| To: | "Harold Castro" <b0ydaem0n@yahoo.com> |
|---|---|
| Subject: | Re: Pentesting Old unsupported Firewall Appliances |
| From: | "Jamie Riden" <jamie.riden@gmail.com> |
| Date: | Tue, 12 Jun 2007 13:36:00 +0100 |
| Cc: | pen-test@securityfocus.com |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | pentest-list2@consult.net |
| Delivered-to: | mailing list pen-test@securityfocus.com |
| Delivered-to: | moderator for pen-test@securityfocus.com |
| Dkim-signature: | a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=bGpzN5FeS3KiH434JWimXHYMHyDwuj0pyF2oz3buKQvRU937MT849V8IferUlAJTmDksfafAnmFJpTq9EoOPGAFhQJefTLHR2ikXetQ5m/DrthZpWODilNEPrUzIhJ0nCSWyqY9ylBttAV8VxCrJ1qRuXsviVc66ZakRoN37uV4= |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=UHQ5ICKyaAo82i0c/b3y6Pa11pDCR/TTi8Z3gnMJ2vZstUK5v2CHTJ9ds7Dl1j5uaPc7bHbREqaVoFiXuEHGzZST/szZitNChGzzSXgFfRtn1ozUNda+iXhIKniSJvc3BrC/7Iyn93XUlyoEwlDr5dFUg1DI+6kjNpMW4gXtG5I= |
| In-reply-to: | <27589.67646.qm@web38403.mail.mud.yahoo.com> |
| List-help: | <mailto:pen-test-help@securityfocus.com> |
| List-id: | <pen-test.list-id.securityfocus.com> |
| List-post: | <mailto:pen-test@securityfocus.com> |
| List-subscribe: | <mailto:pen-test-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:pen-test-unsubscribe@securityfocus.com> |
| Mailing-list: | contact pen-test-help@securityfocus.com; run by ezmlm |
| References: | <27589.67646.qm@web38403.mail.mud.yahoo.com> |
| Resent-date: | Fri, 15 Jun 2007 10:43:04 -0600 (MDT) |
| Resent-from: | pen-test-return-1078484364@securityfocus.com |
| Resent-message-id: | <20070615164304.965C6144219@outgoing2.securityfocus.com> |
| Resent-sender: | listbounce@securityfocus.com |
| Sender: | listbounce@securityfocus.com |
On 11/06/07, Harold Castro <b0ydaem0n@yahoo.com> wrote: Hi, .. Since I'm doing an external black box pentest, I have to rely on some tools for OS fingerprinting. Nmap guesses it to be either Nokia IPSO 4.0 or 4.1Build19. Now I tried googling for that particular appliance (IP650) and I found out that the appliance is too old as its existence dates back as early as 1999. I'm having a hard time trying to find anything that can be useful for this Usually the next stage would be to try to exploit it - providing that is allowed for by your penetration-testing contract. (It should be, otherwise it's more of an audit rather than a pen-test.) If all else fails, do you tell the customer that it is safe to ignore those warnings and vulnerabilities because you, on a hacker's perspective, was not able to penetrate the network by making use of those vulnerabilities found, that the hacker might have a hard time as well and eventually opt for another target? I don't like to. If you aren't able to break it, just say so. As a pen-tester, you haven't got enough information to say if it's safe. Obviously, if you break it, it's not safe, otherwise you don't know. cheers, Jamie -- Jamie Riden, CISSP / jamesr@europe.com / jamie@honeynet.org.uk UK Honeynet Project: http://www.ukhoneynet.org/ ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Pen Testing Tippingpoint, Jeremiah Brott |
|---|---|
| Next by Date: | Re: [Full-disclosure] SECNICHE : Dwelling Security is On the Run, dcdave |
| Previous by Thread: | Pentesting Old unsupported Firewall Appliances, Harold Castro |
| Next by Thread: | RE: Pentesting Old unsupported Firewall Appliances, Clemens, Dan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |