Security Toolkit for dummies

View: New views
15 Messages — Rating Filter:   Alert me  

Parent Message unknown Security Toolkit for dummies

by exzactly :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2
to be used in the event of a breach/infection or suspected breach/infection.
In a nutshell I want to give them some tools to use to gain further
information about the system and processes and/or malicious tools running on
it. This toolkit is designed for a Windows desktop and Server environment. I
am looking at building out tools that are fairly easy to use and do not
require much training. Currently I have the following tools on it:

 (SysInternal tools)
Autoruns
PortMon
Process Explorer
Process Monitor
Ps Tools
Logon Sessions

Other tools:
Adaware


Is there anything else folks out there are using to provide their lower
level support guys with some tools for informational gathering
purposes....the tools have to run offline as systems are removed in the
event of a breach or infection...I am not looking for a full blown forensics
kit, just something I can train folks unfamiliar with tool fairly quickly...


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by noobposer :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message



Sent from my iPhone

On Nov 4, 2009, at 12:48 PM, "exzactly" <exzactly@...> wrote:

> I am currently working on a (free)toolkit to pass down to Tier 3 and  
> Tier 2
> to be used in the event of a breach/infection or suspected breach/
> infection.
> In a nutshell I want to give them some tools to use to gain further
> information about the system and processes and/or malicious tools  
> running on
> it. This toolkit is designed for a Windows desktop and Server  
> environment. I
> am looking at building out tools that are fairly easy to use and do  
> not
> require much training. Currently I have the following tools on it:
>
> (SysInternal tools)
> Autoruns
> PortMon
> Process Explorer
> Process Monitor
> Ps Tools
> Logon Sessions
>
> Other tools:
> Adaware
>
>
> Is there anything else folks out there are using to provide their  
> lower
> level support guys with some tools for informational gathering
> purposes....the tools have to run offline as systems are removed in  
> the
> event of a breach or infection...I am not looking for a full blown  
> forensics
> kit, just something I can train folks unfamiliar with tool fairly  
> quickly...
>
>
> ---
> ---------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs  
> an SSL certificate.  We look at how SSL works, how it benefits your  
> company and how your customers can tell if a site is secure. You  
> will find out how to test, purchase, install and use a thawte  
> Digital Certificate on your Apache web server. Throughout, best  
> practices for set-up are highlighted to help you ensure efficient  
> ongoing management of your encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
> ---
> ---------------------------------------------------------------------
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by noobposer :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

I did a sim project for tier 1 and 2 techs, I used alot of the free  
bees out there and local ms tools via all on one style. Id google  
barts pe plugins, you might not use the boot cd how ever most of the  
base tools are already ripped and can be added to flash or indego rose  
all in one app.

When I did this I had is scan the system for spyware, reg keys, temps,  
and av then provide access to the tools.

Some of the tools you list are easier to script or automate if you use  
native tools like

Tasklist
Netstat

I would also dig around in autoit archives, alot of this is already  
done or a foundation is built,  plus the scripting Lang plugs nicely  
into vbs, wshell, kix and so on to use tools.

Hit the forums and look up

fw log viewer
Win cleaner

Auto it is a windows script Lang based on all the cool parts of  
batching and scripting.

I'll dig through old projects and share if you like.

On Nov 4, 2009, at 12:48 PM, "exzactly" <exzactly@...> wrote:

> I am currently working on a (free)toolkit to pass down to Tier 3 and  
> Tier 2
> to be used in the event of a breach/infection or suspected breach/
> infection.
> In a nutshell I want to give them some tools to use to gain further
> information about the system and processes and/or malicious tools  
> running on
> it. This toolkit is designed for a Windows desktop and Server  
> environment. I
> am looking at building out tools that are fairly easy to use and do  
> not
> require much training. Currently I have the following tools on it:
>
> (SysInternal tools)
> Autoruns
> PortMon
> Process Explorer
> Process Monitor
> Ps Tools
> Logon Sessions
>
> Other tools:
> Adaware
>
>
> Is there anything else folks out there are using to provide their  
> lower
> level support guys with some tools for informational gathering
> purposes....the tools have to run offline as systems are removed in  
> the
> event of a breach or infection...I am not looking for a full blown  
> forensics
> kit, just something I can train folks unfamiliar with tool fairly  
> quickly...
>
>
> ---
> ---------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs  
> an SSL certificate.  We look at how SSL works, how it benefits your  
> company and how your customers can tell if a site is secure. You  
> will find out how to test, purchase, install and use a thawte  
> Digital Certificate on your Apache web server. Throughout, best  
> practices for set-up are highlighted to help you ensure efficient  
> ongoing management of your encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
> ---
> ---------------------------------------------------------------------
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


RE: Security Toolkit for dummies

by Murda Mcloud :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Fport might come in handy.
I'm guessing you want 'clean' versions of everything because who knows what
is running on the box itself or what has been modified.
How will you be able to trust that the cmd window that you run some of these
from is legit? Or that it will run at all?
Maybe a cmd alternative will help, too.
Fciv so you could check hashes?
Regalyzer?


Will you image the machines before allowing the support guys to do their
stuff?




> >-----Original Message-----
> >From: listbounce@... [mailto:listbounce@...]
> >On Behalf Of exzactly
> >Sent: Thursday, November 05, 2009 4:27 AM
> >To: security-basics@...
> >Subject: Security Toolkit for dummies
> >
> >I am currently working on a (free)toolkit to pass down to Tier 3 and Tier
> >2
> >to be used in the event of a breach/infection or suspected
> >breach/infection.
> >In a nutshell I want to give them some tools to use to gain further
> >information about the system and processes and/or malicious tools running
> >on
> >it. This toolkit is designed for a Windows desktop and Server
> >environment. I
> >am looking at building out tools that are fairly easy to use and do not
> >require much training. Currently I have the following tools on it:
> >
> > (SysInternal tools)
> >Autoruns
> >PortMon
> >Process Explorer
> >Process Monitor
> >Ps Tools
> >Logon Sessions
> >
> >Other tools:
> >Adaware
> >
> >
> >Is there anything else folks out there are using to provide their lower
> >level support guys with some tools for informational gathering
> >purposes....the tools have to run offline as systems are removed in the
> >event of a breach or infection...I am not looking for a full blown
> >forensics
> >kit, just something I can train folks unfamiliar with tool fairly
> >quickly...
> >
> >
> >------------------------------------------------------------------------
> >Securing Apache Web Server with thawte Digital Certificate
> >In this guide we examine the importance of Apache-SSL and who needs an
> >SSL certificate.  We look at how SSL works, how it benefits your company
> >and how your customers can tell if a site is secure. You will find out
> >how to test, purchase, install and use a thawte Digital Certificate on
> >your Apache web server. Throughout, best practices for set-up are
> >highlighted to help you ensure efficient ongoing management of your
> >encryption keys and digital certificates.
> >
> >http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f
> >727d1
> >------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by Gettin Phunky :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Tools I have used in the past.

combofix
malwarebytes
sdfix
vundofix
spybot search and destroy




On Wed, Nov 4, 2009 at 1:27 PM, exzactly <exzactly@...> wrote:

> I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2
> to be used in the event of a breach/infection or suspected breach/infection.
> In a nutshell I want to give them some tools to use to gain further
> information about the system and processes and/or malicious tools running on
> it. This toolkit is designed for a Windows desktop and Server environment. I
> am looking at building out tools that are fairly easy to use and do not
> require much training. Currently I have the following tools on it:
>
> (SysInternal tools)
> Autoruns
> PortMon
> Process Explorer
> Process Monitor
> Ps Tools
> Logon Sessions
>
> Other tools:
> Adaware
>
>
> Is there anything else folks out there are using to provide their lower
> level support guys with some tools for informational gathering
> purposes....the tools have to run offline as systems are removed in the
> event of a breach or infection...I am not looking for a full blown forensics
> kit, just something I can train folks unfamiliar with tool fairly quickly...
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an SSL
> certificate.  We look at how SSL works, how it benefits your company and how
> your customers can tell if a site is secure. You will find out how to test,
> purchase, install and use a thawte Digital Certificate on your Apache web
> server. Throughout, best practices for set-up are highlighted to help you
> ensure efficient ongoing management of your encryption keys and digital
> certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


RE: Security Toolkit for dummies

by Jacob-20 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Other Ideas...

FileMon
RegMon
Malwarebytes
RootKit Revealer
HijackThis

-----Original Message-----
From: listbounce@... [mailto:listbounce@...] On
Behalf Of exzactly
Sent: Wednesday, November 04, 2009 10:27 AM
To: security-basics@...
Subject: Security Toolkit for dummies

I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2
to be used in the event of a breach/infection or suspected breach/infection.

In a nutshell I want to give them some tools to use to gain further
information about the system and processes and/or malicious tools running on

it. This toolkit is designed for a Windows desktop and Server environment. I

am looking at building out tools that are fairly easy to use and do not
require much training. Currently I have the following tools on it:

 (SysInternal tools)
Autoruns
PortMon
Process Explorer
Process Monitor
Ps Tools
Logon Sessions

Other tools:
Adaware


Is there anything else folks out there are using to provide their lower
level support guys with some tools for informational gathering
purposes....the tools have to run offline as systems are removed in the
event of a breach or infection...I am not looking for a full blown forensics

kit, just something I can train folks unfamiliar with tool fairly quickly...



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and how
your customers can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on your Apache web
server. Throughout, best practices for set-up are highlighted to help you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727
d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


RE: Security Toolkit for dummies

by Jacob-20 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Also..

TCPView

-----Original Message-----
From: listbounce@... [mailto:listbounce@...] On
Behalf Of exzactly
Sent: Wednesday, November 04, 2009 10:27 AM
To: security-basics@...
Subject: Security Toolkit for dummies

I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2
to be used in the event of a breach/infection or suspected breach/infection.

In a nutshell I want to give them some tools to use to gain further
information about the system and processes and/or malicious tools running on

it. This toolkit is designed for a Windows desktop and Server environment. I

am looking at building out tools that are fairly easy to use and do not
require much training. Currently I have the following tools on it:

 (SysInternal tools)
Autoruns
PortMon
Process Explorer
Process Monitor
Ps Tools
Logon Sessions

Other tools:
Adaware


Is there anything else folks out there are using to provide their lower
level support guys with some tools for informational gathering
purposes....the tools have to run offline as systems are removed in the
event of a breach or infection...I am not looking for a full blown forensics

kit, just something I can train folks unfamiliar with tool fairly quickly...



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and how
your customers can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on your Apache web
server. Throughout, best practices for set-up are highlighted to help you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727
d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Parent Message unknown Re: Security Toolkit for dummies

by cybercops911 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Have you seen this site. Lots of good tools
http://technet.microsoft.com/en-us/sysinternals/default.aspx

Jim Henderson
561-809-6800
cybercop@...
www.topsecretprotection.com
www.computerforensics911.com

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


RE: Security Toolkit for dummies

by Jay Vlavianos-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

In addition to the other tools mentioned, I send my tech's out with a bootable USB-Key with Kapersky Rescue for anti-virus scanning.  It is slow but takes updates from the server in ram-disk.  The more advanced tech's also get a copy of the Ultimate Boot CD on CD/USB key as well.


-----Original Message-----
From: listbounce@... [mailto:listbounce@...] On Behalf Of Jacob
Sent: Thursday, November 05, 2009 10:49 AM
To: 'exzactly'; security-basics@...
Subject: RE: Security Toolkit for dummies

Other Ideas...

