199 Symantec Raptor Firewall 6.5 weak ISN detection Firewalls 2004/09/09 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send ATK plugin 199 test request HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/1.1 501 Not Implemented *Simple, Secure Web Server 1.1* 70 Check is inspired by the Nessus plugin. Symantec Raptor Firewall 6.5 Other solutions and maybe the newer Symantec Enterprise Firewall 7.x Weak Authentication The target host seems to be a Symantec Raptor Firewall 6.5. This version may be vulnerable to TCP hijacking und spoofing attacks because of weak ISN generation. An attacker may be able to attack the environment over the network. You should upgrade your Symantec Raptor Firewall 6.5 to the new Symantec Enterprise Firewall 7.x or newer. See http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html for more details. Approx. 1 hour Yes http://www.securityfocus.com/bid/5387/exploit/ Yes Yes Medium 8 5 7 7 High Nessus is able to do the same check more accurate. CAN-2002-1463 5387 11057 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html