CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-27
Member
 
Join Date: 2006-02-21
Location: 127.0.0.1
Posts: 56
Rep Power: 3
runcmd has an average reputation (10+)
Default SmartDefense Update CPAI-2006-033 / CVE-2006-1359

I've noticed that CheckPoint has indicated that some performance degradation may occur (depending upon traffic types) after enabling this protection. Has anyone noticed any adverse effects after enabling? Thanks!


Reference:

CheckPoint: Protection Against Microsoft Internet Explorer createTextRange () Vulnerability
http://www.checkpoint.com/defense/ad...ai-27-Mar.html

Microsoft Security Advisory (917077)
http://www.microsoft.com/technet/sec...ry/917077.mspx

CVE: Common Vulnerabilities and Exposures
http://cve.mitre.org/cgi-bin/cvename...=CVE-2006-1359

McAfee: Exploit-CreateTxtRng
http://vil.mcafeesecurity.com/vil/content/v_139047.htm
Reply With Quote
  #2 (permalink)  
Old 2006-03-28
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Cisco is blaming CheckPoint in competitive cheat sheet in low performance. As far as i remember Cisco states that Checkpoint with SmartDefence enabled can do only 4Mbps of "real world traffic" (this is the traffic mixture Cisco with a help of third part consultants discover and use for simulations and tests) on a maximum equipped hardware!!! Cisco using this numbers aggresivly. For me this is unbelievable.
Checkpoint is stating that all protocol inspections (e.g. HTTP inspection for example) are moved from Security Servers to the kernel and are "very fast". But I think such complex inspections cam move this inspections back to the Security Servers :|

We have done in home performance testing some time ago. We have used eval version of the Ixia traffic generator. We have found no difference between to hosts routed over Cisco Catalyst 3550 Switch and the same hosts routed over CheckPoint NGX SPLAT (near Gig performance). Undoubtedly our test environment and traffic patterns was pretty simple.
Reply With Quote
  #3 (permalink)  
Old 2006-03-28
Member
 
Join Date: 2006-02-21
Location: 127.0.0.1
Posts: 56
Rep Power: 3
runcmd has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Follow up:

After enabling this update, our external Outlook Web Access (OWA) users began complaining that they could no longer open emails. The list of messages appears and, after double-clicking on a particular email, the new window opens but the message never displays. We are running Exchange 2003. SmartView Tracker shows the traffic being dropped by SmartDefense and cites rule number 99812. Has anyone else experienced this problem?

Also, I've noticed difficulty in posting to some forums on the Internet when this was enabled, but I didn't track the traffic to verify it was being dropped by the same rule number.

Thanks!
Reply With Quote
  #4 (permalink)  
Old 2006-03-28
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

may be with will bw helpful
https://secureknowledge.checkpoint.c....do?id=sk26226

"Strange rule numbers appear when enabling SmartDefense protections (i.e., 99500, 99520, 99801, etc.)."

I didn't see you number in this article. But it exists next

99810
Microsoft Internet Explorer - Detected COM Object (MS05-054) Vulnerability
Reply With Quote
  #5 (permalink)  
Old 2006-04-02
Member
 
Join Date: 2006-02-21
Location: 127.0.0.1
Posts: 56
Rep Power: 3
runcmd has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Quote:
Originally Posted by runcmd
After enabling this update, our external Outlook Web Access (OWA) users began complaining that they could no longer open emails.
I opened a case with support. Apparently, they're aware of the issue with Outlook Web Access and this SmartDefense update, and are working on it. The current solution appears to be disabling this new feature. I'll post an update when I receive a follow up on my open case. Thanks.
Reply With Quote
  #6 (permalink)  
Old 2006-04-18
Member
 
Join Date: 2006-02-21
Location: 127.0.0.1
Posts: 56
Rep Power: 3
runcmd has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Although I have not yet received an update on my CheckPoint case, Microsoft has issued KB912812 to address the "Internet Explorer createTextRange () Vulnerability". The bad news: Microsoft released this as a cumulative security update, which includes the changes made by KB912945. This is the patch that adversely affects ActiveX. The quasi-good news is: Microsoft has granted a temporary "reprieve" on these ActiveX changes with the release of KB917425, which reverses the change made by KB912945--but only until sometime in June.


Summary:
KB912945 - ActiveX Changes
KB912812 - Addresses "Internet Explorer createTextRange () Vulnerability", as well as others. Also includes the ActiveX changes of KB912945.
KB917425 - Temporarily reverses ActiveX changes of KB912945/KB912812


Reference:
Microsoft Security Bulletin MS06-013
http://www.microsoft.com/technet/sec.../MS06-013.mspx

MS06-013: Cumulative security update for Internet Explorer
http://support.microsoft.com/?kbid=912812

Internet Explorer ActiveX update
http://support.microsoft.com/kb/912945

Internet Explorer ActiveX compatibility patch for Mshtml.dll
http://support.microsoft.com/kb/917425/
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0