Firewall-1

Re: [FW-1] vulnerability confirmation

Subject: Re: [FW-1] vulnerability confirmation
From: no-need to-list <ogos69 AT YAHOO DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 31 Jul 2006 17:10:58 -0700
>From what I can read....
  it seems to be related to R55W version only....
  It does not tell us on what Hot Fixes this bug was discovered.....
  and the undelined OS was Windows based....(we all know how secure Windows is!)
  and we all know how lazy some firewall  administrator are ........
   
  In my humble opionion....
   
  SEC-TEC seem to be looking for some free advertising,,,,

   
  
Jason Santana <j.santana AT COMCAST DOT NET> wrote:
  All,

I had seen this vulnerability reported in a number of places but have been
unable to find anything from checkpoint confirming it.

http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html

Can anyone point me to an official announcement or confirmation from
Checkpoint?

Thanks!

Jason Santana

Overview

Check Point Firewall-1 R55W contains a hard coded web server, which runs on
TCP port 18264. This server is there to deal with PKI requirements for Check
Point's VPN functionality.

During a routine penetration test of a client, Sec-Tec discovered a
directory traversal vulnerability that allows a potential attacker to
retrieve files from the underlying OS.

This issue is potentially serious for a number of reasons:

1. Check Point's "rule zero" will often by default allow access to this port
for external IP addresses.

2. It would currently seem that there are few restrictions as to what files
can be retrieved via this mechanism (Sec-Tec were able to obtain the
underlying OS' account repository).

Exploit

The issue can be exploited via a web browser using typical hex encoded
directory traversal strings.

Affected Version(s):

Check Point R55W
Check Point R55W HFA1
Check Point R55W HFA2

(Confirmed on Windows 2003 Server platform, other platforms may be
affected.)

Current Status

Check Point have confirmed that this issue was corrected in R55W HFA03.
However, Sec-Tec have been unable to find any publicly available references
to this issue, either within Check Point's knowledge base or HFA03 release
notes.

Updates to this issue will be found at:
http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================


 __________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>