Security Basics mailing list archives
RE: Firewalls and PCI
From: "Craig Wright" <Craig.Wright () bdo com au>
Date: Thu, 17 Jan 2008 07:58:31 +1100
Even "if" IPSec is running, I have seen it running in AH only. Yes this is faster, but if confidentiality is the goal, then having a signed packet that I can read in a sniffer is not the answer. So yes testing and validation is essential. Regards, Dr Craig Wright (GSE-Compliance) Craig Wright Manager of Information Systems Direct : +61 2 9286 5497 Craig.Wright () bdo com au +61 417 683 914 BDO Kendalls (NSW) Level 19, 2 Market Street Sydney NSW 2000 GPO BOX 2551 Sydney NSW 2001 Fax +61 2 9993 9497 www.bdo.com.au Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within those States and Territories of Australia where such legislation exists. The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system. Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at http://www.bdo.com.au or by emailing administrator () bdo com au. BDO Kendalls is a national association of separate partnerships and entities. -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Jon R. Kibler Sent: Thursday, 17 January 2008 5:31 AM To: Brian Johnson Cc: security-basics () securityfocus com Subject: Re: Firewalls and PCI Brian Johnson wrote:
How does a lack of DHCP let you KNOW who is on your network? Absent DHCP all an attacker with zero knowledge of the network configuration needs to do is sniff the ARP and other broadcast traffic to determine the addressing of the network and find themselves an open address or takeover a used address. Now if you have 802.1x or use IPSEC to limit communications that is another story entirely and can still function with DHCP. A number of clients I visit say that lack of DHCP is a security measure. If they push back on my claim it would only slow an attacker down I demonstrate just how easy it is to find an open address, I end up able to talk to their network inside of 5 minutes.
I agree completely that a lack of DHCP does not mean security. However, anything DHCP I automatically presume is untrustworthy. With static IPs, I lock down switches, associating a MAC with a port or use 802.1x. Since you mentioned it, a comment about IPSec: You not believe the number of sites that think they have IPSec enabled, but don't really. They take the average windows defaults in IPSec setup (no AH, no ESP) and think they now have IPSec security. Like everything else, unless configured correctly, and TESTED, IPSec is not going to provide any additional security. When a site enables IPSec, you would think they would at least sniff the network to see if the traffic is REALLY encrypted, but I have yet to see any site have actually tested their IPSec configuration. Jon -- Jon R. Kibler Chief Technical Officer Advanced Systems Engineering Technology, Inc. Charleston, SC USA (843) 849-8214 ================================================== Filtered by: TRUSTEM.COM's Email Filtering Service http://www.trustem.com/ No Spam. No Viruses. Just Good Clean Email.
Current thread:
- Firewalls and PCI Josh Haft (Jan 15)
- Re: Firewalls and PCI Jon R. Kibler (Jan 15)
- Re: Firewalls and PCI Brian Johnson (Jan 16)
- Re: Firewalls and PCI Jon R. Kibler (Jan 16)
- RE: Firewalls and PCI Craig Wright (Jan 16)
- RE: Firewalls and PCI Timmothy Lester (Jan 16)
- Re: Firewalls and PCI Brian Johnson (Jan 16)
- Re: Firewalls and PCI Jon R. Kibler (Jan 15)
- Re: Firewalls and PCI David Glosser (Jan 16)
- RE: Firewalls and PCI Jason Alexander (Jan 16)
- <Possible follow-ups>
- Re: Re: Firewalls and PCI evilwon12 (Jan 16)
- Re: Re: Firewalls and PCI Josh Haft (Jan 16)
- Message not available
- Re: Firewalls and PCI Lyle Worthington (Jan 17)
- RE: Re: Firewalls and PCI Honer, Lance (Jan 18)
- Re: Re: Firewalls and PCI Josh Haft (Jan 18)
- RE: Re: Firewalls and PCI Scott Williamson (Jan 18)
- RE: Re: Firewalls and PCI Honer, Lance (Jan 18)
- Re: Re: Firewalls and PCI Josh Haft (Jan 16)