<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-19938704</id><updated>2008-07-01T02:25:44.951+02:00</updated><title type="text">Security Zero</title><link rel="alternate" type="text/html" href="http://www.securityzero.com/index.htm" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default?start-index=26&amp;max-results=25" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>205</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/SecurityZero" type="application/atom+xml" /><feedburner:emailServiceId>SecurityZero</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry><id>tag:blogger.com,1999:blog-19938704.post-3423433445522243729</id><published>2006-12-28T15:43:00.002+01:00</published><updated>2008-07-01T02:25:44.980+02:00</updated><title type="text">Release: Microsoft Network Monitor 3.0</title><content type="html">&lt;!-- google_ad_section_start --&gt;After years Microsoft finally release an update for its sniffer: Network Monitor (aka NetMon) 3.0.&lt;br /&gt;&lt;br /&gt;As already said at beta 2 time, this new major release (build 3.0.372) doesn't have limitations network professionals use to damn in 2.x versions: it works in promiscous mode and is released as stand alone package. And it's free of charge.&lt;br /&gt;&lt;br /&gt;Plus NetMon 3 introduces several improvements:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Real time capture and display of frames&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Simultaneous capture on multiple network adapters&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Multiple simultaneous capture sessions&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Network conversations and a tree view displaying frames by conversation &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enhanced capture/display filtering (with boolean expressions and &lt;a href="http://en.wikipedia.org/wiki/IntelliSense"&gt;intelli-sense&lt;/a&gt;)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;A new script-based protocol parser language (NPL), and script-based parsers &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Scriptable execution (and packets capture) through NMcap command line tool&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/NetMon3_capture-731766.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/NetMon3_capture-727767.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityzero.com/uploaded_images/NetMon3_parsers-762847.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/NetMon3_parsers-759047.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;The new filtering system is pretty flexible and allows to write filters in similar you do with Wireshark (formerly Ethereal).&lt;br /&gt;For example filtering HTTP traffic reaching or departing from IP address 192.168.0.1 can be written:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ip.addr==192.168.0.1 and http (Wireshark)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;ipv4.Address==192.168.0.1 &amp;&amp; protocol.HTTP (NetMon)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Filters can be written on multiple lines and comments are allowed, permitting to write complex analysis on packets in an easy way.&lt;br /&gt;&lt;br /&gt;Download it &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=216"&gt;here&lt;/a&gt; (it's unclead why Microsoft is still hosting it on Connect instead of Download website).&lt;br /&gt;Check the development team blog &lt;a href="http://blogs.technet.com/netmon"&gt;here&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sniffer" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/NetMon" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=LAbcmoZa"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/12/release-microsoft-network-monitor-30.html" title="Release: Microsoft Network Monitor 3.0" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=3423433445522243729" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/3423433445522243729" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/3423433445522243729" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-116135134405215863</id><published>2006-10-20T15:35:00.000+02:00</published><updated>2006-10-20T15:35:44.140+02:00</updated><title type="text">Italy adopts Microsoft anti-pedophilia tool</title><content type="html">&lt;!-- google_ad_section_start --&gt;Italy, my country, is the first european state to adopt Microsoft Child Exploitation Tracking System (CETS), &lt;a href="http://www.microsoft.com/presspass/features/2005/apr05/04-07CETS.mspx"&gt;launched in 2005&lt;/a&gt; and offered for free to worldwide governments.&lt;br /&gt;&lt;br /&gt;CETS will be used by our police department dedicated to online crimes, the &lt;a href="http://www.poliziadistato.it/pds/informatica/"&gt;Polizia Postale e delle Comunicazioni&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;CETS offers a national repository, powered by Microsoft SharePoint and SQL Server, where investigators can register suspected online identities, upload child exploitations images, link suspicious web sites, store seized emails, etc. &lt;br /&gt;It then syncronizes informations with other national databases in adhering countries.&lt;br /&gt;&lt;br /&gt;Efficacy of the tool is actually limited because apart Italy only Canada and Indonesia are using it. &lt;br /&gt;US, Japan and Australia are evaluating CETS adoption, but until more countries will share informations on the system there are few chances to improve tracking capabilities.&lt;br /&gt;&lt;br /&gt;It also worth to consider that masquerading an online identity is not too complex and these sexual criminals are used to computer technologies. Their level of know-how is surely improving fast, to adapt new countermisures and tools like CETS could be useless in few years.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Right in these days Microsoft is expanding its offering for defending children and launched a parental control tool called &lt;a href="http://www.securityzero.com/2006/10/microsoft-on-parental-control-with.html"&gt;OneCare Family Safety&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/privacy" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/CETS" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=3MW54yjc"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/italy-adopts-microsoft-anti-pedophilia.html" title="Italy adopts Microsoft anti-pedophilia tool" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=116135134405215863" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116135134405215863" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116135134405215863" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-116134872648272206</id><published>2006-10-20T14:52:00.000+02:00</published><updated>2006-10-20T14:52:06.610+02:00</updated><title type="text">MSDN Magazine November 2006 - Yearly Security Issue</title><content type="html">&lt;!-- google_ad_section_start --&gt;Last issue of MSDN Magazine is dedicated to security.&lt;br /&gt;&lt;br /&gt;Among top articles:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Secure Habits: 8 Simple Rules For Developing More Secure Code (Michael Howard)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Threat Modeling: Uncover Security Design Flaws Using The STRIDE Approach (Shawn Hernan, Scott Lambert, Tomasz Ostwald, Adam Shostack)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Single Sign-On: A Developer's Introduction To Active Directory Federation Services (Keith Brown)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Smart Storage: Protect Your Data Via Managed Code And The Windows Vista Smart Card APIs (Dan Griffin)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Extending SDL: Documenting And Evaluating The Security Guarantees Of Your Apps (Mark Pustilnik)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;SQL Security: New SQL Truncation Attacks And How To Avoid Them (Bala Neerumalla)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Last one seems particularly interesting:&lt;br /&gt;&lt;blockquote&gt;Exploits using SQL injection have drawn a lot of attention for their ability to get through firewalls and intrusion detection systems to compromise your data layers. Whether it's a first-order or second-order injection, if you look at the basic code pattern, it is similar to any other injection issue where you use untrusted data in the construction of a statement. Most developers have started mitigating these vulnerabilities in Web front ends by using parameterized SQL queries in conjunction with stored procedures at the back end, but there are some instances where developers still use dynamically constructed SQL, like in the construction of Data Definition Language (DDL) statements based on user input or for apps written in C/C++.&lt;br /&gt;&lt;br /&gt;In this article I will discuss some new ideas that can result in either modifying SQL statements or injecting SQL code even if the code has escaped the delimiting characters. I will start with some best practices for constructing delimited identifiers and SQL literals, and then I'll show you new ways attackers can inject SQL code in order to help you protect your applications...&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Read the whole MSDN Magazine November 2006 issue &lt;a href="http://msdn.microsoft.com/msdnmag/issues/06/11/default.aspx"&gt;here&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=Hr5yVdzT"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/msdn-magazine-november-2006-yearly.html" title="MSDN Magazine November 2006 - Yearly Security Issue" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=116134872648272206" title="1 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116134872648272206" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116134872648272206" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-116074444904330234</id><published>2006-10-13T15:00:00.000+02:00</published><updated>2006-10-13T15:00:49.200+02:00</updated><title type="text">Release: Check Point NGX R62</title><content type="html">&lt;!-- google_ad_section_start --&gt;Check Point continues to release new minor updated of its platform on regular basis, not changing the strategy already adopted with previous NG platform and its Feature Packs.&lt;br /&gt;&lt;br /&gt;In NGX the company doesn't call new updates Feature Pack anymore but continue to release them every 4 months or so.&lt;br /&gt;&lt;br /&gt;In the new R62 there are some interesting changes:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Integry removing from Media Kit&lt;/strong&gt;&lt;br /&gt;Integrity, the endpoint security solution Check Point obtained with ZoneLabs acquisition over 2 years ago, has been removed from package.&lt;br /&gt;Check Point included it in the R61 package but now already changed its mind, only allowing resellers to distribute it to interested customers.&lt;br /&gt;&lt;br /&gt;This is possibly to reduce piracy of the new product, already available in warez circuits.&lt;br /&gt;If so I don't think it's a very effective countermisure, only slowing down customers evaluation and adoption.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Support for Windows Server 2003 Service Pack 2&lt;/strong&gt;&lt;br /&gt;NGX R62 supports Windows Server 2003 Service Pack 2 even if at the moment of writing the SP2 is not yet released by Microsoft.&lt;br /&gt;&lt;br /&gt;While I'm sure Check Point has access to new builds much earlier than other beta tester, I don't remember the company ever supported a new operating system update so early.&lt;br /&gt;I strongly recommend to not install SP2 on your Windows Server 2003 machines at release time without extended testing for reliability and compatibility with Check Point products.&lt;/li&gt; &lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Multiple SmartDefense profiles&lt;/strong&gt;&lt;br /&gt;Finally customers are able to create several SmartDefense configurations from SmartDashboard and bind them to different gateways in the object database.&lt;br /&gt;In the same fashion SmartDefense can be disabled on gateway basis.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Enhanced Log Forwarding&lt;/strong&gt;&lt;br /&gt;Depending on your configuration Check Point gateways forward local log entries to the default SmartCenter Server log server, or to additional Log Servers configurated as stand-alone tiers.&lt;br /&gt;In this process log entries are stored locally, forwarded to the right location, and finally deleted locally.&lt;br /&gt;&lt;br /&gt;In the NGX R62 all logs can be forwarded directly, without local storing.&lt;br /&gt;I don't see this feature particularly safe to use, because it's necessary to evaluate what happens if, during the forwarding, link goes down.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The NGX R62 supports backward compatibility down to NG FP3.&lt;br /&gt;Older installations have to be upgraded to NG AI [R54] and then migrated to NGX R62.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A last note about build version: tracking Check Point platform updates can be very hard because every single component has a different build numering.&lt;br /&gt;NGX R62 has following build numbers for major components:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;VPN-1 (Power / UTM on any OS) - 120&lt;/li&gt;&lt;br /&gt;&lt;li&gt;SmartCenter Server - 021&lt;/li&gt;&lt;br /&gt;&lt;li&gt;SmarConsole - 618000131&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;SecurePlatform - 031&lt;/li&gt;&lt;/ul&gt;&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/firewall" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Check+Point" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/auditing" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=Tk1vcGxf"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/release-check-point-ngx-r62.html" title="Release: Check Point NGX R62" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=116074444904330234" title="1 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116074444904330234" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116074444904330234" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-116052686979001779</id><published>2006-10-11T02:34:00.000+02:00</published><updated>2006-10-11T02:34:29.810+02:00</updated><title type="text">Symantec and the big Security 2.0 lie</title><content type="html">&lt;!-- google_ad_section_start --&gt;This blog's readers know how much I love Symantec. No other company in the security space provides me so much concern like this one.&lt;br /&gt;&lt;br /&gt;Symantec spent last years acquiring one after another quite dozen of valid security firms, trying to reach a leadership position thanks to marketshare, not quality of products.&lt;br /&gt;The company has been so successful in acquiring and so unsuccessful in integrating that I usually refer to it with the name of &lt;a href="http://www.securityzero.com/2005/10/symantec-resistance-is-futile-you-will.html"&gt;Symantec of Borg&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This strategy never really worked so the company could just maintain a leadership in its own market segment: antivirus.&lt;br /&gt;&lt;br /&gt;Unfortunately this segment is going to be saturated by the biggest competitor possiible, Microsoft, which has interest and economical power to offer multiple anti-malware products for free to consumer and business audience if needed. And will eventually do.&lt;br /&gt;&lt;br /&gt;In my years of experience I cannot remember meeting a single user, system administrator, security professional, CTO or CIO, not complaining about Symantec core product performances or lack of innovation.&lt;br /&gt;&lt;br /&gt;Fearing Microsoft competition and knowing its own weakness, Symantec is now trying to create new (non-existent) markets where it can escape.&lt;br /&gt;So it just launched &lt;a href="http://www.symantec.com/about/news/resources/press_kits/detail.jsp?pkid=security2"&gt;Security 2.0&lt;/a&gt; (I knew someone sooner or later would have this bad idea).  &lt;br /&gt;&lt;br /&gt;Its CEO, John Thompson, launched the initiative declaring worms and viruses problems is solved. Or at least this is what InformationWeek &lt;a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=193200301"&gt;reports&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Security 2.0? But if we still are far away to reach a stable 1.0...&lt;br /&gt;&lt;br /&gt;The new wave of products forming the Symantec Security 2.0 is incredible:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20061010_02"&gt;Norton Confidential Online Edition&lt;/a&gt;&lt;br /&gt;An anti-phising tool (&lt;a href="http://www.securityzero.com/2006/10/anti-phishing-tools-comparison.html"&gt;we are plenty of these tools&lt;/a&gt;. All 1.0) able to block keyloggers (something the anti-virus should already do)? &lt;br /&gt;&lt;br /&gt;In any case a very poor approach to the problem: if banks want to offer a safe environment to customers could simply send them a USB key filled with VMware Player (free) and a custom Linux distribution (free as well), able to only connect home-banking site. Nothing could be more 2.0 than this.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20061010_04"&gt;Symantec Database Security&lt;/a&gt;&lt;br /&gt;A behavioral host IDS? Thanks, we are working on them since years, still addressing false positives and false negatives issues.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20061010_03"&gt;Symantec Mail Security 8300 Series&lt;/a&gt;&lt;br /&gt;The dear old Brightmail Anti-spam engine in a shining new case? It also features content filtering? Thanks, we do that since 10 years, and WebSense is still leader in this segment.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;I prefer to not further comment remaining 2 announcements of this wave: partnership for services with VeriSign (for 2-factors authentication) and Accenture (for risk assessment and management).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If this is Security 2.0 I want to directly skip next major release.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/antivirus" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+2.0" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=9cJQw9aH"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/symantec-and-big-security-20-lie.html" title="Symantec and the big Security 2.0 lie" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=116052686979001779" title="1 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116052686979001779" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116052686979001779" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-116022914352336817</id><published>2006-10-07T15:51:00.000+02:00</published><updated>2006-10-09T21:39:44.383+02:00</updated><title type="text">Anti-phishing tools comparison</title><content type="html">&lt;!-- google_ad_section_start --&gt;3Sharp published an interesting 37-pages comparison between anti-phishing tools available on the market today.&lt;br /&gt;&lt;br /&gt;Not only it's interesting because it provides a useful compendium to the lastest &lt;a href="http://www.securityzero.com/2006/10/internet-security-threat-report-h1.html"&gt;Internet Security Threat Report&lt;/a&gt; published by Symantec, but also because it includes some unexpected results, distinguishing between recognition rate (detailing false positives) and blocking rate.&lt;br /&gt;&lt;br /&gt;GeoTrust TrustWatch is the most capable in recognition but has 2 big issues: has a 32% rating of false positives and is unable to block any phishing attempt.&lt;br /&gt;&lt;br /&gt;Microsoft Phishing Filter included in Internet Explorer 7 Beta 3 is the best in class, able to recognize 89% of threats without false positives, and a 83% capability to block phishing attempts (remaining 6% is only warned) .&lt;br /&gt;&lt;br /&gt;The much popular Google Toolbar included in Firefox is only at 4th place, able to recognize without false positives and block only 53% of threats.&lt;br /&gt;&lt;br /&gt;The interesting &lt;a href="http://www.securityzero.com/2006/02/free-personal-security-advisor-to-surf.html"&gt;SiteAdvisor&lt;/a&gt;, which claimed a 90% worldwide websites coverage before being acquired by McAfee in April, has been included in the comparison even if McAfee clearly states the product doesn't recognize phishing (read comments for more details).&lt;br /&gt;No surprise it was the last one with a mere 3%.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Read the whole report &lt;a href="http://www.3sharp.com/projects/antiphishing/gone-phishing.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Update:&lt;/strong&gt; As every report it should read with due aloofness: &lt;a href="http://blogs.msdn.com/ie/archive/2006/09/28/774513.aspx"&gt;the study has been committed by Microsoft&lt;/a&gt;, 3Sharp &lt;a href="http://www.3sharp.com/about_us.htm"&gt;founders are former Microsoft employees&lt;/a&gt; and the company is mainly skilled on Microsoft technologies.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Google" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/phishing" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=DfNNM1rI"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/anti-phishing-tools-comparison.html" title="Anti-phishing tools comparison" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=116022914352336817" title="3 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116022914352336817" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/116022914352336817" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115997579554726323</id><published>2006-10-04T17:29:00.000+02:00</published><updated>2006-10-04T17:53:08.343+02:00</updated><title type="text">Internet Security Threat Report - H1 2006</title><content type="html">&lt;!-- google_ad_section_start --&gt;Symantec released the 10th edition of its much appreciated Internet Security Threat Report.&lt;br /&gt;&lt;br /&gt;The very first edition of this report has been published in 2002 by Riptech, a company focused on intrusion detection which &lt;a href="http://www.securityzero.com/2005/10/symantec-resistance-is-futile-you-will.html"&gt;Symantec of Borg&lt;/a&gt; acquired in these years.&lt;br /&gt;&lt;br /&gt;The most recent versions of the report are developed by over 1600 Symantec security analysts, the company claims. While results could be manipulated to justify old and new products, or to discredit competitors like Microsoft (and near the Windows Vista launch Symantec has all interests in doing so), it remains a useful tool for evaluation of attack and vulnerability trends.&lt;br /&gt;&lt;br /&gt;The September 2006 edition offers a 120-pages coverage of threat activity between January 1st and June 30th.&lt;br /&gt;Below significant highlights divided in categories.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Attack Trend&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Microsoft Internet Explorer was the most frequently targeted Web browser, accounting for 47% of all Web browser attacks&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Symantec observed an average of 6,110 DoS attacks per day&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The United States was the target of the most DoS attacks, accounting for 54% of the worldwide total&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The Internet service provider (ISP) sector was the most frequently targeted by DoS attacks&lt;/li&gt;&lt;br /&gt;&lt;li&gt;China had the highest number of bot-infected computers during the first half of 2006, accounting for 20% of the worldwide total&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The United States had the highest percentage of bot command-and-control servers with 42%&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Beijing was the city with the most bot-infected computers in the world&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The United States ranked as the top country of attack origin, accounting for 37% of the worldwide total&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The home user sector was the most highly targeted sector, accounting for 86% of all targeted attacks&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Vulnerability Trend&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Symantec documented 2,249 new vulnerabilities, up 18% over the second half of 2005. This is the highest number ever recorded for a six-month period&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Web application vulnerabilities made up 69% of all vulnerabilities this period&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Mozilla browsers had the most vulnerabilities, 47, compared to 38 in Microsoft Internet Explorer&lt;/li&gt;&lt;br /&gt;&lt;li&gt;In the first six months of 2006, 80% of vulnerabilities were considered easily exploitable, up from 79%&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Seventy-eight percent of easily exploitable vulnerabilities affected Web applications&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The window of exposure for enterprise vulnerabilities was 28 days&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Internet Explorer had an average window of exposure of nine days, the largest of any Web browser. Apple Safari averaged five days, followed by Opera with two days and Mozilla with one day&lt;/li&gt;&lt;br /&gt;&lt;li&gt;In the first half of 2006, Sun operating systems had the highest average patch development time, with 89 days, followed by Hewlett Packard with 53 days, Apple with 37 days and Microsoft and Red Hat with 13 days&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Malicious Code Trend&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Eighteen percent of all distinct malicious code samples detected by Symantec honeypots were new&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Five of the top ten new malicious code families reported were Trojan horse programs&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The most prevalent new malicious code family this period was that of the Polip virus&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Worms made up 38 of the top 50 malicious code samples&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Worms made up 75% of the volume of top 50 malicious code reports&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Symantec documented 6,784 new Win32 viruses and worms&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Bots accounted for 22% of the top 50 malicious code reports, up slightly from the 20% reported in the last period&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Thirty of the top 50 malicious code samples exposed confidential information&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Modular malicious code accounted for 79% of the volume of top 50 malicious code, down from 88% in the second half of 2005&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Phishing, Spam and Security Risks&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The Symantec Probe Network detected 157,477 unique phishing messages, an increase of 81%.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Financial services was the most heavily phished sector, accounting for 84% of phishing activity.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Spam made up 54% of all monitored email traffic, up from 50% in the last period.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The most common type of spam detected in the first six months of 2006 was related to health services and products.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Fifty-eight percent of all spam detected worldwide originated in the United States &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Eight of the top ten reported security risks were adware programs.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Three of the top ten new security risks are what Symantec calls &lt;em&gt;misleading applications&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Two of these results are quite expected but still the most interesting: an average of 28 days for vulnerability exposure, and 54% of mail traffic made by spam.&lt;br /&gt;While I'm well persuaded preventing new threats is impossible at the moment, I wonder why the security industry is failing so miserably in mitigating damage.&lt;br /&gt; &lt;br /&gt;I strongly recommend to read the whole &lt;a href="http://www.symantec.com/specprog/threatreport/ent-whitepaper_symantec_internet_security_threat_report_x_09_2006.en-us.pdf"&gt;Internet Security Threat Report - September 2006&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=BYo2x9Zb"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/internet-security-threat-report-h1.html" title="Internet Security Threat Report - H1 2006" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115997579554726323" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115997579554726323" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115997579554726323" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115982069800479004</id><published>2006-10-02T22:04:00.000+02:00</published><updated>2006-10-03T00:59:51.663+02:00</updated><title type="text">Microsoft on parental control with OneCare Family Safety</title><content type="html">&lt;!-- google_ad_section_start --&gt;I already wrote the parental control / Internet filtering security tools are so rare, &lt;a href="http://www.securityzero.com/2006/08/free-parental-control-tools.html"&gt;mentioning free solutions available today on the market&lt;/a&gt; and considering possibility &lt;a href="http://www.securityzero.com/2006/06/google-could-release-content-filtering.html"&gt;Google could release something in this space&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;While waiting for Google, I wanted to try what Microsoft is doing at least in the home market with its new Windows Live OneCare Family Safety (I bet parents out there already got confused trying to understand which is the name of the product).&lt;br /&gt;&lt;br /&gt;The new solution has just been released in beta and it's offered under the umbrella of Windows Live initiative. So this is just a first look at features, I didn't try to find bugs, test workarounds or evaluate URL database consistency in the product (for a public attack at a beta product you better ask Symantec an help...).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;After &lt;a href="http://fss.live.com"&gt;enrolling for the beta&lt;/a&gt;, the very first thing to do is download the OneCare Family Safety (OFS from here) and install it on all home PCs.&lt;br /&gt;Then it's time to go online with a browser and reach the OFS Settings Manager, where I need to add my children accounts and decide how to practice my despotic control over my family (but with so much love):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_console-724895.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_console-776303.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;I don't have children yet but let's imagine I have a 20 years-old son and a little 13 years-old daughter. OFS helps me monitor and protect both of them despite different needs and interaction with Internet they have.&lt;br /&gt;&lt;br /&gt;For my brave son I want to allow maximum freedom, but remember him he's still young. So I allow his account to surf the whole Internet without limitations, but enable a warning screen when he reaches porn sites.&lt;br /&gt;&lt;br /&gt;For my sweet little daughter I still want maximum protection, so I block all categories except &lt;em&gt;Sexual Education&lt;/em&gt; (this is a default setting...I doubt a father would allow such category without being obliged with blackmail). &lt;br /&gt;I also add a custom site to be blocked, MySpace, which I heard being so dangerous in these days.&lt;br /&gt;Finally, I also enable web monitoring so anything my daughter will do, blocked or not, I will know:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_categories-793111.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_categories-734089.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Done. At this point I have absolutely nothing else to do: my home computers are protected by the OFS client so nobody can access Internet without logging in with his/her OFS account.&lt;br /&gt;Obviously I installed the client with administrative permissions but my children don't use that Windows account to work on the machine (otherwise could be simple to vanish all my efforts).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The first one to approach the new locked machine is my son.&lt;br /&gt;He logs in the OFS client and launch the browser. As configured is free to surf around but after few minutes his restless curiosity for the world brings him to a well-known porn site. &lt;br /&gt;He receives the expected warning:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_warning-767222.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_warning-726650.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;which quickly turns to be a very annoying remind because every single popup summoned by the porn site, is considered porn itself, and the warning window appears every 2 seconds. &lt;br /&gt;He'll eventally give up, closing the browser and signing out from OFS client, embracing the hacking career within few months, just to have his free amount of daily obscene action.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It's time for my little daughter to sit in front of screen: she logs in the OFS client, opens the browser and the very first thing she tries to do is reaching last website my son visited, the porn one.&lt;br /&gt;Luckily OFS recognized her and immediately block access:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_blockedURL-724296.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_blockedURL-701497.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;The very second thing she tries is reaching a wonderful site to meet new friends, which she heard at school: MySpace.&lt;br /&gt;As expected she gets another block but this time she's very committed to reach the site and create a &lt;em&gt;permission request&lt;/em&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_permission_request-787939.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_permission_request-756625.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Few hours later, from the same computer, or remotely from the office, I will be able to see which sites she tried to visit:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_monitor-767732.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_monitor-748457.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;and will be able to see and evaluate her request to reach MySpace:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/FSS_requests_management-743959.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/FSS_requests_management-713299.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Leaving the role of severe daddy and going back serious, I can say OneCare Family Safety is a very promising tool, filling a big void in current market offering, but has a couple of isses to be addressed:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Users management&lt;/strong&gt;&lt;br /&gt;The whole system works only if every family member has a Windows Live ID (the former Passport account), which obliges parents to create new mailboxes and provide passwords to children. &lt;br /&gt;This is a counter-sense considering the amount of malicious spam arriving by email every day.&lt;br /&gt;It's also very annoying and has could be a pain trying to use very old Passport accounts (I had to create a new one to perform this preview), even if they are supported.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Speed&lt;/strong&gt;&lt;br /&gt;Since all web requests have to be transmitted to Microsoft (or at least seems so) and verified against the defined policy before allowing the user to reach a site, there are moments where the navigation is unacceptablly slow, even on a 4MBits ADSL line.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;When the final product will be released we'll see how wide its database will be and how smart the filtering engine will be blocking access to unallowed sites from browser and other applications.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/privacy" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Google" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/One+Care" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/parental+control" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/internet+filtering" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/safety+family" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=kHe43CSk"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/10/microsoft-on-parental-control-with.html" title="Microsoft on parental control with OneCare Family Safety" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115982069800479004" title="3 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115982069800479004" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115982069800479004" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115954266270208417</id><published>2006-09-29T17:11:00.000+02:00</published><updated>2006-09-29T17:11:02.770+02:00</updated><title type="text">Rainbow Tables for MD5</title><content type="html">&lt;!-- google_ad_section_start --&gt;&lt;a href="http://www.securityzero.com/2006/03/myth-of-secure-password-is-ended.html"&gt;Rainbow Table method works great with Windows password hashing algoritms&lt;/a&gt;. But it can be applied to other hashing algorithms, like the ubiquitous MD5.&lt;br /&gt;&lt;br /&gt;A new website, &lt;a href="http://www.freerainbowtables.com"&gt;Free Rainbow Tables&lt;/a&gt;, just started its business and the first offering is a great set of 36 tables for lower alphanumeric strings hashed with MD5, from 1 to 8 characters. For free obviously.&lt;br /&gt;&lt;br /&gt;And it's just the beninning since creators developed a Windows distributed application to spend free computation time generating new or extended tables.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/cracking" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Rainbow+Tables" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/MD5" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/authentication" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=AHkGNRCV"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/rainbow-tables-for-md5.html" title="Rainbow Tables for MD5" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115954266270208417" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115954266270208417" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115954266270208417" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115943888521271323</id><published>2006-09-28T12:21:00.000+02:00</published><updated>2006-09-28T12:21:25.226+02:00</updated><title type="text">SMAU 2006</title><content type="html">This year I'll be present at the italian event &lt;a href="http://www.smau.it/english/index.asp"&gt;SMAU 2006&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I'll attend the October 6th day only, Friday (whole day), and I'd be happy to meet some Security Zero italian readers.&lt;br /&gt;So if you partecipate at the exhibition look for me at the Microsoft booth, along with other &lt;a href="http://mvp.support.microsoft.com/default.aspx"&gt;Most Valuable Professionals (MVP)&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;See you there!&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/SMAU" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=ySZJpZkD"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/smau-2006.html" title="SMAU 2006" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115943888521271323" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115943888521271323" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115943888521271323" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115926328529635974</id><published>2006-09-26T11:34:00.000+02:00</published><updated>2006-09-26T11:34:45.316+02:00</updated><title type="text">Release: Microsoft Threat Analysis &amp; Modeling 2.0</title><content type="html">&lt;!-- google_ad_section_start --&gt;Threat Analysis &amp;amp; Modeling is one of that free tools you letting you think Microsoft could do incredible things in security.&lt;br /&gt;&lt;br /&gt;Threat modeling is an analysis process aimed to identify characteristics of an application and potential threats they are exposed to.&lt;br /&gt;And, as I already said during beta, this new version perform the task in an impressive way.&lt;br /&gt;&lt;br /&gt;Here some of the new features:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;TreeView Navigation with visibility to all nodes at all times&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Wizard based threat model creation&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Default Attack library with descriptive countermeasure guidance&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Automatic Threats and Use Cases generation&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Consolidated Call Flow (System Flow), Attack Surface, Threat Tree are some of the few visualizations available, which can all be exported to Visio&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Exportable Analytics and Reports to HTML&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Import 1.0 Threat Model&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Export countermeasures and attack test cases to Visual Studio Team Foundation Server (TFS)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Import SDM Deployment Reports from VSTA&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Copy Paste and Drag-&amp;-Drop features&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enhanced Find Feature&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The new wizard is surely the most notable improvement, helping you defining all application aspects, from users to services, from data to components, from business objectives to relevancies, at a very deep level of detail:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityzero.com/uploaded_images/Threat_modeling-705616.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/Threat_modeling-799143.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Microsoft has also been so smart to create a whole video series to introduce you the tool: &lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=29a6d444-9954-41f3-9666-3688417b5e08&amp;displaylang=en"&gt;What is Microsoft Application Threat Modeling&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=47&amp;p=1&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=29a6d444-9954-41f3-9666-3688417b5e08&amp;u=details.aspx%3ffamilyid%3d28A7E041-8909-4084-8B05-06C3135E2A16%26displaylang%3den"&gt;Creating a Threat Model - Define Application Requirements&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=47&amp;p=2&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=29a6d444-9954-41f3-9666-3688417b5e08&amp;u=details.aspx%3ffamilyid%3dAD067E37-FFBC-4972-BE1E-1DB3854E328A%26displaylang%3den"&gt;Creating a Threat Model - Define Application Architecture&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=47&amp;p=3&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=29a6d444-9954-41f3-9666-3688417b5e08&amp;u=details.aspx%3ffamilyid%3d7D774941-D7B7-4776-B711-22B08FE7C67A%26displaylang%3den"&gt;Creating a Threat Model - Model&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=47&amp;p=4&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=29a6d444-9954-41f3-9666-3688417b5e08&amp;u=details.aspx%3ffamilyid%3d2AC3A039-A3A3-490E-9223-ADB16EA8F9A8%26displaylang%3den"&gt;Creating a Threat Model - Assimilation&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=47&amp;p=5&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=29a6d444-9954-41f3-9666-3688417b5e08&amp;u=details.aspx%3ffamilyid%3d415DD8FE-3778-471A-AF55-2C4222431EB5%26displaylang%3den"&gt;Creating a Threat Model - Measure&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Check the development team blog &lt;a href="http://blogs.msdn.com/threatmodeling/default.aspx"&gt;here&lt;/a&gt; and obviously download the tool &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=334ad466-8b53-4440-8ff0-6ac8142d9198&amp;displaylang=en"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Meanwhile I still wonder if I could have something similar for network security. Microsoft are you listening?&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Threat+Analysis" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=8enuBrlv"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/release-microsoft-threat-analysis.html" title="Release: Microsoft Threat Analysis &amp;amp; Modeling 2.0" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115926328529635974" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115926328529635974" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115926328529635974" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115920278843974637</id><published>2006-09-25T18:45:00.000+02:00</published><updated>2006-09-25T18:46:28.470+02:00</updated><title type="text">Check Point losing key figures</title><content type="html">&lt;!-- google_ad_section_start --&gt;CRN &lt;a href="http://www.channelweb.co.uk/crn/news/2163391/check-point-defiant-following"&gt;revealed&lt;/a&gt; Check Point just lost 2 key persons few days ago:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Viv Francis, EMEA Channel Manager (moved to Symbol Technologies)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Niall Moynihan, founder of Check Point UK and Ireland and Africa Country Manager, (moved to Cisco)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The most interesting thing is &lt;a href="http://www.computing.co.uk/crn/news/2164825/moynihan-takes-cisco-management"&gt;a sentence&lt;/a&gt; from Moynihan:&lt;br /&gt;&lt;blockquote&gt;Moving to Cisco was an easy choice because it has a clear roadmap and vision. Every day I’m seeing more positive developments&lt;/blockquote&gt;&lt;br /&gt;I always said Check Point is an undiscussed market leader in firewall segment but it has a very evident chaotic development model.&lt;br /&gt;This statement seems to indirectly confirm my judgement.&lt;br /&gt;&lt;br /&gt;The biggest question is: are these key figures leaving before &lt;a href="http://www.securityzero.com/2006/08/hp-could-acquire-check-point.html"&gt;Check Point is acquired&lt;/a&gt; (despite denial from its CEO)?&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Check+Point" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/VPN-1" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Cisco" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=b6QLhALm"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/check-point-losing-key-figures.html" title="Check Point losing key figures" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115920278843974637" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115920278843974637" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115920278843974637" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115909202442201792</id><published>2006-09-24T12:00:00.000+02:00</published><updated>2006-09-24T12:00:24.503+02:00</updated><title type="text">Release: ISA Server 2006 Management Pack for MOM 2005</title><content type="html">&lt;!-- google_ad_section_start --&gt;Microsoft released a refreshed management pack for monitoring the new &lt;a href="http://www.securityzero.com/2006/08/release-microsoft-isa-server-2006-and.html"&gt;ISA Server 2006&lt;/a&gt; in Operation Manager (MOM) 2005. &lt;br /&gt;&lt;br /&gt;Luckily it supports older versions 2000 and 2004.&lt;br /&gt;&lt;br /&gt;Download it &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=f6515332-e72f-4860-af02-983a95501452&amp;DisplayLang=en"&gt;here&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/firewall" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/ISA+Server" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/MOM" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=YlPv6FtP"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/release-isa-server-2006-management.html" title="Release: ISA Server 2006 Management Pack for MOM 2005" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115909202442201792" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115909202442201792" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115909202442201792" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115883660645415877</id><published>2006-09-21T13:02:00.000+02:00</published><updated>2006-09-21T13:05:27.420+02:00</updated><title type="text">Free digital certificates for servers, applications and code</title><content type="html">&lt;!-- google_ad_section_start --&gt;Many already know some commercial certificate authorities like Thawte (&lt;a href="http://www.verisign.com/printablePages/page_2003121518083227.html"&gt;acquired by VeriSign in 2000&lt;/a&gt;) already offers free digital certificates.&lt;br /&gt;What not everybody knows is these are client certificates only, which means cannot be installed in a web server for example.   &lt;br /&gt;&lt;br /&gt;If we are in need of a server digital certificate for lab environment or we plan to use it only inside your company, then &lt;a href="http://www.securityzero.com/2006/01/how-to-create-self-signed-ssl.html"&gt;we can create a self-signed one&lt;/a&gt;.&lt;br /&gt;But if we need a worldwide trusted server certificate we'll have to pay for it.&lt;br /&gt;&lt;br /&gt;Unless we turn to &lt;a href="http://www.cacert.org"&gt;CAcert&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;CAcert is a no-profit Certificate Authority based in New South Wales, Australia, and running since 2002 which issues client and server X.509 Class 3 digital certificates for free.&lt;br /&gt;&lt;br /&gt;Client certificates are typically used for email encryption and/or authentication verification.&lt;br /&gt;Lately they are also used for instant messaging encryption as well. And in the near future will probabily be the most used tool to secure VoIP communications.&lt;br /&gt;&lt;br /&gt;Server certificates are instead used for securing and providing authentication verification from a vast range of servers, from web servers to mail servers, up to VPN gateways (where is much safer running a digital certificates peers recognition with IPSec instead of exchanging a secret).&lt;br /&gt;CAcert certificates support all these use and can be used in mail servers to secure all three major protocols: POP3, SMTP and IMAP.&lt;br /&gt;&lt;br /&gt;CAcert certs are also usable as so-called code signing certificates, allowing developers to provide identity verification for their installers, Java web applets or .NET framework executables.  &lt;br /&gt;Unfortunately (or fortunately) this kind of certificates are not immediately available like standard client and server certificates mentioned above, but requester have to enroll a special process to assure his identity.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The biggest issue with CAcert certificates is they are not recognized &lt;em&gt;out-of-the-box&lt;/em&gt;: CAcert is not included among root certificate authorities in Internet Explorer, Firefox and Opera, so everybody interacting with these certs have to import the CAcert certificate inside their operating system.&lt;br /&gt;&lt;br /&gt;This situation will eventually change in the future since more and more distributions are providing default support to CAcert.&lt;br /&gt;Among existing ones today we have: CentOS, Debian, FreeBSD, Gentoo, Knoppix. &lt;a href="http://wiki.cacert.org/wiki/InclusionStatus"&gt;Others will come&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Despite this limitation in many scenarios adopting a CAcert is still better than generating self-signed certificates: providing authentication for several tents or hundreds of servers for example would be unpracticable with self-signed certs, since all of them should be imported in clients.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Another less severe issue with these certificates is they don't contain any personal information immediately after release.&lt;br /&gt;&lt;br /&gt;When a new free certificate is issued it contains the only information the certificate authority can easily verify: our email address for client certificates and domain name for server certificates.&lt;br /&gt;If we want CAcert to certify our email address or our domain name are linked to a real person or company identity we have to prove that identity.&lt;br /&gt;This is done involving human verification of real world documents.&lt;br /&gt;&lt;br /&gt;Usually called Web of Trust (WoT) CAcert defines it &lt;em&gt;Assurance Program&lt;/em&gt;, but the principle behind the process is identical:&lt;br /&gt;some designed persons, &lt;em&gt;assurers&lt;/em&gt;, around the world can verify our identity manually checking photo ID documents, and assign us a limited amount of points.&lt;br /&gt;&lt;br /&gt;A requester is obliged to let serveral different assurers verify his identity, and he too is called to verify identity of other requesters to reach a certain score.&lt;br /&gt;After reaching the required amount of points our certificate is enhanced and can contain more personal data, including for example company name and address.&lt;br /&gt;&lt;br /&gt;Obtain a physical identity verification by assurers is not very easy (at the moment the program counts around 7,000 assurers worldwide) and could cost some money:&lt;br /&gt;while CAcert doesn't charge for the service, sometimes Web of Trust members ask for a small amount of money, &lt;em&gt;for their disturb&lt;/em&gt; (this also happens with Thawte). &lt;br /&gt;&lt;br /&gt;Anyway it's not mandatory having full details in digital certificates to work with them, but once reached the assured status we overcome some other limitations:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;server certificates expire in 24 months instead of 6 (they are in any case renewable)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;client certificates can be used for code signing&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;CAcert is not the only free certification authority available on the net. &lt;br /&gt;Startcom, Linux distributor based in Israel, has &lt;a href="http://cert.startcom.org"&gt;one&lt;/a&gt; existing since less than 2 years, but only issues Class 2 digital certificates.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/endpoint+security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/authentication" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/encryption" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/digital+certificates" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/X.509" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/CAcert" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=6oF0LiQg"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/free-digital-certificates-for-servers.html" title="Free digital certificates for servers, applications and code" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115883660645415877" title="1 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115883660645415877" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115883660645415877" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115862179536579804</id><published>2006-09-19T01:23:00.000+02:00</published><updated>2006-09-19T01:23:15.510+02:00</updated><title type="text">EMC focuses acquisition strategy on security</title><content type="html">&lt;!-- google_ad_section_start --&gt;EMC Corporation (EMC2) is worldwide known as leader in the high-end storage market.&lt;br /&gt;&lt;br /&gt;The company acquired several companies, including LEGATO backup solution provider and &lt;a href="http://www.securityzero.com/2006/05/microsoft-isa-server-looses-high.html"&gt;Rainfinity&lt;/a&gt; high-availability solution provider, in the last 5 years from different markets but gained popularity among the masses after acquiring VMware, the leader in server virtualization (if you read my blog &lt;a href="http://www.virtualization.info"&gt;virtualization.info&lt;/a&gt; you know everything about this story). &lt;br /&gt;&lt;br /&gt;After VMware EMC comes back in the security area and buy in rapid succession RSA, leader in token-based authentication, and &lt;a href="http://www.emc.com/news/emc_releases/showRelease.jsp?id=4605&amp;l=en&amp;c=US"&gt;Network Intelligence&lt;/a&gt;, one of the few players in the &lt;a href="http://www.securityzero.com/2005/02/need-for-security-event-managers.html"&gt;Security Event Manager (SEM)&lt;/a&gt; segment.&lt;br /&gt;&lt;br /&gt;Where EMC is going? &lt;br /&gt;&lt;br /&gt;At first sight they are building fundamental blocks of security around data they store: availability (Rainfinity), reliability (LEGATO), accessibility (RSA) and auditing (Network Intelligence).&lt;br /&gt;But at the moment there isn't a clear integration plan between acquired technologies. It's evident looking at the announced rearrangement strategy, where RSA maintains its brand name but leads the whole security department, where Network Intelligence becomes a RSA business unit, where no word has been said about destiny of previously acquired security firms.&lt;br /&gt; &lt;br /&gt;EMC have to detail how rearrangement will be done exactly and to prove real integration, otherwise will only generate confusion among customers, weakening all brands images and appearing as the new &lt;a href="http://www.securityzero.com/2005/10/symantec-resistance-is-futile-you-will.html"&gt;Symantec of Borg&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/SEM" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/authentication" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/auditing" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=vBhuFuQq"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/emc-focuses-acquisition-strategy-on.html" title="EMC focuses acquisition strategy on security" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115862179536579804" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115862179536579804" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115862179536579804" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115825453422495456</id><published>2006-09-14T19:16:00.000+02:00</published><updated>2006-09-14T19:22:14.256+02:00</updated><title type="text">A free network analyzer from WildPackets</title><content type="html">&lt;!-- google_ad_section_start --&gt;After talking about &lt;a href="http://www.securityzero.com/2006/09/writing-firewall-rules-with-your.html"&gt;enhanced capabilities of Wireshark&lt;/a&gt; (formerly Ethereal) and &lt;a href="http://www.securityzero.com/2006/09/microsoft-opens-network-monitor-3-beta.html"&gt;new style of upcoming Microsoft Network Monitor 3&lt;/a&gt;, another sniffer is worth to mention: WildPackets OminPeek.&lt;br /&gt;&lt;br /&gt;Originally called EtherPeek, OmniPeek offers more than a basic sniffer, with statistical analysis of traffic, advanced protocol decoders and support for hardware capture card (to name a few).&lt;br /&gt;It's a highly appreciated product along with Observer (Network Instruments) and Fluke (Fluke Networks).&lt;br /&gt;&lt;br /&gt;Since some time WildPackets offers for free the OminPeek 4.0 Personal Edition.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/OmniPeek4-766687.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/OmniPeek4-755521.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It has some limitations:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Able to capture from a single network interface at one time only&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Expert analysis limited to 25 active conversations&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Licensed for use on networks up to 200 nodes only&lt;/li&gt;&lt;br /&gt;&lt;li&gt;No support for matrix switches&lt;/li&gt;&lt;br /&gt;&lt;li&gt;No specialized Gigabit or WAN Analyzer Card support&lt;/li&gt;&lt;br /&gt;&lt;li&gt;No VoIP analysis experts or options&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;but it's still fully working and is worth &lt;a href="http://www.wildpackets.com/products/omni/omnipeek_personal/overview"&gt;a full evaluation&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;OminPeek has some clear advantages over Wireshark in statistical analysis (which is updated in real-time, during capture): &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/OmniPeek_Analysis-764480.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/OmniPeek_Analysis-742827.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;while it suffers in filtering capabilities (Wireshark language filtering is unbeatable).&lt;br /&gt;Anyway it can count on a very interesting filtering builder which someone could prefer over Wireshark boolean conditions:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/OmniPeek_filterbuilder-750199.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/OmniPeek_filterbuilder-744398.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Until Wireshark will not get serious enhancements on traffic analysis, I would consider OmniPeek Personal it's mandatory complement.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sniffer" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/WildPackets" rel="tag"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://technorati.com/tag/OminPeek" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=Ny83Ln9M"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/free-network-analyzer-from-wildpackets.html" title="A free network analyzer from WildPackets" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115825453422495456" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115825453422495456" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115825453422495456" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115815139321556588</id><published>2006-09-13T14:41:00.000+02:00</published><updated>2006-09-13T14:59:41.533+02:00</updated><title type="text">Endpoint security interoperability and standards</title><content type="html">&lt;!-- google_ad_section_start --&gt;Endpoint security could revolutionize corporate security. I say this thing since a couple of years.&lt;br /&gt;But endpoint security effectiveness is flawed by at least 2 big issues:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;it cannot handle machines where no endpoint agents are present&lt;/li&gt;&lt;br /&gt;&lt;li&gt;it lacks of interoperability&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;This second point is the most important at the moment: actual solutions aren't based on a standard and aren't interoperable by default.&lt;br /&gt;&lt;br /&gt;A customer adopting the Check Point endpoint security solution (Total Access Protection or TAP) will not be able to integrate it with Cisco equipement featuring Network Admission Control (NAC) endpoint security implementation.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://newsroom.cisco.com/dlls/partners/news/2004/pr_prod_10-18.html"&gt;2 year ago Cisco and Microsoft annouced a cooperation to deliver interoperable endpoint security&lt;/a&gt;. But since that announcement nothing happened (also because Microsoft endpoint security solution, Network Access Protection or NAP, will appear not earlier than another year and a half).&lt;br /&gt;&lt;br /&gt;Now Cisco and Microsoft are &lt;a href="http://www.microsoft.com/presspass/press/2006/sep06/09-06SecStandardNACNAPPR.mspx"&gt;re-announcing their partnership for NAC-NAP interoperability&lt;/a&gt; at Security Standard conference. &lt;br /&gt;&lt;br /&gt;Again? Yes, but this time they made a little more, producing &lt;a href="http://download.microsoft.com/download/d/0/8/d08df717-d752-4fa2-a77a-ab29f0b29266/NAC-NAP_Whitepaper.pdf"&gt;a 8-pages whitepaper&lt;/a&gt; (half marketing half technical), about the interoperability.&lt;br /&gt;&lt;br /&gt;The central point of this interoperability is the endpoint security agent, which is currently integrated in Windows XP SP2 (with some limitations) and in Vista and Windows &lt;em&gt;codename Longhorn Server&lt;/em&gt; beta builds: the Microsoft NAP agent will serve also as Cisco NAC agent.&lt;br /&gt;Luckily the agent will be updated by online Windows Update service or offline Windows Server Update Services (WSUS).&lt;br /&gt;&lt;br /&gt;Meanwhile Cisco will continue to develop its own NAP client (Cisco Trust Agent) for non Microsoft operating systems and possibly for Microsoft OSes prior to Windows Vista.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How customers adopting Check Point TAP or Sygate NAC (now acquired by &lt;a href="http://www.securityzero.com/2005/10/symantec-resistance-is-futile-you-will.html"&gt;Symantec of Borg&lt;/a&gt;) other endpoint security solutions will be able to integrate on this? Has still to be known.&lt;br /&gt;&lt;br /&gt;Obviously this complexity could be addressed creating a standard. The real problem is an attempt to standardize already exists but not all companies are embracing it.&lt;br /&gt;&lt;br /&gt;It's called &lt;a href="http://www.trustedcomputinggroup.org/groups/network"&gt;Trusted Network Connect&lt;/a&gt; and its first draft appeared in May 2005. &lt;br /&gt;By chance both Check Point and Sygate immediately adhered to it, while others like Juniper, Nortel, StillSecure added or announced support to it this year.&lt;br /&gt;&lt;br /&gt;Microsoft &lt;a href="https://www.trustedcomputinggroup.org/news/press/tcg/2005/TNC_and_NAP_news_release.pdf#search=%22Trusted%20Network%20Connect%20microsoft%22"&gt;announced&lt;/a&gt; plans to make its NAP compliant to TNC standards on April 2005 while Cisco didn't.&lt;br /&gt;&lt;br /&gt;So while you ask yourself why Cisco is once again preventing to return on your previous investments, you may want to look at a wonderful summary scheme about NAP-NAC-TNC interoperability, created by &lt;a href="http://www.opus1.com/o/about.html"&gt;Opus One&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/NAP-NAC-TNC-794112.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/NAP-NAC-TNC-785944.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;You may also want to check for further reference a needful terms comparison for all three implementations in the &lt;a href="http://www.opus1.com/nac/IETFdraft-thomson-nea-problem-statement-03.txt"&gt;standardization assessment&lt;/a&gt; published by IETF in June 2006.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/VPN-1" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Cisco" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/PIX" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/endpoint+security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/NAC" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/NAP" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/TNC" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Trusted+Network+Connect" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=G4lBTDyI"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/endpoint-security-interoperability-and.html" title="Endpoint security interoperability and standards" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115815139321556588" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115815139321556588" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115815139321556588" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115797744205980605</id><published>2006-09-11T14:22:00.000+02:00</published><updated>2006-09-11T14:51:26.286+02:00</updated><title type="text">Microsoft opens Network Monitor 3 beta 2 to public</title><content type="html">&lt;!-- google_ad_section_start --&gt;After many years the Microsoft network sniffer, Network Monitor (friendly called NetMon), is coming back.&lt;br /&gt;&lt;br /&gt;Network Monitor 2.1 is included as optional component in every Windows NT/2000 installation but has a severe limitation: it cannot put the network interface in &lt;em&gt;promiscuous mode&lt;/em&gt;, preventing capture of all packets passing on the cable.&lt;br /&gt;To have a full version of Network Monitor 2.1 you have to buy Microsoft System Management Server (SMS) 1.2 or 2.0.&lt;br /&gt;&lt;br /&gt;Upcoming Network Monitor 3 will offer several new features and will finally be an uncapped, free, stand-alone application for Windows XP/2003/Vista/codename Longhorn (both 32 and 64bits):&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Real time capture and display of frames &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Simultaneous capture on multiple network adapters&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Multiple simultaneous capture sessions&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Network conversations and a tree view displaying frames by conversation &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enhanced capture/display filtering (with &lt;a href="http://en.wikipedia.org/wiki/IntelliSense"&gt;intelli-sense&lt;/a&gt;)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;A new script-based protocol parser language (NPL), and script-based parsers &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/NetMon3_capture-731766.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/NetMon3_capture-727767.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;The last feature is particularly interesting, permitting network experts  to create new protocol decoders or complex packet manipulations in an easy and quick way (in previous releases writing a protocol parser implied writing a DLL). &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/NetMon3_parsers-763917.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/NetMon3_parsers-758571.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;With NPL (NetMon Parser Language) Microsoft has a big chance to involve the network and security communities around Network Monitor and should arrange a &lt;em&gt;Parsers Center&lt;/em&gt; or something like that.&lt;br /&gt;&lt;br /&gt;We'll see if it will be able to compete with Wireshark (formerly Ethereal) and its &lt;a href="http://www.securityzero.com/2006/09/writing-firewall-rules-with-your.html"&gt;new enhanced features&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Enroll for the beta &lt;a href="http://connect.microsoft.com"&gt;here&lt;/a&gt; and check dedicated beta newsgroup &lt;a href="nntp://microsoft.beta.networkmonitor3.general"&gt;here&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sniffer" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Wireshark" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Ethereal" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Network+Monitor" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=CZKgZyLv"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/microsoft-opens-network-monitor-3-beta.html" title="Microsoft opens Network Monitor 3 beta 2 to public" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115797744205980605" title="4 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115797744205980605" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115797744205980605" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115774258892022730</id><published>2006-09-08T21:09:00.000+02:00</published><updated>2006-09-08T21:10:04.196+02:00</updated><title type="text">The need for antivirus technologies</title><content type="html">&lt;!-- google_ad_section_start --&gt;Roger Grimes, fellow CISSP and Microsoft MVP, wrote &lt;a href="http://www.infoworld.com/article/06/09/08/37OPsecadvise_1.html"&gt;an article about value of antivirus products&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;He reports antivirus tools are unable to recognize and clean a lot of recent malware code. But most of all he firmly claims they are unnecessary to stay uninfected. Pure truth.&lt;br /&gt;&lt;br /&gt;Antivirus shouldn't even be called this way. &lt;em&gt;Anti&lt;/em&gt; is a term leading to think about proactivity, while antivirus solutions are just virus cleaners. Something to use when you are already infected.&lt;br /&gt;&lt;br /&gt;The most important point is Roger never suffered an infection even if he never used an antivirus. Me too, and probably many others.&lt;br /&gt;He never got infected because he blocks source of malware instead of allowing them and then clean damage.&lt;br /&gt;&lt;br /&gt;He does what I would call traffic sanitization: &lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;blocks unwanted traffic using a personal firewall&lt;/li&gt;&lt;br /&gt;&lt;li&gt;blocks unwanted HTML malware converting incoming email in plaintext and (probably) using an ad-blocker in its browser&lt;/li&gt;&lt;br /&gt;&lt;li&gt;blocks unwanted attachments using an antispam tool&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Plus he maintains his system in good health, hardening and patching it every time is needed.&lt;br /&gt;&lt;br /&gt;It's all the things you need to remain uninfected? It's true the fact he is a high profile security guy doens't help here?