Meterpreter not detected?

Reply
L2 Linker

Meterpreter not detected?

Hi,

I have a PA3020 installed and operational in my enviroment.

I have a vulnerability profile (using "default" actions for detected threats) created and applied to a security policy that covers all zones.

I decided to do some testing and simulate an attack using metasploit.

Based on my results, I have a couple of questions:

  1. I "compromised" several workstations and installed a meterpreter and was able to establish sessions back to my outside "attacker machine". Contrary to expectations, my PA device did not detect anything relating to my attack...I was quite surprised. Is this normal behavior. Have I grievously mis-configured the PA device?
  2. I also conducted a SSH brute force password attack. My PA device did see and correctly classify this attack but the default action is "Alert". Why would it allow such traffic? Why not "Drop" or "Deny" traffic that is obviously malicious?

Any help is greatly appreciated.

M

Tags (1)
L4 Transporter

Re: Meterpreter not detected?

Hi

Re.1 - Please show us your security rule and configurations of profiles that are connected to this rule.

Re.2 - This is default PAN behavior, of course you should change this by creation your own profile in Object>Voulnerability Profile and changing from default to ie. block action

Try this tool too McAfee Evader - did You use it?

Regards

Slawek

L2 Linker

Re: Meterpreter not detected?

Thanks for the reply.

What's the best method to show the policy and profile configuration?

M

L4 Transporter

Re: Meterpreter not detected?

Honestly screenshots would work... I can personally attest that I have seen PAs that I've tested pick up on Metasploit sessions, just as an aside

L2 Linker

Re: Meterpreter not detected?

Here are screenshots of the Security Policy (WSASECURITYPOLICY0):

Capture1.PNG

And the Vulnerability Profile (MJVULNERABILITY00):

Capture2.PNG

Let me know if you need more.

M

L4 Transporter

Re: Meterpreter not detected?

Hi

Are You sure that traffic between station A and B is hitting rule "WSASECURITYPOLICY0"?

Under CLI please use command " show session all filter source x.x.x.x" to find out session id

and next show session id yyyyy you will get details about this session, one of thouse information is:

rule                      : name_of_security_policy

that this traffic hitted.

Second problem, Your Vulnerability Profile (MJVULNERABILITY00) still has default as an actions, please change to block (or reset both where is possible), please show us also exeptions that You made in this profile.

In my opinion this security rule is too wide, You should use security profile as narrow as possible, also PA3020 is a NGF so You should allow aplications that You want to working on application-defaults ports. Automatically rest of traffic is bocked. NGFs should use whitelisting of applications, and You should focus on aplications that should work in Your enviroment.

Please corect me if I'm wrong.

With regards

Slawek

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!