<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: reconfigure]]></title>
    <link>http://securityratty.com/tag/reconfigure</link>
    <description></description>
    <pubDate>Thu, 15 May 2008 07:13:10 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools]]></title>
      <link>http://securityratty.com/article/f3832e30a5771d94dd4085040d808e7f</link>
      <guid>http://securityratty.com/article/f3832e30a5771d94dd4085040d808e7f</guid>
      <description><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could...]]></description>
      <content:encoded><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could change in Windows XP/Vista that would let you reconfigure how the TCP/IP stack works, thus changing how the above tools would detect the OS. I wasn't sure what all registry changes to make, but luckily I found Craig Heffner's work on the subject. In this post I cover the issue of passive/active OS fingerprint detection, as well as release my tool OSfuscate.
<p><a href="http://feedads.googleadservices.com/~a/03Vn2FqYJWbHI0gRYzHRUdpdTQg/a"><img src="http://feedads.googleadservices.com/~a/03Vn2FqYJWbHI0gRYzHRUdpdTQg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/6fYkw5ozRdk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:15:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fingerprint">fingerprint</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/confuse tools">confuse tools</category>
      <category domain="http://securityratty.com/tag/fingerprint detection">fingerprint detection</category>
      <category domain="http://securityratty.com/tag/registry">registry</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/nmap">nmap</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/tcpip stack">tcpip stack</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/6fYkw5ozRdk/i.php">OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools</source>
    </item>
    <item>
      <title><![CDATA[OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools]]></title>
      <link>http://securityratty.com/article/3245b66a0c282a2093d5072a11bb78a8</link>
      <guid>http://securityratty.com/article/3245b66a0c282a2093d5072a11bb78a8</guid>
      <description><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could...]]></description>
      <content:encoded><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could change in Windows XP/Vista that would let you reconfigure how the TCP/IP stack works, thus changing how the above tools would detect the OS. I wasn't sure what all registry changes to make, but luckily I found Craig Heffner's work on the subject. In this post I cover the issue of passive/active OS fingerprint detection, as well as release my tool OSfuscate. ]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:15:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fingerprint">fingerprint</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/confuse tools">confuse tools</category>
      <category domain="http://securityratty.com/tag/fingerprint detection">fingerprint detection</category>
      <category domain="http://securityratty.com/tag/registry">registry</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/nmap">nmap</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/tcpip stack">tcpip stack</category>
      <source url="http://www.irongeek.com/i.php?page=security/osfuscate-change-your-windows-os-tcp-ip-fingerprint-to-confuse-p0f-networkminer-ettercap-nmap-and-other-os-detection-tools">OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools</source>
    </item>
    <item>
      <title><![CDATA[OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools]]></title>
      <link>http://securityratty.com/article/fd747c2c91a8abf71d34c17929fd4ea6</link>
      <guid>http://securityratty.com/article/fd747c2c91a8abf71d34c17929fd4ea6</guid>
      <description><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could...]]></description>
      <content:encoded><![CDATA[I was wondering awhile back how one could go about changing the OS fingerprint of a Windows box to confuse tools like Nmap, P0f, Ettercap and NetworkMiner. I knew there were registry setting you could change in Windows XP/Vista that would let you reconfigure how the TCP/IP stack works, thus changing how the above tools would detect the OS. I wasn't sure what all registry changes to make, but luckily I found Craig Heffner's work on the subject. In this post I cover the issue of passive/active OS fingerprint detection, as well as release my tool OSfuscate.
<p><a href="http://feedads.googleadservices.com/~a/03Vn2FqYJWbHI0gRYzHRUdpdTQg/a"><img src="http://feedads.googleadservices.com/~a/03Vn2FqYJWbHI0gRYzHRUdpdTQg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/CPyWOms5XYA" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:15:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fingerprint">fingerprint</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/confuse tools">confuse tools</category>
      <category domain="http://securityratty.com/tag/fingerprint detection">fingerprint detection</category>
      <category domain="http://securityratty.com/tag/registry">registry</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/nmap">nmap</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/tcpip stack">tcpip stack</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/CPyWOms5XYA/i.php">OSfuscate: Change your Windows OS TCP/IP Fingerprint to confuse P0f, NetworkMiner, Ettercap, Nmap and other OS detection tools</source>
    </item>
    <item>
      <title><![CDATA[When Psychology Meets Network Administration]]></title>
      <link>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</link>
      <guid>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</guid>
      <description><![CDATA[The library comic Unshelved has a fun strip todaywhere the new library intern announces she will reconfigure the network to correct the librarians snarky attitude. But can computer administrators...]]></description>
