Bugtraq mailing list archives
BUG: Win NT TCP/IP Security filters does not get enforced
From: stnor () SWEDEN HP COM (Stefan Norberg)
Date: Fri, 8 Oct 1999 19:04:13 +0200
Regardless of settings in the TCP/IP Security filters any IP protocol is accepted. TCP/IP security configuration example: Permit all TCP ports, Permit all UDP ports, Permit only IP protocols: 6 The easiest way to prove it's broken is to configure it to only allow IP-protocol 6 (TCP) and then ping (ICMP) the host. ICMP being IP protocol 1 of course. Another simple way to test this is to use Weld Pond's NT-port of Hobbit's netcat (http://www.l0pht.com/~weld/netcat/ ) to set up a udp-listener on a host that is supposed to block udp. Then use netcat on another host to send it a nice message. CLIENT: C:\>nc -u server 5000 tcp/ip security is broken :) SERVER: C:\>nc -u -l -p 5000 tcp/ip security is broken :) windump: listening on \Device\Packet_El90x1 18:49:06.731069 CLIENT.3533 > SERVER.5000: udp 29 Seems pretty broken to us... Tested on NT4.0 SP5 (both w. no hotfixes and all hotfixes) Regards, Stefan Norberg (stnor () sweden hp com , http://people.hp.se/stnor) Daryl Banttari (daryl () windsorcs com)
Current thread:
- BUG: Win NT TCP/IP Security filters does not get enforced Stefan Norberg (Oct 08)
- Re: BUG: Win NT TCP/IP Security filters does not get enforced Stefan Norberg (Oct 10)
- Re: BUG: Win NT TCP/IP Security filters does not get enforced David LeBlanc (Oct 12)
- SCO OpenServer 5.0.5 overwrite /etc/shadow Brock Tellier (Oct 11)
- IE 5.0 security vulnerability - reading local (and from any domain, probably window spoofing is possible) files using IFRAME and document.execCommand Georgi Guninski (Oct 11)
- Re: SCO OpenServer 5.0.5 overwrite /etc/shadow Bela Lubkin (Oct 11)
- Re: SCO OpenServer 5.0.5 overwrite /etc/shadow Ralph the Wonder Llama (Oct 12)
- Re: SCO OpenServer 5.0.5 overwrite /etc/shadow Bela Lubkin (Oct 12)
- Xerox DocuColor 4 LP D.O.S Jason Lutz (Oct 13)
- Security of "Virtual Network Computer" Mikael Olsson (Oct 12)
- Re: Security of "Virtual Network Computer" Cameron Simpson (Oct 12)
- Re: BUG: Win NT TCP/IP Security filters does not get enforced Stefan Norberg (Oct 10)
