199
Symantec Raptor Firewall 6.5 weak ISN detection
Firewalls
2004/09/09
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send ATK plugin 199 test request HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/1.1 501 Not Implemented *Simple, Secure Web Server 1.1*
70
Check is inspired by the Nessus plugin.
Symantec Raptor Firewall 6.5
Other solutions and maybe the newer Symantec Enterprise Firewall 7.x
Weak Authentication
The target host seems to be a Symantec Raptor Firewall 6.5. This version may be vulnerable to TCP hijacking und spoofing attacks because of weak ISN generation. An attacker may be able to attack the environment over the network.
You should upgrade your Symantec Raptor Firewall 6.5 to the new Symantec Enterprise Firewall 7.x or newer. See http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html for more details.
Approx. 1 hour
Yes
http://www.securityfocus.com/bid/5387/exploit/
Yes
Yes
Medium
8
5
7
7
High
Nessus is able to do the same check more accurate.
CAN-2002-1463
5387
11057
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html