Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
BID:3647
Info
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
| Bugtraq ID: | 3647 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2001 12:00AM |
| Updated: | Dec 06 2001 12:00AM |
| Credit: | Discovered by Tom Liston <[email protected]>. |
| Vulnerable: |
Zone Labs ZoneAlarm Pro 2.6 Zone Labs ZoneAlarm Pro 2.4 Zone Labs ZoneAlarm 2.6 Zone Labs ZoneAlarm 2.5 Zone Labs ZoneAlarm 2.4 Zone Labs ZoneAlarm 2.3 Zone Labs ZoneAlarm 2.2 Zone Labs ZoneAlarm 2.1 Tiny Personal Firewall 2.0 Tiny Personal Firewall 1.0 |
| Not Vulnerable: | |
Discussion
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
Due to a common design error, it may be possible for outbound packets to bypass packet filtering in many personal firewalls.
Many of these applications only block packets created by the standard Windows protocol adapter. It is possible for a user with administrative privileges to create packets with other protocol adapters that are not evaluated against the personal firewall rules when transmitted.
Exploitation will result in a violation of security policy.
Tiny Personal Firewall, ZoneAlarm and ZoneAlarm Pro are confirmed vulnerable. It is believed that other applications similar in design may also be vulnerable.
Due to a common design error, it may be possible for outbound packets to bypass packet filtering in many personal firewalls.
Many of these applications only block packets created by the standard Windows protocol adapter. It is possible for a user with administrative privileges to create packets with other protocol adapters that are not evaluated against the personal firewall rules when transmitted.
Exploitation will result in a violation of security policy.
Tiny Personal Firewall, ZoneAlarm and ZoneAlarm Pro are confirmed vulnerable. It is believed that other applications similar in design may also be vulnerable.
Exploit / POC
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
The discoverer has created a proof of concept program that can be used to determine whether a personal firewall is vulnerable (see webpage in references section):
The discoverer has created a proof of concept program that can be used to determine whether a personal firewall is vulnerable (see webpage in references section):
Solution / Fix
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
Solution:
ZoneAlarm has reportedly released a fix that does not allow for transmission of outbound traffic from non-standard protocol adapters. Currently we do not have information on this fix, however we will update this record when it is available.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
ZoneAlarm has reportedly released a fix that does not allow for transmission of outbound traffic from non-standard protocol adapters. Currently we do not have information on this fix, however we will update this record when it is available.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
References:
References:
- OutBound! (proof of concept) (HackBusters)
- Personal Firewall Homepage (Tiny Software)
- Zone Labs Homepage (Zone Labs)