Eicon Networks S92 Uživatelský manuál Strana 190

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 209
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 189
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 190
FirewallAttack
InformationGathering:
VisitthetargetGIACwebsite.Studyitthoroughly.Knowwhatbusinessitisin.
Knowwhatfunctionsthesiteisproviding.Fromthe“sitevisit”,wecantellwhat
applicationprotocolsareallowed(suchasHTTP,HTTPS,FTP,SMTP…etc.),andcan
makeaneducatedguesson therulebaseconfiguration.
Run NSLOOKUP againstGIAC.Atypicalsetupusedbymanyecommercesitesisto
haveasecondaryDNSserverrunningoffsitesomewhere(mostlylikelyintheISP’s
premise).NSLOOKUP tellsuswhatDNSserversareusedby GIAC.IfoneDNS
serverishostedoffsite,zonetransfertraffichastobeallowedbetweentheonsiteDNS
andtheoffsiteDNS. Thisopensupapotentialsecurityhole.
Collectinformationaboutthefirewall.Althoughthearchitecturemapwehaveon
handshowsclearlythatFW1istheprimaryfirewallinuse,thismighthavebeen
changedbythetimeweplantheattack.
AngelaOrebaughinherGCFWpractical
59
suggeststhatwedetectFW1byscanning
itsdefaultTCPportsat256,257,and258usingnmap
(nmap–n vv –P0–p256,257,258X.Y.Z.1.254),orbyrunningtracerouteagainst
GIAC’ssite(#traceroutewww.giacfortunes.com).IpersonallytriedusingRetina
(whichisbasedonnmaptechnology
60
)toscanaFW1installation,andfoundthatits
OStypecanbedetectedonlyifthestealthruleisdisabled.
ToomuchscanningmaytriggeranyhiddenIDSandblockoursubsequent
intrusionattempts!
Attacking–theport259route:
ThisattackallowsustobypassFW1andreachtheinternalhostsbehindit.
59
http://www.giac.org/practical/Angela_Orebaugh_GCFW.zip
60
http://www.eeye.com/html/Products/Retina/index.html
Zobrazit stránku 189
1 2 ... 185 186 187 188 189 190 191 192 193 194 195 ... 208 209

Komentáře k této Příručce

Žádné komentáře