Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
Administrative
»
Feedback
»
It's always nice reading these things about your favourite firewall
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: It's always nice reading these things about your favourite firewall (Read 3201 times)
0 Members and 1 Guest are viewing this topic.
Ozzik
Full Member
Offline
Posts: 102
It's always nice reading these things about your favourite firewall
«
on:
July 30, 2010, 05:00:49 am »
Quote
Heffner also called on router vendors to build in DNS Rebinding mitigations into their routers directly.
"The only router software that I know of that does this now is pfsense," Heffner said. "They contacted me when my Black Hat talk abstract went up."
http://www.esecurityplanet.com/features/article.php/3895851/Millions-of-Home-Routers-at-Risk.htm
Logged
mhab12
Hero Member
Offline
Posts: 627
Re: It's always nice reading these things about your favourite firewall
«
Reply #1 on:
July 30, 2010, 11:39:54 am »
Agreed - the interaction between the devs and community here are about as good as it gets. Thanks for all that you do.
Logged
HiTekRedNek
Jr. Member
Offline
Posts: 40
Re: It's always nice reading these things about your favourite firewall
«
Reply #2 on:
August 03, 2010, 12:13:12 pm »
And just how does PFSense mitigate against this type of attack compared to competitors?
Logged
David Szpunar
Full Member
Offline
Posts: 165
Re: It's always nice reading these things about your favourite firewall
«
Reply #3 on:
August 03, 2010, 01:14:54 pm »
Well, the main way is by not allowing webGUI access using a hostname other than the one assigned to pfSense in version 2.0. There is an exception list for other hostnames used if needed, or IP address can be used without restriction, as that is not a security risk with DNS Rebinding attacks. These protections are on by default in 2.0 beta currently, even when upgrading from 1.x. It's always recommended to change the default administration password for the webGUI as well, and if you do this and are not logged into the webGUI (or are not logged into the same web browser used for other tasks), even attempts at DNS Rebinding attacks are unlikely to succeed because they would need to rely on a flaw in the LAN administration code to authenticate/change the firewall (this is the case even in 1.x). So the main recommendations beyond the build-in protections are: 1) use a different web browser for administration than for web browsing, and 2) change the default password to something secure (do this anyway!).
At least that's what I'm familiar with. I'm sure someone else may have information about additional precautions taken.
Logged
David Szpunar
I use pfSense wherever I can, and I break the rule about not using 2.0 beta in production, because it's so cool :-)
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...