Groups | Blog | Home
all groups > iis security > july 2003 >

iis security : Hacking into firewall


Ajitesh Pathak
7/30/2003 5:43:41 AM
Hi There,
How can I hack the security in the office and
try and access the sites which we are denied access into??
Keith W. McCammon
7/30/2003 9:14:17 AM
[quoted text, click to view]

Ask your network administrator the following questions, and post the answers
here:

1) What type of network operating system is used to run the firewall?
2) What firewall vendor is used?
3) Is there an alternate outbound circuit that bypasses the firewall?

If the answer to 3 is "no":

4) What is the username and password for the firewall's management console?
5) How fast will I lose my job for using this information to violate
corporate policy?

Louis Davidson
7/30/2003 10:59:53 AM

[quoted text, click to view]
If you have to ask for this information, getting the
correct method would not be useful. You would not be able
to follow the instructions. So you should, read, read,
read, build your home network with two computers
connected via broadband to the Internet(static IP type)
without the appropriate hacking defenses, and one computer
dial-up that you will use to hack your own network. After
a few years, and you have succeeded then add the
appropriate firewall+hacking defence shields and learn how
to pass through to your network.

just trying to help you become a great Hacker, and not a
frustrated Cracker.

Louis.



Karl Levinson [x y] mvp
7/30/2003 11:01:55 AM
You should really be doing that surfing from home, if you want to keep your
job. Anything you do on the network can and will be seen by someone else.


[quoted text, click to view]

paul_lynch67 NO[at]SPAM hotmail.com
7/30/2003 12:33:00 PM
Just go and tell your boss that you want to surf for porn all day
instead of working. He'll probably be impressed by your candour and
reward your honesty with a pay rise and a promotion.

Go on do it.... I dare you...



[quoted text, click to view]
Ajitesh
7/30/2003 12:49:45 PM

Ask your network administrator. You've got nerve. Hope
you are ready to get fired.


[quoted text, click to view]
Alessandro Perilli
7/30/2003 3:10:34 PM
[quoted text, click to view]

Ajitesh,
nice to see you detailed your request in this new post :)

Basically a firewall can deny you access to web sites bythree different
methods:

1. Block any request for certain IPs
2. Evaluate your office clients HTTP requests every time are generated and
perform a comparison against a prohibited web sites database (so called
internet filtering talking about firewall action, so called content
analysis talking about firewall technology in place)
3. Specify which destination your machine (or you as user) can reach, and
prohibit any other destination.

In first two cases, both methods can be bypassed simply using a web
anonymous proxy. There are many online, free for a certain amount of
traffic volume (then you have to pay for more bandwidth), eventually
capable of hiding your real request inside an HTTPS request (to avoid
sniffers check or firewall content analysis).
Specifically in second case, some administrators, to avoid this behavior
and don't let company users walkaround firewall restrictions, put into
prohibited web sites database also this kind of web anonymous proxy sites,
so you cannot go directly for your destination and neither go for them. But
anonymous web proxies grow every day and it's very difficult to catalog and
block every of them.

In third case you cannot use this technique to avoid firewall restriction.
You should implement a personal web proxy on one resource administrator
allowed for you, but this become very complex when your resources allowed
are inside your company and not outside. Anyway this last method for block
company users is rarely used.

--

Alessandro Perilli
Security Consultant / Trainer

MCT - MCSE 2000 SECURITY - LINUX+
CCSI - CCSE 2000 - CCSE+ NG
CCNA - CIWP - CIWSA - CCA XP
AddThis Social Bookmark Button