CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-09
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default checking for password strength in NG/AI and NGx Administrators

Hi All,

I've been tasked to do a security audit for all of our firewall
Administrators. One of the tasks is to audit the password strength
anyone who can log into the Provider-1 and CMAs regardless of
privileges.

Anyway, I have access to the $MDSDIR/conf/mdsdb/cp-admins.C file
and I can see all user accounts in here and the password is encrypted.
I would like to run this password through a some kind of password
cracker and see how strong these passwords are because I can create
a P-1 supper user with a password of "123456", which is NOT good.
This is what I see in the file:

[root@Linux-lab mdsdb]# more cp-admins.C
(
:version (6.08)
: (admin
:AdminInfo (
:chkpf_uid ("{4DD1C39A-D709-11DC-B0AE-0AFA61096565}")
:ClassName (pv1_administrator)
:table (pv1_administrators)
:LastModified (
:Time ("Sat Feb 9 12:19:47 2008")
:By (localhost)
:From (Linux-lab)
)
:icon ("Provider-1/pv1_admin")
)
:GlobalSdbReadOnly (0)
:SdbReadOnly (0)
:administrator (true)
:auth_method ("Old User Password")
:connection_state (uninitialized)
:customer_perms ()
:days (127)
:fromhour ("00:00")
:internal_password (6b846265fd68a762707f8102a2d4711f1e26f479)
:msp_perm (80000000)
:pv1_auth_server ()
:sic_name ()
:tohour ("23:59")
:type (pv1_administrator)
:vsx_provisioning (true)
)
[root@Linux-lab mdsdb]#

Anyone know I can crack the checkpoint internal password string,
in this case, 6b846265fd68a762707f8102a2d4711f1e26f479

Any ideas?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-02-09
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 324
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: checking for password strength in NG/AI and NGx Administrators

Rather than a brute-force or dictionary attack through the GUI, there's no easy way to get the password in the clear. CP's password system is basic to say the least - the assumption is that if you're serious about authentication security, you'll outsource auth to a 3rd party (preferably two-factor based) authentication technology.

If I were to speculate, you could possibly try and run a dictionary attack using the authentication in dbedit or an equivalient command line tool. The success or otherwise of this would tell whether going down the path of 3rd-party authentication systems is required... :)

Good luck.
Reply With Quote
  #3 (permalink)  
Old 2008-02-09
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: checking for password strength in NG/AI and NGx Administrators

My P-1 supper users, myself included, use RSA SecurID for authentication.
Everyone with read-only access use checkpoint internal password for
authentication. However, checkpoint has no internal mechanism to force
complex password creation. Therefore, someone could be creating an
account with a very easy password such as "123456" and checkpoint will
NOT complain about it.

I am interested in a freeware that I can use to crack checkpoint password.
any ideas where I can get one? Thanks.
Reply With Quote
  #4 (permalink)  
Old 2008-02-10
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 324
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: checking for password strength in NG/AI and NGx Administrators

Not sure this solves your problem - if your issue is that you can create an admin with a cryptographically poor password, then "cracking" the password isn't going to prove anything, because the "problem" as you describe it will still exist even after you crack the existing passwords.

If such a tool exists that could decrypt the entry, and this was in the open, I would think that would be a big problem.... It ain't going to work that way!
Reply With Quote
  #5 (permalink)  
Old 2008-02-10
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: checking for password strength in NG/AI and NGx Administrators

corporate security dictates that password scheme must be complexed
and hard to guess. I am trying to enforce corporate security. There
are people who are lazy and create easy to guess password. Yes,
my problem still exists but I can tell those users to change the password
and make it harder to guess.

"If such a tool exists that could decrypt the entry, and this was in the open, I would think that would be a big problem.... It ain't going to work that way!"

I have to disagree with this. There are tools out there to crack Windows
and Unix password. Why is checkpoint password any different?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:51.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0