home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!know!hri.com!noc.near.net!inmet!bu.edu!rpi!zaphod.mps.ohio-state.edu!usc!nic.csu.net!csufres.CSUFresno.EDU!oleg
- From: oleg@csufres.CSUFresno.EDU (Oleg Kibirev)
- Newsgroups: alt.security
- Subject: Re: Lan watchers and sniffers
- Message-ID: <1992Nov12.200500.3166@nic.csu.net>
- Date: 13 Nov 92 04:04:59 GMT
- References: <BxHts7.3s2@minerva1.bull.it> <1dtgfcINN28a@neuro.usc.edu>
- Distribution: alt
- Organization: California State University, Fresno
- Lines: 51
- Nntp-Posting-Host: csufres.csufresno.edu
-
- In article <1dtgfcINN28a@neuro.usc.edu> merlin@neuro.usc.edu (merlin) writes:
- >In article <BxHts7.3s2@minerva1.bull.it> alexb@minerva1.bull.it (Alessandro Bottonelli) writes:
-
- >>ANYONE OUT THERE HAD ANY EXPERIENCE WITH PROTECTING LANS OF LARGE
- >>ORGANIZATIONS FROM LAN SNIFFERS ???
- >
- >Make LAN sniffing -- particularly password snooping -- a terminal
- >offense -- issue written notices such snooping will result in the
- >immediate dismissal of the responsible parties.
- >
-
- How would you like if the state was to issue a law tomorrow that
- exceeeding speed limit results in capital punishment? That's about
- what you suggest. I would disable an account for a couple of weeks --
- unless a person has really damaged important files, etc.
-
- It's a frustration to see how sites are adopting policies just design
- to say that users have no rights and {college, university, company}
- has all priviliges to erase there files, read their love letters and
- kick them out of {} if they don't like their face. Rather than to
- reflect real life.
-
- >
- >Divide your ethernet up into several segments using smart routers
- >-- isolate sensitive people/machines onto a relatively secure leg
- >of your ethernet -- put known snoopers on their own isolated leg.
- > ^^^^^^^^^^^^^^
-
- Aren't they supposed to be shot by now :). Seriously, this is likely
- to take a lot of time and money - potentially much more that to deal
- with security break-in.
-
- >Forbid indescriminant ethernet snooping -- only permit monitoring
- >for debugging purposes when filtering for some specific source and
- >destination address -- forbid packet sniffing by pc's -- require
- >all packet sniffing to be done via authorized accounts on audited
- >host systems such as sun systems with full logging turned on.
- >
-
- I don't remember what original article said, but I recall that software
- used for debugging was PC based.
-
- Anyway, fascist measures above will hardly prevent a person interested
- enough to do snooping anyway and will certainly make bull.it users
- hate Alessandro Bottonelli. It looks for me is the only way to avoid
- password snooping but still permit network debugging is end-to-end
- encryption. If network is using TCP/IP, original poster may want to
- look at latest version of BSD telnet[d] ( @gatekeeper.dec.com ) that
- has built-in encryption.
-
- Oleg
-