authentication mode of the USM can be used to guarantee the security of management
modules.
The SNMPv3 and SNMP Trap V3 use the message digest algorithm 5 (MD5) or secure hash
algorithm (SHA) for authentication, and the Data Encryption Standard (DES) or Advanced
Encryption Standard (AES) for encryption. The default authentication protocol is MD5,
which is weak and vulnerable to being cracked. You are advised to set the authentication
protocol to SHA.
The management modules conform to the SNMPv1, SNMPv2c, and Telnet protocols. However, these
protocols are disabled by default for security purposes.
Web Service Security
The E9000 chassis provides the web service for chassis management over the WebUI. The
web service security functions are listed as follows:
l
Automatically converting HTTP requests into HTTPS requests
The web service platform automatically converts HTTP requests into HTTPS requests
when users access the web service platform using HTTP, enhancing access security.
l
Preventing cross-site scripting (XSS)
XSS is a type of computer vulnerability typically found in web applications. XSS
enables attackers to inject client-side scripts into web pages viewed by other users.
l
Preventing SQL injection
SQL injection is a code injection technique. Malicious SQL statements are inserted into
an entry field of a web form or a query string of a page request for execution.
l
Preventing cross-site request forgery
Cross-site request forgery is a type of malicious exploit of a website whereby
unauthorized commands are transmitted from a user that the website trusts. For example,
when a user logs in to website A and the session does not time out, the user then logs in
to website B, which is embedded with malicious programs. In this situation, an attacker
can obtain the session ID of website A and use this ID to log in to website A and
intercept private information.
l
Hiding sensitive information
The web service platform protects sensitive information from being obtained by
attackers.
l
Restricting file uploads and downloads
The web service platform limits file uploads and downloads, protects confidential files
from leakage, and prevents insecure files from being uploaded.
l
Preventing URL overriding
Specific permissions are granted to each type of user to prevent users from performing
unauthorized operations on the system.
l
Ensuring the security of user names and passwords
Web user names and passwords must meet system security requirements, for example,
password strength.
E9000 Server
User Guide
2 Overview
Issue 25 (2019-11-30)
Copyright © Huawei Technologies Co., Ltd.
38