Advertisement
Promo

Security threats Toolkit

Check Point warns firewall can be breached

Published: 05 Feb 2004 08:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two flaws in Check Point Software's flagship firewall software could allow an attacker to crash or compromise its firewall products, the company said on Wednesday.

The flaws -- found by security firm Internet Security Systems (ISS) -- may give intruders access to corporate networks through the devices designed to keep attackers out.

"Really controlling the firewall is controlling the gatekeeper for the network," said Dan Ingevaldson, director of vulnerability researcher and development for ISS. "If [an attacker] can control all the data going in and out -- really, the game is over at that point."

Check Point released a patch for its latest line of firewalls, the NG, or Next Generation series. The patch corrects a flaw in the way the software inspects Web data passing through the device. The second flaw affects the company's earlier virtual private network product, VPN-1, and won't be fixed, as Check Point no longer supports the software.

"About 70 percent [of our customers] or better are on NG," said Mark Kraynak, product marketing manager for Check Point. "The [earlier version] is no longer supported, so customers still on [that version] are in the process of migrating."

Ingevaldson said the vulnerabilities are serious, but that writing the code to exploit the issues is not easy.

"If you look at the history of the vulnerabilities in Check Point, a lot of them have been theoretical," he said. "In this case, what we are looking at is a machine working in a default environment, in default conditions, and they are still vulnerable."

Both Check Point and ISS have released advisories on the issues.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
87 out of 154 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters