<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>IT a digital life</title>
	
	<link>http://www.digitallachance.com/blog</link>
	<description>Thoughts and notes mostly about computer related stuff</description>
	<lastBuildDate>Sun, 23 May 2010 23:18:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/ItADigitalLife" /><feedburner:info uri="itadigitallife" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>ItADigitalLife</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Virus definition update on the F-Secure rescue CD</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/rnwmR5BF2uI/</link>
		<comments>http://www.digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/#comments</comments>
		<pubDate>Sun, 23 May 2010 23:18:54 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[How-to]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software & Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=130</guid>
		<description><![CDATA[So, a co-worker from the office asked me to clean their personal laptop from one of those anti-virus application that install themselves and creates a bunch of pop-ups telling you you are infected.  Obviously, I didn't want to connect that machine to our corporate LAN, so I figured I should use a rescue CD of some sort that does AV scans.  I was highly recommended to use F-Protect's rescue CD for this type of malware in my SANS 504 course that I just took last week.]]></description>
			<content:encoded><![CDATA[<p>So, a co-worker from the office asked me to clean their personal laptop from one of those anti-virus application that install themselves and creates a bunch of pop-ups telling you you are infected.  Obviously, I didn&#8217;t want to connect that machine to our corporate LAN, so I figured I should use a rescue CD of some sort that does AV scans.  I was highly recommended to use F-Protect&#8217;s rescue CD for this type of malware in my SANS 504 course that I just took last week.</p>
<p>A quick Google search returned a very useful page from techmixer.com titled <a href="http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/" target="_blank">FREE Bootable AntiVirus Rescue CDs Download List</a>.  This page lists seven freely available Antivirus rescue CD options.  So I downloaded the ISO for F-Protect and burned it to a CD.  Obviously, you want to make sure you are scanning with the latest virus definition update, but since the CD is a read-only media, you can&#8217;t update the virus definition on it.  The ISO contains a virus definition file from July 2009, but that&#8217;s way to old to be useful.  I tried to follow the instructions that were on the techmixer.com page about F-Protect to use the updates on a USB stick, but without success.  When all else fails, read the instructions.  <img src='http://www.digitallachance.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I downloaded the PDF manual from <a href="http://www.f-secure.com/linux-weblog/files/rescue_cd_user_guide.20090717.pdf" target="_blank">http://www.f-secure.com/linux-weblog/files/rescue_cd_user_guide.20090717.pdf</a> and those instructions, unlike the ones on the techmixer.com ones, instructed to create a fsecure\rescuecd folder on your USB stick.  That way, the virus definition gets expanded to the rescuecd folder as well as the results of the scan is saved in a reports folder.  The trick is to use a USB drive that has nothing else on it.  Why they had to do it that way, I&#8217;m not sure.  I wished that it wasn&#8217;t so because I would rather carry only one stick instead of dedicating one to having the F-Secure virus definition file.</p>
<p>For those of you who prefer bullets and get &#8216;er done, here is a step-by-step how-to:</p>
<ol>
<li>Download the ISO  from the F-Secure web site.  As of this writing, version 3.11 is current.</li>
<li>Burn the ISO to a CD.</li>
<li>Have a FAT formated USB thumb drive with nothing on it.</li>
<li>Create a fsecure folder at the root of the drive.</li>
<li>Create a rescuecd folder in the fsecure folder.</li>
<li>Download the latest virus definition file from F-Secure from <a href="http://download.f-secure.com/latest/fsdbupdate9.run" target="_blank">http://download.f-secure.com/latest/fsdbupdate9.run</a></li>
<li>Copy the fsdbupdate9.run to the root of your USB drive.</li>
<li>Plug-in the USB drive on the sick computer and then boot the rescue CD.</li>
</ol>
<p>F-Secure picked-up that I had a USB drive connected and used the virus definition for the scan.  Simply follow the on-screen instructions and your computer will be cleaned up.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/sLV10sLJFewtsaXoe9jDUiwSXSw/0/da"><img src="http://feedads.g.doubleclick.net/~a/sLV10sLJFewtsaXoe9jDUiwSXSw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/sLV10sLJFewtsaXoe9jDUiwSXSw/1/da"><img src="http://feedads.g.doubleclick.net/~a/sLV10sLJFewtsaXoe9jDUiwSXSw/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=rnwmR5BF2uI:D0MdB20yO4o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=rnwmR5BF2uI:D0MdB20yO4o:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=rnwmR5BF2uI:D0MdB20yO4o:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=rnwmR5BF2uI:D0MdB20yO4o:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=rnwmR5BF2uI:D0MdB20yO4o:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=rnwmR5BF2uI:D0MdB20yO4o:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/</feedburner:origLink></item>
		<item>
		<title>VLC media player auto-update and vulnerability</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/QgnEHtG7B8w/</link>
		<comments>http://www.digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 04:56:12 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=124</guid>
		<description><![CDATA[Secunia has published an advisory about new vulnerabilities found in VLC Media Player.]]></description>
			<content:encoded><![CDATA[<p>I just picked up an <a href="http://secunia.com/advisories/39558" target="_blank">advisory</a> from Secunia about VLC Media Player vulnerabilities. There are 9 vulnerabilities. Three are related to A/52, DTS and MPEG audio decoders. Three are about the AVI, ASF and Matroska demuxer. The other three are about the XSPF playlist, the ZIP and RTPM implementation.</p>
<p>Successful exploitation of the vulnerabilities may allow execution of arbitrary code, but requires that the user is tricked into opening a specially crafted file.</p>
<p>There is no CVE Reference and unfortunately cannot figure out a <a href="http://www.networkworld.com/community/node/21105" target="_blank">CVSS</a> score.  You can find the original advisory (VideoLAN-SA-1003) here:<br />
<a href="http://www.videolan.org/security/sa1003.html" target="_blank">http://www.videolan.org/security/sa1003.html</a></p>
<p>There are two interesting things about this one.  One, as of right now (April 25, 2010 at 22:39 GMT-6), the fixed version for Windows (1.0.6) is still not available on the Video LAN web site.  That&#8217;s a bit unusual because, typically, the vendor likes to make sure the patch/updated version of the vulnerable software is available before publishing the vulnerability on their on web site.  The second thing that&#8217;s interesting is that the auto-update does not seem to work in my installed version (1.0.1).</p>
<p>I thought that maybe I had a problem in my home LAN that caused the auto-update to fail.  I fired up Wireshark and did a quick sniff of the traffic when trying to get VLC to update.  I used the <em>Follow TCP Stream</em> feature and it was quickly apparent that the problem wasn&#8217;t with me at all.  The GET that VLC sent got a <em>206 Partial Content</em></p>
<blockquote><p>HTTP/1.1 206 Partial Content<br />
Content-Type: text/plain<br />
Accept-Ranges: bytes<br />
ETag: &#8220;3280753111&#8243;<br />
Last-Modified: Mon, 01 Feb 2010 23:15:18 GMT<br />
Content-Range: bytes 0-485/486<br />
Content-Length: 486<br />
Date: Mon, 26 Apr 2010 04:24:08 GMT<br />
Server: lighttpd/1.4.19</p>
<p>1.0.5</p>
<p>http://www.videolan.org/mirror-geo-redirect.php?file=vlc/1.0.5/win32/vlc-1.0.5-win32.exe</p>
<p>Due to a bug in the update feature of your on of VLC, the automatic download of the new VLC will fail.</p>
<p>You have to download VLC 1.0.5 from VideoLAN&#8217;s website: http://www.videolan.org</p>
<p>VLC 1.0.5 is a minor release of 1.0.x version of VLC. It fixes a few bugs, updates the codecs and the compiler for Windows, and should improve decoding speed. It also improves and update many translations.</p></blockquote>
