Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Where you need it, When you need it. Network World's iDemand platform delivers the information you need right to your desktop.

Student evades Cisco NAC; gets suspended

Cisco adjusts its default settings following student hack
By Tim Greene , NetworkWorld.com , 04/26/2007

A default setting in Cisco NAC gear allowed a University of Portland student to dodge a security scan by Cisco’s NAC software agent and get on the school network.

The exploit was the work of a sophomore who was suspended for doing it, and further use of the weakness has been blocked by changing a setting on the Cisco Clean Access box involved, according to Cisco.

By default, the device allows access to endpoints for which a “null” entry is made when the endpoint is queried about its operating system at login. With software version 4.1.1 of the Clean Access platform, the default has been changed to deny access for endpoints with null entries for operating system.

The initial allow-access default was in place so users with devices such as handhelds that can’t be scanned by the agent could gain access to the network, Cisco says.

The student’s exploit fooled the Clean Access device into not requiring an endpoint scan.

That is different from and less complicated than sending false scan results to the device, a weakness exploited and demonstrated by security experts at the Black Hat Conference in Amsterdam earlier this year (watch the video).

Even when it works, endpoint scanning doesn’t guarantee that the devices scanned are healthy, experts say, so customers of this class of NAC device should be aware of exactly what they can do to protect networks, experts say.

“The number one thing you learn in security is that there’s no such thing as client-based security,” says Ofir Arkin, CTO of NAC vendor Insightix, who outlined the vulnerabilities of various NAC schemes at the Black Hat Conference in Las Vegas last year.

When software on a machine reports on the state of the machine, it is possible to write a separate agent that can spoof the responses of an actual agent, he says. Or a user could install the agent on a virtual machine that complies with the security posture set by the NAC policy, then switch to a separate non-compliant machine once admitted to the network, he says.

Steve Hanna, a distinguished engineer at Juniper and leader of IETF and Trusted Computing Group efforts to standardize NAC, says hardware-based checks of endpoints are best. He advocates the use of Trusted Platform Module chips in PCs that creates a mathematical hash of the machine’s configuration and can alert users to any deviation from known acceptable configurations.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (8)
Login
Forgot your account info?

Acronym Best PracticesBy Anonymous on August 31, 2007, 4:33 pmWhenever acronyms are used, best practice says to spell it out the first time it is used in an article. This makes the article more worthwhile to read. NAC is...

Reply | Read entire comment

Student should be suspendedBy Anonymous on May 2, 2007, 5:04 pmIf the student would have disclosed the vulnerability to cisco and the university authorities when he discovered it, rather than abusing the flaw for 7 months, then...

Reply | Read entire comment

Student should be suspendedBy Anonymous on May 2, 2007, 5:03 pmIf the student would have disclosed the vulnerability to cisco and the university authorities when he discovered it, rather than abusing the flaw for 7 months, then...

Reply | Read entire comment

Student evades Cisco NACBy Tom Jones on May 2, 2007, 4:14 pmAll the student needs to do is set their browser agent to LINUX and they will bypass all scanning. Very easy to do.

Reply | Read entire comment

Easier methodBy JoeF on April 27, 2007, 2:01 pmThere is a way easier method to fool Cisco NAC: Make it think it is talking to a non-Windows machine. See http://www.securityfocus.com/archive/1/444424/30/0/threaded (Disclosure:...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

In all of these letters that you have posted, Chuck, I have yet to see one that apologizes to PZ Myers...- bullet

Join the Discussion