
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 179
1723/tcpPPTP
8080/tcpproxy
8080/udpproxy
ThefunctionofW2K_VPNisservicingremoteaccess
VPNclientsandnothingelse.Theexistenceofany
activeportmustbeinvestigatedtodetermineifthey
arerelevanttotheremoteaccessfunctions.While
thereisnoknownvulnerabilityontheseportsthat
arerelatedtoRRAS,werecommendthe
considerationoffilteringthem(except1723,whichis
requiredbyPPTP).
Specificattentionmustbegiventoport7,9and13.
AccordingtoCisco,theseportsareknownassmall
serversthatcangetinvolvedinDoSattack
52
.
ThefactthattheOStypeoftheserverisdetected
deservesahighlynegativecomment.Thisallowsa
hackertoinitiateOS/platform/productspecific
attacks.However,withoutafirewallservicerunning
onit,suchweaknesscanhardlybeeliminated.
Kommentare zu diesen Handbüchern