In case you didn't know you can run firmware developers by folk's other than Linksys on a Linksys router. Why? The best answer to this question is that these other developers are adding features that Linksys just doesn't have in their firmware. Like what? Most often it's support for advanced crypto (AES cypher) or routing (protocols other than RIP). Here's a link to an article by Eric at Roachfiend that goes into more detail about why.
Who should be thinking about this? From what I've seen this is something that just a handful of Linksys users might even consider and still fewer should do. If the feature that you want isn't in a Linksys router it is probably because it doesn't belong there. Case in point AES. Using AES to encrypt data over the wire is great and much more secure than DES or 3DES. The problem is that it's computationally harder and therefore to be done quickly you need a bigger, faster processor. My message is that if you want AES or advanced routing; buy a real router.
If you are still interested in doing this; more power to you. Experiment with it. My suggestion would be to make sure that you have another router of some sort to fall back on if the Linksys becomes wedged (i.e. the lights are on but it stops working) and can't be reset right away.
To learn more about the firmware choices that are out there see this article over on Linksysinfo.org.
"On the Firewall" is a online journal on the subject of network Firewalls and all things Internet security.
January 11, 2006
January 02, 2006
Top 10 ways to protect DNS
Something that I think everyone using the Internet should be concerned about is protecting the Domain Name System or DNS. Without DNS this blog, Google, all my other work, and everything else would be a series of IP addresses in dotted decimal notation.
While I'm not usually a fan of thinking found on Tech Republic (I have a link to a link sometimes to yet another link to some content problem) they do justice to this topic in this article.
Here is a link to the original article where I found this over at ZDNet: Top 10 ways to protect DNS | ZDNet Government Blog | ZDNet.com.
While I'm not usually a fan of thinking found on Tech Republic (I have a link to a link sometimes to yet another link to some content problem) they do justice to this topic in this article.
Here is a link to the original article where I found this over at ZDNet: Top 10 ways to protect DNS | ZDNet Government Blog | ZDNet.com.
December 24, 2005
PIX Firewall Documentation
This is a link to all PIX Firewall documentation from version 2.7 through 7.0.
December 19, 2005
Happy Holidays
If you have a moment (and are looking for a laugh) please take a look at my personal online holiday greeting to everyone in the IT business.
As the year draws to a close I have a lot to be thankful for. I find it's a good time to think about those who are less fortunate. If you can spare some money (it doesn't have to be much) these folks could sure use all of our help.
Happy holidays!
As the year draws to a close I have a lot to be thankful for. I find it's a good time to think about those who are less fortunate. If you can spare some money (it doesn't have to be much) these folks could sure use all of our help.
Happy holidays!
December 15, 2005
Common Vulnerabilities and Exposures - CVE
The list of Common Vulnerabilities and Exposures or CVE creates a list of standardized names for vulnerabilities and other information security exposures. The goal of CVE is to make it easier to share data across separate vulnerability databases and security tools. In the past if a vulnerability was discovered on one platform, say Windows and then also found in Linux it might have a different name or title while essentially being the same issue. This highlights a problem in the use of the word "vulnerability" in the security world today.
To many It professionals a "vulnerability" refers to any fact about a computer system that is a security concern in their network environment. The CVE web site cites the TCP/IP finger protocol as an example. Since the finger service reveals user information, many network operators put in place security policies that disallow finger from being run on some systems. That makes sense at the edge where finger service might be exploited, but there might be real uses for finger in other parts of the network. But because of the issue at the edge finger would be considered a "vulnerability" and described as such in that networks security policy.
Rather than referring to this as a vulnerability even though given different use cases different use cases this may not be considered to be vulnerabilities by everyone. So CVE introduces the term "exposure" to allow a service to be identified as potentially creating a security issue without necessarily being a problem.
CVE defines vulnerabilities and exposures like this:
To many It professionals a "vulnerability" refers to any fact about a computer system that is a security concern in their network environment. The CVE web site cites the TCP/IP finger protocol as an example. Since the finger service reveals user information, many network operators put in place security policies that disallow finger from being run on some systems. That makes sense at the edge where finger service might be exploited, but there might be real uses for finger in other parts of the network. But because of the issue at the edge finger would be considered a "vulnerability" and described as such in that networks security policy.
Rather than referring to this as a vulnerability even though given different use cases different use cases this may not be considered to be vulnerabilities by everyone. So CVE introduces the term "exposure" to allow a service to be identified as potentially creating a security issue without necessarily being a problem.
CVE defines vulnerabilities and exposures like this:
A universal vulnerability is a state in a computing system (or set of systems) which either:
- allows an attacker to execute commands as another user
- allows an attacker to access data that is contrary to the specified access restrictions for that data
- allows an attacker to pose as another entity
- allows an attacker to conduct a denial of service
- allows an attacker to conduct information gathering activities
- allows an attacker to hide activities
- includes a capability that behaves as expected, but can be easily compromised
- is a primary point of entry that an attacker may attempt to use to gain access to the system or data
- is considered a problem according to some reasonable security policy
December 12, 2005
Inexpensive Cisco Network Log Analysis
I saw a reference to an article titled Inexpensive Cisco Network Log Analysis by Mark Lachniet over at LinuxSecurity.com this morning. The log analysis article is well written and describes setting up Kiwi Syslog, configuring a PIX Firewall for syslog; and then configuring Sawmill log analyzer to provide reports based on the logged data.
Reading through the article the PIX configuration had one issue: the author omitted the "logging on" command that enables the logging process on the PIX.
If you are thinking of running Kiwi and the Sawmill analyzer I'd suggest starting out with a PIX Firewall that is at the same location as the syslog server. The PIX can generate quite a lot of log data and I'd suggest learning what your PIX will log given your network, users, and applications before trying to setup logging from a remote location.
Reading through the article the PIX configuration had one issue: the author omitted the "logging on" command that enables the logging process on the PIX.
If you are thinking of running Kiwi and the Sawmill analyzer I'd suggest starting out with a PIX Firewall that is at the same location as the syslog server. The PIX can generate quite a lot of log data and I'd suggest learning what your PIX will log given your network, users, and applications before trying to setup logging from a remote location.
December 01, 2005
How to configure your PIX Firewall for SSH
This (or click on the title above) is a paper I wrote on how to configure the PIX for SSH. It's really very easy to do.
What Model & Version of Linksys Hardware?
Subscribe to:
Posts (Atom)

If you are trying to upgrade the firmware on your Linksys router and you are not sure which version of the hardware you have make sure to look at the label on the bottom of the router. The version number of the router is right next to the model number.