<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1786185134212231068</id><updated>2011-12-18T18:01:29.410-05:00</updated><category term='Wireless'/><category term='Twitter'/><category term='Varonis'/><category term='CREATOR OWNER'/><category term='NAC'/><category term='ECM'/><category term='Zero Day'/><category term='domain name'/><category term='Reader'/><category term='AIIM'/><category term='Acrobat'/><category term='Adobe Reader'/><category term='FairWarning'/><category term='Active Directory Group'/><category term='Poulsen'/><category term='Admin'/><category term='Aleynikov'/><category term='SMTP'/><category term='OWASP'/><category term='Adobe Acrobat'/><category term='Heartland'/><category term='LinkedIn'/><category term='DarkReading'/><category term='Nicholas Carr'/><category term='Fatal System Error'/><category term='Shutdown'/><category term='VB Script'/><category term='Adobe'/><category term='Laserjet 3100'/><category term='Goldman Sachs'/><category term='PDF'/><category term='Cloud Computing'/><category term='SharePoint Users Group'/><category term='security'/><category term='RBS'/><category term='administrator'/><category term='Top 10'/><category term='Personal Data Privacy and Security Act.'/><category term='SharePoint'/><category term='Senator Leahy'/><category term='SQL Server 2005'/><category term='YouTube'/><category term='Cybersecurity'/><category term='Terry Childs'/><category term='Reporting Services'/><category term='hacker'/><category term='Infonomics'/><category term='privileged account'/><category term='Two-factor authentication'/><category term='Garden State Chapter'/><category term='Windows Server'/><category term='cybercrime'/><category term='ForeScout'/><category term='Security Groups'/><category term='Kingpin'/><category term='HIPAA'/><category term='McAfee VirusScan'/><category term='encrpyion'/><category term='Active Directory'/><category term='Hacked'/><category term='WIndows Server 2003'/><category term='SID'/><category term='Russinovich'/><category term='CounterACT'/><category term='DatAdvantage'/><category term='Service Account'/><category term='Data Breach'/><category term='spear-phishing'/><category term='SAAS'/><category term='Gonzalez'/><title type='text'>Tech Tips from the Castle</title><subtitle type='html'>Tips on Improving IT Security and System Adminstration from Castle Ventures LLC.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>57</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5112400893151863669</id><published>2011-12-18T17:35:00.005-05:00</published><updated>2011-12-18T18:01:29.417-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LinkedIn'/><category scheme='http://www.blogger.com/atom/ns#' term='spear-phishing'/><title type='text'>LinkedIn Needs to Add a Warning to its Connection Emails</title><content type='html'>Like most of us, I receive invitations from random folks on the Internet asking me to connect with them via LinkedIn. In some cases they are from accounts with no connections and no reasonable profile. They are clearly looking for information for nefarious purposes. Yet when the email comes in, this is all that LinkedIn says:&lt;br /&gt;&lt;br /&gt;"WHY MIGHT CONNECTING WITH SHAMSODIN KARIMI LASAKI BE A GOOD IDEA?&lt;br /&gt;shamsodin karimi lasaki's connections could be useful to you&lt;br /&gt;After accepting shamsodin karimi lasaki's invitation, check shamsodin karimi lasaki's connections to see who else you may know and who you might want an introduction to. Building these connections can create opportunities in the future."&lt;br /&gt;&lt;br /&gt;What is LinkedIn thinking? Why encourage me to connect with a potential hacker?&lt;br /&gt;Social networks lose their effectiveness when people lose trust in the overall experience and it is LinkedIn's best interest overall the long run to discourage people from connecting with people they do not have a relationship with.&lt;br /&gt;&lt;br /&gt;Let's encourage LinkedIn to add a warning to those emails as well. Here is one potential idea.&lt;br /&gt;&lt;br /&gt;"WHY MIGHT CONNECTING WITH SHAMSODIN KARIMI LASAKI BE A BAD IDEA?&lt;br /&gt;If you have no freaking idea who LASAKI is, he might be trying to gather personal information from you as part of a plan to launch a spear-phishing attack against you or one of your connections. Building these connections with people you do not know can create risks and privacy concerns in the future."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5112400893151863669?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5112400893151863669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/12/linkedin-needs-to-add-warning-to-its.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5112400893151863669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5112400893151863669'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/12/linkedin-needs-to-add-warning-to-its.html' title='LinkedIn Needs to Add a Warning to its Connection Emails'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8047836927139116905</id><published>2011-11-19T11:37:00.004-05:00</published><updated>2011-11-19T11:55:05.816-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DatAdvantage'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Group'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><title type='text'>Tracking AD Groups Changes with Varonis</title><content type='html'>Varonis DatAdvantage tracks changes in Active Directory group membership by comparing the results of the nightly AD walks. If we want to see the changes that have been made to a user we can use the "1a - User Access Log report." The key filter to remember is that we want to show data from the "History of Differences." This shows the changes that have been picked up by the nightly jobs. Then we need to select the date range that we want to look at.&lt;br /&gt;&lt;br /&gt;Then select the "Operation Type" filter. There are two operation types that we can select depending on what we are trying to track:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Membership Removed&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Membership Added&lt;/li&gt;&lt;/ul&gt;Add the filter to look only at "Groups" for the Object Type.&lt;br /&gt;The final piece is that the user affected by the change is identified in the "Change Description" field. Use the "Like" operator and remember to enter in the domain name before the start of the user name.&lt;br /&gt;&lt;br /&gt;Run the report and you have the answer you were looking for.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-2Ts5UWhoUYM/TsfdJNwunvI/AAAAAAAAAGg/rulBzu6qNqA/s1600/ADChanges.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 291px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5676749005706403570" border="0" alt="" src="http://4.bp.blogspot.com/-2Ts5UWhoUYM/TsfdJNwunvI/AAAAAAAAAGg/rulBzu6qNqA/s400/ADChanges.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;Note: Starting in Version 5.6 of Varonis DatAdvantage we also have the "3e - Historical Group Membership" which will display the groups a user belonged to on a specific date. Great report for answering those tricky audit questions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8047836927139116905?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8047836927139116905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/11/tracking-ad-groups-changes-with-varonis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8047836927139116905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8047836927139116905'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/11/tracking-ad-groups-changes-with-varonis.html' title='Tracking AD Groups Changes with Varonis'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-2Ts5UWhoUYM/TsfdJNwunvI/AAAAAAAAAGg/rulBzu6qNqA/s72-c/ADChanges.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-4330582062136536169</id><published>2011-07-08T07:19:00.003-04:00</published><updated>2011-07-08T07:34:11.997-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='FairWarning'/><title type='text'>UCLA Health System Settles Potential HIPAA Privacy and Security Violations</title><content type='html'>The Department of Health and Humans Services reached it third &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/news/uclahs.html"&gt;settlement&lt;/a&gt; this year with a healthcare organization for violations of the HIPAA regulations when UCLA agreed to pay $865,000 to resolve charges that employees were inappropriately snooping into the records of celebrity patients.&lt;br /&gt;&lt;br /&gt;In the previous settlements of 2011, Massachusetts General agreed to pay a fine of $1,000,o00 and Cignet Health of Prince George's County agreed to a fine of $4,300,000. Clearly HHS is taking these violations much more seriously than had been done in the first 14 years of HIPAA's existence.&lt;br /&gt;&lt;br /&gt;Organizations that deal with PHI need to have clearly defined policies and procedures to protect patient data, training to make sure that employees are aware of the rules, and most importantly methods that can be used to monitor that the policies are being followed. If you are the CISO of a healthcare organization you should be asking yourself questions such as:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Are all of the laptops that access our systems encrypted?&lt;/li&gt;&lt;br /&gt;&lt;li&gt;How do I validate that they are encrypted?&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Are we monitoring access to patient information?&lt;/li&gt;&lt;br /&gt;&lt;li&gt;How do we detect inappropriate access to PHI?&lt;/li&gt;&lt;/ul&gt;The stakes are being raised and the privacy groups within Healthcare organizations have to respond accordingly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-4330582062136536169?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/4330582062136536169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/07/ucla-health-system-settles-potential.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/4330582062136536169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/4330582062136536169'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/07/ucla-health-system-settles-potential.html' title='UCLA Health System Settles Potential HIPAA Privacy and Security Violations'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-752710364422197135</id><published>2011-07-04T13:59:00.005-04:00</published><updated>2011-07-04T14:10:36.293-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Zero Day'/><category scheme='http://www.blogger.com/atom/ns#' term='Russinovich'/><title type='text'>Zero Day by Mark Russinovich</title><content type='html'>Of course you can tell by reading this blog that I am not a storyteller; and certainly not a novelist. Therefore I preface this review with that caveat that I could not have written &lt;u&gt;Zero Day&lt;/u&gt; as well as Mark Russinovich. &lt;u&gt;Zero Day&lt;/u&gt; is a thriller surrounding the release of a set of extremely destructive computer viruses. We track the progress of Jeff Aiken, a private security consultant, and Darryl Haugen, a PhD. Computer scientist from MIT working for the Department of Homeland Security, as they try to identify the viruses, determine a solution, and track down the perpetrators. The main flaws of the novel is that the characters are on dimensional and the book is hitting us over the head with a hammer to indicate the potential devastation that society could face as result of a cadre of determined evildoers exploiting the weaknesses of the Internet and computer systems.&lt;br /&gt;&lt;br /&gt;As a technical expert, Mark Russinovich is world famous. He is known to us in the security world as one of the cofounders of Sysinternals; which is one of the key solutions available to Windows administrators everywhere. With this technical background, &lt;u&gt;Zero Day&lt;/u&gt; describes how a set of evil actors could technically wreck havoc on the computer systems of America and Europe.&lt;br /&gt;The story is engaging and suspenseful and as someone in the security field, I was interested to see where the story led us. Without the importance of the subject matter, the risks to our cyber infrastructure, the book would not be that interesting. The storytelling and actors is too shallow. We have “obligatory” love scenes and one of the “usual suspects,” a Russian cybercriminal, involved. There is limited character development in the story and the bureaucrat that Daryl reports to is as helpful as our stereotypes of bureaucrats would lead us to believe. That being said, I believe like Mark does that the risks we face are severe and the more coverage that they get the better. With that as a backdrop I would recommend this book.&lt;br /&gt;&lt;br /&gt;In my opinion, to learn more about the security implications and the deep impact of the Internet on our society, I would first read Daniel Suarez’s two novel set, &lt;a href="http://www.blogger.com/%3Ca%20href=%22http://www.amazon.com/gp/product/B003L1ZXCU/ref=as_li_tf_tl?ie=UTF8&amp;amp;tag=tectipfrothec-20&amp;amp;linkCode=as2&amp;amp;camp=217145&amp;amp;creative=399377&amp;amp;creativeASIN=B003L1ZXCU"&gt;Daemon&lt;/a&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=B003L1ZXCU&amp;amp;camp=217145&amp;amp;creative=399377" width="1" height="1" /&gt; and &lt;a href="http://www.blogger.com/%3Ca%20href=%22http://www.amazon.com/gp/product/B003MAJNUS/ref=as_li_tf_tl?ie=UTF8&amp;amp;tag=tectipfrothec-20&amp;amp;linkCode=as2&amp;amp;camp=217145&amp;amp;creative=399377&amp;amp;creativeASIN=B003MAJNUS"&gt;Freedom (TM)&lt;/a&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=B003MAJNUS&amp;amp;camp=217145&amp;amp;creative=399377" width="1" height="1" /&gt;. These provide a much more nuanced look at the good and bad associated with the Internet and our dependence on it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-752710364422197135?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/752710364422197135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/07/zero-day-by-mark-russinovich.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/752710364422197135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/752710364422197135'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/07/zero-day-by-mark-russinovich.html' title='Zero Day by Mark Russinovich'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6293129070945066274</id><published>2011-05-31T09:16:00.005-04:00</published><updated>2011-05-31T09:26:33.723-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Poulsen'/><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><category scheme='http://www.blogger.com/atom/ns#' term='Kingpin'/><title type='text'>Kingpin</title><content type='html'>Kevin Poulsen's &lt;u&gt;Kingpin&lt;/u&gt; is a fascinating look at the world of cybercrime involving credit card theft and fraud. The story is told from two angles. The first is from the perspective of Max Butler, one of the leading cyber criminals of the last ten years, and the second is from the perspective of law enforcement. We follow the path of J. Kevin Mularski, an FBI agent, who leads the effort to track down and ultimately capture Max Butler.&lt;br /&gt;&lt;br /&gt;As “Iceman,” Butler ran Carders Market, an online marketplace for illegal credit card data. The book covers many of the high-level techniques that Butler uses to break into systems, invade Point of Sale Systems, and it includes a solid discussion of how SQL injection is used to steal data. In fascinating detail Poulsen covers how Max uses hacking techniques to take over many of the illegal sites that hackers use to buy and sell credit card information, shut down his competitors, and move all of the traffic over to his Carders Market site.&lt;br /&gt;&lt;br /&gt;The dual focus on the criminals and the law enforcement efforts to capture them makes the story a page turner, and it reads like a crime novel. Kingpin also covers some of the law enforcement efforts surrounding, Shadowcrew, the online criminal marketplace that was shut down due to the information received from the combination informant / cybercriminal Albert Gonzalez, who would later be arrested and convicted for the TJX and Heartland Payment Systems breaches. The FBI brilliantly set up a VPN for the Shadowcrew service so that they could tap all of the online conversations and identify the evildoers.&lt;br /&gt;&lt;br /&gt;Kevin Poulsen certainly knows the hacker underground, as he was convicted in June of 1994 of several computer crimes and was sentenced to over 4 years in prison. Jonathan Littman covered his Kevin’s exploits in &lt;a href="http://www.blogger.com/%3Ca%20href=%22http://www.amazon.com/gp/product/0316528579/ref=as_li_tf_tl?ie=UTF8&amp;amp;tag=tectipfrothec-20&amp;amp;linkCode=as2&amp;amp;camp=217145&amp;amp;creative=399353&amp;amp;creativeASIN=0316528579"&gt;The Watchman: The Twisted Life and Crimes of Serial Hacker Kevin Poulsen&lt;/a&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0316528579&amp;amp;camp=217145&amp;amp;creative=399349" width="1" height="1" /&gt;&lt;label id="showTextCategoryLinkPreview_l1"&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0316528579&amp;amp;camp=217145&amp;amp;creative=399357" width="1" height="1" /&gt;. Poulsen is now a Senior Editor at Wired.com&lt;br /&gt;&lt;br /&gt;Poulsen’s first-hand knowledge leads to one of the most interesting facets of the book. At many times Poulsen’s story of Max Butler describes the psychology of Max. He parallels many who are involved in the world of hacking. They are conflicted individuals, with a childlike love of learning and exploration, without the moral tools to stop them from crossing the line into criminal behavior.&lt;br /&gt;&lt;br /&gt;The book has the two key elements that I look for: it is entertaining and informative. It is a must-read for those who have an interest in information security and care about the digital economy. &lt;/label&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;label&gt;&lt;/label&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p align="center"&gt;&lt;iframe style="WIDTH: 120px; HEIGHT: 240px" marginheight="0" src="http://rcm.amazon.com/e/cm?t=tectipfrothec-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=as1&amp;amp;asins=0307588688&amp;amp;ref=qf_sp_asin_til&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" frameborder="0" marginwidth="0" scrolling="no"&gt;&lt;/iframe&gt;&lt;/p&gt;&lt;br /&gt;&lt;label id="showTextCategoryLinkPreview_l1"&gt;&lt;/label&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6293129070945066274?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6293129070945066274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/05/kingpin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6293129070945066274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6293129070945066274'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/05/kingpin.html' title='Kingpin'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2664440310614008261</id><published>2011-02-20T18:55:00.006-05:00</published><updated>2011-02-20T19:14:54.332-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CREATOR OWNER'/><category scheme='http://www.blogger.com/atom/ns#' term='SID'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows Server 2003'/><title type='text'>The CREATOR OWNER Problem</title><content type='html'>This post describes the problem caused by the CREATOR OWNER permissions that are set by default in Windows Server 2003 on folders. Take the example here of the Human Resources folder and all of the subdirectories underneath it. This is sensitive data that we want to manage the permissions extremely carefully. The challenge with the CREATOR OWNER permission is that when a user creates a subfolder within a folder that contains this permission, the SID of that User is set to Full permissions on the new folder, even though we had given them only Modify permissions within the "Terminations" folder. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-dLmOL04Q0_E/TWGq8BxQjfI/AAAAAAAAAGM/HPW6QHElDZI/s1600/CreatorOwner-Folders.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 301px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5575925761905298930" border="0" alt="" src="http://4.bp.blogspot.com/-dLmOL04Q0_E/TWGq8BxQjfI/AAAAAAAAAGM/HPW6QHElDZI/s400/CreatorOwner-Folders.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If we look at the security of the "DoneBYSSmith-CO-ON" folder, we can see that Windows Server 2003 has added an Access Control Entry for Sally Smith and given that user Full control. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-CVn8bHdwLCY/TWGqITEuRUI/AAAAAAAAAF0/3e4TFU-5KEQ/s1600/CreatorOwner-Sally.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 311px; DISPLAY: block; HEIGHT: 400px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5575924873197143362" border="0" alt="" src="http://3.bp.blogspot.com/-CVn8bHdwLCY/TWGqITEuRUI/AAAAAAAAAF0/3e4TFU-5KEQ/s400/CreatorOwner-Sally.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is not what we wanted, but Windows does it because the CREATOR OWNER permission was set at the parent folder as shown here.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-mIh0oFox7vM/TWGqPRwNvzI/AAAAAAAAAF8/4L35JBBCn-I/s1600/CreatorOwner-Initial.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 311px; DISPLAY: block; HEIGHT: 400px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5575924993101774642" border="0" alt="" src="http://2.bp.blogspot.com/-mIh0oFox7vM/TWGqPRwNvzI/AAAAAAAAAF8/4L35JBBCn-I/s400/CreatorOwner-Initial.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;What we need to do is remove the CREATOR OWNER at the top level folder where inheritance is turned off and then push it down to all of the child objects. The permissions should then look like this at the parent folder. When any user in the grp.Share.HumanResources.Modify group creates a folder, then they will not inherit full permissions, which is normally what we want. They will instead retain just the permissions granted by the group they belong to.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-KN92JHUTt9U/TWGqVGAljXI/AAAAAAAAAGE/qE5ACLzeP4E/s1600/CreatorOwner-Correct.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 311px; DISPLAY: block; HEIGHT: 400px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5575925093028433266" border="0" alt="" src="http://1.bp.blogspot.com/-KN92JHUTt9U/TWGqVGAljXI/AAAAAAAAAGE/qE5ACLzeP4E/s400/CreatorOwner-Correct.jpg" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Beware the CREATOR OWNER SID.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2664440310614008261?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2664440310614008261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2011/02/creator-owner-problem.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2664440310614008261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2664440310614008261'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2011/02/creator-owner-problem.html' title='The CREATOR OWNER Problem'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-dLmOL04Q0_E/TWGq8BxQjfI/AAAAAAAAAGM/HPW6QHElDZI/s72-c/CreatorOwner-Folders.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6785884364655900133</id><published>2010-12-29T14:10:00.004-05:00</published><updated>2010-12-29T14:19:39.908-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><title type='text'>Stop Monitoring a Directory in Varonis</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;There are several types of directories that you may not want to monitor at all in Varonis DatAdvantage. These might be temporary folders that are used by products such as disk archiving solutions that have a cache directory on each Drive that is archived. This will stop all event collection and permissions monitoring for that folder and any subfolders.  &lt;br /&gt;Go to each drive where you believe this is an issue, click on the folder to be excluding to select it. Then right click on the folder and select the “Stop Monitoring” option. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/TRuIeMH1MTI/AAAAAAAAAFY/ipsPzSL753g/s1600/stopmonitoring.jpg"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 286px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5556184617523163442" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/TRuIeMH1MTI/AAAAAAAAAFY/ipsPzSL753g/s400/stopmonitoring.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;When you select the directory a warning dialog box appears asking you to confirm your choice.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/TRuIipOBENI/AAAAAAAAAFg/Jek1F3qSLsI/s1600/StopMonitorDialog.bmp"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 372px; DISPLAY: block; HEIGHT: 130px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5556184694053212370" border="0" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/TRuIipOBENI/AAAAAAAAAFg/Jek1F3qSLsI/s400/StopMonitorDialog.bmp" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;If you click “Yes” then the system stops monitoring the folder immediately. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6785884364655900133?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6785884364655900133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/12/stop-monitoring-directory-in-varonis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6785884364655900133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6785884364655900133'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/12/stop-monitoring-directory-in-varonis.html' title='Stop Monitoring a Directory in Varonis'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/TRuIeMH1MTI/AAAAAAAAAFY/ipsPzSL753g/s72-c/stopmonitoring.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-3610467120247387133</id><published>2010-12-07T12:06:00.003-05:00</published><updated>2010-12-07T12:12:22.661-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='NAC'/><category scheme='http://www.blogger.com/atom/ns#' term='DarkReading'/><title type='text'>Wireless Security and Monitoring in Government Agencies</title><content type='html'>Ericka Chickowski has posted on article on DarkReading discussing the shortfalls of wireless security across government agencies. I offered several of my thoughts to Ericka on the topic which were cited, especially mentioned the need for Network Access Control solutions. Here is the &lt;a href="http://www.darkreading.com/security-monitoring/167901086/security/news/228600091/wireless-monitoring-and-security-lags-in-government-agencies.html"&gt;article&lt;/a&gt;.   Here is a link to the GAO &lt;a href="http://www.gao.gov/new.items/d1143.pdf"&gt;report&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-3610467120247387133?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/3610467120247387133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/12/wireless-security-and-monitoring-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3610467120247387133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3610467120247387133'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/12/wireless-security-and-monitoring-in.html' title='Wireless Security and Monitoring in Government Agencies'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-744599331495248765</id><published>2010-11-19T08:02:00.004-05:00</published><updated>2010-11-19T08:46:36.983-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><title type='text'>Who is minding your Data Stores?</title><content type='html'>I recently received the “Benchmark Study on Patient Privacy and Data Security” by the &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Ponemon&lt;/span&gt; Institute, that was released on November 10, 2010. One thing that always screams out to me from these reports is how few of the data breaches are detected by the organization that was breached.   According to this study less than half (47%) were detected by a hospital employee and in a significant number of cases (41%) it was the patient themselves that noticed the breach.&lt;br /&gt;&lt;br /&gt;When you look at &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-corrected"&gt;statistics&lt;/span&gt; from &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Gartner&lt;/span&gt; and other industry analysts, much of the security spending dollars are going to preventative controls and a much smaller percentage are going to monitoring solutions and detective controls.  Do we as a security professionals have that backwards?&lt;br /&gt;&lt;br /&gt;In spite of significant investments in firewalls and anti-virus tools - generally the two largest categories overall - organizations continue to get breached and data continues to leave the castle.  Are you focused enough on detecting when unusual activities are taking place in your company and spotting potential breaches?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-744599331495248765?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/744599331495248765/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/11/who-is-minding-your-data-stores.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/744599331495248765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/744599331495248765'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/11/who-is-minding-your-data-stores.html' title='Who is minding your Data Stores?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8553901115927161318</id><published>2010-10-13T12:46:00.002-04:00</published><updated>2010-10-13T12:54:27.049-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><title type='text'>Home Directory Data Usage</title><content type='html'>One of the neat things that you can do with Varonis DatAdvantage is monitor how much disk space your users' home directories are taking up.  If you are like most organizations where all of the home directories are stored in a common directory on the file server, this is a snap.&lt;br /&gt;&lt;br /&gt;Using the 4f report - "File System Objects List" create a report with two filters. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;The first is: "Access Path" and should be set to the top level folder that contains the users' folders; such as "D:\home."&lt;/li&gt;&lt;li&gt;The second is: "Directory Depth" and should be set to 3 so you capture each user's folder on a separate line in the report; such as "D:\home\auser."&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Then click on the "Extended Properties" tab and select the "File count" and "Total size in MB" options.   Sort, the report on "Total size in MB" and away you go.&lt;/p&gt;&lt;p&gt;This will generate a list of all of the home directories with their associated disk usage, allowing you to identify users who are taking up an inordinate amount of disk space.  Save this report to a spreadsheet and run this on a periodic basis and you will be able to track usage trends.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8553901115927161318?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8553901115927161318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/10/home-directory-data-usage.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8553901115927161318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8553901115927161318'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/10/home-directory-data-usage.html' title='Home Directory Data Usage'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5414926927296674872</id><published>2010-09-14T08:18:00.003-04:00</published><updated>2010-09-14T08:28:39.062-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='RBS'/><title type='text'>Slap on the wrist for Russian Hacker in RBS Case</title><content type='html'>Unfortunately, the Russian authorities only handed out a suspended sentence for Viktor Pleshchuk, one of the hackers who broke into the systems at RBS WorldPay Inc. They stole approximately $9 million from 2,100 accounts and Viktor essentially got off scot free.&lt;br /&gt;&lt;br /&gt;Several inherent problems are revealed in this decision. First, the United States has no extradition treaty with Russia for these types of crimes. Since a large number of attacks originate from Russia, this is something that the State Department should be working as one of the top priorities in Obama's efforts to improve cybersecurity. If we cannot punish the bad guys, all of the reports and committees are of little use. Second, according to the story on &lt;a href="http://bit.ly/cBGmQ6"&gt;Bloomberg&lt;/a&gt;, his lawyer's statement that “This is not a regular crime but a cybercrime and Pleshchuk didn’t really have a full understanding of the damage he was causing,” is comical.&lt;br /&gt;&lt;br /&gt;These type of criminals hurt thousands of people on a daily basis and need to be severely punished.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5414926927296674872?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5414926927296674872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/09/slap-on-wrist-for-russian-hacker-in-rbs.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5414926927296674872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5414926927296674872'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/09/slap-on-wrist-for-russian-hacker-in-rbs.html' title='Slap on the wrist for Russian Hacker in RBS Case'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-273023351686111386</id><published>2010-07-25T18:34:00.003-04:00</published><updated>2010-07-25T18:42:31.050-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Groups'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Where are AD Groups Used?</title><content type='html'>Utilizing Varonis DatAdvantage, one can determine how an Active Directory group is being used on a file server. To find where a security group is applied to a folder directly, run the &lt;strong&gt;4a – Effective Permissions for User or Group&lt;/strong&gt; report. You need to select each File Server that you want Varonis to investigate and since we are only interested where the group is in the “ACL” there are two options that need to be selected and set to True:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;"Show only direct permissions"&lt;/li&gt;&lt;li&gt;"Distinguished unique"&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://2.bp.blogspot.com/_eFSy8U14xIE/TEy8TqX1unI/AAAAAAAAAFA/0LUjgJkA6q4/s1600/groupusage.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 245px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5497976291090348658" border="0" alt="" src="http://2.bp.blogspot.com/_eFSy8U14xIE/TEy8TqX1unI/AAAAAAAAAFA/0LUjgJkA6q4/s400/groupusage.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This allows you to see every folder where the security group is directly applied.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-273023351686111386?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/273023351686111386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/07/where-are-ad-groups-used.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/273023351686111386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/273023351686111386'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/07/where-are-ad-groups-used.html' title='Where are AD Groups Used?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_eFSy8U14xIE/TEy8TqX1unI/AAAAAAAAAFA/0LUjgJkA6q4/s72-c/groupusage.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2600157304904674284</id><published>2010-07-06T22:01:00.013-04:00</published><updated>2010-07-06T22:21:12.992-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CounterACT'/><category scheme='http://www.blogger.com/atom/ns#' term='ForeScout'/><title type='text'>Dealing with the CounterACT "Port Scan - SNMP" message</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;One of the challenges in managing the ForeScout CounterACT appliance is to deal with and clean up the false positives that arise from anomalous network behavior that is not malicious. For example, today, we received a set of errors from one particular server, 192.168.111.18, that indicated that it was performing SNMP port scans. ForeScout correctly detected that something unusual was occurring and classified it as a malicious event.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/TDPh18Eml_I/AAAAAAAAAE4/GbGEn5H2Hy4/s1600/ForeScoutError.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5490980687469516786" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/TDPh18Eml_I/AAAAAAAAAE4/GbGEn5H2Hy4/s400/ForeScoutError.jpg" /&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; Every several hours the server was performing SNMP port scans on IP addresses that were no longer existed. What was causing these scans?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_eFSy8U14xIE/TDPhyA5EG9I/AAAAAAAAAEw/TJ3rLnt1onc/s1600/ForeScoutDetail.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5490980620043819986" border="0" alt="" src="http://2.bp.blogspot.com/_eFSy8U14xIE/TDPhyA5EG9I/AAAAAAAAAEw/TJ3rLnt1onc/s400/ForeScoutDetail.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Upon further investigation, they were IP addresses for printers that had been moved and given new IP addresses. By running regedit and searching for one of the IP addresses we were able to determine that it was a printer that the server was looking for. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/TDPhunjx47I/AAAAAAAAAEo/fS_SqRH3Pzg/s1600/ForeScoutRegistry.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 279px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5490980561704051634" border="0" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/TDPhunjx47I/AAAAAAAAAEo/fS_SqRH3Pzg/s400/ForeScoutRegistry.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:trebuchet ms;"&gt;We went into the Control Panel, selected the printer in question, assigned the LPT1 port to the printer, deleted the old port, and then deleted the print queue. The problem was solved and another false positive was eliminated. Thanks John!&lt;/span&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2600157304904674284?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2600157304904674284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/07/dealing-with-counteract-port-scan-snmp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2600157304904674284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2600157304904674284'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/07/dealing-with-counteract-port-scan-snmp.html' title='Dealing with the CounterACT &quot;Port Scan - SNMP&quot; message'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/TDPh18Eml_I/AAAAAAAAAE4/GbGEn5H2Hy4/s72-c/ForeScoutError.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8428505671161761468</id><published>2010-06-30T08:52:00.006-04:00</published><updated>2010-06-30T09:05:52.255-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDF'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe Acrobat'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe Reader'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><title type='text'>Warning - You Have Received a PDF file</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;With recent spate of vulnerability disclosures in the Adobe Reader and Acrobat programs it is time to take a big picture look at the PDF (Portable Document Format) format. The first observation that I make is that the PDF is not a strictly a static file; because of its potential for embedded JavaScript actions, it is an executable program. Since it is an executable program it needs to be treated as such from a security perspective. We need to have virus scanners aware of the executable functions within PDF files and warn us or inoculate us against the executable code that exists in the format.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Most people assume that a PDF file is a safe, immutable way to save and transmit unstructured information. Unfortunately because of the ability to create forms and JavaScript actions the PDF file has moved far beyond that; which is why the format has become so vulnerable to hackers. One solution that would stop this problem in its tracks would be for Adobe to create two different formats (PDF and PDX for example) and remove the JavaScript capabilities from the core PDF format. Until that happens we need to be wary of PDF files and take some of the following steps: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Educate the user community that PDF files are inherently unsafe and should be treated with caution&lt;/li&gt;&lt;br /&gt;&lt;li&gt;By default, disable the functionality to run JavaScript within Adobe Reader and use it only as an exception.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Make sure that we have prevention tools in place to detect rogue PDF files.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Make sure that we have deployed detective controls to notice when unusual behavior is taking place on a user’s workstation or on the network so that we can fight off the PDF-borne attacks.&lt;/li&gt;&lt;/ol&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;For those who are interested in the latest patches, Adobe issued updates yesterday for Adobe Reader and Acrobat that deal with the Critical security issues that have been discovered in the current release 9.3.2 (and earlier versions). Here is the &lt;a href="http://www.adobe.com/support/security/bulletins/apsb10-15.html"&gt;security bulletin&lt;/a&gt; from Adobe with links to version 9.3.3 of the software products. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8428505671161761468?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8428505671161761468/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/06/with-recent-spate-of-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8428505671161761468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8428505671161761468'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/06/with-recent-spate-of-vulnerability.html' title='Warning - You Have Received a PDF file'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-9144722360162584107</id><published>2010-06-26T08:39:00.006-04:00</published><updated>2010-06-26T08:57:10.063-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server 2005'/><title type='text'>SQL Server Job History</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;In running Varonis DatAdvantage there are times when you want to look at the history of the nightly jobs for a longer period then the defaults provided by SQL Server 2005. These defaults are based on 'Maximum job history log size (rows)' and 'Maximum job history rows per job.' If you are monitoring a large number of servers than the system may only keep several days worth of history for each job. Where disk space on the SQL Server is not an issue one change the the delete option to purge data based on an overall duration, which can be specified in days, weeks or months. For example, we might want to retain 10 days worht of history to assist in debugging issues. To do that perform the following steps.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;First run SQL Server Management Studio.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Then navigate to:&lt;br /&gt;• Root&lt;br /&gt;• SQL Server Instance&lt;br /&gt;• SQL Server Agent&lt;br /&gt;• Right click on SQL Server Agent &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/TCX4Jm5_8JI/AAAAAAAAAEI/ZHJN8ZYAh9A/s1600/SQLServerAgent.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 359px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5487064564967141522" border="0" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/TCX4Jm5_8JI/AAAAAAAAAEI/ZHJN8ZYAh9A/s400/SQLServerAgent.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:verdana;"&gt;From here right-click on history.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;"&gt;Select the option to "Automatically remove agent history" and enter the duration that you want to keep the job history.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;"&gt;Click on OK and you are ready to run.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href="http://2.bp.blogspot.com/_eFSy8U14xIE/TCX2MZGtOJI/AAAAAAAAAEA/m8zE69lMutY/s1600/SQLServerHistory.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 359px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5487062413778696338" border="0" alt="" src="http://2.bp.blogspot.com/_eFSy8U14xIE/TCX2MZGtOJI/AAAAAAAAAEA/m8zE69lMutY/s400/SQLServerHistory.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-9144722360162584107?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/9144722360162584107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/06/sql-server-job-history.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/9144722360162584107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/9144722360162584107'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/06/sql-server-job-history.html' title='SQL Server Job History'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_eFSy8U14xIE/TCX4Jm5_8JI/AAAAAAAAAEI/ZHJN8ZYAh9A/s72-c/SQLServerAgent.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6479365651235895438</id><published>2010-05-05T08:03:00.003-04:00</published><updated>2010-05-05T08:20:49.927-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><title type='text'>Justice Prevails</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;The recent convictions of the Sarah Palin email hacker, David Kennel, and the San Francisco system administrator, Terry Childs, are welcome events in the history of cyber crime.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;These transgressions are not victimless; they affect everyone.  One of the beauties of the Internet is its openness.  That openness is only works if people feel safe on the Internet.  When individuals take advantage of that freedom by abusing their privileges or infringing on the rights of others, &lt;/span&gt;&lt;span style="font-family:Trebuchet MS;"&gt;it harms all of us by whittling away at that trust.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;The Internet has revolutionized the way we live and that can only continue when people who violate the laws involving computer usage are punished severely.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6479365651235895438?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6479365651235895438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/05/justice-prevails.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6479365651235895438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6479365651235895438'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/05/justice-prevails.html' title='Justice Prevails'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6849029019042667489</id><published>2010-05-01T14:12:00.004-04:00</published><updated>2010-05-01T14:22:00.676-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Terry Childs'/><title type='text'>Is Terry Childs a Cyber Extortionist?</title><content type='html'>On Tuesday, April 27&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;th&lt;/span&gt;, a jury of his peers, which included a network engineer, convicted Terry &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Childs&lt;/span&gt; of a felony for withholding administrative access to the City of San Francisco's networks by refusing to hand over privileged user credentials.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;KTVU&lt;/span&gt;.com covers the story &lt;a href="http://www.ktvu.com/news/23283217/detail.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;His defense that his supervisors were not qualified to have the passwords is rather remarkable.  He was a "privileged user" because his employer placed him in that position, not because of any rights he held.  &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Childs&lt;/span&gt;' refusal to turn over the information to his superiors seems likes a pure case of extortion and a total misunderstanding of his responsibilities and I believe it is a good thing that he was convicted.  Another case of the laws starting to deal with new threats that we face in the Information Technology world in the 21st century.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6849029019042667489?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6849029019042667489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/05/is-terry-childs-cyber-extortionist.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6849029019042667489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6849029019042667489'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/05/is-terry-childs-cyber-extortionist.html' title='Is Terry Childs a Cyber Extortionist?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5864630212625651125</id><published>2010-04-03T09:07:00.008-04:00</published><updated>2010-04-03T09:28:58.879-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SMTP'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='McAfee VirusScan'/><title type='text'>SMTP Errors</title><content type='html'>The other day I was installing Varonis DatAdvantage for a customer and during the installation process received the following error, "&lt;span style="font-family:courier new;font-size:85%;"&gt;The message could not be sent to the SMTP server. The transport error code was 0x800ccc15."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/S7c_stdXIfI/AAAAAAAAADo/8LIeIZhGsHg/s1600/SMTP+Error.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 62px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5455899510932185586" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/S7c_stdXIfI/AAAAAAAAADo/8LIeIZhGsHg/s400/SMTP+Error.jpg" /&gt;&lt;/a&gt;The first thing I wanted to check was that I had connectivity to the Exchange Server. So I used telnet to connect to port 25. That worked fine, so there was not a firewall in place blocking the connection. The Exchange server was set up to accept relays so that was not the problem.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;After some investigation it turned out that McAfee VirusScan Enterprise 8.7.0 was the culprit.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/S7dBCKTfynI/AAAAAAAAADw/2-kdx98P1-4/s1600/McAfeeConsole.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 188px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5455900978964318834" border="0" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/S7dBCKTfynI/AAAAAAAAADw/2-kdx98P1-4/s400/McAfeeConsole.jpg" /&gt;&lt;/a&gt;Access Protection was enabled, so I reviewed the settings.  &lt;div&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/S7c_YXmSr_I/AAAAAAAAADg/1x2IBqWIBTs/s1600/McAfeeAccess.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 263px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5455899161466679282" border="0" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/S7c_YXmSr_I/AAAAAAAAADg/1x2IBqWIBTs/s400/McAfeeAccess.jpg" /&gt;&lt;/a&gt; The issue was the rule to "Prevent mass mailing worms from sending mail" was blocking all traffic from the Varonis server.  It was stopping all programs except those that are explicitly allowed from using SMTP to send messages.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_eFSy8U14xIE/S7c-lp7sCEI/AAAAAAAAADI/VLX4N2jjDfk/s1600/McAfeeRules.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 246px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5455898290214930498" border="0" alt="" src="http://4.bp.blogspot.com/_eFSy8U14xIE/S7c-lp7sCEI/AAAAAAAAADI/VLX4N2jjDfk/s400/McAfeeRules.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;Back to the McAfee server to add the programs in question and we are back in business.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5864630212625651125?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5864630212625651125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/04/smtp-errors.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5864630212625651125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5864630212625651125'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/04/smtp-errors.html' title='SMTP Errors'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/S7c_stdXIfI/AAAAAAAAADo/8LIeIZhGsHg/s72-c/SMTP+Error.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6258614246269647096</id><published>2010-03-17T21:19:00.003-04:00</published><updated>2010-03-17T21:22:50.412-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><title type='text'>Adobe Please Fix Your Software</title><content type='html'>I was configuring a new &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Varonis&lt;/span&gt; server today and needed to download Adobe Reader so that we can access the documentation.  I went to the Adobe web site and clicked on the download button. When I finish the installation, what do I find out?  That they are still installing 9.3.0 by default!  This is the &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;unpatched&lt;/span&gt; version that has been the subject of a number of exploits.  If a random user who doesn't deal with security on a daily basis installed this, they could be hosed.  I ran the updates, but many people wouldn't.  Adobe, please release a version that includes the patches built-in.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6258614246269647096?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6258614246269647096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/03/adobe-please-fix-your-software.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6258614246269647096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6258614246269647096'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/03/adobe-please-fix-your-software.html' title='Adobe Please Fix Your Software'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-69801375314576391</id><published>2010-02-23T14:10:00.002-05:00</published><updated>2010-02-23T14:17:43.775-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><category scheme='http://www.blogger.com/atom/ns#' term='Two-factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='encrpyion'/><title type='text'>Businesses Victims of On-line Bank Fraud</title><content type='html'>There have been a number of small business that have been getting ripped of through fraudulent wire transfers.  In one example, &lt;a href="http://www.krebsonsecurity.com/2010/02/it-firm-loses-100000-to-online-bank-fraud/"&gt;Krebs on Security&lt;/a&gt; covers the details of how an IT consulting firm lost nearly $100,000 through wire transfers it did not make.&lt;br /&gt;&lt;br /&gt;Customers need to make sure that their banks are using robust authentication, not just static passwords with additional questions to verify identity.  These are too easily captured by keyboard loggers or other spoofing devices.  The banks need to employ multi-factor authentication that cannot be victimized by the malware that is rampant throughout corporate America.&lt;br /&gt;&lt;br /&gt;In addition,  companies should be looking into keyboard encryption for computers that are accessing sensitive information.  Please reach out if you would like to learn about how to defend you and your business.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-69801375314576391?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/69801375314576391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/02/businesses-victims-of-on-line-bank.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/69801375314576391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/69801375314576391'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/02/businesses-victims-of-on-line-bank.html' title='Businesses Victims of On-line Bank Fraud'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5450022561234011669</id><published>2010-02-16T17:02:00.003-05:00</published><updated>2010-02-16T17:07:01.179-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Acrobat'/><category scheme='http://www.blogger.com/atom/ns#' term='Reader'/><title type='text'>Adobe Patches Reader and Acrobat Again</title><content type='html'>Security issues continue to crop up in Adobe Reader and Acrobat.  Adobe has issued patches for Reader and Acrobat to correct security issues.  Users should upgrade to version 9.3.1 of the software.  Click &lt;a href="http://www.bit.ly/aBVofX"&gt;here&lt;/a&gt; to see the Security Bulletin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5450022561234011669?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5450022561234011669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/02/adobe-patches-reader-and-acrobat-again.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5450022561234011669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5450022561234011669'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/02/adobe-patches-reader-and-acrobat-again.html' title='Adobe Patches Reader and Acrobat Again'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5853713887226892714</id><published>2010-02-13T11:26:00.003-05:00</published><updated>2010-02-13T13:29:14.913-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fatal System Error'/><title type='text'>Fatal System Error</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;We read every day about Eastern European crime syndicates that are involved in cybercrime, cyberwarfare, and other nefarious activities on the Internet. In many ways these organizations are block boxes, with very little information reported on who they are and how they work. Joseph Menn in his new book, “Fatal System Error,” tells the stories of two individuals, Barrett Lyon and Andrew Crocker, who have gone toe-to-toe with the evil hackers of the East. Menn has created a thrilling and informative work that delves into the specifics of these two Internet heroes. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;The book starts off telling the story of a young self-taught computer whiz named Barrett Lyon. Barrett becomes an expert in fighting off Denial of Service attacks. For those looking for an in-depth technical discussion of how Barrett wards off the attacks you will need to search elsewhere. The specific approaches that Prolexic takes are not described here; which in entirely appropriate in the context of how this story is told. Most of Barrett’s initial clients were in the Internet gambling business and were located out of the United States. He founds a company, Prolexic to provide a secure hosting environment to protect his clients from the Distributed Denial of Services attacks. Unfortunately for Barrett, the politics involved in running Prolexic get in the way of its mission and he decides to move on.&lt;br /&gt;One of the main goals of the attackers was to extort money from the gambling sites. After many episodes of defending against the numerous extortion attempts Barrett tries to fight back. He contacts the FBI on many occasions, without much success. However, in researching the attacks on BetCRIS, one of clients, he gets the involvement of Andrew Crocker of England’s National Hi-Tech Crime Unit.&lt;br /&gt;&lt;br /&gt;Menn expertly transitions the story to tales of Andrew Crocker. Crocker’s goal is to identity the criminals in Russia and bring them to justice. In the telling of this story, Menn sheds significant light on to why convicted these foes is such a challenge. At the core of the problem is that the Russian government does not want these people prosecuted. On the local level bribes of police and judicial employees keep the criminals out of jail. At the national level the criminal masterminds are protected by high-level operatives in the Russian government. They touch on the periphery of the Russian Business Network and speculate that the Russian government overlooks the illegal activities of these groups because they want to use this expertise to support political aims such as the suppression of dissent and information in places such as Georgia and Estonia.&lt;br /&gt;&lt;br /&gt;One of the conclusions that Menn and the investigators come to is that the protocols of the Internet need to be redesigned. They were developed by the US government to build a distributed, resilient network, as which they have been an enormous success. The protocols were not developed with security in mind; it was not a consideration 35 years ago. Policing the Internet with current policies is extremely difficult if not impossible because the countries of the world have different objectives and place different emphasis on these crimes.&lt;br /&gt;If you want a look into the Belly of the Beast, &lt;a href="http://www.amazon.com/gp/product/1586487485?ie=UTF8&amp;tag=tectipfrothec-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1586487485"&gt;Fatal System Error&lt;/a&gt;&lt;img src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;l=as2&amp;o=1&amp;a=1586487485" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /&gt;&lt;br /&gt;, is a great place to start. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5853713887226892714?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5853713887226892714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/02/we-read-every-day-about-eastern.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5853713887226892714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5853713887226892714'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/02/we-read-every-day-about-eastern.html' title='Fatal System Error'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7169224644105160662</id><published>2010-02-08T21:33:00.003-05:00</published><updated>2010-02-08T22:05:51.437-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DatAdvantage'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><title type='text'>Updating Varonis DA Immediately</title><content type='html'>Varonis DatAdvantage updates the Work Area's File Permissions and User Information on a nightly basis.  Sometimes,  after performing significant changes to improve your security you want to get a view of the current state your server.  To do that you need to run the nightly jobs.  You can run those jobs manually in two ways.  One is through the Configuration menu with the DA GUI.  The other, which I prefer, is to go directly to the SQL Management Studio to perform the jobs so I can monitor their progress.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/S3DJuoBOZdI/AAAAAAAAADA/q4N04kJVPBo/s1600-h/VaronisJobs.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 399px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5436066553089910226" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/S3DJuoBOZdI/AAAAAAAAADA/q4N04kJVPBo/s400/VaronisJobs.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Here are the steps:&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;1) Run the AD Walk(s)&lt;/div&gt;&lt;div&gt;2) Run the File Walk for each server that you have updated.&lt;/div&gt;&lt;div&gt;3) When those jobs are finished run the Pull Walk.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;After the Pull Walk is complete, you can restart the DatAdvantage UI and the permissions will be current.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7169224644105160662?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7169224644105160662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/02/updating-varonis-da-immediately.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7169224644105160662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7169224644105160662'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/02/updating-varonis-da-immediately.html' title='Updating Varonis DA Immediately'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/S3DJuoBOZdI/AAAAAAAAADA/q4N04kJVPBo/s72-c/VaronisJobs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5285966643515858070</id><published>2010-02-07T14:56:00.007-05:00</published><updated>2010-07-16T08:11:58.746-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Service Account'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Harden Your Service Accounts</title><content type='html'>In many cases we have service accounts that need powerful privileges to perform their tasks. This power also means that there is an elevated level of risk associanted with these accounts. They could be used inappropriately to access resources without accountability, since they are not tied directly to a person. There are two steps that I recommend that people follow in locking fown these accounts. Both of these activities involve starting &lt;strong&gt;Active Directory Users and Groups&lt;/strong&gt; and then selecting the &lt;strong&gt;Properties&lt;/strong&gt; options on the selected service acccout. First, select the &lt;strong&gt;Terminal Services Profile&lt;/strong&gt; and check the option to &lt;strong&gt;Deny this user permissions to log on to any Terminal Server&lt;/strong&gt;. The screen shot is listed here:&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/S28qSksPnHI/AAAAAAAAACo/8Ou8bMdoxcY/s1600-h/TerminalServices.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 334px; DISPLAY: block; HEIGHT: 400px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5435609773834738802" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/S28qSksPnHI/AAAAAAAAACo/8Ou8bMdoxcY/s400/TerminalServices.jpg" /&gt;&lt;/a&gt;Then we want to restrict the computers that the service account cal log into. This is found on the &lt;strong&gt;Account&lt;/strong&gt; tab. Once on this tab, click on the &lt;strong&gt;Log On To &lt;/strong&gt;command button. At this point enter the computer name(s) where the service account is used. This will limit the account to logging into only this machine.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_eFSy8U14xIE/S28rcjDALBI/AAAAAAAAAC4/K3ChciUBswY/s1600-h/LogonWorkstations.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 365px; DISPLAY: block; HEIGHT: 400px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5435611044703644690" border="0" alt="" src="http://4.bp.blogspot.com/_eFSy8U14xIE/S28rcjDALBI/AAAAAAAAAC4/K3ChciUBswY/s400/LogonWorkstations.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5285966643515858070?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5285966643515858070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/02/harden-your-service-accounts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5285966643515858070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5285966643515858070'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/02/harden-your-service-accounts.html' title='Harden Your Service Accounts'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/S28qSksPnHI/AAAAAAAAACo/8Ou8bMdoxcY/s72-c/TerminalServices.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-3716737504341145838</id><published>2010-01-26T12:08:00.002-05:00</published><updated>2010-01-26T12:13:04.889-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><title type='text'>Stop Monitoring a Server in Varonis</title><content type='html'>When you have a Windows server that is going offline, but you want to retain all the historical information in Varonis ( the events and permissions) here are the steps you need to follow.&lt;br /&gt;&lt;br /&gt;From within the Configuration Screen select &lt;strong&gt;File Servers&lt;/strong&gt;.  Then move to the server that you want to decommission.&lt;br /&gt;1) Uncheck all of the boxes for &lt;strong&gt;Collect Events.&lt;/strong&gt;&lt;br /&gt;2) Uncheck the box for &lt;strong&gt;Local Accounts.&lt;/strong&gt;&lt;br /&gt;3) For each drive make sure the &lt;strong&gt;Crawl File System&lt;/strong&gt; is set to &lt;strong&gt;Disable&lt;/strong&gt;.&lt;br /&gt;4) Click &lt;strong&gt;OK&lt;/strong&gt; and you are all set.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/S18hmaasfZI/AAAAAAAAACY/Sz0PRtw9RTU/s1600-h/VaronisConfigServers.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 379px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5431096619442142610" border="0" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/S18hmaasfZI/AAAAAAAAACY/Sz0PRtw9RTU/s400/VaronisConfigServers.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-3716737504341145838?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/3716737504341145838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/01/stop-monitoring-server-in-varonis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3716737504341145838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3716737504341145838'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/01/stop-monitoring-server-in-varonis.html' title='Stop Monitoring a Server in Varonis'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/S18hmaasfZI/AAAAAAAAACY/Sz0PRtw9RTU/s72-c/VaronisConfigServers.