Archive for March, 2004

Infocus: Dogs of War: Securing Microsoft Groupware Environments with Unix (Part One)

Friday, March 26th, 2004

Infocus: Dogs of War: Securing Microsoft Groupware Environments with Unix (Part One) This article discusses the implementation of layered mail security using Unix as MTA in front of Microsoft groupware products. Part one describes the use of Sendmail, MIMEDefang and SpamAssassin.

[via SecurityFocus News]

Security vendor offers commercial C# crypto library

Friday, March 26th, 2004

Security vendor offers commercial C# crypto library Certicom, a commercial vendor of cryptography algorithms and software, has released what it claims is the “first commercially available cryptographic developer toolkit for the Microsoft .NET Framework and .NET Compact Framework”. It includes a digital certificate management toolkit, and a “complete” SSL/TLS toolkit, according to the site.

[via TheServerSide.NET: Your Enterprise .NET Community Forum]

Determining Free Physical RAM

Friday, March 26th, 2004

Determining Free Physical RAM 24 Mar 2004: “This article explores how application programs can find out how much free physical memory is available and how you can take advantage of this information. Specifically for the Solaris Operating System (Solaris OS), it provides a routine to determine the currently available physical memory, plus a sample program demonstrating how this interface can be used.” Story

[via RootPrompt — Nothing but Unix]

Security One Step at a Time

Friday, March 26th, 2004

Security One Step at a Time 26 Mar 2004: “Last year, the not-so-dramatically-named CAN-2003-0434 vulnerability allowed humble PDF files to run arbitrary commands as you. Linux users and distributions dealt with it quickly enough that it didn’t turn into a vector for spreading a worm. With today’s larger Linux user base and more desktop standardization, the next vulnerability will be a bigger risk.” Story

[via RootPrompt — Nothing but Unix]

Internet Information Services (IIS) 6.0 Resource Kit

Friday, March 26th, 2004

Internet Information Services (IIS) 6.0 Resource Kit Whether you manage a single Web server or many, the prescriptive, task-based, and scenario-based guidance in this book will help you effectively plan, deploy, operate, and troubleshoot your IIS 6.0 solution.

[via Microsoft Download Center]

Securing Windows Server 2003 Active Directory

Wednesday, March 24th, 2004

Securing Windows Server 2003 Active Directory This guide explains how to avoid loss of access to network resources by legitimate clients or the inappropriate disclosure of potentially sensitive information by enhancing security for Microsoft Windows Server 2003 network operating system (NOS) environments.

[via Microsoft Download Center]

Timing Perfect for Sun’s Java Desktop System

Wednesday, March 24th, 2004

Timing Perfect for Sun’s Java Desktop System

[via DesktopLinux]

Infocus: Forensic Analysis of a Live Linux System, Pt. 1

Tuesday, March 23rd, 2004

Infocus: Forensic Analysis of a Live Linux System, Pt. 1 This article is the first of a two-part series that provides step-by-step instructions on forensics of a live Linux system that has been recently compromised.

[via SecurityFocus News]

Neowin guide to Removing Spyware

Tuesday, March 23rd, 2004

Neowin guide to Removing Spyware

[via Neowin.net]

IT Security at Microsoft

Tuesday, March 23rd, 2004

IT Security at Microsoft

Microsoft has released a great slide deck and Word document discussing what the Microsoft Corporate Security group does to prevent malicious or unauthorized use of digital assets at Microsoft.


It is very interesting to see how their asset protection takes place through a formal risk management framework, risk management processes, and clear organizational roles and responsibilities. The basis of the approach is recognition that risk is an inherent part of any environment and that risk should be proactively managed. They say that the principles and techniques described can be employed to manage risk at any organization.


Its well worth your time to see how they present the information. Although this is not really “new” information, its interesting to see Microsoft so open about it. And man.. their slide decks sure are looking much better now adays.


Enjoy.


[via Dana Epp’s ramblings at the Sanctuary ]

Handbook of Information Security Management

Monday, March 22nd, 2004

Handbook of Information Security Management

The CISSP Open Study Guides Web Site in collaboration with Auerbach have released the content online for the book “Handbook of Information Security Management”.


Personally I prefer to read books in analog( ie: paper) form, since its much more comfortable, but if you are into reading an entire book online, check it out.


Of course, this does give me more incentive to rethink the idea of getting a TabletPC… :)


[via Dana Epp’s ramblings at the Sanctuary ]

Using key-based authentication over SSH

Monday, March 22nd, 2004

Using key-based authentication over SSH

[via NewsForge]

Tackling Unix security in large organisations, part 2

Monday, March 22nd, 2004

Tackling Unix security in large organisations, part 1 and part 2

[via NewsForge]

Change Management

Friday, March 19th, 2004

Change Management The Change Management SMF is responsible for the process of documenting, assessing the impact of, approving, scheduling, and reviewing changes in an IT environment.

[via Microsoft Download Center]

Server Consolidation White Paper

Thursday, March 18th, 2004

Server Consolidation White Paper Find out if your company is a candidate for server consolidation and how to get started on the right track to achieve lower total cost of ownership.

[via Microsoft Download Center]

RSS And BitTorrent, Together At Last

Thursday, March 18th, 2004

RSS And BitTorrent, Together At Last

Identity breach risk accelerates

Wednesday, March 17th, 2004

Flaws in identity management have huge impact. Security breaches resulting from identity management flaws are rising and creating huge problems for businesses, research shows. Identity management breaches affected one in 10 large companies last year, and half of them said it was their worst security problem of the year, according to the Department of Trade and Industry’s biennial Information Security Breaches Survey 2004.

Detection of SQL Injection and Cross-site Scripting Attacks

Wednesday, March 17th, 2004

Infocus: Detection of SQL Injection and Cross-site Scripting Attacks This article discusses techniques to detect SQL Injection and Cross Site Scripting (CSS) attacks against your networks using regular expressions with the open-source IDS, Snort.

[via SecurityFocus News]

Networking improvements in the 2.6 kernel

Tuesday, March 9th, 2004

The new Linux kernel includes support for and improvements in many areas of networking: from tunneling and better file security to encryption and privacy protection. This article covers how these improvements affect users even as they make Linux more secure and more enterprise-ready. (Posted 9 Mar 2004 by Idean Momtaheni)

[via Librenix.com | Linux Sysadmin Central]

HOW TO: Tune and Scale Performance of Applications That Are Built on the .NET Framework

Tuesday, March 9th, 2004

HOW TO: Tune and Scale Performance of Applications That Are Built on the .NET Framework HOW TO: Tune and Scale Performance of Applications That Are Built on the .NET Framework
(818015) - This step-by-step article describes important considerations for performance tuning and scaling of applications that are built on the .NET Framework. This is one of a series of articles that provide detailed information for applications built on the..

 


[via kbAlertz - ASP.NET]