Home page logo
/

oss-sec logo oss-sec mailing list archives

Attack on badly configured Netfilter-based firewalls
From: Eric Leblond <eric () regit org>
Date: Sat, 25 Feb 2012 19:37:14 +0100

Hello,

I've discovered a generic attack on firewall using Application Level
Gateway (like Netfilter or Checkpoint).

Impact:
An attacker on a local network can open some pinholes in a firewall
which is not correctly protected.
Fix:
None, the issue has to be fixed in the firewall configuration.
Workaround:
Apply a strict anti-spoofing policy for IPv4 and IPv6 as described in
the document "Secure use of iptables and connection tracking helpers" 
This document was written after private disclosure of the attack to the
Netfilter's team.

This attack will be presented at Cansecwest, March 9th 2012.

Secure use of iptables and connection tracking helpers:
http://home.regit.org/netfilter-en/secure-use-of-helpers/

Best regards,
-- 
Eric Leblond 
Blog: http://home.regit.org/

Attachment: signature.asc
Description: This is a digitally signed message part


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]