RE: pushing exploits through the Firewall



Ok Ill answer between ============ as usual =)

-----Mensaje original-----
De: Mike Gilligan [mailto:mikewgilligan@xxxxxxxxxxx]
Enviado el: Domingo, 12 de Febrero de 2006 02:42 a.m.
Para: pen-test@xxxxxxxxxxxxxxxxx
Asunto: pushing exploits through the Firewall

Hi group
Say a pentester manages to discover a vulnerable version of BIND running on
an external DNS server and has successfully sourced an exploit for the vuln.

==================
Sounds doable and usable =)
==================

I'm curious how it would be possible to launch the exploit against the
server when a packet filtering device and stateful inspection Firewall sit
between the pentester and the vuln host. It would seem at first glance that
this is not a viable option. How else might one go about exploiting the
vuln?

==================
I would just run the exploit, unless you have an IPS you are pretty much
doable since well firewall is just a filter, should let the port 53 go, if
you have one of tose 1 does it all then just change the shellcode or rewrite
the exploit, ala maybe sending tons of broken up packets and using IDS
bypassing techniques ....

Encrypted shellcodes work nicely to, have it exchange rc4 keys and voila it
wont detect the uname -a;id trigger string again if it has the IDS module
on, a simple firewall should just let you pass =)
==================


Mike

_________________________________________________________________
Get MSN Hotmail alerts on your mobile.
http://mobile.msn.com/ac.aspx?cid=uuhp_hotmail


----------------------------------------------------------------------------
--
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are

futile against web application hacking. Check your website for
vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers
do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
----------------------------------------------------------------------------
---





------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------



Relevant Pages

  • Re: Hacking to Xp box
    ... I think there was a misunderstanding in the firewall point: ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ...
    (Pen-Test)
  • Re: Hacking to Xp box
    ... I think there was a misunderstanding in the firewall point: ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ...
    (Pen-Test)
  • RE: Hacking to Xp box
    ... I think there was a misunderstanding in the firewall point: ... Regarding ICMP backdoors, this technique was first use by some skilled guy ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ...
    (Pen-Test)
  • Re: Hacking to Xp box
    ... I think there was a misunderstanding in the firewall point: ... you need to find some vulnerability that could be ... > restricts most of the attacks that use anonymous connections. ... > Audit your website security with Acunetix Web Vulnerability ...
    (Pen-Test)
  • RE: Hacking to Xp box
    ... If the firewall doesn't block ICMP, ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ... > login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
    (Pen-Test)