Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts
Wednesday, April 26, 2017
Egresser Tool to Enumerate Outbound Firewall Rules
Egresser Tool to Enumerate Outbound Firewall Rules

Egresser is a tool to enumerate outbound firewall rules, designed for penetration testers to assess whether egress filtering is adequate from within a corporate network. Probing each TCP port in turn, the Egresser server will respond with the clients source IP address and port, allowing the client to determine whether or not the outbound port is permitted (both on IPv4 and IPv6) and to assess whether NAT traversal is likely to be taking place.
How it Works
The server-side script works in combination with Iptables - redirecting all TCP traffic to port 8080 where the real server resides. The server-side script is written in Perl and is a pre-forking server utilising Net::Server::Prefork, listening on both IPv4 and IPv6 if available. Any TCP connection results in a simple response containing a null terminated string made up of the connecting clients IP and port. Feel free to use Telnet to interact with the service if you are in a restricted environment without access to the Egresser client (our Egresser server can be found at egresser.labs.cyberis.co.uk, which you are free to use for legitimate purposes).
The client is also written in Perl and is threaded for speed. By default it will scan TCP ports 1-1024, although this is configurable within the script. It is possible to force IPv4 with the -4 command line argument, or IPv6 with -6; by default it will choose the protocol preferred by your operating system. If you want to explicitly list all open/closed ports, specify the verbose flag (-v), as normal output is a concise summary of permitted ports only.
It is recommended that outbound firewall rules are restricted within corporate environments to ensure perimeter controls are not easily circumvented. For example, inadequate egress filtering within an organisation would allow a malicious user to trivially bypass a web proxy providing filtering/AV/logging simply by changing a browsers connection settings. Many other examples also exist - many worms spread over SMB protocols, malware can use numerous channels to exfiltrate data, and potentially unauthorised software (e.g. torrent/P2P file sharing) can freely operate, wasting corporate resources and significantly increasing the likelihood of malicious code being introduced into the environment.
Generally, it is recommended that all outbound protocols should be restricted, allowing exceptions from specific hosts on a case-by-case basis. Web browsing should be conducted via dedicated web proxies only, with any attempted direct connections logged by the perimeter firewall and investigated as necessary.
Egresser is a simple to use tool to allow a penetration tester to quickly enumerate allowed ports within a corporate environment.
Download Egresser
Go to link download
Tuesday, April 11, 2017
SmartSPLAT Tool to troubleshoot Checkpoint firewall issues and perform management tasks
SmartSPLAT Tool to troubleshoot Checkpoint firewall issues and perform management tasks

Smart SPLAT is a freeware software to troubleshoot Checkpoint firewall issues and perform management tasks.
It periodically checks for an update and when a new release is published, updates itself via the SmartSPLAT web site.
SmartSPLAT lets you connect to your firewall via secure channel SSH
Critical commands like cpstop, kill, reboot and etc. deleting a license or similar commands that can cause your firewall not to function properly are colored red protected by checkboxes and shows confirmation dialogs.
In this project we have used an ssh Library based on the Poderosa project.
For file transfer operations, SmartSPLAT uses putty pscp.exe, to work with SCP /etc/scpusers/ file should be modified.
Smart SPLAT has a script named preparescp. It checks if user exists at /etc/scpusers/ if not, adds a line for it.
Download SmartSPLAT
Go to link download
Labels:
and,
checkpoint,
firewall,
issues,
management,
perform,
smartsplat,
tasks,
to,
tool,
troubleshoot
Sunday, March 5, 2017
Webfwlog 1 01 Web Based Firewall Log Analysis and Reporting
Webfwlog 1 01 Web Based Firewall Log Analysis and Reporting

Webfwlog is a flexible web-based firewall log analyzer and reporting tool. It supports standard system logs for linux, FreeBSD, OpenBSD, NetBSD, Solaris, Irix, OS X, etc. as well as Windows XP®. Supported log file formats are netfilter, ipfilter, ipfw, ipchains and Windows XP®. Webfwlog also supports logs saved in a database using the ULOG or NFLOG targets of the linux netfilter project, or any other database logs mapped with a view to the ulogd schema. Versions 1 and 2 of ulogd database schemas are supported.
Webfwlog fully supports IPv6 for database logs, and netfilter and ipfilter system logs.
With Webfwlog you can design reports to use on your logged data in whatever configuration you desire. Included are example reports as a starting point. You can sort a report with a single click, "drill-down" on the reports all the way to the packet level, and save your reports for later use. You can also create a link directly to any saved report.
PREREQUISITES
- A web server with PHP >= 4.1
- Log files in standard netfilter, ipfilter, ipfw, ipchains or Windows XP® format
or database logs populated with the ULOG or NFLOG target of netfilter,
or other database logs mapped with a view to ulogd version 1 or 2 schemas
- A MySQL or PostgreSQL database server:
- MySQL >= 3.23.52 or any production release of 4.x or 5.x
- MySQL >= 5 required for IPv6
- PostgreSQL >= 7.1
- PostgreSQL >= 7.4 required for IPv6
- Your favorite web browser.
Windows XP® support provided via Cygwin.
Download Webfwlog 1.01
Go to link download
Saturday, March 4, 2017
Isowall A mini firewall that completely isolates a target device from the local network
Isowall A mini firewall that completely isolates a target device from the local network

This is a mini-firewall that completely isolates a target device from the local network. This is for allowing infected machines Internet access, but without endangering the local network.
Building
This project depends upon
libpcap, and of course a C compiler.On Debian, the following should work:
# apt-get install git gcc make libpcap-dev
# git clone https://github.com/robertdavidgraham/isowall
# cd isowall
# makeThis will put the binary
isowall in the local isowall/bin directory.This should also work on Windows, Mac OS X, xBSD, and pretty much any operating system that supports
libpcap.Running
First, setup a machine with three network interfaces.
The first network interface (like
eth0) will be configured as normal, with a TCP/IP stack, so that you can SSH to it.The other two network interfaces should have no TCP/IP stack, no IP address, no anything. This is the most important configuration step, and the most common thing youll get wrong. For example, the DHCP software on the box may be configured to automatically send out DHCP requests on these additional interfaces. You have to go fix that so nothing is bound to these interfaces.
To run, simply type:
# ./bin/isowall --internal eth1 --external eth2 -c xxxx.confwhere
xxxx.conf contains your configuration, which is described below.Configuration
The following shows a typical configuration file.
internal = eth1
internal.target.ip = 10.0.0.129
internal.target.mac = 02:60:8c:37:87:f3
external = eth2
external.router.ip = 10.0.0.1
external.router.mac = 66:55:44:33:22:11
allow = 0.0.0.0/0
block = 192.168.0.0/16
block = 10.0.0.0/8
block = 224.0.0.0-255.255.255.255The target device we are isolating has the indicated IP and MAC address.
Only IPv4 and ARP packets are passed.
Outbound packets must have the following conditions:
- source MAC address equal to
internal.target.mac - destination MAC address equal to
external.router.mac - EtherType of 0x800 or 0x806
- source IPv4 address equal to
internal.target.ip - destination IPv4 address within an
allowrange, but not in ablockrange - if an ARP packet, then the destination IPv4 address must equal that
external.router.ip - if an ARP packet, must be a "request"
Inbound packets must have the following conditions:
- destination MAC address equal to
internal.target.mac - source MAC address equal to
external.router.mac - EtherType of 0x800 or 0x806
- destination IPv4 address equal to
internal.target.ip - source IPv4 address within an
allowrange, but not in ablockrange - if an ARP packet, then the source IPv4 address must equal that
external.router.ip - if an ARP packet, then must be a "reply"
Download Isowall
Go to link download
Subscribe to:
Posts (Atom)