NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] How do you prevent the Firewal operating system from being identified?



Make sure Telnet, finger and SNMP are blocked from the Internet.  Also, if
using security servers, modify the banenrs from within the FW GUI to hide
the fact that you're running a Checkpoint firewall.  The defaults are
probably well known amongst the hacking community.
Telnet is the most common way of finding out what version the host is.
The telnet banner can be stripped if necessary (eg modify inetd.conf under
UNIX to start telnetd with a -h).

----- Original Message -----
From: Fernandes, Andy (ANDF) <[email protected]>
To: <[email protected]>
Sent: 21 March 2001 20:40
Subject: [FW1] How do you prevent the Firewal operating system from being
identified?


>
> Hello all:
>
> I have been told that it is possible to identify a Checkpoint Firewall's
> operating system type, build and version type from the outside by
examining
> banners and using various fingerprinting techniques. How can a Checkpoint
> firewall be protected against this vulnerability?
>
> Andy
>
>
>
============================================================================
====
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
>
============================================================================
====
>


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.