The enhanced password security in Cisco IOS introduced in 12.0(18)S allows an admin to configure MD5 encryption for passwords. Prior to this feature the encryption level on Type 7 passwords used a week encryption and can be cracked easily and the clear text password (type 0) as anyone would know is completely insecure. Anyone who can gain access to the privilege mode can view/decrypt these passwords.
Tag: Security
Enable/Configure DHCP Snooping in Cisco Catalyst Switches (IOS)
DHCP snooping is a DHCP security feature that provides security by filtering untrusted DHCP messages and by building and maintaining a DHCP snooping binding table. An untrusted DHCP message is a message that is received from outside the network or firewall causing denial of service attacks.
The DHCP snooping binding table contains the MAC address, IP address, lease time, binding type, VLAN number, and interface information that corresponds to the local untrusted interfaces of a switch. An untrusted interface is an interface that is configured to receive messages from outside the network or firewall. A trusted interface is an interface that is configured to receive only messages from within the network.
DHCP snooping can be enabled on the switch per vlan as it can intercept the DHCP messages at the layer2.
VLAN Hopping – Layer 2 Security exploit bypass Layer 3 security
VLAN Hopping is a Layer 2 security exploit by which a malicous user connected to a switchport on a Switch assigned to a VLAN can hop on and gain access to another VLAN which otherwise is not accessible. This security exploit allows the malicous hacker to bypass the IP Securities implemented at Layer 3.
Set Login Restrictions to protect Cisco IOS Routers & Switches
While no security is fool proof, it is important that we do as much as we can to ensure maximum protection on our netowrk devices like Routers and Switches. Cisco IOS has enhanced Login restriction features which can control login attempts to it. This includes time delay between failed login attempts, block period after a set of failed login attempts and audit logs of successful and failed login attempts.
These login restrictions provides more control and make it that more harder for unauthorised accesses and prevent against Dictionary based DoS attacks.
(more…)Secure Internet Explorer browsing with Haute Secure plugin
Haute Secure is a free Internet Explorer plugin that secures you from loading bad content or malicious content or download and install malware onto your PC. When the Haute Secure add-on on your internet explorer comes across bad content it will block access to the website and prompt you for further option. It will also warn of malicious content try to load from known website. With Phishing scams, malicious malware spreading minute and the identity theft scams, it is important that we secure the browsers thereby no malicious content is downloaded onto the PC. Haute Secure supports only Internet Explorer at the moment but Firefox is expected to be onboard soon. There is also a Windows Vista 64 bit supported version available download. (more…)