      <content:encoded><![CDATA[<p>The library comic Unshelved has a fun strip today&#8230;where the new library intern announces she will reconfigure the network to correct the librarian&#8217;s snarky attitude. But can computer administrators really control their users&#8217; behavior? Our fearless young librarian Dewey doesn&#8217;t seem too worried.</p>
<p><a rel="nofollow" target="_blank" href="http://www.unshelved.com/"><img class="alignnone" src="http://www.unshelved.com/strips/20080930.gif" alt="" width="600" height="210"/></a>Luckily we do have some technologies to warn users who still haven&#8217;t learned to stop opening spammy attachments, click pop up ads and so on&#8230;but I don&#8217;t think they&#8217;d help with the snarky attitude problems. I&#8217;m not sure I&#8217;d want my computer network to try doing that anyway.</p>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 11:17:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/snarky attitude">snarky attitude</category>
      <category domain="http://securityratty.com/tag/librarians snarky attitude">librarians snarky attitude</category>
      <category domain="http://securityratty.com/tag/library intern announces">library intern announces</category>
      <category domain="http://securityratty.com/tag/computer network">computer network</category>
      <category domain="http://securityratty.com/tag/fun strip todaywhere">fun strip todaywhere</category>
      <category domain="http://securityratty.com/tag/click pop">click pop</category>
      <category domain="http://securityratty.com/tag/librarian dewey">librarian dewey</category>
      <category domain="http://securityratty.com/tag/spammy attachments">spammy attachments</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/407690914/">When Psychology Meets Network Administration</source>
    </item>
    <item>
      <title><![CDATA[Best Security Tools: Free online Web utilities]]></title>
      <link>http://securityratty.com/article/d82b8f12c9176be7f58c82b0f424ba86</link>
      <guid>http://securityratty.com/article/d82b8f12c9176be7f58c82b0f424ba86</guid>
      <description><![CDATA[Have you ever needed to PING a host, run trace a Web route, or see what information you're exposing to Internet without having to reconfigure the security on your perimeter devices? Have you tired of...]]></description>
      <content:encoded><![CDATA[Have you ever needed to PING a host, run trace a Web route, or see what information you're exposing to Internet without having to reconfigure the security on your perimeter devices?  Have you tired of having to call your managed security services provider to let them know it's you creating the anomalous behavior, not an attacker?  Then maybe you should check out one of the free, online Web services providers. ]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 05:30:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security services provider">security services provider</category>
      <category domain="http://securityratty.com/tag/anomalous behavior">anomalous behavior</category>
      <category domain="http://securityratty.com/tag/perimeter devices">perimeter devices</category>
      <category domain="http://securityratty.com/tag/web route">web route</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/reconfigure">reconfigure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://blogs.ittoolbox.com/security/adventures/archives/best-security-tools-free-online-web-utilities-25555">Best Security Tools: Free online Web utilities</source>
    </item>
    <item>
      <title><![CDATA[Best Security Tools: Free online Web utilities]]></title>
      <link>http://securityratty.com/article/e740ee74768490daf30fffd1c9d6318e</link>
      <guid>http://securityratty.com/article/e740ee74768490daf30fffd1c9d6318e</guid>
      <description><![CDATA[Have you ever needed to PING a host, trace a Web route, or see what information you're exposing to the Internet without having to reconfigure the security on your perimeter devices? Have you tired of...]]></description>
      <content:encoded><![CDATA[Have you ever needed to PING a host, trace a Web route, or see what information you're exposing to the Internet without having to reconfigure the security on your perimeter devices?  Have you tired of having to call your managed security services provider to let them know it's you creating the anomalous behavior, not an attacker?  Then maybe you should check out one of the free, online Web services providers. ]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 05:30:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security services provider">security services provider</category>
      <category domain="http://securityratty.com/tag/anomalous behavior">anomalous behavior</category>
      <category domain="http://securityratty.com/tag/perimeter devices">perimeter devices</category>
      <category domain="http://securityratty.com/tag/web route">web route</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/reconfigure">reconfigure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/best-security-tools-free-online-web-utilities-25555">Best Security Tools: Free online Web utilities</source>
    </item>
    <item>
      <title><![CDATA[Crypto-Gram Tenth Anniversary Issue]]></title>
      <link>http://securityratty.com/article/5e181dd024ec7a383a883f66471cc5db</link>
      <guid>http://securityratty.com/article/5e181dd024ec7a383a883f66471cc5db</guid>
      <description><![CDATA[Ten years ago I started Crypto-Gram . It was a monthly newsletter written entirely by me. No guest columns. No advertising. Nothing but me writing about security, published the 15th of the month every...]]></description>
      <content:encoded><![CDATA[<p>Ten years ago I started <a href="http://www.schneier.com/crypto-gram.html">Crypto-Gram</a>.  It was a monthly newsletter written entirely by me.  No guest columns.  No advertising.  Nothing but me writing about security, published the 15th of the month every month.  Now, <a href="http://www.schneier.com/crypto-gram-back.html">120 issues later</a>, none of that has changed.</p>

<p>I started Crypto-Gram because I had a lot to say about security, and book-length commentaries were too slow and too infrequent.  Sure, I was writing the occasional column in the occasional magazine, but those were also too slow and infrequent.  Crypto-Gram was supposed to be my personal voice on security, sent directly to those who wanted to read it.</p>

<p>I originally thought about charging for Crypto-Gram.  I knew of several newsletters that funded themselves through subscription fees, and figured that a couple of hundred subscribers at $150 or so would sustain itself very nicely.  I don't remember why I decided not to -- did someone convince me, or did I figure it out myself -- but it was easily the smartest decision I made about this newsletter.  If I'd charged money for the thing, no one would have read it.  Since I didn't, lots of people subscribed.</p>

<p>There were 457 subscribers by the end of the first day.  After that, circulation climbed slowly and steadily.  Here are the totals for May of each year:</p>

<table cellpadding=5 cellspacing=0 border=0>
<tr><td>1999</td><td style="text-align:right">15964</td></tr>
<tr><td>2000</td><td style="text-align:right">33827</td></tr>
<tr><td>2001</td><td style="text-align:right">45832</td></tr>
<tr><td>2002</td><td style="text-align:right">58046</td></tr>
<tr><td>2003</td><td style="text-align:right">66368</td></tr>
<tr><td>2004</td><td style="text-align:right">75907</td></tr>
<tr><td>2005</td><td style="text-align:right">83835</td></tr>
<tr><td>2006</td><td style="text-align:right">87839</td></tr>
<tr><td>2007</td><td style="text-align:right">92488</td></tr>
<tr><td>2008</td><td style="text-align:right">98618</td></tr>
</table>

<p>Those numbers hide a lot of readers, like the tens of thousands that read Crypto-Gram via the Web.  I also know of people that forward my newsletter to hundreds of others.  There are many foreign translations that have their own subscription list.  These days I estimate that I have about 25,000 newsletter readers not included in those numbers.</p>

<p>I have no idea where the initial batch of subscribers came from. Nor do I remember how people subscribed before the webpage form was done.  I do remember my first big burst of subscribers, though.  It was following my special issue after 9/11.  I wrote something short for the September issue, but I found that I couldn't stop writing.  Two weeks later, I published a <a href="http://www.schneier.com/crypto-gram-0109a.html">special issue</a> on the terrorist attacks.  Readers forwarded that issue again and again, and I ended up with many new subscribers as a result.</p>

<p>Reader comments began earlier, in <a href="http://www.schneier.com/crypto-gram-9812.html">December 1998</a>.  I found I was getting some really intelligent comments from my readers -- especially those that disagreed with me -- and I wanted to publish some of them.  Some of the disagreements were nasty.  In <a href="http://www.schneier.com/crypto-gram-9810.html">October 1998</a>, I started a column called "The Doghouse," where I made fun of snake-oil security products.  Some of the companies didn't like being so characterized, and sent me threatening legal letters.</p>

