RE: UPDATE: [wcolburn@nmt.edu: SMTP relay through checkpoint fire wall]

From: Peter Bieringer (pb@bieringer.de)
Date: 02/22/02


Date: Fri, 22 Feb 2002 19:23:07 +0100
From: Peter Bieringer <pb@bieringer.de>
To: "Proescholdt, timo" <Timo.Proescholdt@brk-muenchen.de>, bugtraq@securityfocus.com


Hi,

sure this reply is also not posted on bugtraq :-(

but perhaps interesting for someone...

--On Thursday, February 21, 2002 12:55:49 AM +0100 "Proescholdt,
timo" <Timo.Proescholdt@brk-muenchen.de> wrote:

>
>> It's not just Checkpoint Firewall that has a problem with HTTP
> CONNECT.>
>> From what I can tell default installations of the CacheFlow web
>> proxy software, some Squid installations, some Apache
>> installations with proxying enabled, and some other web proxy
>> installations I haven't identified allow anyone to use the HTTP
>> CONNECT method. This is being
>
> Finjan-SurfinGate/4.0 ( NT ) is "vulnerable" , Trend Micro Interscan
> Viruswall ( 3.51 ) ( NT ) as well. Both do not seem to have a
> configuration
> switch to change this behaviour.

I have confirmed today also
Trend Micro Interscan Viruswall 3.6 / Linux / Build 1182

and found two interesting points, too:

1) if used also for SMTP, a firewall cannot block CONNECT to port 25
anymore. Solution: split installation to different machines (TM
license allows this).

2) Looks like content transported over CONNECT isn't scanned anymore,
theremore malicous code can be transported.

See also
http://www.aerasec.de/security/index.html?lang=en&id=ae-200202-051

They published some hints how to test and had setup web servers on
port 444 and 44444 containing the eicar.com file for checks.

        Peter Bieringer






Relevant Pages

  • No incoming email problem
    ... Mail is sent directly to my exchange server. ... ISP say they are not blocking port 25. ... What had I done by way of installations etc since Wednesday? ... Godfrey Nicholson ...
    (microsoft.public.windows.server.sbs)
  • Re: libapreq2 broken?
    ... Erik Norgaard wrote: ... given to the port make process. ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (freebsd-questions)
  • Re: Trend - Clients shows disconnected.
    ... Allthough the port number is rarely the same on ... any two installations. ... You can find the port number in Officescan console | ... > installed before SP2 the XP firewall blocks the ports Trend uses to ...
    (microsoft.public.windows.server.sbs)
  • broken ports
    ... does anybody know where to report broken ports, or, where to get ... information if/why a port currently is broken. ... in this case on my 5.4-RELEASE-p6 installations, ... enabled/disabled and which optional modules are installed) ...
    (freebsd-questions)
  • Re: Upgrade xorg 6.9 to 72
    ... while building the port "xdriinfo"? ... I've tried building Mesa 7.0 by hand ... X seems to work perfectly well without xdriinfo [since this machine's ... I believe that on some installations ...
    (freebsd-questions)