home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.novell
- Path: sparky!uunet!ornl!rsg1.er.usgs.gov!darwin.sura.net!zaphod.mps.ohio-state.edu!moe.ksu.ksu.edu!usenet-feed.cc.umr.edu!mcs213i.cs.umr.edu!rfranken
- From: rfranken@mcs213i.cs.umr.edu (Richard Brett Frankenberger)
- Subject: Security Patches - How Secure???
- Date: Thu, 19 Nov 1992 03:02:32 GMT
- Nntp-Posting-Host: mcs213i.cs.umr.edu
- Organization: University of Missouri - Rolla
- Sender: cnews@umr.edu (UMR Usenet News Post)
- Message-ID: <1992Nov19.030232.10943@umr.edu>
- Lines: 35
-
- I hate to be the one to start another security discussion here, but inquiring
- minds want to know ... (seriously, I believe Netowrk administrators should
- have access to this information) ...
-
- Novell recently released patches designed to counteract HACK.EXE. It appears
- that this will prevent HACK.EXE and anything like it from working.
-
- It is clear that I will not be able to forge a packet-signature with information
- available by asking the server (connection number, IPX address, etc); HOWEVER,
- can I forge the packet-signature if I were to montior the wire and
- CAPTURE EVERY PACKET from the time the client workstation runs NETX.
-
- I'm not talking about coming in after the session is already established. I'm
- talking about capturing EVERY PACKET sent between the workstation and the
- server since the beginning to the connection.
-
- Would doing so give me sufficient information to forge a packet signature?
-
- What I am looking for here is either:
-
- (a) a statement that this CAN BE DONE. (I would not expect details, as
- they could be used by a hacker to gain access, although hacker's will probably
- figure this out before too long); or
-
- (b) A detailed explanation of why it cannot be done. There is no danger in
- disclosing protocol details if it won't do hacker any good. A statement from
- someone simply saying this CANNOT BE DONE doesn't mean much - I would much
- rather have it stand up to the scrutiny of the net. (Unix and TCP/IP).
- (And novell has applied for a patent, no there should be no trouble with the
- disclosing of how it works)
-
- Does anyone have any information in this area?
-
- - Brett (rfranken@cs.umr.edu)
-
-