Firewall-1

[FW-1] Check Point R55W Directory Traversal

Subject: [FW-1] Check Point R55W Directory Traversal
From: Tauseef Khan <Tauseef_Khan AT 3I DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 25 Jul 2006 11:25:09 +0100
This might be useful to everyone.

Kind regards


From: Sec-Tec Lists [mailto:zen31438 AT zen.co DOT uk] 
Sent: 24 July 2006 17:33
To: bugtraq AT securityfocus DOT com
Subject: Check Point R55W Directory Traversal


Overview

Check Point Firewall-1 R55W contains a hard coded web server, which runs
on TCP port 18264. This server is there to deal with PKI requirements
for Check Point's VPN functionality.

During a routine penetration test of a client, Sec-Tec discovered a
directory traversal vulnerability that allows a potential attacker to
retrieve files from the underlying OS.

This issue is potentially serious for a number of reasons:

1. Check Point's "rule zero" will often by default allow access to this
port for external IP addresses.

2. It would currently seem that there are few restrictions as to what
files can be retrieved via this mechanism (Sec-Tec were able to obtain
the underlying OS' account repository).

Exploit

The issue can be exploited via a web browser using typical hex encoded
directory traversal strings.

Affected Version(s):

Check Point R55W
Check Point R55W HFA1
Check Point R55W HFA2

(Confirmed on Windows 2003 Server platform, other platforms may be
affected.)

Current Status

Check Point have confirmed that this issue was corrected in R55W HFA03.
However, Sec-Tec have been unable to find any publicly available
references to this issue, either within Check Point's knowledge base or
HFA03 release notes.

Updates to this issue will be found at:
http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html


Pete Foster
Senior Consultant
Sec-Tec Ltd






*************************************************
For addressee only. No legally binding commitments will be created by this 
e-mail message. Where we intend to create legally binding commitments these 
will be made through hard copy correspondence or documents.

3i Investments plc
Registered office: 

16 Palace St
London
SW1E 5JD

Registered no:3975789
Authorised and Regulated by the Financial Services Authority

If you are not the intended recipient it may be unlawful for you to read, copy, 
distribute, disclose or otherwise use the information in this e-mail. If you 
are not the intended recipient please contact us immediately. E-mail may be 
susceptible to data corruption, interception and unauthorised amendment, and we 
do not accept liability for any such corruption, interception or amendment or 
the consequences thereof.

3i is committed to following policies which protect your privacy and comply 
with current international data protection laws and regulations in respect of 
personal data. Further details of these policies can be found at www.3i.com.
*************************************************


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>