Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Routers, Switches, and Firewall testing |
|---|---|
| Date: | Mon, 3 Jan 2005 15:20:02 -0500 |
The Firewall Analyzer is less a penetration testing tool and more of a firewall rules analyzer. It started out first as a commercial product called the Lumeta Firewall Analyzer. From previous experience - for complex firewall configurations, it gives pretty decent insight. From their site: ---- Manual inspection of firewall rules involves a high probability of errors. Corporations need to have their firewalls audited in a systematic and comprehensive way to avoid the errors that leave security gaps. Only sophisticated computerized products are able to tackle such a task: there are simply too many possibilities for humans to handle unassisted. A comprehensive approach to firewall policy analysis requires analyzing all intrusion scenarios between all IP addresses (source and destinations), analyzing all possible source and destination ports and all protocols. A quick calculation shows that there are over 1030 possible combinations. On such a scale, active testing is not a viable option, since it would take longer than the age of our planet in order to complete. FA started its development in 1998 by a team of researchers at Bell Labs, led by FA creator Avishai Wool, PhD. It is protected by four patents in various approval stages. The FA report contains over 1,500 richly-linked HTML-based files. This structure allows a very easy drill down to more detail, without cluttering the high level view. All the reports may be stored on a server to allow easy access to any authorized user, or exported to MS office file format such as Word or Excel. This allows you to import the results of the firewall analysis into a database, as well as to include portions of the reports in tailor-made documents. ---- Steve
-----Original Message----- From: Chuck Fullerton [mailto:chuckf69@ceinetworks.com] Sent: Monday, January 03, 2005 1:25 PM To: Greg Dreelin; pen-test@lists.securityfocus.com Subject: RE: Routers, Switches, and Firewall testing Here is a commercial tool that is rather new but looking very promising.
www.algosec.com It is a Firewall Analysis tool. It imports all configs into the software and analyzes it for possible vulnerabilities. Has some bells and whistles to make the job easier.. Chuck F. -----Original Message----- From: Greg Dreelin [mailto:gdreelin@edsicorp.com] Sent: Monday, January 03, 2005 9:59 AM To: pen-test@lists.securityfocus.com Subject: Routers, Switches, and Firewall testing Pen-Test Group, I have a question to present that is in need of a good answer. The question I have is "Is there any good programs for VAP testing routers, switches, and firewalls?" I know there is the Router Assessment Tool (RAT) for Cisco router and there is FTEST for firewalls, but are there any other programs that can be loaded on to a Laptop Toolkit that can do the testing? Looking for a all in one program if there is such a thing. If anyone has any good ideas please let me know. Thanks ahead. v/r Gregory (Greg) S. Dreelin Senior Systems Analyst Marine Corp Information Assurance Assessment Team (MCIAAT) gdreelin@edsicorp.com 540-720-0841/0843/2093 /2106 Cell 703-843-1962 __________________________________________________________________ 'Information is Knowledge, Knowledge is Power, and Power is Dangerous"
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Routers, Switches, and Firewall testing, R. DuFresne |
|---|---|
| Next by Date: | Information Systems Security Assessment Framework (ISSAF) Draft0.1, Balwant Rathore |
| Previous by Thread: | RE: Routers, Switches, and Firewall testing, Bob Davies |
| Next by Thread: | Re: To moderator - disregard my last post, Don Parker |
| Indexes: | [Date] [Thread] [Top] [All Lists] |