DOC PREVIEW
SJSU CS 265 - Firewall Vulnerabilities

This preview shows page 1-2-3-4-5 out of 14 pages.

Save
View full document
View full document
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience
Premium Document
Do you want full access? Go Premium and unlock all 14 pages.
Access to all documents
Download any document
Ad free experience

Unformatted text preview:

Firewall VulnerabilitiesTopicsFirewallsFirewall Design (The benefits)Firewall Design (The drawbacks)OSI StackApplicationsFirewall ImplementationSymantec Firewall/VPN AppliancePyramid BenHur FirewallKerio Personal FirewallCheck Point Firewall-1DeleGate Application ProxyConclusionFirewall VulnerabilitiesPresented by Vincent J. OhmTopics• Firewall design•(Stateful) Packet Filter, Application proxy, Personal Firewall• OSI Stack Layer• IP, TCP spoofing• Applications•sendmail• Firewall implementation• broad permissions, overflows, etc.Firewalls• Network gateway• handles incoming & outgoing traffic• Access manager•blocks/grants access to services, networksFirewall Design(The benefits)• Packet Filter– scans IP address, port number– block specific adresses, ports– Stateful: adds connection filtering• Application Proxy– scans packet payload– filter harmful data, program commands• Personal– combination of filter & proxyFirewall Design(The drawbacks)• Packet Filter– harmful data passes through• Application Proxy– unknown application vulnerabilitiesOSI Stack• Network – I.P.– no address authentication– address is spoofable• Transport – T.C.P.– sequence number enforces exclusivity– spoof I.P. address and guess seq. number...– T.C.P. spoofingApplications•Applications with vulnerabilities–sendmail ‘WIZ’  debugging command creates root shell access on remote server•Methods of exploitation–crafted data (overflows)–commands (sendmail)•Packet Filters can block some•Application Proxies can block moreFirewall Implementation•Symantec Firewall/VPN Appliance–Password leak•Pyramid BenHur–Active FTP•Kerio Personal Firewall–Rules bypassable•Cisco PIX–SNMPv3, VPNC IPsec•Check Point Firewall-1 & DeleGate application proxy–overflowsSymantec Firewall/VPN Appliance•Accessing firewall to change password from unsecured terminal using web browser•Firewall’s HTTP response, stored in browser cache•HTTP response contains the new password…•…in cleartext!•Symantec’s fix: strips password dataPyramid BenHur Firewall•Firewall access rules can be bypassed…•…by sending connect request with source port = 20  FTP data port•Can connect to any port•Workaround: block all outside access from port 20 OR apply patchKerio Personal Firewall•Problem with default configuration•Firewall would allow any UDP packet through if source port = 53  DNS port•Intention: allow DNS responses•Fix: allow packet only if DNS request precedes the responseCheck Point Firewall-1•Invalid HTTP request•Generates error message using portion of input…•…included in format string used for call to sprintf()•Exploit for:–command execution on firewall–arbitrary code executionDeleGate Application Proxy•Uses fixed array size for username & password•Arrays used in calls to strcpy()•Input sufficiently long strings…•…buffer overflow!Conclusion•Firewalls are not invulnerable•Vulnerable by …–Design–Other O.S.I. Layers vulnerabilities–Implementation


View Full Document

SJSU CS 265 - Firewall Vulnerabilities

Documents in this Course
Stem

Stem

9 pages

WinZip

WinZip

6 pages

Rsync

Rsync

7 pages

Hunter

Hunter

11 pages

SSH

SSH

16 pages

RSA

RSA

7 pages

Akenti

Akenti

17 pages

Blunders

Blunders

51 pages

Captcha

Captcha

6 pages

Radius

Radius

8 pages

Firewall

Firewall

10 pages

SAP

SAP

6 pages

SECURITY

SECURITY

19 pages

Rsync

Rsync

18 pages

MDSD

MDSD

9 pages

honeypots

honeypots

15 pages

VPN

VPN

6 pages

Wang

Wang

18 pages

TKIP

TKIP

6 pages

ESP

ESP

6 pages

Dai

Dai

5 pages

Load more
Download Firewall Vulnerabilities
Our administrator received your request to download this document. We will send you the file to your email shortly.
Loading Unlocking...
Login

Join to view Firewall Vulnerabilities and access 3M+ class-specific study document.

or
We will never post anything without your permission.
Don't have an account?
Sign Up

Join to view Firewall Vulnerabilities 2 2 and access 3M+ class-specific study document.

or

By creating an account you agree to our Privacy Policy and Terms Of Use

Already a member?