<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: configure]]></title>
    <link>http://securityratty.com/tag/configure</link>
    <description></description>
    <pubDate>Mon, 28 Jul 2008 11:29:19 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Comments, administrivia, and the future of the infosec professional]]></title>
      <link>http://securityratty.com/article/aa143c7f981843ba4a20d86448ecfd43</link>
      <guid>http://securityratty.com/article/aa143c7f981843ba4a20d86448ecfd43</guid>
      <description><![CDATA[Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. Ive removed the limitation now, for two reasons: the spam is under control, and I wanted to reply...]]></description>
      <content:encoded><![CDATA[<p>Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. I’ve removed the limitation now, for two reasons: the spam is under control, and I wanted to reply to a comment made to my post on IPsec/IPv6 direct connect.</p>  <p>On <a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3104911">13 August, jcorey</a> asked about how to deal with those who firmly believe that the only answer to any security problem is to inspect everything at the edge. This is an important question, and I wanted to give Joe an answer. (You might have to scroll down when you click the previous link, it seems that linking to individual comments is broken.)</p>  <p>Today, <a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3136984">15 October, I</a> wrote a little thesis as an answer to his question. I’m calling it out in a separate post because I want to make sure those of you with aggregators that don’t update when posts receive new comments still have a chance to reply with your thoughts. I’ll also repost it here:</p>  <blockquote>   <p>jcorey-- You've nailed the biggest obstacle to deploying something like direct connect. Many security professionals have been taught that there simply is, and never will be, a process or technology that allows you to trust anything that originates from outside your corpnet. These professionals cling to this belief, and have been the cause that allowed the whole “detection” market to bloom. </p>    <p>Let me be clear: this total lack of trustworthiness is no longer absolutely true. Of course there will be times when unknown machines will be used by known and unknown people to access your information. But what about one particular subset -- known humans, with known portable computers -- can't we do something better than treat them as toxic invaders? </p>    <p>Indeed we can. And that's what I'm proposing with direct connect. The technology -- managed, of course, with the right processes -- exists so that you can extend the trust to known computers even though you don't trust the network they're connected to. This is because you have mechanisms that: </p>    <p>1. Allow you to configure the machine according to your requirements (domain join, group policy) </p>    <p>2. Dictate computer and user authentication requirements (IPsec policies, smart cards) </p>    <p>3. Limit what the users of these machines can do (UAC, non-admin, Forefront Client Security, Windows Firewall, even software restriction policies) </p>    <p>4. Validate the health of machines initiating incoming connections and remediate if necessary (NAP, System Center Configuration Manager) </p>    <p>5. Limit the threat of attacks against stolen computers (domain logon, smart cards, BitLocker with TPM) </p>    <p>With the robust authentication, validation, configuration, and control mechanisms available to you, I simply don't see that there's any need to fall back to “detection” now. Detection technologies were -- and remain -- necessary for the times when we have no clue about the health of client computers and when we had no way to gauge the intent of the users. But it is truly reflective of a head-in-the-sand mentality to assume that this is a complete description of what's capable today. </p>    <p>You know, someone once asked me what it takes to be a security professional. I answered that there are two primary elements: <strong>become a networking/packet wonk</strong>, and <strong>be willing to change your opinions</strong> when the right evidence comes along. Indeed, I suspect that many security folk have forgotten the need to keep their wonikness updated, which in turn makes them resist new ideas regardless of the strength of the evidence. I'm not very proud of what I just wrote, because I loathe generalities, but I'm not sure what else to think here. Sigh.</p> </blockquote>  <p>Joe’s question is important and strikes at the foundation of what it means to be a security professional today. I’m eager to continue this conversation, because it’s reflective of what I sense to be a radical shift in our jobs—we are, or should be, no longer the wolf-crying propeller-head who sits in the basement and twiddles with the firewall. Instead, our job should be defined as one who’s charged with protecting the organization’s information from attack, while maximizing its utility to authorized users, according to the principles of least privilege. Your thoughts?</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3136996" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 18:29:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/forefront client security">forefront client security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/professionals">professionals</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/direct connect">direct connect</category>
      <category domain="http://securityratty.com/tag/ipsecipv6 direct connect">ipsecipv6 direct connect</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/10/15/comments-administrivia-and-the-future-of-the-infosec-professional.aspx">Comments, administrivia, and the future of the infosec professional</source>
    </item>
    <item>
      <title><![CDATA[Ethernet and WiFi and Bluetooth, oh my!]]></title>
      <link>http://securityratty.com/article/7e68a654ca332da27ddcdad36cf536ff</link>
      <guid>http://securityratty.com/article/7e68a654ca332da27ddcdad36cf536ff</guid>
      <description><![CDATA[Customers have long requested a way to configure a computer to automatically disable its wireless NIC when its Ethernet is in use. Many third-party utilities can do this for you, but neither XP nor...]]></description>
      <content:encoded><![CDATA[<p>Customers have long requested a way to configure a computer to automatically disable its wireless NIC when its Ethernet is in use. Many third-party utilities can do this for you, but neither XP nor Vista have a built-in way to accomplish this, nor will Windows 7. Although having both NICs enabled first appears to cause a security issue, in reality that would be true only if both of the following were also true: </p>  <ul>   <li>The user is logged on as a local administrator</li>    <li>The user, or some code the user runs, enables IP routing</li> </ul>  <p>By default, all forms of IP routing (including NIC bridging) are disabled. Only local administrators (or group policy) can enable them. So the risk, actually, is minimal. </p>  <p>If you have a stroll through group policy, you'll discover this setting: &quot;Prohibit installation and configuration of Network Bridge on your DNS domain network&quot; (more <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc783558.aspx">here</a>, <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc758455.aspx">here</a>). This setting allows you turn a computer into a router that bridges two networks. The bridging works only when one of the interfaces is in the same DNS namespace it was in when the bridge setting was enabled, and it works only when the Windows firewall is <em>disabled</em> on both interfaces (<a target="_blank" href="http://blogs.technet.com/steriley/archive/2007/05/29/technet-exploring-the-windows-vista-firewall.aspx">never a good idea</a>). Additionally, regardless of the group policy setting, the function doesn’t even appear as an option when the user is logged in as a non-admin. The group policy setting simply removes the option from people who are local admins of their computers. So here's a way you can remove the ability even for local admins to enable routing. </p>  <p>However, let me admit that I wish we <em>did</em> have a way to implement your request, but for an entirely different reason: IP address preservation. Consider what happens when I'm on my own corpnet in my office. I put my laptop in its dock, which is connected to the Ethernet. I never bother disabling my wireless (I'm lazy). So whenever I'm in my office I'm taking up two IP addresses: one on the Ethernet and one on the wireless. Such wasteful profligacy, I know! (Note this isn’t a problem for any Bluetooth adapter, which always uses <a target="_blank" href="http://support.microsoft.com/kb/220874">APIPA</a> in its default configuration; I can’t imagine a scenario where you’d want Bluetooth to use DHCP.)</p>  <p>If you agree with me that this is something we should address post Windows 7, not for &quot;security&quot; reasons but as a good general networking practice of being conservative with address allocation, please speak up. Now's the time for your input.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3136959" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 17:16:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bluetooth">bluetooth</category>
      <category domain="http://securityratty.com/tag/ethernet">ethernet</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows firewall">windows firewall</category>
      <category domain="http://securityratty.com/tag/user runs">user runs</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/wireless nic">wireless nic</category>
      <category domain="http://securityratty.com/tag/address post windows">address post windows</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/10/15/ethernet-and-wifi-and-bluetooth-oh-my.aspx">Ethernet and WiFi and Bluetooth, oh my!</source>
    </item>
    <item>
      <title><![CDATA[Web Based Malware Emphasizes on Anti-Debugging Features]]></title>
      <link>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</link>
      <guid>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</guid>
      <description><![CDATA[Following the ongoing development of a particular web based malware, always comes handy in terms of assessing the commoditization of anti-debugging features within modern malware. With plain simple,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/fmDkcbMwPSs/s1600-h/web_based_malware_cc1_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/1HWDayNG6dU/s200-R/web_based_malware_cc1_.JPG" /></a>Following the ongoing development of a particular web based malware, always comes handy in terms of assessing <a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">the commoditization</a> of <a href="http://ddanchev.blogspot.com/2008/09/commercialization-of-anti-debugging.html">anti-debugging features</a> within modern malware. With plain simple, "managed binary crypting and firewall bypassing verification" on demand in February, to August's overall anti antivirus software mentality as a key differentiation factor of the malware.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/oRig4C4IWHo/s1600-h/web_based_malware_cc3_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/FyZQV_azx1o/s200-R/web_based_malware_cc3_.JPG" /></a>So what are they working on? Anti tracing and emulation protection, PeiD and PESniffer protection, as well as anti heuristic scanning with a simple junk data adding feature in order to maintain a smaller binary size.<i> <br />
</i><br />
Here's a translated description :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/vMxRy0XpiTc/s1600-h/web_based_malware_cc_new_version1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/WCAOc2P-dV8/s200-R/web_based_malware_cc_new_version1.jpg" /></a>"<i>- The binary works under admin and under normal user</i><br />
<i>- The binary is always run as the "current user"</i><br />
<i>- An unlimited number of bots can be loaded and integrated within the command and control, and with the geolocation feature, filters can be applied for a particular country</i><br />
<i>-After successful infection, the binary which is tested against popular firewall and proactive protection security ensures that the actions it takes and their order do not trigger protactive protection mechanisms in place</i><br />
<i>- binary file size is 25k, the size can be reduced once it's crypted<br />
</i><br />
<i></i> <br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/PD09GhFmXi4/s1600-h/web_based_malware_cc_new_version2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/6VE-Clw7bNk/s200-R/web_based_malware_cc_new_version2.jpg" /></a><i>- Doesn't take advantage of BITS protocol </i><br />
<i>- Doesn't allow an infected host to be infected twice</i><br />
<i>- Bypassing NAT and supporting "always-on" connections</i><br />
<i>- A simple, easy to configure web based admin panel</i>" <br />
<br />
What if the buyer doesn't care about the quality assurance practices applied? <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Managed lower AV detection and firewall bypassing service</a> comes into play.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W8uJM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W8uJM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ilgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ilgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZaTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZaTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=msyxm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=msyxm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YpECM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YpECM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1sBzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1sBzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pqSlm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pqSlm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413578893" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 22:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/binary file">binary file</category>
      <category domain="http://securityratty.com/tag/binary">binary</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/plain simple">plain simple</category>
      <category domain="http://securityratty.com/tag/anti">anti</category>
      <category domain="http://securityratty.com/tag/simple junk data">simple junk data</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413578893/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Logs and Log Management - 2]]></title>
      <link>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</link>
      <guid>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</guid>
      <description><![CDATA[I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not &quot;the original logging evangelist&quot; anymore :-) Here is a bunch of good log-related reading, useful for those...]]></description>
      <content:encoded><![CDATA[<p>I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not <a href="http://www.chuvakin.org">&quot;the original logging evangelist&quot;</a> anymore :-) Here is a bunch of good log-related reading, useful for those struggling with logs (aka &quot;everybody&quot; :-))</p>  <ol>   <li>Our brilliant field engineer Dimitri McKay <a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">talks about</a> the eternal topic of converting Windows event logs to syslog. <a href="http://blogs.msdn.com/ericfitz/">Yes, Eric, we ALL know</a> it is ugly, but that is the only way that actually works well across all systems ...</li>    <li>More on Windows and syslog: &quot;<a href="http://redmondmag.com/columns/article.asp?editorialsid=1868">Syslog ... 20 Years Later</a>.&quot;&#160; BTW, this is really not about syslog, but about Vista/2k8 finally getting an ability to natively centralize the event logs via event subscriptions (&quot;It's only about twenty years behind schedule, if you're counting.&quot;)</li>    <li>Two fun pieces on correlation: <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">1</a> and <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">2</a>. What often kills &quot;a log correlation project&quot;? &quot;Whoever had worked on it <em>had not had much time available to learn the way to properly configure the software</em>&quot; (from <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">this</a>)&#160; and &quot;correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs.&quot; (from <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">this</a>) None of this is new, but a useful reminder nonetheless</li>    <li>Fun <a href="http://www.loglogic.com">LogLogic</a> podcast is <a href="http://blogs.zdnet.com/Gardner/?p=2723">here</a>. The topic of this high-level discussion (CEO) is related to operational use for logs. I did one with them too; on logs and virtualization (will be up soon)</li>    <li>A couple of good posts on logging from Nemertes Research: &quot;<a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals</a>&quot;,&#160; &quot;<a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy</a>&quot;</li>    <li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Reminder</a> about a few useful Windows Vista and 2k8 events: 4802 (screensaver engaged) and 4803 (screensaver dismissed)</li>    <li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">One person is wondering</a> about the usefulness of logging after &quot;experiencing&quot; Linux auditd logging (kernel audit): &quot;Logs are like a warm blanket; verbose logging means you can know what's happening on your systems if you keep up with the logs.&#160; At the same time, logs become a burden very very easily, and they are easy to ignore.&quot; <a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">This post</a> is a must read for <a href="http://www.chuvakin.org">us logging afficionados</a>; producing too much log data is a sure way to make people hate you...</li>    <li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">This</a> also follows the same theme: people doubting the god-like power of logs :-) &quot;So for an administrator to not care about logs was a shock.&quot; But would I argue that &quot;<a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">log management is NOT a pain?</a>&quot; Now, would I? :-)</li>    <li>A classic about logging for application developers: &quot;<a href="http://www.securityfocus.com/infocus/1888">Building Secure Applications: Consistent Logging</a>.&quot;&#160; I am noticing a lot more discussions about logging in a developer community, e.g. see <a href="http://ayende.com/Blog/archive/2008/08/02/Logging-Auditing-and-Alerts.aspx">this</a> and <a href="http://www.softwaremag.com/l.cfm?doc=1048-5/2007">this</a> (the latter, BTW, contains a lot of info on &quot;why log&quot; for developers). Overall, &quot;getting logging right&quot; is important (and will get more important in the future) and people need something NOW and cannot wait for the <a href="http://cee.mitre.org">standards.</a>&#160; BTW, I am planning a mini-crusade on how to train application developers to include useful logging in their applications...</li>    <li>Finally, the &quot;Is SIEM dead?&quot; theme is continued in this fun post &quot;<a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">Life after SIEM. Situational Awareness is next.</a>&quot; Indeed, <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">context is key for logs</a>. BTW, if somebody mentions that I have &quot;vendor bias&quot;, I will kick your ass! :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gABUL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gABUL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5mpyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5mpyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AMhOL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AMhOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393291744" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 04:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/windows event logs">windows event logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/train application developers">train application developers</category>
      <category domain="http://securityratty.com/tag/log correlation project">log correlation project</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393291744/fun-reading-on-logs-and-log-management.html">Fun Reading on Logs and Log Management - 2</source>
    </item>
    <item>
      <title><![CDATA[Don't Mix MX And CNAME Records]]></title>
      <link>http://securityratty.com/article/004725fe5a13e6eeac176518aa1a62ec</link>
      <guid>http://securityratty.com/article/004725fe5a13e6eeac176518aa1a62ec</guid>
      <description><![CDATA[An ambiguity in RFC 2821 , which defines how email should be delivered, causes problems for some users, according to Ferris Research. In their first blog on the subject they relate a story of someone...]]></description>
      <content:encoded><![CDATA[An ambiguity in <A class=external href="http://www.faqs.org/rfcs/rfc2821.html" target=_blank>RFC 2821</A>, which defines how email should be delivered, causes problems for some users, according to Ferris Research.

In <a href="http://www.ferris.com/2008/09/07/beware-using-cname-and-mx-at-the-same-time/">their first blog on the subject</a> they relate a story of someone (names are expunged to protect the innocent from embarrassment) who decided to configure his DNS with both an MX record (which advertises the mail server) and a CNAME record defining where the web server was. More specifically, the CNAME defined "the-domain-in-question.com." to be "www.the-domain-in-question.com", the IP address of which was defined in a separate A record. After this, Mr. Anonymous's e-mail wasn't consistently reaching the mail server anymore. Some external servers were no longer finding the mail server.

The problem turns out to be that when a server has a CNAME record some sending mail servers will attempt to connect to that and not to the server pointed to by the MX record. So in the example, the outside mail was being sent to the web server, which of course didn't respond to it.

<a href="http://www.ferris.com/2008/09/08/why-you-shouldnt-mix-cname-and-mx/">The problem, says Ferris, is in an ambiguity in RFC 2821.</a> They have a point. The SMTP standard seems to <i>recommend</i> against mixing CNAME and MX records, but it doesn't prohibit it, and it's unclear on how the server should behave when it finds both.

Bottom line: Don't mix them.
<p><a href="http://feedads.googleadservices.com/~a/pPJkrG0shTbAW-nlDb8Q4C1Xj8c/a"><img src="http://feedads.googleadservices.com/~a/pPJkrG0shTbAW-nlDb8Q4C1Xj8c/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/ntgwYENutcQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 04:59:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <category domain="http://securityratty.com/tag/mail server anymore">mail server anymore</category>
      <category domain="http://securityratty.com/tag/mail servers">mail servers</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/mail server">mail server</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/cname">cname</category>
      <category domain="http://securityratty.com/tag/web server">web server</category>
      <category domain="http://securityratty.com/tag/record">record</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/ntgwYENutcQ/dont_mix_mx_and_cname_records.html">Don't Mix MX And CNAME Records</source>
    </item>
    <item>
      <title><![CDATA[Network skill level gap is growing, but growth opportunities abound!]]></title>
      <link>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</link>
      <guid>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</guid>
      <description><![CDATA[A recent IDC report sponsored by the Cisco Learning Institute reveals a huge networking skills gap is emerging in North America, which spells trouble for enterprises. Listen to this: 600,000 IT...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/exam.jpg" border="0" alt="Test Quiz" width="240" height="160" align="left" /> A recent IDC report sponsored by the Cisco Learning Institute reveals <a href="http://www.networkworld.com/newsletters/itlead/2008/080408itlead1.html" target="_blank">a huge networking skills gap</a> is emerging in North America, which spells trouble for enterprises. Listen to this: “600,000 IT workers were needed to install, configure, manage and secure networks in North America in 2007, 14% of the total IT workforce.” However, IDC reports that another 180,000 engineers with wireless as well as traditional network engineering experience will need to be added by 2011 to keep pace with advances in technology that is transforming the role of the network.</p>
<p>The convergence of voice and video traffic are quickly transforming the growing complexity of networks at a torrid pace. IDC estimates that the skills gap in VOIP should grow to 19% by 2011.</p>
<p>This changing profile in the role of the network plays a key role in the skills shortage. Network enabled collaboration tools such as social networking apps and the Webex conferencing/collaboration solutions we use in our business each and every day are demanding a new set of IT skills to deliver business value.</p>
<p>My perspective is two-fold on this issue; the first is what I have seen in the resources we have attempted to hire! We give a very straightforward quick written/oral test to all new technical hires. This requires basic networking knowledge and some Unix commands. On average, (after filters from reputable recruiting firms, some with 5-10 years experience) less than 10% pass muster for the first filter we use in our hiring process. This is a troubling fact, which has cost us considerable time and effort to secure the right resources with competent skills. So I can say from our market assessment in a very strong technological job skills market, core Unix and networking foundation skills are slipping.</p>
<p>The second is that we as an IT Operations Management (ITOM) industry need to keep pushing hard to build better proactive and intuitive solutions to aggregate instrumentation from all Data Center tools, including more work around VOIP, video streaming, and collaboration so that we can ease this transition. If ITOM solutions become more proactive across the typical Cisco infrastructure that is commonly installed in the Data Center, we can free up some additional time for advanced “emerging technologies” training where existing IT workers can enhance their core skills and re-invigorate their careers. We have to do a much better job of getting our existing IT professionals trained on emerging technologies!</p>
<p>While there’s less that ScienceLogic can do around <a href="http://www.cisco.com/web/learning/le3/learning_career_certifications_and_learning_paths_home.html" target="_blank">training</a>, we certainly strive to do our part to enhance a day in the life of the networking engineers who use our solutions to simplify monitoring of increasingly complex networking, <a href="http://www.networkworld.com/news/2008/080608-p-g.html" target="_blank">Wireless, VOIP, and collaboration needs</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 17:06:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/foundation skills">foundation skills</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/skills gap">skills gap</category>
      <category domain="http://securityratty.com/tag/skills shortage">skills shortage</category>
      <category domain="http://securityratty.com/tag/intuitive solutions">intuitive solutions</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/traditional network">traditional network</category>
      <category domain="http://securityratty.com/tag/recent idc report">recent idc report</category>
      <source url="http://blog.sciencelogic.com/network-skill-level-gap-is-growing-but-growth-opportunities-abound/08/2008">Network skill level gap is growing, but growth opportunities abound!</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Even More Logging Questions - Answered]]></title>
