Home > Security Tips > Scott Sidel's Downloads > Nipper audits routers, reveals insecure settings
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SCOTT SIDEL'S DOWNLOADS

Nipper audits routers, reveals insecure settings


Scott Sidel
04.18.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


A solid security audit includes a review of routers and firewalls, which is exactly what Nipper, an open source network infrastructure parser, excels at. Nipper examines router and firewall configuration files and generates an easy to understand report that highlights key settings and shows how they can affect security.

For more information:
In this Q&A, Mike Chapple explains if a firewall should ever be placed before a router.

Learn how a detailed network security change-management and remediation process can make audit preparation easier.

Joel Dubin unveils the best practices for protecting a router security password from compromise.
Nipper supports a number of popular security devices, including Check Point Software Technologies Ltd.'s Firewall-1, Cisco Systems Inc. routers (IOS), Cisco Security Appliances, Juniper Networks Inc.'s NetScreen, SonicWall Inc. and others.

A Nipper security audit checks configuration settings, password strength, potential problems with protocols and more. The password audit reveals weak passwords or those vulnerable to a dictionary attack, and can export encrypted passwords in a format ready for brute-force attack with a john-the-ripper file. The OS check identifies known vulnerabilities, providing CVE reference and BugTraq IDs. An ACL audit detects rules that are wide open to the point of being insecure, and spots insecure settings -- such as the failure to authenticate OSPF and RIP updates. Checks are customizable, which allows audits to target specific compliance requirements.

Nipper runs on Windows, Mac OS X and Linux at the command line, though there is a rudimentary GUI for using it within Windows. Nipper audits against an exported copy of a router's configuration file, so a router is never touched or changed during the audit.

It also supports reporting to HTML, XML, Latex and ASCII. Reports note observed findings, potential effects and provide recommendations in understandable English. The recommendations are helpful for understanding possible weaknesses, but the tool can not determine if, say, having IP source routing turned on is necessary to an organizations operations for their environment.

In general, Nipper is a good tool for helping organizations keep routers and firewalls configured correctly.

About the author:
Scott Sidel is an ISSO with Lockheed Martin

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Scott Sidel's Downloads
Enigmail: Wrapping email in a digital security blanket
Secure file copying with WinSCP
FreeRADIUS: Acing a secure connection
Spiceworks: Free network monitoring and management with a little zest
VirusTotal: On-demand antivirus service scans malicious files
Shining a spotlight on rootkits
Closing the case on network firewall security with IPCop
Eliminating the threat of spam email attacks
ClamAV clamps down on e-mail security
Digital forensics tool Helix 'does no harm'

Network Firewalls
Is security improved when the number of Internet gateways is reduced?
Should a firewall ever be placed before the router?
What to consider before opening a port
What is a 'top-down' IPS sensor search?
Comparing proxy servers and packet-filtering firewalls
Preparing for a network security audit starts with monitoring and remediation
Cisco releases updates for multiple flaws
Barracuda Networks acquires NetContinuum
Bringing the network perimeter back from the "dead"
Will iptables screen UDP traffic?

Network Routers and Switches
New virtual switch integrates with multiple security vendors
Should a firewall ever be placed before the router?
Cisco plugs serious UCM flaw
How to prevent hackers from accessing your router security password
Cisco injects role-based access control into the network
Cisco releases updates for multiple flaws
Researchers warn of new attack methods against Cisco IOS
Barracuda Networks acquires NetContinuum
Cisco issues CallManager security update
Can Snort be configured with a FreeBSD router?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bastion host  (SearchSecurity.com)
firewall  (SearchSecurity.com)
Firewall Builder  (SearchSecurity.com)
personal firewall  (SearchSecurity.com)
screened subnet  (SearchSecurity.com)
virus  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts