{"id":1976,"date":"2026-05-15T07:17:20","date_gmt":"2026-05-15T07:17:20","guid":{"rendered":"https:\/\/jperez.inscastellbisbal.net\/?page_id=1976"},"modified":"2026-05-15T07:29:20","modified_gmt":"2026-05-15T07:29:20","slug":"%f0%9f%9f%a0-cataleg-dincidencies-tipiques-i-com-resoldre-les","status":"publish","type":"page","link":"https:\/\/jperez.inscastellbisbal.net\/index.php\/%f0%9f%9f%a0-cataleg-dincidencies-tipiques-i-com-resoldre-les\/","title":{"rendered":"\ud83d\udfe0 \u2013 Cat\u00e0leg d\u2019incid\u00e8ncies t\u00edpiques i com resoldre-les"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Cat\u00e0leg d&#8217;Incid\u00e8ncies T\u00e8cniques<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Protocols de gesti\u00f3 no xifrats (Telnet\/HTTP)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Configuraci\u00f3 per defecte.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Escaneig de ports (23, 80) amb Nmap.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Deshabilitar-los i activar SSH i HTTCat\u00e0leg d&#8217;Incid\u00e8ncies T\u00e8cniques<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Credencials per defecte<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Omissi\u00f3 del canvi de claus inicial.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Intents de login manual (admin\/admin).<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Establir pol\u00edtica de contrasenyes robustes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Firmware obsolet<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Falta de manteniment.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Comandament show version vs base de dades CVE.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Actualitzar a la versi\u00f3 estable del fabricant.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. VLAN nativa sense canviar (VLAN 1)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Configuraci\u00f3 de f\u00e0brica.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Tr\u00e0nsit de control barrejat amb dades a Wireshark.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Moure la gesti\u00f3 a una VLAN espec\u00edfica i tancar la 1.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. Abs\u00e8ncia de Port Security<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Prioritzar connectivitat sobre seguretat.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Connexi\u00f3 d&#8217;equips aliens amb \u00e8xit.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Limitar MACs per port i activar Port-Security.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Servidor DHCP il\u00b7legal (Rogue DHCP)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Connexi\u00f3 accidental de routers dom\u00e8stics.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> IPs err\u00f2nies rebudes pels usuaris.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Activar DHCP Snooping als switches.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7. Protocols de descoberta actius (CDP\/LLDP)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Actius per defecte per facilitar la gesti\u00f3.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Captura de paquets d&#8217;informaci\u00f3 del hardware.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Desactivar-los en ports que donen a l&#8217;usuari.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8. Seguretat Wi-Fi feble (WPA\/TKIP)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Compatibilitat amb dispositius antics.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Escaneig de xarxes sense fils.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Migrar a WPA2-AES o WPA3.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9. SNMP amb comunitat per defecte<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> \u00das de la paraula &#8220;public&#8221; per monitoratge.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Consulta d&#8217;informaci\u00f3 amb snmpwalk.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Canviar la &#8220;string&#8221; o passar a SNMPv3.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10. Falta de protecci\u00f3 contra bucles (STP)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Causa:<\/strong> Configuraci\u00f3 incompleta en ports d&#8217;acc\u00e9s.<\/li>\n\n\n\n<li><strong>Detecci\u00f3:<\/strong> Caiguda de xarxa per tempesta de broadcast.<\/li>\n\n\n\n<li><strong>Resoluci\u00f3:<\/strong> Habilitar BPDU Guard i Portfast.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Incid\u00e8ncia<\/strong><\/td><td><strong>Gravetat<\/strong><\/td><td><strong>Temps Resoluci\u00f3<\/strong><\/td><td><strong>Sistema d&#8217;Alerta \/ Prevenci\u00f3<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Credencials per defecte<\/strong><\/td><td>\ud83d\udd34 Cr\u00edtica<\/td><td>&lt; 5 min<\/td><td>Auditories de configuraci\u00f3 automatitzades.<\/td><\/tr><tr><td><strong>Rogue DHCP<\/strong><\/td><td>\ud83d\udfe0 Alta<\/td><td>15 min<\/td><td>Alertes de logs de Switch (SNMP Traps).<\/td><\/tr><tr><td><strong>Firmware obsolet<\/strong><\/td><td>\ud83d\udfe1 Mitjana<\/td><td>1h \/ equip<\/td><td>Subscripci\u00f3 a llistes de correu de seguretat.<\/td><\/tr><tr><td><strong>CDP\/LLDP actiu<\/strong><\/td><td>\ud83d\udfe2 Baixa<\/td><td>5 min<\/td><td>Plantilles de configuraci\u00f3 est\u00e0ndard (Templates).<\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Cat\u00e0leg d&#8217;Incid\u00e8ncies T\u00e8cniques 1. Protocols de gesti\u00f3 no xifrats (Telnet\/HTTP) 2. Credencials per defecte 3. Firmware obsolet 4. VLAN nativa sense canviar (VLAN 1) 5. Abs\u00e8ncia de Port Security 6. Servidor DHCP il\u00b7legal (Rogue DHCP) 7. Protocols de descoberta actius (CDP\/LLDP) 8. Seguretat Wi-Fi feble (WPA\/TKIP) 9. SNMP amb comunitat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1976","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/pages\/1976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/comments?post=1976"}],"version-history":[{"count":5,"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/pages\/1976\/revisions"}],"predecessor-version":[{"id":1983,"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/pages\/1976\/revisions\/1983"}],"wp:attachment":[{"href":"https:\/\/jperez.inscastellbisbal.net\/index.php\/wp-json\/wp\/v2\/media?parent=1976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}