Symantec warns of firewall flaw

Researchers have discovered a flaw in Symantec's Raptor firewall that could allow attackers to hijack legitimate communications with a protected system.

The vulnerability lies in the way the software creates and uses random numbers--called TCP Initial Sequence Numbers--for each new connection. In order to speed performance, the system reuses the same number for connections coming from the same source IP address and TCP port for a short time after the initial connection is closed, researchers said. During this period, an attacker could use the IP address and TCP information for an earlier, legitimate connection and create a new, unauthorized connection, a technique called "spoofing".

This connection would appear to be coming from an address other than that of the real source, and could be used to carry out an attack. In addition, researchers said that the way the ISN is generated is not random enough. "A weakness in the generation of these ISNs could allow a remote attacker to easily predict the sequence numbers for a certain session," said Kristof Philipsen, a security engineer with e-security firm Ubizen Luxembourg, which discovered the flaw.

Philipsen said that the generation of ISNs is based on two factors: the source and destination port number, and the source and destination IP address. The problem has been duplicated on six Raptor firewalls, according to Philipsen.

The systems affected are: · Raptor Firewall 6.5 for Windows NT
· Raptor Firewall V6.5.3 for Solaris
· Symantec Enterprise Firewall 6.5.2 for Windows 2000 and NT
· Symantec Enterprise Firewall V7.0 for Solaris
· Symantec Enterprise Firewall 7.0 for Windows 2000 and NT
· VelociRaptor Model 500/700/1000
· VelociRaptor Model 1100/1200/1300
· Symantec Gateway Security 5110/5200/5300

Ubizen and Symantec issued statements warning of the hole on Monday, and Symantec has issued a patch for the problem. Symantec's bulletin and patch are available on its Web site.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured