Identification of Symantec Enterprise Firewall Version

Identification of Symantec Enterprise Firewall Version

am 28.09.2006 17:14:13 von kingthorin

I've been looking for a way to identify SEF from the outside. nmap and
Nessus seem to have tests associated with version 6.x but not for 7.x
or 8.x.

Can someone out there with a definate version 7 or version 8 intsall
help me out with the following:

1) telnet 80
2) Enter "HEAD" (without quotes) and hit enter. [I know HEAD isn't a
valid command like that, but that's kinda the point]
3) An error should be displayed including the Server information
string. [You may have to sroll back to see it]

On a SEF 6.x installation this appears as "Server: Simple, Secure Web
Server 1.1"

Can you confirm that 7.x and 8.x reply with a different Server string?

Re: Identification of Symantec Enterprise Firewall Version

am 05.10.2006 14:48:11 von kingthorin

Cmon someone out there has to be able to verify this.

Re: Identification of Symantec Enterprise Firewall Version

am 15.11.2006 15:04:10 von kingthorin

Ok so just incase someone else ever needs this info. I finally got
confirmation from Symantec that version 6.5, 7.x, and 8.x all use the
same default banner. This also applies to version 3.x of their
appliance implementation.

However, it should be noted that version 8.x and appliance 3.x can have
the header altered in configuration files. While for version 6.5 and
7.x you can only alter the header by editing the binary directly (which
may cause other issues if you make a mistake).