Home > Midmarket IT Security Tips > > Nipper audits routers, reveals insecure settings
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Nipper audits routers, reveals insecure settings


Scott Sidel
02.05.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


A solid security audit includes a review of routers and firewalls, which is exactly what Nipper, an open source network infrastructure parser, excels at. Nipper examines router and firewall configuration files and generates an easy to understand report that highlights key settings and shows how they can affect security.

Nipper supports a number of popular security devices, including Check Point Software Technologies Ltd.'s Firewall-1, Cisco Systems Inc. routers (IOS), Cisco Security Appliances, Juniper Networks Inc.'s NetScreen, SonicWall Inc. and others.

A Nipper security audit checks configuration settings, password strength, potential problems with protocols and more. The password audit reveals weak passwords or those vulnerable to a dictionary attack, and can export encrypted passwords in a format ready for brute-force attack with a john-the-ripper file. The OS check identifies known vulnerabilities, providing CVE reference and BugTraq IDs. An ACL audit detects rules that are wide open to the point of being insecure, and spots insecure settings -- such as the failure to authenticate OSPF and RIP updates. Checks are customizable, which allows audits to target specific compliance requirements.

Nipper runs on Windows, Mac OS X and Linux at the command line, though there is a rudimentary GUI for using it within Windows. Nipper audits against an exported copy of a router's configuration file, so a router is never touched or changed during the audit.

It also supports reporting to HTML, XML, Latex and ASCII. Reports note observed findings, potential effects and provide recommendations in understandable English. The recommendations are helpful for understanding possible weaknesses, but the tool can not determine if, say, having IP source routing turned on is necessary to an organizations operations for their environment.

In general, Nipper is a good tool for helping organizations keep routers and firewalls configured correctly.

About the author:
Scott Sidel is an ISSO with Lockheed Martin

Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Configuration and patch management
Hackers targeting unpatched Microsoft DirectShow flaw
Adobe shifts to Microsoft patching process, incident response plan
PCI DSS requirement: Building and maintaining a secure network
How to fill patch management gaps using Microsoft MBSA
Assess your security state in five steps
Internet Explorer 8 includes a bevy of security features
Adobe issues patch to block zero-day flaw
Determine when to use a workaround rather than patch systems
Auto shutoff switches save money, tighten security
How to prepare for security patch testing

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts