ARTICLE

Nipper 0.11.0 updated and doped with many options

Monday 31 December 2007

Nipper processes network device configuration files, performs a security audit and outputs a security report with recommendations and a configuration report. nipper currently supports Cisco IOS, PIX, ASA, FWSM, NMP, CatOS and Juniper NetScreen devices

Changes: The following nipper features have been added or improved with this release. A * represents new features.

General Program Features:
- Added support for an external configuration files.
- Modified input code to enable support for multiple file configurations.
- Added support for Nortel Passport devices.
- Added support for Checkpoint Firewall-1 devices.
- Added support for SonicWall Firewalls.
- Added option to force a config type.
- Added conclusions section to security audit.
- Added a stdin timeout to stop some users from staring at a blank console.
- Added filter/policy/acl object HTML report to the object definitions.
- Added man pages for nipper and nipper.conf *
- Added Makefile.
- Removed CMake file.
- Improved on-line help system.
- Improved Nipper error reporting and feedback.
- Improved command processing.
- Improved program return codes.
- Expanded the built-in mini dictionary.
- Improved firewall rule auditing.
- Improved built-in HTML CSS.
- Moved main introduction to after the table of contents.
- Improved contents page.
- Improved report introduction.
- Improved report command text output.
- Improved ScreenOS config processing.
- Improved HTML report opening.
- Feature 1839093 - More info on ACL audit lines. *

- Cisco Security Device (PIX/ASA/FWSM) Security Audit:

  • Dictionary-based Passwords
  • Weak Passwords
  • Vulnerabilities
  • uRPF
  • SNMP
  • Flood Guard
  • ACL

- Cisco Security Device (PIX/ASA/FWSM) Configuration Reports:

  • Static PAT
  • Static NAT
  • SNMP
  • Interfaces
  • HTTPS
  • Flood Guard
  • Name Mappings
  • Objects
  • ICMP
  • ACL

- Cisco IOS-based Device Configuration Reports:

  • ACL
  • Interfaces

- Cisco IOS-based Device Security Audit:

  • ACL

- Cisco CSS-based Device Configuration Reports:

  • ACL

- Cisco CSS-based Device Security Audit:

  • ACL

- ScreenOS-based Device Security Audit:

  • Dictionary-based Passwords
  • Weak Passwords
  • SNMP v1/2
  • SSH Protocol Version 1
  • Policy Lists

- ScreenOS-based Device Configuration Reports:

  • SNMP Configuration
  • Zones
  • Administrative Settings
  • Policy Lists
  • Name Mappings
  • Name Mapping Groups
  • Default Policy

- Firewall-1-based Device Security Audit:

  • Policy Collections

- Firewall-1-based Device Configuration Reports:

  • Object Definitions
  • Service Definitions
  • Policy Collections

- Passport-based Device Security Audit:

  • Filters

- Passport-based Device Configuration Reports:

  • Software Version
  • Monitor Version
  • Passport Device configuration Type
  • Hostname (guessed)
  • Filters
  • Filter Sets (incl. Global Sets)

- SonicOS-based Device Configuration Reports:

  • Access Rules

- SonicOS-based Device Configuration Reports:

  • Device Name
  • Serial No.
  • IP Address and Network Mask
  • Access Rules
  • Service Definitions

POSTSCRIPTUM

Download


RELATED ARTICLES

Configurations checks, Local auditing, Nipper,

31 August 2008 : Nipper 0.12.0 released (featuring library and command line based)
17 August 2008 : Nipper 0.11.10 released
30 July 2008 : Nipper 0.11.9 released
21 June 2008 : Nipper 0.11.8 in the wild
11 May 2008 : Nipper updated to 0.11.7