<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT A Digital Life</title>
	<atom:link href="http://digitallachance.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://digitallachance.com/blog</link>
	<description>All things digital</description>
	<lastBuildDate>Sun, 06 Nov 2011 08:01:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>pfSense 2.0RC1 is now available.</title>
		<link>http://digitallachance.com/blog/2011/03/pfsense-2-0rc1-is-now-available/</link>
		<comments>http://digitallachance.com/blog/2011/03/pfsense-2-0rc1-is-now-available/#comments</comments>
		<pubDate>Tue, 01 Mar 2011 15:37:45 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software & Tools]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[pfSense]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=151</guid>
		<description><![CDATA[Looks like the pfSense team has put out their first release candidate for the version 2 of the open source pfSense firewall. <a href="http://digitallachance.com/blog/2011/03/pfsense-2-0rc1-is-now-available/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Looks like the pfSense team has put out their first release candidate for the version 2 of the open source pfSense firewall.  This is a great firewall that will run on just about any hardware.  It has as many features as commercially available firewalls and works great.  I&#8217;ll be doing a few upgrades shortly and may post about it here.</p>
<p>Take a look at the <a title="2.0-RC1 Now Available!" href="http://blog.pfsense.org/?p=585" target="_blank">blog post</a> about this release on the pfSense site.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2011/03/pfsense-2-0rc1-is-now-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Vulnerability in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server</title>
		<link>http://digitallachance.com/blog/2010/12/vulnerability-in-the-pdf-distiller-of-the-blackberry-attachment-service-for-the-blackberry-enterprise-server/</link>
		<comments>http://digitallachance.com/blog/2010/12/vulnerability-in-the-pdf-distiller-of-the-blackberry-attachment-service-for-the-blackberry-enterprise-server/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 17:14:23 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[BES]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=143</guid>
		<description><![CDATA[Looks like there has been another vulnerability discovered in the BlackBerry Enterprise Server PDF distiller of the BlackBerry Attachment Service.   <a href="http://digitallachance.com/blog/2010/12/vulnerability-in-the-pdf-distiller-of-the-blackberry-attachment-service-for-the-blackberry-enterprise-server/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Looks like there has been another vulnerability discovered in the BlackBerry Enterprise Server PDF distiller of the BlackBerry Attachment Service.  This vulnerability is scoring 7.8 on the CVSS scale, so it is a high risk vulnerability.  You should apply the patch to your BES server ASAP.</p>
<p>See <a title="This will open a new window to the BlackBerry web site." href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB24761" target="_blank">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB24761</a> for the details from RIM.</p>
<p>If you haven&#8217;t already done so, you really should have the attachment service running in a segmented network in order to prevent the spread of malware.  The PDF distiller has required quite a few patches in the past few years and is, in my opinion, the weakest point in the whole BES architecture.  See the BlackBerry technical notes on how to achieve segmentation <a title="This will open a new window to the BlackBerry web site." href="http://docs.blackberry.com/en/admin/deliverables/17843/index.jsp?name=Placing+the+BlackBerry+Enterprise+Server+in+a+segmented+network+-+Technical+Note+-+BlackBerry+Enterprise+Server+for+Microsoft+Exchange5.0.2&amp;language=English&amp;userType=2&amp;category=BlackBerry+Enterprise+Server+for+Microsoft+Exchange&amp;subCategory=" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2010/12/vulnerability-in-the-pdf-distiller-of-the-blackberry-attachment-service-for-the-blackberry-enterprise-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safe boot trick for BlackBerry</title>
		<link>http://digitallachance.com/blog/2010/12/safe-boot-trick-for-blackberry/</link>
		<comments>http://digitallachance.com/blog/2010/12/safe-boot-trick-for-blackberry/#comments</comments>
		<pubDate>Sun, 12 Dec 2010 06:29:39 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[How-to]]></category>
		<category><![CDATA[safe-mode]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=139</guid>
		<description><![CDATA[I just learned of a nice trick for BlackBerry. Just like safe mode in Windows XP, you can boot your BlackBerry into safe mode where it will not automatically load any third-party application. This can be useful for situations where &#8230; <a href="http://digitallachance.com/blog/2010/12/safe-boot-trick-for-blackberry/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I just learned of a nice trick for BlackBerry.</p>
<p>Just like safe mode in Windows XP, you can boot your BlackBerry into safe mode where it will not automatically load any third-party application.  This can be useful for situations where you have something that is making your BlackBerry unstable.</p>
