Firewall Wizards mailing list archives

Re: Firewalls that generate new packets..


From: Darren Reed <Darren.Reed () Sun COM>
Date: Wed, 28 Nov 2007 15:54:44 -0800

J. Oquendo wrote:

...
On the flip side of this whole argument right here... Coming from an attack
vector, I've pretty much shut down (local and remotely) three of the five
firewalls I mentioned with a DoS tool I wrote that is being looked at by 2
of the five mentioned. Isn't that ironic... Here they are protecting, yet
here they are all vulnerable at the bottom of it all. I cannot, will not
post any coding probably ever because I do not believe there are fixes
(legacy TCP thing I believe). PSIRT has tinkered with it for the past 60+
days without a resolution. The other vendor solely sent a generic "eye eye
Spock we will look at it!" but my guess is they'd rather spend money on
inviting us all to continental breakfast and a movie (hey you got that
too!)

To be fair to firewall vendors about this attack though, it pretty much
shuts down anything connected period, from a DSL --> DS3 goodbye. So I
guess it would be fair to state that as opposed to seeming as if I'm
pointing a finger at the entire firewall industry.
 


This kind of attitude really annoys the heck out of me.

There are more people that care about hearing about these styles
of problems than those 5 companies.

Put up or shut up - at present, what you're describing sounds like
something you can talk about to make yourself seem clever as
there is no acknowledgement from anyone else that what you've
thought of works.

It's highly doubtful that you've run across something that nobody
else has and email like this does nothing except spread FUD.

Darren

_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: