Re: iptables rule to block FTP-NAT-Helper-Traffic



On Wed, 26 Nov 2008 17:34:07 +0100, Pascal Hambourg wrote:

Anyway, is this really efficient ? Couldn't the hostile applet just
connect locally to the VNC port and relay the communication with the
hostile server ?

Alternatively, why bother using FTP for this? Could the applet not open
a connection from the local machine's port P to some specified port on
the malicious remote server? That remote/malicious server could then
connect to port P on the victim machine from that specific port. This
should work for any port P greater than 1024 and for either UDP or TCP.

I can envision a way to prevent this for TCP: Add to the
ESTABLISHED,RELATED rule logic which blocks a SYN w/o the ACK. But I'm
not sure how one could prevent UDP from sliding through in this attack.

- Andrew
.



Relevant Pages

  • Re: ipfw and nmap
    ... > even be correct but I have a bsd box that is simply providing me SSH ... add allow tcp from any to me 22 setup in via fxp0 keep-state ... Note too that there is nothing to prevent port scanners simply setting ... the 'SYN' flag in the probe packets they send to your server. ...
    (freebsd-questions)
  • Re: Scans on port 17107
    ... Some were TCP and others UDP. ... Hard to say - seeing both TCP and UDP to the same port number (other than ... meaning it's not a regular server. ...
    (comp.os.linux.security)
  • Re: Open port PIX 501
    ... :i can't open the port in my PIX. ... :I need open the port 1000 to point to the IP 10.254.254.222. ... in practice only DNS servers doing zone transfers need tcp. ... of UDP, it would be a highly unusual client which did not stick ...
    (comp.dcom.sys.cisco)
  • Re: SQL 2008 Remoteverbindung
    ... Ich kann mich jetzt auf den Server verbinden & es funktioniert wirklich ... die Grundsätzliche Verbindung funktioniert jetzt. ... Bei IPALL bist du schon richtig, den Port must du aber bei 'TCP Port' ...
    (microsoft.public.de.sqlserver)
  • Re: Connect to SQL 2005 database on local network fails
    ... ActiveSync doesn't forward UDP packets. ... but after looking at your remote connection string I ... using the correct port number to connect to the database server. ...
    (microsoft.public.dotnet.framework.compactframework)