Firewall Wizards mailing list archives

Re: Phrack #60: "Java tears down the Firewall"


From: Dragos Ruiu <dr () kyx net>
Date: Fri, 3 Jan 2003 18:33:51 +0000

On January 3, 2003 10:02 pm, Marcus J. Ranum wrote:
Mikael Olsson wrote:
- The firewall automagically pokes a hole for this "data channel"
- The server box is suddenly allowed to connect to this
 vulnerable port, through the firewall.

Could the java app proxy to other ports internally? Seems
like a simple exercise for the malcoder.

mjr.

In theory the java security model was supposed to limit this.
Practice so far has fallen short of theory. :-)

cheers,
--dr

-- 
dr () kyx net   pgp: http://dragos.com/kyxpgp
Advance CanSecWest/03 registration available: http://cansecwest.com
"The question of whether computers can think is like the question
  of whether submarines can swim." --Edsger Wybe Dijkstra 1930-2002

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: