Re: smoothall vpn im

Chris Moody <chris-I9FJmSBx9zMChIqafcl4fQC/[email protected]> Mon, 22 Nov 2004 16:31:16 -0800
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Organization Silicon Hotrod
Message-ID <1101169876.13413.32.camel@localhost>
> Hmmmm, I am quoting myself...proof that I am insane!!!
> This just goes to show why you should setup publicly accessible
> servers in the orange zone, atm we have no way of knowing what kind of
> access the attacker has to the SW webserver and as such, what kind of
> access they may have to other computers on the same network (if any)
> 

This is also an appropriate time to go on another rant about a firewall
NOT being some magic-bullet defend-all solve-all solution.

Just because you have your inbound traffic filtering access to certain
ports on certain subnets...does NOT make the answering application(s)
any more secure.

Certainly, there is a strong case to use ingress filtering...such as the
smoothwall supplies.  This restricts connection attempts to services
that you do NOT want readily accessible (telnet access to your
switches/routers on your DMZ being one example)...but does NOT prevent
against attacks via allowed traffic.

So, for example, you allow inbound connections on the classic port 80
for your web-server.  You have followed recommended practice and located
this server on the DMZ segment.  Users can reach the web-content...they
are denied any other access to the web-box...and all is good with the
world.

Are you sure that the web-forms that you provided are programmed well? 
Do they allow buffer-overflows?  Can someone own the machine through a
privelege escalation attack via unchecked sql queries?  How tight -IS-
your server config anyways?  How about accidental information leakage of
admin accounts on the eCommerce suite that runs your site (because you
didn't delete the README file and setup/ directory that the instructions
told you explicitly to do) ?

I'm not trying to make anyone lose faith in the smoothwall product.  In
fact, quite the contrary.

The firewall can do it's job all day long...and not miss a beat...but
there are other holes that all to often get overlooked and forgotten due
to a false sense of security.  The firewall did it's job.  It did it
perfectly.  The hole lied elsewhere...and you allowed traffic to it.

I have a LOT of faith in these guys, and the smoothwall distro that is
provided.  Just because their webserver got taken out of commission does
not make the smoothwall any more/less secure.  

Taking a guess (looking at whois and their different ns-record
components)...it appears that their different servers (mail, dns, etc)
are hosted by several hosting companies.  More than likely, the web-site
was located on a non-smoothwall owned system on a non-smoothwall
protected network.  Not that any other firewall could have prevented the
compromise...but hopefully this lays a lot of fear about the security of
this product to rest.

This is also the appropriate time to remind people that MD5sums are not
a joke. :o)  Hopefully nobody downloads anything that may have been
modified.

Cheers,
-Chris

> Imagine if this was your webserver and you had it on green, how long
> would it be until the attacker finds the other computers on your
> network...
> 
> The other cause for concern is that the attacker might have access to
> the personal information stored by the forums, such as full names,
> email addresses (even the ones hidden from the public), IP addresses
> you have had when visiting the forums etc.
> 
> My other concern is how much of this can be blamed on memset (the
> people who host the server), I suppose we won't know that until we
> know what happened to the server in the first place.

I'm not a member either.  Just a proud owner/operator.
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall