![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Network Card not recognized / How to save network configuration on a Slack Distrib | Winol | UNIX for Dummies Questions & Answers | 1 | 09-08-2008 01:00 PM |
| TA08-190B: Multiple DNS implementations vulnerable to cache poisoning | iBot | Security Advisories (RSS) | 0 | 07-08-2008 05:40 PM |
| FAA: Boeing?s New 787 May Be Vulnerable to Hacker Attack | iBot | Complex Event Processing RSS News | 0 | 01-06-2008 12:11 AM |
| Network device driver | niketan | High Level Programming | 1 | 04-17-2007 10:56 PM |
| Flaw leaves Linux computers vulnerable | killerserv | News, Links, Events and Announcements | 3 | 04-08-2002 12:33 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
The most vulnerable device in the network
During a conversation with some folks last week we wondered about what is the most vulnerable
type of devices in ours networks. The answer for almost everyone in the table was: Routers... So we start talking about risks, how to protect a border router, which hardening actions can be taken in order to improve security, etc. A important point that I noticed is that event nowadays many companies does not implement controls to improve routers security. Based on it I decided to write a few notes mentioning risks and hardening actions that can prevent a attacker to be successful. Main Risks The most obvious risk associate with a router compromised or disabled is that all communications that is forwarded by this router will be disabled but there are others not so obvious:
Some important actions that can harder a router and increase security:
Also is important to enforce password encryption.
Other actions is to allow only console port (not always possible) or to implement a SSH gateway so all users must log in into the SSH gateway and then jump to the router.
This banner shall be legally sufficient for prosecution of malicious users, to shield administrators from liability and not leak information.
Many routers are just opened due to SNMP default configurations. Try to implement SNMPv3 or at least v2c
This is a powerful tool because it's possible to cross routers logs with IPS's logs, FW 's logs and others to identify threats that can't be identified using only a single source.
If it's a situation where is possible to do it and you have the budget to do it, why not?
Determine if the incident is an attacker or an accident; Discover what happened; Preserve the evidence; Recover from the incident; Identify root causes and manage or mitigate them to prevent from happening again.
Conclusion A router is a very important device (if not the most important one) and many companies does not put in place appropriated controls. It's important for administrators to be aware that if they do not change this scenario quickly soon or later they'll have to face themselves with a compromised router. More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|