iSCSI Security Part 1
I mentioned before that I am using iSCSI on Win2K3 talking to a Netapp filer (simulator) with Ethereal on the host Win2K3 box to monitor I/O activity. I tried today to write to a test file with Ethereal running and tracing I/O activity. The tool is splendid in its interpretation of the data it sees, formatting the packets on the basis of the content. My save of a file containing some test data yielded some interesting results.
Firstly, I found Ethereal detected the logfile entries for NTFS being saved before my actual file. These are RCRD and RSTR records which NTFS uses to recover the filesystem should anything untoward happen before the data is actually committed to disk.
After this, I tracked the MFT entries being written. These are the actual file saves which contain my data. Non-encrypted I can see the content. Using Ethereal and a tool to map NTFS records, I could easily spy on data being stored on iSCSI volumes. Here are some screenshots:
even format the data to allow me to locate the iSCSI data. This is no good for any organisation which must offer data security. Part II will discuss what can be done.
_uacct = “UA-1104321-2″;
urchinTracker();
One Response to iSCSI Security Part 1
Leave a Reply Cancel reply
You must be logged in to post a comment.
- Use Symantec and know your sensitive data is protected with industry-leading backup & recovery software.
Experience Symantec Backup Software
Popular Posts
- Netapp: The Inflexibility of Flexvols (3815)
- Back to Blogging (2310)
- The technical solution is not always the best (2018)
- Data ONTAP 8.0 – Part III (1827)
- Solid State Arrays: Pure Storage Inc (1775)
- EMC Releases All Flash VNX (1757)
- Enterprise Computing: Why Thin Provisioning Is Not The Holy Grail for Utilisation (1549)
- Who Will Be The First Solid State Array Vendor To Be Acquired? (1511)
- Drive Prices Increase – Who Will Suffer Most? (1448)
- VAAI Follow Up – VMware Recommend Disabling Thin Reclaim (1356)








Chris,
I just thought Id point out that the phrase should be “the quick brown fox….” Otherwise the sentence doesnt contain every letter in the alphabet