Possible weakness ??

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Possible weakness ??

Postby ngrayson » Jan 26 04 3:30 am

Guys,

I recently had an incident whereby Someone got further than they should have.

Under ENS, I do not allow intenet pings, and I have add a rule to firewall which says connections from the internet, port 1-65535 action deny for TCP and UDP.

according to me therefore, only sessions created from inside the network through a NAT port should allow the NAT to pass traffic back and this seems to work well.

I also run a time server from analogue x "atomic timesync" which both retrieves the time and acts as an internal time server for the network. I can see therefor that since this will rcreate a session whilst it retrieves the time, someone could try to follow in on it, which is what happened, somone tried to telnet to it. I have checked this and it connects and immediatly disconnects so nothing could be done through it. Interestingly though, at the same time, my logs show that the guest account on wingate was activated and that there was a session initiated from NAT To one of the networked machines.

Can you help me try to understand whats happened here please. If you want the logs, I can email them directly.

Also, if you added a time server to wingate the port of which was under your control, you could prevent this as you could retrieve time and then close the port until the next retrieval. I know it was a feature which has been discussed any idea if and when it may come about?

Many thanks,
ngrayson
Senior Member
 
Posts: 178
Joined: Sep 28 03 12:13 am
Location: UK

Postby genie » Jan 26 04 9:14 am

Did you use FTP or H323 (like NetMeeting)?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Ftp or H323

Postby ngrayson » Jan 26 04 9:54 am

No to h323. Its only a small domestic network.

FTP its possible one of the kids did but I cant say for certain.
ngrayson
Senior Member
 
Posts: 178
Joined: Sep 28 03 12:13 am
Location: UK

Postby genie » Jan 26 04 9:59 am

That might be a reason why you saw this Guest account being activated from the outside - FTP active mode forces the server connect back to the client resulting in the outside connection. It is fairly easy to check - take a look at your log file and check what connection were established before this outside connection appeared.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am


Return to WinGate

Who is online

Users browsing this forum: No registered users and 5 guests

cron