<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>(-) HatSecurity.com &#187; compliance</title>
	<atom:link href="http://hatsecurity.com/tag/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://hatsecurity.com</link>
	<description>../something for all Hats</description>
	<lastBuildDate>Sat, 07 Mar 2009 15:33:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Dodgy domain registrar de-accredited by ICANN</title>
		<link>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/</link>
		<comments>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 21:51:20 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=234</guid>
		<description><![CDATA[The Internet Corporation for Assigned Names and Numbers (ICANN) has terminated its Registrar Accreditation Agreement (RAA) with EstDomains.com after the President of the company was convicted for credit card fraud, money laundering and document forgery. This comes as welcome news by the cyber security community as EstDomains.com has been used by cyber criminals for years to hide their [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-235" title="estdomains" src="http://hatsecurity.com/wp-content/uploads/2008/10/estdomains.jpg" alt="" width="211" height="64" />The Internet Corporation for Assigned Names and Numbers (ICANN) has terminated its Registrar Accreditation Agreement (RAA) with EstDomains.com after the President of the company was convicted for credit card fraud, money laundering and document forgery.</p>
<p>This comes as welcome news by the cyber security community as EstDomains.com has been used by cyber criminals for years to hide their identities and conduct various malicious activities such as using domains for bot command &amp; control servers, drive-by downloads as well as spamming.</p>
<p>Here are some links of interest that provide more information on this story:</p>
<p>1. F-Secure Weblog - <a href="http://www.f-secure.com/weblog/archives/00001522.html" target="_blank">&#8220;Case EstDomains&#8221;</a> <br />
2. The Washington Post Company &#8211; <a href="http://voices.washingtonpost.com/securityfix/2008/10/icann_de-accredits_estdomains.html" target="_blank">&#8220;ICANN De-Accredits EstDomains for CEO&#8217;s Fraud Convictions&#8221;</a><br />
3. Notice sent to EstDomains.com by ICANN <a href="http://www.icann.org/correspondence/burnette-to-tsastsin-28oct08-en.pdf" target="_blank">(pdf)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Audit network devices with ease</title>
		<link>http://hatsecurity.com/2008/07/04/audit-network-devices-with-ease/</link>
		<comments>http://hatsecurity.com/2008/07/04/audit-network-devices-with-ease/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 21:07:07 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[general]]></category>
		<category><![CDATA[reviews]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[firewall]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=33</guid>
		<description><![CDATA[Assessing security posture of network devices like routers and firewalls can become a nightmare when a security practitioner is faced with tens of devices with hundreds (sometimes thousands) of lines of configuration data to go through. Manually going through the entire configuration data may not always be the right course of action especially when faced [...]]]></description>
			<content:encoded><![CDATA[<p>Assessing security posture of network devices like routers and firewalls can become a nightmare when a security practitioner is faced with tens of devices with hundreds (sometimes thousands) of lines of configuration data to go through. Manually going through the entire configuration data may not always be the right course of action especially when faced with tight deadlines.</p>
<p>There is help available and it comes in the form of automation tools that can make our life easier. I will discuss a couple of tools that I have worked with and how they can support in auditing and vulnerability assessment activities.<span id="more-33"></span></p>
<p><a href="http://www.niiconsulting.com/products/Firesec.html" target="_blank"><strong>FireSec</strong></a> (v1.1), a Windows-based commercial application, is primarily targeted as a firewall rule base analysis tool for medium to large enterprises. FireSec is priced at US$1000 per installation and requires a SQL Server database access to function. MSDE or SQL Server 2005 Express Edition will work just fine.</p>
<p>FireSec comes strong on the features &#8211; supporting removal of redundant rules, grouping similar rules, and detecting potentially vulnerable rule patterns by means of analysis. All of this can be achieved for a wide range of firewall devices from Cisco, Juniper (NetScreen) and Secure Computing (CyberGuard). NII Consulting (India), the developers of FireSec also claim support for a generic ruleset allowing support for CheckPoint, Fortinet and others.</p>
<p>To get started, the device configuration file needs to be imported in to the SQL Server database which is handled by the application itself. The configuration file can be supplied as a flat text file and loaded as a &#8220;Firewall&#8221; in to FireSec. The loading process is slow as it took about five minutes to load a PIX configuration file with just over 900 lines of configuration data, on an above-average performance machine (2GB DDRII, Core2 Duo 2GHz, 160GB 7200RPM HDD). Once loaded, everything else is a breeze and there is good documentation supplied to walk you through the application.</p>
<p style="text-align: center;"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/firesec1.jpg"><img class="aligncenter size-medium wp-image-36" title="firesec1" src="http://hatsecurity.com/wp-content/uploads/2008/07/firesec1-300x213.jpg" alt="" width="300" height="213" /></a><br />
Figure 1: FireSec GUI</p>
<p>FireSec sports a poor GUI though &#8211; main window cannot be maximized, left firewall selection pane cannot be adjusted and even worse is the progress bar that, at random, just stares at you even after processing the requested tasks. It took me a while to work my way through the various functions.</p>
<p>Interface issues aside, FireSec is a very capable product that can let you clean up your configuration (Figure 2), generate a comprehensive analysis report (Figure 3) and even do an analysis of how your rules perform against a given set of source and destination addresses (Figure 4). I was only able to test it with a PIX configuration and it worked as expected.</p>
