Re: Pen-Testing Smoothwall FireWall



My guess:

Figure out wich version of SmoothWall is running on the pc (express,
corporate etc ...)

Try to do a firewall rules enumeration (open ports to ...)

Verify each running services to figure out if there is any public
exploits or else

Once again, only a guess ;)

Cheers

--
Machiavel

On 9/20/06, s-williams@xxxxxxxxxx <s-williams@xxxxxxxxxx> wrote:
Hey Guys,

I am doing a test and noticed that port 222, 80, 81 and a few others were open. After doing a few more test I believe the are using Smoothwall on one end of the network.

Do any have a few pointers on pen testing a Smoothwall box?
Sent via BlackBerry from T-Mobile

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Pen-Testing Smoothwall FireWall
    ... Subject: Pen-Testing Smoothwall FireWall ... Try to do a firewall rules enumeration (open ports to ...) ... Verify each running services to figure out if there is any public ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: The legal / illegal line?
    ... Barry Fawthrop wrote: ... in doing a pen test on a third party company? ... Cenzic Hailstorm finds vulnerabilities fast. ... as far as I am aware scanning for open ports is not illegal. ...
    (Pen-Test)
  • RE: The legal / illegal line?
    ... scanning without authorisation is illegal. ... as far as I am aware scanning for open ports is not illegal. ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: nmap -S option
    ... so the replies are going back to that spoffed address. ... Because when i use nmap with "nmap -sS targetaddress", nmap shows me open ports at the end of scan. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Pen-Testing Smoothwall FireWall
    ... Hey Guys, ... I am doing a test and noticed that port 222, 80, 81 and a few others were open. ... After doing a few more test I believe the are using Smoothwall on one end of the network. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)