Advertisement
Promo

Industry watch Toolkit

Flaw detected in Check Point security

Dennis Fisher, eWeek ZDNet US

Published: 11 Jul 2001 11:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two of the most popular pieces of security software on the Internet contain a newly discovered flaw that could enable an intruder to send traffic through a firewall or possibly launch a denial-of-service attack.

Check Point Software Technologies' popular FireWall-1 and VPN-1 products have a vulnerability in the way they handle Reliable Data Protocol packets. Instead of verifying the source of the packets, the software only checks the destination (port 259 in this case) and makes sure that the RDP command is present before allowing the traffic into or out of the firewall or VPN gateway.

An attacker need only add a false RDP header to a normal User Datagram Protocol packet, and the traffic could be sent to port 259 on any host on either side of the firewall.

The vulnerability was discovered by Inside Security, a German security concern. It affects Check Point FireWall-1 4.1 and VPN-1. Check Point, of Redwood City, California, has issued a patch for the vulnerability.

FireWall-1, widely used by telecommuters and other home broadband users, is among the most popular firewalls on the market.

The CERT Coordination Centre has also issued an advisory about the flaw, warning that, because an attacker would be able to pass traffic through the firewall or VPN gateway, software could be planted to be used later in a DoS attack.

In addition, if an attacker gains control of a machine inside of the firewall, he or she might also be able to establish a tunnel to push traffic through the firewall.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
49 out of 115 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Discussions

J.A. Watson J.A. Watson

Taking Out the Skype Garbage

Sunday 15 November 2009, 6:12 AM

4 comments
CA CA

No thomas..

Sunday 15 November 2009, 2:16 AM

12 comments
roger andre roger andre

Taking Out the Skype Garbage

Saturday 14 November 2009, 8:48 PM

4 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters