The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Weak TCP Sequence Numbers in Sonicwall SOHO Firewall


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Wed, 25 Jul 2001 17:17:28 -0600
From: Dan Ferris <danf@percept.com.>
To: [email protected]
Subject: Weak TCP Sequence Numbers in Sonicwall SOHO Firewall

This may not seem bad, but to me it seems that this defeats the point of NAT
if somebody can steal your sessions.  Note the section on TCP sequence
prediction.  This was a Sonicwall SOHO firewall.

=======
Host  (192.168.1.254) appears to be up ... good.
Initiating SYN half-open stealth scan against  (192.168.1.254)
Adding TCP port 80 (state open).
The SYN scan took 8 seconds to scan 1523 ports.
For OSScan assuming that port 80 is open and port 1 is closed and neither
are firewalled
Interesting ports on  (192.168.1.254):
(The 1518 ports scanned but not shown below are in state: closed)
Port       State       Service
23/tcp     filtered    telnet
67/tcp     filtered    bootps
80/tcp     open        http
137/tcp    filtered    netbios-ns
514/tcp    filtered    shell

TCP Sequence Prediction: Class=64K rule
                         Difficulty=1 (Trivial joke)

Sequence numbers: 3EC519BD 3EC613BD 3EC70DBD 3EC807BD 3EC901BD 3EC9FBBD
Remote operating system guess: Accelerated Networks - High Speed Integrated
Access VoDSL
OS Fingerprint:
TSeq(Class=64K)
T1(Resp=Y%DF=N%W=2000%ACK=S++%Flags=AS%Ops=MNW)
T2(Resp=N)
T3(Resp=Y%DF=N%W=2000%ACK=O%Flags=A%Ops=)
T4(Resp=Y%DF=N%W=2000%ACK=O%Flags=R%Ops=)
T5(Resp=Y%DF=N%W=0%ACK=S++%Flags=AR%Ops=)
T6(Resp=Y%DF=N%W=0%ACK=O%Flags=R%Ops=)
T7(Resp=Y%DF=N%W=0%ACK=S%Flags=AR%Ops=)
PU(Resp=Y%DF=N%TOS=0%IPLEN=38%RIPTL=148%RID=E%RIPCK=0%UCK=0%ULEN=134%DAT=E)


Nmap run completed -- 1 IP address (1 host up) scanned in 8 seconds
======

Dan Ferris
Percept Technology
mailto:danf@percept.com.
http://www.percept.com



<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру