31 CheckPoint Firewall-1 web administration detection Firewalls 2003/11/14 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.3 Corrected the plugin structure and added the accuracy values in 1.3 tcp 80 open|send GET / HTTP/1.0|sleep|close|pattern_exists HTTP/#.# ### *ConfigToolPassword* 90 This plugin was written with the ATK Attack Editor. CheckPoint Firewall-1 with activated web administration Configuration If the Firewall-1 web administration is running, users could login the device over HTTP. Do not allow remote administration over HTTP. 30 minutes Yes Yes Yes Low 7 8 5 6 Medium Nessus is also able to do the same check. 11518 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch