• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Can this be stopped?

Yeah.

I guess some of us are competent and concerned about network security and some.... aren't.

Before you go internet nut swinging you have no clue what people's credentials are. You should think about a full policy before saying local admins are the devil. You can control this with GPO, but I assume you know that. If our security was so bad as you insist it is, why would our SOX and EY auditors not have one word to say about security, what about the 3rd party company hired to test security against us. Assuming they all dont know what their doing because of my one line shows your ingnorance for the big picture.
Go back to maintaining mom and dads home network troll.
 
Go back to maintaining mom and dads home network troll.
You'd probably be well advised not to make baseless assumptions about the employment of other people.

My "mom and dads home network" has almost 1000 users who work all over the state.

I didn't make any insulting (and probably wrong) assumptions about what you do for a living. Don't do so to me.

No halfway decent network administrator who cares about security would let all of the users in his "Fortune 500 company with thousands of clients" have local admin access. It's just unacceptable. It's basically rule #1 of administering workstations.

You can get away with it, sure, but it's still a terrible, terrible idea and it's only a matter of time before something catastrophic happens.
 
Good point.
OP, why do you have two public IPs? Perhaps you can eliminate this VERY easily by dropping the 2nd one?

because we got a T1 they assignd us 6 IP's (4 usabel) with it. i guess i could ask them to take the others away and only give us the one? but knowing the ISP's here anything that causes work they will refuse to do and also if we ever need more IP's i am sure it would be a nightmare to get them back
 
Just use local permissions and cut the user access down. It will solve all your problems and some that you don't yet even know you have.

one of my office buildings has just 1 computer... just 1 stand alone unit and even that has the access limited using gpedit.msc

And there coms the other problem (which i think a DC would get around), our main software client we use, needs admin rights to run, even creating a user and giving that app full admin rights on files and dir. it needs, still wont work and our devs refuse to fix it cause they dont see it as an issue.
 
I'll add that corrective action needs to be taken with this user. I suggest implementing some IT policies and have the users agree to them immediately if you have not already done so.

Definately. Businesses/Organizations should have computer/network usage policies in place. Every new hire should be required to sign a form stating that they understand said policy before the person can be allowed on a computer.

This won't directly make your network more secure, but it'll help in disciplining troublemakers.
 
I had spoke with the CEO and due to some previous legalities and worry of backlash the move to a new company name and such recently, he has given me the approval to proceed with the usage policy and have people sign it, i recently found out our accountant also has been staying late at night using her webcam and Skype which is a bandwidth hog to talk to friends back home!!! (no wonder speeds have been shiet lately) also i spoke with the person whom's actions got me to start this thread and explaind to them the problems behind it, he understood it since i really put it to him what he had potentially exposed and the CEO (who i have known for 7 years and i would say we are close) would have his ass in a second and he should know that.


All things aside, i am still taking the great advice given and moving forth so it will never be an issue so long as i work here.


On the usage policy does anyone have a basic layout of one to which i can start from? just not completly sure how i should lay it out, or present it?
 
There is always a way to give these programs enough access. I worked for a large chain of Hotels and the software they used was DOS based. I had it running very well on Citrix! If I can do that I am sure you can come up with a way to sort your program access problems.

Just remove the icon for the network connection in the bottom right, stop them being able to access the command prompt and remove access to control.exe. They can't change their IP then. You can cut down the admin account using gpedit.msc they will still have access to all files etc but won't be able to mess with the PCs settings.
 
Before you go internet nut swinging you have no clue what people's credentials are.

You should think about a full policy before saying local admins are the devil.
I provided a scenario based on the "domain users in the local administrators group" line that is easily repeatable and, aside from shutting from admin shares which are used by many many different applications, there's little you can do to stop it. I also provided a way around providing local administrative access (regmon/filemon and specific file access) and a better policy to apply (individual credentials on individual systems rather than "Domain Users") when faced with challenges. Many applications will also work just fine with Power User permission rather than full-blown administrative access.

If our security was so bad as you insist it is, why would our SOX and EY auditors not have one word to say about security, what about the 3rd party company hired to test security against us. Assuming they all dont know what their doing because of my one line shows your ingnorance for the big picture.
The answer is very simple - many auditors and security companies rely on software and many security applications scan from an external aspect without administrative credentials. Want to see something scary? Ask them to run a scan using user credentials rather than scanning against the perimeter without credentials.

Spoofing a generic user account is a relatively easy thing to do and a hard thing to track down and secure but thanks to all domain users being administrators on your desktops, all it takes is one moment of weakness. We could debate probability all day long until we're both tired but the fact of the matter is it happens. When it happens and one hack gets admin access on one box, it's easily contained. When a hack gets admin access on one of your boxes, they now have admin access on all desktops in your environment. Look at it any way you want and defend it any way you want, it's still a bad decision.

Go back to maintaining mom and dads home network troll.
See the first quote as you said it best yourself. You're making a wild assumption as well. If you would have said that about me or a number of others here you'd be sorely mistaken. Not that I'm the end-all-be-all either, there are better. You stick around in this industry long enough and you'll realzie that the truly frightening fact of the matter is that nothing is ever secure. If it can be built, it can be unbuilt.

It is not so much about security as containment - debating that the worse-case scenario will never happen gets you no where, it will. The difference is whether you will be prepared for it or not.

You are in IT and as such are in a unique position of power in the 21st century. With that power comes responsibility and more importantly the ability to change. IF your company continues to buy software that does not work well in an enterprise space, you need to be letting your CIO know. There's a lot more at stake than your ego or even your job.
 
MrGuvernment,
It's pretty easy to only allow your DHCP address range through the router. Assuming your usable internal address range is 10.0.0.1-10.0.0.254, here's how you do it

login to the router then type:
ena
config t
access-list 102 permit ip 10.0.0.0 0.0.0.255 any
int fa0 (assuming your LAN interface is FastEthernet0)
ip access-group 102 in
exit
write mem
 
^^ sweet!! just saved that!!

havent had a chance to mess with th router yet, fixing a MySQL db currently cause the last operations people didnt bother to have any type of backs-ups, or raid set ups! argh what fun!
 
Assuming they all dont know what their doing because of my one line shows your ingnorance for the big picture..

Which is why I was asking about the line of business before jumping into an online mudfest, with the credentials question aside, has anyone at your business been able to go the regmon/filemon and specific file access route that Orinthical suggested (this being the route that I and my coworkers have used in the past) for your problem applications?


EDIT:
For the OP on policy docs:
http://www.sans.org/resources/policies/

http://www.sans.org/resources/policies/Acceptable_Use_Policy.pdf
 
I may of missed something because I didn't read the entire thread, but....


If this guy is abusing the network, and violating company policy, he needs to be written up..

Better yet, why does he have the ability to change the IP on his workstation?
 
because we got a T1 they assignd us 6 IP's (4 usabel) with it. i guess i could ask them to take the others away and only give us the one? but knowing the ISP's here anything that causes work they will refuse to do and also if we ever need more IP's i am sure it would be a nightmare to get them back

Then I would definitely just block the IP addresses- only allowing those in your DHCP range. Still not quite sure how they were even working in the first place... Might be something you look into- but fixing it now will stop it.

^^ sweet!! just saved that!!

havent had a chance to mess with th router yet, fixing a MySQL db currently cause the last operations people didnt bother to have any type of backs-ups, or raid set ups! argh what fun!

After testing it to make sure it works (And that the IP addresses don't work), be sure to save it to your startup config (right now (unless you did already) it is just running in RAM. As soon as power is lost- settings are forgotten).
copy run start is the command to do that.
 
Two things:

1) Fix your NAT settings
2) Remove this person's admin rights. No admin rights, can't set an IP.
 
Then I would definitely just block the IP addresses- only allowing those in your DHCP range. Still not quite sure how they were even working in the first place... Might be something you look into- but fixing it now will stop it.



After testing it to make sure it works (And that the IP addresses don't work), be sure to save it to your startup config (right now (unless you did already) it is just running in RAM. As soon as power is lost- settings are forgotten).
copy run start is the command to do that.



havent touched the router yet, not had a chance too, but his system is off the IP.

Two things:

1) Fix your NAT settings
2) Remove this person's admin rights. No admin rights, can't set an IP.


as for admin rights and just not being able to change tIP, our software we use for internal reporting anf other things, requires Admin rights on the local computer and our devs refuse to change that (shit part of a developer owning half the company)

power user doesnt work, no other type of account works but admin, trust me i have tried and we dont have a DC so i cant do it that way.
 
he has admin right and thus access to gpedit, and also knows about gpedit and how to use it.
 
Use group policy at the Active Directory level to prevent this.
You can set a GPO to prevent 'domain users' access to local gpedit along with many other things including changing IP address (you can prevent users from changing network settings through group policy)
Be careful GP edit is very powerful and needs to be well thought out.
 
well you need to make it hard for him.

They way I cut things down is to use gpedit and make it so the only way to get back into gpedit is to create a cmd.exe icon on the desktop and run it from there. If he goes to the extent to get into it he needs to be put into a disciplinary.
 
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.

For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.
 
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.

For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.
Agree 100%.

I said a page or so ago that the OP is wholly unqualified to configure this device. A forum thread is not the place to learn truly basic network topology.

Your best bet is to simply find a basic router configuration/network design book and bury yourself in it or to simply find someone who knows what's going on.
 
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.

For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.

Exactly. I too agree 100%.

All an AD or user-rights solution will do is put a temporary band-aide on the problem, not actually fixing the problem itself.
 
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.

For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.

At the very least taking that right away will put a temporary, immediate solution in place, this taking the compromised portion of the network out.
This is especially true since the OP can't get into the router and change it to fix it right now.
Then, after you have the band-aid on, you go in and fix the problem later.

Or you can let things go, and let this user run rampant on the internet doing who knows what while you wait for who knows how long to figure out how to fix it. Since this user is obviously a local admin, he can do a lot of damage quickly. And, again, obviously he knows enough to be a concern.

OP; have you thought of a proxy server, by any chance? That way you can at least still see (and filter if wanted) what this user is doing.
 
I agree that cutting the user down is not the solution in the long run but right now it will sort the problem while he gets stuck into the router setup.
 
Agree 100%.

I said a page or so ago that the OP is wholly unqualified to configure this device. A forum thread is not the place to learn truly basic network topology.

Your best bet is to simply find a basic router configuration/network design book and bury yourself in it or to simply find someone who knows what's going on.


I know what needs to be done, but need to learn how to do it with this specific router, give me a smoothwall, give me a watchguard and i could do it with my eyes closed (i am te one who configured our router access for our hosted systems / website / mail servers in our ISP with our watchguard x550e and have had a few friends test it (some very talented friends who know what is what when it comes to security and it passed their tests [they have been too busy to help with this, why i posted here), i have just never done it with a CLI based router such as a cisco 1701,

Am i wholly unqualified to handle this, no, am i wholly unqualified for knowing how to do it on a cisco 1701, yes.

This thread is basically my burrying my head in it and finding out what specifiically the issue was as i wasnt sure (since i have never seen this issue crop up before) since i wasnt sure with the Cisco, and as said, i was not the person who configured this router in the first place, 2 other people handled this job prior to me, who clearly knew a hell of alot less then me, otherwise this wouldnt be an issue and now i am the one who has to fix it.

I know i can handle this task and i know i can get this stopped, otherwise i would of taken this task on, network security has always been something that had my interested, starting 7 years ago when broadband first came out and thing were wide open to have fun with.
 
At the very least taking that right away will put a temporary, immediate solution in place, this taking the compromised portion of the network out.
This is especially true since the OP can't get into the router and change it to fix it right now.
Then, after you have the band-aid on, you go in and fix the problem later.

Or you can let things go, and let this user run rampant on the internet doing who knows what while you wait for who knows how long to figure out how to fix it. Since this user is obviously a local admin, he can do a lot of damage quickly. And, again, obviously he knows enough to be a concern.

