Security Basics mailing list archives

RE: Firewalls and PCI


From: "Craig Wright" <Craig.Wright () bdo com au>
Date: Thu, 17 Jan 2008 07:58:31 +1100

Even "if" IPSec is running, I have seen it running in AH only. Yes this is faster, but if confidentiality is the goal, 
then having a signed packet that I can read in a sniffer is not the answer.

So yes testing and validation is essential.

Regards,
Dr Craig Wright (GSE-Compliance)



Craig Wright
Manager of Information Systems

Direct : +61 2 9286 5497
Craig.Wright () bdo com au
+61 417 683 914

BDO Kendalls (NSW)
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
www.bdo.com.au

Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within 
those States and Territories of Australia where such legislation exists.

The information in this email and any attachments is confidential.  If you are not the named addressee you must not 
read, print, copy, distribute, or use in any way this transmission or any information it contains.  If you have 
received this message in error, please notify the sender by return email, destroy all copies and delete it from your 
system. 

Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls.  
You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or 
Director of BDO Kendalls.  It is your responsibility to scan this communication and any files attached for computer 
viruses and other defects.  BDO Kendalls does not accept liability for any loss or damage however caused which may 
result from this communication or any files attached.  A full version of the BDO Kendalls disclaimer, and our Privacy 
statement, can be found on the BDO Kendalls website at http://www.bdo.com.au or by emailing administrator () bdo com au.

BDO Kendalls is a national association of separate partnerships and entities.

-----Original Message-----

From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Jon R. Kibler
Sent: Thursday, 17 January 2008 5:31 AM
To: Brian Johnson
Cc: security-basics () securityfocus com
Subject: Re: Firewalls and PCI

Brian Johnson wrote:
How does a lack of DHCP let you KNOW who is on your network?  Absent
DHCP all an attacker with zero knowledge of the network configuration
needs to do is sniff the ARP and other broadcast traffic to determine
the addressing of the network and find themselves an open address or
takeover a used address.  Now if you have 802.1x or use IPSEC to limit
communications that is another story entirely and can still function
with DHCP.

A number of clients I visit say that lack of DHCP is a security
measure.  If they push back on my claim it would only slow an attacker
down I demonstrate just how easy it is to find an open address, I end
up able to talk to their network inside of 5 minutes.


I agree completely that a lack of DHCP does not mean security. However,
anything DHCP I automatically presume is untrustworthy. With static IPs,
I lock down switches, associating a MAC with a port or use 802.1x.

Since you mentioned it, a comment about IPSec: You not believe the number
of sites that think they have IPSec enabled, but don't really. They take
the average windows defaults in IPSec setup (no AH, no ESP) and think
they now have IPSec security. Like everything else, unless configured
correctly, and TESTED, IPSec is not going to provide any additional
security. When a site enables IPSec, you would think they would at least
sniff the network to see if the traffic is REALLY encrypted, but I have
yet to see any site have actually tested their IPSec configuration.

Jon
--
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
(843) 849-8214





==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


Current thread: