<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: shortcut]]></title>
    <link>http://securityratty.com/tag/shortcut</link>
    <description></description>
    <pubDate>Fri, 14 Mar 2008 07:39:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Used your CCleaner lately?]]></title>
      <link>http://securityratty.com/article/757d7505f67debca656ad5270d6b0308</link>
      <guid>http://securityratty.com/article/757d7505f67debca656ad5270d6b0308</guid>
      <description><![CDATA[Great way to insure a lil extra security besides the AntiVirus and AntiSpyware thats running on your puter


clipped from www.howtogeek.com
Setup CCleaner to Automatically Run Each Night in Vista or...]]></description>
      <content:encoded><![CDATA[<div > Great way to insure a lil extra security besides the AntiVirus and AntiSpyware thats running on your puter. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/D14589A6-D443-4D15-809D-5DFF880FDE5F/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e96a1d38-acb3-46b0-aa77-671ab02c34eb/D14589A6-D443-4D15-809D-5DFF880FDE5F/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/" href="http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/" style="font-size: 11px;">www.howtogeek.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/ --><H2><A title="Permanent Link: Setup CCleaner to Automatically Run Each Night in Vista or XP" rel="bookmark" href="http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/">Setup CCleaner to Automatically Run Each Night in Vista or XP</A></H2></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/D14589A6-D443-4D15-809D-5DFF880FDE5F/" title="go to this clipmark"><img src="http://content7.clipmarks.com/images/clip-icon.gif" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/" href="http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/" style="font-size: 11px;">www.howtogeek.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.howtogeek.com/howto/windows-vista/setup-ccleaner-to-automatically-run-each-night-in-vista-or-xp/ --><P>After writing the article yesterday about how to run <A href="http://www.howtogeek.com/howto/windows-vista/create-a-shortcut-or-hotkey-to-run-ccleaner-silently/">CCleaner silently through a shortcut or a hotkey</A>, many people expressed to me that they&#8217;d like to know how to run it every single night on a schedule, so I&#8217;m writing that up for everybody&#8217;s benefit.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/D14589A6-D443-4D15-809D-5DFF880FDE5F/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Sat, 26 Jul 2008 11:59:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lil extra security">lil extra security</category>
      <category domain="http://securityratty.com/tag/night">night</category>
      <category domain="http://securityratty.com/tag/single night">single night</category>
      <category domain="http://securityratty.com/tag/everybodys benefit">everybodys benefit</category>
      <category domain="http://securityratty.com/tag/article yesterday">article yesterday</category>
      <category domain="http://securityratty.com/tag/ccleaner silently">ccleaner silently</category>
      <category domain="http://securityratty.com/tag/setup ccleaner">setup ccleaner</category>
      <category domain="http://securityratty.com/tag/howtogeek">howtogeek</category>
      <category domain="http://securityratty.com/tag/antispyware">antispyware</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=520">Used your CCleaner lately?</source>
    </item>
    <item>
      <title><![CDATA[Windows Admin Goodies From Microsoft]]></title>
      <link>http://securityratty.com/article/8b99cbff598abd26fee789464d831e4b</link>
      <guid>http://securityratty.com/article/8b99cbff598abd26fee789464d831e4b</guid>
      <description><![CDATA[Microsoft has released a couple of handy items for Windows administrators. Neither are really big deals, but conveniences. We all use Microsoft's Sysinternals tools, written by Mark Russinovich and...]]></description>
      <content:encoded><![CDATA[Microsoft has released a couple of handy items for Windows administrators. Neither are really big deals, but conveniences.

We all use Microsoft's Sysinternals tools, written by Mark Russinovich and Bryce Cogswell, but it's been a minor pain keeping up with all the updates they put out and installing them. Now, if you don't want to, you don't have to bother: You can get the tools live off the web and run them directly rather than going through the obfuscatory Microsoft Download Center and then having to unzip a file or run an installer..

Go to the <a href="http://live.sysinternals.com/">Sysinternals Live</a> web page. You'll see a directory listing of the current files in the Sysinternals set. For instance, the current version of Process Explorer is <a href="http://live.sysinternals.com/procexp.exe">http://live.sysinternals.com/procexp.exe</a>. In IE you can choose to run directly from the browser, but you can also create shortcuts on the desktop or in the Start Menu system to these files, and every time you run that shortcut you'll be running the current version. You do need to go through some confirmations, agreeing to the license, etc.

The second trick is the <a href="http://technet.microsoft.com/en-us/magazine/cc510320.aspx">Elevation PowerToys for Windows Vista</a>. These expand the Windows RunAs functionality to some popular 3rd party admin tools, like <a href="http://www.kixtart.org/">KiXtart</a> and <a href="http://www.activestate.com/">ActivePerl</a>. Some examples combine it with the Elevate power tool to allow you to do RunAs for programs, like the MMC, which are often resistant to RunAs. There is also a PowerToy for running a CMD shell or PowerShell as the SYSTEM account.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=f5cac60dc8ac15cdcc6f3a85b2e063a1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f5cac60dc8ac15cdcc6f3a85b2e063a1"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=f5cac60dc8ac15cdcc6f3a85b2e063a1" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/303267596" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 14:03:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sysinternals set">sysinternals set</category>
      <category domain="http://securityratty.com/tag/windows runas functionality">windows runas functionality</category>
      <category domain="http://securityratty.com/tag/runas">runas</category>
      <category domain="http://securityratty.com/tag/sysinternals">sysinternals</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/current version">current version</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/current files">current files</category>
      <category domain="http://securityratty.com/tag/sysinternals tools">sysinternals tools</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/303267596/windows_admin_goodies_from_microsoft.html">Windows Admin Goodies From Microsoft</source>
    </item>
    <item>
      <title><![CDATA[Windows Admin Goodies from Microsoft]]></title>
      <link>http://securityratty.com/article/fb03a5be7a319bcb264ae433443bee91</link>
      <guid>http://securityratty.com/article/fb03a5be7a319bcb264ae433443bee91</guid>
      <description><![CDATA[Microsoft has released a couple of handy items for Windows administrators. Neither are really big deals, but conveniences. We all use Microsoft's Sysinternals tools, written by Mark Russinovich and...]]></description>
      <content:encoded><![CDATA[Microsoft has released a couple of handy items for Windows administrators. Neither are really big deals, but conveniences.

We all use Microsoft's Sysinternals tools, written by Mark Russinovich and Bryce Cogswell, but it's been a minor pain keeping up with and installing all the updates they put out. Now, if you don't want to, you don't have to bother: You can get the tools live off the Web and run them directly rather than going through the obfuscatory Microsoft Download Center and then having to unzip a file or run an installer..

Go to the <a href="http://live.sysinternals.com/">Sysinternals Live</a> Web page. You'll see a directory listing of the current files in the Sysinternals set. For instance, the current version of Process Explorer is <a href="http://live.sysinternals.com/procexp.exe">http://live.sysinternals.com/procexp.exe</a>. In IE you can choose to run directly from the browser, but you can also create shortcuts on the desktop or in the Start Menu system to these files, and every time you run that shortcut you'll be running the current version. You do need to go through some confirmations, agreeing to the license, etc.

The second trick is the <a href="http://technet.microsoft.com/en-us/magazine/cc510320.aspx">Elevation PowerToys for Windows Vista</a>. These expand the Windows RunAs functionality to some popular third-party admin tools, like <a href="http://www.kixtart.org/">KiXtart</a> and <a href="http://www.activestate.com/">ActivePerl</a>. Some examples combine it with the Elevate power tool to allow you to do RunAs for programs, like the MMC, which are often resistant to RunAs. There is also a PowerToy for running a CMD shell or PowerShell as the SYSTEM account.
<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=27fe589803270528afec91b45b3a3d7a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=27fe589803270528afec91b45b3a3d7a" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/338277696" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 14:03:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sysinternals set">sysinternals set</category>
      <category domain="http://securityratty.com/tag/windows runas functionality">windows runas functionality</category>
      <category domain="http://securityratty.com/tag/runas">runas</category>
      <category domain="http://securityratty.com/tag/sysinternals">sysinternals</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/current version">current version</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/current files">current files</category>
      <category domain="http://securityratty.com/tag/sysinternals tools">sysinternals tools</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/338277696/windows_admin_goodies_from_microsoft.html">Windows Admin Goodies from Microsoft</source>
    </item>
    <item>
      <title><![CDATA[Stolen University Health Care laptop requires notification of 4800]]></title>
      <link>http://securityratty.com/article/e9555f16d1d087d7b85993176f2956f2</link>
      <guid>http://securityratty.com/article/e9555f16d1d087d7b85993176f2956f2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/13/08

Organization
University of Utah

Contractor/Consultant/Branch
University Health Care

Victims
patients

Number Affected
4,800

Types of Data...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/uhc.jpg" align="right" height="49" width="201"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/13/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.utah.edu/portal/site/uuhome/">University of Utah</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://healthcare.utah.edu/index.cfm">University Health Care</a><br><br><span style="font-weight: bold;">Victims:</span><br>patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>4,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, social security numbers and personal health information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Possibly 4,800 patient’s information could be compromised, when a laptop with names, social security numbers and personal health information was stolen from University Healthcare"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.kutv.com/content/news/topnews/story.aspx?content_id=5843cde8-1fb5-4945-b396-df5b682ddbb4">KUTV Channel 2 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>KUTV Channel 2<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>Possibly 4,800 patient’s information could be compromised, when a laptop with names, social security numbers and personal health information was stolen from University Healthcare over two weeks ago.&nbsp; <br><br>The hospital says that someone broke into a locked office and took a lap top and a flash drive.<br><br>The hospital does not believe that whoever stole the laptop was searching for the patient’s information.<br><span style="font-style: italic;">[Evan] What leads the hospital to believe this?&nbsp; There's no money in selling or using compromised confidential information, right?&nbsp; WRONG!</span><br><br>The hospital also says that the laptop is password protected and it is confident that the person who stole the laptop will not be able to access the information.<br><span style="font-style: italic;">[Evan] Seriously, remarks like this demonstrate complete information security incompetence.</span><br><br>The information on the laptop is varies for patients. Not all patients have social security numbers listed with the hospital.<br><br>University Healthcare began mailing out letters to people affected by the theft this week<br><br>The University Healthcare is trying to figure out which patients had information on that computer and what the information was. The hospital says that this process caused the notification delay.<br><span style="font-style: italic;">[Evan] Not knowing what confidential information is where is a very common problem in today's organizations.</span><br><br>University Healthcare is providing the 4800 patients with a year of free credit monitoring and is making changes in their policy.<br><span style="font-style: italic;">[Evan] I feel like doing some math.&nbsp; The cost for full disk laptop encryption, maybe $100 - 150.&nbsp; The cost for investigation of the breach (say 20 hours @ $100/hr.), reconstruction (say 20 hours @ $100/hr.), notification ($300 to draft letter and maybe $2,400 to address and mail), and credit monitoring ($15/mo. x 12 months x 4800 customers) might cost $870,000.&nbsp; Maybe the hospital didn't believe they would ever lose a laptop or have one stolen that contained sensitive information.&nbsp; Risk management anyone?!</span><br><br>Employees will no longer be allowed to download sensitive information onto laptops, even if they're password protected.<br><span style="font-style: italic;">[Evan] This is not the root of the problem.&nbsp; We have an information security governance and management problem.&nbsp; No easy fix. </span><br><br>University Healthcare apologizes for the problem and the notification delay.<br><br><span style="font-weight: bold;">Commentary:</span><br>It's Friday!&nbsp; I have some time on my hands, and I am getting tired of poor security of personal information.&nbsp; I go through phases.<br><br>One thing that is worth mentioning, we (meaning information security personnel) must go through the arduous task of data inventory and classification if we are to be effective.&nbsp; We should know what confidential information we create, collect, store, transfer, and/or destroy.&nbsp; We need to know where confidential information is throughout the lifecycle.&nbsp; We need to know what the threats are.&nbsp; We need to know what the vulnerabilities are.&nbsp; We need to know what the risks are.&nbsp; We need to know the costs of compromise (hard and soft dollars) when possible.&nbsp; We need to know the costs of protection.&nbsp; Maybe most importantly, we need to measure all of our efforts against the organizational goals and objectives.&nbsp; The list goes on and on and on.<br><br>If you are charged with securing your company's information assets, you need to understand that this is a serious business and not for the faint of heart.&nbsp; We don't just password protect and install firewalls for a living.&nbsp; We solve complex technical and political problems every day.&nbsp; If you need additional training (we all do) then get it.&nbsp; Don't look for shortcuts, because there aren't any.&nbsp; The dichotomy is that most effective solutions are simple and not complex.&nbsp; Simple sometimes gets confused with shortcut, but a shortcut is lazy.&nbsp; The money is good, but the challenges are GREAT.<br><br>OK, I've rambled enough.&nbsp; I'm stepping down from the podium now.&nbsp; Thanks for reading! <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/14/uhc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 14 Mar 2008 07:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information assets">information assets</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/patients information">patients information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/information security personnel">information security personnel</category>
      <source url="http://breachblog.com/2008/03/14/uhc.aspx">Stolen University Health Care laptop requires notification of 4800</source>
    </item>
  </channel>
</rss>