<p>This works with a battery pull or doing the hard reset key combination (Alt-left-shift-del).  Right after the red light goes off, press and hold the escape key until the boot is complete.  You will know that you are in safe mode because it will say &#8220;safe mode&#8221; in the top-middle of the screen.  This works on my BlackBerry Bold.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2010/12/safe-boot-trick-for-blackberry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus definition update on the F-Secure rescue CD</title>
		<link>http://digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/</link>
		<comments>http://digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/#comments</comments>
		<pubDate>Sun, 23 May 2010 23:18:54 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[How-to]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software & Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=130</guid>
		<description><![CDATA[So, a co-worker from the office asked me to clean their personal laptop from one of those anti-virus application that install themselves and creates a bunch of pop-ups telling you you are infected.  Obviously, I didn't want to connect that machine to our corporate LAN, so I figured I should use a rescue CD of some sort that does AV scans.  I was highly recommended to use F-Protect's rescue CD for this type of malware in my SANS 504 course that I just took last week. <a href="http://digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>So, a co-worker from the office asked me to clean their personal laptop from one of those anti-virus application that install themselves and creates a bunch of pop-ups telling you you are infected.  Obviously, I didn&#8217;t want to connect that machine to our corporate LAN, so I figured I should use a rescue CD of some sort that does AV scans.  I was highly recommended to use F-Protect&#8217;s rescue CD for this type of malware in my SANS 504 course that I just took last week.</p>
<p>A quick Google search returned a very useful page from techmixer.com titled <a href="http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/" target="_blank">FREE Bootable AntiVirus Rescue CDs Download List</a>.  This page lists seven freely available Antivirus rescue CD options.  So I downloaded the ISO for F-Protect and burned it to a CD.  Obviously, you want to make sure you are scanning with the latest virus definition update, but since the CD is a read-only media, you can&#8217;t update the virus definition on it.  The ISO contains a virus definition file from July 2009, but that&#8217;s way to old to be useful.  I tried to follow the instructions that were on the techmixer.com page about F-Protect to use the updates on a USB stick, but without success.  When all else fails, read the instructions.  <img src='http://digitallachance.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I downloaded the PDF manual from <a href="http://www.f-secure.com/linux-weblog/files/rescue_cd_user_guide.20090717.pdf" target="_blank">http://www.f-secure.com/linux-weblog/files/rescue_cd_user_guide.20090717.pdf</a> and those instructions, unlike the ones on the techmixer.com ones, instructed to create a fsecurerescuecd folder on your USB stick.  That way, the virus definition gets expanded to the rescuecd folder as well as the results of the scan is saved in a reports folder.  The trick is to use a USB drive that has nothing else on it.  Why they had to do it that way, I&#8217;m not sure.  I wished that it wasn&#8217;t so because I would rather carry only one stick instead of dedicating one to having the F-Secure virus definition file.</p>
<p>For those of you who prefer bullets and get &#8216;er done, here is a step-by-step how-to:</p>
<ol>
<li>Download the ISO  from the F-Secure web site.  As of this writing, version 3.11 is current.</li>
<li>Burn the ISO to a CD.</li>
<li>Have a FAT formated USB thumb drive with nothing on it.</li>
<li>Create a fsecure folder at the root of the drive.</li>
<li>Create a rescuecd folder in the fsecure folder.</li>
<li>Download the latest virus definition file from F-Secure from <a href="http://download.f-secure.com/latest/fsdbupdate9.run" target="_blank">http://download.f-secure.com/latest/fsdbupdate9.run</a></li>
<li>Copy the fsdbupdate9.run to the root of your USB drive.</li>
<li>Plug-in the USB drive on the sick computer and then boot the rescue CD.</li>
</ol>
<p>F-Secure picked-up that I had a USB drive connected and used the virus definition for the scan.  Simply follow the on-screen instructions and your computer will be cleaned up.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2010/05/virus-definition-update-on-the-f-secure-rescue-cd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VLC media player auto-update and vulnerability</title>
		<link>http://digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/</link>
		<comments>http://digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 04:56:12 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=124</guid>