&lt;br /&gt;I don't think so. And even if so, I still see many problems in this approach (which is the one I apply too).&lt;br /&gt;&lt;br /&gt;For sure Roger knowledge granted him capability to recognize, choose, configure and update security tools mentioned above. &lt;br /&gt;No matter if a less experienced user (his daughter) is then able to run virus-free even without skills. He secured the system at beginning. &lt;br /&gt;It's easy to avoid troubles when every tool is at the right place.&lt;br /&gt;&lt;br /&gt;Also, every time a threat bypass security defenses experience becomes the most powerful tool. &lt;br /&gt;In some cases, when surfing or reading emails, there is something strange around and only experienced users are able to recognize the risk they are going to face, even if the malware or the technique is completely new and they never saw it before.&lt;br /&gt;&lt;br /&gt;Not every system administrator or home user out there has same skills. But even having them, how much time costs deploying all mentioned tools? Surely 10 times what you would spend configuring and updating an antivirus tool.&lt;br /&gt;&lt;br /&gt;Antivirus are useless and should disappear not because other tools exist and defend better, but because the way they try to provide fast and easy protection is fault.&lt;br /&gt;We still need fast and easy protection, but with a different approach.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/antivirus" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=DFpOWQSM"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/need-for-antivirus-technologies.html" title="The need for antivirus technologies" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115774258892022730" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115774258892022730" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115774258892022730" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115753717497156328</id><published>2006-09-06T12:06:00.000+02:00</published><updated>2006-09-06T12:06:14.983+02:00</updated><title type="text">Microsoft releases Security Configuration Wizard for ISA Server 2006</title><content type="html">&lt;!-- google_ad_section_start --&gt;While still much perfectible, Security Configuration Wizard (SCW). almong with WSUS, is one of the best tool Microsoft ever made in its path towards enterprise security leadership.&lt;br /&gt;&lt;br /&gt;I covered it before in  &lt;a href="http://www.securityzero.com/2006/03/hardening-windows-2003-platforms-made.html" target="_blank"&gt;Hardening Windows 2003 platforms made easy&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;SCW has 2 big limits: &lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;it doesn't work on all Windows editions&lt;/li&gt;&lt;br /&gt;&lt;li&gt;its roles cannot be updated with Windows Update or WSUS&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;This second limit obliges Microsoft to release a new version every time a new backend plaftorm is out, but since this process seems pretty time consuming it happens only when a critical product is released.&lt;br /&gt;&lt;br /&gt;It's the case of the new &lt;a href="http://www.securityzero.com/2006/08/release-microsoft-isa-server-2006-and.html" target="_blank"&gt;ISA Server 2006&lt;/a&gt;, for which Microsoft silently published an updated SCW on early August.&lt;br /&gt;&lt;br /&gt;It works for both Standard and Enterprise edition and can be downloaded &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=2748A927-BD3C-4D87-80FA-8687D5E2AB35&amp;displaylang=en" target="_blank"&gt;here&lt;/a&gt;.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/hardening" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/ISA+Server" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/SCW" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=LSs3N86v"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/microsoft-releases-security.html" title="Microsoft releases Security Configuration Wizard for ISA Server 2006" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115753717497156328" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115753717497156328" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115753717497156328" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115738641451517565</id><published>2006-09-04T18:13:00.000+02:00</published><updated>2006-09-04T18:13:34.546+02:00</updated><title type="text">Whitepaper: How to Protect Insiders from Social Engineering Threats</title><content type="html">&lt;!-- google_ad_section_start --&gt;Microsoft published a 37-pages paper about a rarely-treated topic: social engineering.&lt;br /&gt;&lt;br /&gt;The large majority of people listening at social engineering examples usually smiles or laughes, thinking about action movies like Mission Impossible or 007 series.&lt;br /&gt;Security professionals aren't much different: in years of security courses I rarely found persons sensible to the topic, or taking it seriously.&lt;br /&gt;&lt;br /&gt;The biggest reason for such behaviour is unbelief. People simply don't believe someone is able to threat service desk like it happens on the movies.&lt;br /&gt;Even those security professionals who are aware of social engineering, usually have an inner conviction that there are no real chances an attacker could use social engineering techniques.&lt;br /&gt;&lt;br /&gt;This lead to a numer of documents about this topic near to zero.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=05033e55-aa96-4d49-8f57-c47664107938&amp;displaylang=en" target="_blank"&gt;How to Protect Insiders from Social Engineering Threats&lt;/a&gt;, aimed to SMB companies, is interesting because, while very introductory, touches several points, including how to plan a reception hall:&lt;br /&gt;&lt;blockquote&gt;To attack your organization, social engineering hackers exploit the credulity, laziness, good manners, or even enthusiasm of your staff. Therefore it is difficult to defend against a socially engineered attack, because the targets may not realize that they have been duped, or may prefer not to admit it to other people. The goals of a social engineering hacker-someone who tries to gain unauthorized access to your computer systems-are similar to those of any other hacker: they want your company's money, information, or IT resources.&lt;br /&gt;&lt;br /&gt;A social engineering hacker attempts to persuade your staff to provide information that will enable him or her to use your systems or system resources. Traditionally, this approach is known as a confidence trick. Many midsize and small companies believe that hacker attacks are a problem for large corporations or organizations that offer large financial rewards. Although this may have been the case in the past, the increase in cyber-crime means that hackers now target all sectors of the community, from corporations to individuals. Criminals may steal directly from a company, diverting funds or resources, but they may also use the company as a staging point through which they can perpetrate crimes against others. This approach makes it more difficult for authorities to trace these criminals...&lt;/blockquote&gt;&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/privacy" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/social+engineering" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=6uqNvHHo"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/whitepaper-how-to-protect-insiders.html" title="Whitepaper: How to Protect Insiders from Social Engineering Threats" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115738641451517565" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115738641451517565" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115738641451517565" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115719974323135936</id><published>2006-09-02T14:20:00.000+02:00</published><updated>2006-09-02T14:27:23.870+02:00</updated><title type="text">Writing firewall rules with your sniffer</title><content type="html">&lt;!-- google_ad_section_start --&gt;Wireshark, the most popular network analyzer in the world (once known as Ethereal), reached &lt;a href="http://www.wireshark.org/news/20060823.html" target="_blank"&gt;version 0.99.3&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This new release introduces some very interesting feautres:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;support for ESP, Kerberos, and SSL decryption&lt;/li&gt;&lt;br /&gt;&lt;li&gt;support for USB wireless adapters&lt;/li&gt;&lt;br /&gt;&lt;li&gt;firewall rules writing capability&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Last 2 of them deserve a detailed explaination.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Support for USB wireless adapters is at the moment limited to a special USB 2.0 dongle CACE Technologies, the company developing Wireshark, is selling online.&lt;br /&gt;It costs $189 which is pretty high if you consider &lt;a href="http://www.newegg.com/Product/ProductList.asp?Submit=ENE&amp;N=2050410031&amp;Subcategory=31&amp;description=&amp;srchInDesc=usb+wireless+adapter&amp;minPrice=&amp;maxPrice=" target="_blank"&gt;the average price for such gear is $50&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Wireshark is able to put the wireless adapter in &lt;em&gt;monitor mode&lt;/em&gt; (the equivalent of promiscous mode in the Ethernet world) thanks to a new packet driver for Windows: &lt;a href="http://www.cacetech.com/products/airpcap.htm" target="_blank"&gt;AirPcap&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;AirPcap is a different project from the universal packet driver originally deleloped by Politecnico di Torino italian university, &lt;a href="http://www.winpcap.org/" target="_blank"&gt;WinPcap&lt;/a&gt; (even if they are fully integrated since &lt;a href="http://www.winpcap.org/install/" target="_blank"&gt;new version 4.0 beta 1&lt;/a&gt;), and is not included in the standard Wireshark package.&lt;br /&gt;&lt;br /&gt;Unfortunately there are no informations about which vendor manifactures the CACE dongle or about AirPcap compatibility with other USB adapters.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Firewall rules writing capability is much more unexpected.&lt;br /&gt;&lt;br /&gt;Wireshark is now able to build simple ACL rules for most popular firewalls, including Windows Firewall, starting from any captured package.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securityzero.com/uploaded_images/wireshark_ACL-737756.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.securityzero.com/uploaded_images/wireshark_ACL-734014.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;The interface is still very raw (it doesn't permit to create multiple rules given a group of selected packets) but the idea in itself is very interesting.&lt;br /&gt;&lt;br /&gt;While I don't think at the moment this feature is particularly useful, the immediate translation of the rule in every major rulebase language is particularly appreciated and has a great educative value.&lt;br /&gt;&lt;br /&gt;I hope to see support for the new &lt;a href="http://www.microsoft.com/technet/community/columns/cableguy/cg0106.mspx" target="_blank"&gt;Windows Vista firewall&lt;/a&gt; (which finally is able to filter for both inbound and outbound directions) soon.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/privacy" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Google" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/antivirus" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/firewall" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Microsoft" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Cisco" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/PIX" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/ASA" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=HnMR7RuY"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/09/writing-firewall-rules-with-your.html" title="Writing firewall rules with your sniffer" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115719974323135936" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115719974323135936" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115719974323135936" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115702654713563766</id><published>2006-08-31T14:15:00.000+02:00</published><updated>2006-09-14T12:57:41.000+02:00</updated><title type="text">HP could acquire Check Point</title><content type="html">&lt;!