pen-test
[Top] [All Lists]

Re: PIX configuration parser...

To: pen-test@securityfocus.com
Subject: Re: PIX configuration parser...
From: visitnikhil@gmail.com
Date: 7 Apr 2007 14:10:40 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Sun, 8 Apr 2007 04:47:55 -0600 (MDT)
Resent-from: pen-test-return-1078483876@securityfocus.com
Resent-message-id: <20070408104755.9CD84161F84@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hello Mohamed A. Kader,
 
Center for Information Security (CIS) has developed a tool called "Router Audit 
Tool" (RAT) for auditing Cisco PIX and Cisco Router configurations.
 
The Router Audit Tool performs a baseline test on the configuration of a Cisco 
Router and Cisco PIX. The tool provides a list of the potential security 
vulnerabilities discovered in an easy to read format. It even provides a list 
of commands to be applied to the router/PIX in order to correct the potential 
security problems discovered. 
 
The Router Audit Tool (RAT) downloads configurations of devices to be audited 
(optionally), and then checks them against the settings defined in the 
benchmark. For each configuration examined, it produces a report listing the 
following: 
A list of each rule checked with a pass/fail score.
A raw overall score
A weighted overall score (1-10)
A list of IOS/PIX commands that will correct problems identified.
In addition, RAT produces a composite report listing all rules (settings) 
checked on all devices, as well as an overall score.
 
More Information: 
http://www.cisecurity.org/bench_cisco.html
http://www.sans.org/reading_room/whitepapers/networkdevs/238.php
 
------------------
Nikhil Wagholikar
Security Analyst

NII Consulting
Web: www.niiconsulting.com

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>