Proxy/firewall detection with PVSBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
HOME TIPS NEWS TOOLS DOWNLOADS VIRUS & SPYWARE FORUM BOOKS FREE MAGAZINES & PAPERS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Firewalls : Proxy/firewall detection with PVS
Posted by Max on 2006/10/10 6:27:18 (1121 reads)
Firewalls

During the past year, the Passive Vulnerability Scanner's rules were modified to detect network proxies and firewalls. This process also involved the reduction of reporting multiple browser types for different hosts running behind a NAT device or proxy.

As an example, what happens if PVS (or any sniffer, IDS, etc.) see's the following string in a packet leaving the network?


GET/StageOne/msnmsgr_exe/6_2_0_137/hungapp/0_0_0_0/00000000.htm?OS=5.1.2600.2.00010300.1.0&...
User-Agent: MSDW
Host: watson.microsoft.com

Well, most folks would think that:

1. The source IP is running MS Windows version 5.1.2600.2.etc and,
2. An error just occurred in MSN Messenger version 6.20.0.137 and,
3. The client is now sending an error message to Microsoft

nd, a year ago, the PVS would have flagged the machine for the items denoted above. However, within the last six months, Tenable has been undergoing a process of detecting where and why false positives are occurring within PVS. One of the problem areas was that PVS was flagging firewalls and proxies as the actual client. Mind you, I'm not talking about known NAT devices, as you can always turn off alerts going to/from those devices via the configuration file.

We decided to find a generic way of detecting proxies and firewalls on the network. The primary goal of this was to weed out false positives. A tangential benefit has been that companies can now detect firewalls and proxies that are deep within their corporate network.

more on http://blog.tenablesecurity.com/2006/10/proxyfirewall_d.html





Other articles
2008/7/18 14:34:52 - Symantec Releases Public Betas of Norton Internet Security 2009, Norton AntiVirus 2009
2008/7/18 14:10:39 - Agent.JEN Trojan spreads trough fake UPS Emails
2008/7/16 0:09:34 - How Cybercrime Became a Booming Business - Finjan Q2 2008 Web Security Trends Report
2008/7/14 7:20:37 - Gmail Is Free of eBay and PayPal Phishing - Forever !
2008/7/14 1:43:11 - New iPhone 3G Web Security Application

The comments are owned by the poster. We aren't responsible for their content.