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6630590620865455660</id><published>2010-01-08T11:23:00.001-05:00</published><updated>2010-01-08T11:25:26.100-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>8 Predictions for 2010 on Document Management Security</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Each year there seem to be more and more breaches in information security. Some only cause embarrassment; others could cause harm. Take a look at this &lt;a href="http://bit.ly/8BQUIZ"&gt;list&lt;/a&gt; of my predictions that I prepared for AIIM.  Could you be affected by any of these items? If so, start locking down your information effectively.  I would love to hear your feedback.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6630590620865455660?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6630590620865455660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/01/8-predictions-for-2010-on-document.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6630590620865455660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6630590620865455660'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/01/8-predictions-for-2010-on-document.html' title='8 Predictions for 2010 on Document Management Security'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8469987986030113910</id><published>2010-01-07T21:13:00.001-05:00</published><updated>2010-01-07T21:15:42.391-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Acrobat'/><title type='text'>Adobe Issues Update on Security Issues with Reader and Acrobat</title><content type='html'>Adobe issued an advisory today giving more information about the securityissues with Adobe Acrobat and Reader. They plan to release a patch on January 12, 2010. Here is the &lt;a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html"&gt;security bulletin&lt;/a&gt; from Adobe.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8469987986030113910?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8469987986030113910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2010/01/adobe-issues-update-on-security-issues.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8469987986030113910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8469987986030113910'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2010/01/adobe-issues-update-on-security-issues.html' title='Adobe Issues Update on Security Issues with Reader and Acrobat'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-4178642159839487210</id><published>2009-12-26T15:17:00.004-05:00</published><updated>2009-12-26T15:30:44.406-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nicholas Carr'/><category scheme='http://www.blogger.com/atom/ns#' term='Cloud Computing'/><title type='text'>The Big Switch</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Cloud computing is all the rage. According to Nicholas Carr, one of the unstoppable drivers is the economics of cloud computing.  Carr uses the history of the electric industry to explain the historical forces that are in play today in the information technology market and that will move Information Technology to more and more of a utility computing model.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;There is an informative description of companies such as YouTube who generate tremendous value by providing a platform with a small number of employees that millions of people add value to for free.  This viral model has been used a number of times in the Internet space and is one of the forces that is negatively affecting traditional industries such as newspapers.&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Carr also covers a number of the social changes that are occurring, including the loss of privacy, which in some ways was the opposite effect that early Internet pioneers predicted.  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Trebuchet MS;"&gt;This is book is required reading for anyone who wants to understand the major forces that are moving the Information Technology field.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Buy &lt;a href="http://www.amazon.com/gp/product/0393333949?ie=UTF8&amp;amp;tag=tectipfrothec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0393333949"&gt;The Big Switch: Rewiring the World, from Edison to Google&lt;/a&gt;&lt;img style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; MARGIN: 0px; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" height="1" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0393333949" width="1" border="0" /&gt;&lt;br /&gt;from Amazon now.&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-4178642159839487210?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/4178642159839487210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/12/big-switch.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/4178642159839487210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/4178642159839487210'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/12/big-switch.html' title='The Big Switch'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-9195188515646843532</id><published>2009-12-22T12:41:00.003-05:00</published><updated>2009-12-22T12:49:21.201-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Acrobat'/><title type='text'>Adobe Reader is Vulnerable Again</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Back in May we first discussed the vulnerability in &lt;a href="http://castletips.blogspot.com/2009/05/adobe-acrobat-requires-critical.html"&gt;Adobe Reader&lt;/a&gt;.  Once again, an issue has cropped up.  I ask the question again, why doesn't Adobe release a standard verison of the reader without Javascript? Sure, it would disable some forms, but the bulk of users in the world want to read documents safely and not use forms.  They could certainly have a Premium Reader with Javascript support for those people that need it. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Here is the statement from them, "Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Here is a &lt;a href="http://www.adobe.com/support/security/advisories/apsa09-07.html"&gt;link&lt;/a&gt; to the security advisory.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-9195188515646843532?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/9195188515646843532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/12/adobe-reader-is-vulnerable-again.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/9195188515646843532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/9195188515646843532'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/12/adobe-reader-is-vulnerable-again.html' title='Adobe Reader is Vulnerable Again'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-658635438934347362</id><published>2009-12-01T18:14:00.003-05:00</published><updated>2009-12-01T18:16:54.229-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Infonomics'/><category scheme='http://www.blogger.com/atom/ns#' term='AIIM'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Who Stole Those Emails</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;I have started writing a column for Infonomics, the publishing portion of AIIM.  The first column covers the basics of Information Security.  Here is a link to &lt;a href="http://www.aiim.org/infonomics/who-stole-those-emails.aspx"&gt;The Article&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-658635438934347362?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/658635438934347362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/12/who-stole-those-emails.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/658635438934347362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/658635438934347362'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/12/who-stole-those-emails.html' title='Who Stole Those Emails'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8738511741759904481</id><published>2009-11-18T15:08:00.004-05:00</published><updated>2009-11-18T15:16:10.320-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Top 10'/><title type='text'>OWASP Releases 2010 - Top 10 Web Application Security Risks</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;OWASP (Open Web Application Security Project) released the preliminary version of the &lt;/span&gt;&lt;a title="OWASP Top 10" href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf" rel="nofollow"&gt;Top 10 Web Application Security Risks&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; in a Request for Comment format.&lt;br /&gt;&lt;br /&gt;According to OWASP they plan "to release the final public release of the OWASP Top 10 -2010 during the first quarter of 2010 after a final, one-month public comment period ending December 31, 2009. This release of the OWASP Top 10 marks this project’s eighth year of raising awareness of the importance of application security risks. This release has been significantly revised to clarify the focus on risk. To do this, we’ve detailed the threats, attacks, weaknesses, security controls, technical impacts, and business impacts associated with each risk. By adopting this approach, we hope to provide a model for how organizations can think beyond the ten risks here and figure out the most important risks that their applications create for their business."&lt;br /&gt;&lt;br /&gt;The full document can be found on the &lt;/span&gt;&lt;a title="OWASP Top 10" href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf" rel="nofollow"&gt;&lt;span style="font-family:trebuchet ms;"&gt;OWASP web site&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;.&lt;br /&gt;&lt;br /&gt;The OWASP Top Ten has been a key driver in improving the security of Web applications across many industries. If you have any questions please ask Arthur, who is an active OWASP member.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8738511741759904481?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8738511741759904481/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/11/owasp-releases-2010-top-10-web.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8738511741759904481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8738511741759904481'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/11/owasp-releases-2010-top-10-web.html' title='OWASP Releases 2010 - Top 10 Web Application Security Risks'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5867884608167993503</id><published>2009-11-01T19:36:00.003-05:00</published><updated>2009-11-01T19:49:55.314-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Laserjet 3100'/><title type='text'>HP Laserjet 3100 on Vista or Windows 7</title><content type='html'>I have a wonderful HP Laserjet 3100 that is still working reliably after seven years of use. I recently added a new laptop that is running Vista Business (no choice in the matter) to my stable of machines. I still want to use this printer with the Vista machine, but HP has no drivers for the printer. What to do?&lt;br /&gt;&lt;br /&gt;The printer is connected to a machine on my network running Windows XP Professional.&lt;br /&gt;&lt;br /&gt;1) I added a new printer on the Windows XP machine without using Plug and Play. It was set up as an HP LaserJet II Series printer connected to LPT1 (The parallel port).&lt;br /&gt;2) I shared out the printer as \\Machine\HPLJII&lt;br /&gt;3) I went to the Vista laptop and added a network printer. Of course it didn't discover it so I clicked on the option "The printer I want isn't listed."&lt;br /&gt;4) I manually entered the Share \\Machine\HPLJII, which the Vista machine recognized as a LaserJet II and &lt;strong&gt;bingo&lt;/strong&gt; I was up and running.&lt;br /&gt;&lt;br /&gt;This solution should work for a Windows 7 machine as well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5867884608167993503?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5867884608167993503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/11/hp-laserjet-3100-on-vista-or-windows-7.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5867884608167993503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5867884608167993503'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/11/hp-laserjet-3100-on-vista-or-windows-7.html' title='HP Laserjet 3100 on Vista or Windows 7'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7235430449521788674</id><published>2009-10-27T22:52:00.004-04:00</published><updated>2009-10-27T22:59:48.681-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LinkedIn'/><category scheme='http://www.blogger.com/atom/ns#' term='Garden State Chapter'/><category scheme='http://www.blogger.com/atom/ns#' term='AIIM'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><title type='text'>AIIM Garden State Chapter Meeting - November 12th</title><content type='html'>I am attending the AIIM Garden State Chapter meeting on November 12, 2009.&lt;br /&gt;&lt;br /&gt;The topic is "Social Media All You Need To Know: A to Z"&lt;br /&gt;&lt;br /&gt;The meeting is at the Woodbridge Hilton, 120 Wood Avenue South -- Iselin, NJ&lt;br /&gt;&lt;br /&gt;Key Takeaways:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Learn how to setup Twitter, LinkedIn and Facebook &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Learn how to use Social Media to be found, find talent and promote your company&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Learn what and how enterprise tools are utilizing Twitter, LinkedIn and Facebook&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Speaker(s) &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Michael Potters, The Glenmont Group &lt;/li&gt;&lt;li&gt;Rahul Nirula, OpenText&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="center"&gt;Meet with some of New Jersey's top IT recruiters at this event&lt;br /&gt;Event Time Registration &amp;amp; hors d'oeuvres / Networking opportunities: 5:30 - 6:30 pm Presentation: 6:30 – 8:00 pm Dessert / Networking opportunities: 8:00- 8:30 pm&lt;br /&gt;Fees* AIIM Members $30Non-Members $35On-Site + $10 &lt;/p&gt;&lt;br /&gt;&lt;p align="center"&gt;&lt;br /&gt;&lt;a href="http://www.mmsend2.com/ls.cfm?r=127761844&amp;amp;sid=7784751&amp;amp;m=852003&amp;amp;u=AIIM2&amp;amp;s=http://www.aiimgsc.org/regform.htm"&gt;REGISTER ONLINE&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p align="left"&gt;I hope to see you there!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7235430449521788674?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7235430449521788674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/10/aiim-garden-state-chapter-meeting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7235430449521788674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7235430449521788674'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/10/aiim-garden-state-chapter-meeting.html' title='AIIM Garden State Chapter Meeting - November 12th'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7687998378124519577</id><published>2009-09-08T10:52:00.004-04:00</published><updated>2009-09-08T11:17:11.296-04:00</updated><title type='text'>The Hacker Turned Serial Killer</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Just finished a very entertaining book, &lt;/span&gt;&lt;a href="http://www.amazon.com/gp/product/0316166308?ie=UTF8&amp;amp;tag=tectipfrothec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0316166308" target="_blank"&gt;The Scarecrow&lt;/a&gt;&lt;img style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; MARGIN: 0px; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" height="1" alt="" src="http://www.assoc-amazon.com/e/ir?t=tectipfrothec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0316166308" width="1" border="0" /&gt;,&lt;span style="font-family:trebuchet ms;"&gt; by Michael Connelly&lt;/span&gt;.&lt;span style="font-family:trebuchet ms;"&gt; I am not regularly a reader of crime fiction, but a friend who knew about my interest in information security suggested it to me. I really enjoyed it and was spooked by the effectiveness of the hacker. WIthout giving away any of the story, the hacker uses social engineering, trojan horses, viruses, and other nefarious techniques to further his criminal activities. I highly recommend it; you may just take better care of your personal information after reading it.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7687998378124519577?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7687998378124519577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/09/hacker-turned-serial-killer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7687998378124519577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7687998378124519577'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/09/hacker-turned-serial-killer.html' title='The Hacker Turned Serial Killer'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-1132843038806687559</id><published>2009-08-20T22:54:00.008-04:00</published><updated>2009-08-21T09:50:07.901-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Restoring Deleted Permissions with Varonis</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_eFSy8U14xIE/So4N287qGUI/AAAAAAAAABs/Gb72PZ3yCa8/s1600-h/UsesGroups.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5372246643220027714" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 329px; CURSOR: hand; HEIGHT: 220px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_eFSy8U14xIE/So4N287qGUI/AAAAAAAAABs/Gb72PZ3yCa8/s400/UsesGroups.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;This afternoon a hedge fund client called with a high profile problem. One of the system admins from their outsourcer had deleted all of the Active Directory permissions of the General Counsel. Not a great person to prevent from accessing the system. Since they are a Varonis DatAdvantage user, I was able to help them solve this problem.&lt;br /&gt;&lt;br /&gt;We ran a query from the log area and selected "History of differences" as the data source. The keys were to set the "File Server" to "IDU" and set the "Change Description" to start with his fully defined domain account. Then we got a list of all of the groups that he belogned to and my client was able to restore them all and get the General Counsel up and running ASAP.&lt;br /&gt;&lt;br /&gt;DatAdvantage to the rescue.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-1132843038806687559?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/1132843038806687559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/restoring-deleted-permissions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1132843038806687559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1132843038806687559'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/restoring-deleted-permissions.html' title='Restoring Deleted Permissions with Varonis'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_eFSy8U14xIE/So4N287qGUI/AAAAAAAAABs/Gb72PZ3yCa8/s72-c/UsesGroups.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2429615988819362523</id><published>2009-08-19T09:22:00.001-04:00</published><updated>2009-08-19T09:30:00.531-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gonzalez'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Heartland'/><title type='text'></title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Kudos to the Department of Justice for the indictment of Albert Gonzalez and two of his coconspirators.  With all of the high profile data breaches occurring we need to take a deeper look at what is going on here.  While TJX and Heartland may have been PCI compliant, they were still breached.  The issue with most security approaches is that they focus primarily on “preventative” controls.  There are not enough “detective” controls in place to make sure that if one of the preventative controls fails, there is someone or something there to notice.  No defense is impenetrable and that is why we practice “defense in depth.”&lt;br /&gt;&lt;br /&gt;In the case of Heartland Payments Systems, it is alleged that the hackers were siphoning off data for months and it wasn’t until Visa and MasterCard noticed the fraud, that Heartland found the breach.  Some questions that companies should be asking themselves include:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;ul&gt;&lt;li&gt;Do you have in place a process to review audit logs from your firewalls and core routers on a regular basis?&lt;/li&gt;&lt;li&gt;Do you have a process in place to monitor the activities of privileged users and system accounts?&lt;/li&gt;&lt;li&gt;Do you have a formal entitlement review to verify that security is granted in a “least privilege” model?&lt;/li&gt;&lt;li&gt;Do you audit database and file system activity?&lt;/li&gt;&lt;li&gt;If any user was accessing an unusual amount of data, would anyone notice?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;I would appreciate hearing your thoughts on these questions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2429615988819362523?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2429615988819362523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/kudos-to-department-of-justice-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2429615988819362523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2429615988819362523'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/kudos-to-department-of-justice-for.html' title=''/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-1014634310853515926</id><published>2009-08-11T09:12:00.003-04:00</published><updated>2009-08-11T09:17:26.414-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><category scheme='http://www.blogger.com/atom/ns#' term='Garden State Chapter'/><category scheme='http://www.blogger.com/atom/ns#' term='AIIM'/><title type='text'>AIIM SharePoint Event - September 17, 2009</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;On September 17 , 2009 the AIIM International Garden State Chapter is hosting a Panel Discussion and Networking Event and I will be one of the panelists.  Here is some info in case you are interested in attending.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;a href="http://www.aiimgsc.org/"&gt;Register Here! &lt;/a&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;Panel Topic: MS SharePoint – where is it headed?&lt;br /&gt;&lt;br /&gt;·   How is MS SharePoint different from traditional ECM products&lt;br /&gt;·   How well does MS SharePoint integrate with other ECM products&lt;br /&gt;·   What are the top ECM products being integrated with MS SharePoint&lt;br /&gt;·   How are companies leveraging MS SharePoint&lt;br /&gt;·   What are the "hot skills" in demand around the MS SharePoint&lt;br /&gt;&lt;br /&gt;Panel Members:&lt;br /&gt;&lt;br /&gt;·   Allan Schweighardt, Senior Technology Strategist, Microsoft&lt;br /&gt;·   Joe Giegerich, President / Managing Partner, Gig Werks&lt;br /&gt;·   Kenneth Shea, Former Executive Director of Enabling Technology, KPMG&lt;br /&gt;·   Arthur Hedge III, President, Castle Ventures&lt;br /&gt;&lt;br /&gt;Networking:&lt;br /&gt;&lt;br /&gt;·   Network, Network, Network!!&lt;br /&gt;·   Meet and talk with individuals from the industry&lt;br /&gt;·   Meet some top New Jersey's recruiters in the MS SharePoint space&lt;br /&gt;&lt;br /&gt;Meeting Agenda&lt;br /&gt;&lt;br /&gt;5:30 - 6:30 pm  - Registration &amp;amp; hors d'oeuvres Networking opportunities&lt;br /&gt;6:30 - 7:30 pm -  Panel Discussion&lt;br /&gt;7:30 - 8:30 pm  - Dessert: Networking opportunities&lt;br /&gt;&lt;br /&gt;Location:&lt;br /&gt;&lt;br /&gt;The Woodbridge Hilton&lt;br /&gt;120 Wood Avenue South&lt;br /&gt;Iselin, NJ 08830&lt;br /&gt;Tel: 732-494-6200&lt;br /&gt;&lt;br /&gt;Fees:*&lt;br /&gt;&lt;br /&gt;AIIM Members  $30&lt;br /&gt;Non-Members  $35&lt;br /&gt;On-Site  + $10&lt;br /&gt;&lt;br /&gt;*$10 discount for early registration (September 10th deadline)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.aiimgsc.org/"&gt;Register Here! &lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Hope to see you there.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-1014634310853515926?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/1014634310853515926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/aiim-sharepoint-event-september-17-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1014634310853515926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1014634310853515926'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/aiim-sharepoint-event-september-17-2009.html' title='AIIM SharePoint Event - September 17, 2009'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-323222509545920709</id><published>2009-08-07T12:40:00.002-04:00</published><updated>2009-08-07T12:44:01.748-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacked'/><title type='text'>YouTube Hacked?</title><content type='html'>Yesterday, Twitter and Facebook were attacked.  Is YouTube being hacked today?  There is a video about a healthcare protest that is not having its view counter updated.  People have been commenting that the counter has been stuck at 1,338 views for a while.  Has someone hacked into YouTube or is it just a bug?&lt;br /&gt;&lt;br /&gt;Here is a link to the &lt;a href="http://www.youtube.com/watch?v=_kxaGfClPws"&gt;video&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-323222509545920709?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/323222509545920709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/youtube-hacked.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/323222509545920709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/323222509545920709'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/youtube-hacked.html' title='YouTube Hacked?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-930277784015085830</id><published>2009-08-05T09:58:00.006-04:00</published><updated>2010-02-13T13:28:37.677-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='domain name'/><title type='text'>Hacker Steals Domain Name</title><content type='html'>&lt;div&gt;The New Jersey State Police arrested a man who allegedly stole the P2P.com domain name.  SC Magazine provides the details in this article "&lt;a href="http://www.scmagazineus.com/Hacker-charged-with-domain-name-theft/article/141182/"&gt;Hacker charged with domain name theft."&lt;/a&gt;  What is troubling is that domain owners do not adequately protect their domain names.  We have an offering that will analyze your risks for only $249.  Please visit our &lt;a href="http://www.castleventures.com/domainassess.html"&gt;website &lt;/a&gt;to learn more.&lt;/div&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;Please protect your Domain information.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-930277784015085830?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/930277784015085830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/hacker-steals-domain-name.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/930277784015085830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/930277784015085830'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/hacker-steals-domain-name.html' title='Hacker Steals Domain Name'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-3730640770751515813</id><published>2009-08-04T16:26:00.004-04:00</published><updated>2009-08-04T23:37:03.718-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Reporting Services'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server 2005'/><title type='text'>SQL Server 2005 on Windows Server 2008</title><content type='html'>If you want to install &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SQL&lt;/span&gt; Server 2005 with Reporting &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Services&lt;/span&gt; on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Windows &lt;/span&gt;Server 2008 you have to jump through a few hoops. Reporting Services is dependent on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;IIS&lt;/span&gt; 6 and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;SQL&lt;/span&gt; Server 2008 runs &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;IIS&lt;/span&gt; 7. However, there is the capability to emulate II6, which is critical to making this work.&lt;br /&gt;&lt;br /&gt;There is a great blog post on this issue at &lt;a href="http://www.igregor.net/post/2008/01/Installing-SQL-Server-2005-Reporting-Service-on-IIS-7.aspx"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;iGregor&lt;/span&gt;&lt;/a&gt;, where he walks you through the exact configuration options to make this work.&lt;br /&gt;&lt;br /&gt;Hope this helps all those who see that grayed out Reporting Services box in &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;SQL&lt;/span&gt; Server 2005 install and are shaking their heads.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-3730640770751515813?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/3730640770751515813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/sql-server-2005-on-sql-server-2008.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3730640770751515813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/3730640770751515813'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/sql-server-2005-on-sql-server-2008.html' title='SQL Server 2005 on Windows Server 2008'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5754400879679353900</id><published>2009-08-03T09:44:00.003-04:00</published><updated>2009-08-03T09:45:52.898-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint Users Group'/><title type='text'></title><content type='html'>I am planning to attend the August 5&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;th&lt;/span&gt; New York &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;SharePoint&lt;/span&gt; User Group meeting. It always well attended with somewhere between 50 and 150 people depending upon the evening. The meetings are the first Wednesday of the month at the Microsoft office in New York City.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.clicktoattend.com/invitation.aspx?code=139385"&gt;Click here to register.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope to see you there&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5754400879679353900?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5754400879679353900/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/08/i-am-planning-to-attend-august-5-th-new.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5754400879679353900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5754400879679353900'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/08/i-am-planning-to-attend-august-5-th-new.html' title=''/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8093628567643909003</id><published>2009-07-29T08:52:00.006-04:00</published><updated>2009-07-29T09:12:42.169-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Senator Leahy'/><category scheme='http://www.blogger.com/atom/ns#' term='Cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Personal Data Privacy and Security Act.'/><title type='text'>Is Senator Leahy a Capitalist?</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;On July 22, 2009 Senator Patrick &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Leahy&lt;/span&gt; (D-VT) introduced the "&lt;a href="http://leahy.senate.gov/press/200907/072209b.html"&gt;Personal Data Privacy and Security Act"&lt;/a&gt; to combat the growing number of data breaches. As of July 24, 2009 the Privacy Rights Clearing House had calculated &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#CP"&gt;263,214,232 &lt;/a&gt;records had been "lost." They are posting new breaches every week; and these are just those that are public knowledge.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;We applaud Senator &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Leahy&lt;/span&gt; for tackling this important issue as it threatens the trust in the financial systems that we use and have become central to the American way of life.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;However, several things strike me about the proposed &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;legislation&lt;/span&gt; that protect the data brokers and not individuals. First in Section 303 dealing with the "Privacy and Security of Personally &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Identifiable&lt;/span&gt; Information" there is a prohibition against "private action." That protects the data brokers from being sued by the people that have been adversely affected by a data breach. If someone is defrauded out of tens of thousands of dollars because a company lost their records, there is no recourse to sue and try to recover damages and associated costs in dealing with the identify theft. How does that protect the consumer?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Second, Section 316 gives a breached organization 14 days to report the breach to law enforcement agencies (the Secret Service in this case). That is way too long. In 14 days hundreds of thousands of those records could be resold by hackers and be used in fraudulent transactions. &lt;strong&gt;Why not make the notification requirement 24 hours?&lt;/strong&gt; Better safe than sorry.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;More to follow on this legislation as it is a step in the right direction.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8093628567643909003?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8093628567643909003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/07/is-senator-leahy-capitalist.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8093628567643909003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8093628567643909003'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/07/is-senator-leahy-capitalist.html' title='Is Senator Leahy a Capitalist?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2715492833848781889</id><published>2009-07-13T21:51:00.003-04:00</published><updated>2009-07-17T10:26:27.193-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><title type='text'>Identify Theft Comes to Payday Loans</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;According to the &lt;a href="http://www.chicagobreakingnews.com/2009/07/att-temp-charged-with-stealing-co-worker-info.html?obref=obinsite"&gt;Chicago Tribune&lt;/a&gt; a temporary worker from AT&amp;amp;T, Cassandra Walls, stole information on a number of her co-workers and took out at least 130 loans in their names. Some of the victims found out they had been scammed when collection agencies began calling them.