in reply to Problems with passwords

I realized the password on the wire problem after posting. The solution is the following. A host with a vlan directly to the device, so password isn't on the a sniffable wire. Use a cgi form to fill in information from operator, and then run commands on secured host.

Replies are listed 'Best First'.
Re: Re: Problems with passwords
by Rex(Wrecks) (Curate) on Mar 19, 2002 at 17:54 UTC
    Why bother using up an interface on the device. Look into using the serial port of the PC and the console port of the device (assuming the device has a console port, most do).

    On most network devices (a switch being an arguable exception) Ethernet ports are in enough demand that using one up for management is not only overkill but also expensive.

    Oh and if you are using an overlapped VLAN or even just a regular VLAN, any host on the switch can still sniff the traffic with ARP Poisoning, a little harder to do, but with EtterCap it's not even that hard.

    Your latest solution is better, but still not that secure, Telnet never will be in it's current incarnation unless you use something like IPSec to encrypt it (which is a good idea if the device supports IPSec). You really need to examine your Security Models a little closer, modern attacks are very good and there is very little that people won't try. The best example is monitoring a home DSL line for an evening, see how many malicious hits you get!

    "Nothing is sure but death and taxes" I say combine the two and its death to all taxes!