Re: PCI DSS compliance scans

nick pitlosh <[email protected]> Thu, 7 Jun 2012 17:27:16 -0400
Newsgroups gmane.org.user-groups.nmlug
Message-ID <CA+wiCrgTPgm1J5k2AnLHpu+MDc5o2=C=MwDxW=ew8KdG-Udt0A@mail.gmail.com>
--===============0702512351==
Content-Type: multipart/alternative; boundary=e89a8fb20674462f0604c1e88cea

--e89a8fb20674462f0604c1e88cea
Content-Type: text/plain; charset=ISO-8859-1

A long while ago I did these for a carrier data center. It's actually a
racket of sorts. Essentially you need to set up an automated process for
picking up unauthorized wifi frames and mac addresses. Many network
sniffers do this however you're missing the fundamental idea that sec
scanning is a generally passive process, eliminating any opportunity for
active malevolent communication. A good network is always open and always
listening. Review your strategy. If you're looking for pci scans, go get
certified yourself, or just stay ahead of the curve. Never assume.

That's what the bad guys are hoping to teach you. Learn it before you are
bent over. Also segment your network.

On Thursday, June 7, 2012, Ed Heron wrote:

>  While this isn't completely on topic, I use Linux for my firewalls and
> I expect/hope people on this list are more knowledgeable...
>
>  Does anybody know of a PCI (Payment Card Industry) ASV (Approved
> Scanning Vendor) that can do a wireless scan?  It seems that all the PCI
> ASV's that I can find with Google are external scans only.  Aren't we
> supposed to do wireless scans quarterly?  Though I'm not confident the
> scans could find unauthorized wireless access points if the people
> setting them up weren't stupid about it...
>
>  I'm supposed to do a physical scan for unauthorized equipment but it
> would be so easy to 'see me coming' if they only attached them at
> restricted times, though obviously that would make them less convenient
> (I have to assume an unauthorized WAP would be there for convenience).
> Also, if our employees have any idea how to setup a WAP, I'd think I'd
> have have gotten some hint before.  (and if they are hiding technical
> abilities, I'd think they could get a better paying job)
>
>  I don't think the company I work for is a sufficiently large target to
> entice people to break in to tap into my network or tap into the
> Internet circuit.  Certainly, with the company being in multiple states,
> other than a quick remote scan for new equipment, I can't do much.
>
>  I hope that all we're really looking for is a third party to certify I
> don't have glaringly obvious wireless security holes.  I try to get the
> laptop people to turn off their wireless cards when they hard wire into
> the network...
>
>  Anybody have experience with any PCI ASV's for those external scans?
>
>
> _______________________________________________
> NMLUG mailing list
> [email protected] <javascript:;>
> http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug
>

--e89a8fb20674462f0604c1e88cea
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

A long while ago I did these for a carrier data center. It&#39;s actually a=
 racket of sorts. Essentially you need to set up an automated process for p=
icking up unauthorized wifi frames and mac addresses. Many network sniffers=
 do this however you&#39;re missing the fundamental idea that sec scanning =
is a generally passive process, eliminating any opportunity for active male=
volent communication. A good network is always open and always listening. R=
eview your strategy. If you&#39;re looking for pci scans, go get certified =
yourself, or just stay ahead of the curve. Never assume.<div>
<br></div><div>That&#39;s what the bad guys are hoping to teach you. Learn =
it before you are bent over. Also segment your network.=A0<span></span><br>=
<br>On Thursday, June 7, 2012, Ed Heron  wrote:<br><blockquote class=3D"gma=
il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef=
t:1ex">
 =A0While this isn&#39;t completely on topic, I use Linux for my firewalls =
and<br>
I expect/hope people on this list are more knowledgeable...<br>
<br>
 =A0Does anybody know of a PCI (Payment Card Industry) ASV (Approved<br>
Scanning Vendor) that can do a wireless scan? =A0It seems that all the PCI<=
br>
ASV&#39;s that I can find with Google are external scans only. =A0Aren&#39;=
t we<br>
supposed to do wireless scans quarterly? =A0Though I&#39;m not confident th=
e<br>
scans could find unauthorized wireless access points if the people<br>
setting them up weren&#39;t stupid about it...<br>
<br>
 =A0I&#39;m supposed to do a physical scan for unauthorized equipment but i=
t<br>
would be so easy to &#39;see me coming&#39; if they only attached them at<b=
r>
restricted times, though obviously that would make them less convenient<br>
(I have to assume an unauthorized WAP would be there for convenience).<br>
Also, if our employees have any idea how to setup a WAP, I&#39;d think I&#3=
9;d<br>
have have gotten some hint before. =A0(and if they are hiding technical<br>
abilities, I&#39;d think they could get a better paying job)<br>
<br>
 =A0I don&#39;t think the company I work for is a sufficiently large target=
 to<br>
entice people to break in to tap into my network or tap into the<br>
Internet circuit. =A0Certainly, with the company being in multiple states,<=
br>
other than a quick remote scan for new equipment, I can&#39;t do much.<br>
<br>
 =A0I hope that all we&#39;re really looking for is a third party to certif=
y I<br>
don&#39;t have glaringly obvious wireless security holes. =A0I try to get t=
he<br>
laptop people to turn off their wireless cards when they hard wire into<br>
the network...<br>
<br>
 =A0Anybody have experience with any PCI ASV&#39;s for those external scans=
?<br>
<br>
<br>
_______________________________________________<br>
NMLUG mailing list<br>
<a href=3D"javascript:;" onclick=3D"_e(event, &#39;cvml&#39;, &#39;NMLUG@nm=
lug.org&#39;)">[email protected]</a><br>
<a href=3D"http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug" target=3D"_b=
lank">http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug</a><br>
</blockquote></div>

--e89a8fb20674462f0604c1e88cea--

--===============0702512351==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug

--===============0702512351==--