<p>Well, might as well download 1.0.5 for now and use the auto-update to check the 1.0.6 fix.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/W6QDuWiCagYc5yRJN9XFpobiXF8/0/da"><img src="http://feedads.g.doubleclick.net/~a/W6QDuWiCagYc5yRJN9XFpobiXF8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/W6QDuWiCagYc5yRJN9XFpobiXF8/1/da"><img src="http://feedads.g.doubleclick.net/~a/W6QDuWiCagYc5yRJN9XFpobiXF8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=QgnEHtG7B8w:Bj2J4FUeGyw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=QgnEHtG7B8w:Bj2J4FUeGyw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=QgnEHtG7B8w:Bj2J4FUeGyw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=QgnEHtG7B8w:Bj2J4FUeGyw:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=QgnEHtG7B8w:Bj2J4FUeGyw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=QgnEHtG7B8w:Bj2J4FUeGyw:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/</feedburner:origLink></item>
		<item>
		<title>BackTrack 4 Final Released</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/qATKUvee5NE/</link>
		<comments>http://www.digitallachance.com/blog/2010/01/backtrack-4-final-released/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 02:29:29 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software & Tools]]></category>
		<category><![CDATA[BackTrack 4]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=119</guid>
		<description><![CDATA[I'm back to blogging!  BackTrack 4, the latest version of the most popular all-in-one Linux based penetration testing suite is now out.]]></description>
			<content:encoded><![CDATA[<p>Sorry for being away for so long (almost a year since the last post).  I have been making sure that this server and WordPress is always up to date even though I was not actively posting.  I&#8217;d hate for a blog about IT security to be compromised, especially if I&#8217;m the one managing it.</p>
<p><a href="http://www.digitallachance.com/blog/wp-content/uploads/2010/01/dragonHead.png"><img class="alignleft size-full wp-image-121" style="margin: 3px 6px;" title="dragonHead" src="http://www.digitallachance.com/blog/wp-content/uploads/2010/01/dragonHead.png" alt="BackTrack dragon head" width="150" height="150" /></a>In any case, it would appear that BackTrack 4 is out of Beta and is available for all to download!  I&#8217;m downloading it as I am typing this and will be burning it to a DVD to play with it.  You can download it from <a title="TrackBack download page" href="http://www.backtrack-linux.org/downloads/" target="_blank">http://www.backtrack-linux.org/downloads/</a>.  BackTrack is a great collection of software and tools in a bootable DVD or in a VM.  As described on the <a href="http://www.backtrack-linux.org/" target="_blank">BackTrack home page</a>:</p>
<blockquote><p>BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking.</p></blockquote>
<p>Even if penetration testing is not your thing, this is an easy way to get some of the most popular security tools into your hands without having to search and download from all over the Internet.</p>
<p>Enjoy!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/WuuCunUoRckgJHEcCU17hotKFK8/0/da"><img src="http://feedads.g.doubleclick.net/~a/WuuCunUoRckgJHEcCU17hotKFK8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/WuuCunUoRckgJHEcCU17hotKFK8/1/da"><img src="http://feedads.g.doubleclick.net/~a/WuuCunUoRckgJHEcCU17hotKFK8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=qATKUvee5NE:totgsvoaYig:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=qATKUvee5NE:totgsvoaYig:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=qATKUvee5NE:totgsvoaYig:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=qATKUvee5NE:totgsvoaYig:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=qATKUvee5NE:totgsvoaYig:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=qATKUvee5NE:totgsvoaYig:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2010/01/backtrack-4-final-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2010/01/backtrack-4-final-released/</feedburner:origLink></item>
		<item>
		<title>Adobe Reader is vulnerable yet again</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/4pAKU63c3LU/</link>
		<comments>http://www.digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/#comments</comments>
		<pubDate>Fri, 01 May 2009 05:08:18 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=111</guid>
		<description><![CDATA[I figured it would happen eventually, but not quite so soon. It appears that Adobe Reader is suffering from at least two more zero-day vulnerabilities.  Here's the low-down.]]></description>
			<content:encoded><![CDATA[<p>I figured it would happen eventually, but not quite so soon.  It appears that Adobe Reader is suffering from at least two more zero-day vulnerabilities &#8211; less than two months after the JBIG2 vulnerability.  Here&#8217;s the low-down.</p>
<p style="text-align: left;">All currently supported shipping versions of Adobe Reader and Acrobat (9.1, 8.1.4, and 7.1.1 and<br />
earlier versions) are vulnerable to this issue. Adobe plans to provide updates for all affected versions<br />
for all platforms (Windows, Macintosh and UNIX) to resolve this issue.  The vulnerabilities are in the JavaScript engine of the Adobe products.  This, by the way, affects both Adobe Reader and Adobe Acrobat.  T<span class="rss:item">he vulnerabilities exist in two JavaScript functions; <strong>getAnnots()</strong> and <strong>spell.customDictionaryOpen()</strong> and both allow remote code execution.  One way to protect yourself is to disable JavaScript &#8211; see the simple instructions from <a href="http://www.f-secure.com/weblog/archives/00001671.html" target="_blank">F-Secure</a>.<br />
</span></p>
<p>Many people made this recommendation when the last vulnerability was uncovered (<a title="See my previous post on this topic." href="http://www.digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/" target="_self">jbig2 vulnerability</a>), but it just seems to be louder this time; find an alternative reader to the Adobe Reader product.  If you need an idea for what is available out there, take a look at <a href="http://pdfreaders.org/" target="_blank">PDFreaders.org</a>.  I know that I have made the recommendation where I work, but it might not be that easy.  Corporations sometimes will rely heavyly on Adobe Reader to view custom business forms that are used on a daily basis with customers.  That reliance will often show itself in the in-house applications that make calls directly to the Adobe DLL.</p>
<p>You can read a bit more about the challenges of replacing Adobe Reader and Acrobat <a href="http://blogs.techrepublic.com.com/security/?p=1470" target="_blank">here</a>.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/iH30S9ExBxIT9XU3nl-LDER2-1c/0/da"><img src="http://feedads.g.doubleclick.net/~a/iH30S9ExBxIT9XU3nl-LDER2-1c/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/iH30S9ExBxIT9XU3nl-LDER2-1c/1/da"><img src="http://feedads.g.doubleclick.net/~a/iH30S9ExBxIT9XU3nl-LDER2-1c/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=4pAKU63c3LU:-GNfXDuJ9DY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=4pAKU63c3LU:-GNfXDuJ9DY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=4pAKU63c3LU:-GNfXDuJ9DY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=4pAKU63c3LU:-GNfXDuJ9DY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=4pAKU63c3LU:-GNfXDuJ9DY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=4pAKU63c3LU:-GNfXDuJ9DY:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/</feedburner:origLink></item>
		<item>
		<title>The importance of password audits</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/0jCUGb6yC0U/</link>
		<comments>http://www.digitallachance.com/blog/2009/03/the-importance-of-password-audits/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 07:31:27 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Strategies]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Two-Factor authentication]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=104</guid>
		<description><![CDATA[Have you ever tried to crack your network user's passwords?  Why would you do that you ask?  Simple, compliance check is one reason.  The other is to better understand what is possible and what kind of password your users are using.  In this post, I'll discuss why it is a very good idea to do periodic password audits in your network.]]></description>
			<content:encoded><![CDATA[<p>Have you ever tried to crack your network user&#8217;s passwords?  Why would you do that you ask?  Simple, compliance check is one reason.  The other is to better understand what is possible and what kind of password your users are using.  In this post, I&#8217;ll discuss why it is a very good idea to do periodic password audits in your network.</p>
<p>You might might think that the idea of running a password cracking program on your network users is a waste of time.  In fact, you have to remember that if the bad guys are most likely to use that type of tool, you should use it first.  That way you will know what a black hat will be able to get out our your password database.  Here are a few reasons why you should do regular password audits.</p>
<p>You should not have the false comfort that your network is safe just because you have turned on <a href="http://technet.microsoft.com/en-us/library/cc875814.aspx" target="_blank">complex password group policy in active directory</a>.  The rules of complex password in active directory are as follow:</p>
<ul>
<li>The password is at least six characters long.</li>
<li>The password contains characters from at least three of the following five categories:
<ul>
<li>English uppercase characters (A &#8211; Z)</li>
<li>English lowercase characters (a &#8211; z)</li>
<li>Base 10 digits (0 &#8211; 9)</li>
<li>Non-alphanumeric (For example: !, $, #, or %)</li>
<li>Unicode characters</li>
</ul>
</li>
<li>The password does not contain three or more characters from the user&#8217;s account name.</li>
</ul>
<p>Using those rules, that means that the password <strong>Password1</strong> is actually a valid password.  How good of a password is that?  This a valid password because active directory does not actually do a password complexity check.  What it does is more accurately described as a password constraint check.  The idea of complex passwords is that it should force users to not use dictionary words as their passwords.  Since it is not practical to have a full dictionary in Active Directory to make sure that passwords are not in the dictionary, the designers simply impose constraints on what your password should be like.  Hence, the complex password group policy constraints as described above.</p>
<p>Another aspect of passwords is that people will tend to re-use the same password everywhere they can.  What this means is that the password is only as strong as the weakest link.  Namely, if you use the same password on a web site that is easily compromised, the black hat will try the newly discovered password on your bank account as well, knowing full well that it is likely going to be the same password.</p>
<p>If you are not willing, or allowed to do a password audit on your network, you really should take a look a studies that were done on passwords that have been revealed because of security breaches.  There has been two recent incidents that are worthy of reading.  One is an article on Dark Reading (<a href="http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html" target="_blank">http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html</a>) about the phpbb.com web site hack.  The other one is from Bruce Schneier who did an analysis on passwords that were published by people behind a fake MySpace web page used in a phishing campain.</p>
<p>Whenever possible, you should use some kind of two-factor authentication, such as smart cards or an RSA token.</p>
<p>One of the best known password cracking software is L0pthCrack, which used to be owned by Symantec.  L0pthCrack has recently been <a href="http://searchsecurity.techtarget.com/video/0,297151,sid14_gci1350713,00.html?track=sy160" target="_blank">re-acquired</a> by its original authors.  They intend to update the venerable software and start selling it again.  There is other software that can be purchased (and some free) that can help you audit your user&#8217;s password.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Jq6TzUDSzYp9Yf51bzkTC14wYpU/0/da"><img src="http://feedads.g.doubleclick.net/~a/Jq6TzUDSzYp9Yf51bzkTC14wYpU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Jq6TzUDSzYp9Yf51bzkTC14wYpU/1/da"><img src="http://feedads.g.doubleclick.net/~a/Jq6TzUDSzYp9Yf51bzkTC14wYpU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=0jCUGb6yC0U:pOykFy6V7UI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=0jCUGb6yC0U:pOykFy6V7UI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=0jCUGb6yC0U:pOykFy6V7UI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=0jCUGb6yC0U:pOykFy6V7UI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=0jCUGb6yC0U:pOykFy6V7UI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=0jCUGb6yC0U:pOykFy6V7UI:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/03/the-importance-of-password-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/03/the-importance-of-password-audits/</feedburner:origLink></item>
		<item>
		<title>Critical Adobe Reader update – Upgrade NOW!</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/Fg2xAcwkUhY/</link>
		<comments>http://www.digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 16:17:19 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=100</guid>
		<description><![CDATA[If you do nothing else today, make sure you at least upgrade your users to the latest version of Adobe Reader. The vulnerability was announced back on February 20th, but now Adobe released an update to their Reader product.  You can see the bulletin here: http://www.adobe.com/support/security/bulletins/apsb09-03.html There are a few interesting things to note.  As [...]]]></description>
			<content:encoded><![CDATA[<p>If you do nothing else today, make sure you at least upgrade your users to the latest version of Adobe Reader.</p>
<p>The vulnerability <a href="http://www.infoworld.com/article/09/02/20/Adobe_flaw_heightens_risk_of_encountering_malicious_PDFs_1.html" target="_blank">was announced</a> back on February 20th, but now Adobe released an update to their Reader product.  You can see the bulletin here:</p>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb09-03.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb09-03.html</a></p>
<p>There are a few interesting things to note.  As indicated in a <a href="http://blogs.zdnet.com/security/wp-trackback.php?p=2856" target="_blank">post by Ryan Naraine</a> on ZDNet, the updates are for Adobe Reader 9 only.  The most frustrating thing right now is that in their infinite wisdom, Adobe did not provide a patch update for Adobe Reader (a file with the MSP extension) which can be applied to your existing installation of Adobe Reader.  Instead, they simply point to their standard URL to download Adobe Reader.</p>
<p>Acrobat 9 Standard, Acrobat 9 Pro and Acrobat 9 Extended for Windows are all available as MSP patches.</p>
<p>Don&#8217;t wait, upgrade your users as soon as you can because this is a nasty one.  Users who download a malicious PDF <a href="http://blog.didierstevens.com/2009/03/09/quickpost-jbig2decode-look-mommy-no-hands/trackback/" target="_blank">do not need to open it</a> to fall victim to that flaw.</p>
<p>Hopefully, Adobe will release a patch file for Adobe Reader soon.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Ur4RxWonNKG7r5-rxxCvuAt_O-Q/0/da"><img src="http://feedads.g.doubleclick.net/~a/Ur4RxWonNKG7r5-rxxCvuAt_O-Q/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Ur4RxWonNKG7r5-rxxCvuAt_O-Q/1/da"><img src="http://feedads.g.doubleclick.net/~a/Ur4RxWonNKG7r5-rxxCvuAt_O-Q/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=Fg2xAcwkUhY:L6LNNm6Tmv8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=Fg2xAcwkUhY:L6LNNm6Tmv8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=Fg2xAcwkUhY:L6LNNm6Tmv8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=Fg2xAcwkUhY:L6LNNm6Tmv8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=Fg2xAcwkUhY:L6LNNm6Tmv8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=Fg2xAcwkUhY:L6LNNm6Tmv8:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/</feedburner:origLink></item>
		<item>
		<title>Perimeter defense is useless!</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/iOx6pq79IuA/</link>
		<comments>http://www.digitallachance.com/blog/2009/03/perimeter-defense-is-useless/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 23:50:45 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Strategies]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[HIDS]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=94</guid>
