TCP - IP White Papers

Unverified Fields - A Problem with Firewalls & Firewall Technology Today

Overview The problem discussed in this paper has not yet been identified. Certain firewalls today, will not authenticate the validity of certain protocol fields, within the packet they are processing. The risk is exposure of information. What kind of information can be exposed? Mainly it will be unique patterns of behavior produced by the probed machines answering our crafted queries (or other kind of network traffic initiated in order to elicit a reply). The research paper “ICMP Usage In Scanning 1” has introduced new operating system fingerprinting methods based on changing values inside certain fields of the ICMP datagram. Using some of these methods I will demonstrate the risk. It is important to understand that I am using the ICMP protocol as an example. Other protocols can be used as well for this task.

Further White Paper Details
PublisherSys-Security.com File FormatPDF, requires Acrobat Rdr 5
Date PublishedOctober 2000 Downloads4
FormatWhite Papers   
Topics

Quick Sitemap Links: