Tuesday, May 13, 2008
Vista Security is quite impressive!
Ok So I've been working with Vista and doing some understanding of how it works under the covers. Its actually quite amazing the amount of effort and innovation that was put into the security subsystems. I'll be blogging over the next few weeks about some of the more impressive features like UIPI, Address Space Load Randomization (ASLR), New service security with service SIDs, etc.
So look forward to more ;)
Thanks,
Duane Laflotte
http://www.CyberSpaceSamurai.com
5/13/2008 8:46 PM Eastern Daylight Time  #    Disclaimer  |  Comments [1]  | 
 Monday, May 12, 2008
Data Appliance Encryption
Recently I've spoken to the engineers at Decru. They have developed an appliance that will encrypt data as it hits disk such as Network Appliance storage filers. Now in the past I've spoken to developers and engineers who support/sell encryption solution and found most dont know what they are talking about. I'm happy to report thats not the case with Decru. I had a great conversation with one of their engineers about cryptography, cbc, ciphers, etc. It seems they are doing very well in the financial and government market. Not really a surprise. Just thought I would give my two cents for those out there interested in encryption of storage.

Duane Laflotte
http://www.CyberspaceSamurai.com

5/12/2008 1:13 AM Eastern Daylight Time  #    Disclaimer  |  Comments [0]  | 
 Friday, March 14, 2008
SPAM
It is amazing to me how epic the issue of spam has become.  It not only takes up large percentages of each of our inboxes each day but also is wasting tons of bandwidth on the Internet.  Spam has become so cumbersome to handle that it now can even act as a denial of service attack. 

I've had several customers I've worked with in the past on spam issues and recently had a buddy call me up explaining his woes with spam as well.  The sheer volume of spam that is received is more than the mail servers can handle.  This can either delay valid mail from coming in (sometimes for days!) or could just shutdown the mail gateways ability to respond to anything. 

The question of "How is this solved" is a big one.  There are many technologies that help filter out mail, make sure that mail truly is valid for your organization before it’s allowed inside your company.  But the unfortunate problem is even allowing spam to hit your gateway so it can make that decision can flood most corporate Internet connections. 

In these cases one of the best solutions we've found is to use an outside mail filtering service.  I know CriticalSites even uses one called Fast PC Net (http://www.fastpcnet.net/ ).  You essentially point your MX records at that services mail server.  They take in all the mail and filter out the spam.  Giving you nice clean email.  Not a bad solution if you find yourself in this situation of just too much spam to handle.

Hope this helps

Duane

http://www.CyberSpaceSamurai.com

3/14/2008 8:41 AM Eastern Daylight Time  #    Disclaimer  |  Comments [0]  | 
 Saturday, January 27, 2007
How to protect yourself from phishing attacks!

Thanks to the team at Network Security Journal.  They've created a great article on phishing.  Their "The Fight Against Phishing: 44 Ways to Protect Yourself" is very comprehensive.  I would suggest everyone give it a read.

Safe coding,

Duane Laflotte

http://www.CyberspaceSamurai.com

1/27/2007 12:15 AM Eastern Standard Time  #    Disclaimer  |  Comments [2]  | 
Barracuda spam firewalls are awesome!

Just thought I would share :)  We have many clients that are plagued by spam.  In recent time I've been working with Barracuda Networks and their spam firewall series of product.  Its awesome!  I was skeptical at first.  Being the security guy I am I've never been one to just "trust" that some black box is going to protect me from spam, hackers, etc.  But this thing has been great.  It really does take a few minutes to setup and it starts working right away.

Just to give you an idea of how much spam actually hits a normal company.  I'm working with a client that gets 150,000 pieces of mail a day in their SMTP gateway.  Insert that Barracuda and checking the stats we realize that 135,000+ a day of that is spam!!  They were floored.  Imagine less then 10% of your mail traffic is actually not spam.  These results are with the Barracuda set at default.  Now thats impressive.

Just thought I would let you all know.  If your ever in the market for a spam firewall this one truly gets my approval.  Nice work Barracuda Networks!

Safe coding!

Duane Laflotte

http://www.CyberspaceSamurai.com

1/27/2007 12:05 AM Eastern Standard Time  #    Disclaimer  |  Comments [5]  | 
 Thursday, January 18, 2007
Code Camp 7!!!

Sweet!  There is another code camp that was just announced by Chris Bowen (Our New DE).  I'm sure over the coming weeks there will be an agenda but you can be sure to count Patrick and I in as speakers on this next one.  ;)
http://blogs.msdn.com/cbowen/archive/2007/01/17/save-the-dates-code-camp-7-deer-in-headlights.aspx
So Get ready for a wild ride.  We have TONS of new content to talk about.  If anyone has suggestions of topics they want to hear related to security let me know and I'll see if I can put a presentation together for CC7. 

Safe Coding!
Duane Laflotte
http://www.cyberspacesamurai.com

1/18/2007 9:22 AM Eastern Standard Time  #    Disclaimer  |  Comments [0]  | 
 Sunday, July 02, 2006
SCMagazine (Great security resource)

I usually try to get as much information about security as possible.  Recently I was pointed at http://www.scmagazine.com/us .  This is a e-magazine that is totally devoted to security topics, products, and alerts.  They have some great security articles.  Although, being a consultant and always looking for new security products, the part of the site I really dig their product reviews!  Great job guys keep it up!

Duane Laflotte

www.CyberspaceSamurai.com

 

7/2/2006 7:25 AM Eastern Daylight Time  #    Disclaimer  |  Comments [2]  | 
 Monday, May 22, 2006
Got my xbox 360 back.

Ok... So last post on my xbox ;) promise.

Since I posted my support call with xbox live I've received no less then 30-40 searches a day about people having the same problem from the UK, France, Italy, and here in the US.  ;)  Seems a number of us are having the same issue.

Got my xbox360 back finally!  Opened the box, plugged everything in.. Turned it on.... and.....

 

Error!!!  The lower right light started flashing red and the TV displayed a "This xbox need to be repaired" message in about 28 different languages :(.  So I turned it off and on a few times and if fired up finally.  I havent seen it since but I think I need to spend some serious time burning it in now to make sure it works before the warrantee is out.  So if anyone wants to hit some Battle Field MC or Ghost Recon AW (GRAW). 


Send me a invite ( xbox live ID Onosendai)

Thanks,
Duane Laflotte
http://www.CyberspaceSamurai.com

5/22/2006 9:15 AM Eastern Daylight Time  #    Disclaimer  |  Comments [4]  | 
 Wednesday, May 10, 2006
XBOX 360 Broken again!

Ok I'm usually a very nice guy :)  No really.  I'm quite calm and good under pressure... but when I get on with tech support sometimes I just want to scream. 

So I, like most xbox lovers, went out an bought a 360!  pre-ordered it last July and got it this January.  I was loving life.  Some game are good, graphics are awesome, etc.  But my first xbox 360 (yes I said first) wouldnt connect to my network (so no xbox live!).  Below is listed the highlights of my 6+ hours of calls with support:

Xbox Support Guy: “Duane, I’ve found your problem.  You told me you had a CAT-5 cable plugged into the back of the XBOX.  We do not support that.  You need to plug in EITHER an Rj-45 cable OR and Ethernet cable and that will work”

I then explained how networking works to this guy and what all those terms he was using meant so he would know for the future.

 

Or this

 

Xbox Support Guy: “Sir I know why you aren’t getting an IP address on your xbox.  You need to open up your firewall ports and that should work”

Duane: “Are you sure you know what a firewall is?  Let me help you out.  A firewall is all about blocking access from the internet back to my resources inside my network.  Now my firewall acts as a DHCP server and gives out IP addresses.  I don’t seem to have an IP address because the link light on the xbox network adapter isn’t lit… Make sense?”

Xbox Support Guy: “Sir I thought you weren’t using the wireless network adapter”

Duane: “Where in my last statement did you hear me utter the phrase “Wireless Network Adapter”?”

Xbox Support Guy: “So do you need me to walk you through opening your firewall ports?”


Or this
 

Xbox Support Guy: “I would like it if I could test not using the network jack.. but using the USB network jack in the back of the XBOX.  Can you plug a USB cable into the back of the xbox and then into the back of your cable modem”

Duane: “That is a great idea but my cable modem is 60 feet from my xbox so I don’t have a usb cable long enough”

Xbox Support Guy: “Can you move your xbox”

Duane: “Another wonderful idea I sure can!  But then what will I actually be watching when I turn on the xbox as now my TV will be 60 feet away from my xbox”

Xbox Support Guy: “Can you move your TV to your xbox and cable modem?”

Duane: “I have a 36” WEGA TV.  Its about 280lbs.  No I cant move it”

Xbox Support Guy: “Do you have a smaller TV?”

Duane: “Sure I do I have this wonderful 10” TV just sitting on the table next to me ready to move to my cable modem and xbox I figured that when you asked me to move my TV you obviously wanted me to move the heaviest f’ing TV I own…”

<Silence>

Duane: “No I don’t have another TV.”

