Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Webroot Desktop Firewall <=5.5.10.20 DNS recursion |
|---|---|
| Date: | 28 Oct 2007 09:40:24 -0000 |
Webroot Desktop Firewall 5.5.10.20 ITDEFENCE.ru Advisory Author: Komarov Andrej (komarov@itdefence.ru I. BACKGROUND The Webroot Desktop Firewall secures your computer from Internet threats and reduces the risks of being a victim of online crimes. Unlike the Windows XP and Vista Firewall, Webroot Desktop Firewall combines intelligent firewall technology with intrusion prevention for inbound and outbound protection that is both powerful and easy to use. http://www.webroot.com/ II. DESCRIPTION DNS tunnelling involves inserting data into the DNS packet using "space" in the packet that can take additional data. For example, A DNS packet can contain a TXT record into which any text, up to 220 bytes, can be inserted. You fragment the data, maybe an HTTP request, add it to the packet, and send the modified DNS traffic over the web to a receiving server. It recompiles the sent data, and enables internet access. DNS packets can be used to transfer extra data and this is why they should be controlled by firewalls as any other packets. III. ANALYSIS Windows DNS API using can help an attacker to make data transfer possible. If the successfull recursive DNS query for ?x-site? is done, it is possible to transfer information from your computer past personal and network firewalls. There is a "stealth" way of DNS connectivity checking using Windows System Services (services.exe / svchost.exe) and if it is not controlled there is a possibility of covert channel creating. Additional links: NSTX-suite by Florian Heinz and Julien Oster (http://nstx.dereference.de) Gray-World NET Team (http://gray-world.net/papers.shtml) The DNS-shaped holes that one cuts into firewalls. (http://homepages.tesco.net/~J.deBoynePollard/FGA/dns-shaped-firewall-holes.html) DNSTest by Jarkko Turkulainen (http://www.klake.org/~jt/dnshell/)
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in procedure DBMS_AQADM_SYS.DBLINK_INFO, Team SHATTER |
|---|---|
| Next by Date: | Final Call for Papers for Security Track at ApacheCon Europe 2008, Lars Eilebrecht |
| Previous by Thread: | [Full-disclosure] Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in procedure DBMS_AQADM_SYS.DBLINK_INFO, Team SHATTER |
| Next by Thread: | Final Call for Papers for Security Track at ApacheCon Europe 2008, Lars Eilebrecht |
| Indexes: | [Date] [Thread] [Top] [All Lists] |