Bugtraq mailing list archives
AOL client uses IP tunneling
From: aviram () SECURITEAM COM (Aviram Jenik)
Date: Mon, 21 Dec 1998 21:27:28 +0200
Hi. I don't know if this is well known, but I'm sure it's new to many people on this list. Many administrators allow AOL client communication through their firewall. Those should understand, that while the AOL client only uses port 5190 for communication, the client actually establishes an IP tunnel to the server, in order to become a part of a VPN, thus effectively piercing the firewall. The consequences are that basically the firewall is useless. The firewall can do very little filtering, and certainly not protect the client against attacks from outside (including access to local services running on the client). This means that even though the firewall allows http access only to the internal web server, outsiders can access a local web server running on a client machine running an AOL client. Other malicious attacks (such as the various win nukes) are also possible. For more information please take a look at: http://www.securiteam.com/securityreviews/The_risks_of_using_an_AOL_client_behind_a_firewall.html -- ------------------------- Aviram Jenik "Addicted to Chaos" ------------------------- Today's quote: Nothing is more destructive of respect for the government and the law of the land than passing laws which cannot be enforced. - Albert Einstein, "Ideas and Opinions", 1954
Current thread:
- FTP.SODRE.NET Hacked... Eggdrop Modified.., (continued)
- FTP.SODRE.NET Hacked... Eggdrop Modified.. Geoffrey Huntley (Dec 19)
- Re: FTP.SODRE.NET Hacked... Eggdrop Modified.. Matt Hallacy (Dec 19)
- ip header id patched. awgn () COSMOS IT (Dec 19)
- ValueClick Ellen (Dec 19)
- FTP.SODRE.NET Hacked... Eggdrop Modified.. Geoffrey Huntley (Dec 19)
- Re: OSS nice tmp race Pavel Kankovsky (Dec 18)
- Re: OSS nice tmp race Dr. Mudge (Dec 18)
- Re: OSS nice tmp race Joel Eriksson (Dec 18)
- OSS nice tmp race the razor of love (Dec 18)
- Re: OSS nice tmp race Crispin Cowan (Dec 20)
- Re: OSS nice tmp race X-Force (Dec 21)
- AOL client uses IP tunneling Aviram Jenik (Dec 21)
- Re: your mail Craig A. Huegen (Dec 21)
- Re: your mail Alan Cox (Dec 22)