<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nirlog.com &#187; Security</title>
	<atom:link href="http://nirlog.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://nirlog.com</link>
	<description>Technology, Life and other stuff that come along...</description>
	<lastBuildDate>Sat, 14 Jan 2012 15:42:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Moving on&#8230;</title>
		<link>http://nirlog.com/2012/01/14/moving-on/</link>
		<comments>http://nirlog.com/2012/01/14/moving-on/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 15:09:06 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[job]]></category>
		<category><![CDATA[mimecast]]></category>
		<category><![CDATA[uk]]></category>

		<guid isPermaLink="false">http://nirlog.com/?p=427</guid>
		<description><![CDATA[I’ve had a privilege of working with global service provider, experienced first-hand the benefits and pitfalls of outsourcing, got my hands dirty with many different network security technologies, designed and supported many challenging network security solutions for global enterprises.Thanks Reliance Globalcom for the opportunity. But now it’s time to move on, new challenge, new industry&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve had a privilege of working with global service provider, experienced first-hand the benefits and pitfalls of outsourcing, got my hands dirty with many different network security technologies, designed and supported many challenging network security solutions for global enterprises.Thanks Reliance Globalcom for the opportunity.</p>
<p>But now it’s time to move on, new challenge, new industry&#8230;</p>
<p>I’ve now joined <a href="http://www.mimecast.com/">Mimecast</a> as a Technical Operations Engineer.</p>
<p><a href="http://www.mimecast.com"><img src="http://nirlog.com/wp-content/uploads/2012/01/Mimecast.png" alt="Mimecast" title="Mimecast" width="221" height="58" class="alignnone size-full wp-image-428" /></a></p>
<blockquote><p>Mimecast provides email management as a single service in the cloud that helps you slash on-premise email storage requirements, ensure complete email availability, email security and email compliance, while providing services to help you get more from your email.  We call it &#8220;Unified Email Management&#8221;.</p></blockquote>
<p>Here’s a <a href="http://www.youtube.com/v/vF5j7rvQjgs&#038;rel=0">video</a> that explains how mimecast service works.</p>
<p>I’m really excited about this new role and the new challenge where I’ll be working with core grid team to maintain, design and build core infrastructure, network and security.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2012/01/14/moving-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon Marketplace scam</title>
		<link>http://nirlog.com/2009/06/21/amazon-marketplace-scam/</link>
		<comments>http://nirlog.com/2009/06/21/amazon-marketplace-scam/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 11:23:22 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://nirlog.com/2009/06/21/amazon-marketplace-scam/</guid>
		<description><![CDATA[For last few months I&#8217;d been craving for a DSLR. I thought it was about time to take a step forward from my old point n shoot Canon Powershot S50 and upgrade it to a decent DSLR. BTW, my wife and I are expecting our second child in mid July and thought it&#8217;s the right [...]]]></description>
			<content:encoded><![CDATA[<p>For last few months I&#8217;d been craving for a DSLR. I thought it was about time to take a step forward from my old point n shoot Canon Powershot S50 and upgrade it to a decent DSLR. BTW, my wife and I are expecting our second child in mid July and thought it&#8217;s the right time to have a quality camera to take nice pictures. Spent quite some time researching which camera to buy that fitted my requirements and budget. I narrowed it down to <a href="http://www.digitalreview.ca/content/Nikon-D5000-D90-Compared-to-Canon-Rebel-T1i-500D.shtml">Nikon D90, Nikon D5000 and Canon Rebel T1i / EOS 500D</a>, and finally decided to go for Nikon D90.</p>
<p>I was keeping my eye on the price of D90 in UK at <a href="http://www.camerapricebuster.co.uk/prod724.html">Camera Price Buster</a> (very useful site indeed!). When I was ready to buy it from Currys  (it was £709.00 at that time), just decided to do a last minute check on Amazon (I prefer buying from Amazon because never had any problems in the past) and to my surprise Nikon D90 Digital SLR Camera, 18-105 VR Kit was there for just £649.99 by a seller called &#8220;rodneyjwillis&#8221;. Almost £60 cheaper, Excellent &#8211; I thought. Checked the sellers profile/review &#8211; it had 100% positive feedback from the buyers, nice comments and seller was with Amazon for almost a year. So, ordered it from Amazon marketplace. I didn&#8217;t see anything phisy at that time and anyway I was aware that paying via Amazon will guarantee my purchase with their <a href="http://www.amazon.co.uk/gp/help/customer/display.html/?nodeId=3149571&amp;#what">A-to-z guarantee scheme</a>.</p>
