• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Tcp split handshake

Scheduled Pinned Locked Moved Firewalling
5 Posts 5 Posters 3.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jmack
    last edited by Apr 13, 2011, 12:09 PM

    Hi,

    How does Pfsense 2.0 RC1 perform?  (With standard Snort+ET enabled, 4Gb RAM)

    http://www.nsslabs.com/research/network-security/firewall-ngfw/remediation/network-firewall-remediation-brief-for-tcp-split-handshake.html
    http://news.techworld.com/security/3273840/firewall-software-open-to-tcp-handshake-hack-says-nss-labs/

    1 Reply Last reply Reply Quote 0
    • D
      dszp
      last edited by Apr 13, 2011, 2:00 PM Apr 13, 2011, 1:56 PM

      I was wondering this as well after reading the news. This seems to be one of the better descriptions of the actual mechanics of the TCP split handshake (and is free): http://nmap.org/misc/split-handshake.pdf

      Also it looks like nmap had a discussion last year about implementing split handshake detection which may be useful in testing: http://seclists.org/nmap-dev/2010/q2/723

      David Szpunar

      1 Reply Last reply Reply Quote 0
      • P
        pmb1010
        last edited by Apr 15, 2011, 8:05 PM

        This is sort of important, no?

        I'm not that knowledgable to comment, sure there has to be some bright folks here that know this answer…

        Is PFSense up to the task?

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Apr 18, 2011, 5:38 PM

          We've had a couple people look over that "announcement" and conclude there isn't enough detail to say anything for certain. Seems like something the OpenBSD folks would be all over if pf was vulnerable, and FreeBSD as well. Googling turns up a lack of relevant results. Lots of people discussing it but no authoritative answers. The best info was the older links already posted here. Has anyone actually tried the nmap split handshake scans against a pfSense firewall to see if it made any difference?

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • I
            itshuge
            last edited by Apr 19, 2011, 8:55 AM

            @jimp:

            Has anyone actually tried the nmap split handshake scans against a pfSense firewall to see if it made any difference?

            Without a tool I wouldn't have a clue how.  Wouldn't something this important get incorporated into tools like Metasploit?  Nothing shows up when searching there.
            http://www.metasploit.com/modules/

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received