<p style="text-align: center;"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/firesec2.jpg"><img class="aligncenter size-full wp-image-37" title="firesec2" src="http://hatsecurity.com/wp-content/uploads/2008/07/firesec2.jpg" alt="" width="471" height="200" /></a><br />
Figure 2: Generate commands based on given criteria</p>
<p style="text-align: center;">
<p style="text-align: center;"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/firesec3.jpg"><img class="aligncenter size-full wp-image-38" title="firesec3" src="http://hatsecurity.com/wp-content/uploads/2008/07/firesec3.jpg" alt="" width="415" height="123" /></a><br />
Figure 3: Report generation is limited to HTML format. Click <a href="http://hatsecurity.com/wp-content/reports/firesec_pix_report.html" target="_blank">here</a> for a sample report.</p>
<p style="text-align: center;">
<p style="text-align: center;"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/firesec4.jpg"><img class="aligncenter size-medium wp-image-39" title="firesec4" src="http://hatsecurity.com/wp-content/uploads/2008/07/firesec4-300x192.jpg" alt="" width="300" height="192" /></a><br />
Figure 4: Rule analysis</p>
<p>There is also a firewall comparison function that can assist in change management as well as ensuring rule base integrity and change management.</p>
<p>Overall, FireSec has lot of potential for improvement and I would be keeping my eye on it and watch it grow. For now, I have settled for open source alternatives.</p>
<p><strong><a href="http://nipper.titania.co.uk" target="_blank">Nipper</a> </strong>(v0.11.8)<strong> </strong>is a cross-platform open source tool that processes network device configuration and generates a customizable report. Nipper reports device configuration details, vulnerabilities and recommendations for mitigating the risks. This command line tool supports a wide array of network devices:</p>
<blockquote><p>Cisco Switches (IOS)<br />
Cisco Routers (IOS)<br />
Cisco Firewalls (PIX, ASA, FWSM)<br />
Cisco Catalysts (NMP, CatOS, IOS)<br />
Cisco Content Service Switches (CSS)<br />
Juniper NetScreen Firewalls (ScreenOS)<br />
CheckPoint Firewall-1/ VPN-1<br />
Nortel Passport devices (Multiservice Switch- MSS)<br />
SonicWALL SonicOS Firewalls<br />
Bay Networks Accelar Routing Switch devices (now Nortel)<br />
Nokia IP Firewalls</p></blockquote>
<p>Nipper can take a flat ASCII text file as input for processing data or connect to the device directly and retrieve the configuration through SNMP. Unlike FireSec, Nipper does not import the configuration to a database and report generation is almost instant. I was able to test Nipper&#8217;s capabilities using a standard configuration from a Cisco IOS 12.3 router and a PIX 6.3 firewall device.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-43" title="nipper21" src="http://hatsecurity.com/wp-content/uploads/2008/07/nipper21.jpg" alt="" /><br />
Figure 5: Using nipper for IOS router analysis</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-35" title="nipper3" src="http://hatsecurity.com/wp-content/uploads/2008/07/nipper3.jpg" alt="" /><br />
Figure 6: Using nipper for PIX firewall analysis</p>
<p>Within seconds of executing the above commands, Nipper was able to decode my Cisco Type 7 password for the IOS router, parse over 900 lines of PIX configuration and deliver a comprehensive report in the default HTML format (XML, Latex and ASCII text are supported too). Reports can further be customized and there is also an option to replace Nipper references with your own company name along with a range of other options.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-40" title="nipper2-report" src="http://hatsecurity.com/wp-content/uploads/2008/07/nipper2-report-279x300.jpg" alt="" width="279" height="300" /><br />
Figure 7: HTML report for Cisco IOS router. Click <a href="http://hatsecurity.com/wp-content/reports/nipper_ios_report.html" target="_blank">here</a> for the report</p>
<p style="text-align: center;">
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-42" title="nipper3-report1" src="http://hatsecurity.com/wp-content/uploads/2008/07/nipper3-report1-300x271.jpg" alt="" width="300" height="271" /><br />
Figure 8 : HTML report for Cisco PIX firewall. Click <a href="http://hatsecurity.com/wp-content/reports/nipper_pix_report.html" target="_blank">here </a>for the report</p>
<p style="text-align: left;">
<p style="text-align: left;">Nipper can even output Cisco type 5 passwords to an ASCII text file for later use of <a href="http://www.openwall.com/john/" target="_blank">John the Ripper</a> for brute force attack; a dictionary-file support is present too. Overall, a great tool and highly recommended!</p>
<p style="text-align: left;"><strong>Other tools </strong>to look at:</p>
<ol>
<li><a href="http://www.securepassage.com/FireMon/" target="_blank">Firemon</a> from Secure Passage that does configuration analysis as well as change management and more;</li>
<li><a href="http://dev.inversepath.com/trac/ftester" target="_blank">FTester</a> from Inverse Path to test your firewall and IDS from a behavioral point of view and the Router;</li>
<li><a href="http://www.cisecurity.org/bench_cisco.html" target="_blank">Router Audit Tool (RAT)</a> from Center for Internet Security that benchmarks router configuration against NSA recommended guidelines for security;</li>
<li><a href="http://www.redseal.net/Product-Overview.shtml" target="_blank">RedSeal Security Risk Manager (SRM)</a> from RedSeal Systems is a comprehensive tool for overall network security assessment that can do firewall and router device assessments as well;</li>
</ol>
<p>To sum up, the tools discussed above can greatly reduce the amount of time you would normally take to assess your network devices, however, I am not recommending that you do not do manual reviews to verify the results. I would never give precedence to a report generated by an automation tool over manual report. It all comes down to the nature of the assessment.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/07/04/audit-network-devices-with-ease/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
