HomeRapidalertHaris Floridis: The researcher who identified a weakness in Checkpoint!

Haris Floridis: The researcher who identified a weakness in Checkpoint!

Global Recognition: Haris Floridis – The Cypriot security researcher who identified & disclosed a high-profile vulnerability in the company Checkpoint!!!

SecNews EXCLUSIVELY highlights today the discovery of a critical vulnerability in Checkpoint, a leading security company in the world, by a Cypriot researcher!

checkpoint

According to information brought to the attention of the editorial team of SecNews and confirmed by the report, on March 3, 2015, Cypriot security researcher Mr. Haris Floridis identified a very significant weakness in the website of Check Point Software Technologies Ltd.As  is known, Checkpoint is one of the leading manufacturers of network security systems worldwide. The products of this company, Check Point Software Technologies Ltd, protect over 100,000 businesses worldwide as well as several million users.

hackers-Domain-shadowing

The weakness on the Checkpoint website

The exploitation of the vulnerability identified by Mr. Haris Floridis,  as it turned out, provided the opportunity for an external malicious attacker, with zero knowledge of the company's internal infrastructure, to intercept or alter critical information. The use of the vulnerability, as reported by distinguished researchers contacted by SecNews, could cause incalculable consequences, exposing the company both in terms of confidentiality and legal issues with regard to its customers, but also, above all, to be a blow to the company's reputation.

The vulnerability was due to an incorrect parameter on the subpage where its partners around the world are displayed, specifically here (https://partners.us.checkpoint.com/partnerlocator/).

Partial exploitation of the vulnerability allowed the attacker to gain access to the Check Point Database with additional access expansion capabilities. The evidence of the existence & use of the vulnerability is in the possession of the Researcher and the company. The company confirms this access capability as shown in the relevant announcement, which however does not publish the exact details so as not to damage its reputation.

Haris Floridis Checkpoint

 

 In addition, SecNews has information confirming the existence & use of the vulnerability, but does not make it public since it refers to the details of a Checkpoint customer on whom the tests were conducted.

A few words about the researcher
computer security
Harris Floridis, who holds the CISSP certificate, works as an Information Systems Auditor at the Cooperative Central Bank of Cyprus. In the past, he had worked as an Engineer for the design and implementation of security systems in large organizations' networks and as a Penetration Tester.
The plan to resolve the weakness.
smb-security-businessman-wtih-umbrella-storm_contentfullwidth
Mr. Haris Floridis, after identifying the vulnerability, duly sought and succeeded in continuous communication with the representatives of the Check Point , where he thoroughly informed them about the identification of the vulnerability and the possibilities of its exploitation.
Fully following the ethics of "Responsible Vulnerability Disclosure", Mr. Floridis communicated specific recommendations for its immediate resolution and proposals for additional investigation of possible incidents.
In a communication we sought with Mr. Haris Floridis, he told us that the identification of the extremely critical weakness was done without the use of automated tools, but manually. It is also known that penetration testers of high prestige and knowledge choose to use manual methods based exclusively on their knowledge background. Automated tools, moreover, make the identification and exploitation of weaknesses often impossible (due to the limited checks they perform).
To his credit, Mr. Haris Floridis chose the difficult path of manual detection, and thus was led to the detection of a vulnerability with a global impact. Immediately after the information was provided, Checkpointprepared an action plan for the resolution and additional investigation of the issue. With the successful completion of this action plan, it proceeded to inform its customers and in fact, in the relevant publication, it thanks Mr. Floridis for the detection and cooperation (See more at the link)(code sk105183, https://supportcenter.checkpoint.com/supportcenter/)It is noted that any malicious exploitation of the vulnerability, with all that this entails (introduction of malicious software, information leakage, alteration of the website), combined with the nature and reputation of the company's work as well as its large and important clientele, would perhaps constitute one of the most significant incidents in electronic security issues, at a global level.Security7_610x426_2SecNews would like to congratulate Mr. Haris Floridis for the extremely important discovery of the critical vulnerability and the exemplary handling of the responsible information he provided. However, congratulations also deserve Checkpoint for admitting the incident, publishing a press release to inform its customers, and immediately resolving the critical issue.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS