Bugtraq mailing list archives
Firewall-1 insecurity.
From: avalon () COOMBS ANU EDU AU (Darren Reed)
Date: Thu, 29 Oct 1998 21:40:20 +1100
Sigh, the "Security Policy" properties page is (largely) a farce. It will not matter if you can "see them". The fundamental problem is that they are "global" rules for services and that cannot be changed - i.e. allowing (for example) "Domain Name Download (TCP)" is like a rule which reads "Any Any domain-tcp accept - Gateways Any". The only reasonable thing you can do is disable the following: Accept Firewall-1 Control Connections Accept UDP replies Accept RIP Accept Domain Name Queries (UDP) Accept Domain Name Download (TCP) Accept ICMP I haven't made the time to determine the effect of toggling "Accept Outgoing Packets" or whether that can be moderated by toggling the "Apply Gateway Rules to Interface Direction" to "Eitherbound". Why it doesn't properly configure itself for "Accept Firewall-1 Control Connections" is bewildering given the file with a list of master/clients. A case of "almost" but not quite - something you'd hope not to find in the maker of the world's most popular and perhaps with the world's worst default configured firewall. The only difference doing the above makes is that you need to add a few rules to properly add in FW-1 control, appropriate rules for DNS and setup bi-directional rules for UDP services. I've not looked at how the "Router Access Lists" page of checkboxes impacts on rules generated for (I presume) Ciscos, which is another potential source of trouble. Darren p.s. I'd suggest that anyone who has knowingly installed FW-1 for a client with services such as DNS enabled give their respective clients a free security upgrade of their firewall so that they can fix their own mistake.
Current thread:
- Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice), (continued)
- Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Nick Andrew (Oct 28)
- Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) brian j. pardy (Oct 28)
- [L0pht Advisory] MacOS - FWB passwords easily bypassed Space Rogue (Oct 30)
- Re: Firewall-1 Security Advisory John Horn (Oct 28)
- rootshell hacked via ssh-1.2.26 Felix von Leitner (Oct 28)
- Re: Firewall-1 Security Advisory David S. Goldberg (Oct 27)
- Re: Firewall-1 Security Advisory Gary Gaskell (Oct 27)
- Re: Firewall-1 Security Advisory Ejovi Nuwere (Oct 29)
- Summary of Printer Sharing and M1CR0S0FT Windows98 Paul Leach (Oct 29)
- Re: Firewall-1 Security Advisory Jason Costomiris (Oct 30)
- Firewall-1 insecurity. Darren Reed (Oct 29)
- Bug in Solaris 2.6 ??? Daniel Ezekiel (Oct 29)
- WatchGuard Firewall internal D.O.S Who Wants To Live Forever ... (Oct 29)
- Re: Firewall-1 Security Advisory Gary Gaskell (Oct 27)
- Re: Firewall-1 Security Advisory Larry Pingree (Oct 27)
- Re: Firewall-1 Security Advisory Simon Finn (Oct 29)
- Re: Firewall-1 Security Advisory Keith Young (Oct 29)