		<description><![CDATA[Secunia has published an advisory about new vulnerabilities found in VLC Media Player. <a href="http://digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I just picked up an <a href="http://secunia.com/advisories/39558" target="_blank">advisory</a> from Secunia about VLC Media Player vulnerabilities. There are 9 vulnerabilities. Three are related to A/52, DTS and MPEG audio decoders. Three are about the AVI, ASF and Matroska demuxer. The other three are about the XSPF playlist, the ZIP and RTPM implementation.</p>
<p>Successful exploitation of the vulnerabilities may allow execution of arbitrary code, but requires that the user is tricked into opening a specially crafted file.</p>
<p>There is no CVE Reference and unfortunately cannot figure out a <a href="http://www.networkworld.com/community/node/21105" target="_blank">CVSS</a> score.  You can find the original advisory (VideoLAN-SA-1003) here:<br />
<a href="http://www.videolan.org/security/sa1003.html" target="_blank">http://www.videolan.org/security/sa1003.html</a></p>
<p>There are two interesting things about this one.  One, as of right now (April 25, 2010 at 22:39 GMT-6), the fixed version for Windows (1.0.6) is still not available on the Video LAN web site.  That&#8217;s a bit unusual because, typically, the vendor likes to make sure the patch/updated version of the vulnerable software is available before publishing the vulnerability on their on web site.  The second thing that&#8217;s interesting is that the auto-update does not seem to work in my installed version (1.0.1).</p>
<p>I thought that maybe I had a problem in my home LAN that caused the auto-update to fail.  I fired up Wireshark and did a quick sniff of the traffic when trying to get VLC to update.  I used the <em>Follow TCP Stream</em> feature and it was quickly apparent that the problem wasn&#8217;t with me at all.  The GET that VLC sent got a <em>206 Partial Content</em></p>
<blockquote><p>HTTP/1.1 206 Partial Content<br />
Content-Type: text/plain<br />
Accept-Ranges: bytes<br />
ETag: &#8220;3280753111&#8243;<br />
Last-Modified: Mon, 01 Feb 2010 23:15:18 GMT<br />
Content-Range: bytes 0-485/486<br />
Content-Length: 486<br />
Date: Mon, 26 Apr 2010 04:24:08 GMT<br />
Server: lighttpd/1.4.19</p>
<p>1.0.5</p>
<p>http://www.videolan.org/mirror-geo-redirect.php?file=vlc/1.0.5/win32/vlc-1.0.5-win32.exe</p>
<p>Due to a bug in the update feature of your on of VLC, the automatic download of the new VLC will fail.</p>
<p>You have to download VLC 1.0.5 from VideoLAN&#8217;s website: http://www.videolan.org</p>
<p>VLC 1.0.5 is a minor release of 1.0.x version of VLC. It fixes a few bugs, updates the codecs and the compiler for Windows, and should improve decoding speed. It also improves and update many translations.</p></blockquote>
<p>Well, might as well download 1.0.5 for now and use the auto-update to check the 1.0.6 fix.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2010/04/vlc-media-player-auto-update-and-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BackTrack 4 Final Released</title>
		<link>http://digitallachance.com/blog/2010/01/backtrack-4-final-released/</link>
		<comments>http://digitallachance.com/blog/2010/01/backtrack-4-final-released/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 02:29:29 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software & Tools]]></category>
		<category><![CDATA[BackTrack 4]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=119</guid>
		<description><![CDATA[I'm back to blogging!  BackTrack 4, the latest version of the most popular all-in-one Linux based penetration testing suite is now out. <a href="http://digitallachance.com/blog/2010/01/backtrack-4-final-released/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Sorry for being away for so long (almost a year since the last post).  I have been making sure that this server and WordPress is always up to date even though I was not actively posting.  I&#8217;d hate for a blog about IT security to be compromised, especially if I&#8217;m the one managing it.</p>
<p><a href="http://www.digitallachance.com/blog/wp-content/uploads/2010/01/dragonHead.png"><img class="alignleft size-full wp-image-121" style="margin: 3px 6px;" title="dragonHead" src="http://www.digitallachance.com/blog/wp-content/uploads/2010/01/dragonHead.png" alt="BackTrack dragon head" width="150" height="150" /></a>In any case, it would appear that BackTrack 4 is out of Beta and is available for all to download!  I&#8217;m downloading it as I am typing this and will be burning it to a DVD to play with it.  You can download it from <a title="TrackBack download page" href="http://www.backtrack-linux.org/downloads/" target="_blank">http://www.backtrack-linux.org/downloads/</a>.  BackTrack is a great collection of software and tools in a bootable DVD or in a VM.  As described on the <a href="http://www.backtrack-linux.org/" target="_blank">BackTrack home page</a>:</p>
<blockquote><p>BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking.</p></blockquote>
<p>Even if penetration testing is not your thing, this is an easy way to get some of the most popular security tools into your hands without having to search and download from all over the Internet.</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2010/01/backtrack-4-final-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Reader is vulnerable yet again</title>
		<link>http://digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/</link>
		<comments>http://digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/#comments</comments>
		<pubDate>Fri, 01 May 2009 05:08:18 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=111</guid>
		<description><![CDATA[I figured it would happen eventually, but not quite so soon. It appears that Adobe Reader is suffering from at least two more zero-day vulnerabilities.  Here's the low-down. <a href="http://digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I figured it would happen eventually, but not quite so soon.  It appears that Adobe Reader is suffering from at least two more zero-day vulnerabilities &#8211; less than two months after the JBIG2 vulnerability.  Here&#8217;s the low-down.</p>
<p style="text-align: left;">All currently supported shipping versions of Adobe Reader and Acrobat (9.1, 8.1.4, and 7.1.1 and<br />
earlier versions) are vulnerable to this issue. Adobe plans to provide updates for all affected versions<br />
for all platforms (Windows, Macintosh and UNIX) to resolve this issue.  The vulnerabilities are in the JavaScript engine of the Adobe products.  This, by the way, affects both Adobe Reader and Adobe Acrobat.  T<span class="rss:item">he vulnerabilities exist in two JavaScript functions; <strong>getAnnots()</strong> and <strong>spell.customDictionaryOpen()</strong> and both allow remote code execution.  One way to protect yourself is to disable JavaScript &#8211; see the simple instructions from <a href="http://www.f-secure.com/weblog/archives/00001671.html" target="_blank">F-Secure</a>.<br />
</span></p>
<p>Many people made this recommendation when the last vulnerability was uncovered (<a title="See my previous post on this topic." href="http://www.digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/" target="_self">jbig2 vulnerability</a>), but it just seems to be louder this time; find an alternative reader to the Adobe Reader product.  If you need an idea for what is available out there, take a look at <a href="http://pdfreaders.org/" target="_blank">PDFreaders.org</a>.  I know that I have made the recommendation where I work, but it might not be that easy.  Corporations sometimes will rely heavyly on Adobe Reader to view custom business forms that are used on a daily basis with customers.  That reliance will often show itself in the in-house applications that make calls directly to the Adobe DLL.</p>
<p>You can read a bit more about the challenges of replacing Adobe Reader and Acrobat <a href="http://blogs.techrepublic.com.com/security/?p=1470" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2009/04/adobe-reader-is-vulnerable-yet-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The importance of password audits</title>
		<link>http://digitallachance.com/blog/2009/03/the-importance-of-password-audits/</link>
		<comments>http://digitallachance.com/blog/2009/03/the-importance-of-password-audits/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 07:31:27 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Strategies]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Two-Factor authentication]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=104</guid>
		<description><![CDATA[Have you ever tried to crack your network user's passwords?  Why would you do that you ask?  Simple, compliance check is one reason.  The other is to better understand what is possible and what kind of password your users are using.  In this post, I'll discuss why it is a very good idea to do periodic password audits in your network. <a href="http://digitallachance.com/blog/2009/03/the-importance-of-password-audits/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Have you ever tried to crack your network user&#8217;s passwords?  Why would you do that you ask?  Simple, compliance check is one reason.  The other is to better understand what is possible and what kind of password your users are using.  In this post, I&#8217;ll discuss why it is a very good idea to do periodic password audits in your network.</p>
<p>You might might think that the idea of running a password cracking program on your network users is a waste of time.  In fact, you have to remember that if the bad guys are most likely to use that type of tool, you should use it first.  That way you will know what a black hat will be able to get out our your password database.  Here are a few reasons why you should do regular password audits.</p>
<p>You should not have the false comfort that your network is safe just because you have turned on <a href="http://technet.microsoft.com/en-us/library/cc875814.aspx" target="_blank">complex password group policy in active directory</a>.  The rules of complex password in active directory are as follow:</p>
<ul>
<li>The password is at least six characters long.</li>
<li>The password contains characters from at least three of the following five categories:
<ul>
<li>English uppercase characters (A &#8211; Z)</li>
<li>English lowercase characters (a &#8211; z)</li>
<li>Base 10 digits (0 &#8211; 9)</li>
<li>Non-alphanumeric (For example: !, $, #, or %)</li>
<li>Unicode characters</li>
</ul>
</li>
<li>The password does not contain three or more characters from the user&#8217;s account name.</li>
</ul>
<p>Using those rules, that means that the password <strong>Password1</strong> is actually a valid password.  How good of a password is that?  This a valid password because active directory does not actually do a password complexity check.  What it does is more accurately described as a password constraint check.  The idea of complex passwords is that it should force users to not use dictionary words as their passwords.  Since it is not practical to have a full dictionary in Active Directory to make sure that passwords are not in the dictionary, the designers simply impose constraints on what your password should be like.  Hence, the complex password group policy constraints as described above.</p>
<p>Another aspect of passwords is that people will tend to re-use the same password everywhere they can.  What this means is that the password is only as strong as the weakest link.  Namely, if you use the same password on a web site that is easily compromised, the black hat will try the newly discovered password on your bank account as well, knowing full well that it is likely going to be the same password.</p>
<p>If you are not willing, or allowed to do a password audit on your network, you really should take a look a studies that were done on passwords that have been revealed because of security breaches.  There has been two recent incidents that are worthy of reading.  One is an article on Dark Reading (<a href="http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html" target="_blank">http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html</a>) about the phpbb.com web site hack.  The other one is from Bruce Schneier who did an analysis on passwords that were published by people behind a fake MySpace web page used in a phishing campain.</p>
<p>Whenever possible, you should use some kind of two-factor authentication, such as smart cards or an RSA token.</p>
<p>One of the best known password cracking software is L0pthCrack, which used to be owned by Symantec.  L0pthCrack has recently been <a href="http://searchsecurity.techtarget.com/video/0,297151,sid14_gci1350713,00.html?track=sy160" target="_blank">re-acquired</a> by its original authors.  They intend to update the venerable software and start selling it again.  There is other software that can be purchased (and some free) that can help you audit your user&#8217;s password.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2009/03/the-importance-of-password-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical Adobe Reader update &#8211; Upgrade NOW!</title>
		<link>http://digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/</link>
		<comments>http://digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 16:17:19 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Patching]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=100</guid>
		<description><![CDATA[If you do nothing else today, make sure you at least upgrade your users to the latest version of Adobe Reader. The vulnerability was announced back on February 20th, but now Adobe released an update to their Reader product.  You &#8230; <a href="http://digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you do nothing else today, make sure you at least upgrade your users to the latest version of Adobe Reader.</p>
<p>The vulnerability <a href="http://www.infoworld.com/article/09/02/20/Adobe_flaw_heightens_risk_of_encountering_malicious_PDFs_1.html" target="_blank">was announced</a> back on February 20th, but now Adobe released an update to their Reader product.  You can see the bulletin here:</p>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb09-03.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb09-03.html</a></p>
<p>There are a few interesting things to note.  As indicated in a <a href="http://blogs.zdnet.com/security/wp-trackback.php?p=2856" target="_blank">post by Ryan Naraine</a> on ZDNet, the updates are for Adobe Reader 9 only.  The most frustrating thing right now is that in their infinite wisdom, Adobe did not provide a patch update for Adobe Reader (a file with the MSP extension) which can be applied to your existing installation of Adobe Reader.  Instead, they simply point to their standard URL to download Adobe Reader.</p>
<p>Acrobat 9 Standard, Acrobat 9 Pro and Acrobat 9 Extended for Windows are all available as MSP patches.</p>
<p>Don&#8217;t wait, upgrade your users as soon as you can because this is a nasty one.  Users who download a malicious PDF <a href="http://blog.didierstevens.com/2009/03/09/quickpost-jbig2decode-look-mommy-no-hands/trackback/" target="_blank">do not need to open it</a> to fall victim to that flaw.</p>
<p>Hopefully, Adobe will release a patch file for Adobe Reader soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2009/03/critical-adobe-reader-update-upgrade-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Perimeter defense is useless!</title>
		<link>http://digitallachance.com/blog/2009/03/perimeter-defense-is-useless/</link>
		<comments>http://digitallachance.com/blog/2009/03/perimeter-defense-is-useless/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 23:50:45 +0000</pubDate>
		<dc:creator>Francois</dc:creator>
				<category><![CDATA[Strategies]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[HIDS]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.digitallachance.com/blog/?p=94</guid>
