| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
3.1.2 Routers (Page 3 of 3) Security Issues with Routers Routers communicate using special protocols known as routing protocols, which include standard protocols like RIP, RIPv2, OSPF, BGP and vendor-defined protocols like Ciscos IGRP. These protocols, like many other Internet protocols, have security vulnerabilities, particularly in the area of spoofing. For example, RIP (v1) can be easily spoofed because its messages are not authenticated, so anyone can send update messages via RIP; RIPv2 relies on optional clear text authentication, transmitting passwords across the network where they can be intercepted and used in later spoofing attacks. Even OSPF can be spoofed if the protocol is not used in cryptographic authentication mode. Once youve succeeded in spoofing a router message, you can do a number of things, like redirect switched network traffic to other segments so that it can be sniffed, create a black hole denial of service attack by advertising a non-existent router with a priority route for all traffic, etc. Generally, the stronger the protocols authentication is, the less vulnerable it is to spoofing. Of course, this implies that those with access to router passwords maintain their confidentiality. In keeping with the evolution of the Internet, later protocols tend to incorporate better authentication than earlier ones. When you have a choice, opt for these newer protocols like OSPF, and use the authentication features they provide. Like firewalls, routers are implemented substantially in software, and from time to time, security issues are found in that software. Therefore, the guidelines we offered for firewalls also apply to routers watch for software updates and install them when they are available, subscribe to vendor security bulletin lists and other security discussion lists. Also, similar to firewalls, routers can be challenging to configure properly. Be sure that your network administrators with router configuration responsibility have been trained on proper techniques, and possibly even certified by your routers vendor as having satisfactory knowledge of router administration. Also make sure that you have changed all default passwords. You should turn off SNMP unless you know that your device is not vulnerable to recent SNMP issues, and if you dont turn off SNMP, remember to change the SNMP community name. Reasons you want your routers to be secure include the fact that a compromised router can help someone mask their identity, create sniffing situations and just in general cause packet-routing chaos by changing access control lists, NAT settings, static routes between networks and subnets (which can facilitate MITM attacks), etc.270
__________________ 270. Anonymous, Maximum Security, Sams, June, 2001, http://www.nerdbooks.com/item.html?id=0672318717 271. http://www.aaws25.hemscott.net/Default%20password%20list.htm
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||