19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 8: Network Infrastructure<br />

NetResident also has the capability to perform ARP poisoning, which<br />

allows NetResident to see everything on the local network segment. I cover<br />

ARP poisoning in the section “The MAC-daddy attack,” later in this chapter.<br />

Countermeasures against network protocol vulnerabilities<br />

A network analyzer can be used for good or evil. The good is to help ensure<br />

your security policies are being followed. The evil is when someone uses<br />

a network analyzer against you. A few countermeasures can help prevent<br />

someone from using an unauthorized network analyzer, although there’s no<br />

way to prevent it completely.<br />

If an external attacker or malicious user can connect to your network (physically<br />

or wirelessly), he can capture packets on the network, even if you’re<br />

using an Ethernet switch.<br />

Physical security<br />

Ensure that adequate physical security is in place to prevent someone from<br />

plugging into your network:<br />

✓ Keep the bad guys out of your server room and wiring closet.<br />

Ensure that the web, telnet, and SSH management interfaces on your<br />

Ethernet switches are especially secure to keep someone from changing<br />

the switch port configuration and seeing everything going across the wire.<br />

✓ Make sure that unsupervised areas, such as an unoccupied lobby or<br />

training room, don’t have live network connections.<br />

For details about physical security, see Chapter 6.<br />

Network analyzer detection<br />

You can use a network- or host-based utility to determine whether someone<br />

is running an unauthorized network analyzer on your network:<br />

✓ Sniffdet (http://sniffdet.sourceforge.net) for UNIX-based<br />

systems<br />

✓ PromiscDetect (http://ntsecurity.nu/toolbox/promiscdetect)<br />

for Windows<br />

Certain IPSs can also detect whether a network analyzer is running on your<br />

network. These tools enable you to monitor the network for Ethernet cards<br />

that are running in promiscuous mode. You simply load the programs on<br />

your computer, and the programs alert you if they see promiscuous behaviors<br />

on the network (Sniffdet) or local system (PromiscDetect).<br />

145

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!