Re: PCI DSS compliance scans
nick pitlosh <[email protected]> Thu, 7 Jun 2012 17:42:06 -0400
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <CA+wiCrhg5LFS8NqpgYOsdz6YyN=8URQg2Tc4Zbo+VzvK5-2ugw@mail.gmail.com> |
--===============1764089703== Content-Type: multipart/alternative; boundary=bcaec55405a653dfc604c1e8c1a6 --bcaec55405a653dfc604c1e8c1a6 Content-Type: text/plain; charset=ISO-8859-1 Here's a better question, if I set up an 802.11 radio attached to a cell modem and listened to your net, then started spoofing half a dozen macs, what would you do about it? Recently I worked on a network that was using static arp routing without segmentation. This attack would most likely bring layer 2 routing to its knees, for the entire organization. On Thursday, June 7, 2012, nick pitlosh wrote: > A long while ago I did these for a carrier data center. It's actually a > racket of sorts. Essentially you need to set up an automated process for > picking up unauthorized wifi frames and mac addresses. Many network > sniffers do this however you're missing the fundamental idea that sec > scanning is a generally passive process, eliminating any opportunity for > active malevolent communication. A good network is always open and always > listening. Review your strategy. If you're looking for pci scans, go get > certified yourself, or just stay ahead of the curve. Never assume. > > That's what the bad guys are hoping to teach you. Learn it before you are > bent over. Also segment your network. > > On Thursday, June 7, 2012, Ed Heron wrote: > >> While this isn't completely on topic, I use Linux for my firewalls and >> I expect/hope people on this list are more knowledgeable... >> >> Does anybody know of a PCI (Payment Card Industry) ASV (Approved >> Scanning Vendor) that can do a wireless scan? It seems that all the PCI >> ASV's that I can find with Google are external scans only. Aren't we >> supposed to do wireless scans quarterly? Though I'm not confident the >> scans could find unauthorized wireless access points if the people >> setting them up weren't stupid about it... >> >> I'm supposed to do a physical scan for unauthorized equipment but it >> would be so easy to 'see me coming' if they only attached them at >> restricted times, though obviously that would make them less convenient >> (I have to assume an unauthorized WAP would be there for convenience). >> Also, if our employees have any idea how to setup a WAP, I'd think I'd >> have have gotten some hint before. (and if they are hiding technical >> abilities, I'd think they could get a better paying job) >> >> I don't think the company I work for is a sufficiently large target to >> entice people to break in to tap into my network or tap into the >> Internet circuit. Certainly, with the company being in multiple states, >> other than a quick remote scan for new equipment, I can't do much. >> >> I hope that all we're really looking for is a third party to certify I >> don't have glaringly obvious wireless security holes. I try to get the >> laptop people to turn off their wireless cards when they hard wire into >> the network... >> >> Anybody have experience with any PCI ASV's for those external scans? >> >> >> _______________________________________________ >> NMLUG mailing list >> [email protected] >> http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug >> > --bcaec55405a653dfc604c1e8c1a6 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Here's a better question, if I set up an 802.11 radio attached to a cel= l modem and listened to your net, then started spoofing half a dozen macs, = what would you do about it?<div><br></div><div>Recently I worked on a netwo= rk that was using static arp routing without segmentation. This attack woul= d most likely bring layer 2 routing to its knees, for the entire organizati= on.=A0</div> <div><br></div><div><br></div><span></span><div><br>On Thursday, June 7, 20= 12, nick pitlosh wrote:<br><blockquote class=3D"gmail_quote" style=3D"marg= in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">A long while ago= I did these for a carrier data center. It's actually a racket of sorts= . Essentially you need to set up an automated process for picking up unauth= orized wifi frames and mac addresses. Many network sniffers do this however= you're missing the fundamental idea that sec scanning is a generally p= assive process, eliminating any opportunity for active malevolent communica= tion. A good network is always open and always listening. Review your strat= egy. If you're looking for pci scans, go get certified yourself, or jus= t stay ahead of the curve. Never assume.<div> <br></div><div>That's what the bad guys are hoping to teach you. Learn = it before you are bent over. Also segment your network.=A0<span></span><br>= <br>On Thursday, June 7, 2012, Ed Heron wrote:<br><blockquote class=3D"gma= il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef= t:1ex"> =A0While this isn't completely on topic, I use Linux for my firewalls = and<br> I expect/hope people on this list are more knowledgeable...<br> <br> =A0Does anybody know of a PCI (Payment Card Industry) ASV (Approved<br> Scanning Vendor) that can do a wireless scan? =A0It seems that all the PCI<= br> ASV's that I can find with Google are external scans only. =A0Aren'= t we<br> supposed to do wireless scans quarterly? =A0Though I'm not confident th= e<br> scans could find unauthorized wireless access points if the people<br> setting them up weren't stupid about it...<br> <br> =A0I'm supposed to do a physical scan for unauthorized equipment but i= t<br> would be so easy to 'see me coming' if they only attached them at<b= r> restricted times, though obviously that would make them less convenient<br> (I have to assume an unauthorized WAP would be there for convenience).<br> Also, if our employees have any idea how to setup a WAP, I'd think I= 9;d<br> have have gotten some hint before. =A0(and if they are hiding technical<br> abilities, I'd think they could get a better paying job)<br> <br> =A0I don't think the company I work for is a sufficiently large target= to<br> entice people to break in to tap into my network or tap into the<br> Internet circuit. =A0Certainly, with the company being in multiple states,<= br> other than a quick remote scan for new equipment, I can't do much.<br> <br> =A0I hope that all we're really looking for is a third party to certif= y I<br> don't have glaringly obvious wireless security holes. =A0I try to get t= he<br> laptop people to turn off their wireless cards when they hard wire into<br> the network...<br> <br> =A0Anybody have experience with any PCI ASV's for those external scans= ?<br> <br> <br> _______________________________________________<br> NMLUG mailing list<br> <a>[email protected]</a><br> <a href=3D"http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug" target=3D"_b= lank">http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug</a><br> </blockquote></div> </blockquote></div> --bcaec55405a653dfc604c1e8c1a6-- --===============1764089703== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug --===============1764089703==--