Penetration Testing mailing list archives

Re: Nortel Contivity 2600


From: misiu <misiu_ () gmx de>
Date: Tue, 06 Sep 2005 11:14:18 +0200

Dario Ciccarone (dciccaro) schrieb:
Putting the device in question behind the firewall isn't going to help
him with DoS attacks - unless those attacks are due to malformed
packets, _and_ the firewall in question drops the type of malformed
packets that would trigger the DoS.


Hmm, but if malformed packs come, is it not much better to set it behind an IPS? Firewall is not allways the right thing to protect, i guess.
I don't really understand why Nat is not working....
The Adresses of the tunnel are not encrypted, do they might have a checksum wich is altered through a NAT device?

Do I see this right?

misiu

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: