<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Basics</title>
    <link>http://seclists.org/#basics</link>
    <atom:link href="http://seclists.org/rss/basics.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
    <pubDate>Wed, 10 Mar 2010 22:45:17 GMT</pubDate>
    <lastBuildDate>Wed, 10 Mar 2010 22:45:17 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Reporting SSH abuse</title>
    <link>http://seclists.org/basics/2010/Mar/49</link>
    <description>&lt;p&gt;Posted by James Bensley on Mar 10&lt;/p&gt;I find in these situations, who is it you should actually tell? In the&lt;br&gt;
your case were the traffic is coming from a University I'm sure the&lt;br&gt;
Uni tech team would appreciated knowing but I have had it from some IP&lt;br&gt;
in Brazil, I never reported it because I couldn't think who would give&lt;br&gt;
a damn?&lt;br&gt;</description>
    <pubDate>Wed, 10 Mar 2010 22:35:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/49</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/48</link>
    <description>&lt;p&gt;Posted by Dave LaDuke on Mar 10&lt;/p&gt;Thanks for telling him, I had planned to have some fun later.&lt;br&gt;
&lt;br&gt;
--------------------------------------------------&lt;br&gt;
From: &amp;quot;Curt Shaffer&amp;quot; &amp;lt;cshaffer () gmail com&amp;gt;&lt;br&gt;
Sent: Tuesday, March 09, 2010 1:49 AM&lt;br&gt;
To: &amp;lt;mzcohen2682 () aim com&amp;gt;&lt;br&gt;
Cc: &amp;lt;security-basics () securityfocus com&amp;gt;&lt;br&gt;
Subject: Re: Help hardening router&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte...&lt;br&gt;</description>
    <pubDate>Wed, 10 Mar 2010 21:49:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/48</guid>
  </item>
  <item>
    <title>RE: Reporting SSH abuse</title>
    <link>http://seclists.org/basics/2010/Mar/47</link>
    <description>&lt;p&gt;Posted by Dan Lynch on Mar 10&lt;/p&gt;I could swear I once read an &amp;quot;authoritative&amp;quot; source doc on this subject, maybe an RFC (Site Security Handbook?), or &lt;br&gt;
something from CERT. But I can't seem to dig it up. Anyone?&lt;br&gt;
&lt;br&gt;
Here's what I did find:&lt;br&gt;
&lt;br&gt;
Going to the Source: Reporting Security Incidents to ISPs (2002)&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.securityfocus.com/infocus/1555&quot;&gt;http://www.securityfocus.com/infocus/1555&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
And a most-excellent write up &amp;quot;Composing abuse reports&amp;quot; (2007)&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://blog.anta.net/2007/04/18/composing-abuse-reports/&quot;&gt;http://blog.anta.net/2007/04/18/composing-abuse-reports/&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Wed, 10 Mar 2010 21:43:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/47</guid>
  </item>
  <item>
    <title>Re: Reporting SSH abuse</title>
    <link>http://seclists.org/basics/2010/Mar/46</link>
    <description>&lt;p&gt;Posted by Liquid on Mar 10&lt;/p&gt;Dan Pilcheck wrote:&lt;br&gt;
&lt;br&gt;
Dan,&lt;br&gt;
&lt;br&gt;
Honestly thats more than enough. I've had client sites that were doing &lt;br&gt;
the same and the notifications were more than ample to at least look &lt;br&gt;
into it. A nice note to the person should work, we had a couple in the &lt;br&gt;
past where the admin was a complete jerk in letting us know. So &lt;br&gt;
personally I'd recommend a screenshot of a log and perhaps just listing &lt;br&gt;
the IP and what its hammering against. (ssh in this case). Hope this...&lt;br&gt;</description>
    <pubDate>Wed, 10 Mar 2010 19:51:44 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/46</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/45</link>
    <description>&lt;p&gt;Posted by doug schmidt on Mar 10&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cymru.com/Documents/secure-ios-template.html&quot;&gt;http://www.cymru.com/Documents/secure-ios-template.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how &lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, &lt;br&gt;
install and use a...&lt;br&gt;</description>
    <pubDate>Wed, 10 Mar 2010 19:44:32 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/45</guid>
  </item>


  <item>
    <title>Reporting SSH abuse</title>
    <link>http://seclists.org/basics/2010/Mar/44</link>
    <description>&lt;p&gt;Posted by Dan Pilcheck on Mar 09&lt;/p&gt;Hello list,&lt;br&gt;
&lt;br&gt;
I've been getting a slew of SSH brute forces coming from a university&lt;br&gt;
inside the US over the&lt;br&gt;
past week. Normally I wouldn't even bother with reporting, but I&lt;br&gt;
figured this would be a&lt;br&gt;
chance to clear this up.&lt;br&gt;
&lt;br&gt;
Fail2ban bans for 10 hours, and then the login attempts area right&lt;br&gt;
back at it. Repeat.&lt;br&gt;
&lt;br&gt;
An email with associated logs, and perhaps a little info from this&lt;br&gt;
side is the best I can come&lt;br&gt;
up with. I suppose there's not much else to...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 20:11:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/44</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/43</link>
    <description>&lt;p&gt;Posted by Mike Hale on Mar 09&lt;/p&gt;Wouldn't you want to encrypt your passwords in 5?  Level 7 can be&lt;br&gt;
cracked in seconds online.&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 20:04:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/43</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/42</link>
    <description>&lt;p&gt;Posted by Curt Shaffer on Mar 09&lt;/p&gt;Step one is to now change all of your passwords unless you put bogus hashes in there when you posted this. Otherwise, &lt;br&gt;
everyone on this list can tell you what they are now :)&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how &lt;br&gt;
it benefits your...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 19:57:58 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/42</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/41</link>