FileMon
RegMon
Malwarebytes
RootKit Revealer
HijackThis

-----Original Message-----
From: listbounce@... [mailto:listbounce@...] On
Behalf Of exzactly
Sent: Wednesday, November 04, 2009 10:27 AM
To: security-basics@...
Subject: Security Toolkit for dummies

I am currently working on a (free)toolkit to pass down to Tier 3 and Tier 2
to be used in the event of a breach/infection or suspected breach/infection.

In a nutshell I want to give them some tools to use to gain further
information about the system and processes and/or malicious tools running on

it. This toolkit is designed for a Windows desktop and Server environment. I

am looking at building out tools that are fairly easy to use and do not
require much training. Currently I have the following tools on it:

 (SysInternal tools)
Autoruns
PortMon
Process Explorer
Process Monitor
Ps Tools
Logon Sessions

Other tools:
Adaware


Is there anything else folks out there are using to provide their lower
level support guys with some tools for informational gathering
purposes....the tools have to run offline as systems are removed in the
event of a breach or infection...I am not looking for a full blown forensics

kit, just something I can train folks unfamiliar with tool fairly quickly...



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and how
your customers can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on your Apache web
server. Throughout, best practices for set-up are highlighted to help you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727
d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


RE: Security Toolkit for dummies

by Anshuman Anil Deshmukh :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

I use most of the tools which are mentioned below.
These are some of the tools which I use but do not see in this thread-

LSPFix (a broken one can render an Internet connection dead to the
world)
GMER (detects all rootkits and rogue programs)
Asquared-free (a good antispyware with GUI and commandline scanner)
Ccleaner (CCleaner is a freeware system optimization, privacy and
cleaning tool. It removes unused files from your system - allowing
Windows to run faster and freeing up valuable hard disk space. It also
cleans traces of your online activities such as your Internet history.
Additionally it contains a fully featured registry cleaner). This tool
supports cleanup of all browsers with windows 7 compatibility

-Anshuman


-----Original Message-----
From: listbounce@... [mailto:listbounce@...]
On Behalf Of Jay Vlavianos
Sent: Tuesday, November 10, 2009 12:11 AM
To: 'jacob@...'; 'exzactly';
security-basics@...
Subject: RE: Security Toolkit for dummies

In addition to the other tools mentioned, I send my tech's out with a
bootable USB-Key with Kapersky Rescue for anti-virus scanning.  It is
slow but takes updates from the server in ram-disk.  The more advanced
tech's also get a copy of the Ultimate Boot CD on CD/USB key as well.


-----Original Message-----
From: listbounce@... [mailto:listbounce@...]
On Behalf Of Jacob
Sent: Thursday, November 05, 2009 10:49 AM
To: 'exzactly'; security-basics@...
Subject: RE: Security Toolkit for dummies

Other Ideas...

FileMon
RegMon
Malwarebytes
RootKit Revealer
HijackThis

-----Original Message-----
From: listbounce@... [mailto:listbounce@...]
On
Behalf Of exzactly
Sent: Wednesday, November 04, 2009 10:27 AM
To: security-basics@...
Subject: Security Toolkit for dummies

I am currently working on a (free)toolkit to pass down to Tier 3 and
Tier 2
to be used in the event of a breach/infection or suspected
breach/infection.

In a nutshell I want to give them some tools to use to gain further
information about the system and processes and/or malicious tools
running on

it. This toolkit is designed for a Windows desktop and Server
environment. I

am looking at building out tools that are fairly easy to use and do not
require much training. Currently I have the following tools on it:

 (SysInternal tools)
Autoruns
PortMon
Process Explorer
Process Monitor
Ps Tools
Logon Sessions

Other tools:
Adaware


Is there anything else folks out there are using to provide their lower
level support guys with some tools for informational gathering
purposes....the tools have to run offline as systems are removed in the
event of a breach or infection...I am not looking for a full blown
forensics

kit, just something I can train folks unfamiliar with tool fairly
quickly...



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL
certificate.  We look at how SSL works, how it benefits your company and
how
your customers can tell if a site is secure. You will find out how to
test,
purchase, install and use a thawte Digital Certificate on your Apache
web
server. Throughout, best practices for set-up are highlighted to help
you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727
d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL certificate.  We look at how SSL works, how it benefits your company
and how your customers can tell if a site is secure. You will find out
how to test, purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for set-up are
highlighted to help you ensure efficient ongoing management of your
encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL certificate.  We look at how SSL works, how it benefits your company
and how your customers can tell if a site is secure. You will find out
how to test, purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for set-up are
highlighted to help you ensure efficient ongoing management of your
encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
------------------------------------------------------------------------


"Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or attachment."
www.cybage.com



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by xgermx :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Not to mention Microsoft COFEE now that it's been leaked

On Mon, Nov 9, 2009 at 6:17 PM, Anshuman Anil Deshmukh
<anshuman@...> wrote:

> I use most of the tools which are mentioned below.
> These are some of the tools which I use but do not see in this thread-
>
> LSPFix (a broken one can render an Internet connection dead to the
> world)
> GMER (detects all rootkits and rogue programs)
> Asquared-free (a good antispyware with GUI and commandline scanner)
> Ccleaner (CCleaner is a freeware system optimization, privacy and
> cleaning tool. It removes unused files from your system - allowing
> Windows to run faster and freeing up valuable hard disk space. It also
> cleans traces of your online activities such as your Internet history.
> Additionally it contains a fully featured registry cleaner). This tool
> supports cleanup of all browsers with windows 7 compatibility
>
> -Anshuman
>
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On Behalf Of Jay Vlavianos
> Sent: Tuesday, November 10, 2009 12:11 AM
> To: 'jacob@...'; 'exzactly';
> security-basics@...
> Subject: RE: Security Toolkit for dummies
>
> In addition to the other tools mentioned, I send my tech's out with a
> bootable USB-Key with Kapersky Rescue for anti-virus scanning.  It is
> slow but takes updates from the server in ram-disk.  The more advanced
> tech's also get a copy of the Ultimate Boot CD on CD/USB key as well.
>
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On Behalf Of Jacob
> Sent: Thursday, November 05, 2009 10:49 AM
> To: 'exzactly'; security-basics@...
> Subject: RE: Security Toolkit for dummies
>
> Other Ideas...
>
> FileMon
> RegMon
> Malwarebytes
> RootKit Revealer
> HijackThis
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On
> Behalf Of exzactly
> Sent: Wednesday, November 04, 2009 10:27 AM
> To: security-basics@...
> Subject: Security Toolkit for dummies
>
> I am currently working on a (free)toolkit to pass down to Tier 3 and
> Tier 2
> to be used in the event of a breach/infection or suspected
> breach/infection.
>
> In a nutshell I want to give them some tools to use to gain further
> information about the system and processes and/or malicious tools
> running on
>
> it. This toolkit is designed for a Windows desktop and Server
> environment. I
>
> am looking at building out tools that are fairly easy to use and do not
> require much training. Currently I have the following tools on it:
>
>  (SysInternal tools)
> Autoruns
> PortMon
> Process Explorer
> Process Monitor
> Ps Tools
> Logon Sessions
>
> Other tools:
> Adaware
>
>
> Is there anything else folks out there are using to provide their lower
> level support guys with some tools for informational gathering
> purposes....the tools have to run offline as systems are removed in the
> event of a breach or infection...I am not looking for a full blown
> forensics
>
> kit, just something I can train folks unfamiliar with tool fairly
> quickly...
>
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL
> certificate.  We look at how SSL works, how it benefits your company and
> how
> your customers can tell if a site is secure. You will find out how to
> test,
> purchase, install and use a thawte Digital Certificate on your Apache
> web
> server. Throughout, best practices for set-up are highlighted to help
> you
> ensure efficient ongoing management of your encryption keys and digital
> certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727
> d1
> ------------------------------------------------------------------------
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL certificate.  We look at how SSL works, how it benefits your company
> and how your customers can tell if a site is secure. You will find out
> how to test, purchase, install and use a thawte Digital Certificate on
> your Apache web server. Throughout, best practices for set-up are
> highlighted to help you ensure efficient ongoing management of your
> encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727d1
> ------------------------------------------------------------------------
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL certificate.  We look at how SSL works, how it benefits your company
> and how your customers can tell if a site is secure. You will find out
> how to test, purchase, install and use a thawte Digital Certificate on
> your Apache web server. Throughout, best practices for set-up are
> highlighted to help you ensure efficient ongoing management of your
> encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727d1
> ------------------------------------------------------------------------
>
>
> "Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or attachment."
> www.cybage.com
>
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by exzactly :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Thanks everyone for the feedback

