This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+34 -34
View File
@@ -2,7 +2,7 @@
- A hardware and/or software system
- Prevents unauthorised access of packets from one network to another
- All data leave any subnet must pass through it
- All data leaving any subnet must pass through it
![1647287782.png](img/1647287782.png)
@@ -22,7 +22,7 @@
#### DMZ
- A demilitarised zone is a small subnet that separates exrternally facing services from the internal network
- A demilitarised zone is a small subnet that separates externally facing services from the internal network
![1647288286.png](img/1647288286.png)
@@ -33,45 +33,45 @@
- Defends a network against parties accessing *internal services*
- Can also restrict access from *inside to outside* services
- Network Address Translation
- Hides the internal machines with private addresses
- Hides the internal machines with private addresses
**Firewalls are not enough**
- Cannot protect against attacks that bypass the firewall
- e.g. tunneling
- e.g. tunnelling
- Cannot protect against internal threats or insiders
- Might help a bit by egress filtering
- Might help a bit by egress filtering
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
#### Packet Filters
- Specify which packets are *allowed or dropped*
- Rules based on:
- Source / destination IP
- TCP / UDP port numbers
- Source / destination IP
- TCP / UDP port numbers
- Possible for both *inbound* and *outbound* traffic
- Can be implemented in a router by only examining packet headers (**IP / TCP**)
##### Packet Filter Rules
- Rule execution depends on implementation
- `IPTABLES`: **First** rule to match is applied
- `PF`: All rules are examined, **last** match is applied
- `IPTABLES`: **First** rule to match is applied
- `PF`: All rules are examined, **last** match is applied
- Rules are organised in *chains*, which are logical subgroups of rules
- Depending on the packet, different chains are activated
###### IPTABLES
- An application that provides access to the Linux firewall rule tables
- Not actually a firewall, but configures the firewall
- The firewall is mostly implemented as `netfilter` modules
- Not actually a firewall, but configures the firewall
- The firewall is mostly implemented as `netfilter` modules
###### Tables and Chains
- `IPTABLES` uses tables to store chains
- Default is the filtering table
- Default is the filtering table
- Chains are ordered in lists of rules
- Rules match, or they don’t
- Rules match, or they don’t
- Matches result in a **jump**, else we check the next rule.
![1647289401.png](img/1647289401.png)
@@ -79,7 +79,7 @@
Default policy on this chain is `DROP`
- There can be multiple chains per table
- e.g. a `TCP` handling chain
- e.g. a `TCP` handling chain
- Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain
- Complex behaviour can be built up
@@ -88,10 +88,10 @@ Default policy on this chain is `DROP`
##### Defaults
- There are four built-in tables in `IPTABLES`
- Filter
- `NAT`
- Mangle - packet alteration
- Raw - skips connection tracking
- Filter
- `NAT`
- Mangle - packet alteration
- Raw - skips connection tracking
- The default table is the filtering table, including input, output and forward chains
![1647289692.png](img/1647289692.png)
@@ -105,14 +105,14 @@ $ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
```
- Remember `http` requests are not sent from the client’s port 80, it is sent from a random high numbered port
- This is how clients can have multiple web requests open at the same time
- Remember `http` requests are not sent from the client’s port 80; they are sent from a random high-numbered port
- This is how clients can have multiple web requests open at the same time
##### Policies
- **Permissive** - allow everything by default except dangerous services
- Make a black list
- Easy to make a mistake or forget something
- Make a black list
- Easy to make a mistake or forget something
```bash
iptables -p INPUT ACCEPT
@@ -124,8 +124,8 @@ iptables -A OUTPUT -p tcp --dport ssh -j DROP
```
- **Restrictive** - block everything except designated useful services
- Make a white list
- More secure by default
- Make a white list
- More secure by default
```bash
iptables -p INPUT DROP
@@ -139,17 +139,17 @@ iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
#### Packet Filter Issues
- Packet filters are simple, low-level and have high assurance
- However they cannot:
- Prevent attacks that employ application specific vulnerabilities
- Do not support higher-level authentication schemes
- Easy to accidentally allow or deny packets incorrectly
- However:
- They cannot prevent attacks that employ application-specific vulnerabilities
- Do not support higher-level authentication schemes
- Easy to accidentally allow or deny packets incorrectly
### Stateful Packet Filters
- Understand requests and replies (`ACK/SYN`)
- Dynamically generate rules
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
- Can support policies for a wider range or protocols
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
- Can support policies for a wider range of protocols
- `IPTABLES` has a module for stateful packet filtering
- Allow incoming / outgoing SSH connections
@@ -166,7 +166,7 @@ iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
- Packet filters have limited criteria that allow data in and out
- An application gateway considers the *application-layer* protocol that is in use
- For example if someone sends an `HTTP` request to port 22, it is blocked
- For example if someone sends an `HTTP` request to port 22, it is blocked
##### Proxy Server
@@ -184,11 +184,11 @@ iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
### Network Address Translation
The shortage of IP addresses mean that most routers now perform NAT automatically
The shortage of IP addresses means that most routers now perform NAT automatically
![1647290897.png](img/1647290897.png)
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
- Only **established connections** are forwarded to your internal machine
- Or, specific **port forwarding** rules
- This prevents any unsolicited attacks on random ports, but no other types of attack
- Or, specific **port forwarding** rules
- This prevents any unsolicited attacks on random ports, but no other types of attack