Stories
Slash Boxes
Comments

News for nerds, stuff that matters

SmoothWall Firewall Review

Posted by michael on Wed Jan 09, 2002 06:18 PM
from the security-in-a-box dept.
ray-x sent in a pointer to a review by c't of the Smoothwall firewall product. c't's reviewer described several flaws in the firewall. We asked Smoothwall for their comments on the review, which are posted below.

Daniel Goscomb, one of the lead developers of Smoothwall, responds:

In our opinion this article is extremely badly researched and written. Furthermore it shows a lack of knowledge on the author's part.

The main concern he has is that of people being able to log in to the firewall and read configuration files. This point is irrelevant as there is only a single user that can access the shell, root. This also removes the need of shadow password files, if you have access to the machine to get the passwd file, you are already in as root anyhow.

Secondly he complains of plain text passwords for the ppp passwords. This is not our doing. The passwords are stored in this format as pppd requires them to be in plain text in the two files. He also mentions that the permissions of these files are wrong. If he looked a little more closely he would have seen that they are in fact symlinks to the 2 real files, which do have the proper permissions on them.

He also mentions the same "problem" with the shared keys system in FreeSWAN. Again, they are stored like this as FreeSWAN requires them in this format to read them.

As to the part about user authentification of the CGI scripts. This is completely irrelevant. There is no authentication in the CGI scripts. The authentication is done via .htaccess files, and has no interaction with the CGI at all, other than when you change the passwords.

I also find it disturbing that the author gave us no room for comment in his article, nor did i see anything to suggest he had even asked us about these so called "problems". We would have been happy to answer any questions he had.

Sincerely,

Daniel Goscomb.

This discussion has been archived. No new comments can be posted.
SmoothWall Firewall Review | Log In/Create an Account | Top | 495 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • Lack of Testing by Renraku (Score:1) Wednesday January 09 2002, @06:22PM
  • Smoothwall is Great! (Score:5, Interesting)

    by beezly (197427) <beezlyNO@SPAMbeezly.org.uk> on Wednesday January 09 2002, @06:28PM (#2813364) Homepage
    I've been using Smoothwall for a while now. I'm extremely satisified with it. I've hand crafted firewalls in the past and I decided to give it a try to ease the burden and it has more than filled the shoes of the things I manually configured before.


    It's secure, featurefull and easy to configure - what more could you want?

    • Re:Smoothwall is Great! (Score:4, Interesting)

      by DaveJay (133437) on Wednesday January 09 2002, @06:38PM (#2813441)
      I, too, found it extremely easy to configure. I have been using it, and appreciate the availability of it.

      Ultimately, though, this is a very interesting notation by Daniel:

      >"...nor did i see anything to suggest he had even asked us about these so called "problems"."

      In the review, the reviewer actually states:

      >"My concrete indications of security problems within SmoothWall found sheer disinterest with Richard Morrell, developer and project initiator. "That doesn't matter" was about the politest of all comments comment (sic)."

      The reviewer apparently did attempt to have a dialogue with one of the developers, and was rebuffed (apparently impolitely.) I have had a similar experience with at least one SmoothWall developer behaving somewhat less than tactfully.

      If the reviewer is wrong about the security issues, the development team may feel justified in treating him thusly -- At the same time, I sincerely hope that the development team keeps a reasonably open ear in case a legitimate bug is discovered.
      [ Parent ]
    • Re:Smoothwall is Great! by **SkipKent** (Score:2) Thursday January 10 2002, @12:51AM
    • Yep - he's right by ctimes2 (Score:1) Thursday January 10 2002, @09:21AM
    • Re:Smoothwall is Great! by bobdole34 (Score:1) Thursday January 10 2002, @11:42AM
    • Re:Smoothwall is Great! by beezly (Score:2) Wednesday January 09 2002, @06:41PM
      • 1 reply beneath your current threshold.
    • Re:Smoothwall is GREAT by A.MacGyver (Score:1) Wednesday January 09 2002, @07:01PM
    • Re:Smoothwall is Great! by cmkrnl (Score:1) Thursday January 10 2002, @12:08PM
    • 2 replies beneath your current threshold.
  • sharethenet (Score:4, Offtopic)

    by graveyhead (210996) <fletch@nosPAM.users.sourceforge.net> on Wednesday January 09 2002, @06:29PM (#2813372)
    For an affordable, very easy to configure, and speedy (excellent performance on my 386/33 with 8mb ram) firewall/gateway, you just can't beat sharethenet [sharethenet.com]. I had it up and running in 1/2 hour, and there is almost no performance difference when I have my cable modem hooked up directly to my speedy p3 desktop. It "embeds" linux by loading it from a floppy onto a ram disk. If you get hacked, simply restart your machine, and you are back to factory settings. Downside is you need dedicated hardware, but OTOH, that hardware can be very old and still perform.
  • Typical Developer Reaction by tthomas48 (Score:1) Wednesday January 09 2002, @06:29PM
    • 1 reply beneath your current threshold.
  • Response (Score:4, Informative)

    by wpanderson (67273) on Wednesday January 09 2002, @06:29PM (#2813374)
    we have an article taking what dang has said along with our comments on the way the article author behaved when collecting his "evidence" ...

    our response [smoothwall.org]
    • Re:Response by Anonymous Coward (Score:2) Wednesday January 09 2002, @07:06PM
    • Hmm... by Chazmati (Score:1) Wednesday January 09 2002, @09:05PM
      • 1 reply beneath your current threshold.
    • 1 reply beneath your current threshold.
  • this really surprises me... (Score:3, Insightful)

    by snake_dad (311844) on Wednesday January 09 2002, @06:30PM (#2813376) Homepage Journal
    as c't is (imho ofcourse) a much respected magazine, and normally I would call it a trustworthy source. I would certainly not expect them to publish such a damaging article without giving the authors of Smoothwall a chance to comment on the findings.
  • Smoothwall & GPL (Score:5, Insightful)

    by johnburton (21870) <johnb@jbmail.com> on Wednesday January 09 2002, @06:30PM (#2813380) Homepage
    I used smoothwall for a short time to evaluate it and technically it looked like quite a nice product, but then I started reading about the attitude of it's creator to the GPL.

