You'll get from... .-------------------------------------------------------------. | ___ | | / / øUr NµMBe®s | | ___/ /______ ___ ______ | | / / __/ \/ \/ \ [+32 TØø Fast ] | | / / / // / /\ / / / / \ ___ [+32 4 U ] | | \____/__/ \_____/___/_/__/___// / | | ______ ___ ____/_ /_ ______ ___ | | / \/ \/ ___/ \/__/ \/ \ | | / / / \ / / // / / / / / \ / /\ | | /__/__/___/___/___/__/__/__/__/___/____/BBS | | | | | |AMIGA - /X - IBM - CONSOLE - DirOpUS Ut!ls - GrAPh!cS - Mus!c| `-------------------------------------------------------------' Amiga... Amiga... Amiga... Amiga... Will Get !t Frøm Bigophone The : 21-Juin-9 Greeeeat Job Følks !!! + 3 2 - 1 6 - 2 3 . 5 9 . 6 2 No Fuzz, Just Call ! 3nds Ringdown loaded with AMIGA/ASCII/CONSOLE/PSX/MAC 4040 26mb 7.3gb cd-rom 2/33.6ds 1/28.8ds 3/TELNET * TRSI RECORDZ DKHQ * AFTERSHOCK HQ * HOODLUM DK HQ * * MOT!ON HQ * ROYAL HQ * TRADERS DREAM HQ * STYLE HQ * * LSD HQ * DATA DIVISION EHQ * POLKA BROS. WHQ * PUZZLE WHQ * * KEFRENS WHQ * SAVE OUR SOULS HQ * ARTWORK EHQ * OLDSKOOL HQ * * 5TH DYNASTY HQ * TWILIGHT * LOOKER HOUSE EHQ * ARSENIC HQ * * CRUX & BAD KARMA HQ * LIGHTFORCE HQ * ABUSE HQ * OMA HQ * THE PROTECTORS ARE: ZINKO^PLAYMATE^SISko^BILBO BAGGIn^NEIL/FLT^BLACK PANTHER/PSG UFOK/MsT^LsD^PsG^iHS^FURY/PSG/M!/SYS/HLM^KELDON^CHEWIE <0> +45 58ASK4IT <0> <0> +FIND ON IRC <0> @BEGIN_FILE_ID.DIZ============================================ ===== Risks of dial-up IP (slip/ppp) ===== === === = Firewalls and other "Personal" problems! = ============================================ Bryan Koch - Data Security Leader - Cray Rsc @END_FILE_ID.DIZ ____ /\ _________|_ /__________ //\\ __ __ _ _ \__ __/ \ - __/_ //\\· /_/\ __ _ _ /_____\|__|____\_______\ _/\_ /· \ \_\/____ _ _ _______________________________\__// \ ___ _____ ________________ _/ ____/ __ \_ ___/ ____/_ |_ | |_ |_ ___/_ __/ _\___` \ ` ____/ ` __)_ ` / / | / | /__` \/ \ \________/ |________/______/_____/ |______|____/_______/______\ |______| /ic! \ `--------------' ____________ /___________/\ _____ _______ ___________________________ ._____. \________ \ (_____) / \(_____), / __ \ |o ,| __ |o | \ \|o |/o |___/|o | ,o . /o _|/ \|! |/ \ |! | / \ \! | ! | \|! |\_/|! ||\_/ ! \_ \\: / \\ |: |/ /: | : | \ \: | |: || \ : | , / / |____ /| , _|\_____ , / , _| |_ || \____| /|____ / ======\ /=|___/========\ /|___/=======\ ,j==[WiZ]=l _/======\___/== : \ / ! | \/ |\/ ! \/ | | l |\/ : ! lEECHEd fROm ! :__ __ | | __/\__ | /\_ /\_ :____________________: _______ /\_\ /\_\ | ! \ / ! / Y \ / __ \________ \/ \/ / \ / \ ! : /_ o_\ : /o _| \/o _|/ \|o _|/ /o |___/ /o Y \ : . \/ `/ ! \_ \\! \_ \\! \_ // ! _)__/ ! \\'__/\__ : \ : | , /: | , /: |\ \ : | , \ : \ / , / \ o / . \____| /\____| /|____| \ \____. /\___/Y| / /_ _\ =====|___/======|___/=========\___/===|___/=======|__/== \/ : ThE PhReAkS ArE iN nO oRd: ThE /\/\iGHTY \/\/iZZY - Lo/\/eWolF - Fe/\/Er Node0: +39-6-3381692 Node1: +39-6-PRiVATE Node2: +39-6-ASK4iT! [USR VFC 33600 DUAL] [USR VFC 33600 DUAL] [Ftp 256kb & Telnet] tHiS fiLE wAS uPLOADED bY : Xabaras fROM : .oO eViL-DEATh Oo. pASSED hERE oN 06-18-1997, 18:01:11 aT nODE [00] From winternet.com!uunet!mr.net!mtn.org!timbuk.cray.com!walter.cray.com!btk Mon Feb 27 18:29:24 1995 Newsgroups: mn.general Path: winternet.com!uunet!mr.net!mtn.org!timbuk.cray.com!walter.cray.com!btk From: btk@cray.com (Bryan Koch) Subject: risks of dial-up IP (slip/ppp) Message-ID: <1995Feb27.093918.19044@walter.cray.com> Lines: 311 Nntp-Posting-Host: matrix.cray.com Organization: Cray Research, Inc. Distribution: mn Date: 27 Feb 95 09:39:18 CST In response to some of the flames here about the Channel 9 piece on the Internet, I offer the following from the Firewalls mailing list. It is too long for TV news, and doesn't lend itself to sound bites. My summary: -- there *are* risks when connecting personal computers to the Internet. -- these risks can be managed, through information, and through configuration control. -- my grandmothers, if either were alive, might want to be on Internet, but neither would take the time to learn to configure their systems in a secure way. Ditto for the majority of the 10-25 million people on internet today. More so for the next 25 million. Bryan Koch ================= start of firewalls article ============================ Date: Fri, 24 Feb 1995 10:20:54 -0500 To: firewalls@GreatCircle.COM From: cobb@bb.iu.net (Stephen Cobb) Subject: Firewalls and other "Personal" problems Several members of Firewalls provided input to the following, which I have put together for readers of my column in a UK computer magazine aimed at "personal" Internet users who dial in with PPP or SLIP access from standalone machines or smaller networks. The goal is to raise awareness among a group of users often neglected in corporate inter-networking discussions. Comments welcomed. Thanks to some recent high profile cases, firewalls are now a very hot item, so to speak, with companies such as IBM, Secure Computing, and Harris Computer Systems announcing products in the $20,000 plus range. Obviously these are aimed at corporate users, so what about you and me, the folks who connect to the Internet over the phone. Should we be concerned and should we buy a firewall? The answers are definitely yes and probably not. We definitely need to be concerned but we probably don't need to set up firewalls unless the PC we use to access the Internet is connected to a local area network or contains extremely valuable data. However, it is important to note that accessing the Internet using PPP or SLIP is not in itself a defence against hacking. While you are connected to the net you are running TCP/IP network protocols. These were designed to let you your machine see other machines, and for them to see yours. Of course, if you only have partial Internet access, for example using email through a bulletin board system, then you are hidden from the net. And even if you use PPP or SLIP but only log on to the net for short periods of time to send and receive mail you are only a brief blip on the digital landscape and hardly a promising target for hackers. But if you spend any serious time browsing the Web or exchanging files with ftp then you need to be aware of your exposure. Here is what Grahame Davies at Demon (a major UK provider) has to say: "Service providers will NOT allow PPP connections to act as routed network links. In other words, only packets addressed to your computer would be passed to it by the service provider." Furthermore he notes that "Without running servers there would be no process to connect to." In other words, if you are not running any network software, such as an ftp server, your computer will appear on the net, but not provide anything with which another computer can interact (an ftp server is the software that allows you to download files from another machine using an ftp client program). Another place to look for help with Internet security is the CompuServe forum run by the National Computer Security Association (GO NCSA). Answering a question about PPP exposure Doug Wyman confirmed that "only packets addressed to your computer would be passed to it by most service providers." Spoof Proof? There is more to the story than this, but before we go any further two caveats are in order. First of all, the statement that "only packets addressed to your computer would be passed to it" highlights the technology at the heart of the January CERT alert that was widely reported in the business press. CERT is the Computer Emergency Response Team, established in the wake of the Morris Internet worm incident back in November, 1988 (you can visit CERT on http://www.cert.edu). Whenever there is cause for concern, CERT issues security alerts to the Internet community. On January 23 of this year it warned about IP spoofing. That's IP as in Internet Protocol, as in TCP/IP, the network protocol that enables the Internet to function. IP demands that all computers on the net have a unique address. You might think of this as your Internet name, as in cobb@iu.net, but as Internet consultant Steve Kennedy explains, "IP relies on numbers not names." Kennedy notes that "when you connect to a service, say ftp, the ftp server will talk back to your address. The local service, say the ftp client, will locally convert any names specified to IP addresses. This is usually performed by the local host's file service or by DNS, the Domain Name Service." Some service providers allocate permanent IP addresses to all subscribers, others allocate them dynamically for each session, but in either case you have a specific IP address while you are using the Internet. IP spoofing involves a hacker reading your IP address from the packets of data you send out from your machine (for example, in email) then adding these addresses to his own data to make it look like they belong to you. The hacker then feeds those packets to your computer, thus bypassing the general rule that "only packets addressed to your computer would be passed to it". Ironically, the growing use of firewalls may be responsible for the sudden increase in IP spoofing. People have known about IP spoofing for years but it wasn't considered a problem since few hackers bothered to do it. At one time most Internet sites could be entered without the need for such subterfuge. But as more Internet sites, notably those operated by commercial organisations, introduced routers, specialised computers that control the flow of data packets based on their origin and destination addresses, it became harder to waltz right in. Fortunately, it is not too difficult to defend against IP spoofing. According to Karen Hutchison, Director of Secure Business for Harris Computer Systems, "a good firewall product, such as our Cyberguard, prevents IP spoofing by searching for discrepancies between IP addresses and the network from which the message originated. Any discrepancies indicate and block unauthorised access attempts." The Next Step But that is not the end of the story. Earlier it was noted that if you are not running any network software, such as an ftp server, your computer will appear on the net, but not provide anything with which another computer can interact. In order to verify this I posted a question to the firewalls discussion group host by Great Circle, a firm of Internet consultants. (You can join by sending a message to majordomo@greatcircle.com and placing "subscribe firewalls" in the body of the message -- but be warned, there are about 40 messages a day, so you might want to just get the edited version, using "subscribe firewalls-digest"). I am very grateful to all of those who answered my query about PPP connections. Paul Robertson warned that "Attacks normally depend on the capabilities of the target machine. Quite a few PC based TCP/IP packages include FTP servers. Some of them allow UNPROTECTED FTP by default. In this case, an attacker would have access to the entire hard drive (read/write), and any network drives as well." Even if the package you are using does not install ftp with the server capability turned on, it is very easy to turn it on by mistake (no warning messages appear - see screen). Make sure that you turn it off! Furthermore Roberston notes that "If I am logged on to our company's network, the hacker can then look around for TCP/IP packets to get logins, passwords, and so on." Over on the NCSA, Doug Wyman pointed out that for this type of PPP attack to succeed "the stack would have to be configured to make use of BOTH of the network links (the PPP and the network card) which would require a configuration of your network interface card software to support TCP/IP." If you have ever tried to get more than one network protocol working on a PC you know that it is hardly ever a case of plug-and-play. But there is one obvious situation that is cause for concern -- a network that is already running TCP/IP as the standard protocol. This was pointed out by a network expert at a large UK manufacturing company, who preferred to remain anonymous. Noting that "connecting to the Internet is simply a matter of plugging in a modem and turning on the SLIP feature, which is already built in," he suggests that some users are tempted to do this surreptitiously because "management has refused to provide Internet access." Unfortunately, few users or even manager realise that as soon as one node on a LAN running TCP/IP connects to the Internet, the whole LAN is open to attack. If you think this is alarmist, consider these remarks from Robert Bonomi: "It really depends on what your TCP/IP stack is doing, and what programs are running at the time. Since most PC stacks use Winsock, and it's fairly easy to write Winsock applications, as you can imagine, it's rather trivial to write an application that sits as a server, and hide it under windows, as an extension to the winsock.dll or something. PC virus scanners wouldn't pick this up, since it's not a virus." His comments emphasise the need to know exactly what you're getting when you install comms and networking software. But Bonomi is not all doom and gloom, rating such a sophisticated attack on a dialup PPP machine as unlikely. He says that "if the "personal" machine is NOT providing any services (that is, no server or daemon type tasks) but has only client-side software (telnet not telnetd, ftp not ftpd) then there is no possible "point of attack", and any sort of a firewall would just silly." He observes that "it is unlikely "personal" machines would have any reason to provide any such externally accessible services, EXCEPT POSSIBLY for a mail handler." But there is exposure here "only if mail is being automatically delivered to your machine. If you're using an "on-demand" mail-handler, like Eudora or similar POP-based program, you have no risk here...securing the system reduces to a matter of using "trusted" software for the mail-handler." Despite these reassurances, it is important for all Internet users, even us humble home users, to realise that talk of firewalls and Internet hacker attacks concern us. Consider this comment from Dr. Frederick B. Cohen: "PPP is really no different than any other connection to the Internet. Tell your readers that the Internet is a dangerous place, and by linking to it through PPP, they are placing all of the information on their computer at risk of disclosure and disruption." The bottomline is that you can enjoy the Internet without fear of loss if make sure that: o The server setting in ftp is turned off. o You use a reliable on-demand mail handler like Eudroa. o You connect to the net from a PC that is not networked or, if it is networked, a firewall is used. o All valuable programs and data on the PC you use are regularly backed up. o Any sensitive data files are encrypted (password protected encryption is an option in most word processing, spreadsheet, and database programs). I would like to acknowldege the folks at the Great Circle firewalls discussion group for listening patiently to my questions, in particular Douglas L. Urner, Joe Judge, Dennis Flagg, and Brian W. McKenney. Thanks also to Katherine Hutchison of Harris. You can find more information about firewalls in the Unix/Internet section of the NCSA forum on CompuServe or through these World Wide Web pages: http://www2.checkpoint.com:8000/firewall-1.html http://www.greatcircle.com/gca/tutorial/main.html http://www.cis.ohio-state.edu/hypertext/faq/usenet/firewalls-faq/faq.html Could it happen here? A few months ago, on a warm and sunny Monday morning, many Internet users in central Florida found that they could not dial into their local provider. To be precise, they could dial the number, but they couldn't log on. Some of these users are businesses who rely on the Internet for email and customer orders. A voice phone call to the provider's office revealed the cause of the problem. All of the user passwords had been changed. Was this a prank? A sophisticated hack? No, it was a deliberate action on the part of the provider, who was in the process of contacting each of the many hundreds of users to let them know their new passwords. Here is the announcement that customers received: "There have been reports all over the country about break-ins to computer systems on the Internet for the past several weeks. On Friday, the 3rd of February, it became clear that these had occurred on several local systems, specifically at a local college and at least one local high school. The reason these systems are important to us is that we have a number of users who also have accounts on those systems, and who telnet back and forth from those systems to ours. There was significant damage done at the college as a result of those break-ins. Files were destroyed, and several Unix systems have been taken off the network because they were compromised. Several machines were found to be running "sniffers," programs that spy on information going out onto the Internet. They can be used to capture login/password information when someone telnets from an affected machine to another computer. Then, the person reading the log can log in to the other computer, plant another "sniffer" and gain access to other systems, all by hi-jacking someone's account. Sniffers were also found at one high school and in light of this information, it became apparent that some of our customer passwords could have been available to the people who planted the sniffers. Other software found at those sites would allow such an individual to do severe damage to the system. Based on this, and the advisories issued by the Computer Emergency Response Team, the staff decided to take immediate action. It was impossible to notify you any sooner via mail, and email could not be used because accounts might not be secure. We spent Sunday installing a new operating system which has security patches to defend against the sniffer software and related programs, and we issued new passwords to re-secure any compromised accounts. One member of staff spent about 6 hours on the phone on Sunday and 12 hours on Monday trying to notify customers of the password change and help those that needed it. Several other staff members put in a great deal of time doing the same. Our security expert spent much of Saturday generating the new passwords and the letters that went out, and all of Sunday putting the new operating system on our server. We knew that this would involve a great deal of work on our part, and we did not undertake it lightly. The result was that the system was down for about 12 hours, and some of you didn't have access to your accounts for an additional day or two. We apologise for this, but note that the alternatives could have been much worse. No files were destroyed or damaged on our system, and we had minimal downtime. Allowing the situation to remain the way it was so that we could give you ample notification time could have resulted in loss of data from your accounts, major system damage, and a much longer recovery period. To sum up, we hope we never have to do anything like this again. You can help by protecting your account and your password as explained in the letter we sent. If you have an account on another machine that you use to telnet to our server, please make sure that account is secure. If you have questions about the security of that account, please speak to your system administrator." Our intention in passing on this account is not to scare or alarm, but to raise awareness of what can and is happening. To put it into information security or "infosec" jargon, the customers of this regional Internet provider suffered an "indirect denial of service". In other words, the effect of hacking activity in their area was to prevent them from using their accounts for a significant period of time. The prompt and very sensible action by the provider insured that security compromises were kept to a minimum and the customers, once they knew what was happening, were very appreciative of that action. Furthermore, we appreciate having the provider's permission to share the details of this incident, thus enabling us to learn from their experience. This is in marked contrast to the attitude of some larger companies, such as the American GE, which found its computers invaded from the net last November, but which has refused to discuss the details, even though much could be learned that would benefit the rest of the Internet community. New bio: Stephen Cobb can be reached on CompuServe as 72662,546 or the net as cobb@iu.net. He is currently at work on a new edition of his Guide to PC & Lan Security. ================= end of firewalls article ============================ -- Bryan Koch Data Security Leader VOICE: +1-612-683-3129 (1-800-284-2729 x33129) Cray Research, Inc. FAX: +1-612-683-3126 (clear, or JFX encryption) Eagan, Minnesota, USA EMAIL: btk@cray.com - - - - -= -== -========[ fILE pROCESSED bY FIDEnhance v3.3 bY fLI7e/sAD ]=- @BEGIN_FILE_ID.DIZ . this file has been frozen inside . : ____ _|_ __ : : \/ \ / \/, : : ______ ______ ______ ____ _____ ______ ______ ______: __) _ (____) __ (____) _ (__) (__ __) /_____) ___( __) _ (__) _ (__ / / _ ( _ __ __/_/ _ / _ __(__/ __ / / \___/ /\____ /\___/ \____ ( \___/ /\____ _____/ \___/ / : )___/gdm-)____/ /____/ )______/ /____/ )____/lkr/____/ )___/: : _ _ : : - - -)_)- P · A · L · A · C · E -(_(- - - : : : `----------------.- t.h.e.n.o.r.t.h.e.r.n.p.a.l.a.c.e -.-----------------' _::_ 3nds ringdown loaded with amiga/ascii/console/psx/mac _::_ \/ 4040 26mb 7.3gb cd-rom 2/33.6ds 1/28.8ds 3/telnet \/ motion · royal · traders dream · trsi recordz · aftershock · hoodlum hq style · looker house · lsd · data division ehq · polka bros · puzzle whq oma · sos · abuse hq · crux & bad karma hq · oldskool hq · arsenic hq 5th dynasty · lightforce hq · artwork ehq · twilight · kefrens whq . - - board dedushka-morozes - - . : : zinko · playmate · sisko · bilbo baggins/m! · neil/flt · keldon^chewie ufok/mst^lsd^cbk^ryl · fury/psg/m! · black panther/psg : : . -^- - -santa +45-58aSKyARSELF- - -^- . . .  FIRST DIVISION   DC SHQ - RYL SHQ   ++46.303.NOT.4U!   ++46.303.NOT.4U!   ++46.303.TEL.NET   ++46.303.TEL.NET  + 3 2 - 1 6 - 2 3 . 5 9 . 6 2 No Fuzz, Just Call ! -=- A4000/040 -=- 2.2 GiGs + CD ROM onLinE -=- =-= RuNNiNg F.A.M.E. =-= AmiGa - PC - Mac - BBS Doors =-= SySoPs : ThE FlY/PGS/PTL * YoDa/SCX/PTL * FlaShEr * TFX/PTL NoDe1: +32-5235-1575 <- USR V.Everything -> NoDe2: +32-RING-DOWN tELNET : secretcinema.dyn.ml.org ___ ___ / / / / ___/ /______ ___ ______ ______ ___ ____/_ /_ ______ ___ / / __/ \/ \/ \ / \/ \/ ___/ \/__/ \/ \ / / / // / /\ / / / / \ / / / \ / / // / / / / / \ / /\ \____/__/ \_____/___/_/__/___/ /__/__/___/___/___/__/__/__/__/___/____/ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::-:$anta:-: ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :::::: :::::: :::::: AMIGA - /X - IBM - CONSOLE - DirOpUS Ut!ls - GrAPh!cS :::::: :::::: :::::: :::::: RuNN!ng øN /X 4.x - A3000 - 2250 Mb :::::: :::::: :::::: ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø.ø*¤^°"°^¤*ø Thanks to Bigophone for Upløading this fresh stuff The : 21-Juin-9