|
View:
New views
15 Messages
—
Rating Filter:
Alert me
|
|
|
|
|
|
Re: Security Toolkit for dummiesSent from my iPhone On Nov 4, 2009, at 12:48 PM, "exzactly" <exzactly@...> wrote: > I am currently working on a (free)toolkit to pass down to Tier 3 and > Tier 2 > to be used in the event of a breach/infection or suspected breach/ > infection. > In a nutshell I want to give them some tools to use to gain further > information about the system and processes and/or malicious tools > running on > it. This toolkit is designed for a Windows desktop and Server > environment. I > am looking at building out tools that are fairly easy to use and do > not > require much training. Currently I have the following tools on it: > > (SysInternal tools) > Autoruns > PortMon > Process Explorer > Process Monitor > Ps Tools > Logon Sessions > > Other tools: > Adaware > > > Is there anything else folks out there are using to provide their > lower > level support guys with some tools for informational gathering > purposes....the tools have to run offline as systems are removed in > the > event of a breach or infection...I am not looking for a full blown > forensics > kit, just something I can train folks unfamiliar with tool fairly > quickly... > > > --- > --------------------------------------------------------------------- > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs > an SSL certificate. We look at how SSL works, how it benefits your > company and how your customers can tell if a site is secure. You > will find out how to test, purchase, install and use a thawte > Digital Certificate on your Apache web server. Throughout, best > practices for set-up are highlighted to help you ensure efficient > ongoing management of your encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > --- > --------------------------------------------------------------------- > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesI did a sim project for tier 1 and 2 techs, I used alot of the free
bees out there and local ms tools via all on one style. Id google barts pe plugins, you might not use the boot cd how ever most of the base tools are already ripped and can be added to flash or indego rose all in one app. When I did this I had is scan the system for spyware, reg keys, temps, and av then provide access to the tools. Some of the tools you list are easier to script or automate if you use native tools like Tasklist Netstat I would also dig around in autoit archives, alot of this is already done or a foundation is built, plus the scripting Lang plugs nicely into vbs, wshell, kix and so on to use tools. Hit the forums and look up fw log viewer Win cleaner Auto it is a windows script Lang based on all the cool parts of batching and scripting. I'll dig through old projects and share if you like. On Nov 4, 2009, at 12:48 PM, "exzactly" <exzactly@...> wrote: > I am currently working on a (free)toolkit to pass down to Tier 3 and > Tier 2 > to be used in the event of a breach/infection or suspected breach/ > infection. > In a nutshell I want to give them some tools to use to gain further > information about the system and processes and/or malicious tools > running on > it. This toolkit is designed for a Windows desktop and Server > environment. I > am looking at building out tools that are fairly easy to use and do > not > require much training. Currently I have the following tools on it: > > (SysInternal tools) > Autoruns > PortMon > Process Explorer > Process Monitor > Ps Tools > Logon Sessions > > Other tools: > Adaware > > > Is there anything else folks out there are using to provide their > lower > level support guys with some tools for informational gathering > purposes....the tools have to run offline as systems are removed in > the > event of a breach or infection...I am not looking for a full blown > forensics > kit, just something I can train folks unfamiliar with tool fairly > quickly... > > > --- > --------------------------------------------------------------------- > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs > an SSL certificate. We look at how SSL works, how it benefits your > company and how your customers can tell if a site is secure. You > will find out how to test, purchase, install and use a thawte > Digital Certificate on your Apache web server. Throughout, best > practices for set-up are highlighted to help you ensure efficient > ongoing management of your encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > --- > --------------------------------------------------------------------- > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
RE: Security Toolkit for dummiesFport might come in handy.
I'm guessing you want 'clean' versions of everything because who knows what is running on the box itself or what has been modified. How will you be able to trust that the cmd window that you run some of these from is legit? Or that it will run at all? Maybe a cmd alternative will help, too. Fciv so you could check hashes? Regalyzer? Will you image the machines before allowing the support guys to do their stuff? > >-----Original Message----- > >From: listbounce@... [mailto:listbounce@...] > >On Behalf Of exzactly > >Sent: Thursday, November 05, 2009 4:27 AM > >To: security-basics@... > >Subject: Security Toolkit for dummies > > > >I am currently working on a (free)toolkit to pass down to Tier 3 and Tier > >2 > >to be used in the event of a breach/infection or suspected > >breach/infection. > >In a nutshell I want to give them some tools to use to gain further > >information about the system and processes and/or malicious tools running > >on > >it. This toolkit is designed for a Windows desktop and Server > >environment. I > >am looking at building out tools that are fairly easy to use and do not > >require much training. Currently I have the following tools on it: > > > > (SysInternal tools) > >Autoruns > >PortMon > >Process Explorer > >Process Monitor > >Ps Tools > >Logon Sessions > > > >Other tools: > >Adaware > > > > > >Is there anything else folks out there are using to provide their lower > >level support guys with some tools for informational gathering > >purposes....the tools have to run offline as systems are removed in the > >event of a breach or infection...I am not looking for a full blown > >forensics > >kit, just something I can train folks unfamiliar with tool fairly > >quickly... > > > > > >------------------------------------------------------------------------ > >Securing Apache Web Server with thawte Digital Certificate > >In this guide we examine the importance of Apache-SSL and who needs an > >SSL certificate. We look at how SSL works, how it benefits your company > >and how your customers can tell if a site is secure. You will find out > >how to test, purchase, install and use a thawte Digital Certificate on > >your Apache web server. Throughout, best practices for set-up are > >highlighted to help you ensure efficient ongoing management of your > >encryption keys and digital certificates. > > > >http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f > >727d1 > >------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesTools I have used in the past.
combofix malwarebytes sdfix vundofix spybot search and destroy On Wed, Nov 4, 2009 at 1:27 PM, exzactly <exzactly@...> wrote: > I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2 > to be used in the event of a breach/infection or suspected breach/infection. > In a nutshell I want to give them some tools to use to gain further > information about the system and processes and/or malicious tools running on > it. This toolkit is designed for a Windows desktop and Server environment. I > am looking at building out tools that are fairly easy to use and do not > require much training. Currently I have the following tools on it: > > (SysInternal tools) > Autoruns > PortMon > Process Explorer > Process Monitor > Ps Tools > Logon Sessions > > Other tools: > Adaware > > > Is there anything else folks out there are using to provide their lower > level support guys with some tools for informational gathering > purposes....the tools have to run offline as systems are removed in the > event of a breach or infection...I am not looking for a full blown forensics > kit, just something I can train folks unfamiliar with tool fairly quickly... > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an SSL > certificate. We look at how SSL works, how it benefits your company and how > your customers can tell if a site is secure. You will find out how to test, > purchase, install and use a thawte Digital Certificate on your Apache web > server. Throughout, best practices for set-up are highlighted to help you > ensure efficient ongoing management of your encryption keys and digital > certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
RE: Security Toolkit for dummiesOther Ideas...
FileMon RegMon Malwarebytes RootKit Revealer HijackThis -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of exzactly Sent: Wednesday, November 04, 2009 10:27 AM To: security-basics@... Subject: Security Toolkit for dummies I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2 to be used in the event of a breach/infection or suspected breach/infection. In a nutshell I want to give them some tools to use to gain further information about the system and processes and/or malicious tools running on it. This toolkit is designed for a Windows desktop and Server environment. I am looking at building out tools that are fairly easy to use and do not require much training. Currently I have the following tools on it: (SysInternal tools) Autoruns PortMon Process Explorer Process Monitor Ps Tools Logon Sessions Other tools: Adaware Is there anything else folks out there are using to provide their lower level support guys with some tools for informational gathering purposes....the tools have to run offline as systems are removed in the event of a breach or infection...I am not looking for a full blown forensics kit, just something I can train folks unfamiliar with tool fairly quickly... ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727 d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
RE: Security Toolkit for dummiesAlso..
TCPView -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of exzactly Sent: Wednesday, November 04, 2009 10:27 AM To: security-basics@... Subject: Security Toolkit for dummies I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2 to be used in the event of a breach/infection or suspected breach/infection. In a nutshell I want to give them some tools to use to gain further information about the system and processes and/or malicious tools running on it. This toolkit is designed for a Windows desktop and Server environment. I am looking at building out tools that are fairly easy to use and do not require much training. Currently I have the following tools on it: (SysInternal tools) Autoruns PortMon Process Explorer Process Monitor Ps Tools Logon Sessions Other tools: Adaware Is there anything else folks out there are using to provide their lower level support guys with some tools for informational gathering purposes....the tools have to run offline as systems are removed in the event of a breach or infection...I am not looking for a full blown forensics kit, just something I can train folks unfamiliar with tool fairly quickly... ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727 d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
|
|
|
RE: Security Toolkit for dummiesIn addition to the other tools mentioned, I send my tech's out with a bootable USB-Key with Kapersky Rescue for anti-virus scanning. It is slow but takes updates from the server in ram-disk. The more advanced tech's also get a copy of the Ultimate Boot CD on CD/USB key as well.
-----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of Jacob Sent: Thursday, November 05, 2009 10:49 AM To: 'exzactly'; security-basics@... Subject: RE: Security Toolkit for dummies Other Ideas... FileMon RegMon Malwarebytes RootKit Revealer HijackThis -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of exzactly Sent: Wednesday, November 04, 2009 10:27 AM To: security-basics@... Subject: Security Toolkit for dummies I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2 to be used in the event of a breach/infection or suspected breach/infection. In a nutshell I want to give them some tools to use to gain further information about the system and processes and/or malicious tools running on it. This toolkit is designed for a Windows desktop and Server environment. I am looking at building out tools that are fairly easy to use and do not require much training. Currently I have the following tools on it: (SysInternal tools) Autoruns PortMon Process Explorer Process Monitor Ps Tools Logon Sessions Other tools: Adaware Is there anything else folks out there are using to provide their lower level support guys with some tools for informational gathering purposes....the tools have to run offline as systems are removed in the event of a breach or infection...I am not looking for a full blown forensics kit, just something I can train folks unfamiliar with tool fairly quickly... ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727 d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
RE: Security Toolkit for dummiesI use most of the tools which are mentioned below.
These are some of the tools which I use but do not see in this thread- LSPFix (a broken one can render an Internet connection dead to the world) GMER (detects all rootkits and rogue programs) Asquared-free (a good antispyware with GUI and commandline scanner) Ccleaner (CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. It also cleans traces of your online activities such as your Internet history. Additionally it contains a fully featured registry cleaner). This tool supports cleanup of all browsers with windows 7 compatibility -Anshuman -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of Jay Vlavianos Sent: Tuesday, November 10, 2009 12:11 AM To: 'jacob@...'; 'exzactly'; security-basics@... Subject: RE: Security Toolkit for dummies In addition to the other tools mentioned, I send my tech's out with a bootable USB-Key with Kapersky Rescue for anti-virus scanning. It is slow but takes updates from the server in ram-disk. The more advanced tech's also get a copy of the Ultimate Boot CD on CD/USB key as well. -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of Jacob Sent: Thursday, November 05, 2009 10:49 AM To: 'exzactly'; security-basics@... Subject: RE: Security Toolkit for dummies Other Ideas... FileMon RegMon Malwarebytes RootKit Revealer HijackThis -----Original Message----- From: listbounce@... [mailto:listbounce@...] On Behalf Of exzactly Sent: Wednesday, November 04, 2009 10:27 AM To: security-basics@... Subject: Security Toolkit for dummies I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2 to be used in the event of a breach/infection or suspected breach/infection. In a nutshell I want to give them some tools to use to gain further information about the system and processes and/or malicious tools running on it. This toolkit is designed for a Windows desktop and Server environment. I am looking at building out tools that are fairly easy to use and do not require much training. Currently I have the following tools on it: (SysInternal tools) Autoruns PortMon Process Explorer Process Monitor Ps Tools Logon Sessions Other tools: Adaware Is there anything else folks out there are using to provide their lower level support guys with some tools for informational gathering purposes....the tools have to run offline as systems are removed in the event of a breach or infection...I am not looking for a full blown forensics kit, just something I can train folks unfamiliar with tool fairly quickly... ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 f727 d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 f727d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 f727d1 ------------------------------------------------------------------------ "Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or attachment." www.cybage.com ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesNot to mention Microsoft COFEE now that it's been leaked
On Mon, Nov 9, 2009 at 6:17 PM, Anshuman Anil Deshmukh <anshuman@...> wrote: > I use most of the tools which are mentioned below. > These are some of the tools which I use but do not see in this thread- > > LSPFix (a broken one can render an Internet connection dead to the > world) > GMER (detects all rootkits and rogue programs) > Asquared-free (a good antispyware with GUI and commandline scanner) > Ccleaner (CCleaner is a freeware system optimization, privacy and > cleaning tool. It removes unused files from your system - allowing > Windows to run faster and freeing up valuable hard disk space. It also > cleans traces of your online activities such as your Internet history. > Additionally it contains a fully featured registry cleaner). This tool > supports cleanup of all browsers with windows 7 compatibility > > -Anshuman > > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On Behalf Of Jay Vlavianos > Sent: Tuesday, November 10, 2009 12:11 AM > To: 'jacob@...'; 'exzactly'; > security-basics@... > Subject: RE: Security Toolkit for dummies > > In addition to the other tools mentioned, I send my tech's out with a > bootable USB-Key with Kapersky Rescue for anti-virus scanning. It is > slow but takes updates from the server in ram-disk. The more advanced > tech's also get a copy of the Ultimate Boot CD on CD/USB key as well. > > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On Behalf Of Jacob > Sent: Thursday, November 05, 2009 10:49 AM > To: 'exzactly'; security-basics@... > Subject: RE: Security Toolkit for dummies > > Other Ideas... > > FileMon > RegMon > Malwarebytes > RootKit Revealer > HijackThis > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On > Behalf Of exzactly > Sent: Wednesday, November 04, 2009 10:27 AM > To: security-basics@... > Subject: Security Toolkit for dummies > > I am currently working on a (free)toolkit to pass down to Tier 3 and > Tier 2 > to be used in the event of a breach/infection or suspected > breach/infection. > > In a nutshell I want to give them some tools to use to gain further > information about the system and processes and/or malicious tools > running on > > it. This toolkit is designed for a Windows desktop and Server > environment. I > > am looking at building out tools that are fairly easy to use and do not > require much training. Currently I have the following tools on it: > > (SysInternal tools) > Autoruns > PortMon > Process Explorer > Process Monitor > Ps Tools > Logon Sessions > > Other tools: > Adaware > > > Is there anything else folks out there are using to provide their lower > level support guys with some tools for informational gathering > purposes....the tools have to run offline as systems are removed in the > event of a breach or infection...I am not looking for a full blown > forensics > > kit, just something I can train folks unfamiliar with tool fairly > quickly... > > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL > certificate. We look at how SSL works, how it benefits your company and > how > your customers can tell if a site is secure. You will find out how to > test, > purchase, install and use a thawte Digital Certificate on your Apache > web > server. Throughout, best practices for set-up are highlighted to help > you > ensure efficient ongoing management of your encryption keys and digital > certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727 > d1 > ------------------------------------------------------------------------ > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL certificate. We look at how SSL works, how it benefits your company > and how your customers can tell if a site is secure. You will find out > how to test, purchase, install and use a thawte Digital Certificate on > your Apache web server. Throughout, best practices for set-up are > highlighted to help you ensure efficient ongoing management of your > encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727d1 > ------------------------------------------------------------------------ > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL certificate. We look at how SSL works, how it benefits your company > and how your customers can tell if a site is secure. You will find out > how to test, purchase, install and use a thawte Digital Certificate on > your Apache web server. Throughout, best practices for set-up are > highlighted to help you ensure efficient ongoing management of your > encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727d1 > ------------------------------------------------------------------------ > > > "Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or attachment." > www.cybage.com > > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesThanks everyone for the feedback
-------------------------------------------------- From: "Anshuman Anil Deshmukh" <anshuman@...> Sent: Monday, November 09, 2009 4:17 PM To: "Jay Vlavianos" <jvlavianos@...>; <jacob@...>; "exzactly" <exzactly@...>; <security-basics@...> Subject: RE: Security Toolkit for dummies > I use most of the tools which are mentioned below. > These are some of the tools which I use but do not see in this thread- > > LSPFix (a broken one can render an Internet connection dead to the > world) > GMER (detects all rootkits and rogue programs) > Asquared-free (a good antispyware with GUI and commandline scanner) > Ccleaner (CCleaner is a freeware system optimization, privacy and > cleaning tool. It removes unused files from your system - allowing > Windows to run faster and freeing up valuable hard disk space. It also > cleans traces of your online activities such as your Internet history. > Additionally it contains a fully featured registry cleaner). This tool > supports cleanup of all browsers with windows 7 compatibility > > -Anshuman > > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On Behalf Of Jay Vlavianos > Sent: Tuesday, November 10, 2009 12:11 AM > To: 'jacob@...'; 'exzactly'; > security-basics@... > Subject: RE: Security Toolkit for dummies > > In addition to the other tools mentioned, I send my tech's out with a > bootable USB-Key with Kapersky Rescue for anti-virus scanning. It is > slow but takes updates from the server in ram-disk. The more advanced > tech's also get a copy of the Ultimate Boot CD on CD/USB key as well. > > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On Behalf Of Jacob > Sent: Thursday, November 05, 2009 10:49 AM > To: 'exzactly'; security-basics@... > Subject: RE: Security Toolkit for dummies > > Other Ideas... > > FileMon > RegMon > Malwarebytes > RootKit Revealer > HijackThis > > -----Original Message----- > From: listbounce@... [mailto:listbounce@...] > On > Behalf Of exzactly > Sent: Wednesday, November 04, 2009 10:27 AM > To: security-basics@... > Subject: Security Toolkit for dummies > > I am currently working on a (free)toolkit to pass down to Tier 3 and > Tier 2 > to be used in the event of a breach/infection or suspected > breach/infection. > > In a nutshell I want to give them some tools to use to gain further > information about the system and processes and/or malicious tools > running on > > it. This toolkit is designed for a Windows desktop and Server > environment. I > > am looking at building out tools that are fairly easy to use and do not > require much training. Currently I have the following tools on it: > > (SysInternal tools) > Autoruns > PortMon > Process Explorer > Process Monitor > Ps Tools > Logon Sessions > > Other tools: > Adaware > > > Is there anything else folks out there are using to provide their lower > level support guys with some tools for informational gathering > purposes....the tools have to run offline as systems are removed in the > event of a breach or infection...I am not looking for a full blown > forensics > > kit, just something I can train folks unfamiliar with tool fairly > quickly... > > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL > certificate. We look at how SSL works, how it benefits your company and > how > your customers can tell if a site is secure. You will find out how to > test, > purchase, install and use a thawte Digital Certificate on your Apache > web > server. Throughout, best practices for set-up are highlighted to help > you > ensure efficient ongoing management of your encryption keys and digital > certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727 > d1 > ------------------------------------------------------------------------ > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL certificate. We look at how SSL works, how it benefits your company > and how your customers can tell if a site is secure. You will find out > how to test, purchase, install and use a thawte Digital Certificate on > your Apache web server. Throughout, best practices for set-up are > highlighted to help you ensure efficient ongoing management of your > encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727d1 > ------------------------------------------------------------------------ > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an > SSL certificate. We look at how SSL works, how it benefits your company > and how your customers can tell if a site is secure. You will find out > how to test, purchase, install and use a thawte Digital Certificate on > your Apache web server. Throughout, best practices for set-up are > highlighted to help you ensure efficient ongoing management of your > encryption keys and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442 > f727d1 > ------------------------------------------------------------------------ > > > "Legal Disclaimer: This electronic message and all contents contain > information from Cybage Software Private Limited which may be privileged, > confidential, or otherwise protected from disclosure. The information is > intended to be for the addressee(s) only. If you are not an addressee, any > disclosure, copy, distribution, or use of the contents of this message is > strictly prohibited. If you have received this electronic message in error > please notify the sender by reply e-mail to and destroy the original > message and all copies. Cybage has taken every reasonable precaution to > minimize the risk of malicious content in the mail, but is not liable for > any damage you may sustain as a result of any malicious content in this > e-mail. You should carry out your own malicious content checks before > opening the e-mail or attachment." > www.cybage.com > > > > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an SSL > certificate. We look at how SSL works, how it benefits your company and > how your customers can tell if a site is secure. You will find out how to > test, purchase, install and use a thawte Digital Certificate on your > Apache web server. Throughout, best practices for set-up are highlighted > to help you ensure efficient ongoing management of your encryption keys > and digital certificates. > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesOn Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote:
> Not to mention Microsoft COFEE now that it's been leaked > Funny you say that, there was a news article on the frontpage of Securityfocus about that by Robert Lemos which has now been removed. Anybody know why? ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesProbably for the same reason it was removed as a torrent from various
sites - it is deemed too hot to deal with at the moment. Considering it is one of the only software packages out there that was completely designed for LEOs, it stands to reason that people fear M$ legal/cop smack down. Why get the BSA involved for piracy when you can just let the LEOs you create it for own the case? Even reporting that you reviewed it is an admission of guilt. -Jay On Nov 12, 2009, at 4:27 PM, "n3td3v" <xploitable@...> wrote: > On Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote: >> Not to mention Microsoft COFEE now that it's been leaked >> > > Funny you say that, there was a news article on the frontpage of > Securityfocus about that by Robert Lemos which has now been removed. > Anybody know why? ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
|
|
Re: Security Toolkit for dummiesIt's not been removed, I found it http://www.securityfocus.com/brief/1034
On Fri, Nov 13, 2009 at 2:59 AM, Jay Vlavianos <jvlavianos@...> wrote: > Probably for the same reason it was removed as a torrent from various > sites - it is deemed too hot to deal with at the moment. > > Considering it is one of the only software packages out there that was > completely designed for LEOs, it stands to reason that people fear M$ > legal/cop smack down. > > Why get the BSA involved for piracy when you can just let the LEOs you > create it for own the case? Even reporting that you reviewed it is an > admission of guilt. > > -Jay > > On Nov 12, 2009, at 4:27 PM, "n3td3v" <xploitable@...> wrote: > >> On Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote: >>> Not to mention Microsoft COFEE now that it's been leaked >>> >> >> Funny you say that, there was a news article on the frontpage of >> Securityfocus about that by Robert Lemos which has now been removed. >> Anybody know why? > ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ |
| Free embeddable forum powered by Nabble | Forum Help |