* NTA Monitor's 'Common VPN Security Flaws' white paper
A white paper from a U.K. security consulting firm is a handy item to download if you are considering IPSec VPNs, because it offers some sound advice on setting up a secure VPN regardless of what vendor you use.
A white paper from a U.K.security consulting firm is a handy item to download if you are considering IPSec VPNs, because it offers some sound advice on setting up a secure VPN regardless of what vendor you use.
The paper “Common VPN Security Flaws,” by NTA Monitor, points out problems customers can run into if they aren’t careful deploying their VPNs. Many of the flaws the paper points out are actually the potential for VPN weakness if IT staff doesn’t set up the VPN properly or doesn’t observe good general security practices.
The company points out one category of flaw it claims to have discovered in many vendors’ gear, and that it has warned the vendors about.
It has to do with the authentication phase of VPN setup when user name and password are the authentication method employed. Some VPN gear will respond that the name is invalid after the user name has been entered. This gives hackers trying to guess user names an edge because they can keep trying until they guess a user name, then move on to trying to guess just password.
If the software didn’t reject logon attempts until both user name and password were entered, hackers would not know when they have guessed the user name; they would only know if they had guessed both right. Guessing both is more difficult than guessing one.
The author of the white paper, Roy Hills, says he has notified the companies who make the VPN equipment in which he has found this flaw. He won’t say who they are so as not to encourage attacks on their products.
Download the paper for some sound advice that will help dot the “i”s and cross the “t”s on setting up a sound VPN.




