cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1015
Views
0
Helpful
3
Replies

Check Point RDP exploit

silverm
Level 1
Level 1

Have there been any CSIDS signature updates to check for the Check Point RDP exploit that could allow an intruder to pass traffic through a Check Point Firewall-1 on port 259/UDP?

3 Replies 3

mhossain
Cisco Employee
Cisco Employee

You can do this right now with a "connection signature" looking for

connections to port 259/UDP.

Regards,

-Mun

IDS Product Manager

Your solution will fire an alarm on any traffic trying to establish a vpn, or client authorization. Sounds like a lot of false alarms.