<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-404</id>
	<title>Nabble - Security Basics</title>
	<updated>2009-12-04T05:08:51Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Security-Basics-f404.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security-Basics-f404.html" />
	<subtitle type="html">A high-volume list which permits people to ask 'stupid questions' without being derided as 'n00bs'. I would recommend this list to network security newbies, but be sure to read bugtraq and other lists as well. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26647945</id>
	<title>Re: MASS EMAIL bypass BLACKLIST?</title>
	<published>2009-12-04T05:08:51Z</published>
	<updated>2009-12-04T05:08:51Z</updated>
	<author>
		<name>Bugzilla from tremaine@gmail.com</name>
	</author>
	<content type="html">&lt;a href=&quot;http://en.wikipedia.org/wiki/Fast_flux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/Fast_flux&lt;/a&gt;&lt;br&gt;&lt;br&gt;It's a fairly common practice for spammers.
&lt;br&gt;&lt;br&gt;Tremaine Lea
&lt;br&gt;Network Security Consultant
&lt;br&gt;Intrepid ACL
&lt;br&gt;&amp;quot;Paranoia for hire&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;AFH Security wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hey guys,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I was wondering if there was a way of bypassing blacklist and spam
&lt;br&gt;&amp;gt; filters?
&lt;br&gt;&amp;gt; I keep receiving emails from a domain and I've blocked the ip from my
&lt;br&gt;&amp;gt; server as well as blacklisted the email but for some reason they keep
&lt;br&gt;&amp;gt; getting through. I'm guessing they're using a DNS with a low ttll with
&lt;br&gt;&amp;gt; a botnet? (Yes kinda like the movie Untraceable).
&lt;br&gt;&amp;gt; That'd be awesome if I could get some form of a response.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/MASS-EMAIL-bypass-BLACKLIST--tp26633769p26647945.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26645341</id>
	<title>Re: MASS EMAIL bypass BLACKLIST?</title>
	<published>2009-12-04T04:03:10Z</published>
	<updated>2009-12-04T04:03:10Z</updated>
	<author>
		<name>Nathan O'Neal-2</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;To verify this you would need to collect some emails and review the headers. It also depends on what your spam filter you are using as &amp;nbsp;well.
&lt;br&gt;&lt;br&gt;Hope this helps,
&lt;br&gt;&lt;br&gt;Nathan
&lt;br&gt;On Dec 1, 2009, at 6:30 PM, AFH Security wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hey guys,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I was wondering if there was a way of bypassing blacklist and spam filters?
&lt;br&gt;&amp;gt; I keep receiving emails from a domain and I've blocked the ip from my server as well as blacklisted the email but for some reason they keep getting through. I'm guessing they're using a DNS with a low ttll with a botnet? (Yes kinda like the movie Untraceable).
&lt;br&gt;&amp;gt; That'd be awesome if I could get some form of a response.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/MASS-EMAIL-bypass-BLACKLIST--tp26633769p26645341.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26647847</id>
	<title>Windows Server without AD?</title>
	<published>2009-12-04T02:45:27Z</published>
	<updated>2009-12-04T02:45:27Z</updated>
	<author>
		<name>Scott Race-2</name>
	</author>
	<content type="html">Hello, I have come across a Windows Server 2003 system that has not had
&lt;br&gt;AD (or DNS or DHCP) installed on it. &amp;nbsp;It does have Terminal Services
&lt;br&gt;installed (5 licenses) and there are local accounts setup for each user.
&lt;br&gt;Single server for the organization.
&lt;br&gt;&lt;br&gt;What are the security implications of not having AD installed? &amp;nbsp;I'm
&lt;br&gt;assuming one would be that it'd be easy to reset the local Admin
&lt;br&gt;password and gain access to the box.
&lt;br&gt;&lt;br&gt;One note is that all the clients in the network are Macs, using RDP to
&lt;br&gt;access this Terminal Server.
&lt;br&gt;&lt;br&gt;Thanks in advance.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Windows-Server-without-AD--tp26647847p26647847.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26645122</id>
	<title>FW: [Full-disclosure] Facebook Police</title>
	<published>2009-12-03T21:42:13Z</published>
	<updated>2009-12-03T21:42:13Z</updated>
	<author>
		<name>Murda Mcloud</name>
	</author>
	<content type="html">Has anyone tested the 'policy' in a court of law? Ie, someone has created a
&lt;br&gt;'fake' profile and then been sued or prosecuted by Facebook for doing so?
&lt;br&gt;&lt;br&gt;They have been sued by real people who had their names used on the fake
&lt;br&gt;profiles, though.
&lt;br&gt;&lt;a href=&quot;http://www.guardian.co.uk/technology/2008/jul/24/facebook.privacy&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.guardian.co.uk/technology/2008/jul/24/facebook.privacy&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I'm sure people have made all manner of defamatory statements on Facebook
&lt;br&gt;using the 'anonymity' of it.
&lt;br&gt;Google were recently forced to reveal the name of an anonymous blogger.
&lt;br&gt;&lt;a href=&quot;http://www.smh.com.au/technology/technology-news/model-forces-google-to-reve&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.smh.com.au/technology/technology-news/model-forces-google-to-reve&lt;/a&gt;&lt;br&gt;al-skank-bloggers-identity-20090819-epz0.html
&lt;br&gt;&lt;br&gt;If the police were to stray on the wrong side of the law(which never
&lt;br&gt;happens...) in using the 'fake' identity then perhaps they could be
&lt;br&gt;prosecuted.
&lt;br&gt;&lt;br&gt;I can't see that Facebook's policy actually, physically stops you from
&lt;br&gt;creating a fake ID but if they were to find out that you had done so, then
&lt;br&gt;they would be 'justified' in deleting your account, and if the real person
&lt;br&gt;you have pretended to be finds out, then you could be in trouble.
&lt;br&gt;&lt;br&gt;If, however, I said my name was Zaphod Beeblebrox(apologies to Douglas
&lt;br&gt;Adams) then would I get in trouble?
&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of Stephen Mullins
&lt;br&gt;Sent: Wednesday, December 02, 2009 5:42 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Michael.Barber@...&lt;/a&gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;netinfinity.securitylab@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Full-disclosure] Facebook Police
&lt;br&gt;&lt;br&gt;People assuming false identities on MY internet? &amp;nbsp;Heaven forbid. &amp;nbsp;I am
&lt;br&gt;quite appalled by this drastic revelation.
&lt;br&gt;&lt;br&gt;On Fri, Nov 27, 2009 at 3:12 PM, &amp;nbsp;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Michael.Barber@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Interesting take on the situation... however if you extend internet to
&lt;br&gt;real life your argument takes on a different tone.  By your reasoning it
&lt;br&gt;should be illegal for law enforcement to go undercover.  If you assume it is
&lt;br&gt;legal for a cop to go undercover ... then he/she is using a real name.
&lt;br&gt; Therefore no laws or policy's are being broken.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Just my 0.02.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of netinfinity
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Sent: Thursday, November 26, 2009 7:46 PM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645122&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: [Full-disclosure] Facebook Police
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;  &amp;quot;Facebook policy requires the use of one's real name to sign up, but
&lt;br&gt;&amp;gt; they let the police use fake names..&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sure the policy says that but a lot of people are changing their names
&lt;br&gt;&amp;gt; on a daily basis (ok maybe not daily). And majority of those changes
&lt;br&gt;&amp;gt; are
&lt;br&gt;&amp;gt; just for fun, but never the less they are against the policy. What
&lt;br&gt;&amp;gt; about those people? Only way to verify or check someone's name is
&lt;br&gt;&amp;gt; through IP (ISP). And that can't be done
&lt;br&gt;&amp;gt; by will.. It must have some legal grounds...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Let me get to the point, I'm sure that police is violating some some
&lt;br&gt;&amp;gt; kind of human rights or even law's (?)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; netinfinity
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL
&lt;/div&gt;certificate.  We look at how SSL works, how it benefits your company and how
&lt;br&gt;your customers can tell if a site is secure. You will find out how to test,
&lt;br&gt;purchase, install and use a thawte Digital Certificate on your Apache web
&lt;br&gt;server. Throughout, best practices for set-up are highlighted to help you
&lt;br&gt;ensure efficient ongoing management of your encryption keys and digital
&lt;br&gt;certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL
&lt;br&gt;certificate.  We look at how SSL works, how it benefits your company and how
&lt;br&gt;your customers can tell if a site is secure. You will find out how to test,
&lt;br&gt;purchase, install and use a thawte Digital Certificate on your Apache web
&lt;br&gt;server. Throughout, best practices for set-up are highlighted to help you
&lt;br&gt;ensure efficient ongoing management of your encryption keys and digital
&lt;br&gt;certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL
&lt;br&gt;certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how
&lt;br&gt;your customers can tell if a site is secure. You will find out how to test,
&lt;br&gt;purchase, install and use a thawte Digital Certificate on your Apache web
&lt;br&gt;server. Throughout, best practices for set-up are highlighted to help you
&lt;br&gt;ensure efficient ongoing management of your encryption keys and digital
&lt;br&gt;certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;d1
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FW%3A--Full-disclosure--Facebook-Police-tp26645122p26645122.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633986</id>
	<title>Re: adding another defence layer against viruses/worms</title>
	<published>2009-12-03T12:33:31Z</published>
	<updated>2009-12-03T12:33:31Z</updated>
	<author>
		<name>Kraig Babin</name>
	</author>
	<content type="html">Juan,
&lt;br&gt;&lt;br&gt;Another direction to look at would be sandboxing the server
&lt;br&gt;application(s) or even running a stateless server. There are several
&lt;br&gt;solutions out there which could help isolate the application from the
&lt;br&gt;rest of the system preventing the spread of any infections. Set the
&lt;br&gt;server up in a DMZ/virtual LAN for further isolation and any
&lt;br&gt;infections should be well contained.
&lt;br&gt;&lt;br&gt;Also combine that with a better anti-virus system, or use an
&lt;br&gt;proxy/anti-virus solution to handle all incoming connections to the
&lt;br&gt;server to reduce the occurrence of infections.
&lt;br&gt;&lt;br&gt;Kraig Babin
&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 10:03 AM, Juan B &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633986&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30 remote branches connected to his core. the problem is that sometimes the AV fails to detect new viruses/worms coming from those branches so those viruses/worms mess up his LAN.another problem is that the the client doesn't have much of control over the remote PCs in the branches. so I thought about adding another layer of defence in which we will add an IPS (which Ips detects also viruses/worms??) which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt; juan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;--
&lt;br&gt;[K]
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26633986.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633940</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-12-01T18:14:12Z</published>
	<updated>2009-12-01T18:14:12Z</updated>
	<author>
		<name>juanb007</name>
	</author>
	<content type="html">Thanks for the good advice. I will take a look at the producet.
&lt;br&gt;&lt;br&gt;They also will implent NAC and as I recommended a network level filter they will buy GFI languard to scan the pc's, don’t you think it’s a bit of over kill to implement also core Tracer?
&lt;br&gt;&lt;br&gt;Thanks again,
&lt;br&gt;&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633940&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633940&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Nathan ONeal
&lt;br&gt;Sent: Saturday, November 28, 2009 3:39 AM
&lt;br&gt;To: security basics
&lt;br&gt;Subject: Re: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;Juan,
&lt;br&gt;&lt;br&gt;In addition to all of the solid recommendations given previously, I would ask your client how far they are willing to go to prevent these issues. It also matters if all nodes accessing the network are owned and &amp;nbsp;provisioned by your client (for your sake I truly hope so). Assuming these things are true, and they have a some decent network policies in place, I would suggest looking at &amp;quot;white listing&amp;quot; for your end points. We are all aware of how lacking TPM is with no vendor actually providing certificates on the hardware to validate their signed code, but we have had measured success utilizing programs like Prevx and Core Tracer (neither of which I work for by the way) to fill in these gaps.
&lt;br&gt;&lt;br&gt;Core Tracer specifically had great success at the last Defcon and from what I saw point us towards the future of endpoint security. At the massive rate that malware is being created and mutated, we have decided that a whitelist approach on the end point is the most effective way to mitigate the majority of problems we were experiencing with endusers. It is my no means a silver bullet and I am not suggesting you abandon proactive event correlation and malware mitigation at the network level, but I know it has saved our team massive amounts of time not only by reducing the number of fires that come up, but also allowing us a little bit of time to test out what the vendor patches break while fixing their own code. Good luck mate.
&lt;br&gt;&lt;br&gt;Nathan O'Neal
&lt;br&gt;&lt;br&gt;On Nov 26, 2009, at 9:11 PM, aditya mukadam wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Juan,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I would highly recommend you few solutions as below :
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1) End point Security Check : You can enforce strict PC/Laptop policy
&lt;br&gt;&amp;gt; (which would make sure that every PC/Laptop has AV/Personal Firewall).
&lt;br&gt;&amp;gt; Devices like UAC/NAC, can perform end point security check on
&lt;br&gt;&amp;gt; PC/Laptps while it connects to the network. This will atleast make
&lt;br&gt;&amp;gt; sure every user has an AV.
&lt;br&gt;&amp;gt; 2) (Standalone) Content/Protocol Filtering: With this solution, you
&lt;br&gt;&amp;gt; can make sure that the user traffic passes through an application,
&lt;br&gt;&amp;gt; which filters the content of the traffic and also does protocol
&lt;br&gt;&amp;gt; filtering (Example: Websense)
&lt;br&gt;&amp;gt; 3) Proxy Content Filtering : Since you mentioned that you don't have
&lt;br&gt;&amp;gt; control this solution would not fit in however its worth considering
&lt;br&gt;&amp;gt; for future usage. Example: BlueCoat Proxy
&lt;br&gt;&amp;gt; 4) IPS : I would recommend Tipping Point IPS, Juniper IDP.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hope this helps.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Aditya Govind Mukadam
&lt;br&gt;&amp;gt; CISSP,CEH,JNSA-Advanced Security, JNCIA-UAC, JNCIA_SSL,
&lt;br&gt;&amp;gt; CQS-PIX,CQS-VPN &lt;a href=&quot;http://in.linkedin.com/in/adityamukadam&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://in.linkedin.com/in/adityamukadam&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Tue, Nov 24, 2009 at 7:33 PM, Juan B &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633940&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30 remote branches connected to his core. the problem is that sometimes the AV fails to detect new viruses/worms coming from those branches so those viruses/worms mess up his LAN.another problem is that the the client doesn't have much of control over the remote PCs in the branches. so I thought about adding another layer of defence in which we will add an IPS (which Ips detects also viruses/worms??) which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt;&amp;gt; juan
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ---------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; --- Securing Apache Web Server with thawte Digital Certificate In
&lt;br&gt;&amp;gt;&amp;gt; this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; 442f727d1
&lt;br&gt;&amp;gt;&amp;gt; ---------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; ---
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; -- Securing Apache Web Server with thawte Digital Certificate In this
&lt;br&gt;&amp;gt; guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&lt;/a&gt;&lt;br&gt;&amp;gt; 42f727d1
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26633940.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633874</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-12-01T18:13:25Z</published>
	<updated>2009-12-01T18:13:25Z</updated>
	<author>
		<name>juanb007</name>
	</author>
	<content type="html">Ok I will take look on the AV, they have now symentec.
&lt;br&gt;&lt;br&gt;They have windows 2003 servers and xp as pc's. what you suggest implementing with GPO to elevate the security of the pc's? today they use GPO only to block the screen after 15 minutes of none use. And they need the USB and cd to transefer pictures they really need to use for work tasks. Must of the users don’t have admin rights on there machines. What else can I implenet to elevate the security? They implent patches throw WSUS and keep the pc's updated. Maybe to use the FW feature of the AV? You have a security template you can send me?
&lt;br&gt;&lt;br&gt;Thanks for your answer.
&lt;br&gt;&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Quark Group - Hilton Travis
&lt;br&gt;Sent: Friday, November 27, 2009 5:38 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: RE: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;G'day Juan,
&lt;br&gt;&lt;br&gt;The best move would be to deploy a good AV product instead of whichever one you're currently running. &amp;nbsp;The best one around now (and since about 1999) is still NOD32, however you cannot run the latest version on Servers also running Microsoft Exchange as the Eset guys seem to have deemed Exchange not worth updating for - their current version is 4.x however the latest Exchange version is 2.7x, meaning you need to run an ancient version on Windows Server boxes running Exchange - something I honestly cannot understand why they have left this way.
&lt;br&gt;&lt;br&gt;Aside from that issue, NOD32 has the best heuristics, best detection rates and outstandingly low false positive rates *even* when Heuristics have been cranked up to the highest level.
&lt;br&gt;&lt;br&gt;So, I'd look at fixing the broken AV issue at the source, then look at other ways to implement better control of the remote PCs, such as distributed AD controllers and using GPO for what it was designed for - control of servers and desktops on the domain.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://hiltont.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hiltont.blogspot.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Hilton Travis &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Phone: +61 (0)7 3105 9101
&lt;br&gt;(Brisbane, Australia) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Phone: +61 (0)419 792 394
&lt;br&gt;Manager, Quark IT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.quarkit.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.quarkit.com.au&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Quark Group &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.quarkgroup.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.quarkgroup.com.au&lt;/a&gt;&lt;br&gt;&lt;br&gt;War doesn't determine who is right. &amp;nbsp;War determines who is left.
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; On Behalf Of Juan B
&lt;br&gt;&amp;gt; Sent: Wednesday, 25 November 2009 12:04 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633874&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: adding another defence layer against viruses/worms
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this client have
&lt;br&gt;&amp;gt; around 30 remote branches connected to his core. the problem is that
&lt;br&gt;&amp;gt; sometimes the AV fails to detect new viruses/worms coming from those
&lt;br&gt;&amp;gt; branches so those viruses/worms mess up his LAN.another problem is
&lt;br&gt;&amp;gt; that the the client doesn't have much of control over the remote PCs
&lt;br&gt;&amp;gt; in the branches. so I thought about adding another layer of defence in
&lt;br&gt;&amp;gt; which we will add an IPS (which Ips detects also viruses/worms??)
&lt;br&gt;&amp;gt; which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt; juan
&lt;/div&gt;&lt;br&gt;&lt;br&gt;This document and any attachments are for the intended recipient only.
&lt;br&gt;It may contain confidential, privileged or copyright material which must not be disclosed or distributed without prior approval.
&lt;br&gt;&lt;br&gt;Quark Group Pty Ltd :: ABN 23 114 975 772 Trading As Quark AudioVisual, Quark Automation, Quark IT
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;--------------------------------------------------------------------------------
&lt;br&gt;&amp;lt;&amp;lt; ella for Spam Control &amp;gt;&amp;gt; has removed 2595 Spam messages and set aside 0 Newsletters for me
&lt;br&gt;You can use it too - and it's FREE! &amp;nbsp;www.ellaforspam.com 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26633874.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633769</id>
	<title>MASS EMAIL bypass BLACKLIST?</title>
	<published>2009-12-01T16:30:02Z</published>
	<updated>2009-12-01T16:30:02Z</updated>
	<author>
		<name>AFH Security</name>
	</author>
	<content type="html">Hey guys,
&lt;br&gt;&lt;br&gt;I was wondering if there was a way of bypassing blacklist and spam filters?
&lt;br&gt;I keep receiving emails from a domain and I've blocked the ip from my 
&lt;br&gt;server as well as blacklisted the email but for some reason they keep 
&lt;br&gt;getting through. I'm guessing they're using a DNS with a low ttll with a 
&lt;br&gt;botnet? (Yes kinda like the movie Untraceable).
&lt;br&gt;That'd be awesome if I could get some form of a response.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/MASS-EMAIL-bypass-BLACKLIST--tp26633769p26633769.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26600121</id>
	<title>Re: [Full-disclosure] Facebook Police</title>
	<published>2009-12-01T11:42:26Z</published>
	<updated>2009-12-01T11:42:26Z</updated>
	<author>
		<name>Stephen Mullins</name>
	</author>
	<content type="html">People assuming false identities on MY internet? &amp;nbsp;Heaven forbid. &amp;nbsp;I am
&lt;br&gt;quite appalled by this drastic revelation.
&lt;br&gt;&lt;br&gt;On Fri, Nov 27, 2009 at 3:12 PM, &amp;nbsp;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26600121&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Michael.Barber@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Interesting take on the situation... however if you extend internet to real life your argument takes on a different tone.  By your reasoning it should be illegal for law enforcement to go undercover.  If you assume it is legal for a cop to go undercover ... then he/she is using a real name.  Therefore no laws or policy's are being broken.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Just my 0.02.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26600121&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26600121&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of netinfinity
&lt;br&gt;&amp;gt; Sent: Thursday, November 26, 2009 7:46 PM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26600121&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: [Full-disclosure] Facebook Police
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;  &amp;quot;Facebook policy requires the use of one's real name to sign up, but
&lt;br&gt;&amp;gt; they let the police use fake names..&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sure the policy says that but a lot of people are changing their names
&lt;br&gt;&amp;gt; on a daily basis (ok maybe not daily). And majority of those changes
&lt;br&gt;&amp;gt; are
&lt;br&gt;&amp;gt; just for fun, but never the less they are against the policy. What
&lt;br&gt;&amp;gt; about those people? Only way to verify or check someone's name is
&lt;br&gt;&amp;gt; through IP (ISP). And that can't be done
&lt;br&gt;&amp;gt; by will.. It must have some legal grounds...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Let me get to the point, I'm sure that police is violating some some
&lt;br&gt;&amp;gt; kind of human rights or even law's (?)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; netinfinity
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A--Full-disclosure--Facebook-Police-tp26546745p26600121.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597545</id>
	<title>PCAP replay across firewall/NAT device</title>
	<published>2009-12-01T06:55:36Z</published>
	<updated>2009-12-01T06:55:36Z</updated>
	<author>
		<name>praveen_recker</name>
	</author>
	<content type="html">Hi Folks,
&lt;br&gt;&lt;br&gt;Is there any tool like tcpreplay/tomahawk which is used to replay Packet Captures(PCAPs) across NATting devices or Firewalls?
&lt;br&gt;&lt;br&gt;In tcpreplay we have -N option for NAT, is it straight forward usage or should we need to configure anything to replay properly?
&lt;br&gt;&lt;br&gt;Many Thanks,
&lt;br&gt;Praveen Darshanam,
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PCAP-replay-across-firewall-NAT-device-tp26597545p26597545.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597475</id>
	<title>Re: [Full-disclosure] Facebook Police</title>
	<published>2009-11-30T05:41:34Z</published>
	<updated>2009-11-30T05:41:34Z</updated>
	<author>
		<name>martinez85</name>
	</author>
	<content type="html">NI,
&lt;br&gt;&lt;br&gt;No responses to your post yet, but I agree with you in some degree. I am trying to understand where you are coming from though.
&lt;br&gt;&lt;br&gt;Is there a reason why you want law officials to use their real names, or anyone else, besides the fact that you may want to find an old High School sweet heart?
&lt;br&gt;&lt;br&gt;If you could elaborate a little more, I may be able to see where you are coming from.
&lt;br&gt;&lt;br&gt;Law officials may need to disguise their identity for certain operations, for example, to catch online predators. 
&lt;br&gt;&lt;br&gt;I may be trying to get a job and do not want my prospective employer to find me on Facebook and try to befriend me just obtain information on whether or not they should hire me or not.
&lt;br&gt;&lt;br&gt;The two examples, amongst (I'm sure) many others, are valid in my book and possibly in others too.
&lt;br&gt;Sent via BlackBerry by AT&amp;T
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: netinfinity &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597475&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;netinfinity.securitylab@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: Fri, 27 Nov 2009 01:46:05 
&lt;br&gt;To: &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597475&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Subject: Re: [Full-disclosure] Facebook Police
&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;quot;Facebook policy requires the use of one’s real name to sign up, but
&lt;br&gt;they let the police use fake names..&amp;quot;
&lt;br&gt;&lt;br&gt;Sure the policy says that but a lot of people are changing their names
&lt;br&gt;on a daily basis (ok maybe not daily). And majority of those changes
&lt;br&gt;are
&lt;br&gt;just for fun, but never the less they are against the policy. What
&lt;br&gt;about those people? Only way to verify or check someone's name is
&lt;br&gt;through IP (ISP). And that can't be done
&lt;br&gt;by will.. It must have some legal grounds...
&lt;br&gt;&lt;br&gt;Let me get to the point, I'm sure that police is violating some some
&lt;br&gt;kind of human rights or even law's (?)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;netinfinity
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A--Full-disclosure--Facebook-Police-tp26546745p26597475.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597427</id>
	<title>Compilation of major vendors firewall vulnerability history</title>
	<published>2009-11-29T11:22:12Z</published>
	<updated>2009-11-29T11:22:12Z</updated>
	<author>
		<name>Stephen Mullins</name>
	</author>
	<content type="html">List,
&lt;br&gt;&lt;br&gt;Does anyone know of an existing list of known vulnerabilities for
&lt;br&gt;corporate firewalls from the major vendors (Cisco, Juniper,
&lt;br&gt;McAfee/Secure Computing, Fortinet) over the past few years?
&lt;br&gt;&lt;br&gt;I'm looking for a list of them all in one place rather than searching
&lt;br&gt;vulnerability databases manually.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Steve
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Compilation-of-major-vendors-firewall-vulnerability-history-tp26597427p26597427.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597348</id>
	<title>Re: adding another defence layer against viruses/worms</title>
	<published>2009-11-27T22:39:15Z</published>
	<updated>2009-11-27T22:39:15Z</updated>
	<author>
		<name>Nathan ONeal</name>
	</author>
	<content type="html">Juan,
&lt;br&gt;&lt;br&gt;In addition to all of the solid recommendations given previously, I would ask your client how far they are willing to go to prevent these issues. It also matters if all nodes accessing the network are owned and &amp;nbsp;provisioned by your client (for your sake I truly hope so). Assuming these things are true, and they have a some decent network policies in place, I would suggest looking at &amp;quot;white listing&amp;quot; for your end points. We are all aware of how lacking TPM is with no vendor actually providing certificates on the hardware to validate their signed code, but we have had measured success utilizing programs like Prevx and Core Tracer (neither of which I work for by the way) to fill in these gaps.
&lt;br&gt;&lt;br&gt;Core Tracer specifically had great success at the last Defcon and from what I saw point us towards the future of endpoint security. At the massive rate that malware is being created and mutated, we have decided that a whitelist approach on the end point is the most effective way to mitigate the majority of problems we were experiencing with endusers. It is my no means a silver bullet and I am not suggesting you abandon proactive event correlation and malware mitigation at the network level, but I know it has saved our team massive amounts of time not only by reducing the number of fires that come up, but also allowing us a little bit of time to test out what the vendor patches break while fixing their own code. Good luck mate.
&lt;br&gt;&lt;br&gt;Nathan O'Neal
&lt;br&gt;&lt;br&gt;On Nov 26, 2009, at 9:11 PM, aditya mukadam wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Juan,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I would highly recommend you few solutions as below :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 1) End point Security Check : You can enforce strict PC/Laptop policy
&lt;br&gt;&amp;gt; (which would make sure that every PC/Laptop has AV/Personal Firewall).
&lt;br&gt;&amp;gt; Devices like UAC/NAC, can perform end point security check on
&lt;br&gt;&amp;gt; PC/Laptps while it connects to the network. This will atleast make
&lt;br&gt;&amp;gt; sure every user has an AV.
&lt;br&gt;&amp;gt; 2) (Standalone) Content/Protocol Filtering: With this solution, you
&lt;br&gt;&amp;gt; can make sure that the user traffic passes through an application,
&lt;br&gt;&amp;gt; which filters the content of the traffic and also does protocol
&lt;br&gt;&amp;gt; filtering (Example: Websense)
&lt;br&gt;&amp;gt; 3) Proxy Content Filtering : Since you mentioned that you don't have
&lt;br&gt;&amp;gt; control this solution would not fit in however its worth considering
&lt;br&gt;&amp;gt; for future usage. Example: BlueCoat Proxy
&lt;br&gt;&amp;gt; 4) IPS : I would recommend Tipping Point IPS, Juniper IDP.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hope this helps.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Aditya Govind Mukadam
&lt;br&gt;&amp;gt; CISSP,CEH,JNSA-Advanced Security, JNCIA-UAC, JNCIA_SSL, CQS-PIX,CQS-VPN
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://in.linkedin.com/in/adityamukadam&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://in.linkedin.com/in/adityamukadam&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Tue, Nov 24, 2009 at 7:33 PM, Juan B &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597348&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30 remote branches connected to his core. the problem is that sometimes the AV fails to detect new viruses/worms coming from those branches so those viruses/worms mess up his LAN.another problem is that the the client doesn't have much of control over the remote PCs in the branches. so I thought about adding another layer of defence in which we will add an IPS (which Ips detects also viruses/worms??) which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt;&amp;gt; juan
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26597348.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597234</id>
	<title>Re: adding another defence layer against viruses/worms</title>
	<published>2009-11-27T13:04:28Z</published>
	<updated>2009-11-27T13:04:28Z</updated>
	<author>
		<name>juanb007</name>
	</author>
	<content type="html">Hi Aditya,
&lt;br&gt;&lt;br&gt;The client will implemt NAC for the pc's later the next year and he also has a proxy for web content filtering the thing is that I need an appliance (IPS ?) which will examine all the pc's traffic from the branches coming fron the pc's to the core of the network, but IPS its not enogh I think coase the IPS doensnt scan for viruses just for known attacks am I wrong?
&lt;br&gt;&lt;br&gt;They are worriend about trojans and viruses, they had a problem this year because of the confliker virusres that effected the network, the AV didn't cought it although it was updated.
&lt;br&gt;&lt;br&gt;I know NAC will help but I want something that will look on the wire also.
&lt;br&gt;Some inline appliance but I don't know how to choose, mayve finjan or alladin?
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;Aditya Govind Mukadam
&lt;br&gt;CISSP,CEH,JNSA-Advanced Security, JNCIA-UAC, JNCIA_SSL, CQS-PIX,CQS-VPN &amp;nbsp;&lt;a href=&quot;http://in.linkedin.com/in/adityamukadam&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://in.linkedin.com/in/adityamukadam&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 7:33 PM, Juan B &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597234&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30 remote branches connected to his core. the problem is that sometimes the AV fails to detect new viruses/worms coming from those branches so those viruses/worms mess up his LAN.another problem is that the the client doesn't have much of control over the remote PCs in the branches. so I thought about adding another layer of defence in which we will add an IPS (which Ips detects also viruses/worms??) which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt; juan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; -- Securing Apache Web Server with thawte Digital Certificate In this 
&lt;br&gt;&amp;gt; guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&lt;/a&gt;&lt;br&gt;&amp;gt; 42f727d1
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26597234.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597303</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-11-27T12:37:51Z</published>
	<updated>2009-11-27T12:37:51Z</updated>
	<author>
		<name>Quark Group - Hilton Travis</name>
	</author>
	<content type="html">G'day Juan,
&lt;br&gt;&lt;br&gt;The best move would be to deploy a good AV product instead of whichever one you're currently running. &amp;nbsp;The best one around now (and since about 1999) is still NOD32, however you cannot run the latest version on Servers also running Microsoft Exchange as the Eset guys seem to have deemed Exchange not worth updating for - their current version is 4.x however the latest Exchange version is 2.7x, meaning you need to run an ancient version on Windows Server boxes running Exchange - something I honestly cannot understand why they have left this way.
&lt;br&gt;&lt;br&gt;Aside from that issue, NOD32 has the best heuristics, best detection rates and outstandingly low false positive rates *even* when Heuristics have been cranked up to the highest level.
&lt;br&gt;&lt;br&gt;So, I'd look at fixing the broken AV issue at the source, then look at other ways to implement better control of the remote PCs, such as distributed AD controllers and using GPO for what it was designed for - control of servers and desktops on the domain.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://hiltont.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hiltont.blogspot.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Hilton Travis &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Phone: +61 (0)7 3105 9101
&lt;br&gt;(Brisbane, Australia) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Phone: +61 (0)419 792 394
&lt;br&gt;Manager, Quark IT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.quarkit.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.quarkit.com.au&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Quark Group &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.quarkgroup.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.quarkgroup.com.au&lt;/a&gt;&lt;br&gt;&lt;br&gt;War doesn't determine who is right. &amp;nbsp;War determines who is left.
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597303&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597303&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; On Behalf Of Juan B
&lt;br&gt;&amp;gt; Sent: Wednesday, 25 November 2009 12:04 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597303&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: adding another defence layer against viruses/worms
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30
&lt;br&gt;&amp;gt; remote branches connected to his core. the problem is that sometimes the
&lt;br&gt;&amp;gt; AV fails to detect new viruses/worms coming from those branches so those
&lt;br&gt;&amp;gt; viruses/worms mess up his LAN.another problem is that the the client
&lt;br&gt;&amp;gt; doesn't have much of control over the remote PCs in the branches. so I
&lt;br&gt;&amp;gt; thought about adding another layer of defence in which we will add an IPS
&lt;br&gt;&amp;gt; (which Ips detects also viruses/worms??) which will filter and scan all traffic
&lt;br&gt;&amp;gt; coming from the branches.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt; juan
&lt;/div&gt;&lt;br&gt;&lt;br&gt;This document and any attachments are for the intended recipient only.
&lt;br&gt;It may contain confidential, privileged or copyright material which
&lt;br&gt;must not be disclosed or distributed without prior approval.
&lt;br&gt;&lt;br&gt;Quark Group Pty Ltd :: ABN 23 114 975 772
&lt;br&gt;Trading As Quark AudioVisual, Quark Automation, Quark IT
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26597303.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26597189</id>
	<title>RE: [Full-disclosure] Facebook Police</title>
	<published>2009-11-27T12:12:07Z</published>
	<updated>2009-11-27T12:12:07Z</updated>
	<author>
		<name>Michael.Barber</name>
	</author>
	<content type="html">Interesting take on the situation... however if you extend internet to real life your argument takes on a different tone. &amp;nbsp;By your reasoning it should be illegal for law enforcement to go undercover. &amp;nbsp;If you assume it is legal for a cop to go undercover ... then he/she is using a real name. &amp;nbsp;Therefore no laws or policy's are being broken.
&lt;br&gt;&lt;br&gt;Just my 0.02.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597189&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597189&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of netinfinity
&lt;br&gt;Sent: Thursday, November 26, 2009 7:46 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26597189&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Full-disclosure] Facebook Police
&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;quot;Facebook policy requires the use of one's real name to sign up, but
&lt;br&gt;they let the police use fake names..&amp;quot;
&lt;br&gt;&lt;br&gt;Sure the policy says that but a lot of people are changing their names
&lt;br&gt;on a daily basis (ok maybe not daily). And majority of those changes
&lt;br&gt;are
&lt;br&gt;just for fun, but never the less they are against the policy. What
&lt;br&gt;about those people? Only way to verify or check someone's name is
&lt;br&gt;through IP (ISP). And that can't be done
&lt;br&gt;by will.. It must have some legal grounds...
&lt;br&gt;&lt;br&gt;Let me get to the point, I'm sure that police is violating some some
&lt;br&gt;kind of human rights or even law's (?)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;netinfinity
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A--Full-disclosure--Facebook-Police-tp26546745p26597189.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546592</id>
	<title>Re: OT: Can an old NIC driver affect TLS?</title>
	<published>2009-11-27T10:40:30Z</published>
	<updated>2009-11-27T10:40:30Z</updated>
	<author>
		<name>Adam Mooz</name>
	</author>
	<content type="html">On 2009-11-27, at 7:04 AM, Paul Halliday wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I have been troubleshooting a weird latency issue between a web client
&lt;br&gt;&amp;gt; and a finance application.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The NIC driver was stamped 2006 and after an update the problem seems
&lt;br&gt;&amp;gt; to have disappeared. Does this make sense?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;A driver most certainly can effect latency, or just about any other parameter of the NIC. &amp;nbsp;Example, if the old driver you had installed contained a 'hack' that was put there just to get the driver working while a proper patch was developed, this 'hack' may have been the source of your latency; which when removed in a future update disappeared. &amp;nbsp;Drivers should always be kept up to date, typically for NIC's a driver update is going to improve either performance or stability. &amp;nbsp;
&lt;br&gt;&lt;br&gt;-----------------------------------------------------------------
&lt;br&gt;Adam Mooz
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546592&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Adam.Mooz@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546592&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;AdamMooz@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.AdamMooz.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.AdamMooz.com&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OT%3A-Can-an-old-NIC-driver-affect-TLS--tp26546278p26546592.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546550</id>
	<title>Re: OT: Can an old NIC driver affect TLS?</title>
	<published>2009-11-27T10:40:22Z</published>
	<updated>2009-11-27T10:40:22Z</updated>
	<author>
		<name>Lubrano di Ciccone, Christophe (DEF)</name>
	</author>
	<content type="html">Yes
&lt;br&gt;Driver update rollout policy and strategy apply not only to server but also to client
&lt;br&gt;Christophe
&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546550&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546550&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: Securityfocus &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546550&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Fri Nov 27 13:04:19 2009
&lt;br&gt;Subject: OT: Can an old NIC driver affect TLS?
&lt;br&gt;&lt;br&gt;I have been troubleshooting a weird latency issue between a web client
&lt;br&gt;and a finance application.
&lt;br&gt;&lt;br&gt;The NIC driver was stamped 2006 and after an update the problem seems
&lt;br&gt;to have disappeared. Does this make sense?
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-OT%3A-Can-an-old-NIC-driver-affect-TLS--tp26546550p26546550.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546278</id>
	<title>OT: Can an old NIC driver affect TLS?</title>
	<published>2009-11-27T04:04:19Z</published>
	<updated>2009-11-27T04:04:19Z</updated>
	<author>
		<name>Paul Halliday</name>
	</author>
	<content type="html">I have been troubleshooting a weird latency issue between a web client
&lt;br&gt;and a finance application.
&lt;br&gt;&lt;br&gt;The NIC driver was stamped 2006 and after an update the problem seems
&lt;br&gt;to have disappeared. Does this make sense?
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OT%3A-Can-an-old-NIC-driver-affect-TLS--tp26546278p26546278.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546876</id>
	<title>Re: adding another defence layer against viruses/worms</title>
	<published>2009-11-26T19:11:28Z</published>
	<updated>2009-11-26T19:11:28Z</updated>
	<author>
		<name>aditya mukadam</name>
	</author>
	<content type="html">Juan,
&lt;br&gt;&lt;br&gt;I would highly recommend you few solutions as below :
&lt;br&gt;&lt;br&gt;1) End point Security Check : You can enforce strict PC/Laptop policy
&lt;br&gt;(which would make sure that every PC/Laptop has AV/Personal Firewall).
&lt;br&gt;Devices like UAC/NAC, can perform end point security check on
&lt;br&gt;PC/Laptps while it connects to the network. This will atleast make
&lt;br&gt;sure every user has an AV.
&lt;br&gt;2) (Standalone) Content/Protocol Filtering: With this solution, you
&lt;br&gt;can make sure that the user traffic passes through an application,
&lt;br&gt;which filters the content of the traffic and also does protocol
&lt;br&gt;filtering (Example: Websense)
&lt;br&gt;3) Proxy Content Filtering : Since you mentioned that you don't have
&lt;br&gt;control this solution would not fit in however its worth considering
&lt;br&gt;for future usage. Example: BlueCoat Proxy
&lt;br&gt;4) IPS : I would recommend Tipping Point IPS, Juniper IDP.
&lt;br&gt;&lt;br&gt;Hope this helps.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;Aditya Govind Mukadam
&lt;br&gt;CISSP,CEH,JNSA-Advanced Security, JNCIA-UAC, JNCIA_SSL, CQS-PIX,CQS-VPN
&lt;br&gt;&amp;nbsp;&lt;a href=&quot;http://in.linkedin.com/in/adityamukadam&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://in.linkedin.com/in/adityamukadam&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 7:33 PM, Juan B &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546876&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this client have around 30 remote branches connected to his core. the problem is that sometimes the AV fails to detect new viruses/worms coming from those branches so those viruses/worms mess up his LAN.another problem is that the the client doesn't have much of control over the remote PCs in the branches. so I thought about adding another layer of defence in which we will add an IPS (which Ips detects also viruses/worms??) which will filter and scan all traffic coming from the branches.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks a lot
&lt;br&gt;&amp;gt; juan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26546876.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546888</id>
	<title>Re: Dealing with Scans (portscans, vulnerability, etc.)</title>
	<published>2009-11-26T18:56:19Z</published>
	<updated>2009-11-26T18:56:19Z</updated>
	<author>
		<name>aditya mukadam</name>
	</author>
	<content type="html">I agree with Jon K.
&lt;br&gt;&lt;br&gt;1) Ideally, your IDS shouldn't be seeing port scan from internet.
&lt;br&gt;Either your Border router or Firewall should block this traffic.
&lt;br&gt;2) Do not ignore scans. You need to know the threats your
&lt;br&gt;network/resource is up against. It could be a start to a potential
&lt;br&gt;attack.
&lt;br&gt;3) It is recommended that you report this to the ISP, irrespective of
&lt;br&gt;the fact it takes action or not.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;Aditya Govind Mukadam
&lt;br&gt;&lt;a href=&quot;http://in.linkedin.com/in/adityamukadam&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://in.linkedin.com/in/adityamukadam&lt;/a&gt;&lt;br&gt;&lt;br&gt;On Fri, Nov 27, 2009 at 1:56 AM, Holger Reichert
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546888&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;holger.reichert@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; just one hint regarding the topic of reporting this to a contact of the
&lt;br&gt;&amp;gt; company of where the attacking IP address is located.
&lt;br&gt;&amp;gt; In my times of defence system administration I decided to report major scans
&lt;br&gt;&amp;gt; to companies within my own country, which were the origin of attacks like
&lt;br&gt;&amp;gt; this. They were always very grateful, as they had not detected yet, that
&lt;br&gt;&amp;gt; they were hacked and their system used for scannings.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Kind regards
&lt;br&gt;&amp;gt; Holger Reichert
&lt;br&gt;&amp;gt; Holysword GbR
&lt;br&gt;&amp;gt; Information Security Consulting
&lt;br&gt;&amp;gt; Germany
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546888&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546888&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;&amp;gt; Behalf Of Aarón Mizrachi
&lt;br&gt;&amp;gt; Sent: Dienstag, 24. November 2009 21:29
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26546888&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Cc: Tony Raboza
&lt;br&gt;&amp;gt; Subject: Re: Dealing with Scans (portscans, vulnerability, etc.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Sunday 22 November 2009 01:35:02 Tony Raboza wrote:
&lt;br&gt;&amp;gt; &amp;gt; Hi,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I'm tuning my IDS and I'm thinking of taking out the portscan/web
&lt;br&gt;&amp;gt; &amp;gt; vulnerability scan rules.  Why?  Because, yes - I know that somebody
&lt;br&gt;&amp;gt; &amp;gt; may be scanning my network - but, what can I do about it?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; 1.  Block the IP? But, what if its NAT - meaning only 1
&lt;br&gt;&amp;gt; &amp;gt; workstation/user did the port scanning, I would be blocking all the
&lt;br&gt;&amp;gt; &amp;gt; possibly valid users behind that IP.
&lt;br&gt;&amp;gt; Indeed. That's right.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; 2.  Report it to their ISP or to them?  Then what?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; Not all ISP's take actions against it users doing port scanning. Depends on
&lt;br&gt;&amp;gt; internal policy and local legislation.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I want my IDS console not to be too cluttered that's why I'm tuning
&lt;br&gt;&amp;gt; &amp;gt; it.  If its too cluttered - I might be missing out the really
&lt;br&gt;&amp;gt; &amp;gt; important alerts.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; What about you?  How do you deal with port/vulnerability scans?
&lt;br&gt;&amp;gt; First of all, we must secure enough our sites/servers to prevent attacks,
&lt;br&gt;&amp;gt; even if the attacker know every detail about our platform, including
&lt;br&gt;&amp;gt; usernames, ports, OS, versions, hardware, and more.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; After that, we have two options to _delay_ scanning:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1- Restrict the scan: You can automatically block certain IP using IPS.  It
&lt;br&gt;&amp;gt; will delay, not prevent the scanning. An attacker could use anti-ips
&lt;br&gt;&amp;gt; techniques to prevent detection and surpass the protection.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2- Confuse the attacker: You can automatically send crafted information to
&lt;br&gt;&amp;gt; the scanning process and overload him with trash.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I wrote an application to do that, i called it portjammer / synackflood. Is
&lt;br&gt;&amp;gt; opensource, and you can download it from:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://sourceforge.net/projects/synackflood/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/projects/synackflood/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Is it
&lt;br&gt;&amp;gt; &amp;gt; illegal btw?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; We need to understand that Internet is not ruled by only one legislation.
&lt;br&gt;&amp;gt; Every country have their own laws on that matter. And attackers, usually are
&lt;br&gt;&amp;gt; based in other countries.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In my country (by example), we have a special law for internet crime,  this
&lt;br&gt;&amp;gt; law defines that any attacker can't  be extradited based on foreign laws on
&lt;br&gt;&amp;gt; that matter. And... scanning itself is not defined as a offense here.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Add it to this that many of these countries do not have infrastructure to
&lt;br&gt;&amp;gt; investigate cybercrime. And in addition, many attackers are using the free
&lt;br&gt;&amp;gt; wifi hotspots.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What means?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We must protect our networks against attackers around the world. Not
&lt;br&gt;&amp;gt; thinking that our local laws will protect us. Local laws are intended to
&lt;br&gt;&amp;gt; prevent local crime, and these laws do not always work out of our country.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Thanks.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Best,
&lt;br&gt;&amp;gt; &amp;gt; Tony
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; &amp;gt; -- Securing Apache Web Server with thawte Digital Certificate In this
&lt;br&gt;&amp;gt; &amp;gt; guide we examine the importance of Apache-SSL and who needs an SSL
&lt;br&gt;&amp;gt; &amp;gt; certificate.  We look at how SSL works, how it benefits your company
&lt;br&gt;&amp;gt; &amp;gt; and  how your customers can tell if a site is secure. You will find
&lt;br&gt;&amp;gt; &amp;gt; out how to  test, purchase, install and use a thawte Digital
&lt;br&gt;&amp;gt; &amp;gt; Certificate on your  Apache web server. Throughout, best practices for
&lt;br&gt;&amp;gt; &amp;gt; set-up are highlighted  to help you ensure efficient ongoing
&lt;br&gt;&amp;gt; &amp;gt; management of your encryption keys  and digital certificates.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 42f72
&lt;br&gt;&amp;gt; &amp;gt; 7d1
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Ing. Aaron G. Mizrachi P.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.unmanarc.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.unmanarc.com&lt;/a&gt;&lt;br&gt;&amp;gt; Mobil 1: + 58 416-6143543
&lt;br&gt;&amp;gt; BBPIN: 0x 247066C1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Dealing-with-Scans-%28portscans%2C-vulnerability%2C-etc.%29-tp26498509p26546888.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26546745</id>
	<title>Re: [Full-disclosure] Facebook Police</title>
	<published>2009-11-26T16:46:05Z</published>
	<updated>2009-11-26T16:46:05Z</updated>
	<author>
		<name>netinfinity</name>
	</author>
	<content type="html">&amp;nbsp;&amp;quot;Facebook policy requires the use of one’s real name to sign up, but
&lt;br&gt;they let the police use fake names..&amp;quot;
&lt;br&gt;&lt;br&gt;Sure the policy says that but a lot of people are changing their names
&lt;br&gt;on a daily basis (ok maybe not daily). And majority of those changes
&lt;br&gt;are
&lt;br&gt;just for fun, but never the less they are against the policy. What
&lt;br&gt;about those people? Only way to verify or check someone's name is
&lt;br&gt;through IP (ISP). And that can't be done
&lt;br&gt;by will.. It must have some legal grounds...
&lt;br&gt;&lt;br&gt;Let me get to the point, I'm sure that police is violating some some
&lt;br&gt;kind of human rights or even law's (?)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;netinfinity
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A--Full-disclosure--Facebook-Police-tp26546745p26546745.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535355</id>
	<title>RE: Dealing with Scans (portscans, vulnerability, etc.)</title>
	<published>2009-11-26T12:26:05Z</published>
	<updated>2009-11-26T12:26:05Z</updated>
	<author>
		<name>holger.reichert</name>
	</author>
	<content type="html">Hi, 
&lt;br&gt;just one hint regarding the topic of reporting this to a contact of the
&lt;br&gt;company of where the attacking IP address is located.
&lt;br&gt;In my times of defence system administration I decided to report major scans
&lt;br&gt;to companies within my own country, which were the origin of attacks like
&lt;br&gt;this. They were always very grateful, as they had not detected yet, that
&lt;br&gt;they were hacked and their system used for scannings.
&lt;br&gt;&lt;br&gt;Kind regards
&lt;br&gt;Holger Reichert
&lt;br&gt;Holysword GbR
&lt;br&gt;Information Security Consulting
&lt;br&gt;Germany
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535355&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535355&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of Aarón Mizrachi
&lt;br&gt;Sent: Dienstag, 24. November 2009 21:29
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535355&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Cc: Tony Raboza
&lt;br&gt;Subject: Re: Dealing with Scans (portscans, vulnerability, etc.)
&lt;br&gt;&lt;br&gt;On Sunday 22 November 2009 01:35:02 Tony Raboza wrote:
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm tuning my IDS and I'm thinking of taking out the portscan/web 
&lt;br&gt;&amp;gt; vulnerability scan rules. &amp;nbsp;Why? &amp;nbsp;Because, yes - I know that somebody 
&lt;br&gt;&amp;gt; may be scanning my network - but, what can I do about it?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 1. &amp;nbsp;Block the IP? But, what if its NAT - meaning only 1 
&lt;br&gt;&amp;gt; workstation/user did the port scanning, I would be blocking all the 
&lt;br&gt;&amp;gt; possibly valid users behind that IP.
&lt;br&gt;Indeed. That's right.
&lt;br&gt;&lt;br&gt;&amp;gt; 2. &amp;nbsp;Report it to their ISP or to them? &amp;nbsp;Then what?
&lt;br&gt;&amp;gt; 
&lt;br&gt;Not all ISP's take actions against it users doing port scanning. Depends on
&lt;br&gt;internal policy and local legislation.
&lt;br&gt;&lt;br&gt;&amp;gt; I want my IDS console not to be too cluttered that's why I'm tuning 
&lt;br&gt;&amp;gt; it. &amp;nbsp;If its too cluttered - I might be missing out the really 
&lt;br&gt;&amp;gt; important alerts.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; What about you? &amp;nbsp;How do you deal with port/vulnerability scans? &amp;nbsp;
&lt;br&gt;First of all, we must secure enough our sites/servers to prevent attacks,
&lt;br&gt;even if the attacker know every detail about our platform, including
&lt;br&gt;usernames, ports, OS, versions, hardware, and more.
&lt;br&gt;&lt;br&gt;After that, we have two options to _delay_ scanning:
&lt;br&gt;&lt;br&gt;1- Restrict the scan: You can automatically block certain IP using IPS. &amp;nbsp;It
&lt;br&gt;will delay, not prevent the scanning. An attacker could use anti-ips
&lt;br&gt;techniques to prevent detection and surpass the protection.
&lt;br&gt;&lt;br&gt;2- Confuse the attacker: You can automatically send crafted information to
&lt;br&gt;the scanning process and overload him with trash. 
&lt;br&gt;&lt;br&gt;I wrote an application to do that, i called it portjammer / synackflood. Is
&lt;br&gt;opensource, and you can download it from:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://sourceforge.net/projects/synackflood/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/projects/synackflood/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;gt; Is it
&lt;br&gt;&amp;gt; illegal btw?
&lt;br&gt;&amp;gt; 
&lt;br&gt;We need to understand that Internet is not ruled by only one legislation. 
&lt;br&gt;Every country have their own laws on that matter. And attackers, usually are
&lt;br&gt;based in other countries.
&lt;br&gt;&lt;br&gt;In my country (by example), we have a special law for internet crime, &amp;nbsp;this
&lt;br&gt;law defines that any attacker can't &amp;nbsp;be extradited based on foreign laws on
&lt;br&gt;that matter. And... scanning itself is not defined as a offense here.
&lt;br&gt;&lt;br&gt;Add it to this that many of these countries do not have infrastructure to
&lt;br&gt;investigate cybercrime. And in addition, many attackers are using the free
&lt;br&gt;wifi hotspots.
&lt;br&gt;&lt;br&gt;What means? 
&lt;br&gt;&lt;br&gt;We must protect our networks against attackers around the world. Not
&lt;br&gt;thinking that our local laws will protect us. Local laws are intended to
&lt;br&gt;prevent local crime, and these laws do not always work out of our country. 
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Best,
&lt;br&gt;&amp;gt; Tony
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; -- Securing Apache Web Server with thawte Digital Certificate In this 
&lt;br&gt;&amp;gt; guide we examine the importance of Apache-SSL and who needs an SSL &amp;nbsp;
&lt;br&gt;&amp;gt; certificate. &amp;nbsp;We look at how SSL works, how it benefits your company 
&lt;br&gt;&amp;gt; and &amp;nbsp;how your customers can tell if a site is secure. You will find 
&lt;br&gt;&amp;gt; out how to &amp;nbsp;test, purchase, install and use a thawte Digital 
&lt;br&gt;&amp;gt; Certificate on your &amp;nbsp;Apache web server. Throughout, best practices for 
&lt;br&gt;&amp;gt; set-up are highlighted &amp;nbsp;to help you ensure efficient ongoing 
&lt;br&gt;&amp;gt; management of your encryption keys &amp;nbsp;and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4&lt;/a&gt;&lt;br&gt;&amp;gt; 42f72
&lt;br&gt;&amp;gt; 7d1
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;Ing. Aaron G. Mizrachi P. &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.unmanarc.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.unmanarc.com&lt;/a&gt;&lt;br&gt;Mobil 1: + 58 416-6143543
&lt;br&gt;BBPIN: 0x 247066C1
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Dealing-with-Scans-%28portscans%2C-vulnerability%2C-etc.%29-tp26498509p26535355.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535625</id>
	<title>Re: [OT] IP Address scheme for branch office</title>
	<published>2009-11-26T07:44:56Z</published>
	<updated>2009-11-26T07:44:56Z</updated>
	<author>
		<name>martin-314</name>
	</author>
	<content type="html">Hi All
&lt;br&gt;&lt;br&gt;Thanks for the replies. &amp;nbsp;In answer to your questions, we are actually
&lt;br&gt;using Class A addresses globally (sorry, I didn't use the actual IP's
&lt;br&gt;in my original plan). &amp;nbsp;The EMEA region has been assigned one Class B
&lt;br&gt;network to sub-divide amongst our offices. &amp;nbsp;So unfortunately the
&lt;br&gt;solutions above won't fit our requirements.
&lt;br&gt;&lt;br&gt;Of course, assigning a /21 subnet to each office will meet the IP
&lt;br&gt;address requirements. &amp;nbsp;But it won't give us a standard set of
&lt;br&gt;&amp;quot;numbers&amp;quot; that we can use in each office. &amp;nbsp;I'm sure other global
&lt;br&gt;companies have this same predicament, but I'm wondering how they solve
&lt;br&gt;it ! &amp;nbsp;Assigning a /20 subnet would resolve the problem but would
&lt;br&gt;result is 4 wasted subnets per office.
&lt;br&gt;&lt;br&gt;Maybe I'm thinking &amp;quot;inside the box here&amp;quot; and need to come up with a
&lt;br&gt;different solution other than using the same number for each office.
&lt;br&gt;But unfortunately I'm at a bit of a brick wall :o( &amp;nbsp;I'd appreciate any
&lt;br&gt;guidance/help/ideas anybody else has on this. &amp;nbsp;I'm sure other global
&lt;br&gt;companies face the same challenge, so I'm wondering how they get
&lt;br&gt;around this
&lt;br&gt;&lt;br&gt;thanks in advance
&lt;br&gt;M
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OT--IP-Address-scheme-for-branch-office-tp26326071p26535625.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535567</id>
	<title>Re: Is snort an overkill for desktop only environment ?</title>
	<published>2009-11-26T07:33:51Z</published>
	<updated>2009-11-26T07:33:51Z</updated>
	<author>
		<name>martin-314</name>
	</author>
	<content type="html">2009/11/26 martin &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535567&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;martiniscool@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Guys
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sorry for not responding to this earlier.  First of all, thank you so
&lt;br&gt;&amp;gt; so much for all the replies on this, very much apprecaited.  We've
&lt;br&gt;&amp;gt; decided that we are definitely going to install snort.  Although we
&lt;br&gt;&amp;gt; think we know what all our traffic is, of course without monitoring
&lt;br&gt;&amp;gt; it, we don't actually know.  Likewise, if there's traffic passing
&lt;br&gt;&amp;gt; around the network that doesn't match what we think should be there,
&lt;br&gt;&amp;gt; then we definitely want to know about it, so I think even in our
&lt;br&gt;&amp;gt; environment it will definitely be useful
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks again
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; M
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fwd%3A-Is-snort-an-overkill-for-desktop-only-environment---tp26061107p26535567.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535526</id>
	<title>Re: adding another defence layer against viruses/worms</title>
	<published>2009-11-26T01:59:26Z</published>
	<updated>2009-11-26T01:59:26Z</updated>
	<author>
		<name>Mohamed Aymen SAHLI</name>
	</author>
	<content type="html">Maybe,
&lt;br&gt;&lt;br&gt;-Using local firewalls on these branches to filter outbound traffic to the core
&lt;br&gt;&lt;br&gt;-Centralize the internet access to have all web traffic go through a
&lt;br&gt;filtering appliance such as a &amp;nbsp;Cisco Iron Port &amp;nbsp;or &amp;nbsp;a websense web
&lt;br&gt;security.
&lt;br&gt;&lt;br&gt;-Have an antivirus solution deployed over the campus. &amp;nbsp;I would
&lt;br&gt;recommend Symantec EndPoint Protection as it provides good deal of
&lt;br&gt;flexibility in what concerns remote sites ( replication, local group
&lt;br&gt;updates provide to alleviate the bandwidth, &amp;nbsp;granular policy etc)
&lt;br&gt;&lt;br&gt;-Limit to the strict minimum the users with local administrator
&lt;br&gt;rights on their machines.
&lt;br&gt;-Prohibit removable media usage, thumb drives mainly. This, EndPoint
&lt;br&gt;Protection can do.
&lt;br&gt;-Prohibit local file sharing, system restore etc. (via group policy)
&lt;br&gt;-…
&lt;br&gt;&lt;br&gt;And above all, have a solid security policy written and approved by management.
&lt;br&gt;&lt;br&gt;Regards.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26535526.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535466</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-11-25T09:09:20Z</published>
	<updated>2009-11-25T09:09:20Z</updated>
	<author>
		<name>Rivest, Philippe-2</name>
	</author>
	<content type="html">Thats always an issue with IDS/IPS
&lt;br&gt;Sadly I dont know any heuristic IDS/IPS, I know the overall purpose and
&lt;br&gt;setup of these devices but I did not have the chance to play with any of
&lt;br&gt;them yet.
&lt;br&gt;&lt;br&gt;sorry
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Philippe Rivest - CEH, Network+, Server+, A+
&lt;br&gt;TransForce Inc.
&lt;br&gt;Internal auditor - Information security
&lt;br&gt;Verificateur interne - Securite de l'information
&lt;br&gt;&lt;br&gt;8585 Trans-Canada Highway, Suite 300
&lt;br&gt;Saint-Laurent (Quebec) H4S 1Z6
&lt;br&gt;Tel.: 514-331-4417 &amp;nbsp; 
&lt;br&gt;Fax: 514-856-7541
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.transforce.ca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.transforce.ca/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Message d'origine-----
&lt;br&gt;De : Juan B [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;] 
&lt;br&gt;Envoyé : 25 novembre 2009 11:55
&lt;br&gt;À : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;; Rivest,
&lt;br&gt;Philippe
&lt;br&gt;Objet : RE: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;Hi Philipe,
&lt;br&gt;&lt;br&gt;thanks for your respond !
&lt;br&gt;&lt;br&gt;the issue about heuristic IPS is that it will be in the lan so Im afraid of
&lt;br&gt;a high volume of false positives ! 
&lt;br&gt;which heuristic IPS would you suggest for this task?
&lt;br&gt;&lt;br&gt;thanks 
&lt;br&gt;&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;--- On Wed, 11/25/09, Rivest, Philippe &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;PRivest@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; From: Rivest, Philippe &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;PRivest@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: RE: adding another defense layer against viruses/worms
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Date: Wednesday, November 25, 2009, 11:31 AM
&lt;br&gt;&amp;gt; I believe your looking for a
&lt;br&gt;&amp;gt; Heuristic IPS, also called behavioral IPS.
&lt;br&gt;&amp;gt; Which will take a look at the activities going on your
&lt;br&gt;&amp;gt; network segment and
&lt;br&gt;&amp;gt; build a DB of normal activities (PLEASE ensure you are
&lt;br&gt;&amp;gt; virus, worm, hacker
&lt;br&gt;&amp;gt; and problem free..). When you decide your DB is big enough,
&lt;br&gt;&amp;gt; you stop it and
&lt;br&gt;&amp;gt; run all day-2-day activities against it. Any deviation will
&lt;br&gt;&amp;gt; be flagged as
&lt;br&gt;&amp;gt; unauthorized and action will be taken.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This will allow you to block new virus/worm while your AV
&lt;br&gt;&amp;gt; should detect
&lt;br&gt;&amp;gt; known threats. 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Understand that these solutions are technical and I would
&lt;br&gt;&amp;gt; suggest you get
&lt;br&gt;&amp;gt; help if you're not familiar with these technologies.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I like the solutions ob Boaz, especially network
&lt;br&gt;&amp;gt; segregation. Implementing
&lt;br&gt;&amp;gt; DMZ will contain (should) attacks.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You can also use 2 levels of AV. IE use TrendMicro for
&lt;br&gt;&amp;gt; network detection and
&lt;br&gt;&amp;gt; Mcafe for host AV. This will reduce the risk that if one
&lt;br&gt;&amp;gt; can't detect the
&lt;br&gt;&amp;gt; threat, maybe the other can.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Id also suggests using network proxies. If you break the
&lt;br&gt;&amp;gt; client-server
&lt;br&gt;&amp;gt; communication, you might be able to scan your packets
&lt;br&gt;&amp;gt; deeper and detect
&lt;br&gt;&amp;gt; attacks before they are sent to the client.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hope this helps :)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Philippe Rivest - CEH, Network+, Server+, A+
&lt;br&gt;&amp;gt; TransForce Inc.
&lt;br&gt;&amp;gt; Internal auditor - Information security
&lt;br&gt;&amp;gt; Verificateur interne - Securite de l'information
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 8585 Trans-Canada Highway, Suite 300
&lt;br&gt;&amp;gt; Saint-Laurent (Quebec) H4S 1Z6
&lt;br&gt;&amp;gt; Tel.: 514-331-4417   
&lt;br&gt;&amp;gt; Fax: 514-856-7541
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.transforce.ca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.transforce.ca/&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Message d'origine-----
&lt;br&gt;&amp;gt; De : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; De
&lt;br&gt;&amp;gt; la part de &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Envoyé : 25 novembre 2009 02:08
&lt;br&gt;&amp;gt; À : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Objet : RE: adding another defence layer against
&lt;br&gt;&amp;gt; viruses/worms
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi Juan,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I would advise your Client to either:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 1. Have solid policy as to what sites are accessible/are
&lt;br&gt;&amp;gt; not accessible
&lt;br&gt;&amp;gt; from his branches (can be enforced with bluecoat and the
&lt;br&gt;&amp;gt; like...)
&lt;br&gt;&amp;gt; 2. Segregate the network the branches have access to (kind
&lt;br&gt;&amp;gt; of DMZ) from
&lt;br&gt;&amp;gt; his LAN using FW.
&lt;br&gt;&amp;gt; 3. Give low level permissions to the branches on the core.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; My 2c...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Boaz
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; On Behalf Of Juan B
&lt;br&gt;&amp;gt; Sent: Tuesday, November 24, 2009 4:04 PM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535466&amp;i=15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: adding another defence layer against
&lt;br&gt;&amp;gt; viruses/worms
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this
&lt;br&gt;&amp;gt; client have around
&lt;br&gt;&amp;gt; 30 remote branches connected to his core. the problem is
&lt;br&gt;&amp;gt; that sometimes
&lt;br&gt;&amp;gt; the AV fails to detect new viruses/worms coming from those
&lt;br&gt;&amp;gt; branches so
&lt;br&gt;&amp;gt; those viruses/worms mess up his LAN.another problem is that
&lt;br&gt;&amp;gt; the the
&lt;br&gt;&amp;gt; client doesn't have much of control over the remote PCs in
&lt;br&gt;&amp;gt; the branches.
&lt;br&gt;&amp;gt; so I thought about adding another layer of defence in which
&lt;br&gt;&amp;gt; we will add
&lt;br&gt;&amp;gt; an IPS (which Ips detects also viruses/worms??) which will
&lt;br&gt;&amp;gt; filter and
&lt;br&gt;&amp;gt; scan all traffic coming from the branches.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; thanks a lot 
&lt;br&gt;&amp;gt; juan
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;       
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and
&lt;br&gt;&amp;gt; who needs an
&lt;br&gt;&amp;gt; SSL certificate.  We look at how SSL works, how it
&lt;br&gt;&amp;gt; benefits your company
&lt;br&gt;&amp;gt; and how your customers can tell if a site is secure. You
&lt;br&gt;&amp;gt; will find out
&lt;br&gt;&amp;gt; how to test, purchase, install and use a thawte Digital
&lt;br&gt;&amp;gt; Certificate on
&lt;br&gt;&amp;gt; your Apache web server. Throughout, best practices for
&lt;br&gt;&amp;gt; set-up are
&lt;br&gt;&amp;gt; highlighted to help you ensure efficient ongoing management
&lt;br&gt;&amp;gt; of your
&lt;br&gt;&amp;gt; encryption keys and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&lt;/a&gt;&lt;br&gt;&amp;gt; f727d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and
&lt;br&gt;&amp;gt; who needs an SSL
&lt;br&gt;&amp;gt; certificate.  We look at how SSL works, how it
&lt;br&gt;&amp;gt; benefits your company and how
&lt;br&gt;&amp;gt; your customers can tell if a site is secure. You will find
&lt;br&gt;&amp;gt; out how to test,
&lt;br&gt;&amp;gt; purchase, install and use a thawte Digital Certificate on
&lt;br&gt;&amp;gt; your Apache web
&lt;br&gt;&amp;gt; server. Throughout, best practices for set-up are
&lt;br&gt;&amp;gt; highlighted to help you
&lt;br&gt;&amp;gt; ensure efficient ongoing management of your encryption keys
&lt;br&gt;&amp;gt; and digital
&lt;br&gt;&amp;gt; certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;&amp;gt; d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (2K) &lt;a href=&quot;http://old.nabble.com/attachment/26535466/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26535466.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535343</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-11-25T08:54:43Z</published>
	<updated>2009-11-25T08:54:43Z</updated>
	<author>
		<name>juanb007</name>
	</author>
	<content type="html">Hi Philipe,
&lt;br&gt;&lt;br&gt;thanks for your respond !
&lt;br&gt;&lt;br&gt;the issue about heuristic IPS is that it will be in the lan so Im afraid of a high volume of false positives ! 
&lt;br&gt;which heuristic IPS would you suggest for this task?
&lt;br&gt;&lt;br&gt;thanks 
&lt;br&gt;&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;--- On Wed, 11/25/09, Rivest, Philippe &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;PRivest@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; From: Rivest, Philippe &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;PRivest@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: RE: adding another defense layer against viruses/worms
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Date: Wednesday, November 25, 2009, 11:31 AM
&lt;br&gt;&amp;gt; I believe your looking for a
&lt;br&gt;&amp;gt; Heuristic IPS, also called behavioral IPS.
&lt;br&gt;&amp;gt; Which will take a look at the activities going on your
&lt;br&gt;&amp;gt; network segment and
&lt;br&gt;&amp;gt; build a DB of normal activities (PLEASE ensure you are
&lt;br&gt;&amp;gt; virus, worm, hacker
&lt;br&gt;&amp;gt; and problem free..). When you decide your DB is big enough,
&lt;br&gt;&amp;gt; you stop it and
&lt;br&gt;&amp;gt; run all day-2-day activities against it. Any deviation will
&lt;br&gt;&amp;gt; be flagged as
&lt;br&gt;&amp;gt; unauthorized and action will be taken.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This will allow you to block new virus/worm while your AV
&lt;br&gt;&amp;gt; should detect
&lt;br&gt;&amp;gt; known threats. 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Understand that these solutions are technical and I would
&lt;br&gt;&amp;gt; suggest you get
&lt;br&gt;&amp;gt; help if you're not familiar with these technologies.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I like the solutions ob Boaz, especially network
&lt;br&gt;&amp;gt; segregation. Implementing
&lt;br&gt;&amp;gt; DMZ will contain (should) attacks.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You can also use 2 levels of AV. IE use TrendMicro for
&lt;br&gt;&amp;gt; network detection and
&lt;br&gt;&amp;gt; Mcafe for host AV. This will reduce the risk that if one
&lt;br&gt;&amp;gt; can't detect the
&lt;br&gt;&amp;gt; threat, maybe the other can.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Id also suggests using network proxies. If you break the
&lt;br&gt;&amp;gt; client-server
&lt;br&gt;&amp;gt; communication, you might be able to scan your packets
&lt;br&gt;&amp;gt; deeper and detect
&lt;br&gt;&amp;gt; attacks before they are sent to the client.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hope this helps :)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Philippe Rivest - CEH, Network+, Server+, A+
&lt;br&gt;&amp;gt; TransForce Inc.
&lt;br&gt;&amp;gt; Internal auditor - Information security
&lt;br&gt;&amp;gt; Verificateur interne - Securite de l'information
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 8585 Trans-Canada Highway, Suite 300
&lt;br&gt;&amp;gt; Saint-Laurent (Quebec) H4S 1Z6
&lt;br&gt;&amp;gt; Tel.: 514-331-4417   
&lt;br&gt;&amp;gt; Fax: 514-856-7541
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.transforce.ca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.transforce.ca/&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Message d'origine-----
&lt;br&gt;&amp;gt; De : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; De
&lt;br&gt;&amp;gt; la part de &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Envoyé : 25 novembre 2009 02:08
&lt;br&gt;&amp;gt; À : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Objet : RE: adding another defence layer against
&lt;br&gt;&amp;gt; viruses/worms
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi Juan,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I would advise your Client to either:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 1. Have solid policy as to what sites are accessible/are
&lt;br&gt;&amp;gt; not accessible
&lt;br&gt;&amp;gt; from his branches (can be enforced with bluecoat and the
&lt;br&gt;&amp;gt; like...)
&lt;br&gt;&amp;gt; 2. Segregate the network the branches have access to (kind
&lt;br&gt;&amp;gt; of DMZ) from
&lt;br&gt;&amp;gt; his LAN using FW.
&lt;br&gt;&amp;gt; 3. Give low level permissions to the branches on the core.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; My 2c...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Boaz
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; On Behalf Of Juan B
&lt;br&gt;&amp;gt; Sent: Tuesday, November 24, 2009 4:04 PM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535343&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: adding another defence layer against
&lt;br&gt;&amp;gt; viruses/worms
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm doing some security consulting for a client. this
&lt;br&gt;&amp;gt; client have around
&lt;br&gt;&amp;gt; 30 remote branches connected to his core. the problem is
&lt;br&gt;&amp;gt; that sometimes
&lt;br&gt;&amp;gt; the AV fails to detect new viruses/worms coming from those
&lt;br&gt;&amp;gt; branches so
&lt;br&gt;&amp;gt; those viruses/worms mess up his LAN.another problem is that
&lt;br&gt;&amp;gt; the the
&lt;br&gt;&amp;gt; client doesn't have much of control over the remote PCs in
&lt;br&gt;&amp;gt; the branches.
&lt;br&gt;&amp;gt; so I thought about adding another layer of defence in which
&lt;br&gt;&amp;gt; we will add
&lt;br&gt;&amp;gt; an IPS (which Ips detects also viruses/worms??) which will
&lt;br&gt;&amp;gt; filter and
&lt;br&gt;&amp;gt; scan all traffic coming from the branches.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I just wonder if you guys agree with my suggestion.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; any comments will be welcomed.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; BTW,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; any recomendations for the IPS?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; thanks a lot 
&lt;br&gt;&amp;gt; juan
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;       
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and
&lt;br&gt;&amp;gt; who needs an
&lt;br&gt;&amp;gt; SSL certificate.  We look at how SSL works, how it
&lt;br&gt;&amp;gt; benefits your company
&lt;br&gt;&amp;gt; and how your customers can tell if a site is secure. You
&lt;br&gt;&amp;gt; will find out
&lt;br&gt;&amp;gt; how to test, purchase, install and use a thawte Digital
&lt;br&gt;&amp;gt; Certificate on
&lt;br&gt;&amp;gt; your Apache web server. Throughout, best practices for
&lt;br&gt;&amp;gt; set-up are
&lt;br&gt;&amp;gt; highlighted to help you ensure efficient ongoing management
&lt;br&gt;&amp;gt; of your
&lt;br&gt;&amp;gt; encryption keys and digital certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&lt;/a&gt;&lt;br&gt;&amp;gt; f727d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;&amp;gt; In this guide we examine the importance of Apache-SSL and
&lt;br&gt;&amp;gt; who needs an SSL
&lt;br&gt;&amp;gt; certificate.  We look at how SSL works, how it
&lt;br&gt;&amp;gt; benefits your company and how
&lt;br&gt;&amp;gt; your customers can tell if a site is secure. You will find
&lt;br&gt;&amp;gt; out how to test,
&lt;br&gt;&amp;gt; purchase, install and use a thawte Digital Certificate on
&lt;br&gt;&amp;gt; your Apache web
&lt;br&gt;&amp;gt; server. Throughout, best practices for set-up are
&lt;br&gt;&amp;gt; highlighted to help you
&lt;br&gt;&amp;gt; ensure efficient ongoing management of your encryption keys
&lt;br&gt;&amp;gt; and digital
&lt;br&gt;&amp;gt; certificates.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;&amp;gt; d1
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26535343.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535255</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-11-25T08:31:16Z</published>
	<updated>2009-11-25T08:31:16Z</updated>
	<author>
		<name>Rivest, Philippe-2</name>
	</author>
	<content type="html">I believe your looking for a Heuristic IPS, also called behavioral IPS.
&lt;br&gt;Which will take a look at the activities going on your network segment and
&lt;br&gt;build a DB of normal activities (PLEASE ensure you are virus, worm, hacker
&lt;br&gt;and problem free..). When you decide your DB is big enough, you stop it and
&lt;br&gt;run all day-2-day activities against it. Any deviation will be flagged as
&lt;br&gt;unauthorized and action will be taken.
&lt;br&gt;&lt;br&gt;This will allow you to block new virus/worm while your AV should detect
&lt;br&gt;known threats. 
&lt;br&gt;&lt;br&gt;Understand that these solutions are technical and I would suggest you get
&lt;br&gt;help if you're not familiar with these technologies.
&lt;br&gt;&lt;br&gt;&lt;br&gt;I like the solutions ob Boaz, especially network segregation. Implementing
&lt;br&gt;DMZ will contain (should) attacks.
&lt;br&gt;&lt;br&gt;You can also use 2 levels of AV. IE use TrendMicro for network detection and
&lt;br&gt;Mcafe for host AV. This will reduce the risk that if one can't detect the
&lt;br&gt;threat, maybe the other can.
&lt;br&gt;&lt;br&gt;Id also suggests using network proxies. If you break the client-server
&lt;br&gt;communication, you might be able to scan your packets deeper and detect
&lt;br&gt;attacks before they are sent to the client.
&lt;br&gt;&lt;br&gt;Hope this helps :)
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Philippe Rivest - CEH, Network+, Server+, A+
&lt;br&gt;TransForce Inc.
&lt;br&gt;Internal auditor - Information security
&lt;br&gt;Verificateur interne - Securite de l'information
&lt;br&gt;&lt;br&gt;8585 Trans-Canada Highway, Suite 300
&lt;br&gt;Saint-Laurent (Quebec) H4S 1Z6
&lt;br&gt;Tel.: 514-331-4417 &amp;nbsp; 
&lt;br&gt;Fax: 514-856-7541
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.transforce.ca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.transforce.ca/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Message d'origine-----
&lt;br&gt;De : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] De
&lt;br&gt;la part de &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;boaz.shunami@...&lt;/a&gt;
&lt;br&gt;Envoyé : 25 novembre 2009 02:08
&lt;br&gt;À : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;juanbabi@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Objet : RE: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;Hi Juan,
&lt;br&gt;&lt;br&gt;I would advise your Client to either:
&lt;br&gt;&lt;br&gt;1. Have solid policy as to what sites are accessible/are not accessible
&lt;br&gt;from his branches (can be enforced with bluecoat and the like...)
&lt;br&gt;2. Segregate the network the branches have access to (kind of DMZ) from
&lt;br&gt;his LAN using FW.
&lt;br&gt;3. Give low level permissions to the branches on the core.
&lt;br&gt;&lt;br&gt;My 2c...
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Boaz
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of Juan B
&lt;br&gt;Sent: Tuesday, November 24, 2009 4:04 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535255&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;Hi all,
&lt;br&gt;&lt;br&gt;I'm doing some security consulting for a client. this client have around
&lt;br&gt;30 remote branches connected to his core. the problem is that sometimes
&lt;br&gt;the AV fails to detect new viruses/worms coming from those branches so
&lt;br&gt;those viruses/worms mess up his LAN.another problem is that the the
&lt;br&gt;client doesn't have much of control over the remote PCs in the branches.
&lt;br&gt;so I thought about adding another layer of defence in which we will add
&lt;br&gt;an IPS (which Ips detects also viruses/worms??) which will filter and
&lt;br&gt;scan all traffic coming from the branches.
&lt;br&gt;&lt;br&gt;I just wonder if you guys agree with my suggestion.
&lt;br&gt;&lt;br&gt;any comments will be welcomed.
&lt;br&gt;&lt;br&gt;BTW,
&lt;br&gt;&lt;br&gt;any recomendations for the IPS?
