Re: Firewall assessment

From: Jorge Lozano (lozano_jorge_at_yahoo.com)
Date: 08/25/03

  • Next message: Mariusz Burdach: "RE: Firewall assessment"
    Date: Mon, 25 Aug 2003 09:01:07 -0700 (PDT)
    To: Sasa Jusic <sjusic@pamela.zesoi.fer.hr>, "'pen-test@securityfocus.com'" <pen-test@securityfocus.com>
    
    

    Check the OSSTMM methodology, there's a whole section
    about checking vulnerabilities on firewalls and a list
    of recomended tools for that purpose.

    You can get the methodology here:

    http://www.isecom.org/projects/osstmm.htm

    Cheers

    --- Sasa Jusic <sjusic@pamela.zesoi.fer.hr> wrote:
    > Hi everyone,
    >
    >
    > This interesting discussion about firewall
    > enumeration tools, made me ask
    > one closely related question.
    >
    > I would like to know what are the usual steps when
    > doing a pen test on the
    > firewall?
    >
    > Besides looking for potential vulnerabilities in the
    > actual firewall device
    > (by running some of the vulnerability scanning tools
    > like Nessus, ISS,
    > Retina etc), I am also interested in other automated
    > or manual tests which
    > could be useful for finding other potential security
    > weaknesses
    > (configuration errors, VPN services etc.).
    >
    > I know that this is very general question, and that
    > it depends on the
    > situation and environment where the tests are made,
    > but I would like to hear
    > some general ideas and techniques from people with
    > experience in this area.
    >
    >
    > Thanks,
    >
    > Sasa Jusic
    > e-mail:sasa.jusic@zesoi.fer.hr
    >
    >
    ---------------------------------------------------------------------------
    > Attend Black Hat Briefings & Training Federal,
    > September 29-30 (Training), October 1-2 (Briefings)
    > in Tysons Corner, VA; the world<92>s premier
    > technical IT security event. Modeled after the
    > famous Black Hat event in
    > Las Vegas! 6 tracks, 12 training sessions, top
    > speakers and sponsors.
    > Symantec is the Diamond sponsor. Early-bird
    > registration ends September 6 Visit:
    > www.blackhat.com
    >
    ----------------------------------------------------------------------------
    >

    __________________________________
    Do you Yahoo!?
    Yahoo! SiteBuilder - Free, easy-to-use web site design software
    http://sitebuilder.yahoo.com

    ---------------------------------------------------------------------------
    FREE Trial!
    New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL
    and PROFESSIONAL TL software. Fast, reliable vulnerability assessment
    technology powered by the award-winning FoundScan engine. Try it free for 21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    ----------------------------------------------------------------------------


  • Next message: Mariusz Burdach: "RE: Firewall assessment"

    Relevant Pages

    • Re: My Windows XP system is 100% secure - nobody can get in
      ... Also he is right that new vulnerabilities should be checked elsewhere. ... MicroSoft last year of putting out a fix for a security ... What I have between my system and the Internet is a hardware firewall. ... I too have Charter cable as my ISP, and they provide me with a nice ...
      (alt.computer.security)
    • RE: Microsoft Cant Win.
      ... Subject: Microsoft Can't Win. ... vulnerabilities in anything ... ... an application-level firewall can also help protect the ... > reading through the email (security related mailing lists mostly) when I ...
      (Focus-Microsoft)
    • Re: My Windows XP system is 100% secure - nobody can get in
      ... What does your hardware firewall do besides simple packet filtering? ... > Also he is right that new vulnerabilities should be checked elsewhere. ... > MicroSoft last year of putting out a fix for a security ... > What I have between my system and the Internet is a hardware firewall. ...
      (alt.computer.security)
    • RE: Vulnerability assessment for small business
      ... > Say the customer has a firewall...but they don't host any services. ... You might just concentrate in 2 points: the firewall and the workstations. ... The main vulnerabilities for workstations that you could test for are their ... similar technology is not quite effective against targeted attacks. ...
      (Pen-Test)
    • Re: [fw-wiz] X server in a Firewall
      ... >> The more code, the more potential vulnerabilities, ... A X server running in a firewall ... I don't like remote access to my firewalls, but if I have to have it, then ... the ssh or web server port used to manage it ...
      (Firewall-Wizards)