31
CheckPoint Firewall-1 web administration detection
Firewalls
2003/11/14
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.3
Corrected the plugin structure and added the accuracy values in 1.3
tcp
80
open|send GET / HTTP/1.0|sleep|close|pattern_exists HTTP/#.# ### *ConfigToolPassword*
90
This plugin was written with the ATK Attack Editor.
CheckPoint Firewall-1 with activated web administration
Configuration
If the Firewall-1 web administration is running, users could login the device over HTTP.
Do not allow remote administration over HTTP.
30 minutes
Yes
Yes
Yes
Low
7
8
5
6
Medium
Nessus is also able to do the same check.
11518
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch