nCircle.com >> 360 Security

« How to Disable ICS | Main | SCADAGard SIG To Be Established »

Internet Connection Sharing Vulnerability Test Results

Here at nCircle most of my day has been spent fielding questions about this Internet Connection Sharing vuln. There seems to be a misunderstanding regarding the question: "Is the only way to mitigate this vulnerability by turning off the Windows service 'Windows Firewall/Internet Connection Sharing (ICS)'?"

I wanted to share the below chart that Tyler provided to me. These are the results of his testing this vulnerability in our own lab over the weekend.

* Internet Connection Sharing Disabled/Enabled means the box is checked or not checked
* Windows Firewall Enabled/Disabled means it's set to On or Off
* Service State is the (Windows Firewall/Internet Connection Sharing Service)
* Interface describes which side of the network the attack originated from (LAN being the "inside" and WAN representing the "Internet Connection" side)

Internet Connection SharingWindows FirewallService StateInterfaceCrash
EnabledDisabledEnabledLANYes
EnabledEnabledEnabledLANYes
DisabledDisabledEnabledLANNo
EnabledDisabledEnabledWANNo
EnabledEnabledEnabledWANNo
DisabledDisabledEnabledWANNo













About

This page contains a single entry from the blog posted on October 31, 2006 2:24 PM.

The previous post in this blog was How to Disable ICS.

The next post in this blog is SCADAGard SIG To Be Established.

Many more can be found on the main index page or by looking through the archives.