<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: redundant]]></title>
    <link>http://securityratty.com/tag/redundant</link>
    <description></description>
    <pubDate>Fri, 21 Mar 2008 07:55:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Do you know who your employees are?]]></title>
      <link>http://securityratty.com/article/912fccde5dd0e4681c49ad021e6f3b01</link>
      <guid>http://securityratty.com/article/912fccde5dd0e4681c49ad021e6f3b01</guid>
      <description><![CDATA[Do you really

The Financial Times in London ran an article which illustrates the risks posed by disgruntled IT professionals. According to a recent survey, 88% of redundant IT administrators claimed...]]></description>
      <content:encoded><![CDATA[Do you really?<br /><span id="fullpost"><br />The Financial Times in London ran an article which illustrates the risks posed by disgruntled IT professionals.  According to a recent survey, 88% of redundant IT administrators claimed they would steal valuable and sensitive information from their company if they were ever fired.    <br /></span><br />A real-life example of this is the systems administrator with the Dept. of Technology who earlier this year created a password which locked officials out of the network because he feared he was losing his job.<br /><br />While it is very difficult to know if an employee is thinking this way, proper background checking and screening would likely discover if they ever did anything like this to a previous employer.<br /><br />When a termination is imminent, employers should close all of the employee's accounts and recover devices such as Blackberries, laptops, elctronic key cards and I.D.  When we are called in to assist with terminations, we always advise emloyers and supervisors of the need to do this.<br /><br />Surprisingly, many employers are not in a rush to get back laptops and other devices as they fear "upsetting" the termianted employee. If this is the case, turn over the responsibility to a professional outsourced security consultant who can take care of these duties and the company does not have to worry about being right in the "middle" of the process.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 15 Nov 2008 15:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/elctronic key cards">elctronic key cards</category>
      <category domain="http://securityratty.com/tag/recover devices">recover devices</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/risks posed">risks posed</category>
      <category domain="http://securityratty.com/tag/recent survey">recent survey</category>
      <category domain="http://securityratty.com/tag/proper background">proper background</category>
      <category domain="http://securityratty.com/tag/previous employer">previous employer</category>
      <category domain="http://securityratty.com/tag/systems administrator">systems administrator</category>
      <source url="http://www.thebulletproofblog.com/2008/11/do-you-know-who-your-employees-are.html">Do you know who your employees are?</source>
    </item>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[A tip on using ASP.NET validation controls]]></title>
      <link>http://securityratty.com/article/20fc43ecdf7ca60d64f9285d0e374a62</link>
      <guid>http://securityratty.com/article/20fc43ecdf7ca60d64f9285d0e374a62</guid>
      <description><![CDATA[Executive summary
ValidationSummary controls look at the ErrorMessage field to figure out what to display, so always use ErrorMessage in a verbose enough way that it will be helpful from a...]]></description>
      <content:encoded><![CDATA[<p>Executive summary:</p> <ul> <li>ValidationSummary controls look at the ErrorMessage field to figure out what to display, so always use ErrorMessage in a verbose enough way that it will be helpful from a ValidationSummary control.</li> <li>If you need a shorter message to display inline (i.e., where the validation control is on the form, as opposed to the ValidationSummary) use the body of the control to define it.</li></ul> <p>In the past, I&#39;ve used RequiredFieldValidator controls on my web forms to remind users that certain fields are required. I would set the ErrorMessage to something vanilla like, &quot;This field is required&quot;, or even something simpler like &quot;*&quot; (an asterisk) if I didn&#39;t have much room on the form to display more prose for an error.</p> <p>A friend was recently testing a new feature that I&#39;d built for our sales team and she had a hard time seeing the little red asterisks that were showing up next to required fields. It felt to her as though she was pushing the submit button on the form but nothing was happening. It was clear that a ValidationSummary control would be helpful, especially if placed close to the submit button for the form.</p> <p>I&#39;ve been a bit lazy in the past about using ValidationSummary controls, partially because most of my forms are simple enough that they feel a bit redundant. But on a more complicated form, they can be very helpful to guide users back to the places on the form where there&#39;s problems.</p> <p>So I threw one of those puppies on the form and immediately saw that there was a problem - my error message was set to &quot;*&quot;, which meant that my validation summary was pretty useless - it just displayed a bunch of red asterisks! And in places where I&#39;d used the prose, &quot;This field is required&quot;, well that was pretty useless as an error message in the summary.</p> <p>After a bit of research and experimentation, I discovered that the ValidationSummary control looks at the ErrorMessage property on each validation control in order to figure out what to display in the summary. So it&#39;s important to use ErrorMessage with a summary in mind! Don&#39;t use text like &quot;*&quot; or &quot;This field is required&quot;. Be more specific so the user can find her way up to the problem field, as in, &quot;PostalCode is required&quot;.</p> <p>But if you make ErrorMessage verbose so that it&#39;s helpful in a summary, it may make your form really ugly when displayed inline next to the control being validated. The trick is to use the body of the validation control element to specify the inline error message. Then you end up with two messages: a verbose one that&#39;s used in your summary, and a more localized, brief message that shows up right next to the control being validated. Note the asterisk that&#39;s in the body of the RequiredFieldValidator below:</p><pre class="csharpcode"><span class="kwrd">&lt;</span><span class="html">asp:RequiredFieldValidator</span>
      <span class="attr">ErrorMessage</span><span class="kwrd">=&quot;Zip/postal code is required&quot;</span>
      <span class="attr">ControlToValidate</span><span class="kwrd">=&#39;txtPostalCode&#39;</span>
      <span class="attr">ValidationGroup</span><span class="kwrd">=&#39;BasicInfo&#39;</span>
      <span class="attr">Display</span><span class="kwrd">=&quot;Dynamic&quot;</span>
      <span class="attr">runat</span><span class="kwrd">=&#39;server&#39;</span><span class="kwrd">&gt;</span>*<span class="kwrd">&lt;/</span><span class="html">asp:RequiredFieldValidator</span><span class="kwrd">&gt;</span></pre>
<p>I&#39;ve learned a lesson from all of this. In the future when I use validation controls I&#39;ll always provide a summary-friendly message in the ErrorMessage field, and if I need something different (typically shorter) to display inline, I&#39;ll put it in the body of the validation control element.</p>
<p>Hope this helps!</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=52816" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 13:16:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shorter message">shorter message</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/inline error message">inline error message</category>
      <category domain="http://securityratty.com/tag/validation control element">validation control element</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/inline">inline</category>
      <category domain="http://securityratty.com/tag/display inline">display inline</category>
      <category domain="http://securityratty.com/tag/errormessage">errormessage</category>
      <category domain="http://securityratty.com/tag/errormessage property">errormessage property</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/09/03/a-tip-on-using-asp-net-validation-controls.aspx">A tip on using ASP.NET validation controls</source>
    </item>
    <item>
      <title><![CDATA[Anti-theft Protocols]]></title>
      <link>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</link>
      <guid>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</guid>
      <description><![CDATA[At last Fridays Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong
Examples include
GSM mobile phones have...]]></description>
      <content:encoded><![CDATA[<p>At last Friday&#8217;s Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong.</p>
<p>Examples include:</p>
<ul>
<li>GSM mobile phones have an identifier for the phone (separate from the identifier for the user) that can be blacklisted when the phone is stolen.</li>
<li>Some car radios will stop working when the battery is disconnected, and only start working again when a numeric code is entered. This is intended to deter theft of the radio.</li>
<li>In Windows Vista, Bitlocker can be used to encrypt files. One of  the intended applications for this is that if someone steals your laptop, it will be difficult for them to gain access to your encrypted files.</li>
</ul>
<p>Ross told a story of what happened when he needed to disconnect the battery on his car: the radio stopped working, and the code he had been given to reactivate it didn&#8217;t work - it was the wrong code.<br />
Ross argues that these reactivation codes are unecessary, because other measures taken by the car manufacturers - such as making radios non-standard sizes, and hence not refittable in other car models - have made them redundant.</p>
<p>I described how the motherboard on a laptop had needed to be replaced recently. The motherboard contains the TPM chip, which contains the encryption keys needed to decrypt files protected with Bitlocker. If you replace the motherboard, the files on your hard disk will become unreadable, even if the disk is physically OK. Domain-joined Vista machines can be configured so that a sysadmin somewhere within your organization is able to recover the keys when this happens.</p>
<p>Both of these situations suffer from classic usability problems: the recovery procedures are invoked rarely (so users may not know what they&#8217;re supposed to do), and, if your system is configured incorrectly, you only find out when it is <i>too late</i>: you key in the code to your radio and it remains a doorstop; the admin you hoped was escrowing your keys turns out not to have the private key corresponding to the public key you were encrypting under (or, more subtly: the person with the authority to ask for your laptop&#8217;s key to be recovered is not you, because the appropriate admin has the <i>wrong name</i> for the laptop&#8217;s owner in their database).</p>
<p>I also described what happens when an XBox 360 is stolen. When you buy XBox downloadable content, you buy <i>two</i> licenses: one that&#8217;s valid on any XBox, as long as you&#8217;re logged in to XBox live; and one that&#8217;s valid on just your XBox, regardless of who&#8217;s logged in. If a burglar steals your Xbox, and you buy a new one, you need to get another license of the <i>second</i> type (for all the other people in your household who make use of it). The software makes this awkward, because it knows that you already have a license of the <i>first</i> type, and assumes that you couldn&#8217;t possibly want to buy it again. The work-around is to get a new email address, a new Microsoft Live Account, and a new Gamer Tag, and use these to repurchase the license. You can&#8217;t just change the gamertag, because XBox live doesn&#8217;t let the same Microsoft Live account have two gamertags. And yes, I know, your buddies in the MMORPG you were playing know you by your gamertag, so you don&#8217;t want to change it.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:18:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xbox">xbox</category>
      <category domain="http://securityratty.com/tag/xbox downloadable content">xbox downloadable content</category>
      <category domain="http://securityratty.com/tag/wrong code">wrong code</category>
      <category domain="http://securityratty.com/tag/xbox live">xbox live</category>
      <category domain="http://securityratty.com/tag/wrong">wrong</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/car radios">car radios</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/microsoft live account">microsoft live account</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/03/anti-theft-protocols/">Anti-theft Protocols</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Sergey Katsev of Coyote Point Systems]]></title>
      <link>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</link>
      <guid>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</guid>
      <description><![CDATA[I recently had the opportunity to sit down with Sergey Katsev , an Engineering Project Manager at Coyote Point Systems and discuss his experiences with InteropNet and talk about the Coyote Point...]]></description>
      <content:encoded><![CDATA[<p>I recently had the opportunity to sit down with <a href="http://www.facebook.com/profile.php?id=24405331" target="_blank">Sergey Katsev</a>, an Engineering Project Manager at <a href="http://coyotepoint.com/" target="_blank">Coyote Point Systems</a> and discuss his experiences with InteropNet and talk about the Coyote Point products.  With a couple of years of experience as a vendor for Interop, he had some interesting insights in to how participating in the InteropNet can help a vendor.</p>
<p><strong>ScienceLogic:</strong> How long have you been involved in InteropNet?</p>
