<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-7196788127833928948</atom:id><lastBuildDate>Sat, 14 Nov 2009 08:22:05 +0000</lastBuildDate><title>Information Security Short Takes</title><description /><link>http://www.shortinfosec.net/</link><managingEditor>noreply@blogger.com (Bozidar Spirovski)</managingEditor><generator>Blogger</generator><openSearch:totalResults>184</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/2.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/shortinfosec" type="application/rss+xml" /><feedburner:emailServiceId>shortinfosec</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-5622341738670314089</guid><pubDate>Sat, 14 Nov 2009 07:44:00 +0000</pubDate><atom:updated>2009-11-14T09:22:05.817+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>OWASP Publishes Top 10 Web App Security Risks for 2010</title><description>Last night the &lt;a href="http://www.owasp.org/index.php/Main_Page"&gt;OWASP project&lt;/a&gt; published the 2010 issue of their Top 10 Web Application Security Risks. The list is still in Release Candidate status, so it may change. The difference from the previous lists according to the statement by OWASP&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/Sv5omRpsn0I/AAAAAAAAAWc/laA-pMaMhTI/s1600-h/OWASP.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 134px; height: 134px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/Sv5omRpsn0I/AAAAAAAAAWc/laA-pMaMhTI/s400/OWASP.jpg" alt="" id="BLOGGER_PHOTO_ID_5403871609673785154" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/Sv5oeniI7oI/AAAAAAAAAWU/o1po5PSxH-4/s1600-h/OWASP.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;blockquote&gt;&lt;p style="font-style: italic;"&gt;A significant change for this update will be that the OWASP Top 10 will be focused on the Top 10 &lt;b&gt;Risks&lt;/b&gt; to Web Applications, not just the most common vulnerabilities. At the conference will be the debut of the release candidate of the new Top 10, which will open up a 60 day comment period.&lt;br /&gt;&lt;/p&gt;&lt;/blockquote&gt;As a summary, &lt;span style="font-weight: bold;"&gt;the top 10 risks to your Web Apps are:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Injection flaws&lt;/li&gt;&lt;li&gt;Cross Site Scripting (XSS)&lt;/li&gt;&lt;li&gt;Broken Authentication and Session Management&lt;/li&gt;&lt;li&gt;Insecure Direct Object References&lt;/li&gt;&lt;li&gt;Cross Site Request Forgery (CSRF)&lt;/li&gt;&lt;li&gt;Security Misconfiguration&lt;/li&gt;&lt;li&gt;Failure to Restrict URL Access&lt;/li&gt;&lt;li&gt;Unvalidated Redirects and Forwards&lt;/li&gt;&lt;li&gt;Insecure Cryptographic Storage&lt;/li&gt;&lt;li&gt;Insufficient Transport Layer Protection&lt;/li&gt;&lt;/ol&gt;It is evident that OWASP hasn't invented the wheel all over again, and that this list has already been discussed for years. Yet it still falls on deaf ear for many developers - even large development companies.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf"&gt;You can download the full list document here, with detailed explanation of each risk.&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/01/sans-announced-top-25-programming.html"&gt;SANS Announced Top 25 Programming Errors&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-5622341738670314089?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/vIClCjp8_j0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/vIClCjp8_j0/owasp-publishes-top-10-web-app-security.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Hu1rpxRsqcU/Sv5omRpsn0I/AAAAAAAAAWc/laA-pMaMhTI/s72-c/OWASP.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/owasp-publishes-top-10-web-app-security.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-83222016980090942</guid><pubDate>Thu, 12 Nov 2009 19:10:00 +0000</pubDate><atom:updated>2009-11-12T22:53:32.452+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">windows</category><category domain="http://www.blogger.com/atom/ns#">microsoft</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Analysis of Windows Security Logs with MS Log Parser</title><description>When investigating an intrusion in a Windows system, one of the first places to start is the Windows security log. Security event log is also very useful for analysis when searching for anomalies and possible intrusions.&lt;br /&gt;&lt;br /&gt;Reading through a Windows security log or any other log can be very difficult and time consuming, so a lot of companies have created their own tools to analyze windows event logs. But before you start going commerical, there is a tool that will get you going without any cost. Against all odds, it's a tool made by Microsoft!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The tool&lt;/span&gt;&lt;br /&gt;The tool in question is &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en"&gt;Microsoft Log parser&lt;/a&gt;. Log parser is a command line tool that provides universal query access to text-based data such as log files, XML files and CSV files, as well as key data sources on the Windows operating system such as the Event Log, the Registry, the file system, and Active Directory. So, you can use it to analyze most structured text based files and the eventlog and AD on a single computer.&lt;br /&gt;&lt;br /&gt;You can query remote computers on the network, as long as the credentials that Log parser is running under can access the data sources on the remote computers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;For Security Log, you need to run Log Parser as administrator&lt;/span&gt;&lt;br /&gt;Note that this tool doesn't collect data from multiple computers, it just analyzes data in a single file/single computer repository.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The improved interface&lt;/span&gt;&lt;br /&gt;In it's original form, Log Parser is a command line tool, so it is not the most user friendly tool in the world. Also, it has no way of saving/storing your prepared queries so you can invoke them later. But a promising developer named Dimce Kuzmanov created a free frontend to Log parser called &lt;a href="http://www.lizardl.com/PageHtml.aspx?lng=2&amp;amp;PageId=18&amp;amp;PageListItemId=17"&gt;Log Parser Lizard&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Hu1rpxRsqcU/Svx8CeGQ-iI/AAAAAAAAAWM/_hY1U-Y122Q/s1600-h/Log+Parser+Lizard.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://4.bp.blogspot.com/_Hu1rpxRsqcU/Svx8CeGQ-iI/AAAAAAAAAWM/_hY1U-Y122Q/s320/Log+Parser+Lizard.jpg" alt="" id="BLOGGER_PHOTO_ID_5403330034818677282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Log Parser Lizard enables you to store the prepared queries, and organizes them by type of data source on which you wish to do an analysis. It also includes &lt;span id="grdPageItems__ctl3_Label2"&gt;the ability to export results to Excel, autogenerates charts&lt;/span&gt; on the result of the executed query, or ability to export the queried subset into the original format from which the analysis was performed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Analyzing the Security Log with Log Parser Lizard&lt;/span&gt;&lt;br /&gt;Using Log Parser Lizard for Security Log analysis is very simple. Choose the Queries button and select the Event Logs category, then create the queries that you need for your analysis. Here are some examples:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;SELECT * FROM SECURITY - simple dump all data from the security log&lt;/li&gt;&lt;li&gt;SELECT EVENTID, COUNT(*) FROM SECURITY GROUP BY EVENTID - analyze what types of events appear in the security log and in what quantity&lt;/li&gt;&lt;li&gt;SELECT * FROM SECURITY WHERE EVENTID='517' - find whether the security log was cleared in Win2000/XP/2003&lt;/li&gt;&lt;/ul&gt;After you create the query, choose the apropriate category, then click the 'Generate' button to execute the query. You can also graph the results by choosing the Chart-&gt;Visible option.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;br /&gt;Analyzing the Security Log is always a useful approach to security controls, so you need to include it in your routine operations. And until you buy a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SIEM&lt;/span&gt; system which will run an automatic and scheduled analysis, you should adopt a simple tool like Log Parser and Log Parser Lizard.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/mail-header-security-analysis.html"&gt;Tutorial - Mail Header Analysis for Spoof Protection&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/11/reminder-tutorial-enable-auditing-on.html"&gt;Reminder Tutorial - Enable Auditing on Windows 7&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/10/windows-7-full-disk-encryption-with.html"&gt;Windows 7 Full Disk Encryption with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Truecrypt&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-83222016980090942?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/dmVHVQpqtko" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/dmVHVQpqtko/analysis-of-windows-security-logs-with.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Hu1rpxRsqcU/Svx8CeGQ-iI/AAAAAAAAAWM/_hY1U-Y122Q/s72-c/Log+Parser+Lizard.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/analysis-of-windows-security-logs-with.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-8553565619720424348</guid><pubDate>Tue, 10 Nov 2009 18:35:00 +0000</pubDate><atom:updated>2009-11-10T19:44:07.516+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Role of Information Security Manager</title><description>As the &lt;strong&gt;Information Security Manager &lt;/strong&gt;you will take responsibility for developing, maintaining monitoring compliance of all information security policy and procedures.&lt;br /&gt;&lt;br /&gt;The successful Information Security Manager will perform&lt;br /&gt;&lt;ul&gt;&lt;li&gt;security risk analysis and risk management, &lt;/li&gt;&lt;li&gt;perform security tests &lt;/li&gt;&lt;li&gt;manage internal audits on information security processes, controls and systems.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;You will take responsibility for developing and maintaining the organization's project disaster recovery and business continuity plans for information systems and monitors changes in legislation and accreditation standards that affect information security.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svm0DigzdTI/AAAAAAAAAWE/TPMWeV7Mgr4/s1600-h/Information+Security+Manager.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 318px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svm0DigzdTI/AAAAAAAAAWE/TPMWeV7Mgr4/s320/Information+Security+Manager.png" alt="" id="BLOGGER_PHOTO_ID_5402547200904623410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;You will provide guidance and consultation on projects for IT Security related risks and issues.&lt;br /&gt;&lt;br /&gt;The successful Information Security Manager must be qualified to Degree level in a numerate subject (e.g. Computer Science, maths, engineering) and possess professional level Information Security Certification such as CISA/CISM/CISSP/SSCP. Will possess a minimum of 5 years experience in Information Security Management and be well versed with ISO 27001 accreditation.&lt;br /&gt;&lt;br /&gt;This is a guest post by Venu Potumudi, an Information Security Manager. The orignal text is published on &lt;a href="http://making-of-ism.blogspot.com/"&gt;Making of ISM&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-8553565619720424348?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/hH2khGGu2z4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/hH2khGGu2z4/role-of-information-security-manager.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svm0DigzdTI/AAAAAAAAAWE/TPMWeV7Mgr4/s72-c/Information+Security+Manager.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/role-of-information-security-manager.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-1698653631621159146</guid><pubDate>Sun, 08 Nov 2009 21:11:00 +0000</pubDate><atom:updated>2009-11-09T19:52:02.437+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Computer security</category><category domain="http://www.blogger.com/atom/ns#">windows</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Reminder Tutorial - Enable Auditing on Windows 7</title><description>Auditing is a one of the major tools used in detecting system intrusions or malicious activity  on systems and network. And yet, even in the 'secure by design' incarnation - Windows 7, the Microsoft Client OS log event entries in the security log out of the box.&lt;br /&gt;&lt;br /&gt;So here is another reminder on how to enable auditing on your system.To enable auditing on a computer running Windows 7, use the same old approach used in every standalone Windows OS starting from Windows 2000 Pro:&lt;ol&gt;&lt;li&gt;Open the Control Panel.&lt;/li&gt;&lt;li&gt;In Control Panel, double-click Administrative Tools, and then click Local Security Policy.&lt;/li&gt;&lt;li&gt;In Local Security Settings, double-click Local Policies, double-click Audit Policy, and then click the events that you want to audit. &lt;/li&gt;&lt;/ol&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svc0sTUaGzI/AAAAAAAAAVw/5uJ0zDpeYeY/s1600-h/Local_Policy_Audit_Winsdows7.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 229px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svc0sTUaGzI/AAAAAAAAAVw/5uJ0zDpeYeY/s320/Local_Policy_Audit_Winsdows7.jpg" alt="" id="BLOGGER_PHOTO_ID_5401844213758958386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;We recommend that you audit the following events with the types of audited events specified in the parentheses:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit account logon events (Success, Failure)&lt;/span&gt; - This setting determines whether the OS audits each time this computer validates an account’s credentials.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit account management (Success, Failure)&lt;/span&gt; - This setting determines whether to audit each event of account management on a computer.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit directory service access (Failure)&lt;/span&gt; - This setting determines whether the OS audits user attempts to access Active Directory objects.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit logon events (Success, Failure) &lt;/span&gt;- This setting determines whether the OS audits each instance of a user attempting to log on to or to log off to this computer. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit object access (Failure)&lt;/span&gt; - This setting determines whether the OS audits user attempts to access non-Active Directory objects.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit policy change (Success, Failure)&lt;/span&gt; - This setting determines whether the OS audits each instance of attempts to change user rights assignment policy, audit policy, account policy, or trust policy.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Audit system events (Success, Failure)&lt;/span&gt; - This setting determines whether the OS audits any of the following events: &lt;span style="font-style: italic;"&gt;Attempted system time change; Attempted security system startup or shutdown; Attempt to load extensible authentication components; Loss of audited events due to auditing system failure; Security log size exceeding a configurable warning threshold level.&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;To view the resulting audit events, start Event Viewer and choose Windows Logs -&gt; Security.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SvhiweIT-FI/AAAAAAAAAV8/e3pSCEjk02E/s1600-h/Windows_Event_Viewer.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SvhiweIT-FI/AAAAAAAAAV8/e3pSCEjk02E/s320/Windows_Event_Viewer.jpg" alt="" id="BLOGGER_PHOTO_ID_5402176337892079698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/05/5-rules-to-protecting-information-on.html"&gt;5 rules to Protecting Information on your Laptop&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/05/truecrypt-full-disk-encryption-review.html"&gt;TrueCrypt Full Disk Encryption Review&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/04/5-minute-security-assessment.html"&gt;5 Minute Security Assessment&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-1698653631621159146?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/Us0w2Kzt6JI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/Us0w2Kzt6JI/reminder-tutorial-enable-auditing-on.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Svc0sTUaGzI/AAAAAAAAAVw/5uJ0zDpeYeY/s72-c/Local_Policy_Audit_Winsdows7.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/reminder-tutorial-enable-auditing-on.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6682933395452995732</guid><pubDate>Sun, 08 Nov 2009 20:38:00 +0000</pubDate><atom:updated>2009-11-08T21:46:31.304+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information security</category><title>200 Posts on Shortinfosec</title><description>We are celebrating the 200 posts on Shortinfosec&lt;br /&gt;&lt;br /&gt;Here are some statistics:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Active for 1 year and 9 monts - Shortinfosec started on 15 February 2008&lt;/li&gt;&lt;li&gt;200 original posts written&lt;/li&gt;&lt;li&gt;60,151 visits since it's active&lt;/li&gt;&lt;li&gt;3 changes of design &lt;a href="http://web.archive.org/web/20080407232903/http://www.shortinfosec.net/"&gt;http://web.archive.org/web/20080407232903/http://www.shortinfosec.net/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;2 periods of author's inactivity (very bad form!)&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Keep reading, a lot of new content will be arriving soon!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6682933395452995732?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/S5vWYcWzOzY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/S5vWYcWzOzY/200-posts-on-shortinfosec.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/200-posts-on-shortinfosec.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-5016753460210036517</guid><pubDate>Sat, 07 Nov 2009 22:22:00 +0000</pubDate><atom:updated>2009-11-07T23:59:55.747+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">forensics</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Digital Forensics Framework - A Perspective Forensics Tool</title><description>After Helix Forensic went commercial, the open source Computer Forensics is missing a tool that integrates required forensic techniques as well as Helix did.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The tool&lt;/span&gt;&lt;br /&gt;A group which calls themselves &lt;a href="http://www.arxsys.eu/"&gt;ArxSys &lt;/a&gt;have developed a Python based Forensic Analysis Tool, which they call &lt;a href="http://www.digital-forensic.org/"&gt;Digital Forensics Framework&lt;/a&gt; (DFF).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvX7vUo_AdI/AAAAAAAAAVo/Hhz8dTAtzNY/s1600-h/Digital_Forensic_Framework.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 226px;" src="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvX7vUo_AdI/AAAAAAAAAVo/Hhz8dTAtzNY/s320/Digital_Forensic_Framework.jpg" alt="" id="BLOGGER_PHOTO_ID_5401500118513811922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DFF can be installed on Linux and Windows, and is functional even under Windows 7. The general architecture of the tool is to create a central contained program in which different forensic functions can be added as building blocks to create a fully integrated forensic environment.&lt;br /&gt;In comparison, most current open source tools are merely wrappers for a whole myriad of standalone tools.&lt;br /&gt;While this architecture is a visionary one, it's strength is also it' weakness: all functions need to be written for this framework, which will slow down development of the DFF as a full solution. At it's current state of development, DFF can handle disk dumps in FAT, but not NTFS nor memory dumps.&lt;br /&gt;&lt;br /&gt;Another very important drawback is that DFF has no functionality for Forensic Acquisition, so the forensic investigator still needs additional tools.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;br /&gt;Digital Forensics Framework is still a very 'young' product. It is focusing only on forensic analysis, with no initiative on forensic acquisition and documentation. The strong sides of the product are the flexibility and ease with which new python scripts can be added.&lt;br /&gt;At this moment, it's not the first choice for a Forensic Investigators tool-chest, but we will follow on the development of the product.&lt;br /&gt;&lt;br /&gt;Talback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/tutorial-computer-forensics-process-for.html"&gt;Tutorial - Computer Forensics Process for &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_33"&gt;Beginners&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/tutorial-computer-forensics-evidence.html"&gt;Tutorial - Computer Forensics Evidence Collection&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/competition-computer-forensic.html"&gt;Competition - Computer Forensic Investigation&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-5016753460210036517?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/VMuknGlcjc0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/VMuknGlcjc0/digital-forensics-framework-perspective.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvX7vUo_AdI/AAAAAAAAAVo/Hhz8dTAtzNY/s72-c/Digital_Forensic_Framework.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/digital-forensics-framework-perspective.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6769383693351574128</guid><pubDate>Thu, 05 Nov 2009 20:29:00 +0000</pubDate><atom:updated>2009-11-05T22:39:43.586+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">microsoft</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Example Risk Assessment of Exchange 2007 with MS TAM</title><description>&lt;a href="http://www.shortinfosec.net/2009/11/risk-assessment-with-microsoft-threat.html"&gt;In our previous post&lt;/a&gt;, we discussed the process of risk assessment assisted with Microsoft Threat Analysis and Modeling. While that post was purely theoretical, we are following up with a sample risk assessment of an IT service - Exchange 2007 infrastructure.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SvM62reWCnI/AAAAAAAAAVg/Ob9ehBbZlIY/s1600-h/Exchange2007_Risk_Assessment.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SvM62reWCnI/AAAAAAAAAVg/Ob9ehBbZlIY/s320/Exchange2007_Risk_Assessment.jpg" alt="" id="BLOGGER_PHOTO_ID_5400725089204701810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The Assessment is based on the prototype design of Microsoft Exchange Infrastructure, and all Exchange roles are treated as separate component/server. An Active Directory domain controller is added to the infrastructure since Exchange is integrated with it. Also, we added a Mailbox database role, just as an example that we can dissect the roles to the depth that we need.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The elements&lt;/span&gt;&lt;br /&gt;The analysis contains the following components. Add them to the appropriate container within the MS TAM&lt;br /&gt;&lt;span style="font-style: italic;"&gt;User roles&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Exchange Admins&lt;/span&gt; - all administrators of the infrastructure&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Exchange Users&lt;/span&gt; - users of all Exchange services&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Exchange OWA Users&lt;/span&gt; - users of Online Web Access (webmail users)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;External mail users&lt;/span&gt; - users of other mail servers on the internet&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;"&gt;Components with Service Roles&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Mailbox Server&lt;/span&gt; &lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Mailbox Server Service Role&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Hub Transport Server &lt;/span&gt;&lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Hub Transport Service Role&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Edge Transport Server &lt;/span&gt;&lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Edge Transport Service Role&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Client Access Server &lt;/span&gt;&lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Client Access Service Role&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Mailbox Database &lt;/span&gt;&lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Mailbox Database Service Role&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;AD Domain Controller &lt;/span&gt;&lt;span style="font-style: italic;"&gt;with &lt;/span&gt;Domain Controller Service Role&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;"&gt;External dependencies&lt;/span&gt;&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;External Mail Servers&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;"&gt;Data&lt;br /&gt;&lt;/span&gt;The data processed within this infrastructure is the following&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;E-mail message&lt;/span&gt; - the main target, the incoming and outgoing e-mail messages.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Exchange address&lt;/span&gt; - your e-mail address&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Exchange Configuration&lt;/span&gt; - All Exchange Roles Configuration - Stored within Domain Controller&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Login Credentials&lt;/span&gt; - username/password&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;Use cases&lt;/span&gt;&lt;br /&gt;We have limited the use cases to the most basic and essential activities within this infrastructure. For each use case you will need to include the necessary calls to make it functional.&lt;br /&gt;&lt;ul style="font-weight: bold;"&gt;&lt;li&gt;Receive External E-mail&lt;/li&gt;&lt;li&gt;Read E-mail Via POP3 /IMAP/OWA&lt;/li&gt;&lt;li&gt;Send E-mail To Exchange User&lt;/li&gt;&lt;li&gt;Exchange Admins Manages Exchange Accounts&lt;/li&gt;&lt;li&gt;Send E-mail to External Address&lt;/li&gt;&lt;/ul&gt;&lt;span&gt;Also,&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;span&gt;the assessment has additional &lt;span style="font-style: italic;"&gt;relevancies&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Component utilizes Power Supply &lt;/span&gt;- The component is susceptible to power failures&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Component utilizes Communication Links&lt;/span&gt; - The component is dependent on functional LAN/WAN links to perform it's function&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Component utilizes Disk Capacity &lt;/span&gt;- The component stores data, and relies on disk storage, thus it can lose data of the disk fails, or it's capacity is filled.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Component is a Physical Object&lt;/span&gt; - Component is a Physical Object and can be physically accessed, stolen or tampered with, or ultimately, it can fail&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;The analysis&lt;/span&gt;&lt;br /&gt;After setting up these elements, you click the Tools-&gt;Generate Threats. Choose Generate Threats based on all of your calls, and use Intelligent Append.&lt;br /&gt;The resulting set of risks can be confusing, since they are &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;autogenerated&lt;/span&gt; and have generic names. You will need to read through them, and possibly merge one or more into one, since they can be addressing the same risk.&lt;br /&gt;&lt;br /&gt;After you have finished the filtering, you need to define &lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Probablity&lt;/span&gt; &lt;/span&gt;and &lt;span style="font-weight: bold;"&gt;Impact &lt;/span&gt;of the risk, and select the Risk Response as well as countermeasures from the offered set. This task is very time consuming and often difficult. You should always employ the assistance of a subject matter expert which can give you valuable input.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;When you do this for every risk, you have finished the risk assessment&lt;/span&gt;  &lt;span style="font-weight: bold;"&gt;The Report &lt;/span&gt; &lt;a href="http://www.shortinfosec.net/2009/11/risk-assessment-with-microsoft-threat.html"&gt;As we pointed out in the previous post&lt;/a&gt;, the most useful report template for risk analysis does not exist in the predefined reports, &lt;a href="http://spirovski.b.googlepages.com/risk_report.xslt"&gt;but can be downloaded here&lt;/a&gt;.&lt;br /&gt;&lt;a href="http://sites.google.com/site/spirovskib/files/Exchange_2007_Risk_Report.pdf?attredirects=0&amp;amp;d=1"&gt;The final risk analysis report for this infrastructure can be downloaded here.&lt;/a&gt;&lt;br /&gt;Also, you may benefit from the Comprehensive Report, which is included in the templates of MS TAM.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;br /&gt;We hope that this example will help you to in the everyday use of MS TAM as a risk assessment tool.&lt;br /&gt;&lt;a href="http://sites.google.com/site/spirovskib/files/Exchange2007.atmx?attredirects=0&amp;amp;d=1"&gt;&lt;span style="font-weight: bold;"&gt;We are also publishing the entire ACE Threat Model file of this example for download and use.&lt;/span&gt;&lt;br /&gt;&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;Please do not hesitate to contact &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Shortinfosec&lt;/span&gt; if you have any questions or issues&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/11/risk-assessment-with-microsoft-threat.html"&gt;Risk Assessment with Microsoft Threat Assessment &amp;amp; Modeling&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/02/reduce-risks-in-projects-with-deal.html"&gt;Reduce Risks in Projects with 'Deal Breakers'&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/03/tutorial-secure-web-based-job.html"&gt;Tutorial - Secure Web Based Job Application&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/06/information-risks-when-branching.html"&gt;Information Risks when Branching Software Versions&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6769383693351574128?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/lvmjLwzKgbc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/lvmjLwzKgbc/example-risk-assessment-of-exchange.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SvM62reWCnI/AAAAAAAAAVg/Ob9ehBbZlIY/s72-c/Exchange2007_Risk_Assessment.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/example-risk-assessment-of-exchange.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-8136119994769075705</guid><pubDate>Tue, 03 Nov 2009 20:36:00 +0000</pubDate><atom:updated>2009-11-05T22:40:35.609+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">windows</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Risk Assessment with Microsoft Threat Assessment &amp; Modeling</title><description>Every organization has some form of Information Security Risk assessment. Some perform a formal risk assessment, others simply use their practical &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;experience&lt;/span&gt;. Whatever method is chosen, it always help to use a tool which will assist the organization in performing the risk assessment in a controlled and reproducible manner.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The tool&lt;/span&gt;&lt;br /&gt;There aren't that many tools that assist the organization in performing risk assessment. The most widely used one is Excel, but it is far from a good choice. Microsoft has also created &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=59888078-9DAF-4E96-B7D1-944703479451&amp;amp;displaylang=en"&gt;MS Threat Assessment and Modeling&lt;/a&gt; - a tool that although designed for a slightly different purpose, can easily be used for Risk Assessment.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The process&lt;br /&gt;&lt;/span&gt;Performing risk assessment with MS TAM is easy once you understand the components and the process.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Components of the MS TAM Analysis&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Roles &lt;/span&gt;– Functional Identities involved in the assessed process/system; these can include both service identities and human identities&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Components &lt;/span&gt;– System elements used in the involved in the assessed process/system – most commonly servers or subsystems&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Data&lt;/span&gt; – Data stored and processed in the involved in the assessed process/system – in effect ANYTHING THAT TRAVERSES THE components&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;External Dependencies &lt;/span&gt;– Any external elements including data, components or roles from other processes or systems&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Use Cases&lt;/span&gt; – the steps involved in operating the system/performing the process&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Relevancies&lt;/span&gt;&lt;/span&gt; – characteristics attributed to any component that relevant to the components method of operation and open a possible vector of attack&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Attacks&lt;/span&gt; – methods of compromising or destroying a component via misuse of characteristics of one or several relevancy attributed to the component&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Threats &lt;/span&gt;- the assessed threats to the system. This component will be used to generate and assess the risks&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The process consists of the steps/phases&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 0&lt;/span&gt; – Before starting anything, know your system/process/company. You will need to simulate and configure all relevant elements of the assessed system/process/company.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 1 – Define Roles&lt;/span&gt; - Define the logical groups of users involved in the system/process/company that is assessed&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 2 – Define Components and Data &lt;/span&gt;- These are the building blocks of the system/process. Data traverses components and is accessed by users and components&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 3 – Update and Define &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Relevancies&lt;/span&gt;&lt;/span&gt; - Create or update relevant attributes that define behavior of a component. For instance, a relevancy is that a component uses power supply, therefore it is &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;susceptible&lt;/span&gt; to the risk of power failure. Add new &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;relevancies&lt;/span&gt; for your specific components&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 4 – Update attacks &lt;/span&gt;- Attacks are methods of misusing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;relevancies&lt;/span&gt;. Update the current attacks with specific ones - if you have them. If you have created new &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;relevancies&lt;/span&gt;, create the attacks that compromise them. For each attack, include countermeasures that mitigate this attack. For instance, if the attack is power supply brownout, one possible countermeasure is an in-line UPS that acts as a voltage stabilizer.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 5&lt;/span&gt; – &lt;span style="font-weight: bold;"&gt;Define Use Cases and Calls&lt;/span&gt;- The Use cases are the steps in the process, or the way a system is operated/used. Without the use cases, the risk assessment cannot be performed. For instance, one use case for a mail server system is the reception of an e-mail from an external mail server (from the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;Internet&lt;/span&gt;).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Step 6 – Model Risks &lt;/span&gt;- After you have modeled your system, generate the Threats, and analyze them one by one to assess frequency and impact, and define countermeasures from the offered possibilities. At the end of the process, the finalized threats are the risks to your system.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvCbGWgASWI/AAAAAAAAAVY/MpuVy-DHhJw/s1600-h/MS_TAM_Risk_Assessment_Process.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 160px;" src="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvCbGWgASWI/AAAAAAAAAVY/MpuVy-DHhJw/s320/MS_TAM_Risk_Assessment_Process.jpg" alt="" id="BLOGGER_PHOTO_ID_5399986486638561634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;bold&gt;NOTE: It’s very important to be very meticulous about the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;relevancies&lt;/span&gt; – the attributes of the components. Choosing well in this step allows good modeling of attacks and the more automated risk model is created&lt;/bold&gt;&lt;br /&gt;&lt;bold&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The results&lt;/span&gt;&lt;br /&gt;&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_9"&gt;After&lt;/span&gt; completing the process, the end result is the report set. The MS TAM has a predefined set of reports. Since MS TAM is primarily targeted at software development, the generic reports may be found to be lacking. The most useful report is the comprehensive report, which includes nearly all information. But it is still lacking a report which summarizes the risk assessment parameters:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Impact&lt;/li&gt;&lt;li&gt;Probability&lt;/li&gt;&lt;li&gt;Risk Rating&lt;/li&gt;&lt;li&gt;Risk Response&lt;/li&gt;&lt;li&gt;Countermeasures&lt;/li&gt;&lt;/ol&gt;&lt;a href="http://spirovski.b.googlepages.com/risk_report.xslt"&gt;To address this, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;Shortinfosec&lt;/span&gt; has created a custom report for MS TAM 2.1 which can be downloaded here&lt;/a&gt;. Just place the file in the MS_TAM_INSTALL_FOLDER\Graphics\Reports\Custom and choose Custom Reports, risk_report.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;xslt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;br /&gt;MS Threat Assessment and Modeling 2.1.2 may not be the best tool for Risk Assessment. It may not match your Risk assessment methodology to the letter, nor does it deliver the final result out of the box. But unless you have a better tool, it is very usable, since it controls the process, and with MS TAM you will always follow the mindset of risks, threats and impact.&lt;br /&gt;And of course, until you have a better product, use the one that is readily available!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;If anyone encounters a problem or has a question with using MS TAM, just leave a comment, or send me an e-mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/11/example-risk-assessment-of-exchange.html"&gt;Example Risk Assessment of Exchange 2007 with MS TAM&lt;/a&gt;&lt;br /&gt;&lt;bold&gt;&lt;a href="http://www.shortinfosec.net/2009/02/reduce-risks-in-projects-with-deal.html"&gt;Reduce Risks in Projects with 'Deal Breakers'&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/03/tutorial-secure-web-based-job.html"&gt;Tutorial - Secure Web Based Job Application&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/06/information-risks-when-branching.html"&gt;Information Risks when Branching Software Versions&lt;/a&gt;&lt;br /&gt;&lt;/bold&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-8136119994769075705?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/ggkzlVa8emk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/ggkzlVa8emk/risk-assessment-with-microsoft-threat.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SvCbGWgASWI/AAAAAAAAAVY/MpuVy-DHhJw/s72-c/MS_TAM_Risk_Assessment_Process.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/11/risk-assessment-with-microsoft-threat.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-4870176941935128980</guid><pubDate>Fri, 30 Oct 2009 19:10:00 +0000</pubDate><atom:updated>2009-11-01T20:03:19.015+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Computer security</category><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Nessus vs Retina - Vulnerability Scanning Tools Evaluation</title><description>&lt;a href="http://www.shortinfosec.net/2009/01/system-hardening-process-checklist.html"&gt;We have mentioned our favorite vulnerability scanning tools in this blog&lt;/a&gt;. But a lot of time has passed since, so it is time to put these tools against each other and evaluate the quality of the results received when scanning the same target.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATE: After the constructive input from Michael A. in the comments, we have reworked the test for Nessus, to achieve more comparable results. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SutmnwJtq-I/AAAAAAAAAVQ/8urnTXGXRY8/s1600-h/Retina_VS_Nessus.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 307px; height: 320px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SutmnwJtq-I/AAAAAAAAAVQ/8urnTXGXRY8/s320/Retina_VS_Nessus.jpg" alt="" id="BLOGGER_PHOTO_ID_5398521411460246498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Test Environment&lt;/span&gt;&lt;br /&gt;The tested vulnerability scanning tools were installed on a Windows 7 Pro PC.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/nessus/"&gt;&lt;span style="font-weight: bold;"&gt;Nessus &lt;/span&gt;&lt;/a&gt;server and client were installed and updated to the latest plugins.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.eeye.com/html/Products/Retina/index.html"&gt;Retina&lt;/a&gt; &lt;/span&gt;5.10.18.2135 Evaluation version  was downloaded and installed. The Evaluation version does not allow updates, so we used what updates are included in the build.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The target was Damn Vulnerable Linux (DVL) version 1.5 installed as a VMWARE host with bridged networking on the same host PC as the vulnerability scanning tools. The network of the DVL target was bridged, and all firewalls (both of the host OS and the guest OS) were disabled. The DVL was started with the following services, with default settings and content as included in the distro.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;MySQL&lt;/li&gt;&lt;li&gt;HTTP&lt;/li&gt;&lt;li&gt;IPP Printer sharing which was active by default&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Scanning Process&lt;/span&gt;&lt;br /&gt;Both scanners were started with setting on full port scan, with disabled safety of scanning, and all available plugins were activated. NOTE: Since Retina does not have WebApplication Analysis, Nessus was run twice, once with WebApplications disabled, and once with WebApplication enabled in order to do a meaningful performance comparison&lt;span style="font-style: italic;"&gt;.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;Performance&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The Nessus scanner without WebApplication scan took 8 minutes to complete the scan&lt;/li&gt;&lt;li&gt;The Nessus scanner with WebApplication scan took 67 minutes to complete the scan&lt;/li&gt;&lt;li&gt;The Retina scanner took 38 minutes to complete the scan&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;"&gt;Results&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Both scanners failed to identify the target operating system&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;The Nessus scanner identified the expected open ports, concluded that MySQL does not accept connections from unauthorized IP's. On a repeat scan, it regenerated the same results.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="font-weight: bold;" href="http://spirovski.b.googlepages.com/Nessus_Scan_Results_No_Web.html"&gt;You can download the full report of the Nessus Scan Here&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The Retina scanner identified HTTP and TCP port 631 (IPP Printer Sharing). It did not identify the MySQL port as open. On the Web server, it identified a significant number of vulnerabilites, but did not collect any information from the HTTP server. On a repeat scan it missed the HTTP port and only identified the MySQL port.&lt;br /&gt;&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;a href="http://spirovski.b.googlepages.com/Retina_Scan_Results.pdf"&gt;You can download the full report of the Retina Scan Here&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The Nessus Scanner running the WebApplication Scanning repeated the previous results and additionally it identified a significant number of WebApp vulnerabilites, and collected information from HTTP through web mirroring.&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;&lt;a style="font-weight: bold;" href="http://spirovski.b.googlepages.com/Nessus_Scan_Results_With_Web.html"&gt;You can download the full report of the Nessus Scan with WebApplication Scanning Here&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Conclusions&lt;/span&gt;&lt;br /&gt;Both scanners performed a very well vulnerability identification but missed the OS identification. Also, &lt;span style="font-style: italic;"&gt;both manifested flaws:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Nessus missed the IPP port every time&lt;/li&gt;&lt;li&gt;Retina manifested erroneous scan results, identifying different ports and vulnerabilities during different sessions - while no configuration changes were made to the test environment. &lt;/li&gt;&lt;/ol&gt;&lt;span style="font-style: italic;"&gt;In terms of speed, &lt;/span&gt;&lt;span&gt;without WebApplication Scan Nessus &lt;/span&gt;performed much faster then Retina. On the other hand, with active WebApplication Scan, Nessus was much slower then Retina.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;In terms of scan depth, &lt;/span&gt;Nessus has a small advantage, since it includes a web mirroring tool that is very helpful in HTTP.&lt;br /&gt;&lt;br /&gt;It can be clearly concluded that these tools cannot be used as the sole source of information when performing a vulnerability test. One must also utilize network mapping (NMAP, LanGuard), OS identification (NMAP) and specific application vulnerability scanners (ParosProxy, WebScarab for Web) for maximum effect.&lt;br /&gt;&lt;br /&gt;In a direct comparison, Nessus wins because&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Retina manifested erroneous results on repeat scans,&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The Nessus package includes a WebApplication scanning module, which in eEye products needs to be purchased as a separate application &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/01/system-hardening-process-checklist.html"&gt;System Hardening Process Checklist&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/03/having-web-site-that-is-not-that-easy.html"&gt;Web Site that is not Easy to hack - Part 2 HOWTO - the web site attacks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/12/checking-web-site-security-quick.html"&gt;Checking web site security - the quick approach&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-4870176941935128980?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/aSSIxVLUq8Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/aSSIxVLUq8Q/vulnerability-scanning-tools-evaluation.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SutmnwJtq-I/AAAAAAAAAVQ/8urnTXGXRY8/s72-c/Retina_VS_Nessus.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/10/vulnerability-scanning-tools-evaluation.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-1965548639927502925</guid><pubDate>Wed, 28 Oct 2009 21:13:00 +0000</pubDate><atom:updated>2009-10-28T22:40:12.771+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Computer security</category><category domain="http://www.blogger.com/atom/ns#">windows</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>New Version of Microsoft Baseline Security Analyzer</title><description>Our Microsoft Baseline Security Analyzer scanner has just reported that a new version (2.1.1) is available. It can be downloaded from the following URL&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b1e76bbe-71df-41e8-8b52-c871d012ba78&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=b1e76bbe-71df-41e8-8b52-c871d012ba78&amp;amp;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;displaylang&lt;/span&gt;=en&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sui4PKueV1I/AAAAAAAAAVI/h6GM_7Ko-Yg/s1600-h/Shortinfosec_Microsoft_Baseline_Security_Analyzer.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sui4PKueV1I/AAAAAAAAAVI/h6GM_7Ko-Yg/s320/Shortinfosec_Microsoft_Baseline_Security_Analyzer.jpg" alt="" id="BLOGGER_PHOTO_ID_5397766724120368978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;We were &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;disappointed&lt;/span&gt; to see that the 2.1 version did not work properly on Windows 7 - it just reported that the computer is not a Windows NT/2000/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;XP&lt;/span&gt;/2003 computer.&lt;br /&gt;&lt;br /&gt;The 2.1.1 does not provide any new major functionality, but now it is fully compatible with the current version of Windows.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://spirovski.b.googlepages.com/Shortinfosec_MBSA_SCAN.pdf"&gt;&lt;span style="font-weight: bold;"&gt;You can download the baseline that we did on our demo Windows 7 laptop here&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;posts&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/10/windows-7-full-disk-encryption-with.html"&gt;Windows 7 Full Disk Encryption with Truecrypt&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/12/wmi-scanning-excellent-security-tool.html"&gt;WMI Scanning - Excellent Security Tool&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/example-bypassing-wifi-mac-address.html"&gt;Example - Bypassing WiFi MAC Address Restriction&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-1965548639927502925?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/aSd-SrJ3mg4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/aSd-SrJ3mg4/new-version-of-microsoft-baseline.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sui4PKueV1I/AAAAAAAAAVI/h6GM_7Ko-Yg/s72-c/Shortinfosec_Microsoft_Baseline_Security_Analyzer.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/10/new-version-of-microsoft-baseline.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-4570922449263362588</guid><pubDate>Mon, 26 Oct 2009 18:30:00 +0000</pubDate><atom:updated>2009-10-26T20:05:18.664+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Computer security</category><category domain="http://www.blogger.com/atom/ns#">encryption</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Windows 7 Full Disk Encryption with Truecrypt</title><description>After the &lt;a href="http://www.shortinfosec.net/2008/05/truecrypt-full-disk-encryption-review.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;TrueCrypt&lt;/span&gt; Full Disk Encryption Review&lt;/a&gt; and the &lt;a href="http://www.shortinfosec.net/2008/05/5-rules-to-protecting-information-on.html"&gt;5 rules to Protecting Information on your Laptop&lt;/a&gt;, we are following up with a practical test of full disk encryption of Windows 7.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Shortinfosec&lt;/span&gt; is a great promoter of full disk encryption of laptop hard drives, and we have been using Windows 7 for several months now. On 21 Oct 2009, &lt;a href="http://www.truecrypt.org/downloads"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Truecrypt&lt;/span&gt; published the version 6.3&lt;/a&gt; which has full support for Windows 7. &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;Of course&lt;/span&gt;, why go for an open source product instead of the native &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;BitLocker&lt;/span&gt;? &lt;span style="font-weight: bold;"&gt;Well, Microsoft with it's product strategy includes &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;BitLocker&lt;/span&gt; only in Ultimate and Enterprise versions of Windows 7!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Can someone say 'huge security misstep' - especially for the Windows 7 Pro users?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Encryption&lt;/span&gt;&lt;br /&gt;Naturally, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Shortinfosec&lt;/span&gt; started with a full disk encryption test on a laptop. The laptop has the following configuration.&lt;ul&gt;&lt;li&gt;2.1 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Ghz&lt;/span&gt; Core2Duo CPU&lt;/li&gt;&lt;li&gt;3 GB of RAM&lt;br /&gt;&lt;/li&gt;&lt;li&gt;320 GB of disk drive&lt;/li&gt;&lt;li&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;NVIDIA&lt;/span&gt; graphics&lt;/li&gt;&lt;li&gt;Windows 7 Pro 32 bit operating system&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The process is the same as already described in &lt;a href="http://www.shortinfosec.net/2008/05/truecrypt-full-disk-encryption-review.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;TrueCrypt&lt;/span&gt; Full Disk Encryption Review&lt;/a&gt;. The installation of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;TrueCrypt&lt;/span&gt; is so generic that even the most inexperienced users should have no problems whatsoever.&lt;br /&gt;&lt;br /&gt;The actual encryption is lasts between 6-7 hours. After it finishes, you have an encrypted system drive. If absolutely necessary, you may even use the computer while the drive is being encrypted, but you won't be very productive.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Performance test&lt;/span&gt;&lt;br /&gt;The laptop had a passmark test run before and after the encryption. We focused on CPU and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;HDD&lt;/span&gt; performance, since these areas are impacted when using an encrypted &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_12"&gt;file system&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The test results are presented on the following screenshots. The overall performance of the Test Laptop is marginally better for the non-encrypted disk clone. The disk drive is most impacted on the random read/write test.&lt;br /&gt;&lt;br /&gt;The results in &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;red color&lt;/span&gt; are before the encryption&lt;br /&gt;The results in &lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;green color&lt;/span&gt; are after the encryption&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuXxXNpzKxI/AAAAAAAAAU4/v0WmQymyMSI/s1600-h/Truecrypt_CPUMark.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuXxXNpzKxI/AAAAAAAAAU4/v0WmQymyMSI/s320/Truecrypt_CPUMark.jpg" alt="" id="BLOGGER_PHOTO_ID_5396985109577673490" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SuXyAfIlvOI/AAAAAAAAAVA/RsVj-mk4QDc/s1600-h/Truecrypt_DiskMark.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SuXyAfIlvOI/AAAAAAAAAVA/RsVj-mk4QDc/s320/Truecrypt_DiskMark.jpg" alt="" id="BLOGGER_PHOTO_ID_5396985818644856034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Conclusion&lt;br /&gt;&lt;/strong&gt;Encrypting the entire hard drive of Windows 7 may not seem to be a natural choice, but the product strategy of MS opens up an opportunity for products like &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;Truecrypt&lt;/span&gt;.&lt;br /&gt;&lt;p&gt;Encrypting the entire hard drive &lt;strong&gt;will &lt;/strong&gt;cause performance reduction of the disk subsystem, but the performance reduction on our system is so minute that it is just ignored by everyone.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Related posts&lt;/p&gt;&lt;a href="http://www.shortinfosec.net/2009/02/cracking-truecrypt-container.html"&gt;Cracking a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;TrueCrypt&lt;/span&gt; Container&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/05/truecrypt-full-disk-encryption-review.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;TrueCrypt&lt;/span&gt; Full Disk Encryption Review&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/02/tutorial-hidden-operating-system-with.html"&gt;Tutorial - Hidden Operating System with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;Truecrypt&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/08/tutorial-poor-mans-secure-usb.html"&gt;Tutorial - A Poor Man's Secure &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;USB&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-4570922449263362588?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/X4XL9INfZWE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/X4XL9INfZWE/windows-7-full-disk-encryption-with.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuXxXNpzKxI/AAAAAAAAAU4/v0WmQymyMSI/s72-c/Truecrypt_CPUMark.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/10/windows-7-full-disk-encryption-with.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6805500826327631423</guid><pubDate>Sun, 25 Oct 2009 17:56:00 +0000</pubDate><atom:updated>2009-10-26T08:35:36.781+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network security</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Tutorial - Free Auditing of Active Directory for Information Security</title><description>Active Directory within a large organization goes through a lot of changes throughout the day. There are a lot of possibilities for error, creation of accounts with high privileges or missing the disabling task on an employee leaving the company.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuSY4vsK85I/AAAAAAAAAUo/QWGwhlFHS0k/s1600-h/Active-Directory.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuSY4vsK85I/AAAAAAAAAUo/QWGwhlFHS0k/s320/Active-Directory.gif" alt="" id="BLOGGER_PHOTO_ID_5396606354138526610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Information Security Teams need fast and easily readable auditing, possibly with automation.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;The tool&lt;/span&gt;&lt;br /&gt;While there are several excellent products that perform this function, auditing of Active Directory can become a costly endeavor. NetWrix has a free version of their &lt;span style="font-weight: bold;"&gt;Active Directory Change &lt;/span&gt;Reporter. It can be installed on any  computer that is a member of the domain. Here is a screenshot of the configuration screen:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SuSYuMZxNBI/AAAAAAAAAUg/Y7qwelyU3Sg/s1600-h/netwrix-Active-Directory-Change-Config.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 229px; height: 320px;" src="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SuSYuMZxNBI/AAAAAAAAAUg/Y7qwelyU3Sg/s320/netwrix-Active-Directory-Change-Config.JPG" alt="" id="BLOGGER_PHOTO_ID_5396606172867408914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The process&lt;/span&gt;&lt;br /&gt;The auditing is performed by taking a 'snapshot' of the Active Directory Domain state at scheduled intervals. This snapshot is stored in a directory, and can be used to create HTML reports of the changes that happened between two 'snapshots'. There is even an automated reporting which will deliver report on changes to the directory at predefined schedules.&lt;br /&gt;&lt;br /&gt;The report clearly displays what objects have been added, removed or modified within the Active Directory Domain. Ofcourse, additional history like who made the change and when can be obtained via the commercial version, but even in the free version it produces a nice set of information.&lt;br /&gt;&lt;br /&gt;Here is a screenshot of the report&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SuSdQwAoPkI/AAAAAAAAAUw/MWYb3z8-N80/s1600-h/Active-Directory-Changes-Report.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SuSdQwAoPkI/AAAAAAAAAUw/MWYb3z8-N80/s320/Active-Directory-Changes-Report.jpg" alt="" id="BLOGGER_PHOTO_ID_5396611164587703874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;br /&gt;&lt;/span&gt;While the Free version of NetWrix is far in functionality from the big players, it provides an clear and automated reporting. It is a good choice to start with the free version, and prepare for purchasing a commercial tool by learning from it and noting which functionalities you require that this tool does not deliver.&lt;br /&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/10/firefox-is-great-browser.html"&gt;Controlling Firefox Through Active Directory&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6805500826327631423?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/byzlOyxckPc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/byzlOyxckPc/tutorual-free-auditing-of-active.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SuSY4vsK85I/AAAAAAAAAUo/QWGwhlFHS0k/s72-c/Active-Directory.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/10/tutorual-free-auditing-of-active.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6936401729839355664</guid><pubDate>Wed, 01 Jul 2009 19:39:00 +0000</pubDate><atom:updated>2009-07-01T22:03:19.627+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information strategy</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Evaluation of Security Information Event Management Systems</title><description>Evaluating Security Information Event Management (SIEM) solutions come in a lot of different flavours. The industry is not yet mature, and the competitors are pushing their own solutions, based on their background and capabilities. In general, they will all present more or less the following configuration model for the SIEM implementation.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sku8aGjP08I/AAAAAAAAAUU/FKXX8TCWeZw/s1600-h/Security-Information-Event-Management-Config-Example.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 258px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sku8aGjP08I/AAAAAAAAAUU/FKXX8TCWeZw/s320/Security-Information-Event-Management-Config-Example.JPG" alt="" id="BLOGGER_PHOTO_ID_5353579738681037762" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;But other then the generic model, a lot of things are different. So, in order to sift through the multitude of solutions, the buyer needs to ask the real questions. Here are some of the key questions that need to be taken into consideration:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Is it possible to place an agent on the server machines &lt;/span&gt;- Certain SIEM solutions do not properly support remote collection of OS or application logs so they need a server side agent to do the job. On the other hand, most business critical systems are tightly controlled and do not allow for additional resident programs to be installed on the system for the risk of possible performance or reliability issues &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Are there any custom applications that generate logs that needs to be collected by the SIEM? &lt;/span&gt;- The organization may require that the SIEM also collects and parses such logs, but proper parsing ability needs to be verified with a large sample of logs during a proof of concept run.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Is there any international standard or regulation that is mandating the SIEM solution&lt;/span&gt; - whatever standard needs to be met has a set of predefined controlling reports that confirm compliance to the standard. You need to confirm that the SIEM solution can produce the needed reports. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;How long will you need to keep logs and conclusions online and offline? &lt;/span&gt;- data retention is key to such a massive collection of information. Typically, a SIEM system needs to be able to archive all historical events to external data storage, and preferably, the archival process should include an integrity control (MD5 or SHA1 hash) that guarantee that the logs haven't been tampered with while in archive. &lt;/li&gt;&lt;li&gt;What type of processing and alerting is required?-&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Proper answers to these questions will most likely eliminate the non-acceptable solutions, and will ease the evaluation process of the qualifying shortlist.&lt;br /&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/06/real-benefit-of-security-information.html"&gt;Real Benefit of Security Information Event Management&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6936401729839355664?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/48So_xbN1is" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/48So_xbN1is/security-information-event-management.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sku8aGjP08I/AAAAAAAAAUU/FKXX8TCWeZw/s72-c/Security-Information-Event-Management-Config-Example.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/07/security-information-event-management.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-3402390499716391858</guid><pubDate>Sun, 21 Jun 2009 08:34:00 +0000</pubDate><atom:updated>2009-06-21T12:30:58.682+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information strategy</category><category domain="http://www.blogger.com/atom/ns#">information security</category><category domain="http://www.blogger.com/atom/ns#">audit</category><title>Real Benefit of Security Information Event Management</title><description>Security Information Event Management is the echoing buzzword in most industries these days. Banking, &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;Telecommunications&lt;/span&gt;&lt;/span&gt;, Power and Energy - anyone and everyone is under internal audit and regulator scrutiny to implement a Security Information Event Management system.&lt;br /&gt;But most &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Security Information Event Management&lt;/span&gt;&lt;/span&gt; implementations are rushed and placed only to shut up the auditors and to go on as usual. Since it's a compliance requirement, the &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Security Information Event Management &lt;/span&gt;&lt;/span&gt;salespeople very rarely address whether the customer makes proper use of the solution, and whether this solution brings benefits to the company.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/Sj35EUe2ouI/AAAAAAAAATw/X-a6p9m40dM/s1600-h/compliance-siem.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 249px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5349705784998929122" border="0" alt="" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/Sj35EUe2ouI/AAAAAAAAATw/X-a6p9m40dM/s320/compliance-siem.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;The common issue&lt;br /&gt;&lt;/span&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; is a Security Officer tool, but since it tightly integrates with IT equipment, the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; implementation is usually left to IT departments. The issue with this is that IT will approach the implementation from a purely technical aspect: how to properly connect the IT equipment to the &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; system.&lt;br /&gt;&lt;br /&gt;Once the &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; system is collecting audit logs and events from all required IT elements, the job is done. At most, a retention policy and archiving is also done by IT, and the story ends there.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;The real benefit&lt;/span&gt;&lt;br /&gt;Any &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; system is simply a large database collecting massive amounts of events. But if one does not use these events, the system is placed there just as a form, and brings only costs to the company. Here is what you'll need to set-up to achieve benefits of a &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; system&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Choosing what is most important to be alerted about &lt;/span&gt;- While some automated alerts and analysis are available within all &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; systems, the generic alerts are rarely well matched to a company. For example, a generic alert may be triggered by consecutive failed attempts followed by a successful &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;logon&lt;/span&gt;&lt;/span&gt;, but may not be triggered on a configuration change of a firewall. The first event was merely an employee trying to remember his password, and the &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;config&lt;/span&gt;&lt;/span&gt; change of the firewall just opened up your network to some attack&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Alerting the proper person/team&lt;/span&gt; - The alerting means nothing if the alert does not arrive to the proper person to react in the fastest possible time. A 'transaction log is full' means little to a network admin just as SYN flood may mean absolutely nothing to the &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;DBA&lt;/span&gt;&lt;/span&gt;. And both will mean not too much to the head of the department, if one chooses to send all alerts to the manager.&lt;/li&gt;&lt;li&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Creating and using the proper reports &lt;/span&gt;- Some &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; systems come bundled with reports, other sell the reports as packages. But the vanilla flavour reports may not always be useful to the organization, so the correct report definition should be prepared and implemented during the &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; implementation. This way the company will know that these reports are to their specification, and even more, that the data needed for this report is collected by the &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;SIEM&lt;/span&gt;&lt;/span&gt; system.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;Talkback&lt;/span&gt;&lt;/span&gt; and comments are most welcome&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-3402390499716391858?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/ZGueN072iL0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/ZGueN072iL0/real-benefit-of-security-information.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Hu1rpxRsqcU/Sj35EUe2ouI/AAAAAAAAATw/X-a6p9m40dM/s72-c/compliance-siem.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/06/real-benefit-of-security-information.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-4673376564244640721</guid><pubDate>Wed, 10 Jun 2009 20:19:00 +0000</pubDate><atom:updated>2009-06-10T22:20:45.896+02:00</atom:updated><title>Shortinfosec ReBoot</title><description>I have taken a sabbatical from blogging to rest and focus on other issues. This period is now finished, and Shortinfosec will continue with the regular posts!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-4673376564244640721?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/YUtrVOFQJC0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/YUtrVOFQJC0/shortinfosec-reboot.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/06/shortinfosec-reboot.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6293868721797775626</guid><pubDate>Wed, 22 Apr 2009 13:38:00 +0000</pubDate><atom:updated>2009-04-23T21:16:54.311+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>5 biggest mistakes of information security</title><description>Does your information security implementation suffer from mistakes in approach? Everyone is focused on information security, and security is a constant addition into every corporate mission statement. And yet in nearly every security implementation there is a recurring range of mistakes in information security. Here are the most common five&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Focusing primarily on perimeter security &lt;/span&gt;- Put in firewalls and other firewalls behind those firewalls, and some IPS in the middle, and set them all up to defend the Internet link of the corporation. And that's it, no need to do anything else. Sounds familiar? Defending the perimeter is important, but it's not the only point of security strengthening. A successful attack does not try to punch a hole through the thickest wall - it finds a way to bypass such walls. &lt;span style="font-style: italic;"&gt;Security needs to be layered and focused at properly protecting information storing and processing resources&lt;/span&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SfC-cfSc0GI/AAAAAAAAATo/5zn83sTRF5s/s1600-h/security-mistake.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SfC-cfSc0GI/AAAAAAAAATo/5zn83sTRF5s/s320/security-mistake.jpg" alt="" id="BLOGGER_PHOTO_ID_5327967755823796322" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Relying on hard coded elements &lt;/span&gt;- whether it be a hostname, an IP address or a username/password pair, hard coded elements in a file open a gaping hole in security. Anyone managing to read or disassemble the file has access to a nice set of information very useful to attack. &lt;span style="font-style: italic;"&gt;Always rely on user input elements or single sign-on instead of hard coded elements.&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Trusting people&lt;/span&gt; - Any casino owner will tell you the grim truth - 30% of employees are out to steal from you. This is true in any industry, and by the way, you can never know which are included in the 30%. Therefore, implicit trust and saying "he/she can never do us harm, the loyalty is too great" will only land you in trouble. &lt;span style="font-style: italic;"&gt;Always enforce security rules and policies for every process and employee&lt;/span&gt;.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Relying on an issue being fixed in the "other element"&lt;/span&gt; - "This will be fixed in the program", or "This will be fixed in the database". Finding an issue and hoping that someone else will fix it is stupid to say the least. &lt;span style="font-style: italic;"&gt;Address the issue immediately, for noone else will!&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Improper discarding of documentation&lt;/span&gt; - Hundreds of thousands of confidential documents are thrown into the garbage every day - even whole laptops which are for some reason not functioning properly. This act of simple neglect of unnecessary information is the nicest (and most legal) way of information and identity theft. &lt;span style="font-style: italic;"&gt;Institute simple procedures for information destruction, ranging from paper up to malfunctioning hard drives. The technical resources needed for this are inexpensive and plentiful&lt;/span&gt;!&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Do you have an example of mistakes? Add it in the comments!!!&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/04/3-things-no-book-about-hacking-will.html"&gt;3 Things no book about hacking will ever tell you&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/5-sla-nonsense-examples-always-read.html"&gt;5 SLA Nonsense Examples - Always Read the Fine Print&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6293868721797775626?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/mVst7B7Yzq0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/mVst7B7Yzq0/5-biggest-mistakes-of-information.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Hu1rpxRsqcU/SfC-cfSc0GI/AAAAAAAAATo/5zn83sTRF5s/s72-c/security-mistake.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">6</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/5-biggest-mistakes-of-information.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-5962401222109726741</guid><pubDate>Mon, 20 Apr 2009 21:41:00 +0000</pubDate><atom:updated>2009-04-20T23:45:56.361+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information strategy</category><title>SUN Purchase Analysis</title><description>Oracle owns Sun. It moved to acquire the failing giant ahead of IBM and now it has access to a great amount of installed base of Sun servers. But what will Oracle do with a hardware company, and what will remain of it after Larry Ellison is done with Sun?&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Hardware&lt;/span&gt; - Oracle has it's R&amp;amp;D focused on databases, and to some extent on underlying operating systems. But Oracle does not want to meddle with expensive chip research just to maintain the SPARC platform. So servers division will go on sale to HP, IBM, EMC, Dell or some venture capital firm - lock, stock and barrel. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Solaris &lt;/span&gt;- A wonderful OS, leader in many platforms. Oracle will want to make it's DBMS one-click installable on an empty machine, so Solaris for Intel will probably be the weapon of choice for this move. But in the process, Solaris will become an embedded &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;MySQL &lt;/span&gt;- a possible casualty of the RDBMS war - Oracle will need to position this product carefully, to be less competitive with Oracle RDBMS and more competitive to embedded databases and free competition. If Oracle cannot do this, they'll most probably let MySQL die of age by simply not developing it any further. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Consulting division &lt;/span&gt;- Some will be cut-off, some will become Oracle consulting and integration, to take even more off the high-margin integration consulting business&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Open source initiatives &lt;/span&gt;- THE BEST PLACE for developer breeding. If Oracle retained any smarts, it will maintain the strong support to open source, but steer it towards Oracle as development platform. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;JAVA&lt;/span&gt; - The weapon of mass destruction for Oracle - Just like open source initiatives, excpect that Java will continue to flourish - simply because Oracle wants more and more software that will use their databases.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;In any case, things won't be the same. It is sad to see another one of the high quality system giants go.&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/03/hp-partners-with-sun-anybody-remember.html"&gt;HP partners with Sun - Anybody remember Digital?&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-5962401222109726741?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/yUae1ypPlZw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/yUae1ypPlZw/sun-purchase-analysis.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/sun-purchase-analysis.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6265686353623515885</guid><pubDate>Wed, 15 Apr 2009 18:51:00 +0000</pubDate><atom:updated>2009-04-15T22:05:21.666+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Solution building</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>5 Minute Security Assessment</title><description>A security assessment is a big deal. It takes a lot of time, requires a good chunk of budget since it is done by independent consultants and the outcome is at best 'OK, but could be better'.&lt;br /&gt;&lt;br /&gt;For all these reasons, as well as some egoistic ones which won't be mentioned here, a lot of companies avoid hiring a security consultant and doing this assessment.&lt;br /&gt;&lt;br /&gt;While the real thing may take time, budget lobbying and guts to admit that you are not perfect, here is a very fast self-assessment which will give you a feeling where are you standing. You can do this assessment on your own time, and no one needs to know the outcome.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SeY94PxtgSI/AAAAAAAAATg/j3YuxyZfQdg/s1600-h/security-assessment.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 243px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SeY94PxtgSI/AAAAAAAAATg/j3YuxyZfQdg/s320/security-assessment.jpg" alt="" id="BLOGGER_PHOTO_ID_5325011645929193762" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Assessment instructions&lt;/span&gt;&lt;br /&gt;Answer each of the questions truthfully with a yes or a no. If it is partial, write it up as a no. For each answer add appropriate number of points to a total score (indicated on each question). After finishing with all the questions, sum the score and find the appropriate assessment result depending in which interval your score fell.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Assessment questions&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Do we have a firewall active at all ingress points of the network?&lt;/span&gt; Yes - 5 points, No - 0 points&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Does our team control all firewalls? &lt;/span&gt;Yes - 5 points, No - 0 points&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Do we have the following basic technical policies in place?&lt;/span&gt; Add 1 point for each policy in place&lt;br /&gt;&lt;/li&gt;&lt;ul&gt;&lt;li style="font-weight: bold;"&gt;password complexity&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;password retention&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;password history&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;logon hours&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;controlled registry editing&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Does everyone in the organization have their own individual and unique username for all activities?&lt;/span&gt; Yes - 5 points, No - 0 points&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Do we have logon/logoff auditing active on all servers and stations?&lt;/span&gt; Yes - 5 points, No - 0 points&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Do we have a testing environment for patches, new versions and new software before it is rolled out into production? &lt;/span&gt;Yes - 5 points, No - 0 points&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Do we have written procedures for regulating the above questions as process? &lt;/span&gt;Add 1 point for each procedure in place&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Assessment results&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;30-36 points - Very good security posture &lt;/span&gt;- You have the basics of a great security governance. Continue developing in both the procedural and technical levels of security.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;20-30 points - Acceptable security posture&lt;/span&gt; - You are lacking in written procedures and change management, but basic technical security is at a good level - you need to work harder on formalization&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;10-20 points - Basic security posture &lt;/span&gt;- Very basic security, lacking in any formal process of security, and also probably missing elements in auditing, ingress path control and technical policies. You need to go a long way, and you should have started yesterday!&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;0-10 points - Disaster waiting to happen &lt;/span&gt;- So you have firewalls? Really? And maybe you've even plugged them in? Hire a good security expert - after firing your current one and start getting somewhere&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/03/quick-and-basic-security-assessment-for.html"&gt;Quick and Basic Security Assessment for Databases&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/12/wmi-scanning-excellent-security-tool.html"&gt;WMI Scanning - Excellent Security Tool&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/tutorial-using-ratproxy-for-analysis.html"&gt;Tutorial - Using Ratproxy for Web Site Vulnerability Analysis&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6265686353623515885?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/aO1o09wM2as" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/aO1o09wM2as/5-minute-security-assessment.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Hu1rpxRsqcU/SeY94PxtgSI/AAAAAAAAATg/j3YuxyZfQdg/s72-c/security-assessment.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/5-minute-security-assessment.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-4003896145765433310</guid><pubDate>Mon, 13 Apr 2009 11:23:00 +0000</pubDate><atom:updated>2009-04-13T22:19:09.916+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>3 Things no book about hacking will ever tell you</title><description>There are tons of books which 'teach' you on how to become a hacker. Some boast to make you a hacker in XX number of days, or brag about being authored by the greatest experts in the field, or some other commercial &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;mumbo&lt;/span&gt;-jumbo.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;But is there any great wisdom in those books? No, and they are not even good at teaching technology.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SeOd9ownJ6I/AAAAAAAAATY/PvVNGWu2cDY/s1600-h/hacker.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 332px; height: 373px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SeOd9ownJ6I/AAAAAAAAATY/PvVNGWu2cDY/s400/hacker.gif" alt="" id="BLOGGER_PHOTO_ID_5324272866720950178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Here is what hacking books will NEVER tell you:&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Being a hacker requires a HUGE amount of learning - &lt;/span&gt;All hacking books tell you that you need a lot programming knowledge, a lot of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;TCP&lt;/span&gt;/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;IP&lt;/span&gt; knowledge, and some of them will try to cover the basics. So look around you, these guys are usually the 'gurus' at this and that company, and have a much nicer title - usually it's infrastructure architect, chief designer or something along those lines. And these guys became that by working overtime, nighttime, at home, over &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;weekends&lt;/span&gt;, missed vacations and built systems from the ground up. It took a lot of dedication and a whole lot of time to reach that kind of knowledge.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Being a hacker is very rarely (if ever) a glamorous thing&lt;/strong&gt; - Most hacking activities are not legal, therefore the prominent or established hacker has to watch his/hers back, remain undercover and rarely trust anyone. Even if you employ your skills for patriotic or political goals, you'll be a hero somewhere, but an enemy elsewhere. Oh, and noone will ever make a movie of your achievements and exploits!!!&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;There are few people which earn a legal salary as hackers &lt;/span&gt;- hackers are usually hired to do 'dirty' jobs, or at least jobs of questionable legality. So apart from earning money, these jobs leave the hacker always looking over his/her shoulder for investigators or the police. If you are thinking about penetration testing, think again - hackers are not hired outright for such jobs since penetration testing consent requires an enormous amount of trust in the pen-tester. These jobs are mostly landed by 'white-hat' pen-testers with excellent public track record.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;On the other hand, if you maintain your learining and studying to be a hacker, you will build excellent technical expertise. Focusing your skills not as a hacker, but as a technical expert will bring you a good name, a lot of conferences where you'll do presentations and a lot of contacts in the expert field of IT. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;Talkback and comments are most welcome&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Related posts&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.shortinfosec.net/2008/07/portrait-of-attacker-types.html"&gt;Portrait of Hackers&lt;/a&gt;&lt;/p&gt;&lt;a href="http://www.shortinfosec.net/2008/12/hunting-for-hackers-google-fraud-style.html"&gt;Hunting for hackers - Google fraud style&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-4003896145765433310?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/YF0LgjvH7Jo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/YF0LgjvH7Jo/3-things-no-book-about-hacking-will.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Hu1rpxRsqcU/SeOd9ownJ6I/AAAAAAAAATY/PvVNGWu2cDY/s72-c/hacker.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/3-things-no-book-about-hacking-will.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-8938373914080227421</guid><pubDate>Wed, 08 Apr 2009 07:21:00 +0000</pubDate><atom:updated>2009-04-08T10:07:29.108+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information strategy</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Cloud Backup - A gamble on several levels</title><description>Online or cloud backup was one of the buzz words of cloud computing, and was actually leading the wave in terms of commercial implementation. Hewlett-Packard had it's &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Upline&lt;/span&gt;  service, Yahoo had it's Briefcase, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;IBackup&lt;/span&gt; is going strong. But the market for online backup is still quite &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;volitile&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;For instance, HP has decided to shut down &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Upline&lt;/span&gt;, without much explanation to the customers. It went down on March 31, 2009. Oh, by the way, Yahoo closed shop at Briefcase on March 30, just a day earlier!&lt;br /&gt;&lt;br /&gt;In the meantime, the big players are repositioning: &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;EMC&lt;/span&gt; purchased &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Mozy&lt;/span&gt; - an online backup &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;startup&lt;/span&gt;, and is pushing the service strong. And there are still new players on the field - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;COMODO&lt;/span&gt; has just announced their online backup service. And we are hearing that &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;Symantec&lt;/span&gt; is also going into the online backup business!&lt;br /&gt;&lt;br /&gt;With all these events, several questions regarding the entire Online Backup solution surface from the murky deep&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Who uses whose infrastructure?&lt;/span&gt; - the simultaneous closing of two major services (HP &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;Upline&lt;/span&gt; and Yahoo Briefcase) may be a simple coincidence. But, on the other hand, it is a 'cloud' service, thus one service may outsource it's physical storage to another vendor. This leads to all kinds of unanswered questions like&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Who else has access to the backed-up data?&lt;/li&gt;&lt;li&gt;Is the advertised availability actually achievable?&lt;/li&gt;&lt;li&gt;Can we loose the backed-up data if the outsourced provider fails financially?&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Is your online backup actually safe? &lt;/span&gt;- While technical security measures can be implemented and documented, corporate &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_10"&gt;decisions&lt;/span&gt; fall way outside of the scope of the service. And corporate decisions may include layoffs, selling of assets, closing of divisions, even selling of the entire company. And in such conditions, the service provider's employees could care less about some Joe Average's online photo collection or sales reports&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Can you define a long term data retention policy and rely on online backup to meet it?&lt;/span&gt; - HP is a HUGE company. And it failed to deliver a long-running service. One may discuss that HP is primarily a hardware vendor, but nevertheless, as a large company is always interested to present itself as a serious long-term partner. And yet, it closed it's service. So, who can tell what will happen to the other Online Backup service providers?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Which service provider is the right choice for Online Backup?&lt;/span&gt; - Again, HP and Yahoo are large, and closed up shop. Other service providers are all over the place: From start-ups, through venture capital funded firms up to large players who purchased smaller ones. Which one will prove to be the best, and which one will actually deliver on the promise&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;There are no definite answers to these questions. But in a time of economic instability, the services and service providers can find themselves in all kinds of trouble , relying on online back-up without a second option feels a lot like gambling. And gambling on technical, financial and business level.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/3-rules-to-prevent-backup-headaches.html"&gt;3 Rules to Prevent Backup Headaches&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/08/cloud-computing-premature-murder-of.html"&gt;Cloud Computing - Premature murder of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;datacenter&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/11/know-difference-backup-vs-archive.html"&gt;Know the Difference - Backup vs. Archive&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/01/security-concerns-cloud-cloud-computing.html"&gt;Security Concerns Cloud “Cloud Computing”&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-8938373914080227421?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/S_Ze8BChJuo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/S_Ze8BChJuo/cloud-backup-gamble-on-several-levels.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">7</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/cloud-backup-gamble-on-several-levels.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-6290599020261900840</guid><pubDate>Wed, 01 Apr 2009 06:04:00 +0000</pubDate><atom:updated>2009-04-01T08:21:43.996+02:00</atom:updated><title>Shortinfosec is Acquired</title><description>Yesterday, after a month of negotiations, G-M Venture Investment Fund purchased the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Shortinfosec&lt;/span&gt; blog.&lt;br /&gt;&lt;br /&gt;The price of the entire deal is $100,000 US.&lt;br /&gt;&lt;br /&gt;The blog was purchased in it's entirety, with all text copyright going to G-M Venture, and including the physical assets of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Shortinfosec&lt;/span&gt;:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;3 Backtrack DVDs&lt;/li&gt;&lt;li&gt;3 Helix Forensic &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;CDs&lt;/span&gt;&lt;/li&gt;&lt;li&gt;1 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Noname&lt;/span&gt; Pentium 4 Desktop PC&lt;/li&gt;&lt;li&gt;23 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;VmWare&lt;/span&gt; virtual machines with labs&lt;/li&gt;&lt;li&gt;1 250 GB &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Truecrypt&lt;/span&gt; encrypted Hard drive with lost password&lt;/li&gt;&lt;/ul&gt;Under the terms and conditions, the purchase amount will be paid in cash, in Zimbabwean dollars. The previous &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Shortinfosec&lt;/span&gt; owners are eagerly awaiting the tanker load of cash to close the deal.&lt;br /&gt;&lt;br /&gt;According to G-M official, to minimize the risk of being short in the payment due to the inflation of the Zimbabwean dollar, they have sent three tankers of cash. Whatever is left after the transaction will be used as landfill mass in a nearby harbor.&lt;br /&gt;&lt;br /&gt;And ofcourse, Happy April Fools day!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-6290599020261900840?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/1OVRj_n9EVE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/1OVRj_n9EVE/shortinfosec-is-acquired.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">7</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/04/shortinfosec-is-acquired.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-2224068459651296320</guid><pubDate>Sun, 29 Mar 2009 19:44:00 +0000</pubDate><atom:updated>2009-03-29T22:03:09.191+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Databases</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Quick and Basic Security Assessment for Databases</title><description>When preparing a database solution, one must always make sure that the security of the database is up to specification. The first step in proper securing of the database is a security posture assessment.&lt;br /&gt;&lt;br /&gt;While there are a lot of tools that will do this for you, Imperva has a free tool named &lt;a href="http://www.blogger.com/www.imperva.com/products/scuba.html"&gt;Scuba&lt;/a&gt; that will do very basic but very fast database security posture assessment.&lt;br /&gt;&lt;br /&gt;To use Scuba, just download and extract the zip file to a folder. Input the DBMS connection parameters, test the connection and press Go.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sc_RKhYty7I/AAAAAAAAATI/4E9Qu7xO6kQ/s1600-h/Database-Quick-Security-Posture-Assessment.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 266px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sc_RKhYty7I/AAAAAAAAATI/4E9Qu7xO6kQ/s320/Database-Quick-Security-Posture-Assessment.JPG" alt="" id="BLOGGER_PHOTO_ID_5318699663638776754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;After Scuba finishes the assessment, it produces an XML report. To review it in a human readable form, choose the level of detail from the report templates (Summary, Assessment with details, Assessment without details) and generate the HTML.&lt;br /&gt;&lt;br /&gt;Here is a screenshot of the generated assessment report&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Hu1rpxRsqcU/Sc_Rv0XV32I/AAAAAAAAATQ/EPOiwnW3y_w/s1600-h/Database-Quick-Security-Posture-Report.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_Hu1rpxRsqcU/Sc_Rv0XV32I/AAAAAAAAATQ/EPOiwnW3y_w/s320/Database-Quick-Security-Posture-Report.JPG" alt="" id="BLOGGER_PHOTO_ID_5318700304388448098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The level of the report quality is basic, but it will point you in the right direction by sifting through the well known attack methods and vulnerabilities. One must not rely simply on this tool for database security, and should employ other relevant tools.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;User warning&lt;/span&gt;: Since the tool comes with NO DOCUMENTATION, here are several warnings and tips that will ease your usage&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Since Scuba is a Java based tool, it requires JRE to work. Also, in order to connect to MS SQL RDBMS, you must have a Microsoft SQL Server JDBC Driver installed.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The error messages are logged but there is no user friendly message when an error occurs. In order to debug possible problems, look for the 'scuba-error.txt' file and read through the Java exceptions recorded.&lt;/li&gt;&lt;li&gt;The 'scuba-error.txt' file is appended, so the last error in the file is the one that hit you. For easier debugging, delete the scuba-error.txt after each session to limit the errors from the current session only.&lt;/li&gt;&lt;/ol&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/09/thrown-in-fire-database-corruption.html"&gt;Thrown in the Fire - Database Corruption Investigation&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/05/sql-server-bulk-import-bcp-how-to.html"&gt;SQL Server Bulk Import - BCP HOW TO&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/3-rules-to-prevent-backup-headaches.html"&gt;3 Rules to Prevent Backup Headaches&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-2224068459651296320?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/GSKHdMfZjFk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/GSKHdMfZjFk/quick-and-basic-security-assessment-for.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Hu1rpxRsqcU/Sc_RKhYty7I/AAAAAAAAATI/4E9Qu7xO6kQ/s72-c/Database-Quick-Security-Posture-Assessment.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/03/quick-and-basic-security-assessment-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-2524676586332684607</guid><pubDate>Sun, 22 Mar 2009 20:02:00 +0000</pubDate><atom:updated>2009-03-22T21:26:22.435+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Creating BackTrack4 Pentest Virtual Machine</title><description>BackTrack4 is an excellent Penetration Testing Distro, but in the LiveCD version it is quite crippled:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;There is no possibility to install additional software&lt;/li&gt;&lt;li&gt;There is no possibility to create custom scripts&lt;/li&gt;&lt;li&gt;All attacks need to start from scratch&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;In order to alleviate this issue, there are several options. My most flexible solution is to create a VMware virtual machine with the installation. Since BackTrack4 has no installer included, here is a brief tutorial with the scripts included.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Preparation&lt;/span&gt;&lt;br /&gt;Create a Virtual Machine as Custom Linux, and Choose Ubuntu as the assumed Host Operating System&lt;br /&gt;Choose a SCSI Hard Disk of at least 5GB (We recommend 8GB)&lt;br /&gt;Boot the Virtual Machine from the BackTrack DVD&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Creation of Partitions&lt;/span&gt;&lt;br /&gt;After booting, log-on and partition the SCSI Hard Drive (/dev/sda)&lt;br /&gt;Create 2 primary partitions, one for BackTrack, Linux - type 83 with at least 4 GB space, and one Linux Swap - type 82 of 512MB&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote style="font-family: courier new;"&gt;fdisk /dev/sda&lt;br /&gt;&lt;/blockquote&gt;After creating the partition table, format the BackTrack partition&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;mkfs&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;dev&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sda&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;1&lt;/span&gt;&lt;/blockquote&gt;After formatting, mount the partition&lt;br /&gt;&lt;blockquote style="font-family: courier new;"&gt;mkdir /mnt/sda1&lt;br /&gt;mount /dev/sda1 /mnt/sda1/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Copy the BackTrack Data&lt;/span&gt;&lt;br /&gt;Create the copying script in the root's home directory&lt;br /&gt;&lt;blockquote&gt;cd&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;vi create_&lt;/span&gt;bt&lt;span style="font-family:courier new;"&gt;_disk&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;Paste the following text in the VI editor and save it&lt;br /&gt;&lt;blockquote&gt;    &lt;span style="font-family: courier new;font-family:courier new;" &gt;list=`&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;cd&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /;ls -l|&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;awk&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; {'print $8'}`&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    for i in $list&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    do&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    if [ "$i" = '&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;' -o "$i" = '&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;proc&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;' -o "$i" = '&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sys&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;' ];then i='root';&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;fi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    echo $i&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    &lt;/span&gt;&lt;span style="font-family: courier new;"&gt;cp&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; -&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;pR&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /$i /&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sda&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    done&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    &lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mkdir&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sda&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;1/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sys&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    &lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mkdir&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sda&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;1/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;proc&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    &lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mkdir&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt; /&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;sda&lt;/span&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;1/&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;mnt&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-family:courier new;" &gt;    echo 'Done'&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Make the script executable and run it&lt;br /&gt;&lt;blockquote style="font-family: courier new;"&gt;chmod 755 create_bt_disk&lt;br /&gt;./create_bt_disk&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Finishing Touches&lt;/span&gt;&lt;br /&gt;After the script finishes, change the root directory to the disk drive in order to make the disk bootable&lt;br /&gt;&lt;blockquote style="font-family: courier new;"&gt;mount --bind /dev/ /mnt/sda1/dev/&lt;br /&gt;mount -t proc proc /mnt/sda1/proc/&lt;br /&gt;chroot /mnt/sda1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Run LILO to write info to the MBR of /dev/sda. NOTE: The default lilo.conf works with disk /dev/sda and partition /dev/sda1. If you have a different disk configuration, you need to change the /etc/lilo.conf appropriately before running LILO&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family:courier new;"&gt;lilo -v&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;All done. Just reboot and remove the BackTrack DVD&lt;br /&gt;&lt;blockquote style="font-family: courier new;"&gt;reboot&lt;/blockquote&gt;&lt;br /&gt;We hope that this tutorial eases your use of the BackTrack suite.&lt;br /&gt;&lt;br /&gt;Talkback and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/02/backtrack-4-penetration-test-distro.html"&gt;BackTrack 4 Penetration Test Distro - First Glance&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-2524676586332684607?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/pZHJdfiRuQs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/pZHJdfiRuQs/creating-backtrack4-vmware-virtual.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/03/creating-backtrack4-vmware-virtual.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-3489162549452283927</guid><pubDate>Fri, 20 Mar 2009 19:38:00 +0000</pubDate><atom:updated>2009-03-20T20:44:48.387+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">Incident Management</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>BlogTipz hack - The BlogTipz editor response</title><description>We received the reply from the editor of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;BlogTipz&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;From the info, it seems that the hack on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;BlogTipz&lt;/span&gt; is merely a target of opportunity.&lt;br /&gt;&lt;br /&gt;The hack method is probably not related to error of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;WordPress&lt;/span&gt;, but the editor of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;BlogTipz&lt;/span&gt; does not reveal the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;actual&lt;/span&gt; attack method.&lt;br /&gt;&lt;br /&gt;At any rate, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;blog masters&lt;/span&gt; everywhere need to maintain blog security high on their list of priorities&lt;br /&gt;&lt;br /&gt;Here is the reply in full&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Yes, I was going to possibly write a post on the blog, because I was not aware of it (it could have been up for 12+ hours). They simply changed the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;login&lt;/span&gt; name and password and injected in a new index (main) page, so it was rather simple to recover (within an hour).&lt;br /&gt;&lt;br /&gt;I will be securing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;WordPress&lt;/span&gt; even more form this day forward to prevent it form happening on other sites. I was using a current version of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;WordPress&lt;/span&gt;. The attacker was called "North-Africa Security Team" and appears to be one of the most popular hackers in terms of results (~14 million).&lt;br /&gt;&lt;br /&gt;If you need any further information, please inform me. I will be informing readers about this soon.&lt;br /&gt;&lt;br /&gt;And, thanks for informing your readers about this.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2009/03/blogtipz-hacked.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;Blogtipz&lt;/span&gt; Hacked&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-3489162549452283927?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/WSvVOZTIpPI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/WSvVOZTIpPI/blogtipz-hack-blogtipz-editor-response.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/03/blogtipz-hack-blogtipz-editor-response.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-7196788127833928948.post-7596955793807729037</guid><pubDate>Wed, 18 Mar 2009 19:36:00 +0000</pubDate><atom:updated>2009-03-18T20:55:59.836+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">penetration testing</category><category domain="http://www.blogger.com/atom/ns#">Incident Management</category><category domain="http://www.blogger.com/atom/ns#">information security</category><title>Blogtipz Hacked</title><description>Today, &lt;a href="http://blogtipz.com/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;blogtipz&lt;/span&gt;.com&lt;/a&gt; - a good &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;internet&lt;/span&gt; blogging site got hacked.  The attack is a simple defacement attack, and the signed culprits are Dr.0&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;rYX&lt;/span&gt;|Cr3W-Dz.&lt;br /&gt;&lt;br /&gt;Here is a screenshot of the hacked version of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;blogtipz&lt;/span&gt;.com site&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/ScFN9wgomoI/AAAAAAAAASg/JIoRDeN8J2s/s1600-h/Blog+Tipz+Hacked.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 242px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/ScFN9wgomoI/AAAAAAAAASg/JIoRDeN8J2s/s400/Blog+Tipz+Hacked.JPG" alt="" id="BLOGGER_PHOTO_ID_5314614758663035522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;With the little information available, the most probable attack vector is a vulnerability in the implemented version of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;Wordpress&lt;/span&gt;. We are including two screenshots of the original (google cached and after the defacement was fixed)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Hu1rpxRsqcU/ScFOowQ-6GI/AAAAAAAAASo/Snv_y1dSfzU/s1600-h/Blog+Tipz+Original.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 121px;" src="http://1.bp.blogspot.com/_Hu1rpxRsqcU/ScFOowQ-6GI/AAAAAAAAASo/Snv_y1dSfzU/s200/Blog+Tipz+Original.JPG" alt="" id="BLOGGER_PHOTO_ID_5314615497331763298" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Hu1rpxRsqcU/ScFPt8M48hI/AAAAAAAAAS4/2b9PMDVFh44/s1600-h/Blog+Tipz+Removed+Hack.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 121px;" src="http://3.bp.blogspot.com/_Hu1rpxRsqcU/ScFPt8M48hI/AAAAAAAAAS4/2b9PMDVFh44/s200/Blog+Tipz+Removed+Hack.JPG" alt="" id="BLOGGER_PHOTO_ID_5314616685946794514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;We have submitted the following questions to the editor of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Blogtipz&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;1. Did you get threatened by the hacker teams that hacked the page?&lt;br /&gt;2. How much time did it take for you to recover from the hack?&lt;br /&gt;3. Did you discover the attack vector, and would you share it?&lt;br /&gt;4. Is your &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Wordpress&lt;/span&gt; now patched against such attacks?&lt;br /&gt;5. Any message on your side for the readership?&lt;/blockquote&gt;&lt;br /&gt;As soon as response is back, we'll post the response.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7196788127833928948-7596955793807729037?l=www.shortinfosec.net'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/shortinfosec/~4/pab-_gudDCo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/shortinfosec/~3/pab-_gudDCo/blogtipz-hacked.html</link><author>noreply@blogger.com (Bozidar Spirovski)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Hu1rpxRsqcU/ScFN9wgomoI/AAAAAAAAASg/JIoRDeN8J2s/s72-c/Blog+Tipz+Hacked.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.shortinfosec.net/2009/03/blogtipz-hacked.html</feedburner:origLink></item></channel></rss>
