3 ms·
I'm not a so called security expert nor I'm in the security business anymore, so please take this with a pinch of salt. Isn't rate limiting a thing anymore? Es
by NetStrikeForce 10y ago
I'm not a so called security expert nor I'm in the security business anymore, so please take this with a pinch of salt.
Isn't rate limiting a thing anymore? Especially for packets that should not be coming at this rate. 40k-50k pps? Who gets that amount of ICMP type 3 code 4 as a baseline to consider it normal? Also, many networks out there "deprioritize" ICMP packets.
I see how (mainly) Cisco seems to have screwed up on their ASAs, but in all honesty they've never been the paradigm of firewall security. Before the -X line, which is when I was a very active user of ASAs, the interface buffers of almost any ASA up to the 5580 were insufficient for some kinds of traffic that generated high pps with not so huge bandwidth.
Actually, now that I think about it, I wonder if this "Black Nurse" is partly the result of the ASA's insufficient buffers and not just an actual firmware issue.
All in all, this feels very amateurish to me and I'm surprised people are buying into it - I guess doom and gloom sells pageviews. I mean, if their conclusion is the below, I don't see how this is making so much noise:
"We believe,that what we see when our customers get hit by the BlackNurse attack is that the firewall admins have just followed recommendations or misconfigured firewalls. Mitigation on firewalls could be to change default config or to patch any code that can lead to a DoS state."
(from http://www.blacknurse.dk/Blacknurse_v.1.7.pdf http://www.blacknurse.dk/Blacknurse_v.1.7.pdf)