OP; have you thought of a proxy server, by any chance? That way you can at least still see (and filter if wanted) what this user is doing.


i was considering this aswell, we have an SBS license, installing it and using ISA as the main gateway out, basically doing what the user did with the IP, setting up the external IP on the ISA and forcing everyone to go through it.

T1--> CISCO--->ISA--> Network

this way he definetly couldnt get around the ISA or use an external IP as i would not allow it via the ISA, this would be a temp solution until i get the router properly configured.
 
i was considering this aswell, we have an SBS license, installing it and using ISA as the main gateway out, basically doing what the user did with the IP, setting up the external IP on the ISA and forcing everyone to go through it.

T1--> CISCO--->ISA--> Network

this way he definetly couldnt get around the ISA or use an external IP as i would not allow it via the ISA, this would be a temp solution until i get the router properly configured.

That's a good place to start, though I'm sure it'll be flammed by some other users here.
I would do either that, or lock his rights down to start until you can get the backbone problems straightened out. Once they're done, you can remove the proxy/lockdown, and be fine an dandy.
From the sounds of it, it will take some time to figure out what excatly is and is not happening in that router. 1701's are pretty dated as-is, too. You can always take a huge security risk and post the router's config for us to take a look.
Not that what that user is doing isn't much better, anyway. You're entire network is wide open thanks to him bypassing everything and using a public IP.
 
once i get into the router, going to try tonight (finally finished up fixing one of our main MySQL DB servers implementing a raid 5 array and a backup system)

So now i can move on to conquering the router issue!

I know compared to many i dont know jack, but that certainly doesnt mean i dont know what i am / should be doing, or need to do, is just how to do it with the cisco, CLI for some reason has always intimidated me, i didnt get into computer until win98, so DOS was never something i used much, i got spoiled with purdy GUI crap.

I already talked to the CEO the other day about my friend who i trust with my life, being able to configure the router temporarily since should be visiting me possibly end of november or dec, and is cisco certfied out the ying yang.
 
I know compared to many i dont know jack, but that certainly doesnt mean i dont know what i am / should be doing, or need to do, is just how to do it with the cisco, CLI for some reason has always intimidated me, i didnt get into computer until win98, so DOS was never something i used much, i got spoiled with purdy GUI crap.

With all due respect, you *don't* know what you should be doing. You obviously don't understand even fundamental network topology. Please either get someone who does or get some books and educate yourself.
 
perhaps i am missing something

understanding basic network topology, and not knowing how to configure a specific model of router seem like 2 VERY different things to me....
 
perhaps i am missing something

understanding basic network topology, and not knowing how to configure a specific model of router seem like 2 VERY different things to me....

Yes, they are. You don't understand either.

I'm not trying to be mean or anything. Just honest. You're obviously uneducated in the basics of network management. It sounds like you have some experience with consumer routers which do virtually everything for you, but no experience or training in setting up a "real" router.
 
how is this helping him?

I'm trying to encourage him to go and get some education, whether it's a course, an O'Reilly book, or whatever. He doesn't have a grasp of the fundamentals, but he thinks he does, and he's trying to figure out what exact "thing" he needs to do to patch up this problem.

I'm trying to make him understand that a decent grasp of networking fundamentals is what he needs, not a command to make a Cisco router do... something, but he's not quite sure what.
 
I did not read thru all 5 pages so maybe this was already said. Why not just remove his access from changing his IP address in the first place. remove his admin rights to his box and he wont be able to assign a static.


problem solved.
 
how is this helping him?

My thoughts exactly.


OP...
From the options given- it seems like these are some of them you have.

  • Lock down access to changing IP addresses.
    As said- for right now today- this may be your fastest fix. But the problem is still there. Nobody should be able to run those IP addresses on your network. Simply locking down the access on those boxes doesn't solve the problem. Thus- it turns to a router-configuration solution.
  • Configure the router.
    Only "true" way to fix the issue. Routers don't give a crap about OS- so fix the problem here- you fix it everywhere for good.
  • Run everything through ISA on a SBS.
    This is pretty much the same as configuring the router- only your SBS box would become your router...
 
Back
Top