Friday, December 21, 2007
Flash Player Updates
I read a great blog piece on the update of Flash. What I thought best was a link to Adobe's site where they tell what version you are using and what version to update to.
Thursday, December 20, 2007
Motorola Moto Q
I can admit that I'm a gadget guy. So, we just updated our cellphones. My wife picked out the enV and I'm trying the Moto Q. My last phone was a Motorola E815, a flip phone. So, it's taking a little getting used to the new phone. I don't have the full data plan, which probably diminishes the phone somewhat; but I'm liking it. Texting is certainly easier. I'll post some more thoughts in a couple of days.
Wednesday, December 19, 2007
Patch Tuesday Patches
I finished reading SANS writeup of the patches that MS released on Patch Tuesday. I noticed that there were three patches that were labeled "Critical." As I am not the system/network admin, I passed the reviews on to my co-worker; who is the admin. His response was "Maybe we'll get to them. The AV signatures are up-to-date and the spam filter is up-to-date." Plus, he added, the firewall has been running without a problem. (Not that he would actually know, the logs only get reviewed when there is an incident.)
We use Microsoft's patch server in house (I forget the name of it.) That is, administratively, the admin decides what patches to get from Microsoft, the server fetches the patches, then pushes the patches out to the client machines. How many times is this done a year? Maybe twice. Maybe.
I believe we should be doing this EVERY month. While we might have bolstered defenses in anti-virus, spam detection and firewall rules, what happens if the threat comes from INSIDE the perimeter? I know we have users that click on links in spam email. What if one of those links downloads something malicious? Once it is inside, we could be done.
This same admin refuses to patch the servers, using basically the same logic. "The servers are inside the DMZ, nothing should get to them."
I'm usually the first of the IT guys in the building in the morning. I walk past the server room, just to make sure the lights are on all of the server. I know there's a day coming when they won't.
Any thoughts on how to "persuade" the admin to patch more frequently?
We use Microsoft's patch server in house (I forget the name of it.) That is, administratively, the admin decides what patches to get from Microsoft, the server fetches the patches, then pushes the patches out to the client machines. How many times is this done a year? Maybe twice. Maybe.
I believe we should be doing this EVERY month. While we might have bolstered defenses in anti-virus, spam detection and firewall rules, what happens if the threat comes from INSIDE the perimeter? I know we have users that click on links in spam email. What if one of those links downloads something malicious? Once it is inside, we could be done.
This same admin refuses to patch the servers, using basically the same logic. "The servers are inside the DMZ, nothing should get to them."
I'm usually the first of the IT guys in the building in the morning. I walk past the server room, just to make sure the lights are on all of the server. I know there's a day coming when they won't.
Any thoughts on how to "persuade" the admin to patch more frequently?
Thursday, December 6, 2007
Keyloggers: Hardware or Software?
I've been looking into acquiring a keylogger of some sort. It will help when I'm employed to key tabs on a suspect. I've done a lot of reading on the subject and I have some questions. I realize that there are hardware keyloggers (keyboard connectors,) software, and keyloggers manufactured into the keyboard. A logger manufactured into a keyboard is not in the equation for a couple of reasons. It would be obvious to a user if they are using a different keyboard than they are accustomed to using. Also, I understand they are expensive. That leaves me with two choices: a hardware solution, and a software solution.
I wouldn't mind a hardware solution. Most of the time, where the keyboard is plugged in is out of the way, and mostly hidden. However, I've seen that there space considerations going this route. I'm not sure if I'll be able to check the computer on a regular basis, say nightly.
A software solution would be ideal, something that could be covertly installed. However, I need something that won't show up in task manager, won't trip anti-virus or anti-spyware software, and obviously won't show up in the systray. Is there a good software package for this? Does one exist? The last thing I need is to tip off the suspect.
So, my question is: What do you use, and what do you like? Are there any "certified" for incident response? Does the government or law enforcement have anything (commercially available) that comes recommended?
I wouldn't mind a hardware solution. Most of the time, where the keyboard is plugged in is out of the way, and mostly hidden. However, I've seen that there space considerations going this route. I'm not sure if I'll be able to check the computer on a regular basis, say nightly.
A software solution would be ideal, something that could be covertly installed. However, I need something that won't show up in task manager, won't trip anti-virus or anti-spyware software, and obviously won't show up in the systray. Is there a good software package for this? Does one exist? The last thing I need is to tip off the suspect.
So, my question is: What do you use, and what do you like? Are there any "certified" for incident response? Does the government or law enforcement have anything (commercially available) that comes recommended?
Friday, November 23, 2007
Happy Thanksgiving - sorry there haven't been updates
I'm trying to go independent. I've gotten an office, I'm starting to incorporate, and I've been busy with the chores of opening my own business. It is entirely rewarding and exciting, yet scary and never-wracking at the same time. I'll try to keep the site updated with my progress.
I ran across this link the other day, I think it was just before Thanksgiving.
http://isc.sans.org/diary.html?storyid=3669&rss
Like most security warriors, you get asked to look at the computers of relatives. SANS asked what we bring when we're visiting relatives then compiled the results.
Enjoy, and enjoy the holidays.
I ran across this link the other day, I think it was just before Thanksgiving.
http://isc.sans.org/diary.html?storyid=3669&rss
Like most security warriors, you get asked to look at the computers of relatives. SANS asked what we bring when we're visiting relatives then compiled the results.
Enjoy, and enjoy the holidays.
Monday, October 22, 2007
Email addresses and E-Discovery
This has been bugging me for a while. And I'm just now going to write about it. And only because a user inadvertently brought it up.
While I was in the lunchroom, a user came in to eat; and brought her Blackberry. (We don't have a policy on Blackberrys...grrrr...a post for another day.) Anyway, one of the sales reps had emailed her back a one-word answer. "Yes." She ranted that she was sick of this rep replying one-word answers to her questions; and replying from his personal mail. She sent the original question to his corporate email address.
Back in November, the IT department was successful in changing the policy on forwarding all corporate email to personal email addresses. 90% of the users comply with this policy. First of all, management did not like the fact that official company business was being conducted with an "aol" or "hotmail" address. I didn't like it because we have no record of what is really going on. Suppose a salesrep makes a deal with a dealer giving them X% off of a future order. If the company did not comply (for whatever reason) how would we know. We can't grab aol or hotmail email. Should we get sued, we could never produce that email.
Unfortunately, it is not just salesreps that are doing this. There are some in upper management who use their personal email addresses.
So, how do you enforce this policy? I would love to hear some suggestions.
While I was in the lunchroom, a user came in to eat; and brought her Blackberry. (We don't have a policy on Blackberrys...grrrr...a post for another day.) Anyway, one of the sales reps had emailed her back a one-word answer. "Yes." She ranted that she was sick of this rep replying one-word answers to her questions; and replying from his personal mail. She sent the original question to his corporate email address.
Back in November, the IT department was successful in changing the policy on forwarding all corporate email to personal email addresses. 90% of the users comply with this policy. First of all, management did not like the fact that official company business was being conducted with an "aol" or "hotmail" address. I didn't like it because we have no record of what is really going on. Suppose a salesrep makes a deal with a dealer giving them X% off of a future order. If the company did not comply (for whatever reason) how would we know. We can't grab aol or hotmail email. Should we get sued, we could never produce that email.
Unfortunately, it is not just salesreps that are doing this. There are some in upper management who use their personal email addresses.
So, how do you enforce this policy? I would love to hear some suggestions.
Tuesday, October 2, 2007
Lesson Learned: Always mention when you are going to analyze a machine
It's been an interesting week. People have been leaving the company in record amounts.
The latest occurred yesterday. The manager went to his boss, gave his resignation, said he was going for coffee and would be right back. He hasn't returned yet. At least as far as I've been told. My co-worker disabled the network account and email. He went down to the machine and uploaded to the network any files that were on the C: drive, thereby not being backed up.
We don't have a policy on what to do when a person leaves the company, willfully or not. I've tried. HR doesn't want the extra work.
Later in the afternoon, I figured I would take a look at the ex-employee's computer; looking for deleted files, pictures that shouldn't be, or anything else that shouldn't be on the company computer. So, later in the afternoon, having a few minutes to spare, I head down to the ex-employee's computer; wip out Helix, and start analyzing. I really didn't expect to find anything. I was sidetracked on the way, so I didn't mention to anyone where I was going.
I went to look at IE history, but accidentally hit the button for Nirsoft's Protected Storage Pass View. Well, the Trend Micro client installed on the machine picked it up as "hackerware." A note would be sent to the administrators. About ten minutes later, I there's a knock at the office door, and there standing outside is my co-worker and my boss. I quickly explained what I was doing. They were there because they thought the manager who left had come back and working maliciously on the computer. All was soon well. Important lesson learned, though. Let someone know what you are doing so as not to falsely set off alarms.
The latest occurred yesterday. The manager went to his boss, gave his resignation, said he was going for coffee and would be right back. He hasn't returned yet. At least as far as I've been told. My co-worker disabled the network account and email. He went down to the machine and uploaded to the network any files that were on the C: drive, thereby not being backed up.
We don't have a policy on what to do when a person leaves the company, willfully or not. I've tried. HR doesn't want the extra work.
Later in the afternoon, I figured I would take a look at the ex-employee's computer; looking for deleted files, pictures that shouldn't be, or anything else that shouldn't be on the company computer. So, later in the afternoon, having a few minutes to spare, I head down to the ex-employee's computer; wip out Helix, and start analyzing. I really didn't expect to find anything. I was sidetracked on the way, so I didn't mention to anyone where I was going.
I went to look at IE history, but accidentally hit the button for Nirsoft's Protected Storage Pass View. Well, the Trend Micro client installed on the machine picked it up as "hackerware." A note would be sent to the administrators. About ten minutes later, I there's a knock at the office door, and there standing outside is my co-worker and my boss. I quickly explained what I was doing. They were there because they thought the manager who left had come back and working maliciously on the computer. All was soon well. Important lesson learned, though. Let someone know what you are doing so as not to falsely set off alarms.
Friday, September 14, 2007
Update
There is no update.
My manager told me that they found out who was bringing the laptop in from home and connecting to our network. My manager mentioned that they've "talked" to the individual and are "assured" it will not happen again.
Personally, I think they don't want to discipline/fire a second employee in as many days.
And I think this offense is more egregious.
Sheesh.
My manager told me that they found out who was bringing the laptop in from home and connecting to our network. My manager mentioned that they've "talked" to the individual and are "assured" it will not happen again.
Personally, I think they don't want to discipline/fire a second employee in as many days.
And I think this offense is more egregious.
Sheesh.
Tuesday, September 11, 2007
My first run in with CP
At 8:30 Monday morning, the Director of HR called me to her office. I thought, "I haven't been in long enough to get in trouble." Little did I know what would be ahead of me. I knew I had a full plate of fires to put out; what was coming would dwarf everything for the day.
I reached her office and was told to shut the door. It seems there was an incident over the weekend. A female employee had logged into a computer and found "pictures inappropriate for work." There was probably more to the story, but I wasn't privy to it. I was asked to prove or disprove the accusation; and, if it was there find out how and when.
I took my laptop and retired to a smaller conference room, I really didn't want to do this from my cube. After shutting the door, I mapped a drive to the suspect machine, surfed to the My Pictures folder. Sure enough, there were pictures there. So, without opening anything, I copied the entire directory to a cdrom. Upon viewing the cdrom I was quickly able to verify that there were images inappropriate for work.
Now for the how and when. The when was pretty easy, as all the dates were the same. Could they be faked? Sure, but I didn't think so in this case. Next, I opened up regedit and connected to the suspect computer's registry. I looked in the currentcontrolset key, and found an iPod and Creative MuVo that were listed. When I found the Dos:E\ key, I pieced together that it appeared that the iPod was last listed as the E:\. However, the dates didn't match up. I knew the only way we would prove definitively is to get a hold of the iPod.
Before I started to write up my findings, the Director of HR met me in the conference room where I was working. My co-worker had just joined me and we were going over some other leads we wanted to chase down. The Director asked to see the pictures, mostly to see if there were other employees visible. Talk about awkward. But, I guess I had better get used to it. The first couple of pictures were definitely something taken from websites. Another bunch could have gone either way. But, while viewing the last couple, the Director asked me how old the girl was. Uh-oh.
So, we next formulated the steps to take. My part was easy, I was going to provide the facts; as best I knew them, and what I suspected, in order to fill in the holes. But, I tried to impress upon her that all the ducks had to be in a row.
After lunch, I got called into my manager's office, to find the President and the Director of HR. They asked for the cdrom. Calls had already been made to the company attorney. My manager asked me and my co-worker to go through mail and see if the pictures had been mailed anywhere; both in the company and out. Well, we found one outgoing mail message that was pretty incriminating. It was to an external address. My co-worker noticed that the email address was familiar. What?
It turns out the email address turned up in the firewall logs where we logged failed connection attempts to IM. Right after the IM failures, there was another email address with failures. So, we looked up the IP that the failures were coming from, and son of a gun if it wasn't something in the DHCP scope. Uh-Oh. A look at the the DHCP server showed a lease to a computer that we didn't name.
We've gone from proving a simple case of inappropriate images on the computer, to using an unapproved computer on our network. A quick scan of the firewall logs showed that this rogue computer had been on and off the network for about a month; usually third shift, and usually on the weekends. The sites they were visiting were typically web sites that allow you to IM when the firewall blocks those ports. We've pretty much proved that someone is trying to deliberately circumvent the access controls.
We had a quick meeting with upper management. We gave our statements and left. While chasing some last leads we see the accused go to HR. Of course he denied it. When pressed, he finally admitted most of what we knew. He tried to give what he thought was a valid explanation; but it wouldn't hold up in the face of the evidence we had.
Sit down now.......they didn't fire him on the spot. They let him go back to work until they had heard from the attorney. My co-worker and I almost fell over. I ran to my cube, and checked my mapped drive...sure enough, all the evidence was just deleted from his machine. (I was't too worried; worse case, we would have undeleted it.) Here's the good part, we set up the My Documents folder to redirect to the network. Should we need to, it's a simple restore.
Fast forward to today. The accused was fired first thing in the morning. I still haven't heard what the attorney has done. I wouldn't be surprised if the company gets subpoenaed for the data so that the authorities can go after him. As for the rogue laptop, my manager supposedly knows who it is, but nothing has been done. (Personally, I think this is a bigger offense, and has more risk. But that's just me.)
I went home wiped out. I hope the company doesn't screw this up, but I'm not holding my breath.
The good news is I got my tix for Bruce's new tour.
I reached her office and was told to shut the door. It seems there was an incident over the weekend. A female employee had logged into a computer and found "pictures inappropriate for work." There was probably more to the story, but I wasn't privy to it. I was asked to prove or disprove the accusation; and, if it was there find out how and when.
I took my laptop and retired to a smaller conference room, I really didn't want to do this from my cube. After shutting the door, I mapped a drive to the suspect machine, surfed to the My Pictures folder. Sure enough, there were pictures there. So, without opening anything, I copied the entire directory to a cdrom. Upon viewing the cdrom I was quickly able to verify that there were images inappropriate for work.
Now for the how and when. The when was pretty easy, as all the dates were the same. Could they be faked? Sure, but I didn't think so in this case. Next, I opened up regedit and connected to the suspect computer's registry. I looked in the currentcontrolset key, and found an iPod and Creative MuVo that were listed. When I found the Dos:E\ key, I pieced together that it appeared that the iPod was last listed as the E:\. However, the dates didn't match up. I knew the only way we would prove definitively is to get a hold of the iPod.
Before I started to write up my findings, the Director of HR met me in the conference room where I was working. My co-worker had just joined me and we were going over some other leads we wanted to chase down. The Director asked to see the pictures, mostly to see if there were other employees visible. Talk about awkward. But, I guess I had better get used to it. The first couple of pictures were definitely something taken from websites. Another bunch could have gone either way. But, while viewing the last couple, the Director asked me how old the girl was. Uh-oh.
So, we next formulated the steps to take. My part was easy, I was going to provide the facts; as best I knew them, and what I suspected, in order to fill in the holes. But, I tried to impress upon her that all the ducks had to be in a row.
After lunch, I got called into my manager's office, to find the President and the Director of HR. They asked for the cdrom. Calls had already been made to the company attorney. My manager asked me and my co-worker to go through mail and see if the pictures had been mailed anywhere; both in the company and out. Well, we found one outgoing mail message that was pretty incriminating. It was to an external address. My co-worker noticed that the email address was familiar. What?
It turns out the email address turned up in the firewall logs where we logged failed connection attempts to IM. Right after the IM failures, there was another email address with failures. So, we looked up the IP that the failures were coming from, and son of a gun if it wasn't something in the DHCP scope. Uh-Oh. A look at the the DHCP server showed a lease to a computer that we didn't name.
We've gone from proving a simple case of inappropriate images on the computer, to using an unapproved computer on our network. A quick scan of the firewall logs showed that this rogue computer had been on and off the network for about a month; usually third shift, and usually on the weekends. The sites they were visiting were typically web sites that allow you to IM when the firewall blocks those ports. We've pretty much proved that someone is trying to deliberately circumvent the access controls.
We had a quick meeting with upper management. We gave our statements and left. While chasing some last leads we see the accused go to HR. Of course he denied it. When pressed, he finally admitted most of what we knew. He tried to give what he thought was a valid explanation; but it wouldn't hold up in the face of the evidence we had.
Sit down now.......they didn't fire him on the spot. They let him go back to work until they had heard from the attorney. My co-worker and I almost fell over. I ran to my cube, and checked my mapped drive...sure enough, all the evidence was just deleted from his machine. (I was't too worried; worse case, we would have undeleted it.) Here's the good part, we set up the My Documents folder to redirect to the network. Should we need to, it's a simple restore.
Fast forward to today. The accused was fired first thing in the morning. I still haven't heard what the attorney has done. I wouldn't be surprised if the company gets subpoenaed for the data so that the authorities can go after him. As for the rogue laptop, my manager supposedly knows who it is, but nothing has been done. (Personally, I think this is a bigger offense, and has more risk. But that's just me.)
I went home wiped out. I hope the company doesn't screw this up, but I'm not holding my breath.
The good news is I got my tix for Bruce's new tour.
Thursday, September 6, 2007
You can't make this stuff up...
Subscribe to:
Posts (Atom)

