Bugtraq mailing list archives

Re: Firewall-1 Security Advisory


From: joey () CPIO NET (Ejovi Nuwere)
Date: Thu, 29 Oct 1998 07:39:50 -0800


On Wed, 28 Oct 1998, Gary Gaskell wrote:

*And what about the default of the ports 256, 257, 258 and 259 appearing on
*every interface?  A little concerning, since they are not listed in the
*table of ports in the main manual.  Even more concerning when I'm told
*they are for secure remote support, logging and configuration control!
*This obscurity makes one rather nervous.

Also remote GUI's, putkey commands (public key exchanges), and if you dont
have the VPN modules I believe it uses a 40 bit encryption
algorithm FWZ1, or DES. never seen anything about those ports in any of
the manuals, never heard it mentioned in any of the classes.

Oh, and those ports are a really nice way to identify a FW-1 machine ;)

Ejovi.
joewee.



Current thread: