Re: S-box Experiences

From: Fabio Pietrosanti (naif) (naif@sikurezza.org)
Date: 05/28/02


Date: Tue, 28 May 2002 12:29:36 +0200
From: "Fabio Pietrosanti (naif)" <naif@sikurezza.org>
To: pen-test@securityfocus.com


I'm also working on the evaluation of the products, not only from the security
point of view but also from the "management" point of view .

The box has 3 level of security:

- Low
    Internal Network can go outside with every protocol
    External Network can "ping" external interface of the s-box

- Medium

    Internal Network can go outside with every protocol
    External Network can't "ping" external interface of the s-box

- High
    Internal Network can go outside only for "certain" protocol
    External Network can't "ping" external interface of the s-box

The core of the technology is checkpoint so if you are looking for specific
bug in the implementation of the "firewalling feature" you have to break
checkpoint.

The things that you make wish to "audit" and that you will probably find vulnerable (
because the products is very young ) is:

- Management of the box from the internal network ( the webserver on the s-box
  ) that make intensive use of javascript and if think could be very easy to
  bypass authentication

- Management of the box through SMP ( the web based console on the ISP NOC )
  that use "a lot" of different program so probably there will be "a lot" of
  vulnerability and misconfiguration .

Also i think that in the future will be implemented feature like an snmp agent
( beeing linux could be a vulnerable ucd-snmp ? ) and other things like that.

The most wonderfull thing to try is to reverse the box and find out how to
install a custom version of linux without checkpoint but using iptables .

If so you can have a 5 interface firewall with 2x8mb of flash and 32mb of ram
based on a 133mhz MIPS processor. Good? :)

Sorry for my not so good english...

Regards

On Fri, May 24, 2002 at 10:07:19AM -0400, Kevin Dwyer wrote:
> Hello pen-test,
>
> I'm currently completing an evaluation of SofaWare's S-box
> firewall. It is a small embedded device that runs Linux and Checkpoint.
> Naturally, this is for lower end customers who don't need ultra-flexible
> rulesets and such. That said, I'm interested in hearing if anyone in the
> community has come across one of these devices and what their experiences
> were like. Have you found any gaping security issues? Any showstoppers?

-- 

Fabio Pietrosanti ( naif ) E-mail: naif@sikurezza.org - naif@blackhats.it PGP Key (DSS) http://naif.itapac.net/naif.asc -- "Hacking is the future of security research" R.Power, CSI Free advertising: www.openbsd.org Multiplatform Ultra-secure OS

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • RE: CISSP-ISSMP
    ... management say "that's nice", and move on. ... education, certification, experience, know-how, abilities, and ... Many 'security jobs' are nothing shy than that of an overly glorified ... Download FREE whitepaper on how a managed service ...
    (Pen-Test)
  • Re: Pentesting vs VA - was Pentesting tool - Commercial
    ... vulnerability assessment and management solution. ... I prefer these methods as the primary source of new vulnerability ... that their Reader product is one of the most insecure applications on ... Jaquith's good Security Metrics book) - ...
    (Pen-Test)
  • RE: security not a big priority?
    ... But I have found that upper management will only ... and push out the changes; management has to have this information to ... Network Security Engineer ... Network team with Project Management tasks. ...
    (Security-Basics)
  • RE: Information Security
    ... Totally agree with Matt on this one - configuration and change ... management is an important part of the overall security toolkit. ... A good place to start is to go to mitre's "making security measurable" ... CVSS: vulnerability risk scoring methodology ...
    (Security-Basics)
  • RE: Down with DHCP!!!!
    ... Managing/monitoring the DHCP pools as assignments yourself ... -Other management tools as in Asset ... Security Administrator ... Network Operations-ICW Group ...
    (Security-Basics)