Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: Exploit through firewall question

Subject: Re: Exploit through firewall question
Date: Tue, 18 Jul 2006 21:18:40 -0500
There can be a multitude of things affecting you here.
1. Good that you notify these folks. Just out of curiosity, why would
you perform vul assesment from behind a firewall?

2. The Framework could be sending over dozens of different ports, most
of which are probably blocked as incoming at the firewall, even if they
are part of an established session. They could also be blocked as
outbound, again, depending on ruleset.

3. I'm not sure if you are referring to the source or destination port
here. The source port really wont matter that much if the outbound rules
on your firewall are wide open. If the firewall is watching outbound
connections, then yes, you need to use ports that the firewall will
tolerate. If you are referring to the destination port, then you must
use the default port of the service that is being exploited. (assuming
the target system is using default ports). Its important that you use
these ports because that is how the target OS is determining what
services to pass the network request to.

4. This almost seems as though you aren't fully establishing a
connection. (the handshake process isn't successful)

5. The result of the exploit will depend on a.) whether or not it was
successful and b.) what payload you are using in conjunction with the
exploit.

Hope this helps

-Brad

mr.nasty@ix.netcom.com wrote:
I'm using MetaSploit to test a box for a variety of vulnerabilities. To get 
to the box I have to go through our firewall.


1) I notify our network and ids people

2) I always get that the system is not vulnerable but I feel it's because of 
the firewall.

3) Should I be testing this using port 80 (i.e. on a telnet buffer overflow) 
or just go straight to port 23?

4) here's the output: Connection failed: Connection failed: Operation now in 
progress

5) if it is sucessful will it automagically open a cmd line or remote session?


Thanks

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to 
rise, 
you need to proactively protect your applications from hackers. Cenzic has 
the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------


  

Attachment: signature.asc
Description: OpenPGP digital signature

<Prev in Thread] Current Thread [Next in Thread>