		<description><![CDATA[I think it is well known by security experts that the old perimeter defense model just does not work any more. A firewall does give some protection, but users are constantly asking that ports be opened so that they can access services outside of the corporate network.  Not only that, but there is not much to prevent malicious traffic to go through your ports that are already opened.  Should we ditch the firewall?  No, but you should add more layers to your defense.  In this post, I will list of the defenses you should have in your environment. <a href="http://digitallachance.com/blog/2009/03/perimeter-defense-is-useless/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I think it is well known by security experts that the old perimeter defense model just does not work any more.  A firewall does give some protection, but users are constantly asking that ports be opened so that they can access services outside of the corporate network.  Not only that, but there is not much to prevent malicious traffic to go through your ports that are already opened.  Should we ditch the firewall?  No, but you should add more layers to your defense.  In this post, I will list of the defenses you should have in your environment.</p>
<p>Whenever such a user requests to have yet another port to be opened, you should make sure that you restrict as much as possible the end-points that can make use of that port you are opening up.  For example, John asks that a port be opened so he can establish a VNP connection from the corporate LAN to a business partner, you should make sure that only John&#8217;s IP address is allowed to use that port and that there is only one outside IP address that John can reach on that port.</p>
<p>Firewall management is not what keeps me up at night though.  What keeps my up at night is the fact that it is so easy to create tunnels from inside my network to the outside over well known ports, such as port 80 or 443 in order to access anything that you would normally block at the firewall.  That plus the fact that now you cannot browse most web sites with first installing such things as Flash player and Adobe PDF reader.</p>
<p>A recently <a href="http://www.infoworld.com/article/09/02/20/Adobe_flaw_heightens_risk_of_encountering_malicious_PDFs_1.html" target="_blank">vulnerability in Adobe Reader</a> for which there is no patch as of now (Adobe said they will release one on March 11th) is a rather scary one.  This type of vulnerability can be exploited <a href="http://blog.didierstevens.com/2009/03/04/quickpost-jbig2decode-trigger-trio/" target="_blank">without the user even opening the malicious PDF!</a> How can you defend yourself against that?!  You should have as many layers as possible in order to prevent that malicious PDF from succesfully penetrate your network.  The <a href="http://securityblog.verizonbusiness.com/2009/03/05/pdf-security-through-minority/" target="_blank">Verison Business Security Blog</a> has a very good list of steps that can be taken to protect yourself against that threat.  of course, you could always <a title="eWeek - It May Be Time to Abandon Adobe" href="http://www.eweek.com/c/a/Security/It-May-Be-Time-to-Abandon-Adobe/" target="_blank">drop Abode Reader</a> altogether.</p>
<p>In general though, that approach can be applied against any threats.  Here are the different layers you should have in place in order of priority:</p>
<ol>
<li>A firewall.  I would venture to guess that everyone out there has that one in place.  Make sure that a regular review of what rules you have in place is done.</li>
<li>Intrusion Detection (IDS) or better yet, Intrusion Prevention (IPS).  If you can affort it, TippingPoint is probably a leader in that field and works great.  At the very least, you should have Snort in your network.</li>
<li>Don&#8217;t allow your users to be local administrators.  Most of the people that get infected with malware  and virus are logged on with local administrator rights.  That&#8217;s a very bad idea.  Lock down those users!</li>
<li>Anti-Virus on every machines.  AV is not perfect as it is a reactive technology, but it will catch a lot of what is out there.  Anti-Virus products now can do more than just detecting and cleaning virus.  The can block use of certain ports on your hosts (such as port 25 for e-mails or ports typically used for IRC).</li>
<li><a href="http://en.wikipedia.org/wiki/Host_based_intrusion_detection_system" target="_blank">Host-based Intrusion Detection System (HIDS)</a>.  This technology is starting to catch on in corporate environments.  This is basically the equivalent of having <a href="http://en.wikipedia.org/wiki/Zonealarm" target="_blank">ZoneAlarm</a> on each desktop, but centrally managed by the corporate IT.</li>
<li>Last but not least, patching!  Make sure that you are current in your OS patches and your application patches.  That is not always easy in corporate environment since it sometimes requires careful testing and planning.</li>
</ol>
<p>In my experience, the mobile users are the weak links.  Once they take their laptops outside of the corporate LAN, many of those defensive layers, such as IPS and the firewall, are no longer there to protect them.  That&#8217;s why you need to have strong defenses on the workstations, such as disk encryption and HIDS.</p>
<p>Can anyone think of other layers that should be in place?</p>
]]></content:encoded>
			<wfw:commentRss>http://digitallachance.com/blog/2009/03/perimeter-defense-is-useless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

