what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

SX-20000620-3

SX-20000620-3
Posted Jul 7, 2000
Site securexpert.com

SecureXpert Labs Advisory [SX-20000620-3] - Partial Denial of Service in Check Point Firewall-1 on Windows NT. The SMTP Security Server component of Check Point Firewall-1 4.0 and 4.1 is vulnerable to a simple network-based attack which raises the firewall load to 100%.

tags | exploit, denial of service
systems | windows
SHA-256 | 61c0ad7d028e554c35d5167f8ebd20c832a6adbd1bb7c02554be5c77505b3562

SX-20000620-3

Change Mirror Download
FSC Internet Corp. / SecureXpert Labs

SecureXpert Labs Advisory [SX-20000620-3] - Partial Denial of
Service in Check Point Firewall-1 on Windows NT

Summary

The SMTP Security Server component of Check Point Firewall-1 4.0 and 4.1 is
vulnerable to a simple network-based attack which raises the firewall load to
100%.

Details

Check Point Firewall-1 includes a component called the SMTP Security Server.
This is an SMTP proxy, the use of which is required by several of Firewall-1's
advanced SMTP email processing capabilities, including CVP-based virus
scanning and URI filtering.

The Check Point Firewall-1 SMTP Security Server in Firewall-1 4.0 and 4.1
on Windows NT is vulnerable to a simple network-based attack which can increase
the firewall's CPU utilization to 100%.

Sending a stream of binary zeros over the network to the SMTP port on the firewall
raises the target system's load to 100% while the load on the attacker's
system machine remains relatively low. This can easily be reproduced from
a Linux system using netcat with an input of /dev/zero, with a command such as
"nc firewall 25 < /dev/zero".

This vulnerability could allow a very quick and easy distributed attack
on Check Point Firewall-1.

Status

Check Point Software Technologies has been informed of this vulnerability, and
has assigned it incident ID# TT44913. As of June 20, 2000 Check Point
has stated that a fix for this vulnerability will NOT be included in Service
Pack 2 (SP-2) for Check Point firewall-1 4.1, but it will "probably be included
in SP-3".

Credits

Mike Murray, SecureXpert Labs
Max Degtyar, SecureXpert Labs
Richard Reiner, SecureXpert Labs

About SecureXpert DIRECT

SecureXpert DIRECT is an advance security advisory service provided by
SecureXpert Labs. Subscriptions are free of charge and may be obtained
online at http://www.securexpert.com/services.html.

Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close