Eicon Networks S92 Instrukcja Użytkownika Strona 191

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 209
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 190
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 191
Sincewejusttalkedaboutthedefaultports,onethingwecan try istoexplore
vulnerabilitiesrelatedtoFW1’sports.AsearchonCERTreturnsonesuch
vulnerability.Thisvulnerabilityinvolvesport259 andisrelatedtoFW1’sRDP
protocol:
“ByaddingafakedRDPheadertotypicalUDPtraffic,anycontentcan bepassedto
port259onanyhostoneithersideofthedevice.”
61
So,howdowelaunchanattackbasedonthisinformation?Thebestthingtodoisto
lookatthe“Proofofconceptcode”availableat
http://www.insidesecurity.de/fw1_rdp_poc.html.ThesourcecodeisavailableinC
language.Bycompilingourownattackprogramusingthesecodes,suchattackcanbe
launched.Keepinmindthough,thatthisvulnerabilityisfoundonly onFW1version
4.1. Thereisnoevidencethatidenticalvulnerabilityexistsinversion4.0.
ForGIACadministratortoworkonthisissue,itissuggestedthatthefollowing
workaroundssuppliedbyinsideSECURITYbefollowed:
“
Commentline2646ofbase.def(accept_fw1_rdp;) 
DeactivateimpliedrulesintheCheckPointpolicyeditor(andbuildyourownrules
formanagementconnections).
BlockUDPtraffictoport259onyourperimeterrouter.
”
62
Attacking–theTrojanroute:
Thisattackallowsustotakecontrolof FW1.
Wealreadyknowfromourwebsitevisit”whatprotocolsareallowedinGIAC’s
securityarchitecture.RememberwetalkedaboutsecondaryDNSserverandzone
transfer?FW14.x’sdefaultpolicysettingdoesallowtrafficthatheadstowardsTCP
port53 topass.Sincemanyadministratorssimplyleavethisoptionasis,whatwecan
dothenistouseNSLOOKUP oranyothermeantoinitiateazonetransferagainstthe
61
http://www.kb.cert.org/vuls/id/310295
62
http://issrv1.insidesecurity.de/fw1_rdp.html
Przeglądanie stron 190
1 2 ... 186 187 188 189 190 191 192 193 194 195 196 ... 208 209

Komentarze do niniejszej Instrukcji

Brak uwag