Linuxfromscratch.org Dale Amon
2003-07-24 17:40         ` Linuxfromscratch.org Colin Walters
2003-07-24 18:52           ` Linuxfromscratch.org Dean Anderson
2003-07-27 15:28             ` Tom [this message]
2003-07-27 20:13               ` Linuxfromscratch.org Colin Walters
2003-07-28 17:17                 ` Linuxfromscratch.org Tom
2003-07-24 19:42           ` Linuxfromscratch.org Russell Coker
2003-07-27 15:19         ` Linuxfromscratch.org Tom
2003-07-23 20:26       ` Linuxfromscratch.org Lukasz Luzar
2003-07-24  0:29         ` Linuxfromscratch.org Dale Amon
2003-07-24  6:39           ` Linuxfromscratch.org Brian May
2003-07-24 12:32             ` Linuxfromscratch.org Dale Amon
2003-07-23  1:17   ` Linuxfromscratch.org Carsten P. Gehrke

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030727172837.U542@lemuria.org \
    --to=tom@lemuria.org \
    --cc=dean@av8.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=walters@verbum.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.