<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Barking Seal</title>
	
	<link>http://www.barkingseal.com</link>
	<description>Applied Trust off-leash: IT infrastructure, security, and performance</description>
	<lastBuildDate>Thu, 29 Jul 2010 03:40:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/barkingseal" /><feedburner:info uri="barkingseal" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Slow network performance for Windows Server 2008 guest on vmware ESXi 4.1</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/HC4byTaR0jc/</link>
		<comments>http://www.barkingseal.com/2010/07/slow-network-performance-for-windows-2008-on-vmware-esxi/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 03:40:12 +0000</pubDate>
		<dc:creator>trent</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1398</guid>
		<description><![CDATA[The older I get, the more lessons I seem to learn (or, not learn) over and over.  Have you ever seen TCP offload work correctly?  Of course not!  I&#8217;ve been bitten by a TCP offload (aka TCP Offload Engine or TOE) problem in just about every environment I&#8217;ve touched in the last 20 years, and [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1402" class="wp-caption alignnone" style="width: 235px"><a href="http://www.barkingseal.com/wp-content/uploads/2010/07/tcp-lego-header.jpg"><img class="size-medium wp-image-1402" title="tcp lego header" src="http://www.barkingseal.com/wp-content/uploads/2010/07/tcp-lego-header-225x300.jpg" alt="tcp lego header" width="225" height="300" /></a><p class="wp-caption-text">TCP header, Lego (tm) style</p></div>
<p>The older I get, the more lessons I seem to learn (or, not learn) over and over.  Have you ever seen TCP offload work correctly?  Of course not!  I&#8217;ve been bitten by a TCP offload (aka TCP Offload Engine or TOE) problem in just about every environment I&#8217;ve touched in the last 20 years, and sadly this week was no exception.</p>
<p>To make a long story short, we have a production vmware ESXi 4.1 host with both Linux (CentOS) and Windows Server 2008 guests.  No problems were reported (or measured) with the Linux guests, but the Win 2008 guests suffered from <span style="text-decoration: underline;">extremely</span> choppy network connections, for common services like Remote Desktop and backups (including lost connections).  As you probably know, I&#8217;m big into actually investigating the underlying cause of a problem rather than randomly throwing darts at it, and as such I grabbed some packet traces with wireshark.  Check this out:</p>
<p><span id="more-1398"></span></p>
<div id="attachment_1400" class="wp-caption alignnone" style="width: 670px"><a href="http://www.barkingseal.com/wp-content/uploads/2010/07/offload-bad1.jpg"><img class="size-full wp-image-1400" title="TCP offload bad" src="http://www.barkingseal.com/wp-content/uploads/2010/07/offload-bad1.jpg" alt="TCP offload bad" width="660" height="478" /></a><p class="wp-caption-text">wireshark analysis of poor TCP connection</p></div>
<p>Ouch! That is super ugly (this is across a LAN, btw)!  How can you screw up a single TCP connection so badly in 6 feet of cable?  Probably not the cable (or network), sherlock.  It appears this is a &#8220;known problem.&#8221;    While this problem (described in the vmware article as &#8220;Network performance is very slow and connections drop intermittently&#8221;) seems contrained in the article to vmware guests running on a Windows host, I can attest to this occuring on both ESXi 4.0 Update 1 and ESXi 4.1 hosts with Windows guests.  After following the instructions in this <a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1006619" target="_blank">vmware article</a> to remedy the situation by disabling TCP offload on the Win 2008 guests, they exhibit downright snappy network performance.  Check out the improved trace results:</p>
<div id="attachment_1401" class="wp-caption alignnone" style="width: 672px"><a href="http://www.barkingseal.com/wp-content/uploads/2010/07/offload-good.jpg"><img class="size-full wp-image-1401" title="TCP offload good" src="http://www.barkingseal.com/wp-content/uploads/2010/07/offload-good.jpg" alt="TCP offload good" width="662" height="362" /></a><p class="wp-caption-text">wireshark analysis after disabling TCP offload</p></div>
<p>Moral of the story:  TCP offload always sucks.  Turn it off on Windows Server 2008 vmware guests.</p>
<img src="http://feeds.feedburner.com/~r/barkingseal/~4/HC4byTaR0jc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/07/slow-network-performance-for-windows-2008-on-vmware-esxi/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/07/slow-network-performance-for-windows-2008-on-vmware-esxi/</feedburner:origLink></item>
		<item>
		<title>Now available: Unix and Linux System Administration Handbook, 4th edition</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/iAjAi_KQV2A/</link>
		<comments>http://www.barkingseal.com/2010/07/now-available-unix-and-linux-system-administration-handbook-4th-edition/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:34:10 +0000</pubDate>
		<dc:creator>ben</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[UNIX]]></category>
		<category><![CDATA[USAH]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1386</guid>
		<description><![CDATA[I know you&#8217;ve all been waiting with bated breath for this day:  UNIX and Linux System Administration Handbook, 4th edition, is finally out! More than two years in the making, this edition covers six major operating systems in 1300 pages of fresh deliciousness. Plenty of new topics, including virtualization, green IT, scripting, and modern storage [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.barkingseal.com/wp-content/uploads/2010/07/3DFrontView.jpg"><img class="size-large wp-image-1387 aligncenter" title="ULSAH/4E Cover" src="http://www.barkingseal.com/wp-content/uploads/2010/07/3DFrontView-977x1024.jpg" alt="ULSAH/4E Cover" width="410" height="430" /></a>I know you&#8217;ve all been waiting with bated breath for this day:  <a href="http://www.admin.com" target="_blank">UNIX and Linux System Administration Handbook</a>, 4th edition, is finally out! More than two years in the making, this edition covers six major operating systems in 1300 pages of fresh deliciousness. Plenty of new topics, including virtualization, green IT, scripting, and modern storage and security. Copies available at <a href="http://www.amazon.com/UNIX-Linux-System-Administration-Handbook/dp/0131480057/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1279639136&amp;sr=8-1">Amazon</a>, <a href="http://search.barnesandnoble.com/Unix-and-Linux-System-Administration-Handbook/Evi-Nemeth/e/9780131480056/?itm=1&amp;USRI=UNIX+and+Linux+System+Administration+Handbook">Barnes &amp; Noble</a>, or from <a href="http://www.pearsonhighered.com/educator/product/UNIX-and-Linux-System-Administration-Handbook/9780131480056.page">Pearson Education</a>.</p>
<p style="text-align: left;">Writing a book of this magnitude is an intense process that I learned all about. The steps to produce the book, from inception to dead trees, include:</p>
<ul>
<li>Brainstorm and agree on full topic list</li>
<li>Brainstorm and agree on contributing authors</li>
<li>Assign chapters to authors and contributors</li>
<li>Write chapter, distribute for review</li>
<li>Integrate reviewed comments from all other authors, distribute to external reviewers</li>
<li>Integrate external review comments</li>
<li>Repeat for all 32 chapters</li>
<li>Edit chapters</li>
<li>Index chapters individually</li>
<li>Engage artist (<a href="http://lisahaney.com/">Lisa Haney</a>) for new chapter cartoons, dividers and cover art</li>
<li>Engage outside organizations (IBM, Sun, HP) for test equipment</li>
<li>Regular (semi-weekly) meetings with authors, occasional meetings with publisher</li>
<li>Read and revise page proofs, searching for any obvious errors or inconsistencies</li>
<li>Deliver final manuscript to publisher and wait patiently</li>
</ul>
<p style="text-align: left;">One of the biggest challenges in producing this edition was the distributed collaboration effort. We Skyped regularly to stay in sync. Evi was around for much of the development, but we also corresponded with her while she was sailing in the Caribbean and the Pacific. We used a subversion repository for the Adobe FrameMaker source files to avoid stomping on each other&#8217;s work. I&#8217;d say this was met with mixed success; Frame&#8217;s binary files are hard to merge, despite Garth&#8217;s valiant efforts at a scripted solution.</p>
<p style="text-align: left;">Special thanks to our named and unnamed contributors whose efforts are highly appreciated and certainly worthy of recognition. This is the best edition yet!</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition" title="Slashdot It!"><img src="/wp-content/plugins/slashdot.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition" title="Digg This Story"><img src="/wp-content/plugins/digg.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition" title="Reddit"><img src="/wp-content/plugins/reddit.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="/wp-content/plugins/delicious.gif" width="16" height="16" alt="[del.icio.us]" /></a>

<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F" title="Add to my Technorati Favorites"><img src="/wp-content/plugins/technorati.ico" width="16" height="16" alt="[Technorati]" /></a>

<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fnow-available-unix-and-linux-system-administration-handbook-4th-edition%2F&amp;title=Now+available%3A+Unix+and+Linux+System+Administration+Handbook%2C+4th+edition" title="Stumble it!"><img src="/wp-content/plugins/stumbleupon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/barkingseal/~4/iAjAi_KQV2A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/07/now-available-unix-and-linux-system-administration-handbook-4th-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/07/now-available-unix-and-linux-system-administration-handbook-4th-edition/</feedburner:origLink></item>
		<item>
		<title>The Barking Seal Q3 2010 is Here and Filled with Goodies!</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/29ABUdh9_BI/</link>
		<comments>http://www.barkingseal.com/2010/07/the-barking-seal-q3-2010-is-here-and-filled-with-goodies/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 15:57:22 +0000</pubDate>
		<dc:creator>katief</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[applied trust]]></category>
		<category><![CDATA[AppliedTrust]]></category>
		<category><![CDATA[Git]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[Subversion]]></category>
		<category><![CDATA[version]]></category>
		<category><![CDATA[version-control]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1381</guid>
		<description><![CDATA[The latest version of The Barking Seal is here , and it is filled with a variety of applicable and accessible treats.  Want some? Keep reading for a taste&#8230; Goodie #1: Learn why version control is important for all businesses across the board. Goodie #2: Get some assistance in deciding “Git or Subversion? Git or Subversion? [...]]]></description>
			<content:encoded><![CDATA[<p>The latest version of The Barking Seal is here , and it is filled with a variety of applicable and accessible treats.  Want some? Keep reading for a taste&#8230;</p>
<p><a href="http://www.appliedtrust.com/q3-2010"><img class="alignleft size-medium wp-image-1383" style="margin-left: 10px; margin-right: 10px;" title="platter_large_dessert-basket" src="http://www.barkingseal.com/wp-content/uploads/2010/07/platter_large_dessert-basket-300x212.jpg" alt="" width="300" height="212" /></a>Goodie #1: Learn why version control is important for all businesses across the board.</p>
<p>Goodie #2: Get some assistance in deciding “Git or Subversion? Git or Subversion? Git…?”</p>
<p>Goodie #3 (otherwise known as the cherry on top): Meet Jim Turpin, one of our fabulous network engineers, who embodies the concept of multi-discipline to a T both inside and outside of the office.</p>
<p><a href="http://www.appliedtrust.com/q3-2010">Click here to read Q3 2010</a>, and, as always, enjoy the treat!</p>
<p>We&#8217;d love to hear from you, so please post your comments and questions here.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21" title="Slashdot It!"><img src="/wp-content/plugins/slashdot.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21" title="Digg This Story"><img src="/wp-content/plugins/digg.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21" title="Reddit"><img src="/wp-content/plugins/reddit.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="/wp-content/plugins/delicious.gif" width="16" height="16" alt="[del.icio.us]" /></a>

<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F" title="Add to my Technorati Favorites"><img src="/wp-content/plugins/technorati.ico" width="16" height="16" alt="[Technorati]" /></a>

<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fthe-barking-seal-q3-2010-is-here-and-filled-with-goodies%2F&amp;title=The+Barking+Seal+Q3+2010+is+Here+and+Filled+with+Goodies%21" title="Stumble it!"><img src="/wp-content/plugins/stumbleupon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/barkingseal/~4/29ABUdh9_BI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/07/the-barking-seal-q3-2010-is-here-and-filled-with-goodies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/07/the-barking-seal-q3-2010-is-here-and-filled-with-goodies/</feedburner:origLink></item>
		<item>
		<title>A Gentle Infrastructure Monitoring Reminder</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/1y9db9NPl5I/</link>
		<comments>http://www.barkingseal.com/2010/07/a-gentle-infrastructure-monitoring-reminder/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 18:57:51 +0000</pubDate>
		<dc:creator>ned</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[performance]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1373</guid>
		<description><![CDATA[The fine folks at Twitter Engineering recently posted about the performance issues they have had over the holiday weekend. Since Saturday, the site has been slow for users and API calls. While AppliedTrust hasn&#8217;t (yet) made the leap to Twitter, we recognize how important it is for delivering World Cup news. I give Twitter Engineering tons [...]]]></description>
			<content:encoded><![CDATA[<p>The fine folks at <a href="http://engineering.twitter.com/2010/06/perfect-stormof-whales.html" target="_blank">Twitter Engineering recently posted about the performance issues</a> they have had over the holiday weekend. Since Saturday, the site has been slow for users and API calls. While AppliedTrust hasn&#8217;t (yet) made the leap to Twitter, we recognize how important it is for delivering World Cup news. I give Twitter Engineering tons of credit for being so transparent about the details of the problem &#8211; they say:</p>
<table border="1">
<tbody>
<tr>
<td>
<div id="_mcePaste"><span style="font-size: x-small;"><span style="font-size: small;"><span style="line-height: 19px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px;"><span style="font-size: x-small;"><strong>In brief, we made three mistakes:</strong></span></span></span></span></div>
<div id="_mcePaste"><span style="font-size: x-small;"><span style="font-size: small;"><span style="line-height: 19px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px;"><span style="font-size: x-small;"><strong>* We put two critical, fast-growing, high-bandwith components on the same segment of our internal network.</strong></span></span></span></span></div>
<div id="_mcePaste"><span style="font-size: x-small;"><span style="font-size: small;"><span style="line-height: 19px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px;"><span style="font-size: x-small;"><strong>* Our internal network wasn&#8217;t appropriately being monitored.</strong></span></span></span></span></div>
<div id="_mcePaste"><span style="font-size: x-small;"><span style="font-size: small;"><span style="line-height: 19px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px;"><span style="font-size: x-small;"><strong>* Our internal network was temporarily misconfigured.</strong></span></span></span></span></div>
</td>
</tr>
</tbody>
</table>
<p>
<p>Twitter is well known for great application-layer monitoring and instrumentation, so this gap in monitoring is a surprise. It exposes a common misconception among social software companies &#8211; that their server and network infrastructure is &#8220;covered&#8221; by their hosting provider.  As web applications scale to even 1/1000 the size of Twitter, software becomes critically interdependent on the underlying network. Infrastructure should be instrumented and monitored at least as closely as the software that depends on it.</p>
<p>For more The Barking Seal articles on monitoring and troubleshooting, see:</p>
<div id="_mcePaste">
<ul>
<li><a href="http://www.barkingseal.com/2009/08/monitoring-site-to-site-vpns-on-a-cisco-asa/" target="_blank"><span style="color: #000000;">Monitoring Site to Site VPNs</span></a></li>
<li><a href="http://www.barkingseal.com/2008/12/interpreting-packet-traces-with-wireshark-part-1-of-n/" target="_blank"><span style="color: #000000;">Interpreting Packet Traces</span></a></li>
<li><a href="/2008/10/walk-then-run-thoughts-about-event-value/" target="_blank"><span style="color: #000000;">Thoughts on Monitoring Event Value</span></a></li>
</ul>
</div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder" title="Slashdot It!"><img src="/wp-content/plugins/slashdot.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder" title="Digg This Story"><img src="/wp-content/plugins/digg.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder" title="Reddit"><img src="/wp-content/plugins/reddit.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="/wp-content/plugins/delicious.gif" width="16" height="16" alt="[del.icio.us]" /></a>

<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F" title="Add to my Technorati Favorites"><img src="/wp-content/plugins/technorati.ico" width="16" height="16" alt="[Technorati]" /></a>

<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F07%2Fa-gentle-infrastructure-monitoring-reminder%2F&amp;title=A+Gentle+Infrastructure+Monitoring+Reminder" title="Stumble it!"><img src="/wp-content/plugins/stumbleupon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/barkingseal/~4/1y9db9NPl5I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/07/a-gentle-infrastructure-monitoring-reminder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/07/a-gentle-infrastructure-monitoring-reminder/</feedburner:origLink></item>
		<item>
		<title>AppliedTrust Goes Drupal!</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/_xCN9-4ERnk/</link>
		<comments>http://www.barkingseal.com/2010/06/appliedtrust-goes-drupal/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 00:21:23 +0000</pubDate>
		<dc:creator>ned</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[applied trust]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[platform security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1340</guid>
		<description><![CDATA[This month, AppliedTrust re-launched our web site on the CMS called Drupal. Although the &#8220;look and feel&#8221; of the site hasn&#8217;t changed much, this upgrade has been a breakthrough in terms of both performance and manageability. I would give our previous CMS, Joomla, a grade of a B- in comparison to Drupal&#8217;s solid A. Here [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/06/drupal_drop.jpg"><img class="alignleft size-full wp-image-1367" style="margin-left: 5px; margin-right: 5px;" title="drupal_drop" src="http://www.barkingseal.com/wp-content/uploads/2010/06/drupal_drop.jpg" alt="" width="86" height="99" /></a>This month, <a href="http://www.appliedtrust.com">AppliedTrust re-launched our web site</a> on the CMS called <a href="http://drupal.org" target="_blank">Drupal</a>. Although the &#8220;look and feel&#8221; of the site hasn&#8217;t changed much, this upgrade has been a breakthrough in terms of both performance and manageability. I would give our previous CMS, <a href="http://www.joomla.org/" target="_blank">Joomla</a>, a grade of a B- in comparison to Drupal&#8217;s solid A. Here are six reasons why Drupal is a great fit for <a href="http://www.appliedtrust.com/">www.appliedtrust.com</a>:</p>
<p><span id="more-1340"></span></p>
<div id="_mcePaste">
<ol>
<li><strong>Performance: </strong>In our migration from Joomla to Drupal, we tried to keep as many things constant as possible. We tried to keep our look and feel similar (we didn&#8217;t kill ourselves to replicate every detail, but it&#8217;s very close). We are hosting the site on the same server, with the same database and version of PHP. We didn&#8217;t add or remove any significant functionality. This is definitely not a scientific comparison of Joomla and Drupal performance, but it saved www.appliedtrust.com a full second in load time, which is a 33% reduction and <a href="http://googlewebmastercentral.blogspot.com/2010/04/using-site-speed-in-web-search-ranking.html" target="_blank">important for our Google ranking</a>. We just love performance tuning and are very excited! (This is data from <a href="http://browsermob.com">BrowserMob</a> &#8211; the red circles indicate outages during the site cutover).<a href="http://www.barkingseal.com/wp-content/uploads/2010/06/browsermob_before_after.png" target="_blank"><img class="size-full wp-image-1344 alignright" title="browsermob_before_after" src="http://www.barkingseal.com/wp-content/uploads/2010/06/browsermob_before_after.png" alt="" width="472" height="186" /></a></li>
<li><strong>The &#8220;Boboli&#8221; approach to features: </strong>Most CMSs are like a frozen pizza &#8211; you can usually find one you want, but it&#8217;s never perfect. The &#8220;Boboli&#8221; approach is to separate the tasty dough from the toppings &#8211; you get exactly what you want. Drupal is pretty much the same; it provides a robust &#8220;Drupal Core&#8221; with a minimal set of functionality. You can <a href="http://drupal.org/project/Modules" target="_blank">add only the features you want</a>, just like fresh pizza toppings from throughout the grocery store. This is a win for security <em>and</em> performance. Most CMSs and blogging systems include a large bundle of built-in functionality &#8211; much more like a frozen pizza.</li>
<li><strong>Command-line management:</strong> Drupal offers a <a href="http://drupal.org/project/drush">command-line tool called drush</a>. While many administrators will prefer the nice web-based management interface, old UNIX cowboys will find the drush shell super efficient. You can download, install, and enable modules or themes in just two commands! Drush is also useful for scheduling tasks out of cron, and for general troubleshooting and administration.</li>
<li><strong>Content and menu customization</strong><strong>:</strong> One of the worse &#8220;features&#8221; of Joomla is that it imposes a weird relationship between content (web pages) and menu item links. For a web page to be accessible, it has to be linked to a menu. On our old Joomla site, we constantly had to police for cases where duplicate URLs linked to a single page. Drupal, on the other hand, completely decouples content (and URLs) from menus. If you have ever managed Joomla, I am confident you know what I&#8217;m talking about!</li>
<li><strong>Dogmatic architecture and implementation</strong><strong>:</strong> When I first opened one of Drupal&#8217;s source code files (it&#8217;s written in PHP), I was shocked to see more comments than code! This is something every Computer Science 101 professor covers &#8211; &#8220;comment your code&#8221; &#8211; but is rarely executed well in practice. The Drupal community follows <a href="http://drupal.org/coding-standards">high quality coding standards</a>, and uses a rigorous peer review process for &#8220;the core&#8221;. As a security professional, I especially love their <a href="http://drupal.org/node/101497" target="_blank">policy for security vulnerabilities</a>: if the module developers don&#8217;t start working on important vulnerabilities within a month, the software is removed from the Drupal web site. Can you name a software company that would stop selling their products until an important patch is released? (hint: it&#8217;s not Sun, Microsoft, Oracle, or Google!)</li>
</ol>
</div>
<p>I should emphasize that this was our experience, and your mileage may vary. AppliedTrust is not a web design firm &#8211; we pride ourselves on infrastructure (servers, networks, security, performance, etc.). Still, I am tremendously impressed with Drupal and you are probably making a mistake if you are building a complex web site and haven&#8217;t considered it.</p>
<p>Looking back, since 2001 we have transitioned from static HTML (managed with GoLive), to Joomla, to WordPress (which we continue to use for this blog), to Drupal. Each transition has been a marked improvement, and today, I can&#8217;t imagine using anything except Drupal (for complex sites) or WordPress (for simple ones). In closing, here is a visual history of AppliedTrust&#8217;s web platform &#8220;evolution&#8221;:</p>
<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/06/AT_EvolutionOfWebPlatforms_06-20101.png" target="_blank"><img class="alignnone size-full wp-image-1342" title="AT_EvolutionOfWebPlatforms_06-2010" src="http://www.barkingseal.com/wp-content/uploads/2010/06/AT_EvolutionOfWebPlatforms_06-20101.png" alt="" width="481" height="265" /></a></p>
<img src="http://feeds.feedburner.com/~r/barkingseal/~4/_xCN9-4ERnk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/06/appliedtrust-goes-drupal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/06/appliedtrust-goes-drupal/</feedburner:origLink></item>
		<item>
		<title>Information Security and Running, Long Lost Brothers?</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/xBJzzyrL3SA/</link>
		<comments>http://www.barkingseal.com/2010/06/information-security-and-running-long-lost-brothers/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 16:08:28 +0000</pubDate>
		<dc:creator>terry</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[running]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1335</guid>
		<description><![CDATA[Saturday morning I was up and out the door early for a long run before the heat set in too much. As I was running I was thinking to myself, &#8220;Gosh, having a good exercise routine is kind of like having a good information security program.&#8221; I had lots of time to ponder this particular [...]]]></description>
			<content:encoded><![CDATA[<p>Saturday morning I was up and out the door early for a long run before the heat set in too much.  As I was running I was thinking to myself, &#8220;Gosh, having a good exercise routine is kind of like having a good information security program.&#8221;  I had lots of time to ponder this particular issue, as my iPod was unfortunately not charged and I had no one to talk to.  Here are a few things I thought of that make exercise and security so alike.</p>
<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/06/running-feet.jpg"><img class="alignleft size-medium wp-image-1337" style="margin-left: 5px; margin-right: 5px;" title="running feet" src="http://www.barkingseal.com/wp-content/uploads/2010/06/running-feet-300x191.jpg" alt="" width="300" height="191" /></a>1) Set goals: Both in exercise and in information security, it is good to set goals.  For example, before I can write up a training plan for myself, I need to know what race I&#8217;m training for, and what my target pace is.  Similarly, before I can write up my information security plan, I need to know what information I need to protect and how much protection I need (is this credit card data, or is it records of what color paint my store sold last year?)</p>
<p><span id="more-1335"></span></p>
<p>2) Stick to the plan: Sometimes on Saturday morning at 6 a.m. I don&#8217;t really want to go for a run, but I know that the only way to reach my goal is to throw my legs over the side of the bed and stand up.  I also know that the best infosec plan in the world does no good if it doesn&#8217;t get followed.  It may not be fun to conduct that periodic audit again, and it may be frustrating to have to patch those darn servers in the middle of the night so you don&#8217;t impact the production systems, but you&#8217;ve got to do it.  A plan in a drawer is no plan at all!</p>
<p>3) Make the plan doable: I could probably run my race a lot faster if I was willing to quit my job and train full time, but that&#8217;s just not practical.  I need to keep perspective on the rest of my life and make the plan something that I can accomplish.  The same is true for the security plan.  It&#8217;s not reasonable to expect your team to install each and every patch within 24 hours of release.  Save that extreme stuff for the really critical items that only come up once in a while.  Be reasonable, and you&#8217;ll make everyone&#8217;s life easier.  No one wants a security approach that flies in the face of usability.  But there are some things that just can&#8217;t slip &#8211; and make sure you know what those are.  Passwords, for example: I know it&#8217;s easier to remember five-letter passwords with no complexity requirements, but if you let that happen, you may as well forget the rest of the plan.</p>
<p>4) Celebrate your successes: I run with a group twice a week, and the coach keeps track of our times throughout the season(s).  When I hit a personal record, she knows it and we celebrate the accomplishment.  Do the same thing with security!  Did your annual assessment just come back with 20% fewer recommendations?  Did you just pass a penetration test with flying colors?  Great!  Celebrate!  There&#8217;s always another mitigation recommendation you can implement, but don&#8217;t forget you&#8217;ve done many already, and congratulate yourself on a job well done.</p>
<img src="http://feeds.feedburner.com/~r/barkingseal/~4/xBJzzyrL3SA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/06/information-security-and-running-long-lost-brothers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/06/information-security-and-running-long-lost-brothers/</feedburner:origLink></item>
		<item>
		<title>An IT lesson from the BP disaster</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/dMkH7a0L2xQ/</link>
		<comments>http://www.barkingseal.com/2010/06/an-it-lesson-from-the-bp-disaster/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 16:26:00 +0000</pubDate>
		<dc:creator>ned</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1331</guid>
		<description><![CDATA[Sadly disasters happen, and when they do there are often valuable lessons to be learned. Unfortunately, poor IT infrastructure will limit the lessons the oil industry can learn from this incident. The Deepwater Horizon rig was equipped with a vessel management system (VMS), which records dozens of different metrics about the conditions on the rig [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/06/dwh_onfire.jpg"><img class="alignright size-medium wp-image-1330" title="dwh_onfire" src="http://www.barkingseal.com/wp-content/uploads/2010/06/dwh_onfire-300x226.jpg" alt="" width="300" height="226" /></a>Sadly disasters happen, and when they do there are often valuable lessons to be learned. Unfortunately, poor IT infrastructure will limit the lessons the oil industry can learn from this incident.</p>
<p>The Deepwater Horizon rig was equipped with a vessel management system (VMS), which records dozens of different metrics about the conditions on the rig and in the well. These VMS logs would contain valuable details about the blowout, much like an airplane &#8220;black box&#8221; is essential in understanding a plane crash.</p>
<p><span id="more-1331"></span></p>
<p>Steven Newman, the CEO of Transocean, said during a recent senate hearing, &#8220;There is some delay in the replication of our data, so our operational data, our sequence of events ends at 3 o&#8217;clock in the afternoon on the 20th. And so the VMS system, along with the logs of the VMS system, would have gone down with the vessel.&#8221;  The blowout and massive explosion happened at 10, taking eleven lives and seven hours of VMS data to the bottom of the ocean. Representative Bruce Braley from Iowa followed up with &#8220;So you have no mirrored backup data device so that that information is recorded at some other location than on the rig itself?&#8221;.  Newman replied, &#8220;We do not have real-time off-rig monitoring of what&#8217;s going on on the vessel&#8221;.</p>
<p>The costs to synchronize this data back to shore closer to &#8220;real-time&#8221; are nothing compared to the catastrophe at hand.  If an IT Disaster Recovery risk analysis had been performed, this replication delay would have stood out like a sore thumb.  We can be certain that new congressional regulations will be established to ensure that VMS data is replicated back to shore in a timely manner, but what about the rest of us?  Now is a <strong>perfect</strong> time to take a look at <strong>your</strong> business and make sure that critical data is being backed up appropriately to an off-site location.</p>
<img src="http://feeds.feedburner.com/~r/barkingseal/~4/dMkH7a0L2xQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/06/an-it-lesson-from-the-bp-disaster/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/06/an-it-lesson-from-the-bp-disaster/</feedburner:origLink></item>
		<item>
		<title>AppliedTrust sponsors “Laps for Learning”</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/Jwk0AlguCbA/</link>
		<comments>http://www.barkingseal.com/2010/05/appliedtrust-sponsors-laps-for-learning/#comments</comments>
		<pubDate>Sat, 08 May 2010 22:23:16 +0000</pubDate>
		<dc:creator>trent</dc:creator>
				<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[applied trust]]></category>
		<category><![CDATA[community]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1320</guid>
		<description><![CDATA[Along with other notable members of the community such as Google, Chipotle Mexican Grill, Van Matre Construction, and many others, AppliedTrust is proud to sponsor this year&#8217;s &#8220;Laps for Learning&#8221; fund raiser at Douglass Elementary School.  This event raises funds for the education of elementary school children, helping to close the gap that has resulted [...]]]></description>
			<content:encoded><![CDATA[<p>Along with other notable members of the community such as <a href="http://www.google.com/intl/en/about.html" target="_blank">Google</a>, <a href="http://www.chipotle.com/" target="_blank">Chipotle Mexican Grill</a>, <a href="http://www.vanmatreconstruction.com" target="_blank">Van Matre Construction</a>, and many others, <a href="http://www.appliedtrust.com" target="_blank">AppliedTrust</a> is proud to sponsor this year&#8217;s &#8220;Laps for Learning&#8221; fund raiser at <a href="http://bvsd.org/schools/douglass/Pages/home.aspx" target="_blank">Douglass Elementary School</a>.  This event raises funds for the education of elementary school children, helping to close the gap that has resulted from budget cuts at the State of Colorado and Boulder Valley School District level.</p>
<p><img src="http://www.barkingseal.com/wp-content/uploads/2010/04/at_banner_lfl.jpg" alt="AT Banner" width="391" height="143" /></p>
<p><span id="more-1320"></span>Above, AppliedTrust&#8217;s  banner is displayed along with other &#8220;Laps for Learning&#8221; supporters at the corner of 76th and Baseline in Boulder.  Although the Douglass PTO had obtained advance permission to hang banners for the event along an Open Space-managed fence across the street from the school on 75th Avenue, it was later determined that such use for elementary school fund raising events constitutes prohibited &#8220;commercial use&#8221; of the open space lands and must be removed. Brady Van Matre volunteered to host the banners on his nearby fence as an alternative, and wrote a <a href="http://www.dailycamera.com/ci_14993082#axzz0nNUHfrox" target="_blank">letter to the editor of The Daily Camera titled <em>Lend Schools A Helping Hand</em></a>.</p>
<p>We&#8217;re delighted to be an active supporter of our community, wherever our banner hangs!</p>
<img src="http://feeds.feedburner.com/~r/barkingseal/~4/Jwk0AlguCbA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/05/appliedtrust-sponsors-laps-for-learning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/05/appliedtrust-sponsors-laps-for-learning/</feedburner:origLink></item>
		<item>
		<title>AppliedTrust featured on One Day, One Job!</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/3FmbM2knmU4/</link>
		<comments>http://www.barkingseal.com/2010/04/appliedtrust-featured-on-one-day-one-job/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 15:39:08 +0000</pubDate>
		<dc:creator>ned</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[Recruiting]]></category>
		<category><![CDATA[applied trust]]></category>
		<category><![CDATA[boulder]]></category>
		<category><![CDATA[popular]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1313</guid>
		<description><![CDATA[I&#8217;m very excited to announce that AppliedTrust is being featured today on One Day, One Job, the popular site that highlights a different hiring employer every day.  Created by Willy Franzen, One Day, One Job is a unique resource for college students beginning their careers.  This is awesome exposure for our company and a great opportunity for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/04/One-Day-One-Job-logo.gif"><img class="alignleft size-full wp-image-1314" title="One-Day-One-Job-logo" src="http://www.barkingseal.com/wp-content/uploads/2010/04/One-Day-One-Job-logo.gif" alt="" width="169" height="140" /></a> I&#8217;m very excited to announce that <a href="http://www.onedayonejob.com/jobs/applied-trust/" target="_blank">AppliedTrust is being featured</a> today on <a href="http://www.onedayonejob.com/" target="_blank">One Day, One Job</a>, the popular site that highlights a different hiring employer every day.  Created by Willy Franzen, <a href="http://www.onedayonejob.com/" target="_blank">One Day, One Job</a> is a <a href="http://www.businessweek.com/innovate/content/apr2010/id20100426_642810.htm" target="_blank">unique resource</a> for college students beginning their careers.  This is awesome exposure for our company and a great opportunity for us to find the perfect new Seal to join our team!</p>
<p>As our regular readers know, <a href="http://www.appliedtrust.com" target="_blank">AppliedTrust</a> is <a href="http://www.appliedtrust.com/jobs/infrastructureengineer" target="_blank">looking for a great infrastructure engineer</a> who wants to work in Boulder, Colorado. This role is a &#8220;Jack of all trades&#8221; within the broad field of Information Technology &#8211; they get to play with networks, servers, software, and security.  One ideal candidate for this job would be a graduating Computer Science or Engineering major who has experience with Windows and Linux system administration and doesn&#8217;t want to spend all day programming.  We would definitely also consider someone with more work experience.  If you are interested, or know of a good candidate, please check out our jobs page: <a href="http://www.appliedtrust.com/jobs/infrastructureengineer">http://www.appliedtrust.com/jobs</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21" title="Slashdot It!"><img src="/wp-content/plugins/slashdot.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21" title="Digg This Story"><img src="/wp-content/plugins/digg.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21" title="Reddit"><img src="/wp-content/plugins/reddit.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="/wp-content/plugins/delicious.gif" width="16" height="16" alt="[del.icio.us]" /></a>

