Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: IPS with no IP address?

Subject: Re: IPS with no IP address?
Date: Thu, 6 Jan 2005 18:43:11 -0600
Jeff,

It's actually pretty common in the telco world. ILMI for those from the ATM world is how operators in the telco world manage equipment over the same wire. In that case it's VPI/VCI in this case they have no IP addresses but they listen for an IP address - once they see the IP address they act differently. The danger is that the device can be attacked on the wires it's protecting. I would suggest you run *SIC, (ISIC, etc) on the network address to see how strong the stack that is providing the management is. It's generally not recommended to have your management interface exposed to the network you are protecting. Example, let's say they have a HTTPS interface - why not flood the data path with HTTPS traffic to that IP address and see if you could slow down the device - or perhaps you can discover what type of device it is and they figure out what it's weak on.


Dennis Cox Director of Engineering, TippingPoint Technologies w 512.681.8328


On Jan 5, 2005, at 2:17 PM, Jeff McCarthy wrote:

Hello,

 I recently sat in on an IPS vendor presentation. They
 stated that their IPS has 2 Ethernet interfaces,
 neither of which have IP addresses yet they can manage
 and monitor the device over IP.  I thought this was
 interesting and somewhat unique.

 Are there any other vendors that do that? I know at
 least one other vendor has no IP on the interfaces
 listening to traffic but they have a seperate
 interface with an IP for management.

 Thanks,

 Jeff McCarthy
 USM


                __________________________________ Do you Yahoo!? Yahoo! Mail - Easier than ever with enhanced search. Learn more. http://info.mail.yahoo.com/mail_250

----------------------------------------------------------------------- ---
Test Your IDS


Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
----------------------------------------------------------------------- ---





--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------



<Prev in Thread] Current Thread [Next in Thread>