I’m still shocked at how little some admins know about their own networks. I often advise clients on the recon steps we take and suggest they do the same. For example, I’ve often been on sites that have clear and defined “no wifi” policies, but yet, during wireless LAN surveys paired with ARP discovery, we often find they indeed have wireless access points all over the place, and worse yet, nobody seemed to know it. I’ll often see old Unix servers still connected to the network and not documented anywhere. It usually turns out these servers haven’t been used (or patched) for years. Just nobody bothered to unplug them or disconnect them from the LAN. Why? How can one possibly secure something if they don’t know it’s there? How can a security guard physically secure a building if said building has 10 doors and he only knows about 5 of them? Keatron
Recon yourself?
Analysis
Jan 5, 20091 min




