PDA

View Full Version : Firewall Bypass Vulnerability


S!x
January 13th, 2005, 01:33 AM
A wide range of personal firewall products are vulnerable to bypass by a malicious script. Because the products do not require password verification for rulebase changes, it is possible to inject keystrokes or GUI actions via VBScript (and possibly other scripting languages) to open "backdoors" in the firewall, allowing an attacker unrestricted access.

This flaw enables that any Trojan or similar programs can easily bypass firewall and act as a server or access to another computer. Also most of these firewalls have a "remember" option so if you bypass firewall and successfully exploit it, firewall will never ask again.

http://ferruh.mavituna.com/article/?769
http://www.smoothwall.net/information/news/newsitem.php?id=688

Sorry about landing in this forum ... i don't know what happened.
To avoid double posting i will let the admins. move it.

puff-m-d
January 13th, 2005, 01:37 AM
Hi S!x,

As you figured, I have moved your post from the updates forum to the other firewall forum ;) ...

BlitzenZeus
January 13th, 2005, 01:49 AM
Also many firewalls have a password option, I use it to keep people from messing with my configuration, or even shutting it down on the user account I make available for guests.

Nice try, no dice for those who actually use their firewall how they should. It also has to konw how to properly interact with every firewall, even different versions which might have some variants through different versions.

Paranoid2000
January 13th, 2005, 02:11 AM
This has already been discussed in the Multiple Firewall Products Bypass Vulnerability (http://www.wilderssecurity.com/showthread.php?t=60736) thread...

S!x
January 13th, 2005, 12:51 PM
"This has already been discussed in the Multiple Firewall Products Bypass Vulnerability thread..."

I guess that is what the search feature is for? :o
Didn't notice it until now ... i will use it in the future.

puff-m-d
January 13th, 2005, 01:00 PM
Since this thread has served its purpose as there is another active thread open on the subject "Multiple Firewall Products Bypass Vulnerability (http://www.wilderssecurity.com/showthread.php?t=60736)", I will now close this thread. Any further comments can be made in the original thread.