
Security researchers discovered a new way by which they can bypass corporate firewalls and steal data from networks, via TCP handshakes.
The vulnerability code-named FireStorm was discovered in a joint research by BugSec Group and Cynet. According to the researchers, the vulnerability lies in the way firewalls handle TCP connections.
Every time a TCP connection starts and before any content exchange between client and server, a common communication channel is established between them, through the exchange of certain synchronization packets (TCP SYN). This process is called a TCP handshake and is mandatory for all connections.
Firewalls allow this specific process so that they can know what kind of connection is expected to be initiated. If the connection type, the source, or the destination are included in the firewall's block list, the firewall will block the connection.
In an experiment conducted, security researchers at BugSec Group and Cynet were able to send sensitive data from a firewall-protected network to an external server using only TCP SYN packets and
without making a full TCP connection, which the firewall was configured to block.
The researchers also created a special tool for data tunneling via TCP handshakes, allowing the “extraction” of data from secure networks without being detected.
The vulnerability affects the products of most firewall manufacturers. However, most of them refused to acknowledge Firestorm as a vulnerability issue, saying that their products are designed to operate in this way at a technical level.
Nevertheless “to successfully address the risks posed by Firestorm, the firewalls must block the repeated TCP SYN packet exchanges between client and server and block direct connections between internal hosts and foreign, unauthenticated hosts”, the researchers emphasize.
