Found a huge security hole. How do we plug it?

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Found a huge security hole. How do we plug it?

Postby bhollna92000 » Feb 23 07 10:28 am

We are using the latest version of wingate (6.2.0 build 1121)and are using KAV and Puresight (latest versions). What we have found just today is that if clients use automatic IP address settings, (Wingate DHCP) then everything works like it should, but if clients sets a manual IP address then they have full and open access to the internet, and do not show up anywhere in Gatekeeper or its logs! even in its Client activity screen. The client is just invisible!

Needless to say, this is not acceptable. What is wrong and what can we do about it?

Brian
bhollna92000
 
Posts: 16
Joined: Oct 13 06 6:55 am

Postby ChrisH » Feb 23 07 11:58 am

Do these clients gain access to the internet directly through a router - effectively bypassing WG? Or do they still have Gateway pointing to WG server?
Chris H.
ChrisH
WinGate Master
 
Posts: 388
Joined: Sep 13 03 1:38 am
Location: Canada

Gateway still the same

Postby bhollna92000 » Feb 23 07 12:02 pm

They still have the gateway still pointing to the WG server.

Brian
bhollna92000
 
Posts: 16
Joined: Oct 13 06 6:55 am

PS to that...

Postby bhollna92000 » Feb 23 07 12:03 pm

BTW, they have to go through the WG machine, there is no physical access to the internet otherwise.
bhollna92000
 
Posts: 16
Joined: Oct 13 06 6:55 am

Problem fixed

Postby bhollna92000 » Feb 23 07 12:09 pm

We upgraded to build 1131 and that seems to have fixed the problem.

Brian
bhollna92000
 
Posts: 16
Joined: Oct 13 06 6:55 am

Re: Problem fixed

Postby ChrisH » Feb 23 07 12:59 pm

bhollna92000 wrote:We upgraded to build 1131 and that seems to have fixed the problem.


Interesting - but good to know! I wonder what it was?
Chris H.
ChrisH
WinGate Master
 
Posts: 388
Joined: Sep 13 03 1:38 am
Location: Canada


Return to WinGate

Who is online

Users browsing this forum: No registered users and 2 guests