/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Hacker ‘handshake’ hole found in common firewalls

NSS Labs tested Cisco, Check Point, Fortinet, Juniper, the Palo Alto Networks, and SonicWall firewalls  —  Some of the most commonly-used firewalls are subject to a hacker exploit that lets an attacker trick a firewall and get into an internal network as a trusted IP connection.

Network World Ellen Messmer

Context & Ripple Effects

NSS Labs, an independent firewall-testing shop rather than any single vendor's security team, ran the same exploit against firewalls from Cisco, Check Point, Fortinet, Juniper, Palo Alto Networks, and SonicWall — and the TCP handshake trick worked broadly, letting an attacker enter an internal network dressed as a trusted IP connection. With no prior corpus coverage on this beat, the significance rests on the breadth: this is not one vendor's bug but a shared weakness in how the entire category adjudicates trust at connection setup.

That framing matters because firewall purchases in 2011 lean heavily on vendor claims and certification-style benchmarks; a lab result showing a class-wide hole puts the testing organizations themselves, not just the vendors, at the center of enterprise buying decisions.

First-order effects

  • Enterprises running any of the six tested firewalls must treat their perimeter trust boundary as porous to handshake spoofing until their vendor issues guidance or fixes, making immediate triage a security-team task rather than a procurement one.
  • Cisco, Check Point, Fortinet, Juniper, Palo Alto Networks, and SonicWall each face pressure to publicly characterize whether their implementations are exploitable and on what remediation timeline, since a collective silence reads as confirmation.

Second-order effects

  • Independent test houses like NSS Labs gain leverage over firewall procurement, as buyers weighing competing products start discounting vendor self-attestation in favor of adversarial third-party results.
  • Vendors may differentiate on detection depth beyond connection-level checks — application-layer inspection and identity-aware policies become selling points precisely because handshake-level trust proved spoofable.

Third-order effects

  • If a single protocol-level flaw spans the whole incumbent field, it argues that perimeter firewalls acting as trusted gatekeepers are structurally brittle, pushing enterprise architecture toward layered verification where no single device's verdict on a connection is final.

The trend: Enterprise network security is drifting from trusting connection-level firewall verdicts toward verifying every session independently, with third-party lab testing increasingly setting the terms of vendor credibility.