Security Basics mailing list archives

Re: Firewall question - how easy is it to get thru - Proof


From: Ansgar Wiechers <bugtraq () planetcobalt net>
Date: Tue, 15 Feb 2011 23:45:57 +0100

On 2011-02-14 Rivest, Philippe wrote:
When I do an audit and when I find a major flaw or deficiency, IT
always tells me "its because your in the internal LAN, we have a
firewall protecting us". I know you have all heard that. So I try to
explain that you could attack thru physical security, social
engineering, virus and a lot of other ways and in the end I always add
"Someone more "expert" in Firewall could bypass it".

I don't really need a "how-to" but I'm looking for proof and a time
frame on how long it normally takes for a real hacker/cracker to
attack and bypass (where possible) a Firewall control (IPS/IDS also!). 

I know this is not a click-click your done type of job, but I know its
possible.

Place some rigged USB sticks. Social engineering or lack of physical
security don't require attackers to be "experts in firewalls", as those
attacks bypass firewalls altogether.

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: