Firewall Wizards mailing list archives

Re: FW-1: Questions about DHCP and IPX


From: Adam Shostack <adam () homeport org>
Date: Fri, 25 Sep 1998 14:54:16 -0400

On Thu, Sep 24, 1998 at 02:17:18PM -0400, Joseph S. D. Yao wrote:
| > Don't know about you, but that FW-1 is quite often installed with the
| > ability for anyone to connect to the FW-1 daemon is un-nerving to me.
| > If there were a backdoor, that would be the place to start looking...
| 
| One thing I was told ... it doesn't matter whether or how well you
| review the code.  CP supposedly can do automatic updates to it, to
| "improve" your firewall.  How nice!

        This is, unlike many FW-1 comments, a testable hypothosis.
Use tripwire.

        Responding to someone else; I know of two commercial
enterprises that have FW1 source available to them.  Its apparently
not hard to get if you spend enough money with them and sign the right
NDAs.


Adam

-- 
"It is seldom that liberty of any kind is lost all at once."
                                                       -Hume




Current thread: