<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Roger's Information Security Blog</title>
	
	<link>http://www.infosecblog.org</link>
	<description />
	<lastBuildDate>Thu, 17 May 2012 17:55:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/RogersInfosecBlog" /><feedburner:info uri="rogersinfosecblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Deploy critical patches within 48 hours</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/I55C4pWRZZg/</link>
		<comments>http://www.infosecblog.org/2012/05/deploy-critical-patches-within-48-hours/#comments</comments>
		<pubDate>Thu, 17 May 2012 17:55:41 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5882</guid>
		<description><![CDATA[Critical Control 4: Continuous Vulnerability Assessment and Remediation lists as a &#8220;quick win&#8221; Any vulnerability identified should be remediated in a timely manner, with critical vulnerabilities fixed within 48 hours. Unless you&#8217;re paired up with Nick Nolte, 48 hours isn&#8217;t a very long time.   It seems to conflict a with later requirement: Critical patches must be evaluated [...]]]></description>
			<content:encoded><![CDATA[<p>Critical Control 4: Continuous Vulnerability Assessment and Remediation lists as a &#8220;quick win&#8221; <em>Any vulnerability identified should be remediated in a timely manner, with critical vulnerabilities fixed within 48 hours.</em></p>
<p>Unless you&#8217;re paired up with Nick Nolte, 48 hours isn&#8217;t a very long time.   It seems to conflict a with later requirement: <em>Critical patches must be evaluated in a test environment before being pushed into production on enterprise systems. </em>   That is one quick eval cycle.</p>
<p>So what is critical?</p>
<p>In my vulnerability scan report vulnerabilities are listed 1 through 5.   Every month there are new level 5 vulnerabilities.</p>
<p>PCI says that things with a CVSS score greater than 7.2 (if I remember correctly) need to be patched.   Is that what critical is?</p>
<p>Does critical mean &#8220;was mentioned on the evening news&#8221;?</p>
<p>FISMA 800-53 rev 3 RA-5 leaves it up to the organization to define.</p>
<p>I think I should just update my vulnerability management doc to say that critical updates are defined as those accompanied by four horsemen.   Those must be patched within 48 hours.   If the server can be found in the smoking crater.   All other patches shall be deployed within 30 days unless otherwise instructed.</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/I55C4pWRZZg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/05/deploy-critical-patches-within-48-hours/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/05/deploy-critical-patches-within-48-hours/</feedburner:origLink></item>
		<item>
		<title>The case of the reconfigured product</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/RwfbuWWjHEw/</link>
		<comments>http://www.infosecblog.org/2012/05/case-of-the-reconfigured-product/#comments</comments>
		<pubDate>Mon, 14 May 2012 02:27:37 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5877</guid>
		<description><![CDATA[Can you claim &#8220;King of the Lab&#8221; even when the problem you solve is self-inflected? The phrase King of the Lab originated on the U.S television series &#8220;Bones&#8221; where the scientist who found the key evidence that week was king of the lab. We&#8217;ve noted an odd issue at work where the event logs on [...]]]></description>
			<content:encoded><![CDATA[<p>Can you claim &#8220;King of the Lab&#8221; even when the problem you solve is self-inflected?</p>
<p>The phrase King of the Lab originated on the U.S television series &#8220;Bones&#8221; where the scientist who found the key evidence that week was king of the lab.</p>
<p><iframe src="http://www.youtube-nocookie.com/embed/3Tz0fAkXy84?rel=0" frameborder="0" width="420" height="315"></iframe></p>
<p>We&#8217;ve noted an odd issue at work where the event logs on multiple systems  would report:</p>
<blockquote><p><span style="color: #0000ff;">Windows Installer reconfigured the product. Product Name: &lt;ProductName&gt;. Product Version: &lt;VersionNumber&gt;. Product Language: &lt;languageID&gt;. Reconfiguration success or error status: 0.</span></p></blockquote>
<p>for every installed application.   This set of logs would show up repeatedly.  We were kind of hoping it would go away when systems were migrated from Windows XP to Windows 7 but it is still occuring</p>
<p>Our Bing-fu must be weak because I stumbled across a KB article tonight that explains it.</p>
<p><a href="http://support.microsoft.com/kb/974524">http://support.microsoft.com/kb/974524</a><br />
<strong>Event log message indicates that the Windows Installer reconfigured all installed applications</strong></p>
<p>This is caused by using group policy with WMI filters that use Win32_Product.  It can also be caused by applications that use that WMI class as well.   GuardianEdge documentation instructed me to use that WMI class in a filter to deploy GuardianEdge settings so they would only apply to clients with the specific product version.</p>
<p>The &#8220;Ask the Directory Services Team&#8221; blog at Microsoft recently had a post which linked that KB and reported that use of <a href="http://blogs.technet.com/b/askds/archive/2012/04/19/how-to-not-use-win32-product-in-group-policy-filtering.aspx">Win32_Product will (could?) result in slow boot times.</a>  The reason this WMI Class is an issue is that it uses a DLL to actively query each installed application.   This trigger the reinstall.   Additionally if any of the installed apps are installed remotely this can really slow things down.</p>
<p>The Microsoft blog lists some workarounds.    I&#8217;m not sure any of them are perfect for me.   Until I implement a fix this case isn&#8217;t closed.   But it is enough for me to do a happy dance while yelling &#8220;king of the lab&#8221;.</p>
<p>Now where is my trophy?</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/RwfbuWWjHEw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/05/case-of-the-reconfigured-product/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/05/case-of-the-reconfigured-product/</feedburner:origLink></item>
		<item>
		<title>Dirty Disks Done Dirt Cheap</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/fOSBD6IUpFY/</link>
		<comments>http://www.infosecblog.org/2012/04/ofdirty-disks-done-dirt-cheap/#comments</comments>
		<pubDate>Sat, 28 Apr 2012 02:44:41 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5865</guid>
		<description><![CDATA[Content Information security has a nice writeup of tests they performed on a few cloud security providers. What happens when you delete a virtual server in the course of its lifecycle?   At some point you&#8217;ll leave a provider, turn down a server, or just get moved to another server. On the computers you have control over, [...]]]></description>
			<content:encoded><![CDATA[<p>Content Information security has a nice <a href="http://www.contextis.com/research/blog/dirtydisks/">writeup of tests</a> they performed on a few cloud security providers.</p>
<p>What happens when you delete a virtual server in the course of its lifecycle?   At some point you&#8217;ll leave a provider, turn down a server, or just get moved to another server.</p>
<p>On the computers you have control over, hopefully you&#8217;re already running some sort of disk wiping.  What about the computers you don&#8217;t control?</p>
<p>As any forensicator will tell you, deleted files aren&#8217;t necessarily gone.   The table of contents telling you where the file is may be gone but the data is there until it is overwritten.    It turns out that due to some process problems, old servers weren&#8217;t overwritten and they were able to access data with a simple dd command on their newly provisioned virtual server.</p>
<p>When the data goes to the cloud you  give up a measure of control.   When you&#8217;re at least aware of what can go wrong, you can ask the right questions.</p>
<p>Do check out the article <a href="http://www.contextis.com/research/blog/dirtydisks/">http://www.contextis.com/research/blog/dirtydisks/</a><br />
Hat tip to <a href="http://www.databreaches.net/">Office of Inadequate Security</a></p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/fOSBD6IUpFY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/ofdirty-disks-done-dirt-cheap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/ofdirty-disks-done-dirt-cheap/</feedburner:origLink></item>
		<item>
		<title>Not Dead Yet</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/Xe3IqPwOVrI/</link>
		<comments>http://www.infosecblog.org/2012/04/not-dead-yet/#comments</comments>
		<pubDate>Sat, 21 Apr 2012 12:18:09 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5862</guid>
		<description><![CDATA[While playing around with John the Ripper the phrase &#8220;password are dead&#8221; came to mind.  In the realm of Information Security how many items have been declared dead? Passwords are dead. &#8220;IDS is dead.&#8221; &#8211; Gartner &#8220;Gartner is dead&#8221; &#8211; IDS The firewall/perimeter is dead. Antivirus is dead. SSL is dead. SIEM is dead. Corporate [...]]]></description>
			<content:encoded><![CDATA[<p>While playing around with John the Ripper the phrase &#8220;password are dead&#8221; came to mind.  In the realm of Information Security how many items have been declared dead?</p>
<p>Passwords are dead.<br />
&#8220;IDS is dead.&#8221; &#8211; Gartner<br />
&#8220;Gartner is dead&#8221; &#8211; IDS<br />
The firewall/perimeter is dead.<br />
Antivirus is dead.<br />
SSL is dead.<br />
SIEM is dead.<br />
Corporate IT security is dead.</p>
<p>It starts to look like if you put in any product, idea or compliance regime into google, add on &#8220;is dead&#8221; and you&#8217;ll find results.</p>
<p>Sometimes it is marketing (EIQ and SIEM).  Sometimes predictions.   Occasionally its exasperation at the continuing fail of a product type.  In each case, so one comes out looking like Kreskin.  But the pixels don&#8217;t write themselves and those stances generate traffic.</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/Xe3IqPwOVrI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/not-dead-yet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/not-dead-yet/</feedburner:origLink></item>
		<item>
		<title>WordPress 3.3.2 Security Update</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/5ILND_EI2cQ/</link>
		<comments>http://www.infosecblog.org/2012/04/wordpress-3-3-2-security-update/#comments</comments>
		<pubDate>Sat, 21 Apr 2012 00:18:01 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5860</guid>
		<description><![CDATA[WordPress 3.3.2 is out to fix multiple vulnerabilities.  If you have a WordPress site somewhere on the internet, it is important to keep up to date. &#160; Plupload (version 1.5.4), which WordPress uses for uploading media. SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins. SWFObject, which WordPress [...]]]></description>
			<content:encoded><![CDATA[<p>WordPress 3.3.2 is out to fix multiple vulnerabilities.  If you have a WordPress site somewhere on the internet, it is important to keep up to date.</p>
<p>&nbsp;</p>
<blockquote><p>Plupload (version 1.5.4), which WordPress uses for uploading media.</p>
<ul>
<li>SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins.</li>
<li>SWFObject, which WordPress previously used to embed Flash content, and may still be in use by plugins and themes.</li>
</ul>
<p>WordPress 3.3.2 also addresses:</p>
<ul>
<li>Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances.</li>
<li>Cross-site scripting vulnerability when making URLs clickable.</li>
<li>Cross-site scripting vulnerabilities in redirects after posting comments in older browsers, and when filtering URLs.</li>
</ul>
</blockquote>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/5ILND_EI2cQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/wordpress-3-3-2-security-update/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/wordpress-3-3-2-security-update/</feedburner:origLink></item>
		<item>
		<title>Remotely Recovering Windows Passwords in Plain Text | CYBER ARMS – Computer Security</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/Doo_u6J041s/</link>
		<comments>http://www.infosecblog.org/2012/04/remotely-recovering-windows-passwords-in-plain-text-cyber-arms-computer-security/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 15:22:30 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5855</guid>
		<description><![CDATA[http://cyberarms.wordpress.com/2012/04/16/remotely-recovering-windows-passwords-in-pl/]]></description>
			<content:encoded><![CDATA[<p><a href="http://cyberarms.wordpress.com/2012/04/16/remotely-recovering-windows-passwords-in-pl/">http://cyberarms.wordpress.com/2012/04/16/remotely-recovering-windows-passwords-in-pl/</a></p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/Doo_u6J041s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/remotely-recovering-windows-passwords-in-plain-text-cyber-arms-computer-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/remotely-recovering-windows-passwords-in-plain-text-cyber-arms-computer-security/</feedburner:origLink></item>
		<item>
		<title>Acrobat and Reader Updates: APSB12-08</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/0tlJ_FDdqNk/</link>
		<comments>http://www.infosecblog.org/2012/04/acrobat-and-reader-updates-apsb12-08/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 22:26:19 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Patching]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5852</guid>
		<description><![CDATA[Today Adobe released security updates for Adobe Acrobat and Adobe Reader. An entry to the Adobe Secure Software Engineering Team (ASSET) Blog discusses several aspects of this security bulletin. First, Acrobat and Reader 9 will no longer be using a special version of Flash bundled with those products.   Instead they will look to use what I [...]]]></description>
			<content:encoded><![CDATA[<p>Today Adobe released <a href="http://www.adobe.com/support/security/bulletins/apsb12-08.html">security updates for Adobe Acrobat and Adobe Reader.</a></p>
<p>An <a href="http://blogs.adobe.com/asset/2012/04/background-on-security-bulletin-apsb12-08.html">entry </a>to the <a href="http://blogs.adobe.com/asset">Adobe Secure Software Engineering Team (ASSET) Blog</a> discusses several aspects of this security bulletin.</p>
<p>First, Acrobat and Reader 9 will no longer be using a special version of Flash bundled with those products.   Instead they will look to use what I call the plugin version of Flash.   That is the version for non-Microsoft browsers other than Chrome (Firefox, Opera, etc).   Chrome bundles its own special version of Flash.</p>
<p>Adobe has written the Netscape Plugin Application Programming Interface (NPAPI) to allow Acrobat and Reader to access the plugin based Flash in your Operating System.</p>
<p>The good news is no longer will you have to install an update to Acrobat or Reader every time there is a Flash update.   The bad news is this is only applicable to version 9.   Version 10 is still being developed.  The other bad news is if you don&#8217;t have the plugin version of Flash installed, you will be prompted to install it if you open a PDF with Flash content.</p>
<p>In general having Reader and Acrobat X is much more secure than having 9.   But if you&#8217;re hanging on to 9 for some reason this is good news for you.</p>
<p>Adobe announced that no longer will they have quarterly patches by default.   Instead scheduled releases may occur on Microsoft patch Tuesdays.   They will preannounce three days ahead of time if a patch will occur that month.   So-called out-of-band updates will be released as necessary.   I read this at less frequent Adobe Acrobat and Reader patches.</p>
<p><a href="http://blogs.adobe.com/asset/2012/04/background-on-security-bulletin-apsb12-08.html">Check the Adobe ASSET blog for information.</a></p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/0tlJ_FDdqNk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/acrobat-and-reader-updates-apsb12-08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/acrobat-and-reader-updates-apsb12-08/</feedburner:origLink></item>
		<item>
		<title>Dreamhost Adds One Click Cloudflare Option</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/8Qx0RZcYPu0/</link>
		<comments>http://www.infosecblog.org/2012/04/dreamhost-adds-one-click-cloudflare-option/#comments</comments>
		<pubDate>Sat, 07 Apr 2012 18:19:21 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[CloudFlare]]></category>
		<category><![CDATA[Incapsula]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5849</guid>
		<description><![CDATA[Regular reader of this blog may remember that back in August I looked at both Cloudflare and Incapsula to protect an accelerate infosecblog.org. Webmasters are faced with two huge challenges.  The first is keeping the blog secure.   There were many examples recently of WordPress blogs, even security related ones, compromised.   While it is always easy to [...]]]></description>
			<content:encoded><![CDATA[<p>Regular reader of this blog may remember that back in August I looked at both Cloudflare and Incapsula to protect an accelerate infosecblog.org.</p>
<p>Webmasters are faced with two huge challenges.  The first is keeping the blog secure.   There were many examples recently of WordPress blogs, even security related ones, compromised.   While it is always easy to just blame the webhost, vulnerabilities in TimThumb proved to be many blogs undoing.  If you run a blog and you haven&#8217;t searched to see if you use timthumb unbeknownst to you in one of the many plugins you&#8217;ve added, you&#8217;re blog is probably already compromised.</p>
<p>The second major concern for webmasters is site speed.   All these plugins we install slow the site down.   Search engines penalize your page rank for slow loading.   Users are unlikely to return.   First time visitors may have their ADD kick in and just move on to the next site.</p>
<p>Cloud based mini Content Delivery Networks (CDNs) like Cloudflare and Incapsula provide answers to both problems.</p>
<p>With these types of services the webmaster changes the DNS to point to the cloud based service.   In the cloud, they block the bad and accelerate the good (to steal a phrase from BlueCoat).   You no longer have to mess around with complicated WordPress caching plugins (although some are designed to work hand in hand with CDNs).   If you were slack on security and had a vulnerable version of TimThumb, both of these solutions would block that attack and let you know about it.  The webmaster should still stay on top of all WordPress upgrades including the plugins.   Additionally the password should be strong.</p>
<p>One of the challenges with using these services at Dreamhost was they lock own the A (and AAAA) records for infosecblog and <a href="http://www.infosecblog.org">www.infosecblog.org</a>.   Even to use Incapsula&#8217;s free service, I had to pay for a third party DNS provider so I could have full control over the DNS.  With Cloudflare at least, this problem is now solved.   Dreamhost has partnered with them to allow integration with just a checkbox.   I set it up one of my other domains in minutes.  I&#8217;ll continue to use Incapula on this domain and compare the two services.</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/8Qx0RZcYPu0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/dreamhost-adds-one-click-cloudflare-option/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/dreamhost-adds-one-click-cloudflare-option/</feedburner:origLink></item>
		<item>
		<title>Using NAC to manage the response to MS12-020</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/UZqM85G1TsM/</link>
		<comments>http://www.infosecblog.org/2012/04/using-nac-to-manage-the-response-to-ms12-020/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 19:27:51 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[NAC]]></category>
		<category><![CDATA[Forescout]]></category>
		<category><![CDATA[Patching]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5846</guid>
		<description><![CDATA[Ok, so this isn&#8217;t exactly a timely post. When MS12-020 came out, it was the biggest patching frenzy I&#8217;ve seen in a while.   MS12-020 was a vulnerability in the Remote Desktop Protocol.   While not on by default, this protocol is often enabled on servers and by power users for remote manageability.   This vulnerability in a protocol frequently exposed on the [...]]]></description>
			<content:encoded><![CDATA[<p>Ok, so this isn&#8217;t exactly a timely post.</p>
<p>When MS12-020 came out, it was the biggest patching frenzy I&#8217;ve seen in a while.   MS12-020 was a vulnerability in the Remote Desktop Protocol.   While not on by default, this protocol is often enabled on servers and by power users for remote manageability.   This vulnerability in a protocol frequently exposed on the network resulted in a &#8220;patch now&#8221; attitude.  Our clients were emailing demanding to know our percentage patch compliance.  People were watching on pins and needles to see if a remote code execution exploit became publicly available before patching was complete.</p>
<p>When a denial of service capable exploit for this vulnerability became available, we pushed up our patching timeline figuring the exploitation code couldn&#8217;t be far behind.   Systems not running RDP of course are not susceptible so I wanted to target my attention on systems that had RDP and were missing the patch.   Forescout CounterAct made this easy to do.   I set up a rule looking for systems missing MS12-020 and with 3389/TCP open.</p>
<p>From there Forescout allows many possible remediation and enforcement measures.</p>
<ul>
<li> Send the user an email with instructions on how to patch (Hey Forescout, I&#8217;d love to be able to digitally sign those emails so I don&#8217;t undermine my antiphishing efforts)</li>
<li>Sent HTTP notifications.   (I&#8217;ve purchased trusted SSL certificates so users could verify the source)</li>
<li>Self-Remediation &#8211; HTTP notification with link to patch, forcing user to patch</li>
<li>Initiate installing the patch through Microsoft Update/SCCM.</li>
</ul>
<p>If the situation became dire, I could even use TCPresets or ACLs on the switch port to prevent RDP inbound on systems that haven been patched.</p>
<p>NAC is about so much more than controlling who is admitted to the network.   It is a critical part of endpoint security.</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/UZqM85G1TsM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/04/using-nac-to-manage-the-response-to-ms12-020/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/04/using-nac-to-manage-the-response-to-ms12-020/</feedburner:origLink></item>
		<item>
		<title>Java exploitation on the rise</title>
		<link>http://feedproxy.google.com/~r/RogersInfosecBlog/~3/4_a9aKIWSs4/</link>
		<comments>http://www.infosecblog.org/2012/03/java-exploitation-on-the-rise/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 02:05:27 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[JAVA]]></category>
		<category><![CDATA[Patching]]></category>

		<guid isPermaLink="false">http://www.infosecblog.org/?p=5843</guid>
		<description><![CDATA[The deadline for getting up to date on the latest Java has come an gone. Microsoft posted on the 20th that they were seeing exploit code attacking the vulnerability in Java which Oracle patched in February. Yesterday Brian Krebs posted that an exploit for this vulnerability is now in one of the more popular exploit kits.  [...]]]></description>
			<content:encoded><![CDATA[<p>The deadline for getting up to date on the latest Java has come an gone.</p>
<p><a href="http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx">Microsoft posted</a> on the 20th that they were seeing exploit code attacking the vulnerability in Java which Oracle patched in February.</p>
<p><a href="http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/">Yesterday Brian Krebs posted</a> that an exploit for this vulnerability is now in one of the more popular exploit kits.  Exploit packs are malware distribution for the script kiddie.  You purchase code that will try multiple exploits based on the type of computer that comes to a website.   This means it is far beyond targeted attacks, and into the general distribution.</p>
<p>The same advise as always, applies with Java.</p>
<p>1.  If you don&#8217;t need it, remove it.<br />
2.  If you do need it, always run the most recent version.<br />
3.  Watch for older versions hanging on.   Remove them.<br />
4.  For safety only run Java in one browser, and use another browser for day-to-day browsing activities.   This lowers the attack surface area.<br />
5.  In addition to antivirus, have some sort of URL filtering that blocks malicious sites such as the free consumer BlueCoat K-9.</p>
<p>&nbsp;</p>
<img src="http://feeds.feedburner.com/~r/RogersInfosecBlog/~4/4_a9aKIWSs4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecblog.org/2012/03/java-exploitation-on-the-rise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecblog.org/2012/03/java-exploitation-on-the-rise/</feedburner:origLink></item>
	</channel>
</rss>

