Security

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
Home » Development Group »» Security
  • Symantec Gateway Security DNS exploit

    0 answers - 1056 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg

    I. THE SYSTEM
    Symantec Gateway Security (SGS) is an enterprise-class appliance with a
    linux-based stateful inspection firewall and application proxy
    capabilities (http/https, ftp, smtp, dns, and so on).
    Using the default installation the system keeps listening on the WAN
    interface for all its proxies. All the proxies use an authentication
    system and everything seems ok. DNS until now can not use authentication
    system
    2. THE EXPLIT
    could connect to the 53/tcp or 53/udp ports of the SGS and use it as a
    dns server, for instance to make some "noisy" queries to primary dns
    servers (zone transfers, and so on). This could be a problem if,for
    instance, those types of queries are logged: in this case the source ip
    will be the address of the SGS
    3. THE SLUTIN
    A solution could be, for instance, to create a filter (i.e. an iptables
    rule) in the SGS to cutoff all the queries coming from outside, taking
    into account some particular situation as, for instance, VPNs or DMZs on
    the red interface

Re: Symantec Gateway Security DNS exploit


max 4000 letters.
Your nickname that display:
In order to stop the spam: 0 + 9 =
SPONSORED
QUESTION

SPONSORED
EMSDN