		<description><![CDATA[I think it is well known by security experts that the old perimeter defense model just does not work any more. A firewall does give some protection, but users are constantly asking that ports be opened so that they can access services outside of the corporate network.  Not only that, but there is not much to prevent malicious traffic to go through your ports that are already opened.  Should we ditch the firewall?  No, but you should add more layers to your defense.  In this post, I will list of the defenses you should have in your environment.]]></description>
			<content:encoded><![CDATA[<p>I think it is well known by security experts that the old perimeter defense model just does not work any more.  A firewall does give some protection, but users are constantly asking that ports be opened so that they can access services outside of the corporate network.  Not only that, but there is not much to prevent malicious traffic to go through your ports that are already opened.  Should we ditch the firewall?  No, but you should add more layers to your defense.  In this post, I will list of the defenses you should have in your environment.</p>
<p>Whenever such a user requests to have yet another port to be opened, you should make sure that you restrict as much as possible the end-points that can make use of that port you are opening up.  For example, John asks that a port be opened so he can establish a VNP connection from the corporate LAN to a business partner, you should make sure that only John&#8217;s IP address is allowed to use that port and that there is only one outside IP address that John can reach on that port.</p>
<p>Firewall management is not what keeps me up at night though.  What keeps my up at night is the fact that it is so easy to create tunnels from inside my network to the outside over well known ports, such as port 80 or 443 in order to access anything that you would normally block at the firewall.  That plus the fact that now you cannot browse most web sites with first installing such things as Flash player and Adobe PDF reader.</p>
<p>A recently <a href="http://www.infoworld.com/article/09/02/20/Adobe_flaw_heightens_risk_of_encountering_malicious_PDFs_1.html" target="_blank">vulnerability in Adobe Reader</a> for which there is no patch as of now (Adobe said they will release one on March 11th) is a rather scary one.  This type of vulnerability can be exploited <a href="http://blog.didierstevens.com/2009/03/04/quickpost-jbig2decode-trigger-trio/" target="_blank">without the user even opening the malicious PDF!</a> How can you defend yourself against that?!  You should have as many layers as possible in order to prevent that malicious PDF from succesfully penetrate your network.  The <a href="http://securityblog.verizonbusiness.com/2009/03/05/pdf-security-through-minority/" target="_blank">Verison Business Security Blog</a> has a very good list of steps that can be taken to protect yourself against that threat.  of course, you could always <a title="eWeek - It May Be Time to Abandon Adobe" href="http://www.eweek.com/c/a/Security/It-May-Be-Time-to-Abandon-Adobe/" target="_blank">drop Abode Reader</a> altogether.</p>
<p>In general though, that approach can be applied against any threats.  Here are the different layers you should have in place in order of priority:</p>
<ol>
<li>A firewall.  I would venture to guess that everyone out there has that one in place.  Make sure that a regular review of what rules you have in place is done.</li>
<li>Intrusion Detection (IDS) or better yet, Intrusion Prevention (IPS).  If you can affort it, TippingPoint is probably a leader in that field and works great.  At the very least, you should have Snort in your network.</li>
<li>Don&#8217;t allow your users to be local administrators.  Most of the people that get infected with malware  and virus are logged on with local administrator rights.  That&#8217;s a very bad idea.  Lock down those users!</li>
<li>Anti-Virus on every machines.  AV is not perfect as it is a reactive technology, but it will catch a lot of what is out there.  Anti-Virus products now can do more than just detecting and cleaning virus.  The can block use of certain ports on your hosts (such as port 25 for e-mails or ports typically used for IRC).</li>
<li><a href="http://en.wikipedia.org/wiki/Host_based_intrusion_detection_system" target="_blank">Host-based Intrusion Detection System (HIDS)</a>.  This technology is starting to catch on in corporate environments.  This is basically the equivalent of having <a href="http://en.wikipedia.org/wiki/Zonealarm" target="_blank">ZoneAlarm</a> on each desktop, but centrally managed by the corporate IT.</li>
<li>Last but not least, patching!  Make sure that you are current in your OS patches and your application patches.  That is not always easy in corporate environment since it sometimes requires careful testing and planning.</li>
</ol>
<p>In my experience, the mobile users are the weak links.  Once they take their laptops outside of the corporate LAN, many of those defensive layers, such as IPS and the firewall, are no longer there to protect them.  That&#8217;s why you need to have strong defenses on the workstations, such as disk encryption and HIDS.</p>
<p>Can anyone think of other layers that should be in place?</p>

<p><a href="http://feedads.g.doubleclick.net/~a/IGkk9O6a7geRDSORW6WoQKhfkQQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/IGkk9O6a7geRDSORW6WoQKhfkQQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/IGkk9O6a7geRDSORW6WoQKhfkQQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/IGkk9O6a7geRDSORW6WoQKhfkQQ/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=iOx6pq79IuA:jM9rtHMo1vY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=iOx6pq79IuA:jM9rtHMo1vY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=iOx6pq79IuA:jM9rtHMo1vY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=iOx6pq79IuA:jM9rtHMo1vY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/ItADigitalLife?a=iOx6pq79IuA:jM9rtHMo1vY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/ItADigitalLife?i=iOx6pq79IuA:jM9rtHMo1vY:V_sGLiPBpWU" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/03/perimeter-defense-is-useless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/03/perimeter-defense-is-useless/</feedburner:origLink></item>
		<item>
		<title>Disection of a web based infection</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/ihk41-wpI_o/</link>
		<comments>http://www.digitallachance.com/blog/2009/02/disection-of-a-web-based-infection/#comments</comments>
		<pubDate>Sat, 21 Feb 2009 18:27:42 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[compromises]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[secunia]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=81</guid>
		<description><![CDATA[This post describes how compromised web sites try to infect your pc.]]></description>
			<content:encoded><![CDATA[<p>Gone are the days where you actually had to convince someone to open your malicious e-mail attachment to get malicious software installed.  Now all you need is to browse a compromised web site and you can become a victim in a matter of seconds.  This post will dissect the home page of such a web site and explain the different ways that bad guys are trying to install their malicious software onto your computer.</p>
<p>I was alerted to this compromised web site when our anti-virus console sent me an e-mail because it blocked a trojan on a user&#8217;s machine.  This e-mail also included the URL of the compromised web site.  The trojan is known as <a href="http://vil.nai.com/vil/content/v_144426.htm">JS/Obfuscated</a> by McAfee or JS.Obfuscated.Gen by Bit Defender.  The anti-virus actually is able to detect the way the code on the web page has been obfuscated by the author.  This web page only got a <a title="See the details of the analysis done on the home page of the infected web site" href="http://www.virustotal.com/analisis/6abed0eeeb0a3c1744e9502b5e3c5fe2" target="_blank">12.83% coverage</a> amongst 39 different AV engines according to Virus Total.  I can only hope that the AV that did not catch that compromised web page will catch whatever the web page will download on the user&#8217;s computer before it causes real damage.</p>