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Let's hope that this identify thief and her co-&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;conspirators&lt;/span&gt; are able to compensate all of their victims, even if they have to wait until they get out of prison.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2715492833848781889?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2715492833848781889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/07/identify-theft-comes-to-payday-loans.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2715492833848781889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2715492833848781889'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/07/identify-theft-comes-to-payday-loans.html' title='Identify Theft Comes to Payday Loans'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6197604444889202770</id><published>2009-07-10T12:38:00.005-04:00</published><updated>2009-07-10T12:54:52.734-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Goldman Sachs'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Aleynikov'/><title type='text'>Goldman Sachs Data Breach</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Earlier this week the FBI arrested &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Sergey&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Aleynikov&lt;/span&gt; for the theft of proprietary software from his employer, Goldman Sachs.  The &lt;a href="http://www.castleventures.com/complaintaleynikov.pdf"&gt;complaint&lt;/a&gt; is fascinating in providing insight as to what a leading financial institution is doing to protect its &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_2"&gt;intellectual&lt;/span&gt; property.  Here are some of the items that they had in place (we know there are more controls that were not revealed in the document):&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Scanned and analyzed outgoing mail&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Prohibited file transfers using ftp to outside locations&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Recorded commands performed on the user's desktop&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Logged access to systems&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Monitored https traffic&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Sergey&lt;/span&gt; was a &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;sophisticated&lt;/span&gt; insider with technical skills who tried to cover his tracks, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;unfortunately&lt;/span&gt; for him, the security folks at Goldman Sachs were several steps ahead of him.  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;One other lesson that we should learn from the affidavit is that:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;1) They had a written security policy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;2) That put tools in place to support that policy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;3) They had a security &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;architecture&lt;/span&gt; in place to detect when the policy was being violated.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Kudos to the security team at Goldman and the FBI agents who arrested &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Aleynikov&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6197604444889202770?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6197604444889202770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/07/goldman-sachs-data-breach.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6197604444889202770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6197604444889202770'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/07/goldman-sachs-data-breach.html' title='Goldman Sachs Data Breach'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7904353068914657990</id><published>2009-06-17T15:27:00.002-04:00</published><updated>2009-06-17T15:35:16.629-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><title type='text'>New York SharePoint Users Group Meeting - July 1</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;I am planning to attend the July 1st &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SharePoint&lt;/span&gt; User Group meeting.  It always well attended 50 to 150 people depending upon the evening.  The meetings are the first Wednesday of the month at the Microsoft office in New &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;York&lt;/span&gt; City.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sharepointusergroup.org/NewYork/default.aspx"&gt;http://www.sharepointusergroup.org/NewYork/default.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope to see you there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7904353068914657990?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7904353068914657990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/06/new-york-sharepoint-users-group-meeting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7904353068914657990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7904353068914657990'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/06/new-york-sharepoint-users-group-meeting.html' title='New York SharePoint Users Group Meeting - July 1'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-658420192584935894</id><published>2009-06-16T20:13:00.002-04:00</published><updated>2009-06-17T15:55:27.955-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VB Script'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server 2005'/><title type='text'>Renaming SQL Backup Files</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;If you use a SQL 2005 Maintenance Plan to create backups of individual databases, the &lt;strong&gt;.bak&lt;/strong&gt; files have a date stamp on them. I have a customer that wants to handle the files with an automated tool and would prefer that the backup files have a consistent name. We could backup up the databases en masse, but we wanted separate backups for this purpose.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;The solution was to create a VB script that runs as a scheduled task and renames the files every night after the backups are run. Here is the code that I wrote to handle renaming all of the files. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;-------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/SjlIGANtHcI/AAAAAAAAAA0/B0vNvatwEM4/s1600-h/SQLRenameBlog.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5348385300453072322" style="WIDTH: 320px; CURSOR: hand; HEIGHT: 145px" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/SjlIGANtHcI/AAAAAAAAAA0/B0vNvatwEM4/s320/SQLRenameBlog.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:trebuchet ms;"&gt;------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family:trebuchet ms;"&gt;Note: this will fail in 2100. Just setting up some Y2100 work for your grandchildren.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-658420192584935894?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/658420192584935894/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/06/renaming-sql-backup-files.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/658420192584935894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/658420192584935894'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/06/renaming-sql-backup-files.html' title='Renaming SQL Backup Files'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_eFSy8U14xIE/SjlIGANtHcI/AAAAAAAAAA0/B0vNvatwEM4/s72-c/SQLRenameBlog.PNG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5570042358758006482</id><published>2009-06-06T08:57:00.007-04:00</published><updated>2009-06-06T09:10:10.397-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory Security Groups</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Yesterday, during a Varonis training session, Paul Ezhaya started a great discussion by asking my opinion on strategies for naming security groups and organizing folders on file servers. The primary debate was whether to use security groups named after departments and roles or to use security groups named after folders that they provide access to. For example, if there was folder called Human Resources with sub-folders such as Employee Data, Forms, and Terminations, and folders specific to several departments how would we set this up from a security perspective? Would we create Active Directory groups based on Roles for the HR people who handle each department and then apply those groups to the corresponding folders on the file server? Or would we create AD groups named after the specific sub-folders and then add the specific people to those groups as needed? Along with the security groups we would take the lead in organizing the folder structure to match the security group naming conventions.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p align="left"&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/SipodPmyaBI/AAAAAAAAAAs/-O_GyeixNnc/s1600-h/FolderStructure.JPG"&gt;&lt;/a&gt;&lt;/p&gt;&lt;p align="center"&gt;&lt;/p&gt;&lt;p align="center"&gt;&lt;a href="http://3.bp.blogspot.com/_eFSy8U14xIE/SipodPmyaBI/AAAAAAAAAAs/-O_GyeixNnc/s1600-h/FolderStructure.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5344198759443228690" style="WIDTH: 396px; CURSOR: hand; HEIGHT: 225px" alt="" src="http://3.bp.blogspot.com/_eFSy8U14xIE/SipodPmyaBI/AAAAAAAAAAs/-O_GyeixNnc/s320/FolderStructure.JPG" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style="font-family:trebuchet ms;"&gt;There is no “right” answer, but here are some of my thoughts on the Role versus Folder question.&lt;br /&gt;&lt;br /&gt;In general, I prefer the Folder-based solution. The first reason is for the long-term security of your organization. Finding the data is always top priority so regardless of how you organize the folders; users will learn the taxonomy and adjust to it. You need to force the organization to apply security; therefore, if you organize the infrastructure in a secure manner, they won’t have to. Second, When you first set up your Role-based Security Groups you might have an accurate grouping of the users by department. However, over time people will not make the appropriate adjustments to those groups. After the initial setup fades away, when you add someone to a role-based security group to they can access a particular set of data, you may not realize what else that gives them access to. You may not it even give it any consideration because security will always be an afterthought. In a Folder-based solution, the security of the data is pushed to the forefront as the IT department knows what folders the Active Directory group gives them access to. And if the access is insufficient user will surely let you know, where the odds of them notifying you that they were given too much access in the Role-based scenario is highly unlikely.&lt;br /&gt;&lt;br /&gt;Of course, we may have a hybrid approach. At the top level shares we might want to have security groups for the department and apply those at that level. Then we would turn off inheritance on folders with confidential data and apply the folder-based security to those folders. So we end up with a set of groups like this:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;grp_HumanResources&lt;br /&gt;grp_Terminations-RO&lt;br /&gt;grp_Terminations-RW&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Where RO is for the group with Read Only privileges and RW is the group with Modify privileges.&lt;br /&gt;&lt;br /&gt;If there are other reasons for you to use a Role-based strategy then I would highly recommend an automated Identify Access Management system. I think that you will still find that the default will be to provide too much access, but the results will be better. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5570042358758006482?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5570042358758006482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/06/yesterday-during-varonis-training.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5570042358758006482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5570042358758006482'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/06/yesterday-during-varonis-training.html' title='Active Directory Security Groups'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_eFSy8U14xIE/SipodPmyaBI/AAAAAAAAAAs/-O_GyeixNnc/s72-c/FolderStructure.JPG' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7494826588783745331</id><published>2009-05-26T21:17:00.004-04:00</published><updated>2009-06-09T08:55:36.254-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><category scheme='http://www.blogger.com/atom/ns#' term='ECM'/><category scheme='http://www.blogger.com/atom/ns#' term='AIIM'/><category scheme='http://www.blogger.com/atom/ns#' term='SAAS'/><title type='text'>AIIM Garden State Chapter Meeting - Software as a Service</title><content type='html'>&lt;span style="font-family:Trebuchet MS;"&gt;I am a member of AIIM, which is a trade association and professional organization focused on the Enterprise Content Management market. The Garden State Chapter of AIIM is holding its next meeting on June 18, 2009 at the Woodbridge Hilton. The meeting starts at 5:00 p.m. and goes until 8:00 p.m.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;There is a Panel Discussion: With panelists from Adobe, SpringCM and IPS covering &lt;/span&gt;"&lt;span style="font-family:trebuchet ms;"&gt;Software as a Service (SaaS) - a Better Solution?"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;Does SaaS deliver on its promise to lower ECM costs? &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;Where does it fit in the market vs. ho&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;sted and in-house models? &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;Learn how companies are leveraging SaaS technologies Hear what the "hot skills" are in SaaS&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Go to the Garden State Chapter &lt;a href="http://www.aiimgsc.org/"&gt;web site&lt;/a&gt; to register.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;There are plenty of networking opportunities as well.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Hope to see you there.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7494826588783745331?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7494826588783745331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/05/aiim-garden-state-chapter-meeting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7494826588783745331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7494826588783745331'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/05/aiim-garden-state-chapter-meeting.html' title='AIIM Garden State Chapter Meeting - Software as a Service'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-1237501585299088445</id><published>2009-05-19T23:29:00.001-04:00</published><updated>2009-05-19T23:37:37.002-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDF'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Adobe Acrobat Requires Critical Security Update</title><content type='html'>It is astonishing that software that was created to present documents in a "neutral format", Adobe Acrobat, can be hacked.  Another case of taking a great product and adding features that eventually take the software far beyond the original architecture and creating security vulnerabilities.&lt;br /&gt;&lt;br /&gt;Why is JavaScript even an option in PDF files?  PDF files were suppossed to be the safe alternative to documents that you might receive in formats such as Word.  I guess that has gone by the wayside.&lt;br /&gt;&lt;br /&gt;Here is the &lt;a href="http://www.adobe.com/support/security/bulletins/apsb09-06.html"&gt;link &lt;/a&gt;to Adobe's update site. &lt;br /&gt;&lt;br /&gt;US-CERT has more detail about the vulnerabilities and other workarounds and protection methods on their &lt;a href="http://www.us-cert.gov/cas/techalerts/TA09-133B.html"&gt;web site&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-1237501585299088445?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/1237501585299088445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/05/adobe-acrobat-requires-critical.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1237501585299088445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/1237501585299088445'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/05/adobe-acrobat-requires-critical.html' title='Adobe Acrobat Requires Critical Security Update'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8948825751978912429</id><published>2009-05-15T15:23:00.000-04:00</published><updated>2009-05-15T15:35:53.870-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><category scheme='http://www.blogger.com/atom/ns#' term='ECM'/><category scheme='http://www.blogger.com/atom/ns#' term='AIIM'/><title type='text'>AIIM New York Metro Chapter Presentation - May 15, 2009</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;I gave a presentation today to the New York Metro Chapter of AIIM on&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;strong&gt;"Is SharePoint the future of Enterprise Content Management?"