IDS mailing list archives

IDS Stealth Mode


From: "r)(o)(m" <nom.de.guerre () bonbon net>
Date: Wed, 08 Jan 2003 08:39:55 -0600

Retrying this post after 2 days:
A common deployment configuration of Network IDS is to have 2 NICs;
Teh monitoring interface in "stealth mode" with no IP
and
the "management" interface on a trusted internal network.

My question is:
Has anyone ever exploited the "stealth" interface to traverse networks?
Has anyone (else) ever had to defend such a configuration against the argument:
"where there's a wire, there's a way"
?
r)(0)(m



Current thread: