Posts

Chip Andrews Webcasts on SQL Server Security

Image
Chip Andrews of SQLSecurity.com and co-founder of Special Ops Security will present his fourth Webcast on SQL Server Security tomorrow morning. I hadn't heard about these previously, but I am sure they are excellent. Chip was also author of the excellent SQL security book pictured at left, SQL Server Security .

What Does Your ISP Block?

The only low cost broadband provider in my neighborhood is Comcast . I determined this evening that they block ports 135-139 and 445 TCP inbound and outbound. What ports does your ISP block? I am seriously considering getting a T-1 from Speakeasy .

Request for Comments on NSA IAM and NSA IEM

Does anyone have experience with NSA's Infosec Assessment Methodology and Infosec Evaluation Methodology ? Through my local ISSA chapter , I've signed up to take courses on both programs for a combined price less than that offered for the IAM alone at another venue. Being a consultant in the DC metro area, I believe I am going to hear NSA IAM and IEM mentioned more frequently. Any thoughts?

TaoSecurity Podcast

I've been considering launching an audio supplement to this blog called the TaoSecurity Podcast . I have more than a dozen "show elements" that I could mix and match every two weeks or so, discussing digital security, incident response, network forensics, FreeBSD, and other subjects carried here. Would anyone be interested in such a program? If so, please leave a comment. Also, what would you want me to cover, and how often? Thank you.

Cool Site Unfortunately Miscategorizes Threats

Image
While chatting with Aaron Higbee of the SecureMe Blog yesterday, he mentioned a cool new site: Threats and Countermeasures . A majority of the contributors are Foundstone consultants and parent company McAfee is paying the bills. Anyone who's been reading my blog for a while knows of my linguistic crusade involving words in the standard risk equation, with risk being a product of threat, vulnerability, and asset value. (See Risk, Threat, and Vulnerability 101 , OCTAVE Properly Distinguishes Between Threats and Vulnerabilities , SANS Confuses Threats with Vulnerabilities , and The Dynamic Duo Discuss Digital Risk .) How does the Threats and Countermeasures site match proper definitions? At left is a screen shot of the site's main knowledge base menu. I don't see the word threat being used correctly here. "Default network appliance passwords" aren't threats; those are vulnerabilities. "Running unnecessary services" is a vulnerability, as is...

My Criteria for Good Technical Books

I was recently asked if I would review an upcoming book. In my reply, I listed four criteria I use when making my review evaluations. Accuracy. If a book contains several large or numerous small technical errors, I will lower my rating. I may stop reading entirely if I lose confidence in the author's capacity to deliver reliable information. This is a problem if I am reading a book outside my core expertise. Originality. I really dislike reading books that cover material already published elsewhere. I do not mind some repetition if the result makes sense, but in most cases authors should just start covering new material. For example, I would prefer a new book on network attack and defense to avoid explaining TCP/IP. Authors: if a book explaining your introductory material already exists, cite that title and present your new material in your book. Brian Carrier's book is a great example of how to make me happy. He doesn't bother explaining security; he sets u...

Trying Microsoft Update and MBSA 2.0

Image
Today while updating my Windows 2000 laptop I had the opportunity to try two new Microsoft programs. The first is the new Microsoft Update , more of a one-stop-shop for Windows patches. The second is version 2.0 of Microsoft Baseline Security Analyzer . Computerworld has some coverage, but here was my experience. When I started Windows Update, I saw the following screen. I decided to follow the "Upgrade" recommendation. After running Microsoft Update, I got these results. You can see that Microsoft Office updates and updates for other Microsoft programs are available. I think the new interface works well. Once I downloaded and installed all of the updates, I turned to the new MBSA 2.0. It doesn't look that much different, so the improvements are under the hood. I got my results following the scan of the single laptop. I don't necessarily agree with the "severe risk" assessment. I think MBSA complained because it found a FAT partition I use to share d...