Telecom and Logistics Associates 

new6.gif (1031 bytes) TLAalert    Security Service 

Translate this page from:  publication: Christian ALT 
  Save Time and Money

TLAnews: Security NEWs Service

 updated 6.7.2000
5.7.2000
SecurityCheckpoint vulnerability found in Firewall-1
T
he vulnerability was found by SecureXpert Labs and for the moment no patch is available. This can easily be reproduced from a Linux system.

En français: Checkpoint une vulnerabilité a été trouvée dans Firewall-1
La vulnérabilité a été trouvée par SecureXpert Labs et pour le  moment il n'y a pas de "patch" disponible.
Cela peut facilement être reproduit sur une machine Linux

Home
Consulting
Tech Doc
FW-1 FAQ
Training
Products
TLAnews
Archive
Advertising
 

TLAnews.com
Information for security concerned people

 

Register to TLAnews letter

English version

Check Point Firewall-1 includes a component called the SMTP Security Server. This is an SMTP proxy, the use of which is required by several of Firewall-1's advanced SMTP email processing capabilities, including CVP-based virus scanning and URI filtering.

The  SMTP Security Server in Firewall-1 4.0 and 4.1
on Windows NT
and Solaris 2.6  are vulnerable to a simple network-based attack which can increase the firewall's CPU utilization to 100%.

Sending a stream of binary zeros over the network to the SMTP port on the firewall
raises the target system's load to 100% while the load on the attacker's
system machine remains relatively low.  This can easily be reproduced from
a Linux system using netcat with an input of /dev/zero, with a command such as
"nc firewall 25 < /dev/zero".

Résumé en français
Si le serveur SMTP est configuré sur un firewall de Checkpoint en version 4.0 ou 4.1, il est vulnérable à une attaque simple par le réseau qui peut augmenter l'utilisation du processeur à 100%. C'est le composant appelé "SMTP Security Server" qui est sensible, il est utilisé pour la messagerie et pourles contrôles anti-virus.

Pour le moment cela n'est confirmé que sous Windows NT 4.0 et solaris 2.6.

Il suffit d'envoyer une séquence de zéros binaire sur le port SMTP du serveur pour augmenter la charge du processeur à 100%. Cela peut facilement être reproduit sur une machine Linux en  utilisant la commande:

nc firewall 25 < /dev/zero


Christian Julien <christian.julien@enac.fr> confirms that fw1 4.0 SP5, with Solaris 2.6 is also vulnerable with CPU climbing up aldow not saturated at 100%. For Details see below.

Initial vulnerability advice

FSC Internet Corp. / SecureXpert Labs

SecureXpert Labs Advisory [SX-20000620-3] - Partial Denial of
Service in Check Point Firewall-1 on Windows NT

Summary

The SMTP Security Server component of Check Point Firewall-1 4.0 and 4.1 is
vulnerable to a simple network-based attack which raises the firewall load to 100%.

Details

Check Point Firewall-1 includes a component called the SMTP Security Server.
This is an SMTP proxy, the use of which is required by several of Firewall-1's advanced SMTP email processing capabilities, including CVP-based virus scanning and URI filtering.

The Check Point Firewall-1 SMTP Security Server in Firewall-1 4.0 and 4.1
on Windows NT is vulnerable to a simple network-based attack which can increase the firewall's CPU utilization to 100%.

Sending a stream of binary zeros over the network to the SMTP port on the firewall
raises the target system's load to 100% while the load on the attacker's
system machine remains relatively low.  This can easily be reproduced from
a Linux system using netcat with an input of /dev/zero, with a command such as
"nc firewall 25 < /dev/zero".

This vulnerability could allow a very quick and easy distributed attack
on Check Point Firewall-1.

Status

Check Point Software Technologies has been informed of this vulnerability, and
has assigned it incident ID# TT44913.  As of June 20, 2000 Check Point
has stated that a fix for this vulnerability will NOT be included in Service
Pack 2 (SP-2) for Check Point firewall-1 4.1, but it will "probably be included
in SP-3".

Credits

Mike Murray, SecureXpert Labs
Max Degtyar, SecureXpert Labs
Richard Reiner, SecureXpert Labs

About SecureXpert DIRECT

SecureXpert DIRECT is an advance security advisory service provided by
SecureXpert Labs.  Subscriptions are free of charge and may be obtained
online at http://www.securexpert.com/services.html.

Update details for Solaris 2.6

1) Avec fw1 4.0 SP5, sur Solaris 2.6, cela donne aussi un ecroulement du
CPU. Cependant, la machine accepte malgre tout de la charge, surement
parce que la run-queue n'est pas saturee.

sar -u 5 100:
09:58:41     %usr    %sys    %wio   %idle
09:58:46      58      42       0       0
09:58:51      61      39       0       0
09:58:56      57      40       1       2
09:59:01      60      40       0       0
09:59:06      63      37       0       0
09:59:11      62      38       0       0
09:59:16      58      41       0       0
09:59:21      58      42       0       0
09:59:26      54      46       0       0
09:59:31      54      43       1       2
09:59:36      59      41       0       0
09:59:41      58      41       1       0
09:59:46      54      46       0       0
09:59:51      60      40       0       0
09:59:56      49      39       1      11
10:00:01      54      37       4       5
10:00:06      58      38       1       4
10:00:11      58      37       0       5
10:00:16      57      43       0       0
.......
10:01:36      61      39       0       0
10:01:41      61      39       0       0
10:01:46      63      37       0       0
10:01:51      58      41       0       1
10:01:56      56      44       0       0
10:02:01      60      40       0       0
10:02:06      47      35       0      18
10:02:11       0       2       0      98
10:02:16       2       3       0      95
10:02:21       1       4       0      95
10:02:26       0       3       0      96

 
Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: July 06, 2000 .

All information provided is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the facts of the particular situation.