This might be useful to everyone.
Kind regards
From: Sec-Tec Lists [mailto:zen31438 AT zen.co DOT uk]
Sent: 24 July 2006 17:33
To: bugtraq AT securityfocus DOT com
Subject: Check Point R55W Directory Traversal
Overview
Check Point Firewall-1 R55W contains a hard coded web server, which runs
on TCP port 18264. This server is there to deal with PKI requirements
for Check Point's VPN functionality.
During a routine penetration test of a client, Sec-Tec discovered a
directory traversal vulnerability that allows a potential attacker to
retrieve files from the underlying OS.
This issue is potentially serious for a number of reasons:
1. Check Point's "rule zero" will often by default allow access to this
port for external IP addresses.
2. It would currently seem that there are few restrictions as to what
files can be retrieved via this mechanism (Sec-Tec were able to obtain
the underlying OS' account repository).
Exploit
The issue can be exploited via a web browser using typical hex encoded
directory traversal strings.
Affected Version(s):
Check Point R55W
Check Point R55W HFA1
Check Point R55W HFA2
(Confirmed on Windows 2003 Server platform, other platforms may be
affected.)
Current Status
Check Point have confirmed that this issue was corrected in R55W HFA03.
However, Sec-Tec have been unable to find any publicly available
references to this issue, either within Check Point's knowledge base or
HFA03 release notes.
Updates to this issue will be found at:
http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html
Pete Foster
Senior Consultant
Sec-Tec Ltd
*************************************************
For addressee only. No legally binding commitments will be created by this
e-mail message. Where we intend to create legally binding commitments these
will be made through hard copy correspondence or documents.
3i Investments plc
Registered office:
16 Palace St
London
SW1E 5JD
Registered no:3975789
Authorised and Regulated by the Financial Services Authority
If you are not the intended recipient it may be unlawful for you to read, copy,
distribute, disclose or otherwise use the information in this e-mail. If you
are not the intended recipient please contact us immediately. E-mail may be
susceptible to data corruption, interception and unauthorised amendment, and we
do not accept liability for any such corruption, interception or amendment or
the consequences thereof.
3i is committed to following policies which protect your privacy and comply
with current international data protection laws and regulations in respect of
personal data. Further details of these policies can be found at www.3i.com.
*************************************************
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|