Sunday, May 5, 2013

Customizing Windows 8 Tips

There are a lot of things that have changed with the new Windows 8 "Modern Interface" design from Microsoft. Microsoft has had a lot of criticism for the changes and has been pressured to keep or scale back some of the design changes. I don't believe they should. I enjoy the new change and new look. It is very easy to navigate. And some people are even changing Windows 8 to look like Windows 7. What is the point of doing that? Why buy a Windows 8 machine only to get rid of the Modern Interface.
There are some tips to help you customize Windows 8 so you may be more productive, and to better organize your tiles around on your desktop. Because when you do install a program it does just add it to the end of the tiles.
  1. Make Groups: There are plenty of ways to arrange your Start screen tiles to taste: Simply click and drag a tile to change its position on the screen (or hold and drag on a touchscreen). For more global changes, you can pinch to zoom out (or Ctrl-mouse wheel), making your whole screen shrink, with all tiles on multiple screens visible. From this view, you can move and even name groups of tiles.
  2. Lock Screen: You can customize the picture on the lock screen like you can  on a smart phone, which is pretty nice. So when your PC or tablet is in sleep mode or locked it will look nice. :) The way you do that is simple. Just go to the right side of the screen to bring up your settings charms. Then click Personalize--> Lock Screen and then choose either the default pictures or add your own picture. SNAPPY!!
  3. Lock Screen Apps: While we are  customizing our lock screen we might as well provide some useful information. While the screen is locked you can also tell how much battery is left, the time, number emails and other useful information. So the lock screen isn't just for being locked. Under the Lock Screen App section click on the plus sign to add an app you would like to run during the lock screen.
  4. Resize the Tile: If you don't like the size of the tile change it. right click on the tile and a menu will appear at the bottom of the screen. If you want to make the tile smaller the smaller option will appear. If you want to make the tile larger the make larger option will appear.
Those are just a few tips to help make Windows 8 a little more user friendly. I hope this helps, and if you have any questions feel free to leave a comment and let me know.

Thanks

Sunday, July 24, 2011

Metasploit Book Unleashed

I just finished reading a new book from some of the guys at Offensive Security, Metasploit: The Penetration Tester's Guide and all I can say is that it is amazing.  Be sure to check it out and get yours from Amazon.com or your favorite bookseller.

One thing I have to say about it is that if you want to learn how to do a solid penetration test using a tool in every pen tester's toolbox then this has to be in you library. It not only shows you how to test the security of your network using Metasploit.

You learn how to integrate other programs such as nmap, nessus, and nexpose. It also teaches how exploits work and how to craft cleaver exploits that avoid detection. All of this is done with the goal of teaching best practices within pen testing and testing systems. The final step it goes over is cleaning up after the testing.

Another benefit of the book is that it tells you how to configure your lab environment to test some of the techniques and tools to attack both a Windows virtual machine and a Linux virtual machine, and walks you through the steps of doing a pen test in a safe and legal manner. It puts together the steps that you learned throughout the book into a consistent and concise chapter. The pen test is a small one, but with the skills and vm's that they give you it is a good starting point.  

Overall I give this book a 4 out of 5 stars only because I wish it would have been a bigger book. :) I hope they will continue to update the book or expand as the Metasploit Project continues to grow and techniques become more standardized though the Penetration Execution Standards become more firm. 

Friday, June 10, 2011

Gray Hat Hacking 3rd Edition Review

I have just finished reading Gray Hat Hacking: The Ethical Hacker's Handbook 3rd Edition by: Shon Harris. The book has been updated and expanded with new content and expended chapters and techniques.

The book starts out explaining what "Ethical Hacking" is, and what is Responsible Disclosure. You also learn about conducting and managing a penetration test in a professional setting.

Then an exploration of BackTrack 4 R2 is introduced. This is the defacto standard in security and penetration testing used by professionals. The BackTrack chapter could have been longer, but this book isn't designed as a BackTrack manual. Metasploit is also introduced. I think these are the best chapters in the book on using the Metapretor Shell and scripting Metasploit. It goes into real in-depth knowledge on using Metasploit to exploit the systems.
ow to an
The book teaches an introduction on computer programming for security professionals, which is always needed I think. Programming teaches you how to think logically and you can follow what the source code may be trying to accomplish.

The chapters on Malware Analyst is excellent. It builds on the previous chapters of programming and exploitation, which is great. You learn about capturing malware and how to run analysis software to figure out how the malware works and how to possible defend against it.

Monday, May 9, 2011

The Revolution is Coming!!!!

Back|Track Linux 5.0 Codename Revolution is being released on May 10, 2011. This is an exciting release for the security community. Check out Backtrack-linux.org to find out more information and download it.

It may take a couple of days to get to the site because with such a big release the site usually will go down or is slow downloading. That is just the effects of having such a popular computer program.

Some of the features include:
  • 32-bit, and 64-bit Versions (Which is a first for BackTrack)
  • More GPU processing power to crack passwords faster
  • Using Ubuntu 10.04 as the Base OS
  • Updated the Tools.
  • GPL v 3 compliant (Which means this is finally 100% free software with the source code)
  • Redesigned Repository that will be kept up-to-date
  • and so much awesomeness I cannot talk about.

Monday, February 21, 2011

Top Twenty-three Network Administration and Information Security Applications on Android