I love support.  So I get home tonight and decide I was going to call xbox support (for the third time) and this is how it goes.... (I'm writing this as its happening on support phone call right now!!)

Xbox Support "So when you plug in your xbox to your pc do you see a pc light?"

Me:  "Do you mean when I plug in my xbox into the modem do I see a link light?"

Xbox Support: "Yeah!  Thats it.  Do you?"

Me:  "No I dont.  When I plug in my laptop I see the link light but when I plug the xbox in no link light"

Me:  "And I've also tried three different Ethernet cables and those dont work either"

Xbox Support: "Which three did you try?"

Me (after a pause): "I tried that blue one, a short red one, and a kinda purpleish one"

Xbox Support:  "Let me check to see if those are supported and will work"

Me... waiting....

Xbox Support:  "Ok Sir goto the network settings on your xbox"

Me: "Ok"

Xbox Support: "Do you see the link light there"

Me: "yes"

Xbox Support: "Its should be solid green" <-- I can tell she is reading out of a step by step "how to diagnose the xbox" book

Me: "Its not its red"

Xbox Support: "Well thats your problem right there"

Me:  "What the fact that I dont have a connection to my cable modem?"

Xbox Support: "No that your link light is red and it should be green"

Me: *Sigh*

Xbox Support:  "Sir can you look at the A C T light.  It should flash yellow when data is going over the wire.  Is it flashing yellow"

Me:  "No the activity light is not flashing"

Xbox Support" "The A C T light is not flashing?"

Me: "No.."

Xbox Support: "Well thats weird.  It says here it should be flashing"

Me:  "Its not flashing cause I have no link light..."

Xbox Support:  "Can you check the wire for physical damage?"

Me: "Which one of the three different cables that I've tried did you want me to check"

Xbox support: "Ummm.... The one plugged in I think " <-- smartest thing she said all night

Me:  "Nope looks great"

Xbox Support:  "Oh good cause I would have had to ask you to try another cable if you had one"

Me waiting for her to comprehend what she just said...

Xbox Support: "Oohh wait you said you had three cables right"

*sigh*

Finally the manager gets on and says...

"Sir I see you've been on calls with support for many hours over the last few weeks.  I really apologize.  I think we have enough data here to decide you have a bad network jack.  I'm going to authorize the repair, I will have all the supplies over nighted to you so we can get you back up and running quickly as you have been down for soo long.  I apologize for the time it took and the run around you were getting.  Thank you very much."

Me:  "I love you mr. supervisor man"

 

 

Soooo I get my SECOND xbox 360 and after a week of play now when I turn it on I get just a series of flashing red lights :(  Nothing else, no video no game play no nothing just three damn red lights on the front of my "refurbished" xbox 360.  Soo I call support... AGAIN..

 

XBOX Support:  "Can you turn the unit off"

Me: "Sure"

XBOX Support:  "OK turn it back on... Whats it doing?"

Me: "Flashing three red lights"

Xbox Support: "Ok can you turn it off and unplug it"

Me: *sigh* "Sure"

Xbox Support:  "OK turn it back on... Whats it doing?"

Me: "Flashing three red lights"

Xbox Support: "Ok can you turn it off and take out the hard drive"

Me: *sigh* "Sure"

Xbox Support:  "OK turn it back on... Whats it doing?"

Me: "Flashing three red lights"

Xbox Support: "Does it always flash three red lights?"

Me: "No if I turn it on and off like 100 times it sometimes fires up"

Xbox Support: "Ok here is a ref#.  Can you play with the xbox for a few days to see if the problem resolves.  If not call us and we can replace it again"

Me: "By "Play with it" you mean turn it on, watch the three red lights, turn it off, and turn it back on to watch the three red lights again?"

Xbox Support: "Yes sir."

***** So I called back a few days later ******

Xbox Support: "Still red lights... ok we will have to send your xbox back for repair."

Me: "Does it matter that this is now my second xbox I'm getting repaired?  can we expedite it?"

Xbox Support: "No it doesnt matter.  We will send you a box, it will get there in 3 days, you will send it back to us, we will get it in 3 days, it will take 8 days to "fix it" (just sending me a refurb) and then 3 days back to you"..

 

 

Soo long story short.. I'm still waiting for my xbox... again...

Duane Laflotte

http://www.cyberspacesamurai.com

5/10/2006 11:38 AM Eastern Daylight Time  #    Disclaimer  |  Comments [37]  |