
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 192
DNSserverthroughthefirewall.Iftheresultispositive,wecanstructureanattack
basedonport53relatedvulnerabilities.
OnepossibleattackoptionistouseTrojanhorse.AccordingtoDOShelp,TCPport53
isapopulartargetofTrojanhorseattack
63
. A toolthatcan beusedforthisattackis
BackOrifice.
BackOrificeis,inessence,aremoteadministrationtool.AccordingtoPCHelp:
“Itgives"systemadmin"typeprivilegestoaremoteuserbywayofthecomputer's
Internetlink.Whatdoesthismean?ItmeansthatifBackOrificeisrunninginyour
computer,aremoteoperatoranywhereontheglobalInternetcangainaccessanddo
almostanythingyoucandoonyourcomputerandsomethingsyoucan'tdoall
withoutanyoutwardindicationofhispresence.
BackOrificecanarrivedisguisedasacomponentofpracticallyany software
installation.Itcan beattachedtootherfilesorprogramsorrunonitsown. Itmustbe
run,byitselforbyanotherapplication.Ittheninstallsitselfinseconds,typically
erase s theoriginal,thenmayrunaspecifiedprogram.To theuserinstallingan
"infected"application,itwillappearthatallwentnormally.Butfromthatmoment
forward,yoursystemofferseasyandcomprehensiveaccessanytimeitisconnectedto
theInternet.”
64
With thistool,wecangaincontrolofthetargetedFW1installation.ForGIACto
workagainstthisrisk,coupleof thingscanbedone:
n Disablethedefaultport53option.
n SetuparulethatallowzonetransferonlybetweentheoffsiteDNSserverand
theonsiteone.Blockallotherzonetransferrequests.
n InstallBODetect
65
(aproductspecifically designedfordetectingBackOrifice
attacks) onthefirewall.
63
http://www.doshelp.com/trojanports.htm
64
http://www.nwinternet.com/~pchelp/bo/bo.html
65
http://www.cbsoftsolutions.com/Products/products.htm
Comentarios a estos manuales