Eicon Networks S92 Manual de usuario Pagina 191

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 209
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 190
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 191
Sincewejusttalkedaboutthedefaultports,onethingwecan try istoexplore
vulnerabilitiesrelatedtoFW1’sports.AsearchonCERTreturnsonesuch
vulnerability.Thisvulnerabilityinvolvesport259 andisrelatedtoFW1’sRDP
protocol:
“ByaddingafakedRDPheadertotypicalUDPtraffic,anycontentcan bepassedto
port259onanyhostoneithersideofthedevice.”
61
So,howdowelaunchanattackbasedonthisinformation?Thebestthingtodoisto
lookatthe“Proofofconceptcode”availableat
http://www.insidesecurity.de/fw1_rdp_poc.html.ThesourcecodeisavailableinC
language.Bycompilingourownattackprogramusingthesecodes,suchattackcanbe
launched.Keepinmindthough,thatthisvulnerabilityisfoundonly onFW1version
4.1. Thereisnoevidencethatidenticalvulnerabilityexistsinversion4.0.
ForGIACadministratortoworkonthisissue,itissuggestedthatthefollowing
workaroundssuppliedbyinsideSECURITYbefollowed:
“
Commentline2646ofbase.def(accept_fw1_rdp;) 
DeactivateimpliedrulesintheCheckPointpolicyeditor(andbuildyourownrules
formanagementconnections).
BlockUDPtraffictoport259onyourperimeterrouter.
”
62
Attacking–theTrojanroute:
Thisattackallowsustotakecontrolof FW1.
Wealreadyknowfromourwebsitevisit”whatprotocolsareallowedinGIAC’s
securityarchitecture.RememberwetalkedaboutsecondaryDNSserverandzone
transfer?FW14.x’sdefaultpolicysettingdoesallowtrafficthatheadstowardsTCP
port53 topass.Sincemanyadministratorssimplyleavethisoptionasis,whatwecan
dothenistouseNSLOOKUP oranyothermeantoinitiateazonetransferagainstthe
61
http://www.kb.cert.org/vuls/id/310295
62
http://issrv1.insidesecurity.de/fw1_rdp.html
Vista de pagina 190
1 2 ... 186 187 188 189 190 191 192 193 194 195 196 ... 208 209

Comentarios a estos manuales

Sin comentarios