<p>You would think that it would be easy to convince the owner of the web site to take action.  Unfortunately, it is not so.  I phoned them personally on Wednesday, Feb. 11.  I actually got a call back on Tuesday, Feb. 17.  I gave the details to the web master.  As of right now (Feb. 21), the site is still has the malicious JavaScript on its home page.  The site is at www dot airdrietrailer dot com and you should <strong>not </strong>browse it with Internet Explorer on Windows.  You are likely to get infected (especially if you do not keep up with patches).  I took a closer look at the malicious code and it tries to infect you through multiple attack vector, but those are specifically targeting IE.  The nice lady at Airdri Trailer Sales told me that she had already received calls from other people also telling her that their web site is infecting people, but their webmaster could not find what the problem was.</p>
<p>Here is a quick summary of how the infection works:</p>
<ol>
<li>The web site is somehow compromised and web page(s) modified to inject iFrame into each page on the site.</li>
<li>A user browse the web site, the injected JavaScript code is executed, creating the iFrame which connect to a malicious site to download more code.</li>
<li>The downloaded code is executed and tries multiple attack vectors in order to write to your hard drive.  If one of those vulnerabilities work, a payload is downloaded and executed on your computer.</li>
</ol>
<p>And voila!  You have been p0wned.</p>
<h1>Dissecting the attack</h1>
<p>The malicious code is tacked at the bottom of the web page. The code is in two &lt;script&gt;&lt;/script&gt; blocks.  It is obfuscated by having a bunch of gibberish assigned to variables.  There is actually a bit of code visible in that gibberish, just enough to remove the obfuscation, which is rather simple.  Using the <a href="http://malzilla.sourceforge.net/" target="_blank">Malzilla</a> tool, it makes it easy to see the code.  The first block reveals how it will de-obfuscate the code.  There are four block of codes that will be de-obfuscated by doing a string substition.  Here are some of the string that are replaced.</p>
<ol>
<li>Replace <em>aHM</em> with a % character</li>
<li>Replace <em>Zm</em> with the <em>D</em> character</li>
<li>Replace <em>ouG</em> with a <em>%</em> character</li>
<li>Replace <em>tr4</em> with a <em>3</em> character</li>
<li>Replace <em>%P5</em> with a <em>2</em> character</li>
<li>there are more such substitions</li>
</ol>
<p>All of those strings are then unescaped, and passed to the eval() function to be executed.  That&#8217;s where the real action is.</p>
<ol>
<li>The first block inserts a &lt;BODY&gt; &lt;/BODY&gt; and a &lt;DIV&gt; tag into the web page if it finds that the body is empty.</li>
<li>The second block gets a pointer to that DIV and saves it to a variable.  As well, it creates an iFrame element and sets it to a size of 1&#215;1 and sets the source to point to a malicious web site (store16 dot looneytoons dot cc).  Doing a whois on <a href="http://www.whois.net/whois_new.cgi?d=looneytunes&amp;tld=cc" target="_blank">that site</a> reveals that it is a legitimate site registered by Warner Brothers.  Although there is a web server there, it does not return anything as of right now.</li>
<li>Finally, the third block set the iFrame to hidden, gives it an id and appends it to the DIV created in the first block of code.</li>
</ol>
<p>Since the iframe src attribute is pointing to malicious site, it populates itself with new HTML wich includes more JavaScript.  At that point, the code tries a few number of things in order to gain access to the operating system to enable to write files to your hard drive.  In fact, some of the code looks very much like it was borrowed from the <a href="http://metasploit.com/" target="_blank">Metasploit</a> framework.  Here are all of the attack vectors that this code tries to exploit:</p>
<ol>
<li>Flash ActiveX if the version less than 9.0.124</li>
<li>Adobe Reader</li>
<li>Microsoft Office snapshot viewer ActiveX exploit (<a href="http://www.microsoft.com/technet/security/bulletin/MS08-041.mspx" target="_blank">MS08-041</a> will protect you)</li>
<li><a href="http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=50079" target="_blank">AOL SB.SuperBuddy ActiveX</a> code found in AOL Client Software 9.0 Security</li>
<li>QuickTime</li>
<li>Microsoft DirecAnimation ActiveX (<a href="http://www.microsoft.com/technet/security/bulletin/MS06-067.mspx" target="_blank">MS06-067</a> will protect you)</li>
<li>An oldie but goodie, Microsoft DDS Library Shape Control which was part of Visual Studio 2002 (<a href="http://www.microsoft.com/technet/security/bulletin/MS05-052.mspx" target="_blank">MS05-052</a> will protect you)</li>
<li>Windows Sell Remote Code Execution Vulnerability (<a href="http://www.microsoft.com/technet/security/bulletin/MS06-057.mspx" target="_blank">MS06-57</a> will protect you)</li>
</ol>
<p>Bottom line, if you are up to date on patches, you will not have problems.  The trick is to update not only Windows, but all your software you have on your computer.  Not so easy as most people do not really know what actually have installed over time.  The best thing you can do is to visit <a href="http://secunia.com/vulnerability_scanning/" target="_blank">Secunia Software Scanning</a> and use their scanner.  It will tell you all the software you have installed that requires updates.  If you actually download and install their software, it will keep track of what you have and let you know when there are new updates.</p>
<p>I do have the JavaScript saved, let me know if you would like to see it.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Vm9L8zb3XMzdBuxo9LbSEVc9I-4/0/da"><img src="http://feedads.g.doubleclick.net/~a/Vm9L8zb3XMzdBuxo9LbSEVc9I-4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Vm9L8zb3XMzdBuxo9LbSEVc9I-4/1/da"><img src="http://feedads.g.doubleclick.net/~a/Vm9L8zb3XMzdBuxo9LbSEVc9I-4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=00MTfpFG"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=lBY9vhaq"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=vsNpPR1z"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=vsNpPR1z" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=5NYQJGMD"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=5NYQJGMD" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/02/disection-of-a-web-based-infection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/02/disection-of-a-web-based-infection/</feedburner:origLink></item>
		<item>
		<title>Time to patch your printers</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/Eh_rW-VbmTs/</link>
		<comments>http://www.digitallachance.com/blog/2009/02/time-to-patch-your-printers/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 20:13:47 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[printers]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=69</guid>
		<description><![CDATA[HP revealed a new vulnerability that a directory traversal issue in the web admin interface allows remote user to view files on the printers.  Should you start including printers in your patching policies?  Here are some things you should do to protect yourself.]]></description>
			<content:encoded><![CDATA[<p>This might surprise some, but printers need patching too.  The rule of thumb you should use is<em> if it has an IP address, then it can be vulnerable and will most likely require a patch at some point in time.</em></p>
<p>SANS handler&#8217;s diary has just published such a story &#8211; <a href="http://isc.sans.org/diary.html?storyid=5809">Time to patch your HP printers</a>.  The actual HP bulletin is <a title="HP Web Jetadmin Software - HPSBPI02398 SSRT080166 rev.1 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and   HP Digital Senders, Remote Unauthorized Access to Files - c01623905 - HP Business Support Center" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01623905" target="_blank">here</a>.  Looks like PC Advisor also <a title="HP printer owners exposed by web hack" href="http://www.pcadvisor.co.uk/news/index.cfm?NewsID=110590" target="_blank">picked up the story</a>.</p>
<p>The easiest way to do the firmware upgrade is to use HP&#8217;s <a title="HP Web Jetadmin software - overview and features" href="http://h20338.www2.hp.com/Hpsub/cache/332262-0-0-225-121.html" target="_blank">Web Jetadmin</a>.  Using Web Jetadmin, you can discover all your printers on your LAN and remotely do firmware upgrades.</p>
<p>Although this vulnerability only allows the bad guys to access any files on the printer (and therefore view previously printed documents), I can foresee printers being used as a staging point for more serious things.  The reason is that printers have not received the same amount of scrutiny that workstations/serves have and most likely are softer targets.  As well, printers do not run anti-virus or other kind of defensive software.  So what should you do?  Here are a few things that will harden your printers:</p>
<ol>
<li>Use a central management console like Web Jetadmin.  This will allow you to discover any new printers added and to easily deploy the latest firmware.</li>
<li>Keep up with the firmware releases.  This is probably a difficult one to do, especially if you use printers from a number of vendors.  You should at least do a round of patching once a year.</li>
<li>Scan your printers for vulnerabilities.  Make sure to use a tool that can differentiate between a printer device and a workstation.  If it doesn&#8217;t, scanning can lead to lockups and rebooting of your printers.  Not so good if it&#8217;s in the middle of printing a big color job by your boss.  Nessus scanner is one such scanner.  Be warned that scanning your printer will probably cause it to print a few pages.</li>
</ol>
<p>If anyone else has anything else that they do to harden their printers, please use the comments below.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Dir7F_dzQq9mSUKh6AYZB919cRA/0/da"><img src="http://feedads.g.doubleclick.net/~a/Dir7F_dzQq9mSUKh6AYZB919cRA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Dir7F_dzQq9mSUKh6AYZB919cRA/1/da"><img src="http://feedads.g.doubleclick.net/~a/Dir7F_dzQq9mSUKh6AYZB919cRA/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=hNifQxUy"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=mdh3vBat"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=lbPpRa8J"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=lbPpRa8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=UfuliKrY"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=UfuliKrY" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/02/time-to-patch-your-printers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/02/time-to-patch-your-printers/</feedburner:origLink></item>
		<item>
		<title>Web content filtering without installing any software</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/I8AXriNyC9M/</link>
		<comments>http://www.digitallachance.com/blog/2009/02/web-content-filtering-without-installing-any-software/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 18:00:24 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[downadup]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=51</guid>
		<description><![CDATA[Free protection without installing any software.  The solution is simple, just use the right DNS to prevent the traffic from entering your network in the first place.]]></description>
			<content:encoded><![CDATA[<p>If you could protect your whole network from malware, adware, porn and other web sites that should not ever be viewed by employees or children, wouldn&#8217;t you do it?  What if I told  you that you can, and you don&#8217;t even have to install any software anywhere in your network?  I usually go by the old adage that if it sounds to good to be true, it probably is.  This is one time where that&#8217;s not true.</p>
<p>My secret weapon is called <a href="http://www.opendns.com" target="_blank">OpenDNS</a>.  I use <a href="http://www.pfsense.com/" target="_blank">pfSense</a> firewall at home and I also have installed this great freeBSD based firewall at three other customer&#8217;s sites.  Although the ISP for each of these sites supply their own DNS server, I do not point the firewall to their DNS.  I simply set the DNS server address on the General Setup page to point to</p>
<ul>
<li>208.67.222.222</li>
<li>208.67.222.220</li>
</ul>
<p>Using OpenDNS does not really slow things down in any way (not that anybody can truly notice anyway).  Also, OpenDNS is introducing a free service to protect you from the Conficker worm.  Read <a href="http://www.theregister.co.uk/2009/02/07/opendns_conficker_protection/" target="_blank">this post</a> from The Register to see all of the details.  Go on and create yourself an account on OpenDNS.  You&#8217;ll be able to do filtering based on 27 categories.  The service you get for free from these guys is top notch.</p>
<p><strong>Update:</strong> Looks like has just published a very concise page about the Conficker worm and how to deal with it.  Check it out at <a href="http://technet.microsoft.com/en-us/security/dd452420.aspx" target="_blank">http://technet.microsoft.com/en-us/security/dd452420.aspx</a></p>
<p><strong>Update (Feb. 10): </strong>Looks like <a title="Stats are back; and we're blocking Conficker" href="http://blog.opendns.com/2009/02/09/stats-are-back-and-conficker/" target="_blank">OpenDNS official blog</a> has more information about their new feature.</p>
<p><!-- OpenDNS button --><br />
<a title="Use OpenDNS to make your Internet faster, safer, and smarter." href="http://www.opendns.com/share/"><img src="http://images.opendns.com/buttons/use_opendns_150x40.gif" width="150" height="40" style="border:0;" alt="Use OpenDNS" /></a><br />
<!-- / end OpenDNS button --></p>
<p><a href="http://www.mippin.com/link/mippit.jsp?id=50252"><img src="http://www.mippin.com/app/images/blogger_button.gif" border="0" alt="Add IT a digital life Mippin widget" /></a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/l6_Xa_osb9wl6IoWjv9uEeZSLag/0/da"><img src="http://feedads.g.doubleclick.net/~a/l6_Xa_osb9wl6IoWjv9uEeZSLag/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/l6_Xa_osb9wl6IoWjv9uEeZSLag/1/da"><img src="http://feedads.g.doubleclick.net/~a/l6_Xa_osb9wl6IoWjv9uEeZSLag/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=Feqp5CFO"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=4v1rT1nW"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=rWSxXQXk"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=rWSxXQXk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=U2xygW3I"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=U2xygW3I" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/02/web-content-filtering-without-installing-any-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/02/web-content-filtering-without-installing-any-software/</feedburner:origLink></item>
		<item>
		<title>How to use a Smart Card to digitally sign your e-mails in Outlook</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/h7QYzWwGTR0/</link>
		<comments>http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 07:34:10 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[How-to]]></category>
		<category><![CDATA[Digital Certificates]]></category>
		<category><![CDATA[Digital Signing]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Outlook]]></category>
		<category><![CDATA[S/MIME]]></category>
		<category><![CDATA[SmartCards]]></category>
		<category><![CDATA[Two-Factor authentication]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=25</guid>
		<description><![CDATA[If you are using smart card in your network only for authentication, you are missing out on the other things you can do to secure your communication with others.  This post will show you how to enable your smart card to be used to digitally sign or encrypt your e-mails in Outlook 2003.]]></description>
			<content:encoded><![CDATA[<p>Where I currently work, we are using smart cards in order to secure Active Directory accounts with elevated privileges.  That&#8217;s great way to do two-factor authentication because smart cards are integrated in AD natively.  In order to force an account to use a smart card, you only have to click on a checkbox on the <a title="User and computer accounts" href="http://technet.microsoft.com/en-us/library/cc759279.aspx" target="_blank">user account</a>.</p>
<p>In order to be able to digitally sign and encrypt your e-mails, you have to first take the following steps:</p>
<ol>
<li>Import the certificate on your smart card into the IE Store</li>
<li>Configure Outlook to use the certificate</li>
<li>Start signing/encrypting your e-mail</li>
</ol>
<p>Sounds simple enough.  Let&#8217;s get into the details of how we do all of that.</p>
<p>The first step is to import the digital certificate that is on the smart card into what is sometimes called the IE store.  Since I use <a title="Gemalto's web site" href="http://www.gemalto.com/" target="_blank">Gemalto</a>&#8216;s GemSafe drivers, it is fairly easy.</p>
<ol>
<li>I first go to the Certificates section of the Toolbox and click on my certificate.</li>
<li>This enables the <em>Export&#8230;</em> button.  Click on it to go to the export screen.</li>
<li>Select <em>Export to IE store</em> and make sure that you select <em>Personal</em> as the certificate store.</li>
<li>Click the Export button.</li>
</ol>
<p>This puts a copy of the certificate (private and public keys) into your personal store for your use.  You can verify that the certificate was imported properly by opening up Internet Explorer, click on <em>Tools</em> | <em>Internet Options</em> |<em> Content</em> | <em>Certificates</em>.  Your certificate should be listed in the Personal tab.  Click on the certificate.  This will fill the <em>Certificate intended purposes</em> section at the bottom of the dialog box.  If <strong>Secure Email</strong> is not one of the intended purposes, then you will not be able to use this certificate to sign your e-mails.</p>
<p>Now the last thing to do is to configure Outlook to use that certificate.</p>
<ol>
<li>In Outlook (I&#8217;m using Outlook 2003), click on <em>Tools</em> | <em>Options&#8230;</em> | <em>Security</em> tab| <em>Settings&#8230;</em> button in the <em>Encrypted e-mail</em> section.</li>
<li>Here we need to choose our signing certificate and encryption certificate.  Click on the <em>Choose&#8230;</em> button and select the same certificate in both cases.</li>
<li>Your <em>Hash Algorithm</em> should be <strong><a title="More information about SHA1 from Wikipedia.org" href="http://en.wikipedia.org/wiki/Sha1" target="_blank">SHA1</a> </strong>because it is stronger than the old <a title="More information about MD5 from Wikipedia.org" href="http://en.wikipedia.org/wiki/MD5" target="_blank"><strong>MD5</strong></a>.</li>
<li>Your <em>Encryption Algorithm</em> is probably defaulted to <a title="More information about 3DES from Wikipedia.org" href="http://en.wikipedia.org/wiki/3DES" target="_blank"><strong>3DES</strong></a>, which is the strongest algorithm available.</li>
<li>Make sure that the checkbox for the <em>Send these certificates with signed messages</em> option is checked.  This will then allow your recipient to import your certificate (with your public key only) into their store.  This way they will be able to encrypt e-mails to you and only you will be able to decrypt them.</li>
</ol>
<p>And there you go.  The next time you write an e-mail, simply click on the <em>Options&#8230;</em> button and then the <em>Security Settings&#8230;</em> button to open the dialog box that will allow you to digitally sign and encrypt your e-mail.  Make sure that your smart card is inserted.  When you click on the <em>Send</em> button, you will be asked to enter your PIN before your e-mail is signed and encrypted in order to confirm your identity.</p>
<p>I hope this was helpful to you.  Let me know if you have any questions.</p>

<a href='http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/gemsafe_cert/' title='GemSafe toolbox certificates screenshot'><img width="150" height="150" src="http://www.digitallachance.com/blog/wp-content/uploads/gemsafe_cert-150x150.png" class="attachment-thumbnail" alt="GemSafe toolbox certificates screenshot" title="GemSafe toolbox certificates screenshot" /></a>
<a href='http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/certdetails/' title='Smart card certificate details'><img width="150" height="150" src="http://www.digitallachance.com/blog/wp-content/uploads/2009/02/certdetails-150x150.png" class="attachment-thumbnail" alt="Smart card certificate details" title="Smart card certificate details" /></a>
<a href='http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/gemsafe_export/' title='GemSafe toolbox certificate export options'><img width="150" height="150" src="http://www.digitallachance.com/blog/wp-content/uploads/gemsafe_export-150x150.png" class="attachment-thumbnail" alt="GemSafe toolbox certificate export options" title="GemSafe toolbox certificate export options" /></a>
<a href='http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/iestore_personal/' title='IE 7 Personal certificate store'><img width="150" height="150" src="http://www.digitallachance.com/blog/wp-content/uploads/iestore_personal-150x150.png" class="attachment-thumbnail" alt="IE 7 Personal certificate store" title="IE 7 Personal certificate store" /></a>


<p><a href="http://feedads.g.doubleclick.net/~a/Z5VO5En03IWCd_z2067uncZYIq0/0/da"><img src="http://feedads.g.doubleclick.net/~a/Z5VO5En03IWCd_z2067uncZYIq0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Z5VO5En03IWCd_z2067uncZYIq0/1/da"><img src="http://feedads.g.doubleclick.net/~a/Z5VO5En03IWCd_z2067uncZYIq0/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=E3NHRSxy"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=yjDiJxrC"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=NlXGymSr"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=NlXGymSr" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=WKmOx7qP"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=WKmOx7qP" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/02/how-to-use-a-smart-card-to-digitally-sign-your-e-mails-in-outlook/</feedburner:origLink></item>
		<item>
		<title>Should you kill NetBIOS from your network?</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/Mq7ZFoAPfR0/</link>
		<comments>http://www.digitallachance.com/blog/2009/02/should-you-kill-netbios-from-your-network/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 03:27:21 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[NetBIOS]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=9</guid>
		<description><![CDATA[In a Windows XP network, NetBIOS is on by default. There are some misconceptions regarding whether NetBIOS is required in order to have file sharing working. In fact, that is not the case. This post will explain what I found out when investigating the impact of removing NetBIOS from our corporate network.]]></description>
			<content:encoded><![CDATA[<p>Do you still have NetBIOS turned on on all of your workstations and servers in your corporate LAN?  This old network protocol puts you at risk and should be killed without prejudice!</p>
<p>There are quite a few reasons why NetBIOS is bad for your network.</p>
<ol>
<li>NetBIOS is an inneficient protocol.  It is very chatty with lots of broadcasts.</li>
<li>When used with its defaults settings, it can be used by the bad guys to gather information about your network and users.  This is done through null sessions.  An excellent source of information on null session can be found in the (old, but still true) page titled <a href="http://puna.net.nz/archives/Hacking/NetBIOS%20Null%20Sessions%20The%20Good,%20The%20Bad,%20and%20The%20Ugly.htm" target="_blank">NetBIOS Null Sessions: The Good, The Bad, and The Ugly</a>.</li>
<li>Although it can now be routed across LANs by using NetBIOS over TCP/IP (NetBT), it was never meant to be used in a WAN environment.</li>
<li>The original design of NetBIOS was actually for a LAN of about 70 users.</li>
</ol>
<p>One of the major misconception about NetBIOS is the fact that people think that it has to be there in order for you to have a file share to serve files to your network users.  <a title="Direct hosting of SMB over TCP/IP" href="http://support.microsoft.com/kb/204279" target="_blank">That is actually not the case</a>.</p>
<h2>File sharing on your LAN</h2>
<p>NetBIOS uses these ports:</p>
<ul type="disc">
<li>UDP 137: NetBIOS name service</li>
<li>UDP 138: NetBIOS datagram service</li>
<li>TCP 139: NetBIOS session service</li>
</ul>
<p>In actual fact, a workstation that tries to connect to a file share might start by trying using those ports.  Windows will automatically fall back to using SMB, which is on port TCP 445.  You might have heard of SMB (Server Message Blocks) and CIFS (Common Internet File System) in the same conversation.  That&#8217;s because <a href="http://msdn.microsoft.com/en-us/library/aa365233.aspx" target="_blank">CIFS is actually a dialect of SMB</a>.</p>
<h2>The downside of disabling NetBIOS</h2>
<p>I found only two problems that you might run into if you disable NetBIOS.  Another side effect is that this will <a title="NETBIOS: Leave On or Turn Off?" href="http://www.windowsnetworking.com/kbase/WindowsTips/Windows2003/AdminTips/Network/NETBIOSLeaveOnorTurnOff.html" target="_blank">affect trusts between forests</a>.  This is definitely true for domains at the Windows 2000 functional level or even a Windows NT to Windows 2003 trust.  In a simpler network with only one domain in your forest, this will not be an issue.</p>
