<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Inliniac</title>
    <link>https://inliniac.net/blog/tag/security/</link>
    <description>Recent content in Security on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 24 Aug 2007 16:26:47 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/security/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Follow up on Sguil securtiy</title>
      <link>https://inliniac.net/blog/2007/08/24/follow-up-on-sguil-securtiy/</link>
      <pubDate>Fri, 24 Aug 2007 16:26:47 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/08/24/follow-up-on-sguil-securtiy/</guid>
      <description>&lt;p&gt;In the discussion about my post about Sguil security there have been a number of ideas and general thoughts. I&amp;rsquo;d like to write about them here to we can further discuss them. There seems to be consensus on that when a sensors is rooted, there is nothing we can do to prevent injection of bogus data as long as it isn&amp;rsquo;t malformed.&lt;/p&gt;&#xA;&lt;p&gt;Having the agent authenticate itself is a solution, but it relies on the agent credentials to remain secret. So when a webserver is rooted the attacker will have access to the credentials as they will be stored on the webserver itself. So this approach does provide an extra layer of defense but local roots aren&amp;rsquo;t uncommon, so it remains risky. It may still be worth the effort though.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts on Sguil security</title>
      <link>https://inliniac.net/blog/2007/08/24/thoughts-on-sguil-security/</link>
      <pubDate>Thu, 23 Aug 2007 22:25:26 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/08/24/thoughts-on-sguil-security/</guid>
      <description>&lt;p&gt;Sguil is build using a server and sensors. Traditionally the sensors are passive monitoring agents running Snort and a few other tools. Best practice was (and still is) to separate the management network of these sensors and server from the monitored network(s). This way it would be fairly hard for an attacker to get a shot at the Sguil server.&lt;/p&gt;&#xA;&lt;p&gt;Sguil of course, would be a extremely interesting target for hackers. It contains so much info about the monitored network. Also, it has realtime access to all network traffic. A hacker may also be interested in shutting Sguil down to avoid detection.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