--------------------------------------------------
From: "Anshuman Anil Deshmukh" <anshuman@...>
Sent: Monday, November 09, 2009 4:17 PM
To: "Jay Vlavianos" <jvlavianos@...>;
<jacob@...>; "exzactly" <exzactly@...>;
<security-basics@...>
Subject: RE: Security Toolkit for dummies

> I use most of the tools which are mentioned below.
> These are some of the tools which I use but do not see in this thread-
>
> LSPFix (a broken one can render an Internet connection dead to the
> world)
> GMER (detects all rootkits and rogue programs)
> Asquared-free (a good antispyware with GUI and commandline scanner)
> Ccleaner (CCleaner is a freeware system optimization, privacy and
> cleaning tool. It removes unused files from your system - allowing
> Windows to run faster and freeing up valuable hard disk space. It also
> cleans traces of your online activities such as your Internet history.
> Additionally it contains a fully featured registry cleaner). This tool
> supports cleanup of all browsers with windows 7 compatibility
>
> -Anshuman
>
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On Behalf Of Jay Vlavianos
> Sent: Tuesday, November 10, 2009 12:11 AM
> To: 'jacob@...'; 'exzactly';
> security-basics@...
> Subject: RE: Security Toolkit for dummies
>
> In addition to the other tools mentioned, I send my tech's out with a
> bootable USB-Key with Kapersky Rescue for anti-virus scanning.  It is
> slow but takes updates from the server in ram-disk.  The more advanced
> tech's also get a copy of the Ultimate Boot CD on CD/USB key as well.
>
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On Behalf Of Jacob
> Sent: Thursday, November 05, 2009 10:49 AM
> To: 'exzactly'; security-basics@...
> Subject: RE: Security Toolkit for dummies
>
> Other Ideas...
>
> FileMon
> RegMon
> Malwarebytes
> RootKit Revealer
> HijackThis
>
> -----Original Message-----
> From: listbounce@... [mailto:listbounce@...]
> On
> Behalf Of exzactly
> Sent: Wednesday, November 04, 2009 10:27 AM
> To: security-basics@...
> Subject: Security Toolkit for dummies
>
> I am currently working on a (free)toolkit to pass down to Tier 3 and
> Tier 2
> to be used in the event of a breach/infection or suspected
> breach/infection.
>
> In a nutshell I want to give them some tools to use to gain further
> information about the system and processes and/or malicious tools
> running on
>
> it. This toolkit is designed for a Windows desktop and Server
> environment. I
>
> am looking at building out tools that are fairly easy to use and do not
> require much training. Currently I have the following tools on it:
>
> (SysInternal tools)
> Autoruns
> PortMon
> Process Explorer
> Process Monitor
> Ps Tools
> Logon Sessions
>
> Other tools:
> Adaware
>
>
> Is there anything else folks out there are using to provide their lower
> level support guys with some tools for informational gathering
> purposes....the tools have to run offline as systems are removed in the
> event of a breach or infection...I am not looking for a full blown
> forensics
>
> kit, just something I can train folks unfamiliar with tool fairly
> quickly...
>
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL
> certificate.  We look at how SSL works, how it benefits your company and
> how
> your customers can tell if a site is secure. You will find out how to
> test,
> purchase, install and use a thawte Digital Certificate on your Apache
> web
> server. Throughout, best practices for set-up are highlighted to help
> you
> ensure efficient ongoing management of your encryption keys and digital
> certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727
> d1
> ------------------------------------------------------------------------
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL certificate.  We look at how SSL works, how it benefits your company
> and how your customers can tell if a site is secure. You will find out
> how to test, purchase, install and use a thawte Digital Certificate on
> your Apache web server. Throughout, best practices for set-up are
> highlighted to help you ensure efficient ongoing management of your
> encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727d1
> ------------------------------------------------------------------------
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an
> SSL certificate.  We look at how SSL works, how it benefits your company
> and how your customers can tell if a site is secure. You will find out
> how to test, purchase, install and use a thawte Digital Certificate on
> your Apache web server. Throughout, best practices for set-up are
> highlighted to help you ensure efficient ongoing management of your
> encryption keys and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
> f727d1
> ------------------------------------------------------------------------
>
>
> "Legal Disclaimer: This electronic message and all contents contain
> information from Cybage Software Private Limited which may be privileged,
> confidential, or otherwise protected from disclosure. The information is
> intended to be for the addressee(s) only. If you are not an addressee, any
> disclosure, copy, distribution, or use of the contents of this message is
> strictly prohibited. If you have received this electronic message in error
> please notify the sender by reply e-mail to and destroy the original
> message and all copies. Cybage has taken every reasonable precaution to
> minimize the risk of malicious content in the mail, but is not liable for
> any damage you may sustain as a result of any malicious content in this
> e-mail. You should carry out your own malicious content checks before
> opening the e-mail or attachment."
> www.cybage.com
>
>
>
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an SSL
> certificate.  We look at how SSL works, how it benefits your company and
> how your customers can tell if a site is secure. You will find out how to
> test, purchase, install and use a thawte Digital Certificate on your
> Apache web server. Throughout, best practices for set-up are highlighted
> to help you ensure efficient ongoing management of your encryption keys
> and digital certificates.
>
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by n3td3v :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote:
> Not to mention Microsoft COFEE now that it's been leaked
>

Funny you say that, there was a news article on the frontpage of
Securityfocus about that by Robert Lemos which has now been removed.
Anybody know why?

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by Jay Vlavianos-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Probably for the same reason it was removed as a torrent from various  
sites - it is deemed too hot to deal with at the moment.

Considering it is one of the only software packages out there that was  
completely designed for LEOs, it stands to reason that people fear M$  
legal/cop smack down.

Why get the BSA involved for piracy when you can just let the LEOs you  
create it for own the case?  Even reporting that you reviewed it is an  
admission of guilt.

-Jay

On Nov 12, 2009, at 4:27 PM, "n3td3v" <xploitable@...> wrote:

> On Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote:
>> Not to mention Microsoft COFEE now that it's been leaked
>>
>
> Funny you say that, there was a news article on the frontpage of
> Securityfocus about that by Robert Lemos which has now been removed.
> Anybody know why?

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Re: Security Toolkit for dummies

by n3td3v :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

It's not been removed, I found it http://www.securityfocus.com/brief/1034

On Fri, Nov 13, 2009 at 2:59 AM, Jay Vlavianos
<jvlavianos@...> wrote:

> Probably for the same reason it was removed as a torrent from various
> sites - it is deemed too hot to deal with at the moment.
>
> Considering it is one of the only software packages out there that was
> completely designed for LEOs, it stands to reason that people fear M$
> legal/cop smack down.
>
> Why get the BSA involved for piracy when you can just let the LEOs you
> create it for own the case?  Even reporting that you reviewed it is an
> admission of guilt.
>
> -Jay
>
> On Nov 12, 2009, at 4:27 PM, "n3td3v" <xploitable@...> wrote:
>
>> On Tue, Nov 10, 2009 at 4:47 PM, xgermx <xgermx@...> wrote:
>>> Not to mention Microsoft COFEE now that it's been leaked
>>>
>>
>> Funny you say that, there was a news article on the frontpage of
>> Securityfocus about that by Robert Lemos which has now been removed.
>> Anybody know why?
>

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------