what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

NCPbypass.txt

NCPbypass.txt
Posted Jul 2, 2006
Authored by ml3

The NCP VPN/PKI client version 8.30 suffers from a UDP bypass vulnerability in its provided firewall functionality.

tags | advisory, udp, bypass
SHA-256 | 0e50b70bed9f72501c61a0a43c6b1d570b5941d9c2d3be52bf78cf23a278143a

NCPbypass.txt

Change Mirror Download
Application:     NCP VPN/PKI Client
Site: http://www.ncp.de
Version: 8.30, Build 59 and maybe lower
OS: Windows
Possible problem: UDP Bypassing


Product:
========
NCP's Secure Communications provides a comprehensive portfolio of
products for implementing total solutions for high-security remote
access. These software-based products comply fully with all current
major technology standards for communication and encryption, as defined
by the IETF (Internet Engineering Task Force) and ITU (International
Telecommunication Union). Consequently all products can be smoothly
integrated into any existing network and communication architectures.
Your Internet infrastructure, which may already consist of third-party
security and access components, can be further used without changes -
thus avoiding any unnecessary administrative costs.


About:
=====
There are two 'firewalls' part of the NCP VPN/PKI Client. The 'Link
Firewall' and some sort of 'personal firewall'. The function of the
'Link Firewall' is to prevent any traffic between an untrusted net and
an active vpn connection. The 'Link Firewall' just can be turned on or
off. The 'personal firewall' can be configured with rules like all of
you probably know from other similar personal firewalls.

For my tests I activated the 'Link Firewall' and configured the
'personal firewall' to prevent any in- or outbound traffic.


UDP Bypassing, both directions
=====
During some configuration tests for the NCP VPN/PKI Client I noticed
that the machine still received an ip-address via DHCP, although both
firewalls were enabled. So I did some research and figured out that it's
possible to send and receive data from and to another machine. On the
client with the NCP VPN/PKI Client installed you have to use port 68
(UDP, sending and receiving) and on the 'other side' you have to use
port 67 (UDP, sending and receiving).

For testing I wrote a little perl script which looks so unbelievable
embarrassing that I better show how to use the bug using hping ;)

So to send something to the machine secured with the NCP VPN/PKI Client
use hping like this.

hping.exe -2 -c 1 -s 67 -p 68 -e "You should've never gone to Hollywood"
$TARGET

To send data from the machine with the NCP VPN/PKI Client to another pc
use hping like this.

hping.exe -2 -c 1 -s 68 -p 67 -e "You should've never trusted Hollywood"
$TARGET

This will also work if you're connected to a VPN.


History:
========
2006-05-12: Found the possible problems
2006-05-16: Mailed the vendor, no response
2006-05-22: Mailed the vendor again
2006-05-23: The vendor replied
2006-05-26: The vendor replied with technical details


ports

--
SYS 64767

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close