I decided to review some of the top network administration and infosec applications that I have been using on my Droid 2 phone. Most of these applications are free, and some of them have more advanced features that you can buy in the marketplace. Check it out and if you have any questions or have problems installing or using the application leave me a comment and I will try to help you out.
Thanks,
  1. DNSLookUp: DNS and WHOIS lookup tool that supports the use of multiple nameservers and DNS records types. 
  1. DNS Lookup Tool: DNS Lookup tool provides the ability to perform MX, A, NS, TXT and Reverse DNS lookups
  1. DroidSCP: SCP for Android devices. Transfer your files over SSH for maximum security. Features a recent connection log, local and remote file browser, public/private keys and batch upload/download. With the free version you are limited to transfer only 2 files in batch transfers. And ads are included at the top of the screen. If you don’t won’t those restrictions get the Unlock Key version for $1.49.
  1. Dropbox: Synch your files between your computers and your mobile device. Now you can browse the files in your Dropbox folder from anywhere. Share links to files, save photos and video from your camera to your computers, and open files using your favorite Android apps.
  1. G-Mon: This is a powerful wardriving scanner and GSM/UMTS Netmonitor and drive test tool. It scans for all WiFi networks in range and saves the data with GPS coordinates into a file on your SD card. You can create a kml file for Google Earth. It shows you the encryption, channel and signal strength. It shows all Aps in range in a live map. G-MoN is a wardriving scanner to collect and map all received wifi access points. It is also a 2G/3G netmonitor and field test drive tool for radio planning engineers. You do need to enable GPS for correct position in map.
You can log GSM or UMTS RX levels into a kml file for Google Earth or a csv file. There are 5 color groups for different levels. These levels can be defined by the user in the settings menue. This file is saved into the gmon folder on the sdcard or external memory. When the log is running the G-MoN Notification icon changes color to red. 2G/3G logging does not work when the screen is off.
  1. IP Calculator (IPv4 and IPv6):Performs calculations on IPv4 and IPv6 addresses, networks and netmasks.
  1. Ipconfig:
  1. Location Spoofer: A simple utility to set a fake wireless network location. You have to allow mock locations under Settingsà Applicationsà Development. Pro Version is available for $2.04 which includes: No ads. Spoof a GPS path, setting start and destination or loading a KML file from the sdcard. Set accuracy, max distance allowed from fake location. Search in map screen. Improved location history. Save your favorite places.
  1. ConnectBot: A powerful open-source SSH client. It can manage simultaneous SSH sessions, create secure tunnels, and copy/paste between other applications. This client allows you to connect to Secure Shell servers that typically run on Unix-based servers.
  1. HTTPing: This is a ping but for http-requests. Give it an URL, and it’ll show you how long it takes to connect, send a request and retrieve the reply (only the headers).
  1. NetInfo
  1. OSMonitor
  1. Passdroid: Password manager that stores your passwords in a secure way on your Android device. The passwords are guarded by a master password and strong cryptographic algorithms (AES and SHA256). Includes a password generator.
  1. Mobile Remote Network Controller: Use mobile through WiFi, you can control your PC. Download the PC client to your PC and you are all set. You are also able to use it to control powerpoint presentations or iTunes or any media player. Instructions: http://ben-works.blogspot.com/2011/01/remote-network-controller.html     Desktop Client: https://docs.google.com/leaf?id=0B_VLOKCL5YljMTlmYTc0ZmYtNTc0Mi00NDhhLTgwYTgtOTczZTlhZjhkOWU0&sort=name&layout=list&num=50&pli=1
  1. PingUp
  1. Shark: This is a version of wireshark for the Andriod. It sniffs traffic on both 3G and WiFi. You can download the dumped traffic, which is saved on the SD card, using wireshark on the PC or Shark Reader on the Android.
  1. Shark Reader: This is an application for reading pcap files. It does have problems with large files. But it works good if you do not have access to a PC at the time and need to look at your pcap files quickly.
  1. W&YPages: White and Yellow Pages directory. Easy to use.
  1. Wardrive: Wardriving app, stores scans in sqlite db on the sdcard and displays found networks around in the map. Requires Google Maps installed. Requires valid GPS position to work. You can also filter based on information that you want to show.
  1. Wifi Analyzer: Turns your android phone into a Wi-Fi analyzer. Shows the Wi-Fi channels around you. Helps you to find a less crowded channel for your wireless router. It is a good diagnostic tool to find out where issues with clients wireless may exist.
  1. WifiScanner: A simple scanner for wireless networks.
  1. Wireless Tether: Enables tethering (via wifi and Bluetooth)  for “rooted” handsets running android. Clients can connect via wifi (ad-hoc mode) or Bluetooth and get access to the internet using the 3G, 2G mobile connection. Features: Access-control features. Allow/deny clients to use your mobile-data connection. Wifi-Encryption. 128-bit WEP in general. WPA/WPA2 on supported devices. Settings for wifi-ssid, wifi-channel, lan-network and more.
  1. Z4root: Gain SuperUser Privileges on your android phone.  One of the simplest solutions I’ve seen. All you have to do is load the app onto your phone, run it, and click the button. It will give you root access to your phone, allowing you to install and run apps that require root access. If you run into any probles, just reboot your device and everything should be back to normal, since z4root doesn’t make any major changes to your system files. To find z4root go to http://4shared.com and search for z4root.apk.

Sunday, December 5, 2010

Social Culture of Hackers



Hacking is seen as an underground group. They are very social in nature. No man is an island in the hacker or security community. Hackers share information very liberally. Sites spring up every day to share tools, techniques, news, and other information to fellow hackers and security professionals. Security professionals need to be embracing joining the hacker community not in order to use the techniques of crackers, but so the techniques are known and defenses can be developed.

A couple of well known hacker underground sites include:
Hackers Center Security: http://forums.hackerscenter.com/index.php, T
he Hacker Community:
http://www.hacker.org/,
The 2600:
http://www.2600.com/
Defcon: http://www.defcon.org/.
Most of the hacker community never meets face-to-face. They hang out on irc, chat sites, and IM.
The only time a person get together are at Defcon and Blackhat security conferences.

Mailing lists and RSS feeds are the lifeblood to the security professional. Within the mailing lists and RSS feeds information is delivered as soon as it is available. If you keep up with the research and
security holes within software packages then you are better able to defend against these weaknesses.

Its a fine line between a criminal cracker and a security professional. They both use the same tools and techniques to defend and attack a computer security system. They both run in the same hacker
community because they are both curious about technology and gadgets. The only way you can tell the difference is by their actions.


Hackers have big egos. They love to talk and in most instance they love to share their secrets. Hacking is not hard. You just have to know what you want to accomplish before you start the hack. You can go to forums and chat sites and discover all sorts of new techniques and procedures to hack.

Friday, December 3, 2010

Personal Information as a Security Vector

Personal information such as SSN, medical records, and academic records are as secure as the knowledge that the staff has gained in order to protect the information. The security team can be well trained in computer and physical security. They can be the expert in the field of cryptography and a firewall or security architect, but if the security team does not train and pass along some of their knowledge then it will not be long before the information that they are trying to protect will be owned by an evil cracker that knows how to get within the company and compromise the integrity of the data.

No matter how good a security policy is companies are always vulnerable to penetration from the outside or even from the inside. Just this past week the employees of my company was told that we could no longer bring USB devices or any other storage devices including personal laptops because one employee was caught bringing company information to his home. Although I was not informed of what information the employee was taking home or why, the fact is that he brought the information home. We used to have a program that was supposed to encrypt the drive and the drive would then only be useful only on the computer that encrypt the drive, so I’m not sure what happened with that security measure. The bad thing is my company deals with social security
numbers and medical information every day, so I know that system and procedure would not be HIPPIA compliant.

Also it would not be hard to gather the username and password of the employees at the company because most of the time the information is on their desk or you can just ask them and they will be happy to give you the information, and most of the time the users do not lock their desktops when they leave their desks. This provides instant access to every SSN in the country and the person that would get called out would be the user because SSA knows who accesses what SSN and when it is accessed.
Remember to go to the training classes when offered. If you don't then you may unknowingly give out personal information that you may not have the right to release.

Thursday, December 2, 2010

Part 2: Cross-Site Scripting (XSS)

Cross-site scripting (XSS) is one of the most common application-layer web attacks. XSS targets scripts which are executed on the web browser rather than on the server-side. Cross-site scripting causes applications to execute in the manner desired by the malicious user. A basic example of XSS is when a malicious user injects a script in a legitimate shopping site URL which in turn redirects a user to a fake but identical page. The page would run a script to capture the cookie of the user browsing the shopping site, and that cookie gets sent to the malicious user who now hijack the legitimate user's session.
As on-line business project cannot afford to lose the trust of its present and future customers simply because nobody has ever stepped forward to prove that their site is really vulnerable to XSS exploits. Exploited XSS is commonly used to achieve the following malicious results:
Identity theft
Accessing sensitive or restricted information
Gaining free access to otherwise paid for content
Spying on user's web browsing habits
Altering browser functionality
Public defamation of an individual or corporation
Web application defacement
Denial of Service attacks
Security flaws in high-profile web sites have allowed hackers to obtain credit card details and user information which allowed them to perform transactions in their name. The major cause of XSS is code validation within the application. A
lot of applications do not validate their input. They don't check to see if the code accepts non-malicious input.

Ways to Prevent Cross-Site Scripting Attacks
1.      Validate Code: Go through your code and test your code. Ask yourself, “If a person enters “code” in the textbox will the code execute.” The only way to discover this is to try to run “code” within the textbox. The most common code is SQL commands and JavaScript commands.
2.      Escaping: Escaping is using special characters as escape characters instead of actual characters such as <,>, &, !, etc.  
For more information on Cross-Site Scripting and other web application security check out OWASP.com at


 

Thursday, June 24, 2010

Web Application Security 101

Part One: An Introduction

Web applications are often the forgotten child of web designers and programmers. Why is that? It should look like web applications are the single most important code and process that needs to be taken into account when designing websites. After all you are trusting the websites to be trustworthy especially from established brick and mortar stores. That is where the problem lies. A lot of stores and websites are not used to designing security plans for collecting and processing customers' information.


