ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

Flaw discovered in Symantec firewall

Matthew Broersma ZDNet.co.uk

Published: 06 Aug 2002 11:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Researchers have discovered a flaw in Symantec's Raptor firewall that could allow attackers to hijack legitimate communications with a protected system.

The vulnerability lies in the way the software creates and uses random numbers -- called TCP Initial Sequence Numbers -- for each new connection. In order to speed performance, the system reuses the same number for connections coming from the same source IP address and TCP port for a short time after the initial connection is closed, researchers said. During this period, an attacker could use the IP address and TCP information for an earlier, legitimate connection and create a new, unauthorised connection, a technique called "spoofing".

This connection would appear to be coming from an address other than that of the real source, and could be used to carry out an attack.

In addition, researchers said that the way the ISN is generated is not random enough. "A weakness in the generation of these ISNs could allow a remote attacker to easily predict the sequence numbers for a certain session," said Kristof Philipsen, a security engineer with e-security firm Ubizen Luxembourg, which discovered the flaw.

Philipsen said that the generation of ISNs is based on two factors: the source and destination port number, and the source and destination IP address. The problem has been duplicated on six Raptor firewalls, according to Philipsen.

The systems affected are:

  • Raptor Firewall 6.5 for Windows NT
  • Raptor Firewall V6.5.3 for Solaris
  • Symantec Enterprise Firewall 6.5.2 for Windows 2000 and NT
  • Symantec Enterprise Firewall V7.0 for Solaris
  • Symantec Enterprise Firewall 7.0 for Windows 2000 and NT
  • VelociRaptor Model 500/700/1000
  • VelociRaptor Model 1100/1200/1300
  • Symantec Gateway Security 5110/5200/5300
  • Ubizen and Symantec issued statements warning of the hole on Monday, and Symantec has issued a patch for the problem. Symantec's bulletin and patch are available on its Web site.


    For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

    Have your say instantly, and see what others have said. Go to the Security forum.

    Let the editors know what you think in the Mailroom.

    • Email
    • Trackback
    • Clip Link
    • Print friendly Print with Dell

    Did you find this article useful?
    46 out of 83 people found this useful


    Full Talkback thread

    0 comments


    Company/Topic Alerts

    Create a new alert from the list below:









    Related Jobs

    S&P (Security) IT Specialist

    ME/2000/NT/XP/2003 & UNIX/Linux flavours Solaris, AIX etc - Have knowledge of firewalls, switches, routers - Have knowledge of networking - Vlan's, ...

    Implementation Engineer - Unix / Servers - London

    Ensuring there are documented processes within the teams for the smooth running of the services -Provide troubleshooting and specialist support to ...

    Environment Engineer

    Skills and experience: Windows NT, Windows XP, Norton Ghost, Unix (Solaris). Other activities would include booking and scheduling rig usage, ...

    Featured Talkback

    The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

    By: ator1940

    Read full story:
    Microsoft prepares to take Office online