Re: fedora-list@redhat.com

From: ryan (ryanag_at_zoominternet.net)
Date: 03/13/05

  • Next message: David Curry: "Archive Searches - Suggested Approaches"
    Date: Sun, 13 Mar 2005 10:47:57 +0000
    To: rick@workcity.ca
    
    

    Rick Meyer wrote:

    >Yep...., except that the real information that is being transmitted by the
    >firewall is inside an encrypted VPN. Also the file system itself is
    >encrypted. The firewall won't accept SSH from just any system. It's locked
    >down. I'm just trying to make it extremely difficult for an unauthorized
    >user to get access to it.
    >
    >Rick.
    >
    >| -----Original Message-----
    >| From: ryan [mailto:ryanag@zoominternet.net]
    >| Sent: Sunday, March 13, 2005 6:16 AM
    >| To: fedora-list@redhat.com; rick@workcity.ca
    >| Subject: fedora-list@redhat.com
    >|
    >| "How do I lock or disable unused ports such as keyboard, video and USB
    >| ports?
    >|
    >|
    >| Here is the scenario; I have several firewalls built upon Fedora that are
    >| in
    >| closets physically unmonitored. An unscrupulous individual could plug in
    >| a
    >| keyboard, mouse and monitor into one of these systems and start getting
    >| access to it. Even worse the individual could plug in other devices to
    >| log
    >| all packets flowing through the firewall. This gives me chills just
    >| thinking about it!
    >|
    >| I would like to disable any I/O devices that aren't actually needed."
    >|
    >|
    >| Way too much work with no tangible benefits. If you did all this, what is
    >| to keep a malicious attacker from dropping in a $10 hub, then setting up a
    >| monitoring station. He/She could just walk in occaisionally and get the
    >| logs off, or worse, set up a cheap access point and just pull into the
    >| parking lot, SSH into their sniffer machine, and get the logs that way.
    >|
    >| Physically secure the machines or don't think too hard about it. Stripping
    >| the servers down to a CPU/RAM/HD and ethernet ports won't provide much
    >| additional security.
    >|
    >|
    >
    >
    >
    >
    >
    >
    >
    >
    I meant that the attacker can SSH into their seperate sniffing machine.

    The VPN setup helps as lot, but still doesn't protect you. Once the
    attacker figures out that you are running a VPN, they can just crash (or
    steal) your system.

    Worse, they can steal your hard drive. Even assuming you've encrypted
    important stuff, this is still a big enough issue to force you to re-do
    everything (how long will you encryption be good for, until it can be
    easily broken? 1 year? 10 years?).

    With physical access to the machine reasonably possible, you have to
    make the assumption that any attacker can gain control of your system,
    if they are willing to break and enter to do so.

    You need to think about what else at these locations is not secured, and
    their relative value. Also consider how many strangers wander these
    buildings, or is it the same old people all the time.

    If there are things of greater business importance than your firewall
    not secured, I think its an organizational problem. If only your
    firewalls are in unlocked closets, it sounds like you need some good ol'
    physical access control. A nice lock, alarm system, and webcam would
    probably take far less time to setup, and be less dangerous to your
    network, than disabling everything on your firewall machines. ;-)

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: David Curry: "Archive Searches - Suggested Approaches"

    Relevant Pages

    • Re: Problem w/symantec firewall & SSH Tunnel
      ... having a firewall protects your system to a certain point, ... Although I've learned a LITTLE about VPN, SSH proxies and SSH tunnels, I was ... much less well encryption than the SSH tunnel that is provided, ... do not understand, and until I do, I should do everything I can to protect ...
      (comp.security.ssh)
    • Re: Problem w/symantec firewall & SSH Tunnel
      ... > Luckily the service I use for VPN that also supplies services for SSH ... > apperently the program does (.bat files that launch other files). ... > something to do with the firewall. ...
      (comp.security.ssh)
    • Re: [fw-wiz] RE: firewall-wizards digest, Vol 1 #679 - 2 msgs
      ... This is using a single DMZ (simple firewall) for the servers ... > to host VPN engine. ... You're forced to break the encryption boundary for most of ...
      (Firewall-Wizards)
    • Re: VPN Access for Consultants
      ... They want to be able to access their network and our network ... VPN between their network and my own. ... Even though both are exposing holes in the firewall, VPN and SSH are ...
      (Security-Basics)
    • Re: Initiate SSH session from other side?
      ... internal network is going to be exposed to home computers' ... VPN would require the company's firewall to allow the VPN ... we're using ssh port forwarding to work around what the ...
      (comp.security.ssh)