NetFilter
[Top] [All Lists]

Re: RELATED connections and the feeling of security

To: Hugo Mildenberger <Hugo.Mildenberger@t-online.de>
Subject: Re: RELATED connections and the feeling of security
From: Cedric Blancher <blancher@cartel-securite.fr>
Date: Fri, 13 Apr 2007 16:31:04 +0200
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <200704131457.59976.Hugo.Mildenberger@t-online.de>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Cartel Securite
References: <200704131202.27971.Hugo.Mildenberger@t-online.de> <1176463828.9361.14.camel@anduril.intranet.cartel-securite.net> <200704131457.59976.Hugo.Mildenberger@t-online.de>
Sender: netfilter-bounces@lists.netfilter.org
Le vendredi 13 avril 2007 à 14:57 +0200, Hugo Mildenberger a écrit :
> I base this solely on my observation and did not descend into sources until 
> now.  But I am nearby sure that I had  not tried to establish an ftp 
> connection to the site named in my original post. Even if so, following 
> your remarks, should the ftp-conntrack helper expose arbitrary ports on 
> the originating host?

There's a few conntrack helper around: FTP, IRC, H323, SIP, etc.

> Until today my understanding of this matter was, that the difference between 
> related and established states would be, that within ESTABLISHED state 
> ip-address and port are considered pairwise, while within RELATED state only 
> ip-addresses are considered, making the described attack possible.

No that's not.

> Perhaps we could setup a test case? My equipment here has changed, and 
> for the moment I have no shell access to my DSL router at the internet front.

The very first step to me is reliably reproducing your issue.


-- 
http://sid.rstack.org/
PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
>> Hi! I'm your friendly neighbourhood signature virus.
>> Copy me to your signature file and help me spread!


<Prev in Thread] Current Thread [Next in Thread>