<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Basics</title>
    <link>http://seclists.org/#basics</link>
    <atom:link href="http://seclists.org/rss/basics.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
    <pubDate>Thu, 26 Nov 2009 22:30:07 GMT</pubDate>
    <lastBuildDate>Thu, 26 Nov 2009 22:30:07 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: [OT] IP Address scheme for branch office</title>
    <link>http://seclists.org/basics/2009/Nov/125</link>
    <description>&lt;p&gt;Posted by martin on Nov 26&lt;/p&gt;Hi All&lt;br&gt;
&lt;br&gt;
Thanks for the replies.  In answer to your questions, we are actually&lt;br&gt;
using Class A addresses globally (sorry, I didn't use the actual IP's&lt;br&gt;
in my original plan).  The EMEA region has been assigned one Class B&lt;br&gt;
network to sub-divide amongst our offices.  So unfortunately the&lt;br&gt;
solutions above won't fit our requirements.&lt;br&gt;
&lt;br&gt;
Of course, assigning a /21 subnet to each office will meet the IP&lt;br&gt;
address requirements.  But it won't give us a standard...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:14:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/125</guid>
  </item>
  <item>
    <title>Re: Is snort an overkill for desktop only environment ?</title>
    <link>http://seclists.org/basics/2009/Nov/124</link>
    <description>&lt;p&gt;Posted by martin on Nov 26&lt;/p&gt;2009/11/26 martin &amp;lt;martiniscool () gmail com&amp;gt;:&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how &lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, &lt;br&gt;
install and use a thawte...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:10:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/124</guid>
  </item>
  <item>
    <title>Re: adding another defence layer against viruses/worms</title>
    <link>http://seclists.org/basics/2009/Nov/123</link>
    <description>&lt;p&gt;Posted by Mohamed Aymen SAHLI on Nov 26&lt;/p&gt;Maybe,&lt;br&gt;
&lt;br&gt;
-Using local firewalls on these branches to filter outbound traffic to the core&lt;br&gt;
&lt;br&gt;
-Centralize the internet access to have all web traffic go through a&lt;br&gt;
filtering appliance such as a  Cisco Iron Port  or  a websense web&lt;br&gt;
security.&lt;br&gt;
&lt;br&gt;
-Have an antivirus solution deployed over the campus.  I would&lt;br&gt;
recommend Symantec EndPoint Protection as it provides good deal of&lt;br&gt;
flexibility in what concerns remote sites ( replication, local group&lt;br&gt;
updates provide...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:05:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/123</guid>
  </item>
  <item>
    <title>RE: adding another defence layer against viruses/worms</title>
    <link>http://seclists.org/basics/2009/Nov/122</link>
    <description>&lt;p&gt;Posted by Rivest, Philippe on Nov 26&lt;/p&gt;Thats always an issue with IDS/IPS&lt;br&gt;
Sadly I dont know any heuristic IDS/IPS, I know the overall purpose and&lt;br&gt;
setup of these devices but I did not have the chance to play with any of&lt;br&gt;
them yet.&lt;br&gt;
&lt;br&gt;
sorry&lt;br&gt;
&lt;br&gt;
Philippe Rivest - CEH, Network+, Server+, A+&lt;br&gt;
TransForce Inc.&lt;br&gt;
Internal auditor - Information security&lt;br&gt;
Verificateur interne - Securite de l'information&lt;br&gt;
&lt;br&gt;
8585 Trans-Canada Highway, Suite 300&lt;br&gt;
Saint-Laurent (Quebec) H4S 1Z6&lt;br&gt;
Tel.: 514-331-4417   &lt;br&gt;
Fax:...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:01:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/122</guid>
  </item>
  <item>
    <title>RE: Dealing with Scans (portscans, vulnerability, etc.)</title>
    <link>http://seclists.org/basics/2009/Nov/121</link>
    <description>&lt;p&gt;Posted by Holger Reichert on Nov 26&lt;/p&gt;Hi, &lt;br&gt;
just one hint regarding the topic of reporting this to a contact of the&lt;br&gt;
company of where the attacking IP address is located.&lt;br&gt;
In my times of defence system administration I decided to report major scans&lt;br&gt;
to companies within my own country, which were the origin of attacks like&lt;br&gt;
this. They were always very grateful, as they had not detected yet, that&lt;br&gt;
they were hacked and their system used for scannings.&lt;br&gt;
&lt;br&gt;
Kind regards&lt;br&gt;
Holger Reichert&lt;br&gt;
Holysword...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:50:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/121</guid>
  </item>
  <item>
    <title>RE: adding another defence layer against viruses/worms</title>
    <link>http://seclists.org/basics/2009/Nov/120</link>
    <description>&lt;p&gt;Posted by Juan B on Nov 26&lt;/p&gt;Hi Philipe,&lt;br&gt;
&lt;br&gt;
thanks for your respond !&lt;br&gt;
&lt;br&gt;
the issue about heuristic IPS is that it will be in the lan so Im afraid of a high volume of false positives ! &lt;br&gt;
which heuristic IPS would you suggest for this task?&lt;br&gt;
&lt;br&gt;
thanks &lt;br&gt;
&lt;br&gt;
juan&lt;br&gt;
&lt;br&gt;
--- On Wed, 11/25/09, Rivest, Philippe &amp;lt;PRivest () transforce ca&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:48:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/120</guid>
  </item>
  <item>
    <title>Onapsis Research: SAP Security In-Depth Vol. I</title>
    <link>http://seclists.org/basics/2009/Nov/119</link>
    <description>&lt;p&gt;Posted by Onapsis Research on Nov 26&lt;/p&gt;Dear colleague,&lt;br&gt;
&lt;br&gt;
The first volume of the Onapsis' SAP Security In-Depth publication has been released.&lt;br&gt;
&lt;br&gt;
SAP Security In-Depth is a free technical publication leaded by the Onapsis Research Labs with the purpose of providing &lt;br&gt;
specialized information about&lt;br&gt;
the current and future risks in the SAP security field, allowing all the different actors (financial managers, &lt;br&gt;
information security managers, SAP&lt;br&gt;
administrators, auditors, consultants and the...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:45:43 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/119</guid>
  </item>
  <item>
    <title>RE: adding another defence layer against viruses/worms</title>
    <link>http://seclists.org/basics/2009/Nov/118</link>
    <description>&lt;p&gt;Posted by Rivest, Philippe on Nov 26&lt;/p&gt;I believe your looking for a Heuristic IPS, also called behavioral IPS.&lt;br&gt;
Which will take a look at the activities going on your network segment and&lt;br&gt;
build a DB of normal activities (PLEASE ensure you are virus, worm, hacker&lt;br&gt;
and problem free..). When you decide your DB is big enough, you stop it and&lt;br&gt;
run all day-2-day activities against it. Any deviation will be flagged as&lt;br&gt;
unauthorized and action will be taken.&lt;br&gt;
&lt;br&gt;
This will allow you to block new...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:42:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/118</guid>
  </item>
  <item>
    <title>RE: Is snort an overkill for desktop only environment ?</title>
    <link>http://seclists.org/basics/2009/Nov/117</link>
    <description>&lt;p&gt;Posted by Rivest, Philippe on Nov 26&lt;/p&gt;I'M not sure we are tackling this the right way. The question that was ask&lt;br&gt;
is &amp;quot;is it overkill for a desktop only environment&amp;quot;.&lt;br&gt;
&lt;br&gt;
Every time you want to implement a control, you need to evaluate if you need&lt;br&gt;
it (cost-benefit). If theres no need for IDS (H-N) at all, dont implement&lt;br&gt;
them. But if you are the NSA and have (for what ever reason) a desktop only&lt;br&gt;
environment in on of their branch/location, you MIGHT want to have these&lt;br&gt;
controls....&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:39:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/117</guid>
  </item>
  <item>
    <title>Re: When SPAMMERS Pay You !</title>
    <link>http://seclists.org/basics/2009/Nov/116</link>
    <description>&lt;p&gt;Posted by Shreyas Zare on Nov 26&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
That mail came from paypal server, I did verify the mail headers and I&lt;br&gt;
have that eCheck payment in my account too (although the entire amount&lt;br&gt;
is deducted as fees, so I get nothing).&lt;br&gt;
&lt;br&gt;
Regards,&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:35:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/116</guid>
  </item>
  <item>
    <title>Re: whole disk encryption on multi boot laptop</title>
    <link>http://seclists.org/basics/2009/Nov/115</link>
    <description>&lt;p&gt;Posted by Alexander Klimov on Nov 26&lt;/p&gt;As a professional paranoid I would not recommend using hardware FDE&lt;br&gt;
for anything more than &amp;quot;keeping your kid sister out&amp;quot;: you can never be&lt;br&gt;
sure what backdoors are incorporated into them.  In addition to&lt;br&gt;
intentional backdoors (that, presumably, can be used only by the&lt;br&gt;
authorities) you should be afraid of stupidity: there are known&lt;br&gt;
examples (see Drecom) when a &amp;quot;128-bit AES hardware data encryption&amp;quot;&lt;br&gt;
turns out to be a xor of every...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 21:33:12 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/115</guid>
  </item>


  <item>
    <title>RE: adding another defence layer against viruses/worms</title>
    <link>http://seclists.org/basics/2009/Nov/114</link>
    <description>&lt;p&gt;Posted by boaz.shunami on Nov 25&lt;/p&gt;Hi Juan,&lt;br&gt;
&lt;br&gt;
I would advise your Client to either:&lt;br&gt;
&lt;br&gt;
1. Have solid policy as to what sites are accessible/are not accessible&lt;br&gt;
from his branches (can be enforced with bluecoat and the like...)&lt;br&gt;
2. Segregate the network the branches have access to (kind of DMZ) from&lt;br&gt;
his LAN using FW.&lt;br&gt;
3. Give low level permissions to the branches on the core.&lt;br&gt;
&lt;br&gt;
My 2c...&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
 &lt;br&gt;
Boaz&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: listbounce () securityfocus com [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:listbounce&quot;&gt;mailto:listbounce&lt;/a&gt; ()...&lt;br&gt;</description>
    <pubDate>Wed, 25 Nov 2009 15:35:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/114</guid>
  </item>
  <item>
    <title>scalable syscall proxying</title>
    <link>http://seclists.org/basics/2009/Nov/113</link>
    <description>&lt;p&gt;Posted by pleed on Nov 25&lt;/p&gt;Hi there,&lt;br&gt;
&lt;br&gt;
some weeks ago i ve read papers about syscall proxying.&lt;br&gt;
When i was looking for implementations, i just found very specific&lt;br&gt;
code (e.g. at ueberwall.org) that could be used for minimal application.&lt;br&gt;
&lt;br&gt;
Thats why i thought it could be funny to write my own, scalable syscall&lt;br&gt;
proxy.&lt;br&gt;
My concept includes:&lt;br&gt;
    -   using ptrace SYSEMU to catch a process syscalls instead of&lt;br&gt;
overwriting libc wrappers&lt;br&gt;
    -   providing an interface to enable/disable...&lt;br&gt;</description>
    <pubDate>Wed, 25 Nov 2009 15:27:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/113</guid>
  </item>
  <item>
    <title>Re: Dealing with port/vulnerability scans</title>
    <link>http://seclists.org/basics/2009/Nov/112</link>
    <description>&lt;p&gt;Posted by Michael Painter on Nov 25&lt;/p&gt;Tony Raboza wrote:&lt;br&gt;
&lt;br&gt;
Chapter 1. Getting Started with Nmap&lt;br&gt;
Legal Issues&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://nmap.org/book/legal-issues.html&quot;&gt;http://nmap.org/book/legal-issues.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how &lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will...&lt;br&gt;</description>
    <pubDate>Wed, 25 Nov 2009 15:25:36 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/112</guid>
  </item>
  <item>
    <title>Re: Is snort an overkill for desktop only environment ?</title>
    <link>http://seclists.org/basics/2009/Nov/111</link>
    <description>&lt;p&gt;Posted by pleed on Nov 25&lt;/p&gt;Alexander Klimov wrote:&lt;br&gt;
&lt;br&gt;
In my opinion NIDS on the host itself does not make the box more secure.&lt;br&gt;
When deploying snort, you normaly want to know if there already has been a&lt;br&gt;
_successful_ attack, because when connecting to the internet you re&lt;br&gt;
always being&lt;br&gt;
attacked but mostly without any affect to your system. In your case if&lt;br&gt;
your desktop&lt;br&gt;
is attacked successfully, i wouldnt trust the NIDS output anyway.&lt;br&gt;
In addition snort is just helpfull if someone...&lt;br&gt;</description>
    <pubDate>Wed, 25 Nov 2009 15:24:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2009/Nov/111</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
