Home page logo

basics logo Security Basics mailing list archives

RE: Open All Outbound Ports?
From: "Naveed Ahmed" <naveed.ahmed () vinciti com>
Date: Tue, 12 Nov 2002 03:11:19 +0530

In addition, in case your network inadvertently becomes a zombie in a DDos,
there is no way you can prevent DoS traffice from leaaving your network.
Just wondering, if you do have a web server and if thats allowed to make
outbound connections, it could cause havoc once its compromised


-----Original Message-----
From: Garbrecht, Frederick [mailto:FGarbrecht () ecogchair org]
Sent: Sunday, November 10, 2002 12:25 AM
To: 'tony tony'; security-basics () securityfocus com
Subject: RE: Open All Outbound Ports?

A couple of things come to mind.  Spyware programs installed by internal
users inadvertently can ramp up outgoing traffic considerably and waste your
bandwidth.  Opening up outgoing ports also makes it much easier for
peer-to-peer file sharing applications on your internal LAN to do their
dirty work; clearly a security risk well defined elsewhere.  Some trojans
may also enjoy the new-found ability to establish outbound communications
over whatever port they choose.

I really don't understand why your firewall group would want to do this, it
is such an obvious risk in many ways and violates the well established
security principle of 'least prividege'.  Sounds like your firewall guys are
either really lazy or need some remedial security training.


-----Original Message-----
From: tony tony [mailto:tonytorri () yahoo com]
Sent: Thursday, November 07, 2002 8:34 PM
To: security-basics () securityfocus com
Subject: Open All Outbound Ports?


Our firewall group has came to me several times over the last few months
wanting my approval to open all of the "OUTBOUND" ports on our firewall
the internet.  Their argument is that this would not significantly reduce
security and it will reduce their time/effort in administration.  They claim
they get several requests a week to open up out bound ports and the number
keeps growing each month. They want to go for the gusto...and open up all
outbound ports.

I am in the security area and they want my agreement/sign off before they do
this.  It just does not "feel/smell right" but I am losing ground with my
arguments.  What are some good arguments I can use?


Do you Yahoo!?
U2 on LAUNCH - Exclusive greatest hits videos

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]