Nipper 0.11.0 updated and doped with many options
Monday 31 December 2007
Nipper processes network device configuration files, performs a security audit and outputs a security report with recommendations and a configuration report. nipper currently supports Cisco IOS, PIX, ASA, FWSM, NMP, CatOS and Juniper NetScreen devicesChanges: The following nipper features have been added or improved with this release. A * represents new features.
General Program Features:
Added support for an external configuration files.
Modified input code to enable support for multiple file configurations.
Added support for Nortel Passport devices.
Added support for Checkpoint Firewall-1 devices.
Added support for SonicWall Firewalls.
Added option to force a config type.
Added conclusions section to security audit.
Added a stdin timeout to stop some users from staring at a blank console.
Added filter/policy/acl object HTML report to the object definitions.
Added man pages for nipper and nipper.conf *
Added Makefile.
Removed CMake file.
Improved on-line help system.
Improved Nipper error reporting and feedback.
Improved command processing.
Improved program return codes.
Expanded the built-in mini dictionary.
Improved firewall rule auditing.
Improved built-in HTML CSS.
Moved main introduction to after the table of contents.
Improved contents page.
Improved report introduction.
Improved report command text output.
Improved ScreenOS config processing.
Improved HTML report opening.
Feature 1839093 - More info on ACL audit lines. *
Cisco Security Device (PIX/ASA/FWSM) Security Audit:
- Dictionary-based Passwords
- Weak Passwords
- Vulnerabilities
- uRPF
- SNMP
- Flood Guard
- ACL
Cisco Security Device (PIX/ASA/FWSM) Configuration Reports:
- Static PAT
- Static NAT
- SNMP
- Interfaces
- HTTPS
- Flood Guard
- Name Mappings
- Objects
- ICMP
- ACL
Cisco IOS-based Device Configuration Reports:
- ACL
- Interfaces
Cisco IOS-based Device Security Audit:
- ACL
Cisco CSS-based Device Configuration Reports:
- ACL
Cisco CSS-based Device Security Audit:
- ACL
ScreenOS-based Device Security Audit:
- Dictionary-based Passwords
- Weak Passwords
- SNMP v1/2
- SSH Protocol Version 1
- Policy Lists
ScreenOS-based Device Configuration Reports:
- SNMP Configuration
- Zones
- Administrative Settings
- Policy Lists
- Name Mappings
- Name Mapping Groups
- Default Policy
Firewall-1-based Device Security Audit:
- Policy Collections
Firewall-1-based Device Configuration Reports:
- Object Definitions
- Service Definitions
- Policy Collections
Passport-based Device Security Audit:
- Filters
Passport-based Device Configuration Reports:
- Software Version
- Monitor Version
- Passport Device configuration Type
- Hostname (guessed)
- Filters
- Filter Sets (incl. Global Sets)
SonicOS-based Device Configuration Reports:
- Access Rules
SonicOS-based Device Configuration Reports:
- Device Name
- Serial No.
- IP Address and Network Mask
- Access Rules
- Service Definitions
POSTSCRIPTUM
RELATED ARTICLES
Configurations checks, Local auditing, Nipper,
31 August 2008 : Nipper 0.12.0 released (featuring library and command line based)
17 August 2008 : Nipper 0.11.10 released
30 July 2008 : Nipper 0.11.9 released
21 June 2008 : Nipper 0.11.8 in the wild
11 May 2008 : Nipper updated to 0.11.7
Security Dashboard





