Firewall Wizards mailing list archives

Re: Re: Firewalls breaking stuff: [Was re: fwtk]


From: Paul Robertson <proberts () patriot net>
Date: Mon, 22 Jul 2002 14:19:03 -0400 (EDT)

On Mon, 22 Jul 2002, Charles W. Swiger wrote:

Most of the firewalls sold today are "hardware" running some "software", 
too.  Some of them are nothing more than a PC running *BSD and web-based 
firewall management app.  Let's say the SSL device is internal: on a PCI 
card, or is connected via the SCSI bus.  Even if the device is vulnerable,
  how is an attacker going to get to it?

It doesn't function well as an accelerator if it doesn't accept HTTPS 
connections.

[ Short of compromising and going through the HTTPS server machine, that 
is. ]

It *is* the HTTPS server, that's the idea{NPI].

vulnerable to compromise than any other network appliance.  For instance, 
has anyone else had to update the firmware on their network switches for 
the SNMP vulerability?

Only those who turn that feature on and rely on it for operations.

- And you responded that we should get EVEN MORE COMPLEX by adding
        mystical unauditable devices to the configuration because...?
        it's better than just implementing a subset of SMTP?

Are the mystical unauditable devices sold by some security vendors better?

Nothing is unauditable- it _may_ be that you may or may not have the 
opportunity/skills/time to perform such an audit, but that doesn't make it 
unauditable (we can talk all day about what's important to *you* in an 
audit versus what's important to *me* in an audit- that's a different 
question all together.)

How could I audit the VPN solution you mention below?

1. Source code review.
2. "Black box" testing.
3. Reverse engineering/disassembly.
4. Pick an Open Source solution and do #1.
5. Independent criteria such as ISO 9001[1], Common Criteria[2], ICSA Labs 
IPSec certification[3] either alone, or in combination with some other 
audit criteria.
6. A full 3rd party IT/development audit of the vendor. 

People tend to want VPNs between branch offices or permanent home offices 
because they do take some effort to configure.  People don't tend to want 
VPNs when going to a trade show, or reading their mail from a client site,
  or from some other transient location.

Most of the companies I've looked at which impement VPN connectivity are 
perfectly happy to have sales use if from a tradeshow, hotel or client 
site.

Paul
[1] Falls under the "not acceptable to me" category.
[2] It's necessary to look closely at the protection profile to see if the 
critria is useful to you.
[3] Obviously, ICSA Labs hosts this list, my employer owns the Labs, and 
therefore I might have some bias towards them.  It's necessary to look at 
the criteria to see if it's useful to you.
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts () patriot net      which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: