Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tcp split handshake

    Firewalling
    5
    5
    3.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jmack
      last edited by

      Hi,

      How does Pfsense 2.0 RC1 perform?  (With standard Snort+ET enabled, 4Gb RAM)

      http://www.nsslabs.com/research/network-security/firewall-ngfw/remediation/network-firewall-remediation-brief-for-tcp-split-handshake.html
      http://news.techworld.com/security/3273840/firewall-software-open-to-tcp-handshake-hack-says-nss-labs/

      1 Reply Last reply Reply Quote 0
      • D
        dszp
        last edited by

        I was wondering this as well after reading the news. This seems to be one of the better descriptions of the actual mechanics of the TCP split handshake (and is free): http://nmap.org/misc/split-handshake.pdf

        Also it looks like nmap had a discussion last year about implementing split handshake detection which may be useful in testing: http://seclists.org/nmap-dev/2010/q2/723

        David Szpunar

        1 Reply Last reply Reply Quote 0
        • P
          pmb1010
          last edited by

          This is sort of important, no?

          I'm not that knowledgable to comment, sure there has to be some bright folks here that know this answer…

          Is PFSense up to the task?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            We've had a couple people look over that "announcement" and conclude there isn't enough detail to say anything for certain. Seems like something the OpenBSD folks would be all over if pf was vulnerable, and FreeBSD as well. Googling turns up a lack of relevant results. Lots of people discussing it but no authoritative answers. The best info was the older links already posted here. Has anyone actually tried the nmap split handshake scans against a pfSense firewall to see if it made any difference?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • I
              itshuge
              last edited by

              @jimp:

              Has anyone actually tried the nmap split handshake scans against a pfSense firewall to see if it made any difference?

              Without a tool I wouldn't have a clue how.  Wouldn't something this important get incorporated into tools like Metasploit?  Nothing shows up when searching there.
              http://www.metasploit.com/modules/

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.