| ★ wanayoo — archive 1999 http://www.data.com/miscellani/simulated_attack.html | Nouvelle recherche | Portail wanayoo |
![]() |
![]() |
|
|
Scanning for SecurityThe Internet Scanner master program, which runs on a Unix workstation, initiates multiple scanning processes (1). Each process launches "attacks" against a host (2). The host's replies (3) are monitored by a listening process, which reports them back to the master program (4). The master program sends them to a report writer (5), which issues a detailed statement for users (6).
|
Of particular significance for corporate customers is the package's ability to scan firewalls. Internet Scanner knows to look for certain weaknesses, including source routing (allowing packets that appear to have come from inside the network to pass) and source porting (keeping a specific port on the firewall open to allow FTP [file transfer protocol] transfers). Internet Scanner also tests Socks configuration. Socks is a proxy service that lets net managers configure firewalls in a wa y that will block users from getting onto the Internet. But frequent misconfiguration has the opposite effect: It allows Internet users inside.
In addition, the package includes a "listener" process that checks for responses from the scanned host. The program then compiles a report displaying any flaws found, along with suggested responses.
Another way the Internet Scanner looks for configuration weaknesses is by attempting to log into scanned hosts using common user passwords. But it doesn't stop with common log-ins-it also checks for information about authorized users using the "finger" command, which can often uncover such information as a user's birth date and full name, and the names of family members. It then uses this information to attempt log-ins.
Internet Scanner also checks directories to see if they have been modified by outsiders, and it probes Unix utilities for software that includes known security holes. It can, for example, determine whet her a system is afflicted by the "sendmail" bug, by which an executable program could be sent via e-mail (this was the flaw that permitted the Internet Worm to crash large parts of the Internet in 1987). It also checks World Wide Web software for known flaws-such as the Netscape bug discovered last summer.
In addition, the package can determine which machines are considered "trusted" by the scanned machine (that is, which devices have access to the scanned machine). It will then check to make sure that there is no flaw that would allow the file containing the list of trusted hosts to be modified to include the hacker's host.
That's the story on scanning-but what happens when a weakness is discovered? Internet Scanner sends a report to the network manager containing a description of the weakness found and an indication of its seriousness (vulnerability is classified as high, medium, or low). It also generates a list of suggestions for repairing the flaw. These suggestions can be fairly specific . For example, users of flawed software from a particular vendor are told to request a specific patch or upgrade, and they are given the contact information that enables them to do so.
The vendor releases new versions of Internet Scanner every few months, and each version contains new types of probes to enable users to keep pace with hackers. The availability of these upgrades distinguishes it from Satan, and it makes the package attractive to users. "Internet Scanner does a nice job," says Kenneth Miles, a network manager at Argonne National Labs (Argonne, Ill.). "It's money well spent."
[ Home ]
[
Registration
|
Subscriptions
]
[
Contact Us
|
E-Mail
]
|
|||||||||||
![]() |
|