[18451] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Hidden sniffer on unplumb'ed interface on Solaris

daemon@ATHENA.MIT.EDU (Darren Moffat)
Mon Jan 8 11:38:05 2001

MIME-Version: 1.0
Content-Type: TEXT/plain; charset=us-ascii
Content-MD5: qjEgoQUAk9Fp0UsDf8pXFA==
Message-ID:  <200101052039.f05KdZv169598@jurassic.eng.sun.com>
Date:         Fri, 5 Jan 2001 12:39:35 -0800
Reply-To: Darren Moffat <Darren.Moffat@eng.sun.com>
From: Darren Moffat <Darren.Moffat@eng.sun.com>
X-To:         robert@ROOTPROMPT.NET
To: BUGTRAQ@SECURITYFOCUS.COM

>(http://www.enteract.com/~robt/Docs/Howto/Sun/sniffer-trick.txt) by Rob
>Thomas, it was brought to my attention that a sniffer can be silently
>sitting on an unplumb'ed interface on Solaris. Not only is this dangerous

This is actually very similar to how the stealth mode of the SunScreen
firewall works it doesn't plumb up the interface so you can't directly
attack the firewall by attempting connections to an IP address (it acts
more like a bridge when working in this mode).

>for large networks, it is often hard to find. Has anyone ever contacted Sun
>about this potential problem...I'm fixing to try this on Solaris 8 to
>determine if the problem still exists.

It isn't a problem is is a deliberate feature and is due to the way that
the STREAMS framework and snoop work, this is NOT a bug.

--
Darren J Moffat

home help back first fref pref prev next nref lref last post