|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: NAI Security Advisory - Windows IP source routing
Ronan Waide (waider
SCOPE.IE)
Wed, 22 Sep 1999 09:41:30 +0100
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
- Next message: rfp
WIRETRIP.NET: "Update to ODBC/RDS vulnerabilities"
- Previous message: Vladimir Dubrovin: "Re: More fun with WWWBoard"
- In reply to: Chris Ridd: "Re: More fun with WWWBoard"
- Next in thread: Eric D. Williams: "Re: NAI Security Advisory - Windows IP source routing"
On September 21, hh
it-sec.de said:
> > Windows TCP/IP stacks configured to disable IP forwarding or IP
> > source routing, allow specific source routed datagrams to route
> > between interfaces. Effectively, the Windows TCP/IP stack can
> > not be configured to disable IP datagrams passing between
> > networks if two network cards have been installed.
>
> Any knowledge whether Firewall/Packet-Filtering Products based on the
> Windows TCP/IP stack are concerned and under what circumstances?
>
> thanks, hh
Being similarily concerned, I checked with a friend of mine who works
for an Internet security firm. His response, roughly:
It's only an issue if your Windows TCP/IP stack is out in the open. If
it's behind a router, you can turn off source routing at the router -
and, in fact, most ISPs probably do this already. Additionally, at
least one NT-based firewall vendor claims that their stack 'precedes'
the NT stack in the chain of traffic, so the broken stack should be
protected that way.
He also thinks that current Cisco routers come with source-routed
packets disabled by default.
Cheers,
Waider.
-- waiderscope.ie / Small Planet Ltd. / +353-1-8303455 / +353-1-8300888 (Fax)
"Life sucks. Get a helmet." - Denis Leary, as quoted by Susan Witterick on "It never rains, it POURS."
- Next message: rfp
WIRETRIP.NET: "Update to ODBC/RDS vulnerabilities"
- Previous message: Vladimir Dubrovin: "Re: More fun with WWWBoard"
- In reply to: Chris Ridd: "Re: More fun with WWWBoard"
- Next in thread: Eric D. Williams: "Re: NAI Security Advisory - Windows IP source routing"
This archive was generated by hypermail 2.0b3 on Wed Sep 22 1999 - 13:21:45 CDT