Home > Midmarket CIO Tips > Security for the midmarket > Essential security testing tools for SMBs
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Essential security testing tools for SMBs


Kevin Beaver, CISSP
07.13.2005
Rating: -3.57- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Security testing -- vulnerability assessments, penetration tests and higher-level audits -- requires the proper tools. There's a wide variety of tools that perform dozens of different tasks, making it difficult to determine what you need to get a good view of your overall network security.

I've found several types of essential security testing tools that cover all areas of network security. I'm partial to commercial products because of their ease of use, reporting features and overall professional look and feel, but there are some good freeware and open source options as well. It all depends on your taste and budget.

General network scanning: A ping sweeper and port scanner tool will help you browse your network and find which hosts are active so you'll know what to probe. Mission Viejo, Calif.-based Foundstone Inc.'s SuperScan version 3 is great for getting things kicked off. SuperScan version 4 offers even more options for enumerating Windows systems that can prove to be very fruitful for scanning your own systems. Foundstone's SiteDigger is another neat tool for performing advanced Google queries. SiteDigger allows you to to dig up stuff you may not know has been publicized.

File scanning: A file-scanning utility can be something as basic as the DOS "find" command or the Search function built into Windows Explorer. Files containing private, confidential and other sensitive information are commonly stored on local hard drives and network shares that not everyone needs access to. This is a big vulnerability, especially when it concerns information that's regulated under the Health Insurance Portability and Accountability Act or the Gramm-Leach-Bliley Act.

A great tool for searching local and network drives is Effective File Search. It's blazingly fast (compared with standard Windows programs) and has a lot of interesting text search capabilities. Download this tool and search your network for dob, ssn, license, etc. and I guarantee you'll find some unprotected files in the wrong places.

Operating system scanning: Once you've identified systems with potential vulnerabilities you can dig deeper, looking for specific OS vulnerabilities: Share and file permissions, missing patches and weak security policy settings. A great starter tool that has received significant improvements over the years is GFI Software Ltd.'s LANguard Network Security Scanner. This is especially good if you have a lot of systems and pricing is an issue. My all-time favorite is QualysGuard by Qualys Inc. -- an extremely powerful and comprehensive tool that's a great fit for critical systems. If you're really price-conscious, many people rave about Nessus, which has recently become much more powerful and easier to use.

Password cracking: This is yet another hot issue, especially in light of all the emerging privacy and security regulations. My clients and I are often very surprised at how vulnerable most users' network passwords are. Plain old trial and error guessing or password cracking is still very common. A basic tool that can check for some common password weaknesses in Windows is Microsoft's Microsoft Baseline Security Analyzer. However, if you want to do some hard-core cracking you should look into Elcomsoft Co.'s Proactive Password Auditor, Cain and Abel, or the "no password left uncracked" RainbowCrack.

Web application scanning: These tools are essential for finding common flaws in Web applications. Some even scan back-end databases. They aren't flawless, as manual testing is still often required, but such tools can save you a lot of time and effort. A formidable tool to get started with is N-Stalker, along with my favorite, WebInspect, by SPI Dynamics inc. A reasonably priced tool for scanning back-end databases (you know, where the "money" is) is Application Security Inc.'s AppDetective line of products.

Network analysis: A network analyzer (a.k.a. sniffer) will dig up rogue systems, employees doing things they shouldn't be doing, protocols that don't belong, hack attacks in action, data leakage, and more. They're great for looking at both wired and wireless networks. TamoSoft's CommView products are great for getting started and are very reasonably priced. EtherPeek SE is an extremely powerful wired network analyzer that practically anyone can use. For wireless testing, outside of NetStumbler, check out the bootable Auditor collection of powerful Linux-based utilities and AirMagnet Inc.'s Laptop Analyzer -- all tools that can make your security testing much, much easier.


Kevin Beaver is founder and information security advisor with Atlanta-based Principle Logic LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Kevin has authored five information security-related books including Hacking For Dummies (Wiley), the brand new Hacking Wireless Networks For Dummies, and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach). He can be reached at kbeaver @ principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security for the midmarket
Risk assessment frameworks easy to employ
Compliance: Don't let your guard down
Single sign-on: Sensible security on scale
Laptop theft easily preventable while on the road
Information security requires organized teams
How to choose a DR service provider
Security on a midmarket budget
Security's crystal ball for 2008
Security outlook challenging for SMBs in 2008
SMB security reporting: The devil is in the details

Information security management for the midmarket
A cloud computing takeover? Google thinks so
An IT spring cleaning for CIOs
Single sign-on: Sensible security on scale
Spyware defense for the midmarket
Federal breach notification stuck in Congress
Anti-spam tricks for the midmarket toolbox (expert podcast)
Pre-emptive strategy best approach to breach notification
CIOs under fire and in front of the camera
Compliance-burdened CIOs turning to security management tools
Laptop theft easily preventable while on the road

Security tools for the midmarket
Security monitoring tools: Better to buy than build?
CIO Kathy Lang: Virtual patrolling center enhances campus safety
Marquette CIO enhances student safety with virtual patrolling
Spyware defense for the midmarket
Anti-spam tricks for the midmarket toolbox (expert podcast)
Compliance-burdened CIOs turning to security management tools
Information security requires organized teams
Phishing attacks slam midmarket
Security on a midmarket budget
Security outlook challenging for SMBs in 2008

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts