Re: ICMP pokes holes in firewalls... (fwd from [email protected])

Eugen Leitl <[email protected]> Fri, 26 Sep 2003 20:18:25 +0200
Newsgroups gmane.comp.audio.speak-freely.general
Message-ID <[email protected]>
----- Forwarded message from H D Moore <[email protected]> -----

From: H D Moore <[email protected]>,
	(by way of Lucio <[email protected]>)
Date: Fri, 26 Sep 2003 11:54:57 +0000
To: [email protected]
Subject: Re: ICMP pokes holes in firewalls...
Reply-To: [email protected]
Organization: Elaborazione Dati Pinerolo srl
User-Agent: KMail/1.4.1

Only if these systems are running kernel version 2.2, the 2.4 NAT system
has been rewritten and is not vulnerable.

On Friday 26 September 2003 04:55 am, Lucio wrote:
> > This also applies to Linux NAT gateways.
>
> I'm rellay not an expert in building a firewall with a Linux box, but
> I've tried twice and now I have two customers happy of their
> unexpensive Linux based firewall. These firewalls offer also NAT
> functionality to the respective LANs they protect and use iptables
> rules with stateful inspection to filter the packets. Both customers
> have a DNS in between the linux firewall and the ISP's router. Are they
> vulnerable to any of those attacks?

----- End forwarded message -----
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)

iD8DBQE/dILxdbAkQ4sp9r4RAnfCAKCgwfbZkXQc97qEU+jTxgCPVDNKXgCfatW1
3knLf6ChDjzxRPUKPJLNg2M=
=83ye
-----END PGP SIGNATURE-----