Bug 292741 - RFE: Firewall has no way to block "ping" (ICMP)
Summary: RFE: Firewall has no way to block "ping" (ICMP)
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: system-config-firewall
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Thomas Woerner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-09-17 06:58 UTC by Andy
Modified: 2008-05-05 10:34 UTC (History)
0 users

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-05-05 10:34:35 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Andy 2007-09-17 06:58:16 UTC
Description of problem: Fedora 8 Test2 - The firewall has no option to block
"ping" (ICMP). I've tested F8 using the "Shields Up" test (http://www.grc.com)
and the only vulnerability that was found was that F8 responds to pings.  

Version-Release number of selected component (if applicable): Fedora 8 Test2

How reproducible: Very. Select System, Admin, Firewall. Nowhere in the firewall
settings is there an option to block ping. Compare this to the Firestarter
firewall where ping is easily blocked - just select "Preferences, ICMP filtering". 

Fedora is supposed to be one of the most secure distros, so imo this is a
serious oversight and should be fixed.  

Steps to Reproduce:
1. Go into the firewall settings ("System", "Admin", "firewall"). 
2. Look for an option to block ping. You'll be looking for a long time... ;-) 
  
Actual results: Result is that distro is vulnerable, and if you want to block
ping, you need to grovel around with a config file. Not acceptable for such an
obvious and glaring security hole.  

Expected results: Being rootkitted...

Additional info:

Comment 1 Thomas Woerner 2007-11-06 13:24:23 UTC
Assigning to system-config-firewall.

Comment 2 Thomas Woerner 2007-11-21 12:19:21 UTC
Assigning to devel.

Comment 3 Jon Stanley 2008-04-23 20:30:50 UTC
Adding FutureFeature keyword to RFE's.

Comment 4 Thomas Woerner 2008-05-05 10:34:35 UTC
Fixed in rawhide in package system-config-firewall-1.2.6-1 or newer.


Note You need to log in before you can comment on or make changes to this bug.