Every several hours the server was performing SNMP port scans on IP addresses that were no longer existed. What was causing these scans?Tips on Improving IT Security and System Administration from Castle Ventures Corporation.
Tuesday, July 6, 2010
Dealing with the CounterACT "Port Scan - SNMP" message
One of the challenges in managing the ForeScout CounterACT appliance is to deal with and clean up the false positives that arise from anomalous network behavior that is not malicious. For example, today, we received a set of errors from one particular server, 192.168.111.18, that indicated that it was performing SNMP port scans. ForeScout correctly detected that something unusual was occurring and classified it as a malicious event.
Every several hours the server was performing SNMP port scans on IP addresses that were no longer existed. What was causing these scans?
Every several hours the server was performing SNMP port scans on IP addresses that were no longer existed. What was causing these scans?Wednesday, June 30, 2010
Warning - You Have Received a PDF file
With recent spate of vulnerability disclosures in the Adobe Reader and Acrobat programs it is time to take a big picture look at the PDF (Portable Document Format) format. The first observation that I make is that the PDF is not a strictly a static file; because of its potential for embedded JavaScript actions, it is an executable program. Since it is an executable program it needs to be treated as such from a security perspective. We need to have virus scanners aware of the executable functions within PDF files and warn us or inoculate us against the executable code that exists in the format.
Most people assume that a PDF file is a safe, immutable way to save and transmit unstructured information. Unfortunately because of the ability to create forms and JavaScript actions the PDF file has moved far beyond that; which is why the format has become so vulnerable to hackers. One solution that would stop this problem in its tracks would be for Adobe to create two different formats (PDF and PDX for example) and remove the JavaScript capabilities from the core PDF format. Until that happens we need to be wary of PDF files and take some of the following steps:
For those who are interested in the latest patches, Adobe issued updates yesterday for Adobe Reader and Acrobat that deal with the Critical security issues that have been discovered in the current release 9.3.2 (and earlier versions). Here is the security bulletin from Adobe with links to version 9.3.3 of the software products.
Most people assume that a PDF file is a safe, immutable way to save and transmit unstructured information. Unfortunately because of the ability to create forms and JavaScript actions the PDF file has moved far beyond that; which is why the format has become so vulnerable to hackers. One solution that would stop this problem in its tracks would be for Adobe to create two different formats (PDF and PDX for example) and remove the JavaScript capabilities from the core PDF format. Until that happens we need to be wary of PDF files and take some of the following steps:
- Educate the user community that PDF files are inherently unsafe and should be treated with caution
- By default, disable the functionality to run JavaScript within Adobe Reader and use it only as an exception.
- Make sure that we have prevention tools in place to detect rogue PDF files.
- Make sure that we have deployed detective controls to notice when unusual behavior is taking place on a user’s workstation or on the network so that we can fight off the PDF-borne attacks.
For those who are interested in the latest patches, Adobe issued updates yesterday for Adobe Reader and Acrobat that deal with the Critical security issues that have been discovered in the current release 9.3.2 (and earlier versions). Here is the security bulletin from Adobe with links to version 9.3.3 of the software products.
Saturday, June 26, 2010
SQL Server Job History
In running Varonis DatAdvantage there are times when you want to look at the history of the nightly jobs for a longer period then the defaults provided by SQL Server 2005. These defaults are based on 'Maximum job history log size (rows)' and 'Maximum job history rows per job.' If you are monitoring a large number of servers than the system may only keep several days worth of history for each job. Where disk space on the SQL Server is not an issue one change the the delete option to purge data based on an overall duration, which can be specified in days, weeks or months. For example, we might want to retain 10 days worht of history to assist in debugging issues. To do that perform the following steps.
First run SQL Server Management Studio.
Then navigate to:
• Root
• SQL Server Instance
• SQL Server Agent
• Right click on SQL Server Agent

First run SQL Server Management Studio.
Then navigate to:
• Root
• SQL Server Instance
• SQL Server Agent
• Right click on SQL Server Agent

- From here right-click on history.
- Select the option to "Automatically remove agent history" and enter the duration that you want to keep the job history.
- Click on OK and you are ready to run.
Wednesday, May 5, 2010
Justice Prevails
The recent convictions of the Sarah Palin email hacker, David Kennel, and the San Francisco system administrator, Terry Childs, are welcome events in the history of cyber crime.
These transgressions are not victimless; they affect everyone. One of the beauties of the Internet is its openness. That openness is only works if people feel safe on the Internet. When individuals take advantage of that freedom by abusing their privileges or infringing on the rights of others, it harms all of us by whittling away at that trust.
The Internet has revolutionized the way we live and that can only continue when people who violate the laws involving computer usage are punished severely.
These transgressions are not victimless; they affect everyone. One of the beauties of the Internet is its openness. That openness is only works if people feel safe on the Internet. When individuals take advantage of that freedom by abusing their privileges or infringing on the rights of others, it harms all of us by whittling away at that trust.
The Internet has revolutionized the way we live and that can only continue when people who violate the laws involving computer usage are punished severely.
Saturday, May 1, 2010
Is Terry Childs a Cyber Extortionist?
On Tuesday, April 27th, a jury of his peers, which included a network engineer, convicted Terry Childs of a felony for withholding administrative access to the City of San Francisco's networks by refusing to hand over privileged user credentials.
KTVU.com covers the story here.
His defense that his supervisors were not qualified to have the passwords is rather remarkable. He was a "privileged user" because his employer placed him in that position, not because of any rights he held. Childs' refusal to turn over the information to his superiors seems likes a pure case of extortion and a total misunderstanding of his responsibilities and I believe it is a good thing that he was convicted. Another case of the laws starting to deal with new threats that we face in the Information Technology world in the 21st century.
KTVU.com covers the story here.
His defense that his supervisors were not qualified to have the passwords is rather remarkable. He was a "privileged user" because his employer placed him in that position, not because of any rights he held. Childs' refusal to turn over the information to his superiors seems likes a pure case of extortion and a total misunderstanding of his responsibilities and I believe it is a good thing that he was convicted. Another case of the laws starting to deal with new threats that we face in the Information Technology world in the 21st century.
Saturday, April 3, 2010
SMTP Errors
The other day I was installing Varonis DatAdvantage for a customer and during the installation process received the following error, "The message could not be sent to the SMTP server. The transport error code was 0x800ccc15."
The first thing I wanted to check was that I had connectivity to the Exchange Server. So I used telnet to connect to port 25. That worked fine, so there was not a firewall in place blocking the connection. The Exchange server was set up to accept relays so that was not the problem.
After some investigation it turned out that McAfee VirusScan Enterprise 8.7.0 was the culprit.
Access Protection was enabled, so I reviewed the settings.
The first thing I wanted to check was that I had connectivity to the Exchange Server. So I used telnet to connect to port 25. That worked fine, so there was not a firewall in place blocking the connection. The Exchange server was set up to accept relays so that was not the problem.After some investigation it turned out that McAfee VirusScan Enterprise 8.7.0 was the culprit.
Access Protection was enabled, so I reviewed the settings. Wednesday, March 17, 2010
Adobe Please Fix Your Software
I was configuring a new Varonis server today and needed to download Adobe Reader so that we can access the documentation. I went to the Adobe web site and clicked on the download button. When I finish the installation, what do I find out? That they are still installing 9.3.0 by default! This is the unpatched version that has been the subject of a number of exploits. If a random user who doesn't deal with security on a daily basis installed this, they could be hosed. I ran the updates, but many people wouldn't. Adobe, please release a version that includes the patches built-in.
Subscribe to:
Posts (Atom)




