On Fri, 5 Mar 2004, Robinson, Eric wrote:
> Fair enough, although this assumes the attacker has already positioned
> himself to capture traffic between the source and destination in order
> to know what to spoof.
This is an incorrect assumption. Given enough time and effort, at least
some data will leak about clients behind a NAT device or firewall. In many
cases, a simple footprint analysis will suffice to identify potential
targets; it doesn't require a man-in-the-middle approach.
> point to an entirely different socket. Is that possible? Otherwise, the
> attacker would have to know what process he's talking to, and what
Again, this is an incorrect assumption. Just like spam, or the Code Red
virus, you can inject packets with the assumption that eventually a
crafted packet will have an effect *somewhere*, even if it isn't targeted.
You're thinking too much about directed traffic; you also need to consider
shotgun approaches, such as many worms use.
> True, but you'd still be talking to the browser process on the client.
Again, you're making assumptions based on things not in your original
premise. Who said only the browser process was listening on the client?
What is stopping the client from listening on other ports, or stopping
other ports from passing the NAT device?
At any rate, the point is being missed. No one is saying it's *easy* to
bypass a firewall or NAT device. What we're saying is that it can be done,
and that dynamic NAT *by itself* does not significantly enhance security.
However, clients running few listening sockets and whose translation
address is highly dynamic will certainly reduce the time window available
for *targeted* attacks.
As for packet fragmentation, you can Google for examples. Here's one to
get you started, though:
http://www.insecure.org/sploits/NT.no_first_fragment.IP_frag.attack.html
As part of a defense-in-depth, a bug-free *firewall* performing NAT will
certainly help, but will require additional layers of security to be
effective.
--
Todd's "Customer Disservice Hall of Shame" currently contains:
- Charter Communications: Mislead their customers about service
levels, block normal Internet connectivity, and exhibit excessive
downtime.
- AT&T: Honoring the "checks" they send out to entice you to switch
long-distance providers is apparently optional.
- eFax: Receive (not send) 20 pages of *unsolicited* faxes, and lose
your account.
_______________________________________________
RLUG mailing list
[EMAIL PROTECTED]
http://www.rlug.org/mailman/listinfo/rlug