
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 170
nothingelse.Theexistenceofanyactiveportmustbe
investigatedtodetermineiftheyarerelevanttothe
routingfunctions.Whilethereisnoknown
vulnerabilityontheseportsthatarerelatedtothe
Eiconcardroutingapplication, theyshouldbefiltered
attheWANinterfaceiftheyareofnouse.
ThefactthattheOStypeoftherouterisdetected
deservesahighlynegativecomment.Thisallowsa
hackertoinitiateOS/platform/productspecific
attacks.However,withoutafirewallservicerunning
onit,suchweaknesscanhardlybeeliminated.
Outside
Router_Eico
ncard
NetBrute Nil N/A
Outside
Router_Eico
ncard
Share
Scanner
Nil N/A
Outside
Router_Eico
ncard
Sub_Net 8080 N/A Therouterdoesnotactasaproxy.Therefore,access
tothisportshouldbefilteredatthe WANinterface.
* TCP8080issubjecttotheRingZeroTrojanattack.
Kommentare zu diesen Handbüchern