Re: smoothall vpn im
Chris Moody <chris-I9FJmSBx9zMChIqafcl4fQC/[email protected]> Mon, 22 Nov 2004 16:31:16 -0800
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Organization | Silicon Hotrod |
| Message-ID | <1101169876.13413.32.camel@localhost> |
> Hmmmm, I am quoting myself...proof that I am insane!!! > This just goes to show why you should setup publicly accessible > servers in the orange zone, atm we have no way of knowing what kind of > access the attacker has to the SW webserver and as such, what kind of > access they may have to other computers on the same network (if any) > This is also an appropriate time to go on another rant about a firewall NOT being some magic-bullet defend-all solve-all solution. Just because you have your inbound traffic filtering access to certain ports on certain subnets...does NOT make the answering application(s) any more secure. Certainly, there is a strong case to use ingress filtering...such as the smoothwall supplies. This restricts connection attempts to services that you do NOT want readily accessible (telnet access to your switches/routers on your DMZ being one example)...but does NOT prevent against attacks via allowed traffic. So, for example, you allow inbound connections on the classic port 80 for your web-server. You have followed recommended practice and located this server on the DMZ segment. Users can reach the web-content...they are denied any other access to the web-box...and all is good with the world. Are you sure that the web-forms that you provided are programmed well? Do they allow buffer-overflows? Can someone own the machine through a privelege escalation attack via unchecked sql queries? How tight -IS- your server config anyways? How about accidental information leakage of admin accounts on the eCommerce suite that runs your site (because you didn't delete the README file and setup/ directory that the instructions told you explicitly to do) ? I'm not trying to make anyone lose faith in the smoothwall product. In fact, quite the contrary. The firewall can do it's job all day long...and not miss a beat...but there are other holes that all to often get overlooked and forgotten due to a false sense of security. The firewall did it's job. It did it perfectly. The hole lied elsewhere...and you allowed traffic to it. I have a LOT of faith in these guys, and the smoothwall distro that is provided. Just because their webserver got taken out of commission does not make the smoothwall any more/less secure. Taking a guess (looking at whois and their different ns-record components)...it appears that their different servers (mail, dns, etc) are hosted by several hosting companies. More than likely, the web-site was located on a non-smoothwall owned system on a non-smoothwall protected network. Not that any other firewall could have prevented the compromise...but hopefully this lays a lot of fear about the security of this product to rest. This is also the appropriate time to remind people that MD5sums are not a joke. :o) Hopefully nobody downloads anything that may have been modified. Cheers, -Chris > Imagine if this was your webserver and you had it on green, how long > would it be until the attacker finds the other computers on your > network... > > The other cause for concern is that the attacker might have access to > the personal information stored by the forums, such as full names, > email addresses (even the ones hidden from the public), IP addresses > you have had when visiting the forums etc. > > My other concern is how much of this can be blamed on memset (the > people who host the server), I suppose we won't know that until we > know what happened to the server in the first place. I'm not a member either. Just a proud owner/operator. _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall