fwd: Digital's Statement on SATAN

From: <berc_at_pa.dec.com>
Date: Tue, 11 Apr 95 14:21:24 -0700

[ I no involvement with SATAN or other daemons - lance ]

------- Forwarded Message

From: lionel_at_quark.enet.dec.com (Steve Lionel)
Date: 11 Apr 1995 15:00:17 GMT
Subject: Re: SATAN for AXP?

[Attached is Digital's official response regarding SATAN - FYI]

 =============================================================================
 DEC-95-332A DATE: 07.APR.1995
 =============================================================================

     SOURCE: Digital Equipment Corporation
             Digital Software Security Response Team &
             Digital Firewall Engineering

     COMPONENT: SATAN (or SANTA) Security Analysis U*IX Networks
                Security Administrator Tool for Analyzing Networks (SATAN)

     Dear Valued Digital Customer,

     Subj: ULTRIX, OpenVMS (UCX), DEC OSF/1 and Digital's Firewall Product

     References:
     CERT Advisory CA-95:06 dated 3 April 1995
     CIAC Advisory F-20 dated 5 April 1995
     Available via the Internet, and subsequent news articles published.

     DESCRIPTION:
     -------------------------------------------------------------------------

     SATAN is a testing and reporting tool that collects a variety of
     information about networked hosts. SATAN gathers information about
     specified hosts and networks by examining network services (for example,
     finger, NFS, NIS, and ftp). In addition to reporting potential
     vulnerabilities, SATAN gathers general network information (network
     topology, network services run, types of hardware and software being used
     on the network).


     The advisories, the documentation contained in the SATAN package, or the
     related news stories, do not disclose any previously unknown computer
     system security vulnerabilities and does not pose a threat to Digital
     Equipment Operating Systems properly maintained (with a Security
     Baseline), with the latest software releases and with subsequent release
     patches installed. The reported methods of probing have been known for a
     number of years and corrected through ECO (patch release) and subsequent
     releases of the operating systems.
                                               
     These SATAN probes may be monitored by a number of techniques, only
     some of which are addressed in the CERT Advisory and subsequent articles.
     A more complete analysis of the general problem has been conducted
     by firewall experts in Digital's Palo Alto and Galway, Ireland,
     research labs and product groups. No vulnerabilities where discovered
     in properly configured environments.

     For information to monitor your site for SATAN probes, using
     the proper combination of Digital products, configured in the optimal
     manner please contact your normal Digital support channel.

     Digital Equipment Corporation does not intend to distribute Satan nor does
     it plan any an advisory containing kit location, testing results or
     redistribution of any advisories containing that information.

     Digital Equipment Corporation recommends that this Software be treated
     with all the due care necessary based on the current publicly available
     information or advisories and make an informed decision prior to any
     installation, or use, within their environment and to use all available
     security monitoring techniques to guard against a potential malicious
     probe of SATAN to their environment.

     GENERAL INFORMATION
     ---------------------------------------------------------------------

     SATAN was designed as a security tool for system and network
     administrators for security analysis. However, given its potential wide
     distribution, ease of use, and ability to scan remote networks, SATAN is
     also likely to be used to locate vulnerable hosts for malicious reasons.
     It is also possible that sites running SATAN for a legitimate purpose will
     accidentally scan your systems/environment via SATAN's exploratory mode.

     As always, Digital recommends that you regularly review your system
     management and security procedures. Digital will continue to review
     and enhance security features, and work with our customers to further
     improve the integrity of their systems.

   _____ _____ _______ _________ |
  /____/ \ /____/ \ /______/ \ /________/| | Digital Equipment Corporation
 / ___\/ / ___\/ | ___ \/ | |________|/ |Software Security Response Team
 \ (/__/\ \ (/__/\ | |/__) |/ | | | |
  \___ \ \ \___ \ \ | / | | | |
  ____) )/ ____) )/ | |\ \ \ | | | |
 /___/ / /___/ / | | \ \ \ | | | |
 \______/ \______/ |_|/ \__\/ |_|/ |

------- End of Forwarded Message
Received on Tue Apr 11 1995 - 17:29:20 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:45 NZDT