20000815 Firewall-1 session agent 3.0 -> 4.1, dictionnary and brute force attackmailing list
http://www.securityfocus.com/archive/1/76389 CVE-2000-1037
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (1)
Record summary
CVE-2000-1037 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCheck Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (1)ExploitDB exploitby Nelson BritoNot analyzed1 file
ExploitDBCheck Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (2)ExploitDB exploitby Gregory DucheminNot analyzed1 file
References
31662vdb entry
http://www.securityfocus.com/bid/1662 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1037