<p><strong>Katsev: </strong>I started at Coyote Point 3 years ago and <a href="http://blog.interop.com/2006" target="_blank">InteropNet 2006</a> was my first &#8220;big&#8221; assignment.  This was the first time Coyote Point had put in a proposal to participate, so we were very excited when we were selected.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic: </strong>How long has Coyote Point been involved in Interop overall?</p>
<p><strong>Katsev: </strong>We&#8217;ve been exhibiting at Interop for a number of years, and after seeing the InteropNet in action, we decided to submit a proposal in &#8216;06.  We were actually one of the first companies in the load balancing/traffic management space (we&#8217;ve been doing this for almost 10 years), so we have a lot of experience to share with InteropNet.</p>
<p><strong>ScienceLogic:</strong> What is your role at Coyote Point?</p>
<p>My official title is &#8220;Engineering Project Manager&#8221;.  Basically, that means that I&#8217;m in charge of product releases and maintenance.  It sounds like a weird title for someone participating in InteropNet, but I&#8217;ve actually found it extremely useful since my position means that I don&#8217;t get to see our systems out in the field a lot.  We&#8217;ve added several features and have ideas for others just from my experiences at InteropNet.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic:</strong> What do the Coyote Point products do?</p>
<p><strong>Katsev: </strong>Coyote Point makes a Traffic Management appliance called <a href="http://coyotepoint.com/products/e650.php" target="_blank">Equalizer</a>.  What this means is that any traffic destined for a datacenter&#8217;s servers goes through our appliances and we make sure that the server which is best equipped to handle it, does.  Our systems sit between the clients and the servers and monitor the client traffic and the state of the servers.  If the clients start sending more traffic, we&#8217;ll balance it out so that no server is overloaded.  If one of the servers stops responding or starts responding very slowly, we&#8217;ll steer traffic away from that server.</p>
<p><strong>ScienceLogic: </strong>In what way are your products being used as part of InteropNet?</p>
<p><strong>Katsev: </strong>In the InteropNet, we&#8217;re utilizing a lot of our expertise:  We&#8217;re making sure that traffic is balanced and servers are redundant for show services such as DNS and SMTP.  We&#8217;re also using our geographic load balancing technology to ensure that the ScienceLogic EM7 appliances and some other internal NOC services are available from anywhere, with the lowest latency, with our <a href="http://www.coyotepoint.com/products/xcel.php" target="_blank">SSL acceleration </a>and <a href="http://www.coyotepoint.com/products/express.php" target="_blank">GZIP compression technology</a>.  Finally, we&#8217;re helping logistics in the NOC by allowing a physical separation between systems <a href="http://blog.interop.com/interopnet/2008/04/what-are-these-peds-you-speak-of" target="_blank">located in the NOC</a> and those in an emergency rack outside of the NOC.  If either of these two locations were to fail, the network will continue operating without a glitch.</p>
<p><strong>ScienceLogic:</strong> Are there any special considerations for Interop that cause you to deploy your systems there differently that any other place?</p>
<p><strong>Katsev: </strong>Interop is definitely different than most of our customer installations.   One difference from a standard environment is that the network (at least this year) is one large flat network, with pieces carved out where extra security is needed.  Because of this, we can actually run our failover pairs of Equalizer systems in a non-standard configuration where the two peers are in different racks, or even on different floors.  That&#8217;s one of the things that I really like about InteropNet &#8212; it definitely brings new ideas to mind, which end up becoming &#8217;special configuration&#8217; white papers after the show.</p>
<p><strong>ScienceLogic:</strong> Has InteropNet taught you anything that caused you to actually change your product?</p>
<p><strong>Katsev: </strong>In addition to the failover configuration differences I mentioned above, participating in InteropNet has actually caused us to add several new features and allowed configurations.  One example is the &#8220;no-spoof&#8221; option for <a href="http://www.springerlink.com/content/dcmmpmb53rjp5hr8/" target="_blank">Layer 4 clusters</a>.  Prior to the 2006 shows, we always &#8217;spoofed&#8217; the client&#8217;s IP address when talking to a server so that the server would see the client&#8217;s IP address instead of our own.  At Interop, we ran into a special configuration which would&#8217;ve been very difficult to set up in this manner, so our engineers added this feature, and it&#8217;s been very a very popular configuration with our customers ever since.</p>
<p>We have also had a couple of business relationships that extended outside of the show.  In 2006, we had a good experience using <a href="http://www.spirent.com/analysis/index.cfm?media=3&amp;ws=2" target="_blank">Spirent Communications</a> gear to benchmark the network, so we ended up purchasing a couple of these systems to test our products.  More recently, we have found a way to bundle our Equalizer e350si load balancers with the ScienceLogic <a href="http://www.sciencelogic.com/techdiagram.htm" target="_blank">EM7 collector appliances</a> to help ScienceLogic get the best performance in load balancing large quantities of syslog messages to be processed.  If it wasn&#8217;t for our participation in InteropNet, neither of these relationships would&#8217;ve happened.</p>
<p><strong>ScienceLogic: </strong>What’s the best part of being involved with InteropNet?  What do you most look forward to?</p>
<p><strong>Katsev: </strong>InteropNet is an amazing networking opportunity (no pun intended).  The group of engineers that put the network together every year is, well, amazing.  There is so much combined experience that any question instantly has several possible answers, and the best answer is chosen very quickly.  One of the &#8217;sayings&#8217; at Interop is &#8220;if you run into a problem, ask someone&#8230; we&#8217;ve probably seen that problem before&#8230; five times.&#8221;  One would think that being part of InteropNet is the same thing, year after year.  However, in the two years that I&#8217;ve been part of this (for four shows), there have been huge differences in the way that the network is designed and put together.  These are both because the vendors selected every year are different, and because the engineers who design the network change from year to year.  Somehow, though, when all is said and done, we have a <a href="http://blog.sciencelogic.com/interop-las-vegas-2008-some-interesting-stats/06/2008" target="_blank">network that works</a>.</p>
<p><strong>ScienceLogic:</strong> You don’t have to answer this one if you’re not comfortable… What would you like to see changed with the way things are done at InteropNet?</p>
<p><strong>Katsev: </strong>This isn&#8217;t a cop-out&#8230; I really can&#8217;t think of anything I would do differently.  Sure, there are small problems that pop up sometimes, but every project has those, and the people at InteropNet are more than capable of figuring them all out.  In fact, I know that Interop started out as a show to test the interoperability of devices&#8230; but I&#8217;m still amazed that all of these devices actually talk to each other and <a href="http://blog.sciencelogic.com/qa-with-geoff-horne-of-interopnet/06/2008" target="_blank">&#8220;play nice&#8221; together</a>.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26%23038%3BA+with+Sergey+Katsev+of+Coyote+Point+Systems&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-sergey-katsev-of-coyote-point-systems%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 12:34:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/katsev">katsev</category>
      <category domain="http://securityratty.com/tag/sergey katsev">sergey katsev</category>
      <category domain="http://securityratty.com/tag/interopnet">interopnet</category>
      <category domain="http://securityratty.com/tag/coyote">coyote</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/sciencelogic em7 appliances">sciencelogic em7 appliances</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/client traffic">client traffic</category>
      <source url="http://blog.sciencelogic.com/qa-with-sergey-katsev-of-coyote-point-systems/08/2008">Q&amp;A with Sergey Katsev of Coyote Point Systems</source>
    </item>
    <item>
      <title><![CDATA[Interop NY 2008 Hot Stage: A Tale of Two Cities]]></title>
      <link>http://securityratty.com/article/47273ded1435f902f1bd70d7c7bf36fc</link>
      <guid>http://securityratty.com/article/47273ded1435f902f1bd70d7c7bf36fc</guid>
      <description><![CDATA[For the past week Ive been in Freemont California (outside San Jose) with the InteropNet Team getting the network back up after Vegas so that its ready for New York. This Hot Stage has been...]]></description>
      <content:encoded><![CDATA[<p class="MsoNormal">For the past week I’ve been in Freemont California (outside San Jose) with the InteropNet Team getting the network back up after Vegas so that it’s ready for New York.<span> </span>This Hot Stage has been interesting because it really has been about the difference in the shows in Las Vegas and New York.<span> </span>The show in New York is a bit smaller, but because access to the venue (Javitz Center) is more restrictive than the access the team gets in Vegas (<a href="http://www.mandalaybay.com/Conventions/" target="_blank">Mandalay Bay</a>), things need to be done differently.<span> </span></p>
<p class="MsoNormal">The big difference between the two cities is the amount of time that the InteropNet team gets to produce a live, fully operational and redundant network.<span> </span>In Las Vegas, this was nearly a full week of time - a tight timeframe across 17 different vendors, but now we&#8217;re looking back at that timeframe as a luxury. In NY, we’ll be getting started Saturday morning, and the network needs to be delivered on Sunday morning for the registration desk and exhibitor move-in to begin.<span> </span>If you’re keeping score, that’s about <strong>24 hours to deliver a working network</strong>. Sounds hard, but it’s even harder when you consider that this means four DS-3s from two different locations, 17 full and 7 half racks of network gear, all the fiber and copper that the network is delivered over, etc all have to get done.<span> Good thing that with 2 and 3/4 kids, </span>I’m not planning on much sleep, and I don’t think the rest of the team is either.<span> </span></p>
<p class="MsoNormal">
<p class="MsoNormal">In order to try and get the network delivered in that short timeframe, we worked hard at Hot Stage to assure that everything is ready to go.<span> </span>With some luck, the work that we’ve done here will allow us simply to roll the network gear into place, run the cables, fire up and go.<span> </span></p>
<p class="MsoNormal">Now, things never really work out that way but that’s what EM7 is going to be there for.<span> </span>We’ll watch in real time as the network elements come live and be able to let the other <a href="http://interop.com/newyork/event-highlights/interopnet/sponsors.php" target="_blank">InteropNet vendors</a> know if their gear isn’t behaving<span> </span>as expected or is not visible for all the areas of the network that it should<span> </span>be.<span> We&#8217;ll keep track of all of this in the EM7 ticketing system so that after the show we&#8217;ll be able to analyze the behavior of the network and systems <a href="http://blog.sciencelogic.com/interop-las-vegas-2008-some-interesting-stats/06/2008" target="_blank">as we did after Vegas</a>. </span></p>
<p class="MsoNormal">
<p class="MsoNormal">I&#8217;m looking forward to the show and once again working with some of the top engineers in the country on a complex and rapidly deployed network.  Speaking of which, we&#8217;re still looking for <a href="http://www.networkworld.com/news/2007/052207-interop-networking-religion.html" target="_blank">volunteers</a> to help in the NOC.  Volunteers get to work with some really smart people, get an education that would be hard to get anywhere else, and get a trip to NY <a href="http://www.interop.com/newyork/event-highlights/interopnet/volunteers2.php" target="_blank">where your expenses</a> (for things like hotel accommodations and food provided by the show) are taken care of.  Sound interesting?  Be sure and check out <a href="http://www.networkops.net/vrms/" target="_blank">the application.</a></p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Interop+NY+2008+Hot+Stage%3A+A+Tale+of+Two+Cities&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Finterop-ny-2008-hot-stage-a-tale-of-two-cities%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 18:01:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/redundant network">redundant network</category>
      <category domain="http://securityratty.com/tag/network gear">network gear</category>
      <category domain="http://securityratty.com/tag/gear">gear</category>
      <category domain="http://securityratty.com/tag/network elements">network elements</category>
      <category domain="http://securityratty.com/tag/hot stage">hot stage</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interopnet team">interopnet team</category>
      <source url="http://blog.sciencelogic.com/interop-ny-2008-hot-stage-a-tale-of-two-cities/07/2008">Interop NY 2008 Hot Stage: A Tale of Two Cities</source>
    </item>
    <item>
      <title><![CDATA[Stealing Password Hashes with Java and IE]]></title>
      <link>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</link>
      <guid>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</guid>
      <description><![CDATA[OK, I read a lot, I mean a lot on a regular basis. There is a lot of tripe floating about the tubes of the internet and Im always pleased to read a new posting from several folks who buck that trend....]]></description>
      <content:encoded><![CDATA[<p>OK, I read a lot, I mean <b>a lot</b> on a regular basis. There is a lot of tripe floating about the tubes of the internet and I&#8217;m always pleased to read a new posting from several folks who buck that trend. Among which I count John Heasman. He has a great new post on his site about stealing password hashes with Java and Internet Exploder.</p>
<p>From Aut Disce, Aut Discede:</p>
<blockquote><p>Consider for a moment the state of client-side bugs 5 or 6 years ago. Attacks such as this, a multi-stage miscellany of IE and Mediaplayer bugs that resulted in the &#8220;silent delivery and installation of an executable on the target computer, no client input other than viewing a web page&#8221; were reported with regularity. Gradually these type of attack gave way to exploitation of direct browser implementation flaws such as the IFRAME overflow and DHTML memory corruption flaws. So what has become of the multi-stage attacks - have they become redundant? The answer to this, which I&#8217;m sure you can guess, is a resounding &#8220;no&#8221; and will be emphatically demonstrated in my upcoming Black Hat talk &#8220;The Internet is Broken: Beyond Document.Cookie - Extreme Client Side Exploitation&#8221;, a joint double session presentation co-presented by Billy Rios, Nate McFeters and Rob Carter.</p>
<p>As a teaser for that, I&#8217;m going to revisit an old attack - pre-computed dictionary attacks on NTLM - and discuss how we can steal domain credentials from the Internet with a bit of help from Java. I&#8217;m going to split it into two posts. In this post we&#8217;ll apply the attack to Windows XP (a fully patched SP3 with IE7). In my next post we&#8217;ll consider its impact on Windows Vista.</p></blockquote>
<p>For the full article read on.</p>
<p>Why are you still here? Go read it. </p>
<p> <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://heasman.blogspot.com/2008/06/stealing-password-hashes-with-java-and.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=kFHS3D"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=kFHS3D" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=jii6HI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=jii6HI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=fcDSai"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=fcDSai" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=h9BNei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=h9BNei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=zcteYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=zcteYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=1UYjFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=1UYjFi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/307957636" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 07:34:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/internet exploder">internet exploder</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/dictionary attacks">dictionary attacks</category>
      <category domain="http://securityratty.com/tag/password hashes">password hashes</category>
      <category domain="http://securityratty.com/tag/java">java</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/307957636/">Stealing Password Hashes with Java and IE</source>
    </item>
    <item>
      <title><![CDATA[The Dynamics of Counting and Recounting Votes]]></title>
      <link>http://securityratty.com/article/8dd226f9138864bb898f8476430281b3</link>
      <guid>http://securityratty.com/article/8dd226f9138864bb898f8476430281b3</guid>
      <description><![CDATA[The limitations of current paper- and electronic-based voting systems and recount procedures can undermine the credibility of public elections. A corroborative, redundant voting system that performs...]]></description>
      <content:encoded><![CDATA[The limitations of current paper- and electronic-based voting systems and recount procedures can undermine the credibility of public elections. A corroborative, redundant voting system that performs vote counts via independent mechanisms at the polling place could address these shortcomings.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5b38ecf8a8de6257a28a3e0536bfd1b9" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5b38ecf8a8de6257a28a3e0536bfd1b9" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 10:32:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/performs vote counts">performs vote counts</category>
      <category domain="http://securityratty.com/tag/independent mechanisms">independent mechanisms</category>
      <category domain="http://securityratty.com/tag/recount procedures">recount procedures</category>
      <category domain="http://securityratty.com/tag/current paper-">current paper-</category>
      <category domain="http://securityratty.com/tag/public elections">public elections</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/limitations">limitations</category>
