Networking Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationNetworking Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 4th, 2004, 10:22 AM
kishorepalle kishorepalle is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 14 kishorepalle User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Wink Find Vulnerabilites in this Network Drawing

Hello Guys,

Can you find out any vulnerabilities given the network drawing. Also if you find any pls suggest ways to alleviate the prob.

http://www.geocities.com/pvkkishorereddy/Source/network.JPG

Thanx

Reply With Quote
  #2  
Old August 4th, 2004, 10:49 AM
gt3_dk's Avatar
gt3_dk gt3_dk is offline
!Ruff Ryder!
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jun 2004
Location: Québec, Canada... Represent!
Posts: 689 gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 7 h 10 m 12 sec
Reputation Power: 7
Send a message via Yahoo to gt3_dk
I'm just saying/guessing anything here so don't mind me!!! Dunno nothing about security but here's what I'd guess...

If someone on the internet manages to crash (or block) your router with a DoS attack ALL your computers will be deprived from the internet. Including your corperate web server. (Which I'm assumming is very bad.)

So a switch between the internet and the router, connect another router to it with only the server on that one.
Code:
                        _ Router 1 - old stuff
Internet -Switch-_ New Router - Corporate web server


This is testing myself... so don't be doing anything yet!

Reply With Quote
  #3  
Old August 4th, 2004, 11:40 AM
wanderer2 wanderer2 is offline
Contributing User
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Sep 2003
Location: Oregon
Posts: 1,889 wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 18 h 36 m 21 sec
Reputation Power: 425
Proper design would not have the web server in the same ip subnet as the corporate network. Actual recommended configuration is router then the web server then a router then the corporate network. Routers would be different brands so if one was compromised the 2nd isn't easy to do. Big corporations are at a three tiered router configuration.

Reply With Quote
  #4  
Old August 4th, 2004, 11:47 AM
kishorepalle kishorepalle is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 14 kishorepalle User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thanx for the replies guys. Keep em coming

Reply With Quote
  #5  
Old August 4th, 2004, 01:38 PM
gt3_dk's Avatar
gt3_dk gt3_dk is offline
!Ruff Ryder!
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jun 2004
Location: Québec, Canada... Represent!
Posts: 689 gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level)gt3_dk User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 7 h 10 m 12 sec
Reputation Power: 7
Send a message via Yahoo to gt3_dk
Heh... lucky guess... I wasn't so far off!

Reply With Quote
  #6  
Old August 4th, 2004, 09:16 PM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
I can not believe no one pointed out the most obvious there is NO FIREWALL in your drawing!!!!! Also you never have your unprotected internet router connecting internal private LANs or WANs!!!!! almost all (99%) large and small clients I have use only cisco routersthe thing is you put the core router connecting the WANs/VLANs behind the firewall!!!!!

look you got an "F" for security hehe!!!!

internet
|
router
|
Firewall (IDS, Anti spoofing, NAT/PAT) -> DMZ with webserver
|
Virus protection/anti spam/content filtering
|
Router to LAN1 and LAN2 or switch using inter VLAN routing
|
PCs and servers


side note...

Quote:
If someone on the internet manages to crash (or block) your router with a DoS attack ALL your computers will be deprived from the internet. Including your corperate web server. (Which I'm assumming is very bad.)


they still would not have internet as you only have one ISP and one internet router that is being DoS attacked!!! your design however would allow the two seprate LANs to keep talking to each other!!!

You get a "C" hehe

Quote:
Proper design would not have the web server in the same ip subnet as the corporate network. Actual recommended configuration is router then the web server then a router then the corporate network.


Very good you created a DMZ kinda. however you forgot the firewall!!! you get a "C+" hehe (in the future most implamentations have a seperate firewall that will have 3 interfaces one is the outside to internet router, the other is the DMZ, and the other is the link to the inside network all limititing access through ASA or ACLs to reach one another)

Im thinking wanderer2 will hate me some day but he should know by now I like to be a smart ^&* but mean well.

Last edited by juniperr : August 4th, 2004 at 09:40 PM.

Reply With Quote
  #7  
Old August 4th, 2004, 10:37 PM
wanderer2 wanderer2 is offline
Contributing User
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Sep 2003
Location: Oregon
Posts: 1,889 wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)wanderer2 User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 18 h 36 m 21 sec
Reputation Power: 425
So I was doing this for a grade!?! Oh &@$%#!!

And here I just thought I was helping someone with the basics in dealing with their homework. Have to leave the teacher a few surprises don't we?

Did I forget to mention the 2nd "router" had PIX? :-) Absolutely right about the multiple interfaces.

And yes you are a smart b$$ but that makes me feel right at home :-)

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationNetworking Help > Find Vulnerabilites in this Network Drawing


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway
Stay green...Green IT