&lt;br&gt;&lt;br&gt;thanks a lot 
&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an
&lt;br&gt;SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company
&lt;br&gt;and how your customers can tell if a site is secure. You will find out
&lt;br&gt;how to test, purchase, install and use a thawte Digital Certificate on
&lt;br&gt;your Apache web server. Throughout, best practices for set-up are
&lt;br&gt;highlighted to help you ensure efficient ongoing management of your
&lt;br&gt;encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&lt;/a&gt;&lt;br&gt;f727d1
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL
&lt;br&gt;certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how
&lt;br&gt;your customers can tell if a site is secure. You will find out how to test,
&lt;br&gt;purchase, install and use a thawte Digital Certificate on your Apache web
&lt;br&gt;server. Throughout, best practices for set-up are highlighted to help you
&lt;br&gt;ensure efficient ongoing management of your encryption keys and digital
&lt;br&gt;certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;d1
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (2K) &lt;a href=&quot;http://old.nabble.com/attachment/26535255/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26535255.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535209</id>
	<title>RE: Is snort an overkill for desktop only environment ?</title>
	<published>2009-11-25T08:07:00Z</published>
	<updated>2009-11-25T08:07:00Z</updated>
	<author>
		<name>Rivest, Philippe-2</name>
	</author>
	<content type="html">I'M not sure we are tackling this the right way. The question that was ask
&lt;br&gt;is &amp;quot;is it overkill for a desktop only environment&amp;quot;.
&lt;br&gt;&lt;br&gt;Every time you want to implement a control, you need to evaluate if you need
&lt;br&gt;it (cost-benefit). If theres no need for IDS (H-N) at all, dont implement
&lt;br&gt;them. But if you are the NSA and have (for what ever reason) a desktop only
&lt;br&gt;environment in on of their branch/location, you MIGHT want to have these
&lt;br&gt;controls. But at home, I really dont care about a N/H-IDS.
&lt;br&gt;&lt;br&gt;So yes its overkill if your environment does not need that level of
&lt;br&gt;protection and No its not overkill if you need it.
&lt;br&gt;&lt;br&gt;Risk management all the way.
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Philippe Rivest - CEH, Network+, Server+, A+
&lt;br&gt;TransForce Inc.
&lt;br&gt;Internal auditor - Information security
&lt;br&gt;Verificateur interne - Securite de l'information
&lt;br&gt;&lt;br&gt;8585 Trans-Canada Highway, Suite 300
&lt;br&gt;Saint-Laurent (Quebec) H4S 1Z6
&lt;br&gt;Tel.: 514-331-4417 &amp;nbsp; 
&lt;br&gt;Fax: 514-856-7541
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.transforce.ca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.transforce.ca/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Message d'origine-----
&lt;br&gt;De : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535209&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535209&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] De
&lt;br&gt;la part de pleed
&lt;br&gt;Envoyé : 24 novembre 2009 16:38
&lt;br&gt;À : &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535209&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Objet : Re: Is snort an overkill for desktop only environment ?
&lt;br&gt;&lt;br&gt;Alexander Klimov wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Tue, 27 Oct 2009, [ISO-8859-1] Jos? Manuel Molina Pascual wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; If you have the HW and some time to do it.... Why not?
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Because every new software package you install is a potential
&lt;br&gt;&amp;gt; source of exploitable flaws, even more so if it is always
&lt;br&gt;&amp;gt; working and getting its inputs from network.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;In my opinion NIDS on the host itself does not make the box more secure.
&lt;/div&gt;When deploying snort, you normaly want to know if there already has been a
&lt;br&gt;_successful_ attack, because when connecting to the internet you re
&lt;br&gt;always being
&lt;br&gt;attacked but mostly without any affect to your system. In your case if
&lt;br&gt;your desktop
&lt;br&gt;is attacked successfully, i wouldnt trust the NIDS output anyway.
&lt;br&gt;In addition snort is just helpfull if someone is looking into the alerts
&lt;br&gt;24/7.
&lt;br&gt;&lt;br&gt;I think you should spend your time with more productive stuff. But for
&lt;br&gt;educational purpose
&lt;br&gt;playing with it is never wasted time.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL
&lt;br&gt;certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how
&lt;br&gt;your customers can tell if a site is secure. You will find out how to test,
&lt;br&gt;purchase, install and use a thawte Digital Certificate on your Apache web
&lt;br&gt;server. Throughout, best practices for set-up are highlighted to help you
&lt;br&gt;ensure efficient ongoing management of your encryption keys and digital
&lt;br&gt;certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727&lt;/a&gt;&lt;br&gt;d1
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (2K) &lt;a href=&quot;http://old.nabble.com/attachment/26535209/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fwd%3A-Is-snort-an-overkill-for-desktop-only-environment---tp26061107p26535209.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535161</id>
	<title>Re: When SPAMMERS Pay You !</title>
	<published>2009-11-25T05:51:15Z</published>
	<updated>2009-11-25T05:51:15Z</updated>
	<author>
		<name>Shreyas Zare-2</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;That mail came from paypal server, I did verify the mail headers and I
&lt;br&gt;have that eCheck payment in my account too (although the entire amount
&lt;br&gt;is deducted as fees, so I get nothing).
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;On Wed, Nov 25, 2009 at 3:04 AM, Meta Junkie &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535161&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;metajunkie@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Shreyas Zare:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; From the limited email details you gave, it looks like the message
&lt;br&gt;&amp;gt; didn't actually come from PayPal.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Did you actually receive the ten cent deposit into your account?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If I was to wager, just based upon what I see here - I'd say you
&lt;br&gt;&amp;gt; didn't.  This looks more like a fishing (aka phishing) attack.  But,
&lt;br&gt;&amp;gt; if I'm wrong in my guess - please let me know!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; - metajunkie
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ps - I have an article or two regarding other phishing attacks at
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://cyber-jutsu.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cyber-jutsu.blogspot.com&lt;/a&gt;&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;(&amp;quot;Relax, its only ONES and ZEROS !&amp;quot;)
&lt;br&gt;&lt;br&gt;Shreyas Zare
&lt;br&gt;Co-Founder, Technitium
&lt;br&gt;eMail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535161&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;shreyas@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;..::&amp;lt; The Technitium Team &amp;gt;::..
&lt;br&gt;Visit us at www.technitium.com
&lt;br&gt;Contact us at &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535161&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;theteam@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Join Sci-Tech News group and get the latest science &amp; technology news
&lt;br&gt;in your inbox. Visit &lt;a href=&quot;http://tech.groups.yahoo.com/group/sci-tech-news&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tech.groups.yahoo.com/group/sci-tech-news&lt;/a&gt;&lt;br&gt;to join.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-When-SPAMMERS-Pay-You-%21-tp26499048p26535161.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535126</id>
	<title>Re: whole disk encryption on multi boot laptop</title>
	<published>2009-11-25T00:59:35Z</published>
	<updated>2009-11-25T00:59:35Z</updated>
	<author>
		<name>Alexander Klimov</name>
	</author>
	<content type="html">On Tue, 24 Nov 2009, Adam Mooz wrote:
&lt;br&gt;&amp;gt; For this level of encyption it might be easier for you to get a
&lt;br&gt;&amp;gt; harddrive with hardware encryption
&lt;br&gt;&lt;br&gt;As a professional paranoid I would not recommend using hardware FDE
&lt;br&gt;for anything more than &amp;quot;keeping your kid sister out&amp;quot;: you can never be
&lt;br&gt;sure what backdoors are incorporated into them. &amp;nbsp;In addition to
&lt;br&gt;intentional backdoors (that, presumably, can be used only by the
&lt;br&gt;authorities) you should be afraid of stupidity: there are known
&lt;br&gt;examples (see Drecom) when a &amp;quot;128-bit AES hardware data encryption&amp;quot;
&lt;br&gt;turns out to be a xor of every sector with the same mask.
&lt;br&gt;&lt;br&gt;By the way, some most vocal hardware FDE proponents on this list
&lt;br&gt;actually work for companies that sell hardware FDE -- caveat
&lt;br&gt;emptor :-)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Regards,
&lt;br&gt;ASK
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/whole-disk-encryption-on-multi-boot-laptop-tp25910746p26535126.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26514844</id>
	<title>RE: adding another defence layer against viruses/worms</title>
	<published>2009-11-24T23:08:29Z</published>
	<updated>2009-11-24T23:08:29Z</updated>
	<author>
		<name>boaz.shunami</name>
	</author>
	<content type="html">Hi Juan,
&lt;br&gt;&lt;br&gt;I would advise your Client to either:
&lt;br&gt;&lt;br&gt;1. Have solid policy as to what sites are accessible/are not accessible
&lt;br&gt;from his branches (can be enforced with bluecoat and the like...)
&lt;br&gt;2. Segregate the network the branches have access to (kind of DMZ) from
&lt;br&gt;his LAN using FW.
&lt;br&gt;3. Give low level permissions to the branches on the core.
&lt;br&gt;&lt;br&gt;My 2c...
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Boaz
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26514844&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26514844&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of Juan B
&lt;br&gt;Sent: Tuesday, November 24, 2009 4:04 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26514844&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: adding another defence layer against viruses/worms
&lt;br&gt;&lt;br&gt;Hi all,
&lt;br&gt;&lt;br&gt;I'm doing some security consulting for a client. this client have around
&lt;br&gt;30 remote branches connected to his core. the problem is that sometimes
&lt;br&gt;the AV fails to detect new viruses/worms coming from those branches so
&lt;br&gt;those viruses/worms mess up his LAN.another problem is that the the
&lt;br&gt;client doesn't have much of control over the remote PCs in the branches.
&lt;br&gt;so I thought about adding another layer of defence in which we will add
&lt;br&gt;an IPS (which Ips detects also viruses/worms??) which will filter and
&lt;br&gt;scan all traffic coming from the branches.
&lt;br&gt;&lt;br&gt;I just wonder if you guys agree with my suggestion.
&lt;br&gt;&lt;br&gt;any comments will be welcomed.
&lt;br&gt;&lt;br&gt;BTW,
&lt;br&gt;&lt;br&gt;any recomendations for the IPS?
&lt;br&gt;&lt;br&gt;thanks a lot 
&lt;br&gt;juan
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an
&lt;br&gt;SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company
&lt;br&gt;and how your customers can tell if a site is secure. You will find out
&lt;br&gt;how to test, purchase, install and use a thawte Digital Certificate on
&lt;br&gt;your Apache web server. Throughout, best practices for set-up are
&lt;br&gt;highlighted to help you ensure efficient ongoing management of your
&lt;br&gt;encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442&lt;/a&gt;&lt;br&gt;f727d1
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/adding-another-defence-layer-against-viruses-worms-tp26499262p26514844.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26514691</id>
	<title>Re: Dealing with port/vulnerability scans</title>
	<published>2009-11-24T15:37:38Z</published>
	<updated>2009-11-24T15:37:38Z</updated>
	<author>
		<name>Michael Painter</name>
	</author>
	<content type="html">Tony Raboza wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; What about you? &amp;nbsp;How do you deal with port/vulnerability scans? &amp;nbsp;Is it
&lt;br&gt;&amp;gt; illegal btw?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Chapter 1. Getting Started with Nmap
&lt;br&gt;Legal Issues
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://nmap.org/book/legal-issues.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/book/legal-issues.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;Securing Apache Web Server with thawte Digital Certificate
&lt;br&gt;In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. &amp;nbsp;We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Dealing-with-port-vulnerability-scans-tp26499205p26514691.html" />
</entry>

</feed>
