S!x
January 13th, 2005, 01:33 AM
A wide range of personal firewall products are vulnerable to bypass by a malicious script. Because the products do not require password verification for rulebase changes, it is possible to inject keystrokes or GUI actions via VBScript (and possibly other scripting languages) to open "backdoors" in the firewall, allowing an attacker unrestricted access.
This flaw enables that any Trojan or similar programs can easily bypass firewall and act as a server or access to another computer. Also most of these firewalls have a "remember" option so if you bypass firewall and successfully exploit it, firewall will never ask again.
http://ferruh.mavituna.com/article/?769
http://www.smoothwall.net/information/news/newsitem.php?id=688
Sorry about landing in this forum ... i don't know what happened.
To avoid double posting i will let the admins. move it.
This flaw enables that any Trojan or similar programs can easily bypass firewall and act as a server or access to another computer. Also most of these firewalls have a "remember" option so if you bypass firewall and successfully exploit it, firewall will never ask again.
http://ferruh.mavituna.com/article/?769
http://www.smoothwall.net/information/news/newsitem.php?id=688
Sorry about landing in this forum ... i don't know what happened.
To avoid double posting i will let the admins. move it.