Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Kerio personal firewall multiple bugs

  CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall

From:SECURITEAM <support_(at)_securiteam.com>
Date:28.04.2003
Subject:[NEWS] UDP Bypassing in Kerio Firewall (UDP Scan)

The following security advisory is sent to the securiteam mailing list, and can be found at the
SecuriTeam web site: http://www.securiteam.com
- - promotion

In the US?

Contact Beyond Security at our new California office
housewarming rates on automated network vulnerability
scanning. We also welcome ISPs and other resellers!

Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
- - - - - - - - -



 UDP Bypassing in Kerio Firewall (UDP Scan)
------------------------------------------------------------------------


SUMMARY

<http://www.kerio.com/us/products.html> Kerio develops a free firewall
that is shipped with default rules. Every incoming / outgoing packet is
compared against the default rule-set. As the first rule accepts incoming
packets if remote port is equal to 53 (DNS) the firewall can be easily
bypassed by setting the source port of the attack to 53.

DETAILS

Vulnerable systems:
* Kerio Firewall version 2.1.4

Exploit:
Using the following line will allow you to scan port 1900 on a remote
server:
nmap -v -P0 -sU -p 1900 192.168.0.5 -g 53


ADDITIONAL INFORMATION

The information has been provided by  <mailto:conde0@telefonica.net> David
F. Madrid.



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to:
list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental,
consequential, loss of business profits or special damages.



About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru