From owner-fwtk-users@ex.tis.com Tue Sep  4 11:04 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA05480
	Tue, 4 Sep 2001 11:04:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA26483;
	Tue, 4 Sep 2001 10:11:59 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 4 Sep 2001 10:02:19 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA24277
	for fwtk-users-outgoing; Tue, 4 Sep 2001 10:02:18 -0500 (CDT)
X-Authentication-Warning: martini.super.unam.mx: dsc owned process doing -bs
Date: Mon, 3 Sep 2001 21:13:05 -0500 (CDT)
From: Seguridad en Computo - UNAM <seguridad@seguridad.unam.mx>
X-Sender: dsc@martini.super.unam.mx
To: seguridad@seguridad.unam.mx
Subject: Computer Security Mexico 2001
Message-ID: <Pine.GSO.4.10.10109032055550.27069-100000@martini.super.unam.mx>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from QUOTED-PRINTABLE to 8bit by relay2.nai.com id VAA03738
Sender: owner-fwtk-users@lists.nai.com
Content-Type: TEXT/PLAIN; charset=X-UNKNOWN
Content-Length: 9036
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

-----BEGIN PGP SIGNED MESSAGE-----

- -----------------------------------------------------------------------------
                              Call for papers

                           Centro Mascarones-UNAM
                     November 24th-November 27th, 2001

                      Antiguo Colegio de San Ildefonso
                     November 28th-November 30th, 2001

			  Old Downtown,Mexico City
- -----------------------------------------------------------------------------

The goal  of Computer Security 2001 Mexico (www.seguridad2001.unam.mx) and
the International Computer Security Day(www.disc2001.unam.mx) is to
create awareness among the computer user community about security
strategies and mechanisms used to protect information systems.

Computer Security 2001  will be an event for all the people who are involved
in the  use, design and administration of computer systems.  DISC 2001 is an
annual  world-wide  celebration  led  by   ACM  (Association  for  Computing
Machinery).

Since 1994, Mexico has participated of this celebration through the Computer
Security Department (DSC-UNAM, www.seguridad.unam.mx) and UNAM-CERT 
(www.unam-cert.unam.mx). This year, DISC 2001 will take place
along with Computer Security 2001 on November 30th.

The community  is invited to  participate in Computer  Security 2001 through
the  presentation of theoretical,  technical, and  applied works as  well as
those that  present practical  experiences in the following  topics (but not
limited to them):

   * Electronic commerce
        o Certification
        o Digital cash
        o New protocols
        o Secure transactions
        o New technologies
   * New firewall technologies
        o Hybrids FW
        o New generations of FW
   * World Wide Web security
        o Secure Sockets Layer (SSL)
        o Secure schemes
   * Legislation about Computer Security
        o Advances in legislation 1999-2000
        o Regulation of domain names
        o Copyright and industrial property
   * Network security
        o New network technology applied to security (ATM, Fast Ethernet)
        o Router security
   * Cluster security
   * Software development security
   * Distributed systems security
   * Database security
   * Security of agents and multi-platform languages
   * Incident response teams
   * Computer security incident handling, prevention and coordination
   * Administrative and legal issues on incident handling
   * Software protection and intellectual property
   * New tools for incident handling
   * Intrusion detection
   * Computer attacks
   * Privacy and cryptography protocols
   * Security policies
   * Computer viruses
   * DDOS

             --------------------------------------------------

                             Who should attend ?

   * System administrators who are interested in Computer Security.

   * People working in the field of Computer Security who do handle Computer
     Security incidents.

   *  Anybody  who is  interested  in  Computer Security  and wants  to  meet
     another  interested people.  This event  will help  him or  her improve
     security programs, plans, and tools by listening to the speakers and by
     sharing and interacting with the attendees.

   * People who want to establish incident response teams.

   * Anybody  who has a particular  interest in network security, monitoring
     tools, intrusion detection and firewalls.

   * Managers  of enterprises who are  interested in secure transactions via
     the Internet and that need to improve the security of their systems.

             --------------------------------------------------

                           Why should you assist?

Because it  is the opportunity to find out about  what is being developed in
the  computer security  field  and it  is also  a chance  to share  your own
experience and interests with people of the field.

You can learn about how to manage and respond to computer security incidents
without exposing your resources.

     Important Dates

          Paper submissions: October 12th

          Acceptance notifications: October 26th

          Final papers: November 2th

          Event: November 24th - November 30th.

     Workshop Format

There will  be  tutorial-style and workshop-style presentations  on November
24,25,26  and 27 .  On  November 28,  29  and 30 , there  will be  technical
conferences and business sessions only.

All contributions should follow the next guidelines:

     1. Tutorials  and workshops:  Half or full  day tutorial proposals
     will be considered.

     2. Conference  papers: Written  papers may be as  long as desired,
     but presentations must be limited to 30 minutes.

     3.  Panel  Sessions:  These  are informal  sessions  that  should,
     either,   follow  a   "hands-on"   approach,  or   encourage  more
     participation from the audience.

They should  be tailored to address specific issues  and should be take from
60 to 90 minutes  of duration. Panel Sessions on a particular topic are also
acceptable.

             --------------------------------------------------

                          Instructions for authors

We will  receive proposals  for presentations, workshops  and tutorials that
follow these guidelines:

   * The documents should be submitted by the date indicated above.
   * The  contents of  the documents should  be of high-quality  and must be
     original.

   * They should include an abstract with the description of the content and
     style of the presentation.

   *  The papers  will be  evaluated using  the actual  proposal, which  must
     contain:

        o title
        o format (workshop, tutorial or conference)
        o extended abstract (more than one but less than two pages)
        o requirements for the presentation (computing equipment,
        o datashow projector, slide projector, etc.)
        o author information
             + name
             + address and affiliation
             + brief resume
             + fax and telephone number
             + e-mail address

For tutorials, the following information should also be included:

   * Goal
   * Introduction and summary
   * Outline of the presentation
   * Duration (half or full day)
   * Presentation material (e.g., slides, datashow)

     Accepted formats

Authors whose  papers are  accepted must submit  the complete version  to be
included into the proceedings of the event.

Submissions will be accepted in the following formats:

   * TeX/LaTeX
   * PostScript
   * Word for Windows
   * ASCII
   * HTML

Please contact the committee  (comite@seguridad.unam.mx ) should you need to
use a different format.

Note: For images and graphics use GIF, PCX, BMP, JPEG and JPG formats.

     Submissions

Presentations can be sent using the following means:

        * e-mail:

               comite@seguridad.unam.mx

        * Post mail to the following address:

               Departamento de Seguridad en CÛmputo
               DirecciÛn General de CÛmputo AcadÈmico
               Circuito   Exterior,  Ciudad   Universitaria  04510
               MÈxico, D.F. MÈxico

             --------------------------------------------------

                             Program Committee

The papers will be evaluated and selected by a scientific committee.

The  committee  will  be  integrated  by  investigators  and  profesionistas
recognized in the field of the computer security worldwide.

             --------------------------------------------------

                            Further Information:

	* Web:	  http://www.seguridad2001.unam.mx
		  http://www.disc2001.unam.mx

        * e-mail: comite@seguridad.unam.mx


        * Address:

               Departamento de Seguridad en CÛmputo
               DirecciÛn General de CÛmputo AcadÈmico
               Circuito   Exterior,  Ciudad   Universitaria  04510
               MÈxico, D.F. MÈxico
               Phone  : (52)  56 22  81 69  and (52)  56 85  22 29
               Fax : (52) 56 22 80 43
	       http://www.seguridad.unam.mx
	       http://www.unam-cert.unam.mx


Juan Carlos Guel
- --
Departamento Seguridad en Computo
UNAM-CERT
DGSCA, UNAM			E-mail:seguridad@seguridad.unam.mx
Circuito Exterior, C. U.        Tel.: 5622-81-69  Fax: 5622-80-43
Del. Coyoacan			WWW: http://www.seguridad.unam.mx
04510 Mexico D. F.	        WWW: http://www.unam-cert.unam.mx

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: cp850

iQEVAwUBO5Q4zXAvLUtwgRsVAQGc8Qf/Y5XsrlT97z1RTuRLUHbQdBgCm7SHquhn
2NfasGnnaGiHnV38dEocr07uDCzaeHG7sBoq4rCFuMl740kHEBR/Z2m/PfVrjjk/
cihFhm5BJ7nKdd3nTgJBjFNGkLyhcwL5HU7RxVgK5jRcOyMNUDufZ/TmKOmRBn4P
3AIM9SGrPYuDTPSG/jRy+23GPFdQoUZnxDQucPzFxwzWz0xYz0WdD2iz1BratnJO
BUofoM/0LVftQLAZqwIxv1HqE3WfcCHe0CX56TjjODF5BmzVwReg0JTaFYtx6irW
o1LdUcrBlUfelupYuVtZjyG7pRZU9hByUcjU9pIagaftJUgTak7C/A==
=C9QT
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Wed Sep  5 07:10 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07914
	Wed, 5 Sep 2001 07:10:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA29280;
	Wed, 5 Sep 2001 06:17:22 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 5 Sep 2001 06:14:07 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA28661
	for fwtk-users-outgoing; Wed, 5 Sep 2001 06:14:04 -0500 (CDT)
Message-ID: <3B9608D6.B5D2A238@zrz.TU-Berlin.DE>
Date: Wed, 05 Sep 2001 13:13:26 +0200
From: Gerd Schering <Schering@zrz.tu-berlin.de>
Organization: TUB
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.19-4.4mdk i686)
X-Accept-Language: en
MIME-Version: 1.0
To: FWTK Mailing Liste <fwtk-users@ex.tis.com>
CC: Stefan Schnieber <schnieber@zrz.tu-berlin.de>,
        Eckart Fellner <Fellner@zrz.tu-berlin.de>
Subject: Performance using squid and squid-gw
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1689
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Hi all,

we have the following configuration

outer proxy(squid) <---> fwtk/squid-gw <---> inner proxy (squid)
 
All Users behind the firewall are forced to use the inner proxy, if 
they want to acces the web. Squid-gw forwards the requests to the 
outer proxy. The response is scanned by squid-gw for activeX etc.
Unfortunately the performance of the system ist not too good and we 
are unsure which of the the three components is (the most) responsible.
We can see, that the CPU time needed by squid-gw ist rather small, so 
it could be more a sort of a I/O related problem then a problem 
of scanning the documents by squid-gw.

Has anyone experience with a similar configuration or any hint, 
what we could do, to increase the performance?

Any help is welcome!

Cheers, Gerd

------------------------------------------------------
-- Gerd Schering
-- Email: Schering@zrz.TU-Berlin.DE
-- TU Berlin, Zentraleinrichtung Rechenzentrum
-- Sekr. E-N 50, Einsteinufer 17, 10587 Berlin
-- phone: +49 30 314 24383
-- fax:   +49 30 314 21060
------------------------------------------------------

#########################################################
# Meine digitale Unterschrift wurde vom Trustcenter     #
# der Technischen Universität Berlin zertifiziert.      #
# Sie können sie nach Installation des                  #
# Wurzelzertifikats dieses Trustcenters verifizieren.   #
# Das Wurzelzertifikat erhalten Sie durch Aufruf von    #
#   http://ca.tu-berlin.de/certs/TUB-TC2000cert.der     #
#########################################################

From owner-fwtk-users@ex.tis.com Wed Sep  5 22:33 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA09587
	Wed, 5 Sep 2001 22:33:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA16443;
	Wed, 5 Sep 2001 21:38:30 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 5 Sep 2001 21:32:35 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA15648
	for fwtk-users-outgoing; Wed, 5 Sep 2001 21:32:34 -0500 (CDT)
Message-Id: <5.0.0.25.1.20010906122617.00ad5d58@unixgib>
X-Sender: mto@unixgib
X-Mailer: QUALCOMM Windows Eudora Version 5.0
Date: Thu, 06 Sep 2001 12:36:08 +1000
To: fwtk-users@ex.tis.com
From: Michael <mOrgill@tpgi.com.au>
Subject: Supporting both FTP & FTP proxy on one Host
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 824
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Hi,

I have fwtk installed on a Red Hat linux box with ftp-gw set up in the 
inetd.conf file.
I can ftp out of the box but I need to be able to ftp in & leave files on 
the linux box.
After reading some of the documentation I tried to compile the the code in 
tools/server/ftpd directory of the source code, this gave me 2 errors :-
1)  ftpd.c:1560: macro `strpbrk' used without args
2)  glob.c: In function `matchdir':
      glob.c:231: dereferencing pointer to incomplete type

a) Does anyone know how to fix the compile errors ?
b) Could someone possible give me information on the set up needed to make 
ftp-gw work from outside to the inside as mentioned above.

Regards
Michael Orgill


From owner-fwtk-users@ex.tis.com Thu Sep  6 07:44 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA10247
	Thu, 6 Sep 2001 07:44:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA17120;
	Thu, 6 Sep 2001 06:52:10 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 06:49:14 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA16504
	for fwtk-users-outgoing; Thu, 6 Sep 2001 06:49:12 -0500 (CDT)
From: Betty_Cross@mapinfo.com
Subject: ftp
To: fwtk-users@ex.tis.com
X-Mailer: Lotus Notes Release 5.0.5  September 22, 2000
Message-ID: <OFEB77EE89.FA3A7052-ON85256ABF.0040C57A@mapinfo.com>
Date: Thu, 6 Sep 2001 07:51:03 -0400
X-MIMETrack: Serialize by Router on LINK2/MapInfo Corp(Release 5.0.7 |March 21, 2001) at
 09/06/2001 07:52:30 AM
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 776
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Hi,

  I am new to fwtk.  I am trying to set up a Solaris 8 box so that only
specific hosts can ftp to it.
I was successful at getting one host to ftp to the box while locking out
other hosts.  However,
modifications to my netperm-table file to add additional hosts don't seem
to be working.
Does t he file need to be re-read someway?  I have tried putting multiple
hosts on one
line and putting a separate line in for each host.  Still I can only ftp
into the box from the
original host I specified. I did stop and restart the inet services on the
Solaris box
and that didn't change things either.  I'd appreciate any help.
   Thanks.

Betty


From owner-fwtk-users@ex.tis.com Thu Sep  6 11:46 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10785
	Thu, 6 Sep 2001 11:46:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA25341;
	Thu, 6 Sep 2001 10:53:17 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 10:49:24 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA24290
	for fwtk-users-outgoing; Thu, 6 Sep 2001 10:49:23 -0500 (CDT)
Message-Id: <5.1.0.14.0.20010906065036.01f93800@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Thu, 06 Sep 2001 07:09:48 -0400
To: Michael <mOrgill@tpgi.com.au>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Supporting both FTP & FTP proxy on one Host
In-Reply-To: <5.0.0.25.1.20010906122617.00ad5d58@unixgib>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 2092
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

At 12:36 PM 9/6/01 +1000, Michael wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@lists.nai.com.]
>
>Hi,
>
>I have fwtk installed on a Red Hat linux box with ftp-gw set up in the 
>inetd.conf file.
>I can ftp out of the box but I need to be able to ftp in & leave files on 
>the linux box.

I do this by using netacl to front-end ftpd. If a connection comes from 
127.0.0.1, netacl execs in.ftpd, otherwise it runs ftp-gw. To ftp to the 
firewall, you connect to the ftp-gw then "user foo@localhost" connects you 
to the local ftpd.
Something like the following in your netperm-table should work, if you 
adjust it for where your local ftp daemon lives:

netacl-ftpd:    permit-hosts 127.0.0.1 -exec /usr/bin/in.ftpd -l
netacl-ftpd:    permit-hosts * -exec /usr/local/bin/ftp-gw

>After reading some of the documentation I tried to compile the the code in 
>tools/server/ftpd directory of the source code, this gave me 2 errors :-
>1)  ftpd.c:1560: macro `strpbrk' used without args
>2)  glob.c: In function `matchdir':
>      glob.c:231: dereferencing pointer to incomplete type
>
>a) Does anyone know how to fix the compile errors ?

1. comment out line 1560 in ftpd.c (your header files somewhere define a 
macro for strpbrk; that line in ftpd.c defines strpbrk as a function.)
2. This is harder to fix. The recent Linux kernels don't have a "dd_fd" 
member in their dirent structure. You can change this code from
         if (fstat(dirp->dd_fd, &stb) < 0)
to
         if (fstat(dirfd(dirp), &stb) < 0)

And see if that fixes it. The existing code is using a nonstandard hook to 
grab a field that isn't guaranteed to be there.

>b) Could someone possible give me information on the set up needed to make 
>ftp-gw work from outside to the inside as mentioned above.

As I mentioned, use the netacl approach mentioned above. Be careful about 
patches for your ftpd.
         -Rick

From owner-fwtk-users@ex.tis.com Thu Sep  6 13:16 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA10985
	Thu, 6 Sep 2001 13:16:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA11295;
	Thu, 6 Sep 2001 12:24:04 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 12:21:10 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA10462
	for fwtk-users-outgoing; Thu, 6 Sep 2001 12:21:08 -0500 (CDT)
Date: Thu, 6 Sep 2001 12:51:04 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: <Betty_Cross@mapinfo.com>
cc: <fwtk-users@ex.tis.com>
Subject: Re: ftp
In-Reply-To: <OFEB77EE89.FA3A7052-ON85256ABF.0040C57A@mapinfo.com>
Message-ID: <Pine.GSO.4.31.0109061250380.19276-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1086
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

So Betty,

What tool are you using to limit the connections?  netacl?

ted keller


On Thu, 6 Sep 2001 Betty_Cross@mapinfo.com wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@lists.nai.com.]
>
> Hi,
>
>   I am new to fwtk.  I am trying to set up a Solaris 8 box so that only
> specific hosts can ftp to it.
> I was successful at getting one host to ftp to the box while locking out
> other hosts.  However,
> modifications to my netperm-table file to add additional hosts don't seem
> to be working.
> Does t he file need to be re-read someway?  I have tried putting multiple
> hosts on one
> line and putting a separate line in for each host.  Still I can only ftp
> into the box from the
> original host I specified. I did stop and restart the inet services on the
> Solaris box
> and that didn't change things either.  I'd appreciate any help.
>    Thanks.
>
> Betty
>
>


From owner-fwtk-users@ex.tis.com Thu Sep  6 15:41 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA11224
	Thu, 6 Sep 2001 15:41:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA12202;
	Thu, 6 Sep 2001 14:48:31 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 14:45:22 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA11281
	for fwtk-users-outgoing; Thu, 6 Sep 2001 14:45:21 -0500 (CDT)
Message-ID: <3B97D231.D2E87BE2@usa.alcatel.com>
Date: Thu, 06 Sep 2001 14:44:49 -0500
From: Kris Herrin <kris.herrin@usa.alcatel.com>
X-Mailer: Mozilla 4.76 [en] (WinNT; U)
X-Accept-Language: en
MIME-Version: 1.0
CC: fwtk-users@ex.tis.com
Subject: smap/smapd bug in FWTK??
References: <Pine.GSO.4.31.0109061250380.19276-100000@ns4.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 303
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Does anybody know if the smap/smapd bug recently discovered is present
in FWTK or not?? I've have been so far unsuccessful in getting further
details of the bug.

Thanks.

From owner-fwtk-users@ex.tis.com Thu Sep  6 16:18 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11257
	Thu, 6 Sep 2001 16:18:27 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA20900;
	Thu, 6 Sep 2001 15:25:42 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 15:22:33 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA19658
	for fwtk-users-outgoing; Thu, 6 Sep 2001 15:22:32 -0500 (CDT)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: fwtk-users@ex.tis.com
Date: Thu, 6 Sep 2001 14:21:58 -0600
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: smap/smapd bug in FWTK??
Message-ID: <3B978683.8350.A2A8C6@localhost>
In-reply-to: <3B97D231.D2E87BE2@usa.alcatel.com>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 507
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

The bugtraq archive message that announced this is at:

http://www.securityfocus.com/archive/1/212033

I'm curious about whether this is in FWTK as well.

Ken


On 6 Sep 2001, at 14:44, Kris Herrin wrote:

> Does anybody know if the smap/smapd bug recently discovered is present
> in FWTK or not?? I've have been so far unsuccessful in getting further
> details of the bug.


From owner-fwtk-users@ex.tis.com Thu Sep  6 23:38 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA11734
	Thu, 6 Sep 2001 23:38:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id WAA13924;
	Thu, 6 Sep 2001 22:45:26 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 6 Sep 2001 22:39:35 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id WAA13341
	for fwtk-users-outgoing; Thu, 6 Sep 2001 22:39:34 -0500 (CDT)
Message-ID: <20010907033931.23263.qmail@web20402.mail.yahoo.com>
Date: Thu, 6 Sep 2001 20:39:31 -0700 (PDT)
From: red snake <manish_fwtk@yahoo.com>
Subject: authentication algorithms authsrv
To: fwtk-users@ex.tis.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 409
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

hi all

       can ne one tell me of algorithm of
authentication used by authsrv.
and how does skey works

manish

__________________________________________________
Do You Yahoo!?
Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger
http://im.yahoo.com

From owner-fwtk-users@ex.tis.com Fri Sep  7 06:42 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA12308
	Fri, 7 Sep 2001 06:42:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA24841;
	Fri, 7 Sep 2001 05:49:33 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 05:46:04 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA24310
	for fwtk-users-outgoing; Fri, 7 Sep 2001 05:46:02 -0500 (CDT)
Message-ID: <3B98A533.2A7250CF@zrz.TU-Berlin.DE>
Date: Fri, 07 Sep 2001 12:45:07 +0200
From: Gerd Schering <Schering@zrz.tu-berlin.de>
Organization: TUB
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.19-4.4mdk i686)
X-Accept-Language: en
MIME-Version: 1.0
To: FWTK Mailing Liste <fwtk-users@ex.tis.com>
CC: Stefan Schnieber <schnieber@zrz.tu-berlin.de>,
        Eckart Fellner <Fellner@zrz.tu-berlin.de>
Subject: URGENT: smap /smapd buffer overflow?
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 7879
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Hi,

an advisory of the CERT Coordination Center warn fro a buffer overflow
in the smap/smapd daemons used by Gauntlet firewalls.

Are the smap/smapd daemons of the FWTK also affected?
I include the advisory for conveniance.

Gerd
> - -----BEGIN PGP SIGNED MESSAGE-----
> 
> CERT Advisory CA-2001-25 Buffer Overflow in Gauntlet Firewall allows
> intruders to execute arbitrary code
> 
>    Original release date: September 06, 2001
>    Last revised: --
>    Source: CERT/CC
> 
>    A complete revision history can be found at the end of this file.
> 
> Systems Affected
> 
>   * Systems running the following products that use Gauntlet Firewall
> 
>      * Gauntlet for Unix versions 5.x
>      * PGP e-ppliance 300 series version 1.0
>      * McAfee e-ppliance 100 and 120 series
>      * Gauntlet for Unix version 6.0
>      * PGP e-ppliance 300 series versions 1.5, 2.0
>      * PGP e-ppliance 1000 series versions 1.5, 2.0
>      * McAfee WebShield for Solaris v4.1
> 
> Overview
> 
>    A vulnerability for a remotely exploitable buffer overflow exists
>    in Gauntlet Firewall by PGP Security.
> 
> I. Description
> 
>    The buffer overflow occurs in the smap/smapd and CSMAP daemons.
>    According to PGP Security, these daemons are responsible for
>    handling email transactions for both inbound and outbound email.
> 
>    On September 04, 2001, PGP Security released a security bulletin
>    and patches for this vulnerability. For more information, please
>    see
> 
>           http://www.pgp.com/support/product-advisories/csmap.asp
>           http://www.pgp.com/naicommon/download/upgrade/upgrades-patch.asp
>           http://www.kb.cert.org/vuls/id/206723
> 
> II. Impact
> 
>    An intruder can execute arbitrary code with the privileges of the
>    corresponding daemon.  Additionally, firewalls often have trust
>    relationships with other network devices. An intruder who
>    compromises a firewall may be able to leverage this trust to
>    compromise other devices on the network or to make changes to the
>    network configuration.
> 
> III. Solution
> 
> Apply a patch
> 
>    Appendix A contains information provided by vendors for this
>    advisory.  We will update the appendix as we receive more
>    information. If you do not see your vendor's name, the CERT/CC did
>    not hear from that vendor.  Please contact your vendor directly.
> 
> Appendix A. - Vendor Information
> 
>    This appendix contains information provided by vendors for this
>    advisory.  When vendors report new information to the CERT/CC, we
>    update this section and note the changes in our revision
>    history. If a particular vendor is not listed below, we have not
>    received their comments.
> 
> Network Associates, Inc.
> 
>    PGP Security has published a security advisory describing this
>    vulnerability as well as patches. This is available from
> 
>           http://www.pgp.com/support/product-advisories/csmap.asp
>           http://www.pgp.com/naicommon/download/upgrade/upgrades-patch.asp
> 
> References
> 
>     1. http://www.pgp.com/support/product-advisories/csmap.asp
>     2. http://www.pgp.com/naicommon/download/upgrade/upgrades-patch.asp
>     3. http://www.kb.cert.org/vuls/id/206723
>      _________________________________________________________________
> 
>    The CERT Coordination Center thanks PGP Security for their
>    advisory, on which this document is based.
>    _________________________________________________________________
> 
>    Feedback on this document can be directed to the author, Ian A. Finlay.
>    ______________________________________________________________________
> 
>    This document is available from:
>    http://www.cert.org/advisories/CA-2001-25.html
>    ______________________________________________________________________
> 
> CERT/CC Contact Information
> 
>    Email: cert@cert.org
>           Phone: +1 412-268-7090 (24-hour hotline)
>           Fax: +1 412-268-6989
>           Postal address:
>           CERT Coordination Center
>           Software Engineering Institute
>           Carnegie Mellon University
>           Pittsburgh PA 15213-3890
>           U.S.A.
> 
>    CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) /
>    EDT(GMT-4) Monday through Friday; they are on call for emergencies
>    during other hours, on U.S. holidays, and on weekends.
> 
>     Using encryption
> 
>    We strongly urge you to encrypt sensitive information sent by
>    email.  Our public PGP key is available from
> 
>    http://www.cert.org/CERT_PGP.key
> 
>    If you prefer to use DES, please call the CERT hotline for more
>    information.
> 
>     Getting security information
> 
>    CERT publications and other security information are available from
>    our web site
> 
>    http://www.cert.org/
> 
>    To subscribe to the CERT mailing list for advisories and bulletins,
>    send email to majordomo@cert.org. Please include in the body of
>    your message
> 
>    subscribe cert-advisory
> 
>    *  "CERT"  and  "CERT  Coordination Center" are registered in the U.S.
>    Patent and Trademark Office.
>    ______________________________________________________________________
> 
>    NO WARRANTY
> 
>    Any material furnished by Carnegie Mellon University and the
>    Software Engineering Institute is furnished on an "as is"
>    basis. Carnegie Mellon University makes no warranties of any kind,
>    either expressed or implied as to any matter including, but not
>    limited to, warranty of fitness for a particular purpose or
>    merchantability, exclusivity or results obtained from use of the
>    material. Carnegie Mellon University does not make any warranty of
>    any kind with respect to freedom from patent, trademark, or
>    copyright infringement.
>    _________________________________________________________________
> 
>    Conditions for use, disclaimers, and sponsorship information
> 
>    Copyright 2001 Carnegie Mellon University.
> 
>    Revision History
>    September 06, 2001:  Initial release
> 
> - -----BEGIN PGP SIGNATURE-----
> Version: PGPfreeware 5.0i for non-commercial use
> Charset: noconv
> 
> iQCVAwUBO5gEwAYcfu8gsZJZAQEcjAP+PciEp6xeIK+dGr8Hazin4sXDP9KDYfus
> FGN38fqzRZhNfA6ReO/9bbQp7pvuijcVB0F9BasNZc3HPTnxFpWaguqgWfNnihnB
> +JZHzQ4HaK0tLWT4rcorfu7U5sdXz3zHPHkdPX8B4ael0h6XJ9hJ6rq6PMIDww+P
> DQbVFE886v4=
> =wcI5
> - -----END PGP SIGNATURE-----
> 
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2i
> Comment: Processed by Mailcrypt 3.5.5, an Emacs/PGP interface
> 
> iQEVAgUBO5iZd+I9ttyl3QPRAQGxUQf/WHUplbdINKpn4LtSfnOjsrhlz9FrtvDI
> dXv/na9JaJxJeramaC2sZjz+N2ZmhLELq7GG/Pv9OYjJzNqBSAu7wJrc6d+9Jl16
> L4RPXLvg+Xlri8cMhMpnhTfMyb07BNI9bb85wXBABI8ZiIO2WDdrQY7xbgNiRihE
> WUElACUcE/FhMiwrQT2zJRHcexXjTQTI4gp5wmffQiu47ddEqJhSSPIvm2CazmDj
> jzSJoAR1GpWA+UZ3FNsSq+kpMacb4TtHsLXl+JyGECzILcFNpanD9jtxl315uK0E
> ObBJ73kNET4hz+DCFS7s0sj3RB1zTTvDS3BrFH/Cf5YavwDpOyEpsw==
> =EdJT
> -----END PGP SIGNATURE-----

-- 
------------------------------------------------------
-- Gerd Schering
-- Email: Schering@zrz.TU-Berlin.DE
-- TU Berlin, Zentraleinrichtung Rechenzentrum
-- Sekr. E-N 50, Einsteinufer 17, 10587 Berlin
-- phone: +49 30 314 24383
-- fax:   +49 30 314 21060
------------------------------------------------------

#########################################################
# Meine digitale Unterschrift wurde vom Trustcenter     #
# der Technischen Universität Berlin zertifiziert.      #
# Sie können sie nach Installation des                  #
# Wurzelzertifikats dieses Trustcenters verifizieren.   #
# Das Wurzelzertifikat erhalten Sie durch Aufruf von    #
#   http://ca.tu-berlin.de/certs/TUB-TC2000cert.der     #
#########################################################

From owner-fwtk-users@ex.tis.com Fri Sep  7 09:30 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA12796
	Fri, 7 Sep 2001 09:30:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA04255;
	Fri, 7 Sep 2001 08:37:23 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 08:34:26 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA03301
	for fwtk-users-outgoing; Fri, 7 Sep 2001 08:34:24 -0500 (CDT)
Message-ID: <3B98CCC0.A7B5B68B@usa.alcatel.com>
Date: Fri, 07 Sep 2001 08:33:52 -0500
From: Kris Herrin <kris.herrin@usa.alcatel.com>
X-Mailer: Mozilla 4.76 [en] (WinNT; U)
X-Accept-Language: en
MIME-Version: 1.0
CC: FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Re: URGENT: smap /smapd buffer overflow?
References: <3B98A533.2A7250CF@zrz.TU-Berlin.DE>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 673
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Gerd,

This question has been asked by a couple of us already, with no
response. If anybody has further info on the bug, please let us know.

I'm currently talking to development guys at NAI. If I get the details
of the bug out of them, I'll let the list know.

Kris

Gerd Schering wrote:
> 
> Hi,
> 
> an advisory of the CERT Coordination Center warn fro a buffer overflow
> in the smap/smapd daemons used by Gauntlet firewalls.
> 
> Are the smap/smapd daemons of the FWTK also affected?
> I include the advisory for conveniance.
> 
> Gerd

From owner-fwtk-users@ex.tis.com Fri Sep  7 09:49 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA12848
	Fri, 7 Sep 2001 09:48:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA07878;
	Fri, 7 Sep 2001 08:56:16 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 08:54:35 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA07258
	for fwtk-users-outgoing; Fri, 7 Sep 2001 08:54:33 -0500 (CDT)
Message-ID: <3B98D140.6090103@v-one.com>
Date: Fri, 07 Sep 2001 09:53:04 -0400
From: Keith Young <kyoung@v-one.com>
Reply-To: kyoung@v-one.com
Organization: V-ONE
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:0.9.3) Gecko/20010801
X-Accept-Language: en-us
MIME-Version: 1.0
To: Kris Herrin <kris.herrin@usa.alcatel.com>
CC: FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Re: URGENT: smap /smapd buffer overflow?
References: <3B98A533.2A7250CF@zrz.TU-Berlin.DE> <3B98CCC0.A7B5B68B@usa.alcatel.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 718
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Kris Herrin wrote:

> 
> This question has been asked by a couple of us already, with no
> response. If anybody has further info on the bug, please let us know.
> 
> I'm currently talking to development guys at NAI. If I get the details
> of the bug out of them, I'll let the list know.
> 

I am going to (hopefully) work in our security lab today in order to 
find the actual overflow. Once I discover it, I'll check the FWTK.

I looked at the FWTK source late last night and, if my guess on the 
overflow is correct, FWTK v2.1 is not vulnerable.

-- 
--Keith Young
-kyoung@v-one.com


From owner-fwtk-users@ex.tis.com Fri Sep  7 11:56 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA12973
	Fri, 7 Sep 2001 11:56:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA25775;
	Fri, 7 Sep 2001 11:03:45 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 10:59:04 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA24518
	for fwtk-users-outgoing; Fri, 7 Sep 2001 10:59:02 -0500 (CDT)
X-Authentication-Warning: wall.pdv.de: mail set sender to <Dirk.Nerling@pdv.de> using -f
Message-ID: <6CC81B07CB44D311A1D20001FA7E995657EB74@exchange.pdv.de>
From: "Dirk.Nerling" <Dirk.Nerling@pdv.de>
To: "Firewall Toolkit (M-list)" <fwtk-users@ex.tis.com>
Subject: how do I enable fwtk logging to FreeBSD 4.3 standard syslogd???
Date: Fri, 7 Sep 2001 17:58:13 +0200 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.0.1460.8)
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain
Content-Length: 637
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

Hello,

I try to get FWTK 2.1 to work. Unfortunately I don't get the any messages
from the toolkit logged to my syslogd. firewall.h has LOG_NOTICE and I do
have *.notice in my syslogd.conf. Do I really need the fwtk syslogd ???

thanks in advance and best regards
Dirk Nerling
--
Dirk Nerling, PDV-Systeme Erfurt, Haarbergstr. 73, 99099 Erfurt, phone:
++49-361-4407144
            PGP Fingerprint: C559 FF0E BAD0 9E09 F720  20F3 683E 357F 69B5
CC83
                       	             http://www.pdv.de


From owner-fwtk-users@ex.tis.com Fri Sep  7 14:58 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA13283
	Fri, 7 Sep 2001 14:58:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA20038;
	Fri, 7 Sep 2001 14:06:05 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 14:02:43 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA19070
	for fwtk-users-outgoing; Fri, 7 Sep 2001 14:02:42 -0500 (CDT)
Date: Fri, 7 Sep 2001 15:01:57 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Keith Young <kyoung@v-one.com>
Cc: Kris Herrin <kris.herrin@usa.alcatel.com>,
        FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Re: URGENT: smap /smapd buffer overflow?
Message-ID: <20010907150157.I20199@washington.cospo.osis.gov>
Mail-Followup-To: Keith Young <kyoung@v-one.com>,
	Kris Herrin <kris.herrin@usa.alcatel.com>,
	FWTK Mailing Liste <fwtk-users@ex.tis.com>
References: <3B98A533.2A7250CF@zrz.TU-Berlin.DE> <3B98CCC0.A7B5B68B@usa.alcatel.com> <3B98D140.6090103@v-one.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <3B98D140.6090103@v-one.com>; from kyoung@v-one.com on Fri, Sep 07, 2001 at 09:53:04AM -0400
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 965
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

On Fri, Sep 07, 2001 at 09:53:04AM -0400, Keith Young wrote:
...
> I am going to (hopefully) work in our security lab today in order to 
> find the actual overflow. Once I discover it, I'll check the FWTK.
> 
> I looked at the FWTK source late last night and, if my guess on the 
> overflow is correct, FWTK v2.1 is not vulnerable.

FWIW, I tried to eliminate all such in the "yao" patch collection.
There were some, IIRC.  [How long has it been?  ;-}]

If IBM and Microsoft can't guarantee that their software works for any
given purpose, though, who am I to say that I caught all the bugs?  ;-)

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
OSIS Center Computer Support					EMT-B
-----------------------------------------------------------------------
   This message is not an official statement of OSIS Center policies.

