Re: PCI DSS compliance scans

nick pitlosh <[email protected]> Thu, 7 Jun 2012 17:42:06 -0400
Newsgroups gmane.org.user-groups.nmlug
Message-ID <CA+wiCrhg5LFS8NqpgYOsdz6YyN=8URQg2Tc4Zbo+VzvK5-2ugw@mail.gmail.com>
--===============1764089703==
Content-Type: multipart/alternative; boundary=bcaec55405a653dfc604c1e8c1a6

--bcaec55405a653dfc604c1e8c1a6
Content-Type: text/plain; charset=ISO-8859-1

Here's a better question, if I set up an 802.11 radio attached to a cell
modem and listened to your net, then started spoofing half a dozen macs,
what would you do about it?

Recently I worked on a network that was using static arp routing without
segmentation. This attack would most likely bring layer 2 routing to its
knees, for the entire organization.



On Thursday, June 7, 2012, nick pitlosh wrote:

> A long while ago I did these for a carrier data center. It's actually a
> racket of sorts. Essentially you need to set up an automated process for
> picking up unauthorized wifi frames and mac addresses. Many network
> sniffers do this however you're missing the fundamental idea that sec
> scanning is a generally passive process, eliminating any opportunity for
> active malevolent communication. A good network is always open and always
> listening. Review your strategy. If you're looking for pci scans, go get
> certified yourself, or just stay ahead of the curve. Never assume.
>
> That's what the bad guys are hoping to teach you. Learn it before you are
> bent over. Also segment your network.
>
> On Thursday, June 7, 2012, Ed Heron wrote:
>
>>  While this isn't completely on topic, I use Linux for my firewalls and
>> I expect/hope people on this list are more knowledgeable...
>>
>>  Does anybody know of a PCI (Payment Card Industry) ASV (Approved
>> Scanning Vendor) that can do a wireless scan?  It seems that all the PCI
>> ASV's that I can find with Google are external scans only.  Aren't we
>> supposed to do wireless scans quarterly?  Though I'm not confident the
>> scans could find unauthorized wireless access points if the people
>> setting them up weren't stupid about it...
>>
>>  I'm supposed to do a physical scan for unauthorized equipment but it
>> would be so easy to 'see me coming' if they only attached them at
>> restricted times, though obviously that would make them less convenient
>> (I have to assume an unauthorized WAP would be there for convenience).
>> Also, if our employees have any idea how to setup a WAP, I'd think I'd
>> have have gotten some hint before.  (and if they are hiding technical
>> abilities, I'd think they could get a better paying job)
>>
>>  I don't think the company I work for is a sufficiently large target to
>> entice people to break in to tap into my network or tap into the
>> Internet circuit.  Certainly, with the company being in multiple states,
>> other than a quick remote scan for new equipment, I can't do much.
>>
>>  I hope that all we're really looking for is a third party to certify I
>> don't have glaringly obvious wireless security holes.  I try to get the
>> laptop people to turn off their wireless cards when they hard wire into
>> the network...
>>
>>  Anybody have experience with any PCI ASV's for those external scans?
>>
>>
>> _______________________________________________
>> NMLUG mailing list
>> [email protected]
>> http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug
>>
>

--bcaec55405a653dfc604c1e8c1a6
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Here&#39;s a better question, if I set up an 802.11 radio attached to a cel=
l modem and listened to your net, then started spoofing half a dozen macs, =
what would you do about it?<div><br></div><div>Recently I worked on a netwo=
rk that was using static arp routing without segmentation. This attack woul=
d most likely bring layer 2 routing to its knees, for the entire organizati=
on.=A0</div>
<div><br></div><div><br></div><span></span><div><br>On Thursday, June 7, 20=
12, nick pitlosh  wrote:<br><blockquote class=3D"gmail_quote" style=3D"marg=
in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">A long while ago=
 I did these for a carrier data center. It&#39;s actually a racket of sorts=
. Essentially you need to set up an automated process for picking up unauth=
orized wifi frames and mac addresses. Many network sniffers do this however=
 you&#39;re missing the fundamental idea that sec scanning is a generally p=
assive process, eliminating any opportunity for active malevolent communica=
tion. A good network is always open and always listening. Review your strat=
egy. If you&#39;re looking for pci scans, go get certified yourself, or jus=
t stay ahead of the curve. Never assume.<div>

<br></div><div>That&#39;s what the bad guys are hoping to teach you. Learn =
it before you are bent over. Also segment your network.=A0<span></span><br>=
<br>On Thursday, June 7, 2012, Ed Heron  wrote:<br><blockquote class=3D"gma=
il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef=
t:1ex">

 =A0While this isn&#39;t completely on topic, I use Linux for my firewalls =
and<br>
I expect/hope people on this list are more knowledgeable...<br>
<br>
 =A0Does anybody know of a PCI (Payment Card Industry) ASV (Approved<br>
Scanning Vendor) that can do a wireless scan? =A0It seems that all the PCI<=
br>
ASV&#39;s that I can find with Google are external scans only. =A0Aren&#39;=
t we<br>
supposed to do wireless scans quarterly? =A0Though I&#39;m not confident th=
e<br>
scans could find unauthorized wireless access points if the people<br>
setting them up weren&#39;t stupid about it...<br>
<br>
 =A0I&#39;m supposed to do a physical scan for unauthorized equipment but i=
t<br>
would be so easy to &#39;see me coming&#39; if they only attached them at<b=
r>
restricted times, though obviously that would make them less convenient<br>
(I have to assume an unauthorized WAP would be there for convenience).<br>
Also, if our employees have any idea how to setup a WAP, I&#39;d think I&#3=
9;d<br>
have have gotten some hint before. =A0(and if they are hiding technical<br>
abilities, I&#39;d think they could get a better paying job)<br>
<br>
 =A0I don&#39;t think the company I work for is a sufficiently large target=
 to<br>
entice people to break in to tap into my network or tap into the<br>
Internet circuit. =A0Certainly, with the company being in multiple states,<=
br>
other than a quick remote scan for new equipment, I can&#39;t do much.<br>
<br>
 =A0I hope that all we&#39;re really looking for is a third party to certif=
y I<br>
don&#39;t have glaringly obvious wireless security holes. =A0I try to get t=
he<br>
laptop people to turn off their wireless cards when they hard wire into<br>
the network...<br>
<br>
 =A0Anybody have experience with any PCI ASV&#39;s for those external scans=
?<br>
<br>
<br>
_______________________________________________<br>
NMLUG mailing list<br>
<a>[email protected]</a><br>
<a href=3D"http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug" target=3D"_b=
lank">http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug</a><br>
</blockquote></div>
</blockquote></div>

--bcaec55405a653dfc604c1e8c1a6--

--===============1764089703==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug

--===============1764089703==--