    <description>&lt;p&gt;Posted by Alex on Mar 09&lt;/p&gt;Hi you&lt;br&gt;
&lt;br&gt;
Take a look at the Cisco IOS benchmark from CIS [1]&lt;br&gt;
&lt;br&gt;
type this&lt;br&gt;
&lt;br&gt;
MARIO (config)#ip ssh?&lt;br&gt;
&lt;br&gt;
does it show anything? [2]&lt;br&gt;
&lt;br&gt;
Yes. You better change this access list with one that only allows the&lt;br&gt;
traffic that you want and place a deny-all rule at the end. (You will&lt;br&gt;
see this int the CIS benchmark as well)&lt;br&gt;
&lt;br&gt;
But that's the access list that's applied to your internal network&lt;br&gt;
going out. You also have an access-list that seems to be applied to&lt;br&gt;
the...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 19:46:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/41</guid>
  </item>
  <item>
    <title>RE: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/40</link>
    <description>&lt;p&gt;Posted by Jatmoko, Arif (ID - Jakarta) on Mar 09&lt;/p&gt;If this is a Cisco Catalyst, that should be support SSH. Just enable SSH by entering the command :&lt;br&gt;
crypto key generate rsa&lt;br&gt;
line vty 0 4&lt;br&gt;
And disable telnet, make SSH the only transport agent, use ACL to restrict inbound &amp;amp; outbound packet passing your &lt;br&gt;
interfaces (by ip address &amp;amp; services), enable logging, secure your login, etc...etc.&lt;br&gt;
&lt;br&gt;
You should, at least learn some basic command or consults about configuring Catalyst IOS to someone has...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 16:15:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/40</guid>
  </item>
  <item>
    <title>Re: securing a segment of a network</title>
    <link>http://seclists.org/basics/2010/Mar/39</link>
    <description>&lt;p&gt;Posted by krymson on Mar 09&lt;/p&gt;Would that be a primary concern about the current state of audits and checklists? Basically, there is a *lot* of effort &lt;br&gt;
to camoflage or &amp;quot;limit the scope&amp;quot; of such audits.&lt;br&gt;
&lt;br&gt;
&amp;lt;- snip -&amp;gt;&lt;br&gt;
Now to the issue itself.&lt;br&gt;
&lt;br&gt;
I am willing to believe the issue was actually about potential inappropriate access to system resources such as &lt;br&gt;
applicatiions, shares and/or privileges. Splitting the network does not address this in any way, at best it...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 16:09:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/39</guid>
  </item>
  <item>
    <title>FW: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/38</link>
    <description>&lt;p&gt;Posted by Craig S. Wright on Mar 09&lt;/p&gt;ARGGG!&lt;br&gt;
Always obscure the details.&lt;br&gt;
&lt;br&gt;
It is clear you are not experienced with Cisco security. As such, I would&lt;br&gt;
start with an automated tool such as the router audit tool (RAT) and Nipper.&lt;br&gt;
&lt;br&gt;
You get these from the following sites respectively:&lt;br&gt;
        Centre for Internet Security (CIS) website &lt;br&gt;
                &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cisecurity.org/bench_cisco.html&quot;&gt;http://www.cisecurity.org/bench_cisco.html&lt;/a&gt;.&lt;br&gt;
        Nipper, (Network Infrastructure Parser)...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 16:05:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/38</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/37</link>
    <description>&lt;p&gt;Posted by John Morrison on Mar 09&lt;/p&gt;Joe,&lt;br&gt;
&lt;br&gt;
To protect, or secure, the router there are a few basics. These boil down to:&lt;br&gt;
   Install the latest IOS updates&lt;br&gt;
   Only run required services and disable all others&lt;br&gt;
   Allow only authenticated and encrypted access to the router&lt;br&gt;
   Use ACLs to control remote access to the router&lt;br&gt;
&lt;br&gt;
See&lt;br&gt;
   &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml&quot;&gt;http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Latest IOS Update&lt;br&gt;
==============&lt;br&gt;
Download and installed the latest...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 15:59:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/37</guid>
  </item>
  <item>
    <title>Re: Help hardening router</title>
    <link>http://seclists.org/basics/2010/Mar/36</link>
    <description>&lt;p&gt;Posted by David Goldsmith on Mar 09&lt;/p&gt;Did you change the various encrypted passwords before posting the&lt;br&gt;
config?  If not,  we may not have the IP address of the router, but you&lt;br&gt;
just exposed their passwords (which may be used elsewhere)&lt;br&gt;
&lt;br&gt;
There are also IP address for other interfaces on the router and other&lt;br&gt;
endpoints, descriptions of connections, etc, in the configuration that&lt;br&gt;
you posted.&lt;br&gt;
&lt;br&gt;
If you post configurations to public lists asking for review, you should&lt;br&gt;
be sure to fully...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 15:54:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/36</guid>
  </item>
  <item>
    <title>Re: securing a segment of a network</title>
    <link>http://seclists.org/basics/2010/Mar/35</link>
    <description>&lt;p&gt;Posted by Adam Pal on Mar 08&lt;/p&gt;Hi Roger,&lt;br&gt;
&lt;br&gt;
First point: what you described bellow is nice, but it is one special scenario. &lt;br&gt;
What is the most likely threat you want to mitigate? &lt;br&gt;
Try to keep in mind, that mitigating exitic threats can lead you to higher costs and that is what you wanted to avoid &lt;br&gt;
acording to your first email.&lt;br&gt;
Also another question you can take in consideration: what would be your acceptable risks?&lt;br&gt;
&lt;br&gt;
If the requirement is:&lt;br&gt;
&amp;quot;Keep the same, maintain the...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 00:23:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/35</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