From owner-fwtk-users@ex.tis.com Fri Sep  7 16:06 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA13357
	Fri, 7 Sep 2001 16:06:31 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA02891;
	Fri, 7 Sep 2001 15:13:48 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 15:10:46 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA01916
	for fwtk-users-outgoing; Fri, 7 Sep 2001 15:10:45 -0500 (CDT)
Date: Fri, 7 Sep 2001 16:10:15 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Keith Young <kyoung@v-one.com>
cc: Kris Herrin <kris.herrin@usa.alcatel.com>,
        FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Re: URGENT: smap /smapd buffer overflow?
In-Reply-To: <3B98D140.6090103@v-one.com>
Message-ID: <Pine.GSO.4.31.0109071609160.27339-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1132
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

I tend to agree with Keith.  From the description, it appears that the
vulnerability was tied to their virus checking plug-ins.  I've been
through this code extensively over the past several years.

tek


On Fri, 7 Sep 2001, Keith Young wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@lists.nai.com.]
>
> Kris Herrin wrote:
>
> >
> > This question has been asked by a couple of us already, with no
> > response. If anybody has further info on the bug, please let us know.
> >
> > I'm currently talking to development guys at NAI. If I get the details
> > of the bug out of them, I'll let the list know.
> >
>
> I am going to (hopefully) work in our security lab today in order to
> find the actual overflow. Once I discover it, I'll check the FWTK.
>
> I looked at the FWTK source late last night and, if my guess on the
> overflow is correct, FWTK v2.1 is not vulnerable.
>
> --
> --Keith Young
> -kyoung@v-one.com
>
>


From owner-fwtk-users@ex.tis.com Fri Sep  7 21:28 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA13712
	Fri, 7 Sep 2001 21:28:48 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA03546;
	Fri, 7 Sep 2001 20:36:02 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 20:33:03 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA03047
	for fwtk-users-outgoing; Fri, 7 Sep 2001 20:33:01 -0500 (CDT)
Message-Id: <5.1.0.14.0.20010907212041.01f373a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Fri, 07 Sep 2001 21:31:34 -0400
To: "Dirk.Nerling" <Dirk.Nerling@pdv.de>,
        "Firewall Toolkit (M-list)" <fwtk-users@ex.tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: how do I enable fwtk logging to FreeBSD 4.3 standard
  syslogd???
In-Reply-To: <6CC81B07CB44D311A1D20001FA7E995657EB74@exchange.pdv.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 749
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

At 05:58 PM 9/7/01 +0200, Dirk.Nerling wrote:
>I try to get FWTK 2.1 to work. Unfortunately I don't get the any messages
>from the toolkit logged to my syslogd. firewall.h has LOG_NOTICE and I do
>have *.notice in my syslogd.conf. Do I really need the fwtk syslogd ???

No, the fwtk syslogd isn't necessary. Some operating systems do have 
problems with log calls performed from chroot'd processes; maybe that's 
what you are seeing.
Try building with USE_UDPSYSLOG defined (add a define to your 
Makefile.config) and see if that works (make sure you "make clean" after 
editing the Makefile.config).
         -Rick


From owner-fwtk-users@ex.tis.com Fri Sep  7 21:36 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA13730
	Fri, 7 Sep 2001 21:36:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA04586;
	Fri, 7 Sep 2001 20:44:16 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 7 Sep 2001 20:43:02 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA04094
	for fwtk-users-outgoing; Fri, 7 Sep 2001 20:43:01 -0500 (CDT)
Message-Id: <5.1.0.14.0.20010907213145.01f3c410@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Fri, 07 Sep 2001 21:35:55 -0400
To: Kris Herrin <kris.herrin@usa.alcatel.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: smap/smapd bug in FWTK??
Cc: fwtk-users@ex.tis.com
In-Reply-To: <3B97D231.D2E87BE2@usa.alcatel.com>
References: <Pine.GSO.4.31.0109061250380.19276-100000@ns4.bfg.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 787
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

At 02:44 PM 9/6/01 -0500, Kris Herrin wrote:
>Does anybody know if the smap/smapd bug recently discovered is present
>in FWTK or not?? I've have been so far unsuccessful in getting further
>details of the bug.

Like the others, I don't have any details about the Gauntlet smap problem. 
However, the two proxies have significantly diverged; I'd be surprised if 
there was a common bug. The fact that only recent Gauntlet releases are 
listed as vulnerable also leads me to think that this is a bug in Gauntlet 
code only.

If I get more details about the problem - or an assertion that the FWTK 
isn't  vulnerable, I'll let the list know.
         -Rick


From owner-fwtk-users@ex.tis.com Mon Sep 10 10:46 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA17707
	Mon, 10 Sep 2001 10:46:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA10053;
	Mon, 10 Sep 2001 09:53:54 -0500 (CDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 10 Sep 2001 09:47:25 -0500
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA08769
	for fwtk-users-outgoing; Mon, 10 Sep 2001 09:47:23 -0500 (CDT)
Message-ID: <3B9CD22A.4030405@v-one.com>
Date: Mon, 10 Sep 2001 10:46:02 -0400
From: Keith Young <kyoung@v-one.com>
Reply-To: kyoung@v-one.com
Organization: V-ONE
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:0.9.3) Gecko/20010801
X-Accept-Language: en-us
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: Information for "www.fwtk.org" site mirrors
References: <Pine.GSO.4.31.0109061250380.19276-100000@ns4.bfg.com> <5.1.0.14.0.20010907213145.01f3c410@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.nai.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 532
Status: RO

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@lists.nai.com.]

FYI, for those who are running mirrors of fwtk.org, the mirroring 
address has changed. Please point to "199.181.80.151". You should be 
using the same login/password.

If you have any questions, please let me know at either this e-mail or 
at "avenger@erols.com".

P.S. Testing on the "smap" issue is still ongoing (I am still trying to 
get details from NAI).

-- 
--Keith Young
-kyoung@v-one.com


