ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Check Point warns firewall can be breached

Published: 05 Feb 2004 08:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two flaws in Check Point Software's flagship firewall software could allow an attacker to crash or compromise its firewall products, the company said on Wednesday.

The flaws -- found by security firm Internet Security Systems (ISS) -- may give intruders access to corporate networks through the devices designed to keep attackers out.

"Really controlling the firewall is controlling the gatekeeper for the network," said Dan Ingevaldson, director of vulnerability researcher and development for ISS. "If [an attacker] can control all the data going in and out -- really, the game is over at that point."

Check Point released a patch for its latest line of firewalls, the NG, or Next Generation series. The patch corrects a flaw in the way the software inspects Web data passing through the device. The second flaw affects the company's earlier virtual private network product, VPN-1, and won't be fixed, as Check Point no longer supports the software.

"About 70 percent [of our customers] or better are on NG," said Mark Kraynak, product marketing manager for Check Point. "The [earlier version] is no longer supported, so customers still on [that version] are in the process of migrating."

Ingevaldson said the vulnerabilities are serious, but that writing the code to exploit the issues is not easy.

"If you look at the history of the vulnerabilities in Check Point, a lot of them have been theoretical," he said. "In this case, what we are looking at is a machine working in a default environment, in default conditions, and they are still vulnerable."

Both Check Point and ISS have released advisories on the issues.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
79 out of 146 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

B2B connectivity Network analyst city based investment bank 6 months

Skills Exp of B2B network architect design in finance environments Detailed exp of Cisco Catalyst products Detailed understanding and exp of BGP, ...

Network Engineer - Tier 1 Investment Bank - £95k

Detailed understanding and experience of BGP, OSPF, RIP routing protocols; Detailed understanding and experience of Check Point & Nokia firewall ...

SE, Pre-Sales, Checkpoint, CCSE, CCMSE, Security, VSX, NGX, London

Your Check Point experience will have been gained from either a large organisation, SI or Reseller. Sales Engineer (SE) required for pivotal role ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment