Re: Firewalls and PCI



Brian Johnson wrote:
How does a lack of DHCP let you KNOW who is on your network? Absent
DHCP all an attacker with zero knowledge of the network configuration
needs to do is sniff the ARP and other broadcast traffic to determine
the addressing of the network and find themselves an open address or
takeover a used address. Now if you have 802.1x or use IPSEC to limit
communications that is another story entirely and can still function
with DHCP.

A number of clients I visit say that lack of DHCP is a security
measure. If they push back on my claim it would only slow an attacker
down I demonstrate just how easy it is to find an open address, I end
up able to talk to their network inside of 5 minutes.


I agree completely that a lack of DHCP does not mean security. However,
anything DHCP I automatically presume is untrustworthy. With static IPs,
I lock down switches, associating a MAC with a port or use 802.1x.

Since you mentioned it, a comment about IPSec: You not believe the number
of sites that think they have IPSec enabled, but don't really. They take
the average windows defaults in IPSec setup (no AH, no ESP) and think
they now have IPSec security. Like everything else, unless configured
correctly, and TESTED, IPSec is not going to provide any additional
security. When a site enables IPSec, you would think they would at least
sniff the network to see if the traffic is REALLY encrypted, but I have
yet to see any site have actually tested their IPSec configuration.

Jon
--
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC USA
(843) 849-8214





==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.



Relevant Pages

  • Re: A little FYI
    ... > fix for a different problem or end up making the same configuration ... Maybe faulty network equipment, ... > to look at what might interfere with DHCP. ... you were not here as I was trying to get the card to stay ...
    (comp.security.firewalls)
  • Re: assigning ip addresses on a secure way
    ... DHCP works off of broadcasts. ... has network access to a DHCP server can get an address as long as there are address ... allows you to filter mac addresses in a learn mode that can lock ports to the current ... Only W2K, XP Pro, and Windows 2003 are ipsec aware. ...
    (microsoft.public.security)
  • Re: After SBS 2003 PREM Install (Action PAK) No company web or int
    ... There's no reason why a properly configured device cannot do DHCP for your ... in an SBS network is to let SBS be primary for the DNS ... Server Error in '/' Application. ... "web.config" configuration file located in the root directory of the ...
    (microsoft.public.windows.server.sbs)
  • Re: Allow DHCP only to Client Computers?
    ... network from getting an address from DHCP, ... Couldn't you achieve such a thing with IPSec. ... be assigning the classid to the adaptor - if the adaptor has a ...
    (microsoft.public.windows.server.sbs)
  • RE: Problems with Permissions
    ... For the "Network Configuration Wizard" not accessible issue, ... The DHCP not working properly issue may due to DNS not correctly ... ipconfig /all on SBS server, ...
    (microsoft.public.windows.server.sbs)