RE: 3rd party vuln assesment firms



Disabling CDP is a WONDERFUL idea, but unfortunately the use of Cisco IP
phones needs this service enabled

Chris Serafin
IT Security / Voice Engineer
chris@xxxxxxxxxxxxxxxx

-----Original Message-----
From: Roland Dobbins [mailto:rdobbins@xxxxxxxxx]
Sent: Wednesday, December 28, 2005 12:05 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: 3rd party vuln assesment firms


From an operational security perspective, I'd strongly suggest
reconsidering a blanket disablement of CDP.

You're absolutely correct, one should disable CDP at the peering
edge, customer edge, IDC edge, and access edge - any untrusted edge,
which really means *any* edge. But up through distribution/
aggregation and core, one can actually end up having a negative
impact on the security of one's network by disabling CDP in those non-
edge portions of the topology; when one's in the middle of a big
incident and jumping hop-by-hop and needs to be able to readily see
what one's neighbor devices are, it's invaluable and saves lots of
time when working to resolve the issue at hand.

If a network operator finds himself in a situation in which he's
disabled CDP on all his edges, he's left it enabled deeper in the
toplogy and an attacker is *still* in a position to be able to see it
anyways (i.e., can log into the distribution/aggregation/core network
infrastructure and/or sniff traffic from those links), he in all
probability has bigger problems than worrying about CDP, and losing
the visibility it affords in non-edge portions of the network doesn't
contribute the the overall security posture of the network
infrastructure; quite the opposite.


On Dec 27, 2005, at 1:26 PM, raven@xxxxxxxxxxxxxxx wrote:

> recommending that you disable CDP
> when it's not in diagnostic use

----------------------------------------------------------------------
Roland Dobbins <rdobbins@xxxxxxxxx> // 408.527.6376 voice

Everything has been said. But nobody listens.

-- Roger Shattuck


----------------------------------------------------------------------------
--
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are

futile against web application hacking. Check your website for
vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers
do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
----------------------------------------------------------------------------
---




------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------



Relevant Pages

  • RE: Pen-Test and Social Engineering
    ... "see...your network security is penetrable". ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)
  • RE: Pen-Test and Social Engineering
    ... "see...your network security is penetrable". ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)
  • RE: Nortel Contivity 2600
    ... simplicity and security is a combination of things that have been suggested. ... Put the inside interface in a DMZ of its own with an IPS device between ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping ...
    (Pen-Test)
  • Re: Cracking WEP and WPA keys
    ... SecurityFocus wi-fi security mailing list. ... >>802.11G PCMCIA card, and the Linux server was running Samba to talk to ... >>Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • RE: Windows XP SP2 and Security Tools
    ... issues that were in SP2. ... Windows XP SP2 and Security Tools ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are ...
    (Pen-Test)