pen-test
[Top] [All Lists]

Re: Pentesting Old unsupported Firewall Appliances

To: "Harold Castro" <b0ydaem0n@yahoo.com>
Subject: Re: Pentesting Old unsupported Firewall Appliances
From: "Jamie Riden" <jamie.riden@gmail.com>
Date: Tue, 12 Jun 2007 13:36:00 +0100
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=bGpzN5FeS3KiH434JWimXHYMHyDwuj0pyF2oz3buKQvRU937MT849V8IferUlAJTmDksfafAnmFJpTq9EoOPGAFhQJefTLHR2ikXetQ5m/DrthZpWODilNEPrUzIhJ0nCSWyqY9ylBttAV8VxCrJ1qRuXsviVc66ZakRoN37uV4=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=UHQ5ICKyaAo82i0c/b3y6Pa11pDCR/TTi8Z3gnMJ2vZstUK5v2CHTJ9ds7Dl1j5uaPc7bHbREqaVoFiXuEHGzZST/szZitNChGzzSXgFfRtn1ozUNda+iXhIKniSJvc3BrC/7Iyn93XUlyoEwlDr5dFUg1DI+6kjNpMW4gXtG5I=
In-reply-to: <27589.67646.qm@web38403.mail.mud.yahoo.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <27589.67646.qm@web38403.mail.mud.yahoo.com>
Resent-date: Fri, 15 Jun 2007 10:43:04 -0600 (MDT)
Resent-from: pen-test-return-1078484364@securityfocus.com
Resent-message-id: <20070615164304.965C6144219@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
On 11/06/07, Harold Castro <b0ydaem0n@yahoo.com> wrote:
Hi,
..
Since I'm doing an external black box pentest, I have
to rely on some tools for OS fingerprinting. Nmap
guesses it to be either Nokia IPSO 4.0 or 4.1Build19.
Now I tried googling for that particular appliance
(IP650) and I found out that the appliance is too old
as its existence dates back as early as 1999. I'm
having a hard time trying to find anything
that can be useful for this

Usually the next stage would be to try to exploit it - providing that
is allowed for by your penetration-testing contract. (It should be,
otherwise it's more of an audit rather than a pen-test.)

If all else fails, do you tell the customer that it is
safe to ignore those warnings and vulnerabilities
because you, on a hacker's perspective, was not able
to penetrate the network by making use of those
vulnerabilities found, that the hacker might have a
hard time as well and eventually opt for another
target?

I don't like to. If you aren't able to break it, just say so. As a
pen-tester, you haven't got enough information to say if it's safe.
Obviously, if you break it, it's not safe, otherwise you don't know.

cheers,
Jamie
--
Jamie Riden, CISSP / jamesr@europe.com / jamie@honeynet.org.uk
UK Honeynet Project: http://www.ukhoneynet.org/

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>