<p>Turns out that <a href="http://www.schneier.com/crypto-gram-0504.html">publishing</a> those sorts of <a href="http://www.schneier.com/crypto-gram-0309.html">threats</a> as letters to Crypto-Gram was the best defense, even though my lawyers always discouraged it.  None of these incidents ever went past the threatening stage, even though court papers were occasionally filed.</p>

<p>Over the years, Crypto-Gram's focus has changed.  Initially, it was all cryptography.  Then, more computer and network security.  Then -- especially after 9/11 -- more general security: terrorism, airplanes, ID cards, voting machines, and so on.  And now, more economics and psychology of security.  My career has been a progression from the specific to the general, and Crypto-Gram has generalized to reflect that.</p>

<p>The next big change to Crypto-Gram came in October 2004.  I had been reading about blogging, and wondered for several months if switching Crypto-Gram over to blog format was a good idea or not.  Again, it was about speed and frequency.  I found that others were commenting on security stories faster, and that by the time Crypto-Gram would come out, people had already linked to other stories.  A blog would allow me to get my commentary out even faster, and to be part of the initial discussions.</p>

<p>I went back and forth.  Several people advised me to change, that blogging was the format of the future.  I was skeptical, preferring to push my newsletter into my readers' mailboxes every month.  I sent a survey to 400 of my subscribers -- 200 random subscribers and 200 people who had subscribed within the past month -- asking.  My eventual solution was the second smartest thing I did with this newsletter: to do both.</p>

<p>The Schneier on Security blog started out as Crypto-Gram entries, delivered daily.  And the <a href="http://www.schneier.com/blog/archives/2004/10/">early blog entries</a> looked a lot like Crypto-Gram articles, with links at the end.  Over the following months I learned more about the blogging style, and the entries started looking more like blog entries.  Now the blog is primary, and on the 15th of every month I take the previous month's blog entries and reconfigure them into Crypto-Gram format.  Even today, most readers prefer to receive Crypto-Gram in their e-mail box every month -- even if they also read the blog online.</p>

<p>These days, I like both.  I like the immediacy of the blog, and I like the e-mail format of Crypto-Gram.  And even after ten years, I still like the writing.</p>

<p>People often ask me where I find the time to do all of that writing.  It's an odd question for me, because it's what I enjoy doing.  I find time at home, on airplanes, in hotel rooms, everywhere.  Writing isn't a chore -- okay, maybe sometimes it is -- it's something that relaxes me.  I enjoy putting my ideas down in a coherent narrative flow.  And there's nothing that pleases me more than the fact that people read it.</p>

<p>The best fan mail I get from a reader says something like: "You changed the way I think."  That's what I want to do.  I want to change the way you think about security.  I want to change the way you think about threats, and risk, and trade-offs, about security products and services, about security rhetoric in politics.  It matters less if you agree with me or disagree, only that you're thinking differently.</p>

<p>Thank you.  Thank you on this <a href="http://www.schneier.com/crypto-gram-0805.html">10th anniversary issue</a>.  Thank you, long-time readers.  Thank you, new readers.  Thank you for continuing to read what I have to write.  This is still a lot of fun -- and interesting and thought provoking -- for me.  I hope it continues to be interesting, thought provoking, and fun for you.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=y3JAOH"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=y3JAOH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=y2H1nH"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=y2H1nH" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 15 May 2008 07:13:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crypto-gram">crypto-gram</category>
      <category domain="http://securityratty.com/tag/crypto-gram entries">crypto-gram entries</category>
      <category domain="http://securityratty.com/tag/blog online">blog online</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <category domain="http://securityratty.com/tag/snake-oil security products">snake-oil security products</category>
      <category domain="http://securityratty.com/tag/blog entries">blog entries</category>
      <category domain="http://securityratty.com/tag/crypto-gram format">crypto-gram format</category>
      <category domain="http://securityratty.com/tag/format">format</category>
      <source url="http://www.schneier.com/blog/archives/2008/05/cryptogram_tent_1.html">Crypto-Gram Tenth Anniversary Issue</source>
    </item>
  </channel>
</rss>