&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I &lt;span &gt;described&lt;/span&gt; how SharePoint fits into the traditional ECM Marketplace, where it succeeds, where it falls short, and where it ventures far beyond ECM.  Audience participation was great.  We discussed where SharePoint is an appropriate solution for organizations and some of the challenges in implementing SharePoint to solve business problems.  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Here is a copy of the &lt;a href="http://www.castleventures.com/CastleVenturesAIIMNYSharePointFuture.pdf"&gt;presentation&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8948825751978912429?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8948825751978912429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/05/aiim-new-york-metro-chapter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8948825751978912429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8948825751978912429'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/05/aiim-new-york-metro-chapter.html' title='AIIM New York Metro Chapter Presentation - May 15, 2009'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2387269326700437376</id><published>2009-05-04T20:31:00.000-04:00</published><updated>2009-05-04T21:07:37.715-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DatAdvantage'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>TechRepublic Reviews Varonis Suite</title><content type='html'>The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;TechRepublic&lt;/span&gt; blogger Mark Kaelin has a review of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Varonis&lt;/span&gt; Data Governance suite.&lt;br /&gt;&lt;br /&gt;Here is a &lt;a href="http://blogs.techrepublic.com.com/products/?p=342"&gt;link to the review&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Nice to see the product get some coverage, since it is the greatest thing since sliced bread (actually since &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;VMware&lt;/span&gt;).  The review mentioned three things that are wrong with the product, I take issue with two of them. &lt;br /&gt;&lt;br /&gt;Issue 1 that I disagree with:&lt;br /&gt;&lt;br /&gt;"Culture shock: The general principle of placing decision making concerning data governance in the hands of employees deep in the organization may be a significant change of policy for many established organizations, especially those with established hierarchical structures and controlling IT departments. "&lt;br /&gt;&lt;br /&gt;One of the advantages of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Varonis&lt;/span&gt; solution is that you can start small, with one directory if you want, so that there is no need for any culture shock.  Security provisioning by the user community can be rolled out as slowly or as quickly as the organization can handle.&lt;br /&gt;&lt;br /&gt;Issue 2 that I disagree with:&lt;br /&gt;&lt;br /&gt;"Cost and scope: The scope of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;Varonis&lt;/span&gt; Data Governance Suite 4.0 does not come cheap. Not only will the entire organization have to buy-in to the concept, the initial software installation and training cost will be significant. This suite of software is most likely to be used in larger organizations with very specific and vital data governance needs. "&lt;br /&gt;&lt;br /&gt;The cost of the solution relative to the value of the data is not significant and in terms of improved efficiency of IT administration the product more than justifies the cost.  We have a number of customers that are small (250 users) and see significant &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;benefit&lt;/span&gt; from the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;DatAdvantage&lt;/span&gt; product.  Again the "enterprise" buy in is not a necessity for implementing the solution.  Behind the scenes the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;DatAdvantage&lt;/span&gt; solution monitors and reports and access without disturbing anyone and the Data Privilege component can be rolled out directory by directory if you so desire.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2387269326700437376?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2387269326700437376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/05/techrepublic-reviews-varonis-suite.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2387269326700437376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2387269326700437376'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/05/techrepublic-reviews-varonis-suite.html' title='TechRepublic Reviews Varonis Suite'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8526383592376635646</id><published>2009-05-03T09:16:00.000-04:00</published><updated>2009-05-03T09:19:27.545-04:00</updated><title type='text'>How to we keep users aware of security concerns?</title><content type='html'>An organization can only be successful in securing its data and assests if it is a company-wide effort.  Most security failures involve a technical failure(s) as well as a human failure, through social engineering as an example.  One of the challenges that we face in dealing with the user community is that we need them to be vigiliant all the time even though the threats that we face come very rarely (or hopefully not at all).  I have several thoughts:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Design systems to take the rarity of threats into account and design better "detection" systems in addition to better "prevention" systems.&lt;/li&gt;&lt;li&gt;Vary the reminders that people get about security so they don't become oblivious to them.&lt;/li&gt;&lt;li&gt;Make sure that we design systems so they fail safely.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8526383592376635646?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8526383592376635646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/05/how-to-we-keep-users-aware-of-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8526383592376635646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8526383592376635646'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/05/how-to-we-keep-users-aware-of-security.html' title='How to we keep users aware of security concerns?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-8367040861538979025</id><published>2009-04-28T12:43:00.000-04:00</published><updated>2009-04-29T09:34:49.158-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='administrator'/><category scheme='http://www.blogger.com/atom/ns#' term='privileged account'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Are Your Admins Accountable?</title><content type='html'>&lt;span style="font-family:Verdana;"&gt;A comprehensive security process protecting critical &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;assets&lt;/span&gt; needs to follow a basic outline such as this:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Verdana;"&gt;Prevention &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Verdana;"&gt;Detection &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Verdana;"&gt;Reaction&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Verdana;"&gt;Correction&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-family:Verdana;"&gt;Access to servers is one area where I see this process break down all the time. First, people reasonably &lt;strong&gt;Prevent&lt;/strong&gt; access with passwords. However, they use a common account such as &lt;strong&gt;Administrator;&lt;/strong&gt; which seriously weakens the Detection and Reaction steps. If every system administrator is using the same privileged account to do their work, there is no accountability (a key component of detection) and no reasonable ability to &lt;strong&gt;React&lt;/strong&gt; when something goes wrong.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;CIOs&lt;/span&gt;, don't let your admins grow up to be cowboys! Make it a policy and practice to require that system administrators use their own accounts to perform their jobs.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Verdana;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-8367040861538979025?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/8367040861538979025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/04/are-your-admins-accountable.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8367040861538979025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/8367040861538979025'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/04/are-your-admins-accountable.html' title='Are Your Admins Accountable?'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-5992973907104114550</id><published>2009-04-20T14:50:00.000-04:00</published><updated>2009-04-20T14:52:49.055-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SharePoint'/><title type='text'>SharePoint Designer is Free</title><content type='html'>SharePoint has taken the world by storm.  In almost all of our clients SharePoint has been deployed or is being discussed and this phenomenon is happening everywhere.  SharePoint Designer is one of the key tools that you can use to customize the SharePoint experience without coding.  Download it for free &lt;a title="SharePoint Designer" href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=baa3ad86-bfc1-4bd4-9812-d9e710d44f42" target="_blank"&gt;here.&lt;/a&gt;  You can also use SharePoint Designer to do traditional HTML programming.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-5992973907104114550?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/5992973907104114550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/04/sharepoint-designer-is-free.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5992973907104114550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/5992973907104114550'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/04/sharepoint-designer-is-free.html' title='SharePoint Designer is Free'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-7922182418653250673</id><published>2009-04-02T08:29:00.000-04:00</published><updated>2009-04-02T08:31:54.226-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Two-factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Two-factor authentication comes to Main Street</title><content type='html'>Security can be a wonderful thing and if it is well thought out and it does not have to be onerous.&lt;br /&gt;&lt;br /&gt;I have seen an increase in the number of merchants who are asking me for my billing zip code when using my American Express card. Walmart has been doing it for years. Many gas stations have started and last night, Walgreens asked me for the first time.&lt;br /&gt;&lt;br /&gt;This is a great example of intelligent two-factor authentication. The transaction relies on “something I have,” the credit card, and “something I know,” the billing zip code. Something that is easy for me to remember.&lt;br /&gt;&lt;br /&gt;This is much more effective than a signature because the credit card processor can easily validate my zip code as compared with analyzing handwriting. If security involves a cycle of:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Prevention&lt;/li&gt;&lt;li&gt;Detection&lt;/li&gt;&lt;li&gt;Reaction&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;the use of the Zip Code raises the ability of the bank and merchant to prevent and detect a fraudulent transaction.&lt;br /&gt;&lt;br /&gt;Several years ago someone stole my credit card and spent about $300 before I noticed the next morning that the card was gone. Had the thief been asked my zip code, he never would have been able to order that $50 meal at McDonald’s. Let’s hope that more merchants follow this protocol and we see a drop in credit card theft, saving all of us money in the long run. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-7922182418653250673?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/7922182418653250673/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/04/two-factor-authentication-comes-to-main.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7922182418653250673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/7922182418653250673'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/04/two-factor-authentication-comes-to-main.html' title='Two-factor authentication comes to Main Street'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-2313717444978999120</id><published>2009-03-14T12:09:00.000-04:00</published><updated>2009-03-14T12:27:53.690-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SID'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Varonis'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Unresolved SIDs</title><content type='html'>&lt;span style="font-family:verdana;"&gt;When we are working on cleaning up security in a Active Directory environment using Varonis DatAdvantage, one of the common problems that we run across are SIDs that Varonis cannot resolve to a useful name. In most cases this is because someone has deleted the user from Active Directory, rather than just disabling the user account. However, there are cases when the SID (security identifier) represents a group or machine account. Here is an example:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SID: S-1-5-32-544&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Nobody ever remembers what those are. In walks Jennifer!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;A Varonis user that we were working with, Jennifer Crusade, found this great Knowledge Base article that explains common &lt;/span&gt;&lt;span style="font-family:Verdana;"&gt;security identifiers in Windows operating systems.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/243330"&gt;http://support.microsoft.com/kb/243330&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Hope this helps you resolve a question or two.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-2313717444978999120?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/2313717444978999120/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/03/unresolved-sids.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2313717444978999120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/2313717444978999120'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/03/unresolved-sids.html' title='Unresolved SIDs'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1786185134212231068.post-6168647772367801028</id><published>2009-03-06T11:21:00.000-05:00</published><updated>2009-03-06T11:51:47.124-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Shutdown'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Admin'/><title type='text'>Turning off the Windows Server - Shutdown Event Tracker</title><content type='html'>I often need to reboot the lab server that I am working on. One of the minor annoyances is the &lt;strong&gt;Shutdown Event Tracker&lt;/strong&gt; that pops up and asks for a reason. When you are restarting the box several times during one work period this can be a real pain. So I learned how to shut it off.&lt;br /&gt;&lt;br /&gt;Running &lt;strong&gt;gpedit.msc&lt;/strong&gt; (Group Policy Object Editor) gives you the option to change this. Go to &lt;strong&gt;Computer Configuration:Administrative Templates:System&lt;/strong&gt; and find the &lt;strong&gt;Display Shutdown Event Tracker&lt;/strong&gt; settting.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_eFSy8U14xIE/SbFP_Km550I/AAAAAAAAAAU/poSRN9JORcY/s1600-h/image001.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5310113382244411202" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: hand; HEIGHT: 265px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_eFSy8U14xIE/SbFP_Km550I/AAAAAAAAAAU/poSRN9JORcY/s400/image001.png" border="0" /&gt;&lt;/a&gt;Change the setting to &lt;strong&gt;Disabled&lt;/strong&gt; and you are all set. Another minute saved.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1786185134212231068-6168647772367801028?l=castletips.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://castletips.blogspot.com/feeds/6168647772367801028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://castletips.blogspot.com/2009/03/i-often-need-to-reboot-lab-server-that.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6168647772367801028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1786185134212231068/posts/default/6168647772367801028'/><link rel='alternate' type='text/html' href='http://castletips.blogspot.com/2009/03/i-often-need-to-reboot-lab-server-that.html' title='Turning off the Windows Server - Shutdown Event Tracker'/><author><name>Arthur</name><uri>http://www.blogger.com/profile/01459683604548399698</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_eFSy8U14xIE/S15m4NKZyHI/AAAAAAAAAB4/-LmNQXX_9As/S220/Ahedge.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_eFSy8U14xIE/SbFP_Km550I/AAAAAAAAAAU/poSRN9JORcY/s72-c/image001.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
