Sunday, February 7, 2010

Harden Your Service Accounts

In many cases we have service accounts that need powerful privileges to perform their tasks. This power also means that there is an elevated level of risk associanted with these accounts. They could be used inappropriately to access resources without accountability, since they are not tied directly to a person. There are two steps that I recommend that people follow in locking fown these accounts. Both of these activities involve starting Active Directory Users and Groups and then selecting the Properties options on the selected service acccout. First, select the Terminal Services Profile and check the option to Deny this user permissions to log on to any Terminal Server. The screen shot is listed here:

Then we want to restrict the computers that the service account cal log into. This is found on the Account tab. Once on this tab, click on the Log On To command button. At this point enter the computer name(s) where the service account is used. This will limit the account to logging into only this machine.



Tuesday, January 26, 2010

Stop Monitoring a Server in Varonis

When you have a Windows server that is going offline, but you want to retain all the historical information in Varonis ( the events and permissions) here are the steps you need to follow.

From within the Configuration Screen select File Servers. Then move to the server that you want to decommission.
1) Uncheck all of the boxes for Collect Events.
2) Uncheck the box for Local Accounts.
3) For each drive make sure the Crawl File System is set to Disable.
4) Click OK and you are all set.


Friday, January 8, 2010

8 Predictions for 2010 on Document Management Security

Each year there seem to be more and more breaches in information security. Some only cause embarrassment; others could cause harm. Take a look at this list of my predictions that I prepared for AIIM. Could you be affected by any of these items? If so, start locking down your information effectively. I would love to hear your feedback.

Thursday, January 7, 2010

Adobe Issues Update on Security Issues with Reader and Acrobat

Adobe issued an advisory today giving more information about the securityissues with Adobe Acrobat and Reader. They plan to release a patch on January 12, 2010. Here is the security bulletin from Adobe.

Saturday, December 26, 2009

The Big Switch

Cloud computing is all the rage. According to Nicholas Carr, one of the unstoppable drivers is the economics of cloud computing. Carr uses the history of the electric industry to explain the historical forces that are in play today in the information technology market and that will move Information Technology to more and more of a utility computing model.

There is an informative description of companies such as YouTube who generate tremendous value by providing a platform with a small number of employees that millions of people add value to for free. This viral model has been used a number of times in the Internet space and is one of the forces that is negatively affecting traditional industries such as newspapers.

Carr also covers a number of the social changes that are occurring, including the loss of privacy, which in some ways was the opposite effect that early Internet pioneers predicted.

This is book is required reading for anyone who wants to understand the major forces that are moving the Information Technology field.

Buy The Big Switch: Rewiring the World, from Edison to Google
from Amazon now.

Tuesday, December 22, 2009

Adobe Reader is Vulnerable Again

Back in May we first discussed the vulnerability in Adobe Reader. Once again, an issue has cropped up. I ask the question again, why doesn't Adobe release a standard verison of the reader without Javascript? Sure, it would disable some forms, but the bulk of users in the world want to read documents safely and not use forms. They could certainly have a Premium Reader with Javascript support for those people that need it.
Here is the statement from them, "Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.

Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue."


Here is a link to the security advisory.

Tuesday, December 1, 2009

Who Stole Those Emails

I have started writing a column for Infonomics, the publishing portion of AIIM. The first column covers the basics of Information Security. Here is a link to The Article.