-- google_ad_section_start --&gt;&lt;a href="http://www.securityzero.com/2005/10/check-point-acquiring-sourcefire.html" target="_blank"&gt;Check Point wasn't able to acquire SourceFire&lt;/a&gt;, but in the end maybe the two companies will be together in any case.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forbes.com/business/2006/08/28/hp-0828markets14.html" target="_blank"&gt;Forbes reported HP is going to massively invest in 2007&lt;/a&gt; and among others a potential target is Check Point. &lt;br /&gt;&lt;br /&gt;This could appear as an answer to growing interest of IBM in security companies, &lt;a href="http://www.securityzero.com/2006/08/ibm-acquires-internet-security-systems.html" target="_blank"&gt;which just acquired Internet Security Systems (ISS)&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;If this acquisition would be confirmed I strongly doubt Check Point would be able to maintain its leadership in firewalls segment: HP could follow IBM path and blend Check Point offering with its customers-oriented services.&lt;br /&gt;Also, HP is not known and trusted as security provider among the large public. Changing the name Check Point VPN-1 in HP VPN-1 would hardly conquer the interest and trust of potential customers.&lt;br /&gt;&lt;br /&gt;I would say this can't be worst than being acquired by &lt;a href="http://www.securityzero.com/2005/10/symantec-resistance-is-futile-you-will.html" target="_blank"&gt;Symantec of Borg&lt;/a&gt;, but I'm not sure.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Update:&lt;/strong&gt; Globes offers another point of view, suggesting &lt;a href="http://www.globes.co.il/serveEN/globes/docView.asp?did=1000129920&amp;fid=1176" target="_blank"&gt;Check Point could be near an acquisition or a merge&lt;/a&gt; with another company of the same size. Possibly the Nokia security division, manifacturing since so many years appliances for Check Point VPN-1.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Second update:&lt;/strong&gt; In &lt;a href="http://software.seekingalpha.com/article/16771"&gt;an interesting analysis&lt;/a&gt; Seeking Alpha reports Check Point's CEO firm intention to not be acquired.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/firewall" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Check+Point" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/VPN-1" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/IDS" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Snort" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/HP" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Nokia" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=GHLmQJQ7"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/08/hp-could-acquire-check-point.html" title="HP could acquire Check Point" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115702654713563766" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115702654713563766" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115702654713563766" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115693462531536411</id><published>2006-08-30T12:43:00.000+02:00</published><updated>2006-08-30T12:43:45.336+02:00</updated><title type="text">The frightening return of Check Point CVP</title><content type="html">&lt;!-- google_ad_section_start --&gt;Few Check Point customers remember or even know what Content Vectoring Protocol (CVP) is.&lt;br /&gt;&lt;br /&gt;CVP, together with URL Filtering Protocol (UFP), are the foundations of a very old technology embedded in Check Point VPN-1 and generally called Content Security.&lt;br /&gt;Content Security is the first attempt of the company to approach application inspection, security the 3 most critical protocols of the current business-over-Internet: HTTP, FTP and SMTP.&lt;br /&gt;&lt;br /&gt;Content Security was already present when Check Point conquered big market shares with its Firewall-1 4.1 (aka 2000), more than 6 years ago, and can be considered the pioneering of modern application inspection. Or, if you prefer, the ancestor of today's Check Point Application Intelligence (AI) / Web Intelligence (WI).&lt;br /&gt;&lt;br /&gt;This ancient technology, still present in recent VPN-1 versions, permits administrators to intercept and inspect application traffic by the use of user-mode daemons and vectoring protocols (CVP and UFP exactly). &lt;br /&gt;Depending on required analysis HTTP, FTP and SMTP can be analized on the VPN-1 machine thanks to user-mode daemons, or sent to a 3rd party Security Server through vectoring protocols.&lt;br /&gt;&lt;br /&gt;Check Point developed around its Content Security a whole consotium called &lt;a href="http://www.opsec.com" target="_blank"&gt;OPSEC&lt;/a&gt; (Open Platform for Security), which permitted partners to develop and integrate new Security Servers with FW-1 through a freely available SDK.&lt;br /&gt;&lt;br /&gt;Capabilities of user-mode daemons are very limited and Check Point itself suggests to approach a 3rd party Security Server.&lt;br /&gt;&lt;br /&gt;At beginning the amount of partners offering their UFP/CVP-compliant solutions was notable, including biggest security players like Websense, TrendMicro, Symantec, etc.&lt;br /&gt;But several factors concurred to reduce support to the OPSEC program during years and, one after another, put existing solutions out of the market.&lt;br /&gt;&lt;br /&gt;First of all was too early: the market was't really ready to embrace application inspection, still being occupied in massively adoption of antivirus and firewalls as first defensive line.&lt;br /&gt;Secondly and mostly performance of UFP/CVP solutions were simply indecent.&lt;br /&gt;&lt;br /&gt;The way Content Security works with 3rd party Security Server imposes the inspected application session to travel back and forth through VPN-1 which acts like a proxy:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Content Security is configured to do antivirus inspection of ongoing traffic with help of a 3rd party antivirus Security Server&lt;/li&gt;&lt;br /&gt;&lt;li&gt;a new FTP session starts from a client on the Internet and wants to reach a protected FTP server&lt;/li&gt;&lt;br /&gt;&lt;li&gt;the client's request of sending a new file triggers Security Server daemon on VPN-1&lt;/li&gt;&lt;br /&gt;&lt;li&gt;the incoming file is intercepted by the user-mode daemon, incapsulated in the CVP and sent to the 3rd party antivirus (meanwhile the FTP session is on hold)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;the 3rd party antivirus checks and possibly disinfects the received file&lt;/li&gt;&lt;br /&gt;&lt;li&gt;the 3rd party antivirus sends back to the firewall the disinfected file through CVP&lt;/li&gt;&lt;br /&gt;&lt;li&gt;the disinfected file is decapsulated from CVP and finally sent to FTP server&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;This scheme has a lot of problems and the most critical is obviously speed.&lt;br /&gt;&lt;br /&gt;Since the born of Content Security a large amount of customers lamented sessions time-out, missing or compromised files, network segments congestions, etc.&lt;br /&gt;And if you consider it works not only with FTP but also with SMTP, you can understand risks in its adoption.&lt;br /&gt;&lt;br /&gt;I won't go any further exploring Content Security problems since you can figure out from yourself. I just will say that depending on these performances, few customers in the world adopted the tecnology, avoiding OPSEC partners to return on investment of producing a dedicated UFP/CVP solution.&lt;br /&gt;So, simply, while still existing Content Security cannot be used anymore.&lt;br /&gt;&lt;br /&gt;Until today.&lt;br /&gt;&lt;br /&gt;Kasperski, which is having a big success these days with &lt;a href="http://www.securityzero.com/2006/08/aol-releases-free-antivirus-but.html" target="_blank"&gt;the inclusion of its engine in the new AOL offering&lt;/a&gt;, just launched a version of its &lt;a href="http://www.kaspersky.com/news?id=196700324" target="_blank"&gt;Anti-Virus 5.5 for Check Point VPN-1&lt;/a&gt; (still called Firewall-1, which is a deprecated name), interacting with CVP.&lt;br /&gt;&lt;br /&gt;The funny thing is official announcement states:&lt;br /&gt;&lt;blockquote&gt;The advanced scalability of the solution makes it eminently suitable for use in the largest organizations that see heavy traffic loads. The system administrator can choose to run multiple copies of the antivirus engine and multiple CVP servers for processing requests from the firewall to meet peaks in traffic volumes. Moreover, the solution is optimized for use on the Intel Xeon platform.&lt;/blockquote&gt;&lt;br /&gt;If you really decide to adopt this solution, pretend a very extensive and assisted pilot on real-world traffic. Otherwise you'll discover Content Security performances too late.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/antivirus" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Symantec" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/firewall" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Check+Point" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/VPN-1" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=1wwX9KDr"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/08/frightening-return-of-check-point-cvp.html" title="The frightening return of Check Point CVP" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115693462531536411" title="1 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115693462531536411" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115693462531536411" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-19938704.post-115680504398322287</id><published>2006-08-29T00:44:00.000+02:00</published><updated>2006-08-29T00:44:04.153+02:00</updated><title type="text">Security Engineering from Wiley available online for free</title><content type="html">&lt;!-- google_ad_section_start --&gt;Did you read the free &lt;a href="http://www.securityzero.com/2006/02/tcpip-guide-from-no-starch-press.html" target="_blank"&gt;TCP/IP Guide&lt;/a&gt; from No Starch Press as I suggested?&lt;br /&gt;&lt;br /&gt;If so it's time to approach more directly security topics. And you are lucky.&lt;br /&gt;&lt;br /&gt; Wiley authorized the online publishing of the whole 640 pages book: &lt;a href="http://www.cl.cam.ac.uk/~rja14/book.html" target="_blank"&gt;Security Engineering: A Guide to Building Dependable Distributed Systems&lt;/a&gt; by Ross J. Anderson. For free.&lt;br /&gt;&lt;br /&gt;Even if this book has been published at beginning of 2001 it's one of the best tome ever published and still represent a fundamental part of every security professional bookshelf.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://taosecurity.blogspot.com/2006/08/security-engineering-book-in-digital.html" target="_blank"&gt;TaoSecurity&lt;/a&gt; for the news.&lt;!-- google_ad_section_end --&gt;&lt;a href="http://technorati.com/tag/Alessandro+Perilli" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/Security+Zero" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/security" rel="tag"&gt;&lt;/a&gt;&lt;a href="http://technorati.com/tag/sicurezza" rel="tag"&gt;&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SecurityZero?a=A3QIue7e"&gt;&lt;img src="http://feeds.feedburner.com/~f/SecurityZero?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://www.securityzero.com/2006/08/security-engineering-from-wiley.html" title="Security Engineering from Wiley available online for free" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=19938704&amp;postID=115680504398322287" title="0 Comments" /><link rel="replies" type="application/atom+xml" href="http://www.securityzero.com/securityzero.xml" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115680504398322287" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19938704/posts/default/115680504398322287" /><author><name>Alessandro Perilli</name><email>noreply@blogger.com</email></author></entry></feed>
