30
CheckPoint Firewall-1 telnet authentication detection
Firewalls
2003/11/14
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.4
Corrected the plugin structure and added the accuracy values in 1.4
tcp
256
open|sleep|close|pattern_exists Check Point FireWall-1 Client Authentication Server running on
90
This plugin was written with the ATK Attack Editor.
CheckPoint Firewall-1 with activated telnet administration
Configuration
If a Firewall-1 Client Authentication Server is running, users could login the device over telnet. Telnet has no encryption and sensitive data may be sniffable.
Do not allow remote administration over telnet.
Approx. 15 minutes
Yes
Yes
Yes
Low
Low
Nessus is able to do the same check.
10675
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch