Zone Labs ZoneAlarm 2.1 Personal Firewall - Port 67
Author: Wally Whacker
type: remote
platform: windows
port:
date_added: 2000-04-24
date_updated: 2012-07-16
verified: 1
codes: CVE-2000-0339;OSVDB-1294
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/1137/info
Certain versions of Zone Labs personal Firewall have a vulnerability which allows malicious users to port scan the firewall without being detected. In particular if the port scan originates from source port 67 on the attacking host the ZoneAlarm fails to register the attack.
nmap -g67 -P0 -p130-140 -sU <targethost>