<p>The other negative impact that I found is the fact that you no longer browse for computer in <em>Network Neighborhood </em>(Windows 98) or <em>Microsoft Windows Network</em> (Windows XP). When NetBIOS is enabled in your network, the master browser collects information about all the computers in the network.  That information is then propagated every 12 minutes to all workstations.  This can be displayed in the network neighborhood or using the NET VIEW command.  In effect, this is how name resolution was done, by using the list maintained by the master browser. WINS is the other name resolution method in the NetBIOS world.  This method is <a title="Description of the Microsoft Computer Browser Service" href="http://support.microsoft.com/kb/188001" target="_blank">no longer used by Microsoft</a> OS since Windows 2000.</p>
<h2>How to deal with NetBIOS</h2>
<p>The best thing to do, is simply to eliminate NetBIOS.  You probably won&#8217;t miss it.  Most likely, if your network has more than a few computers in it, you are using DHCP.  You can use <a href="http://support.microsoft.com/kb/313314" target="_blank">DHCP to easily disable NetBIOS</a> on your workstations.  In a smaller setting, you can change the configuration on each computer in your network by doing the following (instructions for Windows XP):</p>
<ol>
<li>Click <strong>Start</strong>, point to <strong>Settings</strong>, and then click <strong class="uiterm">Network and Dial-up Connection</strong>.</li>
<li>Right-click <strong>Local Area Connection</strong>, and then click <strong>Properties</strong>.</li>
<li>Click <strong>Internet Protocol (TCP/IP)</strong>, and then click <strong>Properties</strong>.</li>
<li>Click <strong>Advanced</strong>.</li>
<li>Click the <strong>WINS</strong> tab, and then click <strong class="uiterm">Disable NetBIOS over 				TCP/IP</strong>.</li>
</ol>
<p>This method disables NetBIOS Session Service (which listens on TCP port 139). It does not disable NetBIOS completely.  If you do not want to have SMB enabled, you can disable it all at once by using the following instructions:</p>
<ol>
<li>From the <strong>Start</strong> menu, right-click <strong>My Computer</strong>, and then click <strong>Manage</strong>.</li>
<li>Expand <strong>System Tools</strong>, and then clear the <strong>Device Manager</strong> check box.</li>
<li>Right-click <strong>Device Manager</strong>, point to <strong>View</strong>, and then select <strong>Show hidden devices</strong>.</li>
<li>Expand <strong>Non-Plug and Play Drivers</strong>.</li>
<li>Right-click <strong>NetBios over TCP/IP</strong>, and then click <strong>Disable</strong>.</li>
</ol>
<p>This disables the SMB direct host listener on TCP/445 and UDP 445.</p>
<h2>Final Thoughts</h2>
<p>Before you make such an important change in your network, you need to do some serious testing.  This is especially true if you have a lot of different servers and applications.  I intend to post again with the result of my testing and the effect that disabling NetBIOS had on our network.</p>
<h2>Related links</h2>
<ul>
<li><a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;323357" target="_blank">How To Configure TCP/IP Networking While NetBIOS Is Turned Off on a Server Running Windows Server 2003</a></li>
<li><a href="http://support.microsoft.com/default.aspx?scid=kb;RU;299977" target="_blank">How To Configure TCP/IP Networking While NetBIOS Is Disabled in Windows 2000 Server</a></li>
<li><a href="http://support.microsoft.com/kb/204279" target="_blank">Direct hosting of SMB over TCP/IP</a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms143696.aspx" target="_blank">How to: Disable NetBIOS over TCP/IP</a></li>
<li><a title="How to disable NetBIOS over TCP/IP by using DHCP server options" href="http://support.microsoft.com/kb/313314" target="_blank">How to disable NetBIOS over TCP/IP by using DHCP server options</a></li>
<li><a href="NETBIOS: Leave On or Turn Off?" target="_blank">NETBIOS: Leave On or Turn Off?</a></li>
<li><a href="http://support.microsoft.com/kb/325874">How to establish trusts with a Windows NT-based domain in Windows Server 2003</a></li>
<li><a href="http://support.microsoft.com/kb/188001" target="_blank">Description of the Microsoft Computer Browser Service</a></li>
<li><a href="http://www.windowsdevcenter.com/pub/a/windows/2004/05/11/netbios.html" target="_blank">Understanding NetBIOS and Windows Server 2003</a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms143696.aspx" target="_blank">How to: Disable NetBIOS over TCP/IP</a></li>
</ul>

<p><a href="http://feedads.g.doubleclick.net/~a/Mj23XWuZvQD0SzesUAi-hJ5vj6k/0/da"><img src="http://feedads.g.doubleclick.net/~a/Mj23XWuZvQD0SzesUAi-hJ5vj6k/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Mj23XWuZvQD0SzesUAi-hJ5vj6k/1/da"><img src="http://feedads.g.doubleclick.net/~a/Mj23XWuZvQD0SzesUAi-hJ5vj6k/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=cQMeSW6q"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=WLiLUqVC"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=LzDA8MLN"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=LzDA8MLN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=sR37W92o"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=sR37W92o" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/02/should-you-kill-netbios-from-your-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/02/should-you-kill-netbios-from-your-network/</feedburner:origLink></item>
		<item>
		<title>Starting a new Open Source project shouldn’t be this hard</title>
		<link>http://feedproxy.google.com/~r/ItADigitalLife/~3/NX95LbJ1g0M/</link>
		<comments>http://www.digitallachance.com/blog/2009/01/starting-a-new-open-source-project-shouldnt-be-this-hard/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 17:58:28 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Projects]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=3</guid>
		<description><![CDATA[Creating an open source project should be easy.  This describes my experience with SourceForge and CodePlex when I tried to create my first project.]]></description>
			<content:encoded><![CDATA[<p>Wow!  I thought it would be easier than that.  I have this application I started writing that I feel would be useful to lots of people out there and decided to share.  I wrote an application that takes the output of a <a title="Visit the Nessus web site." href="http://www.nessus.org/nessus/" target="_blank">Nessus</a> scan and loads it into an SQL Server database.  I intend on working on this over time and add features like reporting.  Ultimately, what I am after is better reporting as the Nessus application only provides ONE report.</p>
<p>Since I wrote the code in C Sharp, I decided to go the one of the best known repository for Microsoft technology open source projects, CodePlex.  Creating the project was quick enough, but I can&#8217;t seem to be able to access the source code tab.  I always get the message that <em>The source control server is currently unavailable.</em> Fine, I&#8217;m moving on.</p>
<p>So I went to the best known open source repository, SourceForge.net, and created my project.  It looks like it needs to be reviewed by humans before I can even start uploading code.  Great!  It was bed time anyway.</p>
<p>Today, I decided to see if by chance my project in SourceForge would allow to upload code, and it does.  Awesome.  CodePlex is still displaying the same error message.  I don&#8217;t know if it is me who is doing something wrong or what.  I cannot find anywhere to go if I have problems.  What looks like their support board actually contains more suggestions for enhancements than support requests.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/9Rg-1EDKW5ABFE9rfxtcSd4XWgU/0/da"><img src="http://feedads.g.doubleclick.net/~a/9Rg-1EDKW5ABFE9rfxtcSd4XWgU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/9Rg-1EDKW5ABFE9rfxtcSd4XWgU/1/da"><img src="http://feedads.g.doubleclick.net/~a/9Rg-1EDKW5ABFE9rfxtcSd4XWgU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=OIxzAuDY"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=tCZlMQ1e"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?d=52" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=uPD98Dse"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=uPD98Dse" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/ItADigitalLife?a=5UcK7fW1"><img src="http://feeds.feedburner.com/~f/ItADigitalLife?i=5UcK7fW1" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://www.digitallachance.com/blog/2009/01/starting-a-new-open-source-project-shouldnt-be-this-hard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitallachance.com/blog/2009/01/starting-a-new-open-source-project-shouldnt-be-this-hard/</feedburner:origLink></item>
	</channel>
</rss>