<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F" title="Add to my Technorati Favorites"><img src="/wp-content/plugins/technorati.ico" width="16" height="16" alt="[Technorati]" /></a>

<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fappliedtrust-featured-on-one-day-one-job%2F&amp;title=AppliedTrust+featured+on+One+Day%2C+One+Job%21" title="Stumble it!"><img src="/wp-content/plugins/stumbleupon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/barkingseal/~4/3FmbM2knmU4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/04/appliedtrust-featured-on-one-day-one-job/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/04/appliedtrust-featured-on-one-day-one-job/</feedburner:origLink></item>
		<item>
		<title>issues.apache.org compromised by XSS vulnerability</title>
		<link>http://feedproxy.google.com/~r/barkingseal/~3/sz4dmXPIUEE/</link>
		<comments>http://www.barkingseal.com/2010/04/apache-org-compromised-by-xss-vulnerability/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 23:01:31 +0000</pubDate>
		<dc:creator>ben</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cross-site scripting]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.barkingseal.com/?p=1303</guid>
		<description><![CDATA[As discussed in detail by the Apache infrastructure team, a cross-site scripting vulnerability in Atlassian&#8217;s JIRA led to a full root account compromise on the ASF&#8217;s issue and request tracking server. If you don&#8217;t care to read the full story from the infrastructure team, the following sequence of events led to the compromise: Attackers opened [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.barkingseal.com/wp-content/uploads/2010/04/feather.gif"><br />
</a><a href="http://www.barkingseal.com/wp-content/uploads/2010/04/apache_logo.png"><img class="aligncenter size-full wp-image-1307" title="apache_logo" src="http://www.barkingseal.com/wp-content/uploads/2010/04/apache_logo.png" alt="" width="200" height="178" /></a></p>
<p>As discussed <a href="https://blogs.apache.org/infra/entry/apache_org_04_09_2010">in detail</a> by the Apache infrastructure team, a cross-site scripting vulnerability in Atlassian&#8217;s JIRA led to a full root account compromise on the ASF&#8217;s issue and request tracking server. If you don&#8217;t care to read the full story from the infrastructure team, the following sequence of events led to the compromise:</p>
<ol>
<li>Attackers opened a new JIRA issue with a malicious tinyurl.com link that led to the JIRA page with an XSS vulnerability</li>
<li>Simultaneously, attackers launched a brute force attack on the JIRA login form</li>
<li>Several administrators clicked the tinyurl link, which compromised their cookies (giving the attackers JIRA admin access)</li>
<li>Attackers uploaded malicious a JAR file that collected JIRA passwords at login. One of the compromised passwords had also been used for a local account with full sudo privileges.</li>
</ol>
<p>There&#8217;s more to the story, but those points capture the bulk of the attack.</p>
<p>This compromise interests me because it&#8217;s an explicit, targeted, successful attack against a security conscious and capable next-generation web technology team. Several techniques were used in this attack:</p>
<ul>
<li>Social engineering. The attackers opened an issue as if they were a trusted source posting a legitimate link. The Apache administrators trusted them.</li>
<li>Web application security flaw. XSS is #2 on the <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP top 10 list</a>.</li>
<li>Lack of vigilance. As the infrastructure team points out, the same password was used in a number of cases, and the JIRA user was overly privileged.</li>
</ul>
<p>I hear a lot of grumbling when I highlight XSS vulnerabilities in a penetration testing report. &#8220;Is this really a serious problem?&#8221; and &#8220;we&#8217;re not a target&#8221; and &#8220;it doesn&#8217;t matter if they steal the cookie&#8221; are common complaints. Let&#8217;s face it &#8211; if the Apache team can be powned, we should all be wary.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability" title="Slashdot It!"><img src="/wp-content/plugins/slashdot.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability" title="Digg This Story"><img src="/wp-content/plugins/digg.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability" title="Reddit"><img src="/wp-content/plugins/reddit.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="/wp-content/plugins/delicious.gif" width="16" height="16" alt="[del.icio.us]" /></a>

<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F" title="Add to my Technorati Favorites"><img src="/wp-content/plugins/technorati.ico" width="16" height="16" alt="[Technorati]" /></a>

<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.barkingseal.com%2F2010%2F04%2Fapache-org-compromised-by-xss-vulnerability%2F&amp;title=issues.apache.org+compromised+by+XSS+vulnerability" title="Stumble it!"><img src="/wp-content/plugins/stumbleupon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/barkingseal/~4/sz4dmXPIUEE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.barkingseal.com/2010/04/apache-org-compromised-by-xss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.barkingseal.com/2010/04/apache-org-compromised-by-xss-vulnerability/</feedburner:origLink></item>
	</channel>
</rss>