    Now I'm happy for people to write GPL software if they like, and I'm happy for people to write commecial software if they like, but smoothwall seems to want to get the benifits of both.

    They seem to want to get make free use of other peoples work through the GPL, but to feel free to only release parts of their software commercialy. I'm not claiming they are breaking the GPL or anything, but there seems something very unfair about their approach.

    Also if you get the GPL edition, there are all kinds of requests on the web site that you donate money to them "SmoothWall developers have kids and families too, and it's all about giving back to the people who helped you.
    ". And yet I would guess that about 90% of what they are giving out was written by other people and they don't suggest they are going to give 90% of their donations to them.

    Again, nothing wrong with that, I just don't much like it.

    Basically I suggest that people look at their web site, and search the internet for comments about the creators of this software and how unhappy some people are with them before they go and use it.
    • Re:Smoothwall & GPL by ReD-MaN (Score:1) Wednesday January 09 2002, @06:35PM
    • Re:Smoothwall & GPL (Score:5, Interesting)

      by Anonymous Coward on Wednesday January 09 2002, @07:14PM (#2813683)
      I have also evaluated smoothwall, and while reading up about it noticed the "attitude" to the GPL so looked carefully at the licensing for all parts of the distro as they are very pushy about their rights to do what they like with code they have written (which I fully support).

      However the version I looked at (0.9.9) includes a java ssh terminal (MindTerm [appgate.org]) that is a commerial product that is "Free for non commerial personal use and may be included with other products so long as the different license is drawn attention to" to paraphrase this [appgate.org] license agreement. I saw no sign of this.

      I am posting this anonymously and I haven't rasied this elsewhere as the attitude of the developers to these sorts of questions is well known and I don't really have the time for that.

      How this applies to their commerial support offerings I'm not sure either.
      [ Parent ]
    • Re:Smoothwall & GPL by rossz (Score:3) Wednesday January 09 2002, @08:25PM
    • Re:Smoothwall & GPL by Anonymous Coward (Score:2) Thursday January 10 2002, @07:36AM
    • Re: Unfair? How so? by King_TJ (Score:3) Thursday January 10 2002, @11:22AM
    • 1 reply beneath your current threshold.
  • Old debate...? (Score:5, Insightful)

    by mwalker (66677) on Wednesday January 09 2002, @06:35PM (#2813406) Homepage
    This debate seems to be over whether Smoothwall was designed to secure against attack from outside your DSL dialup or against attack from the inside. Shadow passwords are meant to provide a safeguard against dictionary attacks from logged-in users on a multiuser system. c't's complaint that there is no shadow password on a single-user system is valid; if you're worried about people in your own house trying to hack into your firewall.

    It is true that internal security against logged in users can help defeat attackers who can only partially penetrate external defenses. If, for instance, you can only use a CGI bug to get ahold of the passwd file, you can leverage this with a dictionary attack if shadowing isn't installed. Provided you can disable the packet filter and attempt to login as root externally once you have the password... or even use an su type exploit from your original CGI bug. Either way, there are a lot of large corporations with bigger security holes than this.

    However to claim that his review "shattered the illusion" of Smoothwall being a complete solution for home users is complete hyperbole. A home user who is trying to secure himself from internal attack from other logged in users in his house is probably pretty savvy in the first place and also has bigger problems. If the purpose of this product is have a CD you can ship to your parents to secure their DSL line against script Kiddiez and Hotmail's Traceroute function, then Smoothwall sounds to me like an outstanding effort.

    c't': Two demerits.
    • Re:Old debate...? by sirsnork (Score:1) Wednesday January 09 2002, @06:48PM
      • 1 reply beneath your current threshold.
    • Re:Old debate...? (Score:4, Informative)

      by strags (209606) on Wednesday January 09 2002, @06:49PM (#2813509)
      This debate seems to be over whether Smoothwall was designed to secure against attack from outside your DSL dialup or against attack from the inside. Shadow passwords are meant to provide a safeguard against dictionary attacks from logged-in users on a multiuser system. c't's complaint that there is no shadow password on a single-user system is valid; if you're worried about people in your own house trying to hack into your firewall.

      From what I understand, even a user in your own house wouldn't be able to get at the password file, since only the root account (which one would assume is password protected) has access to a shell. This isn't a multiuser system that people log into.

      (This is my understanding from what I've read - I've never used SmoothWall - please correct me if I'm mistaken).
      [ Parent ]
    • Re:Old debate...? by jonestor (Score:1) Wednesday January 09 2002, @06:53PM
    • Re:Old debate...? (Score:4, Insightful)

      by RC514 (546181) on Wednesday January 09 2002, @06:53PM (#2813537) Homepage

      A false sense of security is worse than no security.

      Even if no users other than root should ever be able to log in to the firewall, there is a reason to carefully set file permissions: Just like on a server, the services running should do so under their private username. That is to prevent a security related bug (aka vulnerability) from compromising the whole system. This is obviously less important on a router/firewall where services are only provided to the inside, but the attitude shown by the authors of Smoothwall certainly destroys my confidence in their general ability to provide a secure system.

      Then there is the false discrimination between inside and outside: Especially when you deal with "non-techie" users you have to expect their systems to become infected by the latest worms and viruses. This opens the possibility of attacks from the inside which really are attacks from the outside. Granted, that is a remote possibility and if it happens, you have bigger problems than firewall file permissions, but it is still not understandable how an easy to fix thing like this is completely ignored. The german review makes it quite clear that the attitude of the firewall authors played a big part in the thumbs-down.

      [ Parent ]
    • 3 replies beneath your current threshold.
  • by zzzeek (43830) on Wednesday January 09 2002, @06:36PM (#2813412)
    He says shadow files are irrelvant as the box has only one account, root. Whatever happened to rule # 1 of having your web server and CGI's run as a different user ?
  • Journalistic integrity? (Score:5, Interesting)

    by chrysrobyn (106763) on Wednesday January 09 2002, @06:37PM (#2813427)
    I hope it is on-subject enough to point out that I believe this is an excellent job Slashdot has done, going out and getting the rebuttal for the review. Although it is not quite perfect -- it acts partially to discredit the link source -- it is much closer to what I think Slashdot could be, a first-run news source with original articles -- for [nerds|geeks]. Until then, while the editors post their comments after a link, it's little more than the second-run movie theatres (which have their place, don't get me wrong). Thanks, Slashdot.
  • No room for comments? by I_am_Rambi (Score:1) Wednesday January 09 2002, @06:37PM
  • Reveiwers have to listen... (Score:4, Insightful)

    by hellcore (549684) on Wednesday January 09 2002, @06:39PM (#2813446) Homepage
    I was in the Smoothwall IRC channel on several occasions when this reporter came in. First of all he didn't conduct himself like any other reporter I have ever met. He was elusive regarding his motives (ie he wouldn't say he was from the press), he was beligerent beyond belief and gave the impression he already knew what he was going to write. Refusing to even listen to the dev team's answers, the sticking the fingers in the ears behaviour he exhibited was most flattering. I just hope c't are more exclusive in future with regards to the staff they employ. This guy was nothing but underhanded and stubborn.
  • Poorly writen reviews are bad for everyone. by dperkins (Score:1) Wednesday January 09 2002, @06:41PM
  • Another firewall distro... by hereward_Cooper (Score:1) Wednesday January 09 2002, @06:41PM
  • Excuses (Score:4, Insightful)

    by Antity (214405) on Wednesday January 09 2002, @06:44PM (#2813474) Homepage

    Secondly he complains of plain text passwords for the ppp passwords. This is not our doing. The passwords are stored in this format as pppd requires them to be in plain text in the two files. He also mentions that the permissions of these files are wrong. If he looked a little more closely he would have seen that they are in fact symlinks to the 2 real files, which do have the proper permissions on them."

    Tsstss.. Look at this excerpt from the article that this SmoothWall guy is complaining about:

    The PPP-Daemon complains in the log file, every start, about the permissive reading rights to its password file, hard to imagine that the developers missed this one.

    I also have a strange feeling about other "security" options that they choose. For example: Not using shadowed password files. They say it wouldn't be neccessary since the only user available is root anyway. But what is the _sense_ of not using shadowed password files? (And what is the sense to require the user to be root to configure the system? Even Apache is supposed to be quite secure, but nobody will run it as root because there still might be holes. Impossible in a hacked-together firewall distribution?) The bytes in length on the harddisk they would have saved would be a joke.

    All in all, I believe there are some truth- and insightful bits in the c't review, even if the reviewer did a mistake.

    btw: To complain that the passwords had to be plaintext because PPPd and FreeSWAN required it is complete nonsense for a Firewall! Sources are available, so why not add a patch to have the passwords encrypted if this is supposed to become a Firewall?

    (Sorry, had to emphasize this, since this is not some desktop distribution but supposed to be a Firewall.)

    • Re:Excuses by Russ Steffen (Score:2) Wednesday January 09 2002, @07:12PM
      • Re:Excuses by WolfWithoutAClause (Score:2) Wednesday January 09 2002, @09:22PM
      • 1 reply beneath your current threshold.
    • Re:Excuses by parc (Score:1) Wednesday January 09 2002, @07:15PM
      • Re:Excuses by fishebulb (Score:1) Wednesday January 09 2002, @09:38PM
        • Re:Excuses by psamuels (Score:2) Thursday January 10 2002, @02:32AM
          • Re:Excuses by TuxGrep (Score:1) Thursday January 10 2002, @07:26PM
          • Re:Excuses by psamuels (Score:1) Thursday January 10 2002, @04:41AM
          • 1 reply beneath your current threshold.
      • 1 reply beneath your current threshold.
    • Re:Excuses (Score:5, Insightful)

      by hearingaid (216439) <redvision@geocities.com> on Wednesday January 09 2002, @08:56PM (#2814180) Homepage
      I also have a strange feeling about other "security" options that they choose. For example: Not using shadowed password files. They say it wouldn't be neccessary since the only user available is root anyway.

      Let's go even farther on this theme of bad choices.

      You can logon directly to the root account remotely? You don't have to su first?

      Ouch, but that's a major hole. That's like waving a Big Flag. Kiddies, look at this "firewall." Guess what account you should try?

      Never allow remote logons to uid 0. Always at least force wheels to su.

      There are CGIs available to manage the firewall? Oh, and they use port 81 to access it. How... creative. And it gets better. SSH is on port 222. Have you guys ever heard of port scanners? Custom ports is a way of flagging to intruders which firewall software is being used, except when the custom port pattern is unique.

      I can go on. It has a built-in DHCP server. DHCP servers should never be mounted on external firewalls as their logfiles contain too much valuable information when the firewall's security is compromised.

      Hmm, at least it has an HTTP proxy. Probably Squid. No SOCKS support though. And yes, it uses NAT. Gack.

      Well anyway, maybe this c't review will convince a few people to give up a NAT-based solution. Sadly, they'll probably just go to another one.

      [ Parent ]
      • Re:Excuses by stickyc (Score:1) Thursday January 10 2002, @12:33AM
        • Re:Excuses (Score:4, Interesting)

          by hearingaid (216439) <redvision@geocities.com> on Thursday January 10 2002, @01:38AM (#2815034) Homepage

          Mainly, NAT can be persuaded to become bidirectional with relative ease. That is, you can trick it into giving access to machines behind the firewall. This is especially easy if there are servers behind the firewall.

          The explanation on how is technical in the extreme, and while I mostly understand it, I don't trust myself to explain it correctly; I'll recommend the Zwicky book again, [amazon.com] perhaps I should put it in my sigfile. :) If you're broke, go find your local university's library. Any decent uni library and many crappy ones will have at least the first edition of Zwicky.

          The simple answer, though: SOCKS4/5 is a server, and NAT is a router solution. Routers route packets around the 'net. They are designed to pass them back and forth. Servers, on the other hand, just receive packets, process them, and decide what to do with them.

          I talked about this a bit more in a BSD thread just earlier today: go here [slashdot.org] to see my other comment.

          Now, don't get me wrong; NAT is much better than just having an open connection. But it will usually pass ICMP packets, and that's an enormous security hole. Dumb network admins usually deal with it by blocking all ICMP packets, which of course breaks a whole pile of things. The better solution is to just not ever route packets from the 'net past the firewall. They should all be caught at the firewall and fed through some kind of proxy before they ever touch the inside. That can only be done if you give up NAT.

          [ Parent ]
        • 1 reply beneath your current threshold.
    • Re:Excuses by Jennifer Ever (Score:1) Wednesday January 09 2002, @11:05PM
      • Re:Excuses by vkt-tje (Score:1) Thursday January 10 2002, @05:14AM
    • 2 replies beneath your current threshold.
  • by mathrawka (549683) on Wednesday January 09 2002, @06:44PM (#2813475)
    I have noticed that the founder of Smoothwall, Richard Morrell has some issues to deal with. He has a huge ego and does not like users that do not pay for his "open source software." He enjoys complaining about how much money he has spent on making CDs and giving them away for free and how people don't donate to him. I have a few quotes that I have collected that he has said on the mailing lists for smoothwall. "i have contacts with people at the kernel team that none of you have... i know people who can get this fixed and i'm on top of it... so stop complaining because you don't know what you're talking about" "i used to work for microsoft, i know how they work" (he worked in the sales dept selling licenses) "You're also not a paying customer - I'll email DIRECTLY my friend who WROTE the official driver. Friendships help. Thats why I'm richard@linux.com" "this is fuck all to do with SmoothWall its hardware level" Also, Mr. Morrell decided to turn it into closed source "enterprise version" that isn't free with extra features. So he's not allowing open source developers to add new features to the open source project because it will compete with his private closed source project.
  • Not a real firewall review (Score:4, Insightful)

    by Lumpy (12016) on Wednesday January 09 2002, @06:44PM (#2813477) Homepage
    First off reviewing a firewall like that is just whining by a non-techie. you want to review a firewall? crack it... Show me times it took and what kiddie tools took it down or circumvented it because of a flaw in the firewall. bitching about how the scripts are written is clutching at straws and trying to add content to an already empty review.

    Why is it that we all will not listen to a SQL review without stats and figures but a firewall review get's any attention at all if it isnt even tested properly by the reviewer?

    This review was like a review about ram and bitching about the color and shape.
  • Smoothwall by futuresheep (Score:2) Wednesday January 09 2002, @06:47PM
  • Their business model by RainbowSix (Score:1) Wednesday January 09 2002, @06:48PM
    • 1 reply beneath your current threshold.
  • It's great for my network at home by twos (Score:1) Wednesday January 09 2002, @06:48PM
  • by BitMan (15055) on Wednesday January 09 2002, @06:57PM (#2813567) Homepage

    As your momma always said: 'If you don't have anything good to say about someone, don't say it' or 'if you someone keeps "bothering" you, just stay away from them.' It's as simple as that.

    So if you don't like Richard Morrell, head of the SmoothWall project, consider:

    • ignoring him
    • the fact that SmoothWall is free software and freely supported (regardless of the "requests" for monetary support made)
    • disregarding SmoothWall altogether, if it really "bothers" you that much (see below)

    Personally, I'm sick of the "one-sided" reporting on Mr. Morrell. I've seen way too many people "complain" about him, but never comment on various personal details that are partially the cause of this -- let alone the daily on-slaught of Windows users who've barely heard of Linux, who don't bother reading the FAQ, let alone demand that SmoothWall automagically support every little, crappy-designed Windows application and their proprietary protocols that don't work well with firewalls anyway. After a week of being on the SmoothWall lists, I'd kill some very rude and ungrateful users well before Morrell. If you feel Morrell is "really bad for the project," then that's his problem, not yours!

    Now if you still want something like SmoothWall without the SmoothWall(TM), take notice that others have forked the project into a new one called IPCop [ipcop.org]. Version 0.1.0 features SmoothWall 0.9.9, all the major post-0.9.9 patches and various enhancements. A final 0.1.1 release is to follow shortly before the team starts to work on version 0.2.0, an Linux 2.4/Netfilter implementation.

    For all I care, you can think of IPCop as "SmoothWall without Morrell." Just don't say it outloud since many of us are all sick of hearing it!

  • Replying to the reply (Score:4, Insightful)

    by OeLeWaPpErKe (412765) on Wednesday January 09 2002, @06:58PM (#2813581) Homepage
    Daniel Goscomb, one of the lead developers of Smoothwall, responds:

    In our opinion this article is extremely badly researched and written. Furthermore it shows a lack of knowledge on the author's part.

    sjah ... reading on

    The main concern he has is that of people being able to log in to the firewall and read configuration files. This point is irrelevant as there is only a single user that can access the shell, root. This also removes the need of shadow password files, if you have access to the machine to get the passwd file, you are already in as root anyhow.

    so you only have one layer of security ? The inability of any attacker to get a shell ? That's it ? I must admit I have not checked if you do that or not but ...

    In my opinion you should at least take a number of these precautions ...

    -> no shell access for nobody but root (of course this is enforced by putting a check in the main loop of bash, which mails "murder" if anybody tries differently)
    -> all binaries --x--x--x, on a single partition which is the only one mounted without the "noexec" and with "ro" flag
    -> *all* daemons chrooted, none have anything in their /bin or /sbin directory that even remotely resembles a shell or mount program (ie do not use perl, use mod_perl, do not use php, use mod_php, etc)
    -> *all* programs compiled from source
    -> there is no such thing as an irrelevant permission

    Secondly he complains of plain text passwords for the ppp passwords. This is not our doing. The passwords are stored in this format as pppd requires them to be in plain text in the two files. He also mentions that the permissions of these files are wrong. If he looked a little more closely he would have seen that they are in fact symlinks to the 2 real files, which do have the proper permissions on them.

    plain text ? wrong permissions ? why would you take a chance ?

    He also mentions the same "problem" with the shared keys system in FreeSWAN. Again, they are stored like this as FreeSWAN requires them in this format to read them.

    again ... why take the chance ?

    As to the part about user authentification of the CGI scripts. This is completely irrelevant. There is no authentication in the CGI scripts. The authentication is done via .htaccess files, and has no interaction with the CGI at all, other than when you change the passwords.

    user authentication is only irrelevant until a hacker gets by the first layer of security (which apparently on your system is the *only* layer of security)

    I also find it disturbing that the author gave us no room for comment in his article, nor did i see anything to suggest he had even asked us about these so called "problems". We would have been happy to answer any questions he had.

    to quote the other article :
    When a group of developers- more than ever one active in the spirit of GPL-want to successfully distribute a good product, they are usually interested in feedback, in order to improve their product. My concrete indications of security problems within SmoothWall found sheer disinterest with Richard Morrell, developer and project initiator. "That doesn't matter" was about the politest of all comments comment. Trust in the developer's competence and integrity is a basic pre-requisite for the usage of security relevant software. Morell has thoroughly destroyed mine."

    this suggests he has contacted you ... wether or not he did I cannot verify, but if he quotes answers from you ("That doesn't matter"), he probably did contact you, and you certainly confirmed that comment with the above reply, I politely wonder about the next part of that sentence ( ... was about the politest of all comments comment.)
  • Anyone recommend a good IPTABLE's based fw? by prisoner-of-enigma (Score:1) Wednesday January 09 2002, @07:00PM
  • Another firewall product: Astaro (Score:3, Informative)

    by Jacco de Leeuw (4646) on Wednesday January 09 2002, @07:00PM (#2813600) Homepage
    Astaro [astaro.com] seems like an interesting product. It too is based on Linux (GPL) and sports a firewall, IPSEC, PPTP etc. I have downloaded the ISO but haven't installed it yet since it insists on whiping the harddisk. Seems reasonable but I'll have to find a test machine first ;-).

    There's also a support community [astaro.org].

    Some companies such as Pyramid [pyramid.de] are reselling [astaro.com] Astaro with hardware and support.

  • Its bad, really it is... by boris_the_hacker (Score:1) Wednesday January 09 2002, @07:02PM
  • The name?!?! by mikael (Score:2) Wednesday January 09 2002, @07:10PM
  • Why not plaintext passwords? by TheSHAD0W (Score:1) Wednesday January 09 2002, @07:13PM
  • Another alternative (Score:3, Informative)

    by SonicBurst (546373) on Wednesday January 09 2002, @07:25PM (#2813750) Homepage
    I've used Coyote Linux (http://www.coyotelinux.com) for about a year now, and it works great. It's a single floppy distro that runs on a dedicated 486 with 8 or meg of memory. It supports PPPoE and dial-on-demand (among other things), and is remotely manageable with ssh, if so desired. Just my $.02.
  • badly? by reidconti (Score:1) Wednesday January 09 2002, @07:27PM
    • Re:poorly? by cantanker (Score:1) Thursday January 10 2002, @04:13AM
  • by oobeleck (313907) <oobeleck&yahoo,com> on Wednesday January 09 2002, @07:27PM (#2813771) Homepage Journal
    OpenBSD is a good solution for anyone with a 486 and 8MB RAM. It is fairly simple and easy to use. (If you are familiar with Unix).
    You can find all kinds of examples of how to set one up like here. [onlamp.com]
    Older distro's used IPF, but as of 3.0 they use pf. You can read about pf here. [openbsd.org]

    OpenBSD has gone 4 years without a remote hole in the default install. Pretty impressive.

    But hey, only use it if you are SERIOUS about security AND don't want to pay anything.
    Although you should consider helping fund the project out of the kindness of you ./ heart...;-)
  • Maybe they told you? by FlyingTom (Score:1) Wednesday January 09 2002, @07:42PM
  • My smoothwall experiance (it was bad) (Score:5, Interesting)

    by mwhahaha (172475) <(mwhahaha) (at) (vt.edu)> on Wednesday January 09 2002, @07:46PM (#2813869) Homepage
    Twice this evening I've tried to get questions answered about their gpl'd smoothwall because my boss saw this slashdot article. And both times I've been nothing but insulted by Richard Morrell, the founder. The first time I was childish and incompetent all because I had the nickname 'nameless'. The second time I was k-lined from the server and he insults me because I have a german last name.

    smoothwall.org.txt [widomaker.com] and smoothwall.org2.txt [widomaker.com]

    Makes you wonder how these guys really act to customers.
  • SmoothWall and ISDN? by Suidae (Score:2) Wednesday January 09 2002, @07:58PM
  • Security = Probability (Score:5, Insightful)

    by 3247 (161794) on Wednesday January 09 2002, @08:02PM (#2813960) Homepage
    The problem with the SmoothWall developers is that they completly fail to understand that security is always only a probability. A complex product can never have 100% security.
    Every part of the system has a (hopefully low) propability to be successfully hacked. The more barriers you have, the securer your system is.

    It's also worth nothing that the only interactive account is root. There are daemons running under different user ids (I assume in favor of the SW team). As with every remote exploit, these daemons are the entry gates. Also note that remote exploits by definition don't relate to any interactive accounts!

    Now, if one service has been hacked, the whole system is already compromised because there are no shadow passwords, files have the wrong permissions, etc.
    You can argue about the passwort files for remote connections. You can't argue about not using shadow passwords, that's just plain stupid.

    It's like leaving your safe unlocked because there is already the locked front door...

  • by TellarHK (159748) <tellarhk@NOspAm.hotmail.com> on Wednesday January 09 2002, @08:04PM (#2813966) Homepage Journal
    Several months ago, I was messing around with Smoothwall as a possible simple solution to my home LAN situation. It was the eve of the 0.9.8 release, and I went on the Smoothwall IRC chat area and joked about getting an early copy of the release. Joked. I know that doesn't happen, and figured that with a technically oriented crowd, that I'd be understood as kidding. At the time, it seemed that I was. However.

    A couple days later, after having installed Smoothwall and found it to be almost-but-not-quite-right, I popped on and asked a pretty simple question. Why wasn't there a copy of any compilation tools present, or any other services that someone on a small, personal network might like?

    The response was pretty terse. "It's a firewall." Repeated inquiries resulted in various forms of the same answer. Now I understand that a firewall has one main purpose, but the -attitude- I got from the developers was really too much. I figured, after being booted from the channel, I'd email Richard and hope that a cooler, more corporate head might reside at the leadership of the Smoothwall project.

    Unfortunately, I could -not- have been further from the truth. The situation escalated with Richard harassing me VIA email for several days, after repeated requests of mine not to email me any longer. He continued, his crude insults became -threats-, and it took three days for the matter to settle.

    I am currently an assistant administrator at a small college using Linux as a gateway/NAS solution that's desperately in need of updating. Smoothwall might have once been a contender for this, but definitely not now.

    I have posted a rather extensive website airing the entire situation with Richard, my own warts and all, at my Smoothwall site [wctc.org] for the perusal of anyone interested. Sure, I might have made a mistake or two, but I don't feel anything I may have said justified what I recieved.

    Anyone else have similar experiences?
  • My own damned reveiw.... (dammit!) (Score:4, Interesting)

    by whoppo (218875) on Wednesday January 09 2002, @08:33PM (#2814084)
    Being a geek *and* the firewall/vpn admin for a large network I was compelled by geekiness to set up a tunnel between the corporate network and my home network. The lack of desire to spend way too much money for an IPSec compliant appliance I opted to try numberous open source solutions, including Smoothwall 0.9.9se. Despite a few shortcomings, I found the "Smoothie" to be quite impressive. A 23 Meg ISO image yielded a bootable CD that installed without a hitch, identified all the hardware and prompted well for install input (reading the install docs is of course advisable). The box was online is just about 10 minutes with internal clients playing quake and surfing for porn. A quick, yet educated review of the default configurations and a nmap scan and I was confortable with the security... onto the VPN config: A straight forward, web based config menu has fields for all the usual Free-S/WAN VPN stuff, like gateway IP's, site network IP's, next-route-hop IPs, preshared secret, but lacked some specific config options that are needed to create a tunnel with a Checkpoint FW-1/VPN-1 gateway (the reason I was trying this product). Manually adding these config options to the ipsec.conf file was easy enough and in just a short while I was enjoying an IKE/3DES/MD5 tunnel into work.. well.. maybe "enjoying" isn't the right word. My next step was to add a few additional work subnets to the tunnel. This is done by creating an additional connection.. like a second tunnel with the same addresses and preshared secret.. piece of cake.. except, adding more info to the VPN configuration overwrites the ipsec.conf file with a newly created one. Doh!. Fortunately, the web interface is well written and it was pretty easy to add some code to make the admin script create the new ipsec.conf file with the Checkpoint specific changes. Total time invested for a fully functional, easily configurable firewall/VPN: just a few hours. Satisfaction level: 90% Summary: It's easy, fast and works as advertised. Pros: Fast install, Works with Static or dynamic IP's, Many other good features (check the website for details)., Easy to customize the code for personal gratification. Cons: it could offer more flexible IP chains config thru the web interface, Could use those additional VPN options for Checkpoint interoperability. I like it and the smoothwall folks can expect documentation of checkpoint compat. fixes along with a PayPal donation very soon.
  • Get a clue AND/OR Do your homework. by mope555 (Score:1) Wednesday January 09 2002, @09:03PM
  • Morrell was helpful to me. by The Panther! (Score:2) Wednesday January 09 2002, @09:16PM
  • Surprise /. double standard by Yankovic (Score:1) Wednesday January 09 2002, @09:35PM
  • by austad (22163) on Wednesday January 09 2002, @09:54PM (#2814397) Homepage
    Even though the Smoothwall developers argue that shadow passwords are not required, I think they are. I have a box running right here with it. Apache runs as the user "nobody", and therefore can read /etc/passwd. If shadow passwords were enabled, reading /etc/passwd would not matter.

    By default, smoothwall does not allow access to the web interface from the outside, but, very frequently, people open that up to the world so they can get at it from anywhere (which is very easy to do through their menuing system). The box does not ask for a password until you actually get into the configuration screens, but cgi's that give you information are not protected by .htaccess files.

    I wanted to install it on a box that only had SCSI on it awhile back, but they ripped support out of the free version for SCSI. So I joined the irc channel and asked about it. They told me to wait until the commercial version was out and to buy that if I wanted scsi support. So I grabbed their *SDK* as they call it, and it had nothing useful in it at all. I joined back up to the irc channel to ask how to compile everything, they asked why, so I told them I was building in SCSI support so I could run it on the extra box that I had laying around. No one would talk to me after that.

    I found a different machine to run it on, but the only reason I'm still running it is because I haven't had time to get something else. I used to recommend smoothwall to people, but not anymore. The developers I talked to were conceited jackass's. If they had helped me out, I probably would have even donated a few dollars to them.
  • Why is this article here? by philovivero (Score:1) Wednesday January 09 2002, @10:22PM
  • by dr.ka0s (549707) on Thursday January 10 2002, @12:11AM (#2814830)
    I have visited irc.smoothwall.org only once. I do feel, however, that my experience there alone was almost enough to discourage my use of the product. I joined the #smoothwall channel in hopes that I might find answers from knowledgable users or developers that I had been unable to find in any of the available documentation (all of which I read in its entirety).

    Upon joining the channel, I was bombarded with the omnipresent topic, "Welcome to #smoothwall :: Please do not expect free
    support if you haven't donated. http://redirect.smoothwall.org/donate"

    Ignoring the blatantly anti-open-source sentiment, I proceeded to ask about features and functionality that I feel are paramount to implementation of a device designed to secure my entire network. Before anyone so much as regarded my first question, I was bombarded with "Have you paid yet?" A simple 'not yet' got me my first response: "Can't you read the f**king topc?!"

    Of course, I wasn't looking for support -- simply answers to questions about the products capabilities. Off to a great start.

    In the end, my questions were answered, privately, by MacGyver, whose answers unfortunaely indicated that features I think are critical in a firewall are only available in the commercial version. To suggest a few:

    - No support for multiple IP's on the external interface

    - No ability to write filter rules for outbound traffic

    - No inherent ability to manage IDS policies used by Snort

    - No immediate planned support for a stateful kernel

    etc...

    Granted, I could accomplish all of these tasks through custom modifications to the product -- but that would defeat the purpose of the product in the first place -- to create a secure filtering firewall that can be easily and securely managed through an integrated portable interface without the need for extensive customization.

    To comment on the article posted this evening, I think that despite the article author's process for review or lack thereof, SmoothWall's response was unacceptable. To say that passwords are not shadowed because the box has but the root user would be to say that Bind and Sendmail need not be firewalled because their latest revisions have no vulnerabilities...

    yet.

    To say that the open-source security packages that comprise the firewall _require_ clear-text passwords is to insult the intelligence of everyone here who knows better or has found more secure alternatives to the same problems in the past. The open-source community is not ignorant, nor are we fooled by any comapny's efforts to conceal laziness.

    Security is an unknown. We place our confidence in hybrid hardware and software solutions that provide protection from the exploits we've identified already, but we expect that new vulnerabilities are inevitable. We cannot neglect commonly accepted security practices because our products have not yet been broken. The correlary would be to argue against home alarms because we already have a lock on the door.

    A single layer of security is never enough. ESPECIALLY for a firewall. If this were to be an end-user distribution sitting _behind_ a firewall, the lack of external access would _probably_ be enough. However, as a firewall, such neglect for security practices that have a negligible effect on performance but provide such a significant measure of protection is both arrogant and ignorant at the same time.

    In conclusion, neither the product's lackluster featureset, nor it's father company's poor customer support practices would have individually discouraged my using it.

    Couple those with questionable security practices, though, and I can assure you that SmoothWall will never be enough to protect _my_ network...
  • Some of this post is very on-topic, but I include the rest for context. Moderators, please be kind.

    I and a buddy recently completed a network installation for a small business. They had about 25 PC's in a 100-year-old wood-frame office building with asbetos everywhere and wanted these people to be able to utilize the Internet for such tasks as tracking packages via web sites, etc. They wanted to reduce costs by eliminating some 6 dialup accounts and free up phone lines for voice. They were less than a quarter mile from the local telco POP. So, they tried ADSL on one PC and consistently got about 1.5 Mbps down and about half that up. They loved it.

    They asked me as an independent consultant what they should do to get the access to the other PC's. We looked at wiring the building, but due to the structural nightmare of the building, we decided that for their needs we could go with 802.11b. We dropped several CAT5e lines to three locations in the building: the computer room, where their mission-critical apps run on an AS400, and two access point mounts we set up.

    We set up a SmoothWall box as their NAT since the evil ISP would only give us one static IP. It looked a lot better than FreeSCO. It was painless, absolutely painless to configure. But it had a shortcomming: it did not support PPPoE, which was necessary for the ADSL drop. Schucks! So we double-NATed using a little Linksys NAT/switch thingy to actually negotiate the PPP for us. We thought this would be nice because if someone were trying to hack in, they would have to circumvent 2 NAT's. We also thought it would have no significant impact on throughput. Big mistake (read on). Regardless, the NAT solution could remain in place should they ever want to add a stateful packet inspection firewall or something like that, or switch to better broadband, or even wire the building.

    We spent almost an entire afternoon trying to configure the blasted access points. They were DLink 1000AP's. I followed DLink's instructions to the letter. I have a little beef with DLink about requiring a Windows machine to configure the things, but I can overlook that. I installed the configuration software on my laptop and was ready-to-rumble. The software failed repeatedly to detect the access point using a DLink branded 802.11b client device (USB DWL120). So I tried step two, isolating the AP's on an Ethernet segment. They failed detection again. So I fed the software MAC addresses manually. This failed. I was using only one machine with a known-to-work crossover patch cable. What the *(!@?

    We eventually tried swtiching PC's, and then we noticed that the typeface DLink used to print the MAC addresses on their AP's made 5's look like 6's because the ink ran too much. I was really pissed. Upon getting the conf software to work on a desktop, I went back to my laptop to try again. It flat out wouldn't work with either of my 3Com CC10BT PCMCIA cards in different machines. Don't know why to this day; DLink couldn't help me on that one. But it did work on a desktop wit a 3Com 3c509b.

    So, we got the access points set up and clients on all the PCs. We set up WEP encryption and tried to hack around a little to get in without the keys. We made sure we altered the default network ID and set good hard-to-guess passwords. It was like butta, for just one day.

    Next weekend, we came back and hooked up more PC's. We went up to say 18 from 12. This is where we started having problems.

    We used MAC address control on the APs as we promised the company we would. But after hours and hours of trial and error, we discovered that after adding more than 17 MAC addresses to the control list on one AP, the AP would spontaneously loose all of its configuration data. This worked this way on both AP's. DLink was not helpful. We would later RMA one of these and the replacement would do the same. So, we ended up having to have control lists that were local instead of network-wide. This defeated the roaming feature of 802.11b entirely (although nobody has a laptop there right now, I don't like it one bit). It also causes more difficulty in configuring the damn things. My friend, who is an Apple Campus Rep, haunts me to this day with suggestions of buying their AirPort brand equipment and says it would work better. Anyway, we choose DLink 'cause it was a hell of a lot cheaper than Orinoco.

    We saved the company lotsa money on their dial-up. Next, we moved their web pages in house on a Red Hat box on a DMZ. DMZ wasn't all that in SmoothWall at the time (no hole poking), but it did what we needed it to. We moved their primary DNS to publicdns.org and set up MX records, the whole works. Set up a sendmail box. Set them up with PHPGroupWare. And, we encouraged them to make donations to the various projects which provided them with these fine products and services. I felt all warm and fuzzy. I had turned them into a free-software shop on commodity hardware and it all worked.

    After a while, I started getting phone calls from them saying their web pages were only accessible to some clients. I looked into this. I left myself a way to get in (a port forwarded to a pc with sshd, I had permission to do this), and so I hopped on in and looked around. I became acutely aware that my ssh sessions were being dropped very frequently. I kept getting some sort of error from my ssh client during sessions.

    We went back down to isolate the problem. We kept removing pieces of hardware from the network to figure out what the &*^% was going on, but found nothing. Then we learned SmoothWall had added support for PPPoE. We scrapped the Linksys, and we had no more dropped TCP sessions. It was freaky . I have seen the same problem affect two other people who used port forwarding since then with Linksys boxes (I help folks out on Mandrake Expert). SmoothWall had also added better DMZ support. I just have to say the system works beautifully.

    Other issues we encountered in the project were users compromising security by using AOL clients. AOL clients create VPNs which in theory could allow hackers to circumvent your company's security. Don't let your users do this.

    Oh, I almost forgot, the AS400. Up until we set them up with a network, they were using this shitty twinax serial network to talk to their AS400. It was expensive. It required shitty ISA adapters to be installed in every PC. It almost made me puke.

    At the start of the project in our proposal we told them that they should use encrypt everything, even internally, and that that was just common sense. We told them they could put the AS400 on the LAN and use ssh instead of those card-and-twinax interfaces. I even verified this with my fiancee's dad, an old-AS400-fart himself, before I promised them this. WE WERE WRONG.

    IBM told us they COULD NOT RUN SSHD WITHOUT BUYING A NEW MACHINE. That is such a load of crap, but we, having no experience with AS400's, could do nothing about it. The IBM man convinced them to run telnet. We told them we would take no responsibility for that. End-of-story.

    Hope this has been an informative venting session for all of you. Please note that there was some relevant content in here, and that SmoothWall solved some of my problems, and I think it is a great product.
  • I have a serious question... by Anonymous Coward (Score:1) Thursday January 10 2002, @02:48AM
  • My Smoothwall review (Score:5, Insightful)

    by juct (549812) <ju@heisec.de> on Thursday January 10 2002, @05:33AM (#2815448) Homepage
    Just a couple of comments to the Smoothwall answer to my review:
    My major concern is not, that somebody other than the administrator might log into the machine. The major issue of a firewall system is, to tighten security, not to remove existing security mechanisms like tight access rigts to sensitive files, shaddow passwords, etc. But that is exactly what Smoothwall does in direct comparism to any standard linux distribution.
    I'm sorry, if the text doesn't make it clear, that I'm not complaining about the format of files but about sensitive files with passwords or secret keys, that are world readable (ie mode 0644). Something like
    -rw-r--r-- /etc/ipsec.secrets
    is a bad thing - period.
    I made every effort, to get "printable" response from the developers. I wrote several E-Mails about the issues to Richard Morrel - who was named as contact person- and I went to the IRC channel of the developers. The only printable comment to the subject I got there is "This doesn't matter".
  • c't review not bad at all by tiomo (Score:1) Thursday January 10 2002, @05:40AM
  • C't _did_ try to reach smoothwall upstream by mbanck (Score:1) Thursday January 10 2002, @05:54AM
  • security hole by swuser (Score:1) Thursday January 10 2002, @06:17AM
  • Reply by the Artivles Author by Airon (Score:1) Thursday January 10 2002, @06:41AM
  • another free Firewall: Gibraltar by Anonymous Coward (Score:1) Thursday January 10 2002, @07:39AM
  • well done /. community by mydigitalself (Score:1) Thursday January 10 2002, @08:19AM
  • mr. morrell should become a journalist... by tiomo (Score:1) Thursday January 10 2002, @09:43AM
  • "...extremely badly researched and written." by yep (Score:1) Thursday January 10 2002, @10:15AM
  • Authentication != verifying CGI data by Genus Marmota (Score:1) Thursday January 10 2002, @01:06PM
  • One more brick in the 'Wall by offline (Score:1) Thursday January 10 2002, @01:22PM
  • Smoothwall missed the boat on this one by TuxGrep (Score:1) Thursday January 10 2002, @03:13PM
  • Smothwall Review Continued by IceJester (Score:1) Friday January 11 2002, @09:09AM
  • News on Heise.de "Security Hole in SmoothWall" by ofassben (Score:1) Monday January 14 2002, @11:42AM
  • I had a good experience by EvilStein (Score:2) Monday January 14 2002, @07:14PM
  • Just been on irc.smoothwall.org... by Cloud K (Score:1) Tuesday January 15 2002, @02:41PM
  • Re:Daniel Goscomb seems far too complaintent by Supa Mentat (Score:1) Wednesday January 09 2002, @06:37PM
  • Re:Daniel Goscomb seems far too complacent by byolinux (Score:2) Wednesday January 09 2002, @06:50PM
  • Re:The smoothwall team is full of GREAT IDEAs.. by A.MacGyver (Score:1) Wednesday January 09 2002, @07:09PM
  • I wanted to build a firewall kit once... by einhverfr (Score:2) Wednesday January 09 2002, @08:36PM
  • Re:Suse Linux Firewall by wpanderson (Score:1) Wednesday January 09 2002, @09:02PM
  • Re:Smoothwall Firewall by cmkrnl (Score:1) Thursday January 10 2002, @06:22AM
  • Re:Firewall question by whoppo (Score:1) Thursday January 10 2002, @03:45PM
  • Re:Security hole in Smoothwall! by Dubu (Score:1) Monday January 14 2002, @10:04AM
  • 31 replies beneath your current threshold.