I will discuss in the next coming weeks areas of vulnerabilities within websites that web designers and programmers need to take into consideration before creating the site. Security should not be taken for granted. Applications need to be designed from the ground up with security in mind. Most applications on the web are designed with security as an afterthought and do not include security checks in them until after there is a breach and it has reached the news media.

During this series of post we will discuss, cross-site scripting, SQL Injection, web site authorization, SSL vulnerabilities, man-in-the-middle attacks, and other topics as I think of it. :) The purpose of the articles is to inform both programmers and end-users what to look out for while exploring the website. Continue with me on this exciting journey, and we will both learn something and maybe better secure the Internet or at least bring about a better understanding and awareness of application security.


Thanks,

Lance Howell

Wednesday, May 12, 2010

Port Scanning

Port scanning is an invasive activity. Port scanning is the process of checking to see if a network is available or not. Port scanning can also cause denial of service on a network if it is scanned long enough. The type of scans that are done are half scans, FIN scans, XMAS scans and other stealth scans that could be used to penetrate a firewall. The ports can be filtered, opened, or closed.


Cases have been attempted to convict people for doing port scans, but the courts have time and time again said as long as people are just scanning they are not committing a crime. The rules do vary from state to state. One of the more famous cases is Moulton vs VC3 where Scott Moulton, a owner and operator of a security company was trying to test the county’s 911 system for vulnerabilities and discovered VC3’s firewall. The judge after Scott explained it to him agreed that it was not a crime. That was in 2000.

But just because it is not illegal by the law does not mean that it is not invasive and uses computer and network resources. It has to send traffic to each port in order to discover if it is an open or closed port. Even if you are not receiving data or information from the ports you are getting information about the network and the company’s network and infrastructure. You are learning how secure or unsecure they are. You in some instincts learn what programs or equipment they may be using.

Thursday, April 8, 2010

Risk Analysis Life Cycle

  1. Identify the Risk: Determine your assets and identify threats that are likely to attack those assets.
  2. Assess the Risks: Determine the asset value. Produce a risk matrix to determine which risk is greater given the company’s environment. 
  3. Develop Risk Management Plan: Set-up policies, procedures, and backup recovery plans. 
  4. Implement Risk Management Actions: Put your policies and procedures in writing, do training and awareness with other employees. 
  5. Re-evaluate the Risks: Every 6-months review your risks and policies and make sure they are still relevant. Determine what risk is most likely to still be compromised.

Thursday, March 25, 2010

Common Threats and Safeguards to Be Aware of

Social Engineering is one of the most difficult hacking techniques to defend against because it is all about attacking the human elements. It is about manipulating employees and using non-technical means to discover information about the company or users to exploit them to gain access to the network. The best safeguard to use against social engineering is to educate the users and executives of the company. Educate them not to give personal private information to others without the employees knowing who they are. No one should have a need to know the user's password or access codes to their equipment. Train the employees on the proper way to discard sensitive information. Train them in not throwing papers with social security numbers or financial information in a regular trash can. Teach them the proper use of shredding material. Security is all about trusts and forming trust relationships. If you do not have trust then how can you be secure, that is why social engineering is so difficult to secure against because you are putting trust in your employees to not click on links in e-mails, give passwords to strangers, not to keep their passwords in the open, and not throw away sensitive information in normal trash.


A Denial of Service Attack (DoS) is attacks on a network and a web infrastructure. Its major objective is to prevent legitimate use of a network by preventing authorized access to resources, delay time critical operations, and by degradation of services. One of the most common types of DoS attacks is called TCP SYN Flooding also known as IP spoofing. A safeguard of this kind of attack is by installing a filtering router that restricts the input to your external interface, known as an input filter or ingress filter. You also should filter outgoing packets that have a source address different from your internal network to prevent a source IP spoofing attack from originating from your site.

E-Mail Attacks are very common as more people are being connected. You can have spam, phishing, and malware sent though e-mail. How do you safeguard against these types of attacks? It is simple don’t use e-mail. Make phone calls or send a letter to the person you are trying to reach. Those are not very good solutions. Just because a technology is not safe to use does not mean you cannot use it safely. If that were the case, why are you on a computer or using a pen or telephone? To protect your network from e-mail attacks remember to educate the users. Don’t click on links in an e-mail. If you have to go to the link open up a new browser and type that link in the browser. If you are told to log-in to your bank or credit card site then do it from the home page, and remember that a bank will never ask you to log in to change records or verify account information. If they do you need to change banks because they lack good Information Security procedures. Do not run a program from your e-mail. Save it to your desktop, and run it from there.

Saturday, March 20, 2010

Knock, Knock Let Me In

Do you know who is trying to get in to your network. Someone is always knocking at your door. The doors of the network is called ports. Anyone working on my network should have a fairly good understanding and knowledge of why a port is open, and if they do not have a good reason for it to be open then close it. Port knocking provides a stealthy method of authentication and information transfer to a networked machine that has no open ports. Some basic functionality needs to be provided with any port knocking implementation:


  1. A way to monitor the firewall log file needs to be devised. 
  2. A method to extract the sequences of ports from the log file and translate their payload into usable information. 
  3. Once the information is obtained from the sequence, the implementation must provide some way to manipulate the firewall rules.
Port knocking sounds like a great solution when it comes to monitoring closed ports on a firewall, but it does come with a few disadvantages. You have to use client script in order to perform the knocks. This script should be kept a secret and on a removable media such as a USB drive. A number of ports need to be allocated for exclusive use by the system. Any system that manipulates firewall rules in an automated fashion requires careful implementation.

Thursday, March 18, 2010

Awards and Achievement

Well it is 2:37pm and I am in the process of getting ready to be inducted into Alpha Beta Kapa National Honor's Society. I do admit I have worked hard towards this event. I know my family and I have both sacificed a lot and will sacifice a lot for this achievement. I have given up my weekends, most of my nights, and days. I could have been with my wife on those times, but my choices have lead me down this path. We both wonder sometimes if the pressure of school is worth it in the end...

I think it will be. I have just one goal, and that is to provide a better lifestyle for my wife and our future child together. That is what this degree is all about to me. Some of my classmates only sees it as a way to get a job and have fun. I see it more than that. I know my value, and I must convey that to any partential employees. That is way I will not settle for just any job it has to be that right job. I have done that before, and I will not go down that road again.

I am very excited about being a member of such a prestiagous organization. I am ready to prove everyone that I am smart and that the decision to go to school was the right one. By December I hope with the help of God that I will be Validictorian of my class. If not that then at least in the top ten percent. I just wish that I had applied myself like this in high school. I may would have turned out a little different. I finally get to right that wrong.

Back to the question... Is the ABK Honor important to me? Heck yes it is. Some people it may not be. I just hope that I can live up to the standards and do them and my family proud.

Thursday, February 18, 2010

Risk Assessment Necessary Evil

This week I have been learning about doing risk assessment in order to inform how much companies would actually lose if the company lost equipment or data. I learned it is tough in coming up with all that could go wrong and with what is of value within a company that I need to take into account.

The hardest part of the "assessment" is assigning a numerical value. You have to think of the employee worth, and the amount of time that goes into the assessment. You also have to think of the time that it takes to replace the data and information that may be compromised if a system fails.

Will you be able to cover quickly? Remember that the longer your system and network may be down the longer you will be not satisfying customers' needs. You have to be prepared. Make the necessary backups, images, have the necessary disks. Do you have extra computer parts in case your system blows up? Are the backup and recovery procedures written down and are the staff prepared on how to implement those procedures. These are the questions to ask.

Systems should be operational within an hour. If it is not then something is wrong with your recovery procedure. The quicker you can get back to work the better. I know there are some extreme instances where that will not be possible, but that also needs to be taken into account.

As always leave me a comment about anything I say, and remember stay secure out there.

Monday, February 15, 2010

Linux in a Nutshell 5th Edition Review

Linux in a Nutshell, 5th Edition By: Ellen Siever, Aaron Weber, Stephen Figgins, Robert Love, Arnold Robbins, et al. is a fantastic reference book for both newbies to Linux or system administrators that have 20+ years of experience. The book is published by O'Reilly Media, which is the leader in great and easy to read technical book. The book is a massive 944 pages. Two-thirds of which is commands to use with linux and a detail and examples of most if not all the options with that command. If you are reading a forum post and want to find the truth about what that command is doing to the system then use this book to find that out so you want be left with possible deleting your system. The list of commands are in alphabetical order so they are easy to thumb to the correct command. It is great to learn about the commands. I think adding the commands in this kind of list and format is the best thing about the book. I will use that section for years to come. 

Also if you want to know about how to set up different services or servers running Linux you can with this book also. You can learn about DNS/BIND, SSH, file sharing, networking and a lot more within the other chapters of the book. 

My only caution with this book is that it is for the person wanting to become proficient in the use of the command line. It is not for the typical user unless you love the command line. If you are a casual user then I would recommend an Ubuntu book by O'Reilly. There are no graphics in the book, so you will know the command line by the time you study and read this book. Also you cannot understand the command line unless you use it day in and day out.

I give this book 4 out of 5 Penguins just because I wished they would have given more examples and covered more administration topics and expanded on them. But it is still a wonderful book and reference tool. It will stay next to me and my computer.

Sunday, December 13, 2009

TV On the Desktop

I have been using Hulu Desktop. It is a new product from www.hulu.com. It brings TV, movies, news, and trailers to watch all in one place without searching on-line for the broadcasts. You can watch clips or in most cases full episodes. This is also a great solution if you have a MythTV solution to your television watching. MythTV is a linux based solution sort of like Windows Media Center, except Myth provides a lot more functionality than Myth does.

Back to Hulu Desktop...

Hulu Desktop allows you to control the screen either with your remote control or with the keyboard, which you would only need your control if it was part of a MythTV solution. Hulu also provides only limited 30 second commercials which are non-obtrusive to the user. The commercial time gives you time to take a break without pausing the shows.

You can edit your profile, subscribe to "channels", and add friends and also discuss shows and offer your opinions on what you thought of the shows. Adding friends and all brings a social networking aspect to whole site and desktop experience.

Check it out I highly recommend it for everyone. This is a great step towards letting go of the cable company or satellite company. People want to watch the shows they want to watch when they want to watch it. Hulu allows that. You get to choose the shows to watch and don't have to record anything any more.

Let me know by leaving a comment if you have looked at it, and what you think. It is availible for Windows, MAC, and Linux.

Link

Friday, October 30, 2009

New Ubuntu


I downloaded the new Ubuntu 9.10 Linux operating system. It is a wonderful operating. It loads and install super fast. It has new features and improvements over the previous versions. This version includes a Software Store see Figure 1. They have taken out some software such as Pidgin and included Empathy as the default IM/Chat program, but the good thing about free and open source software is that if you miss the old programs then you can always get those programs back and re-download them through the synaptic package manager.

Ubuntu also seems to run faster at both start-up and shut-down. They have also updated some of the themes and background images for the desktop which is wonderful. The install looked more professional. While installing Ubuntu I can tell that it is becoming a more mature operating system. I really look forward to the long-term support edition and the future of Ubuntu.

I can tell that Ubuntu is trying to go head-to-head with Microsoft and Apple. It is no accident that Microsoft and Apple both released their operating systems around Ubuntu's normal release. Ubuntu releases an OS every 6-months in April and October.

Saturday, May 23, 2009

Passwords: First Step in Insecurity

It is very hard to come up with a good password. Especially if you don't want you site or data accessed. Why do you think that is? The answer is simple if you take the time and make a truly random password it is so complicated that most people can't remember the password, and they write it down and keep the password under their keyboard, on their monitor, or somewhere close to their workstation. This is a BIG NO NO!!! This goes back to the #1 rule of Security: If people have access to your machine then no security measure you take will make you secure. So it is very important that you take the right physical security precautions and secure your work area.

But I know from experience that know matter how much I talk about not writing passwords down you will still do it. If you do write it down then take some password security precautions and at least keep it secure. My advise is to not use passwords alone. Use what in the security world we call 3-forms of authentications: What you have? What you know? and Who you are?

What you know, are things like passwords, security questions, personal information that you may know. What you have, are things such as flash drive or tokens, PDAs, and mobile device. Who you are include bio tech, such as thumb prints, retina scans, and face recognition.

Steps to Secure Passwords
  • More than 8 characters long
  • Mix of alphanumeric, numeric, and special symbols ($,%,^,@,&,!,?)
  • Not words in dictionaries
  • Not names or common words

If you combined your extra secure password with what you have such as a flash drive and a simple to use password manager such as KeePass Password Safe Portable found at http://portableapps.com/apps/utilities/keepass_portable

With this utility you can set-up a list of websites that you are a member of and have one really strong random password to protect the data within the program to be accessed.

I look forward to your comments and questions.

Saturday, February 28, 2009

Getting Caught with Your Ports Down!!!

What is port scanning? It is like a thief going through your neighborhood and checking every door and window on each house to see which are locked. Port scanning software simply sends out a request to connect to the target computer on each port sequentially and makes a note of which ports responded or seem open to more in-depth probing.

Port scanning can be done with malicious intent, the intruder would generally prefer to go undetected. Network security applications can be configured to alert administrators if they detect connection requests across a broad range of ports from a single host. To get around this the intruder can do the port scan in strobe or stealth mode. Strobing limits the ports to a smaller target set rather than blanket scanning all 65,536 ports. Stealth scanning uses techniques such as slowing the scan.

There are a number of different methods to perform the actual port scans as well as tricks to hide the true source of port scan.

You must find the right balance between network performance and network safety. You could monitor for SYN scans by logging any attempt to send a SYN packet to a port tat isn't open or listening. A SYN scan is a type of TCP scanning that is also known as a "half-open scanning" because it does not open a full TCP connection.

You must ensure you have approval of all the necessary people before port scanning otherwise you may be on the wrong side of the law. Once you find out what ports respond as being open by port scanning your own network you can begin to work on determining whether it is necessary for those ports to be open to outside traffic.

Types of Port Scans Include
  • Vanilla: An attempt to connect to all 65,536 ports
  • Strobe: An attempt to connect to only selected ports (typically under 20)
  • Stealth Scan: Several techniques for scanning that attemp to prevent the request for connection being logged; uses SYN scan FIN scans or other techniques to prevent logging of the scan.
  • FTP Bounce: Scan attempts that are directed through an FTP server to disguise the cracker's location.
  • Fragmented Packets: Scans by sending packet fragments that can get through simple packet filters in a firewall.
  • UDP: Scans for open UDP ports.
  • Sweep: Scans the same port on a number of computers.

Tool Used to Perform Port Scanning

NMap (Network Mapper) is a popular free open source software used to port scan. It is a utility for network exploration or security auditing. You can scan a range of IP addresses and ports and find out what an attacker would see if they were to port scan your network. NMap allows great flexibility and control of almost every aspect of the scan and perform various types of port scans to fit your needs.

NMap was designed to rapidly scan large networks, but works find against a single host NMap is:

  • Flexible: Supports dozens of advanced techniques for mapping out networks filled with IP filters, firewalls, routers, and other obstacles.
  • Powerful: Used to scan huge networks of literally hundreds of thousands of machines.
  • Portable: Most operating systems are supported, including: Linux, Microsoft Windows, FreeBSD, Open BSD, Solaris, IRIX, Mac OS X, HP-UX, NetBSD, Sun OS, Amiga, and more.
  • Easy: You can start out as simply as nmap-v-A targethost. Both traditional command line and graphical (GUI) versions are available to suit your preference.
  • Free: It comes with full source code.
  • Well Documented
  • Supported
  • Popular