IPFilter TTL Fingerprinting Vulnerability
BID:4403
Info
IPFilter TTL Fingerprinting Vulnerability
| Bugtraq ID: | 4403 |
| Class: | Design Error |
| CVE: |
CVE-2002-0515 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Vulnerability discovery credited to Meder Kydyraliev <[email protected]>. |
| Vulnerable: |
Darren Reed IPFilter 3.4.25 |
| Not Vulnerable: | |
Discussion
IPFilter TTL Fingerprinting Vulnerability
IPFilter is a freely available, open source firewall package written by Darren Reed. It is available for multiple platforms, including Unix and Linux operating systems.
Under some circumstances, IPFilter sends responses that can allow an attacker to gain information about the firewall ruleset. When an attempt is made to connect to a system via TCP on a port that is filtered by IPFilter, and IPFilter returns a RST, it is possible to differentiate between filtered and unfiltered ports. A port that is filtered by IPFilter will return a RST with a TTL field set to 60, whereas the operating system will return it's default TTL value for a RST.
IPFilter is a freely available, open source firewall package written by Darren Reed. It is available for multiple platforms, including Unix and Linux operating systems.
Under some circumstances, IPFilter sends responses that can allow an attacker to gain information about the firewall ruleset. When an attempt is made to connect to a system via TCP on a port that is filtered by IPFilter, and IPFilter returns a RST, it is possible to differentiate between filtered and unfiltered ports. A port that is filtered by IPFilter will return a RST with a TTL field set to 60, whereas the operating system will return it's default TTL value for a RST.
Exploit / POC
IPFilter TTL Fingerprinting Vulnerability
This vulnerability may be exploited by using one of numerous available portscanning utilities and packet analysis utilities.
This vulnerability may be exploited by using one of numerous available portscanning utilities and packet analysis utilities.
Solution / Fix
IPFilter TTL Fingerprinting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IPFilter TTL Fingerprinting Vulnerability
References:
References: