<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/infrastructure_security_services</link>
 <description></description>
 <language>en</language>
<item>
 <title>Voice-Over IP (VoIP) Security Assessments</title>
 <link>http://website.isecpartners.com/voice_over_ip_voip_security_assessments</link>
 <description> &lt;ul&gt;
&lt;li&gt;Voice-Over IP (VoIP) Security Assessments
&lt;ul&gt;
&lt;li&gt;Analysis of infrastructure configuration and hardening
&lt;li&gt;Analysis of phone network interfaces and conference bridge controls
&lt;li&gt;Analysis of network based recording and storage&lt;/ul&gt;
&lt;li&gt;Security Analysis of VoIP Architecture
&lt;ul&gt;
&lt;li&gt;Authentication (H.225 Registration and SIP)
&lt;li&gt;Authorization (E.164 Alias, IP address, hostnames)
&lt;li&gt;Encryption (SSIP, AES, SRTP)
&lt;li&gt;Denial of Service Susceptibility (911 and/or operation calls)
&lt;li&gt;Protocols (SIP, H.323, RTP, MGCP)&lt;/ul&gt;
&lt;li&gt;VoIP Attacks
&lt;ul&gt;
&lt;li&gt;Eavesdropping, Hijacking, and Replay Attacks
&lt;li&gt;Spoofing (Endpoints, Gatekeepers, Border Controllers)
&lt;li&gt;Registration Password Compromise
&lt;li&gt;Denial of Service Attack (SIP and H.323)
&lt;li&gt;Attacks on VoIP Hard phones/Soft Phones
&lt;li&gt;H.225 Registration Attacks and DOS&lt;/ul&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Mon, 31 Jul 2006 01:02:35 -0700</pubDate>
 <dc:creator>chris</dc:creator>
 <guid isPermaLink="false">79 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Network Vulnerability Assessment</title>
 <link>http://website.isecpartners.com/network_vulnerability_assessment</link>
 <description> &lt;ul&gt;
&lt;li&gt;Assess to understand the risk and threat exposure level from malicious/unauthorized users&lt;/li&gt;
&lt;li&gt;May be performed on internal or external networks&lt;/li&gt;
&lt;li&gt;Discover the extent of network exposure to Internet attackers, or malicious insiders&lt;/li&gt;
&lt;li&gt;Enumerate and exploit vulnerable network services, applications, devices, and operating systems&lt;/li&gt;
&lt;li&gt;Perform vulnerability analysis and threat exercise to determine possible extent of damage or ease of access&lt;/li&gt;
&lt;li&gt;Document vulnerabilities, remediation, and root causes of insecurity&lt;/li&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 00:47:02 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">58 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Host and Device Security Services</title>
 <link>http://website.isecpartners.com/host_and_device_security_services</link>
 <description> &lt;p&gt;Improve the security of:
&lt;ul&gt;
&lt;li&gt;Operating systems
&lt;li&gt;Firewalls
&lt;li&gt;Routers/switches
&lt;li&gt;VPNs
&lt;li&gt;Mainframes (OS/390) and AS/400.&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:01:16 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">60 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Storage Security Assessments</title>
 <link>http://website.isecpartners.com/storage_security_assessments</link>
 <description> &lt;p&gt;&lt;uL&gt;
&lt;li&gt;Security Analysis of SAN/NAS Architecture&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Authentication (CHAP, DH-CHAP, None)&lt;/li&gt;
&lt;li&gt;Authorization (WWN, iQNs, UID/GIDs, SIDs)&lt;/li&gt;
&lt;li&gt;Encryption (Decru/Neoscale vs. Software encryption)&lt;/li&gt;
&lt;li&gt;Denial of Service (Data destruction and unavailability)&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;Security testing of SAN/NAS networks&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;iSCSI SAN (CHAP Attacks, iQN Spoofing, SNS Man-in-the-Middle, Domain/iGroup Hopping)&lt;/li&gt;
&lt;li&gt;NAS (Authentication Attacks, Authorization Bypass, Export/Share enumeration)&lt;/li&gt;
&lt;li&gt;Fibre Channel SANs (WWN Spoofing, Zone Hopping, DH-CHAP Attacks, LUN Mask Subversion)&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 00:53:58 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">59 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Network Access Control - 802.1x</title>
 <link>http://website.isecpartners.com/network_access_control_802_1x</link>
 <description> &lt;p&gt;Testing of the  802.1x/NAC solutions:
&lt;ul&gt;
&lt;li&gt;Implementation of 802.1X
&lt;ul&gt;
&lt;li&gt;Server / client implementation weaknesses with fuzzing
&lt;li&gt;Authentication/Authorization bypass of 802.1X implementation &lt;/ul&gt;
&lt;li&gt; Implementation of EAP over TLS
&lt;ul&gt;
&lt;li&gt;Fuzzing EAP over TLS server
&lt;li&gt;Fuzzing EAP over TLS client&lt;/ul&gt;
&lt;li&gt;Testing of the Endpoint solution:
&lt;ul&gt;
&lt;li&gt;Stateless vs. Stateful firewall testing on NAC agents
&lt;li&gt;Fuzzing of firewall state by creating hostile servers and clients
&lt;li&gt;Middle person attacks on NAC
&lt;li&gt;Trusted 3rd party Servers
&lt;li&gt;Authentication and authorization bypass for trusted A/V servers
&lt;li&gt;Attempt to subvert security checks completed by external modules&lt;/ul&gt;
&lt;li&gt;802.1x/NAC Attack Profiles
&lt;ul&gt;
&lt;li&gt;Attacks from non-Agent machines
&lt;li&gt;Attacks from malicious machines with Agents
&lt;li&gt;Attacks from infected machines with agents
&lt;li&gt;Attacks on authentication channels
&lt;li&gt;Attacks to bypass/spoof authorization&lt;/ul&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:30:05 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">217 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
