evolve or die

netscreen25.txt

netscreen25.txt
Posted Nov 2, 2002
Authored by H D Moore

Netscreen VPN solutions ship with an SSH daemon that is vulnerable to the SSH1 CRC32 bug. In the default configuration, SSH is not enabled on their devices and when enabled, it is expected that any CRC32 exploits used to attack said device will cause a crash and require a reboot. Original bug discovered by Michal Zalewski.

tags | advisory
MD5 | 5fed7ff8aace600e4148fcf25365f4e1

netscreen25.txt

Change Mirror Download

Discovered by: HD Moore
Products Tested: Netscreen-25 (All models expected to be vulnerable)
Vendor contacted: October 23rd
Vendor confirmed: October 23rd
CVE: CVE-2001-0144 covered this bug.

Original Bug discovered by: Michal Zalewski of the BindView RAZOR Team.

In February of 2001, BindView's RAZOR Team announced the SSH1 CRC32
compensation attack detector bug. After all was said and done, several
vendors found their SSH implementations were vulnerable. Netscreen seems
to have overlooked this for a year and 8 months.

By default the Netscreen does not ship with SSH enabled, and Netscreen
usually doesn't encourage their customers to even access the CLI on their
devices. However, in the GUI you can enabled SSH, and disable telnet. This
only opens SSH on the trusted interfaces, unless you specifically add
rules to forward to this interface/port. On a normal system with SSH
enabled, the unit will only be vulnerable to attackers on the trusted side.

If you use any of the CRC32 exploits out there, the unit will crash
immediately, and require a hard reboot. It does not appear from our
analysis that anything more than a crash can occur from this.

The vendor assured a response with an ETA to a fix by October 25th. After
trying to get more information from them a few times after October 25th
passed, it has fallen on deaf ears.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close