      <link>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</link>
      <guid>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</guid>
      <description><![CDATA[I did this fun webcast on logging for accountability ( here ) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers

Q1: How do you handle variety of...]]></description>
      <content:encoded><![CDATA[<p>I did <a href="http://isc2.brighttalk.com/node/403">this fun webcast</a> on logging for accountability (<a href="http://isc2.brighttalk.com/node/403">here</a>) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers.</p>  <p>&#160;</p>  <p>Q1: How do you handle variety of log sources? There are so many, almost beyond my capability. </p>  <p>A1: Sorry to ponder the meaning of &quot;is&quot; here, but what is meant by &quot;handle&quot;? It is really not that hard to collect logs from a large number of diverse sources (as long as the logs can be delivered via syslog or exist as files and can be collected). Now, there will certainly be challenges&#160; when the volume of logs gets large, but if by &quot;handle&quot; you mean &quot;collect + store&quot;, it is really not that hard, given <a href="http://www.loglogic.com">the right tools.</a> Now, if &quot;handle&quot; means &quot;make sense of what all those logs are trying to tell you,&quot; it is a different story altogether.</p>  <p>&#160;</p>  <p>Q2: You talked about the importance of logging; however for an intermediate or novice admin what are the starting steps .. what are the minimal logs they should start at once?</p>  <p>A2: Answered in <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">&quot;Log Management - Day 1&quot;</a> If you want a simple list of things to &quot;enable today,&quot;&#160; I cannot really answer it since I know neither your needs, nor your environment. In other words, this is the &quot;what is the meaning of life question?&quot; :-)</p>  <p>&#160;</p>  <p>Q3: What regulations, rules or guidance exist regarding sharing or visibility of logs to users?</p>  <p>A3: PCI DSS says in Requirement 10.5:&#160; &quot;Secure audit trails so they cannot be altered.    <br /><em>10.5.1 Limit viewing of audit trails to those with a job-related need      <br /></em>10.5.2 Protect audit trail files from unauthorized modifications     <br />10.5.3 Promptly back-up audit trail files to a centralized log server or media that is difficult to     <br />alter&quot; </p>  <p>NIST guidance for FISMA also says something similar (for example, look in <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">NIST 800-92 doc</a>). Overall, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">log protection and security</a> are mentioned in many other regulations as well. </p>  <p>&#160;</p>  <p>Q4: Privileged groups membership monitoring in AD one of the most important from my point of view. However I did not find effective way to monitor/report on changes in those groups. Any recommendations?</p>  <p>A4: This is indeed a tricky one which might take more space to answer than I have here; it might also take you 'beyond logs.' One good source of information is <a href="http://www.ultimatewindowssecurity.com/encyclopedia.aspx">Randy Smith's site</a> and, specifically, his webinar on 'Active Directory &quot;Logging Gap&quot;' (<a href="http://www.ultimatewindowssecurity.com/aaad/">here somewhere</a>) - which covers how to audit things of that sort when then native logging is not sufficient.</p>  <p>&#160;</p>  <p>Q5: How I can learn what exactly I need to log?</p>  <p>A5: OMG, this is a $1,000,000 question :-) Let me answer &quot;how can I learn&quot; part and not the &quot;what exactly I need to log part,&quot;&#160; (also see discussion on &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a>&quot;) as it is actually answerable. To learn what you need to log, first ask &quot;Why?&quot; (and then see <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">this</a>) - basically establish what you want to accomplish with logs, catalogue your systems, figure how to tweak the logging knobs - and then do it!</p>  <p>&#160;</p>  <p>Q6: How granular should logging be? What is your recommendation for enterprise servers like domain servers and Windows servers?</p>  <p>A6: Again, too long to answer here in details (it will become a subject of a longer blog post later), but some pointers follow: <a href="http://www.ultimatewindowssecurity.com/blog/blog_commento.asp?blog_id=23&amp;month=05&amp;year=2007&amp;giorno=&amp;archivio=OK">here for Windows</a> (MS site also have a few recommendations on audit policies)</p>  <p>&#160; </p>  <p>Q7: What is &quot;more control&quot; and what is &quot;less control&quot; that you <a href="http://isc2.brighttalk.com/node/403">mention in the webcast</a>? Can you give an example?</p>  <p>A7: OK, I did say that &quot;sometimes when you implement more controls, you actually have less control.&quot; What do I mean? If you buy a firewall (a network security control) and then - over time, of course - configure it with 7800 rules (!) that are supposed to give you control over who can and cannot access your network, you will not gain control over your environment. You will actually be less in control of who is touching your network, compared to, say, having only 20 rules.</p>  <p>&#160;</p>  <p>Q8: What about mandated NIST controls for government systems? Auditing is a specific control for Moderate and High risk systems. What list of events do you recommend for auditing?</p>  <p>A8: This is too long to answer here, but <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf ">NIST 800-92 Guide</a> is a really good source of such info (&quot;<a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">Guide to Computer Security Log Management [PDF]</a>&quot;) Also, see my presentation on <a href="http://www.slideshare.net/anton_chuvakin/nist-80092-log-management-guide-in-the-real-world/">NIST 800-92 Guide in the Real World</a>.</p>  <p>&#160;</p>  <p>Q9: The issue that many organizations get stuck on, is the monitoring process, and defining what exceptions to monitor for? Is there guidance / framework for this? How much of it is system specific and how much is applicable generally to all systems?</p>  <p>A9: I outlined some general ideas <a href="http://www.slideshare.net/anton_chuvakin/what-every-organization-should-log-and-monitor">back in 2004 via this presentation</a>&#160;<em>(note to self - update that to be more 2008-relevant);</em> it is mostly general, but also has pointers to specific system. Keep in mind that it is focused on security, not operational monitoring (which is often no less important - in fact, often <a href="http://rationalsecurity.typepad.com/blog/2008/02/omg-availabilit.html">MORE important</a>)</p>  <p>&#160;</p>  <p>Enjoy! Sorry for being brief with some of the answers - I am woefully late with this even as they are...</p>  <p><strong>Other questions that I answered in the past:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/05/more-log-management-questions-answered.html">More Log Management Questions - Answered!</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/some-burning-logging-questions-answered.html">Some Burning Logging Questions - Answered!</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=juyDeK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=juyDeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=o5WeXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=o5WeXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mnNGqK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mnNGqK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/357664119" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 07:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log server">log server</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/log sources">log sources</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/specific control">specific control</category>
      <category domain="http://securityratty.com/tag/network security control">network security control</category>
      <category domain="http://securityratty.com/tag/log protection">log protection</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/357664119/even-more-logging-questions-answered.html">Even More Logging Questions - Answered</source>
    </item>
    <item>
      <title><![CDATA[No, FISMA Doesnt Require That, Silly Product Pushers]]></title>
      <link>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</link>
      <guid>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</guid>
      <description><![CDATA[Post #9678291 on why people dont understand what FISMA really is : Secure64 DNSSEC Press Releases
FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security...]]></description>
      <content:encoded><![CDATA[<p>Post #9678291 on <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">why people don&#8217;t understand what FISMA really is</a>:  <a href="http://www.domaininformer.com/news/press/310708DNSSEC.html" target="_blank">Secure64 DNSSEC Press Releases</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government<span id="bwanpa5">’</span>s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices.&#8221;</em></p>
<p>Yep, if you stamp FISMA on it, people will buy it, maybe in your PR department&#8217;s wettest and wildest dreams.  Guys, it&#8217;s been 6 years, that kind of marketing doesn&#8217;t work nowadays, mostly because we spent ourselves into oblivion buying junkware similar to yours and now we&#8217;re all jaded.</p>
<p>Now don&#8217;t get me wrong, DNSSEC is a good thing, especially this month.  But there is something I need to address:  FISMA requires good security management with a dozen or so key indicators, not a solution down to the technical level.  Allusions to OMB are just FUD, FUD, and more FUD because unless it&#8217;s in a memo to agency heads, it&#8217;s all posturing&#8211;something everybody in this town knows how to do very well.  OMB would rather stay out of mandating DNSSEC and maybe give a &#8220;due date&#8221; once NIST has a final standard.</p>
<p>My one word of wisdom for today:  anybody who tries to sell a product and <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">uses FISMA as the &#8220;compelling event&#8221; has no clue what they&#8217;re talking about</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers&amp;url=http://www.guerilla-ciso.com/archives/440&amp;version=0.7" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/440&amp;t=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2mnw8J"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2mnw8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HAXdPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HAXdPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/351599310" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 10:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma requires">fisma requires</category>
      <category domain="http://securityratty.com/tag/fisma act encourages">fisma act encourages</category>
      <category domain="http://securityratty.com/tag/stamp fisma">stamp fisma</category>
      <category domain="http://securityratty.com/tag/dnssec">dnssec</category>
      <category domain="http://securityratty.com/tag/dnssec requirements">dnssec requirements</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/351599310/440">No, FISMA Doesnt Require That, Silly Product Pushers</source>
    </item>
    <item>
      <title><![CDATA[Damage control rule # 1, shift the blame.]]></title>
      <link>http://securityratty.com/article/876feba1ed1d8fe2437f2b735fbc5253</link>
      <guid>http://securityratty.com/article/876feba1ed1d8fe2437f2b735fbc5253</guid>
      <description><![CDATA[Wow, they must have taken classes from our Government


clipped from vista.blorge.com
Microsoft blaming PC manufactures &amp; their added software for Vista misconception
clipped from vista.blorge.com
In...]]></description>
      <content:encoded><![CDATA[<div>Wow, they must have taken classes from our Government.</div>
<table style="border: 4px solid #e5e5e5; margin: 12px 0px; background: #ffffff none repeat scroll 0%; font-family: arial; color: #333333; width: 100%; clear: left;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table style="border-bottom: 1px solid #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee; background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><a title="go to this clipmark" href="http://clipmarks.com/clipmark/DDDA86A0-A8FD-4AD5-B44F-34945D42935F/"><img style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" src="http://content.clipmarks.com/blog_icon/98f3ad2c-ac63-4512-9654-ae11000a0081/DDDA86A0-A8FD-4AD5-B44F-34945D42935F/" border="0" alt="" width="19" height="19" /></a>clipped from <a style="font-size: 11px;" title="http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/" href="http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/">vista.blorge.com</a></td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/ --></p>
<h3><a title="Permanent Link: Microsoft blaming PC manufactures &amp; their added software for Vista misconception" rel="bookmark" href="http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/">Microsoft blaming PC manufactures &amp; their added software for Vista misconception</a></h3>
</td>
</tr>
</tbody>
</table>
<table style="border-bottom: 1px solid #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee; background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><a title="go to this clipmark" href="http://clipmarks.com/clipmark/DDDA86A0-A8FD-4AD5-B44F-34945D42935F/"><img style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" src="http://content6.clipmarks.com/images/clip-icon.gif" border="0" alt="" width="19" height="19" /></a>clipped from <a style="font-size: 11px;" title="http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/" href="http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/">vista.blorge.com</a></td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://vista.blorge.com/2008/07/26/microsoft-blaming-pc-manufactures-their-added-software-for-vista-misconception/ -->In the minds of Microsoft execs, the problem lies with the fact that Vista is deployed on such a wide variety of PC builds, from a variety of manufacturers.? A configuration from one brand might yield completely different results then that of another.? For example, you can take the same laptop and pre-configure it one way and you get almost instantaneous boot-times, and fantastic battery life. If you pre-configure it with software in another way you get long boots, and much less battery life.? Microsoft, as part of their restructuring plan, plans to educated its OEM providers on these subjects to try an curb any negative compatibility issues at the source.</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td style="background:transparent;border-width:0px;padding:0px;"></td>
<td style="border-width: 0px; padding: 0px; background: transparent none repeat scroll 0%; width: 107px;" width="107" align="right"><a title="blog or email this clip" href="http://clipmarks.com/share/DDDA86A0-A8FD-4AD5-B44F-34945D42935F/blog/"><img style="border-width:0px;padding:0px;margin:0px;" src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" /></a></td>
</tr>
</tbody>
</table>
</div>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 11:29:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fantastic battery life">fantastic battery life</category>
      <category domain="http://securityratty.com/tag/vista misconception">vista misconception</category>
      <category domain="http://securityratty.com/tag/battery life">battery life</category>
      <category domain="http://securityratty.com/tag/vista">vista</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft execs">microsoft execs</category>
      <category domain="http://securityratty.com/tag/negative compatibility issues">negative compatibility issues</category>
      <category domain="http://securityratty.com/tag/wide variety">wide variety</category>
      <category domain="http://securityratty.com/tag/variety">variety</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=521">Damage control rule # 1, shift the blame.</source>
    </item>
  </channel>
</rss>
