Réf. : Penetration Testing a CheckPoint NG FW on Nokia

From: gilles.lami@SAFe-mail.net
Date: Fri Jan 07 2005 - 05:32:29 EST


Hi,

Maybe the CheckPoint as the ipsec agressive mode enable.
You could try the PSK Agressive Mode Attack.
You will need ikescan, ikeprobe, an ipsec client quiet configurable (to force agressive mode), and the ikecrack perl script and windump or caïn.
(google this terms, all are easy to find and all are free.)

You may also have a look on a complete description of the attack :
http://www.giac.org/practical/GCIH/Steve_Pitts_GCIH.pdf

Bye



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:12 EDT