tgreene
Executive Editor

VPN security paper helps users get into an attacker’s mindset

Opinion
Feb 24, 20052 mins

* 'Penetration Testing IPSec VPNs'

Response to a newsletter last week indicates that many readers are interested in the nitty-gritty of setting up sound VPNs and are in search of tips on how to do so. So here are some more tips.

A current paper by two security experts offers some advice about how to test a VPN for vulnerabilities and suggests some tools that might be used. Titled “Penetration Testing IPSec VPNs,” (https://www.securityfocus.com/infocus/1821) the paper is a set of suggestions for testing a VPN followed by a description of a recommended VPN architecture that puts the VPN on a sound security footing.

The paper is valuable in that it walks readers through how an attacker would go about finding the best way to attack a particular VPN. It goes through port scanning, methods by which the attacker might deduce what VPN gateway is being used and forcing the gateway to use less secure Aggressive Mode authentication. It also goes into known vulnerabilities of individual vendor’s gear.

The paper hits on some mundane vulnerabilities that, if overlooked, could compromise security. For instance, changing default settings so attackers have to work harder if they want to get in and avoid easily guessed passwords.

By getting into the attacker’s mindset, those in charge of setting up corporate VPNs are better able to make sure they have proper defenses in place to thwart attacks.

The paper also runs through how the VPN is actually implemented from authentication to maintenance of software patches. This provides a useful checklist of considerations for keeping the VPN in shape once it is set up.