      <category domain="http://securityratty.com/tag/shortcomings">shortcomings</category>
      <category domain="http://securityratty.com/tag/credibility">credibility</category>
      <source url="http://www.pheedo.com/click.phdo?i=5b38ecf8a8de6257a28a3e0536bfd1b9">The Dynamics of Counting and Recounting Votes</source>
    </item>
    <item>
      <title><![CDATA[The Real "Security 2.0"?]]></title>
      <link>http://securityratty.com/article/bacd88d359bef5faad5d771a70263a69</link>
      <guid>http://securityratty.com/article/bacd88d359bef5faad5d771a70263a69</guid>
      <description><![CDATA[Yes! YES! Y-E-S! You guessed right - a blogging frenzy; I am baaack from my vacation/speaking in first cold then warm places and I have a &quot;backblog&quot; of fun items

First is &quot; Why Hacking Changed &quot; from...]]></description>
      <content:encoded><![CDATA[Yes! YES! Y-E-S! You guessed right - a blogging frenzy; I am baaack from my vacation/speaking in first cold then warm places and I have a "backblog" of fun items.<br /><br />First is "<a href="http://www.0x000000.com/?i=536">Why Hacking Changed</a>" from <a href="http://www.0x000000.com">The Hacker Webzine</a>. Please read it; and see thru all the drama.<br /><br />Some quotes:<br /><br />"Old school hacking is dead, network hacking is dead, firewalls are useless and AV software is a mere redundant software package that underlines your frustration and ignorance about contemporary hacking."<br /><br />"If you can define hacking today, it no longer means telnetting into servers or blowing whistles, but exploiting the application layer. With the application layer, I also mean the scripting language beneath it, since it interacts with the applications that it's running and share memory, and thereby the hardware it's running on."<br /><br />and<br /><br />"We can even prove that we can own your network with only seven characters typed into your query string: 1' OR 1=1 is far more dangerous than any shellcode I've ever seen in my life."<br /><br />"What works today works also tomorrow. And what will work in two or 5 years from now is software and application hacking."<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uhMZOIG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uhMZOIG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=28tJsXG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=28tJsXG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/263523198" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 08:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application layer">application layer</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/share memory">share memory</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/characters typed">characters typed</category>
      <category domain="http://securityratty.com/tag/hacker webzine">hacker webzine</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/language beneath">language beneath</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/263523198/real-security-20.html">The Real "Security 2.0"?</source>
    </item>
    <item>
      <title><![CDATA[Security outsourcing: The debate continues]]></title>
      <link>http://securityratty.com/article/67ef58fb256b6103c3767669e94f1f2c</link>
      <guid>http://securityratty.com/article/67ef58fb256b6103c3767669e94f1f2c</guid>
      <description><![CDATA[I've weighed in for this debate in the past, and my views haven't changed. Security outsourcing is a good idea for redundant, time-consuming tasks. It doesn't make sense to outsource activities...]]></description>
      <content:encoded><![CDATA[I've weighed in for this debate in the past, and my views haven't changed.  Security outsourcing is a good idea for redundant, time-consuming tasks.  It doesn't make sense to outsource activities requiring deep understanding of internal technology and the business processes they support.]]></content:encoded>
      <pubDate>Fri, 21 Mar 2008 07:55:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/outsource activities">outsource activities</category>
      <category domain="http://securityratty.com/tag/business processes">business processes</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/internal technology">internal technology</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/deep">deep</category>
      <category domain="http://securityratty.com/tag/tasks">tasks</category>
      <category domain="http://securityratty.com/tag/views">views</category>
      <category domain="http://securityratty.com/tag/redundant">redundant</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://blogs.ittoolbox.com/security/adventures/archives/security-outsourcing-the-debate-continues-23221">Security outsourcing: The debate continues</source>
    </item>
  </channel>
</rss>
