Forum Moderators: phranque

Message Too Old, No Replies

Firewall Vulnerability Found With 'Handshake' Attack

         

engine

1:26 pm on Apr 13, 2011 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Firewall Vulnerability Found With 'Handshake' Attack [networkworld.com]
NSS Labs recently tested half a dozen network firewalls to evaluate security weaknesses, and all but one of them was found not to be vulnerable to a type of attack called the "TCP Split Handshake Attack" that lets a hacker remotely fool the firewall into thinking an IP connection is a trusted one behind the firewall.

"If the firewall thinks you're inside, the security policy it applies to you is an internal one, and you can run a scan to see where machines are," says Rick Moy, president of NSS Labs. An attacker can then pretty much run wild in the network because the firewall mistakenly considers the IP address as a trusted one coming from behind the firewall.

phranque

7:40 am on Apr 14, 2011 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



there is an erratum in that quote.
it should read:
"...all but one of them was found to be vulnerable..."
or
"...only one of them was found not to be vulnerable..."