<p>When all other stuff I ordered together with D90 arrived (camera bag, sd card and d90 book), but there was no sign of my D90 being dispatched, let alone delivered. I sensed something was wrong. Went back and checked the seller&#8217;s profile &#8211; there was one new feedback saying</p>
<blockquote><p>&#8220;BEWARE! This account is being used in a scam &#8211; items don&#8217;t arrive!&#8221;</p></blockquote>
<p><img src="http://nirlog.com/wp-content/uploads/2009/06/rodneyjwills-profile.jpg" height="486" width="420" border="1" hspace="4" vspace="4" alt="Rodneyjwills-Profile" /></p>
<p><span id="more-294"></span></p>
<p>That got me worried. Sent seller an email and alerted Amazon that this might be a scam. The storefront of the seller was immediately taken off (I guess by Amazon)</p>
<p><img src="http://nirlog.com/wp-content/uploads/2009/06/store-front.png" height="137" width="420" border="1" hspace="4" vspace="4" alt="Store-Front" /></p>
<p>Contacted the seller for the status of my delivery &#8211; got an email next day saying, the item was dispatched (without any details):</p>
<p><img src="http://nirlog.com/wp-content/uploads/2009/06/rodney-email-1-1.jpg" height="234" width="420" border="1" hspace="4" vspace="4" alt="Rodney-Email-1-1" /></p>
<p>I then replied asking when was it dispatched, if he was sending it from UK and if he could give me the tracking number. In reply I received another copy of exactly the same email. Called Amazon several times and sent several emails. By now I had no doubt in my mind that it was a scam and I wanted my money back, but amazon was sticking to it&#8217;s  policy of waiting for the 3 days to pass after the seller&#8217;s advertised delivery date, which was 11 to 23 June ( I actually placed the order in 5th June). That meant I could only file a-to-z claim after 26th June (which is 3 weeks after my order), and would have to wait for amazon&#8217;s investigation (one to two weeks), then when they transfer the money back, it can take up to another 10 days to end up in your account. Almost 2 months before you get your money back in worst case scenario.</p>
<p>I think it&#8217;s totally unacceptable for a clear fraud case like this!</p>
<p>When I sent a last email to the seller (June 16) &#8211; got this auto-reply saying his amazon account was closed.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2009/06/rodney-email-2.jpg" height="247" width="420" border="1" hspace="4" vspace="4" alt="Rodney-Email-2" /></p>
<p>After a week of persistent complaining Amazon finally filed the a-to-z claim on my behalf. All in all it was a very dreadful experience. What a waste of time! I&#8217;ve spent most of my last week just checking the sellers profile, reading other victims comments, contacting Amazon and worrying&#8230;</p>
<p>Here&#8217;s the <a href="http://www.amazon.co.uk/gp/help/seller/home.html?ie=UTF8&amp;isAmazonFulfilled=0&amp;marketplaceID=A1F83G8C2ARO7P&amp;isCBA=&amp;orderID=203-6516212-3369918&amp;asin=&amp;marketplaceSeller=0&amp;seller=AOFWYI0HCM3IC&amp;isPopup=">link to scammer&#8217;s amazon profile</a>, at the time of this writing more than 70 people have fallen victim to this scam.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2009/06/rodneyjwills-profile-latest.jpg" height="624" width="420" border="1" hspace="4" vspace="4" alt="Rodneyjwills-Profile-Latest" /></p>
<p>I&#8217;m sure everyone who paid via amazon will get their money back but Amazon has failed here in a big way. Looks like the seller has duped Amazon more than the buyers. At the end of the day buyers will get their money back. Amazon is the real loser here &#8211; the lost customer confidence is more costly for them than the refund they&#8217;ll have to make. Amazon should have been more proactive to refund the money to customers since it was a clear fraud case, which happened due to weaknesses in their Marketplace system, but they kept on dragging.</p>
<p>Every amazon&#8217;s email had this signature:</p>
<blockquote><p>&#8220;We&#8217;re Building Earth&#8217;s Most Customer-Centric Company&#8221;</p></blockquote>
<p>But I wasn&#8217;t convinced. You couldn&#8217;t reply to any emails they sent you because the emails were sent from addresses that cannot accept incoming emails. There might be a valid security reason for doing that but as a customer it was quite difficult to track my email conversation with them (the online contact form didn&#8217;t keep any record of my previous emails to them either). I found Amazon&#8217;s telephone support to be better than their email.</p>
<p>This just shows that it&#8217;s not all safe and well on online purchases. The scammers can trick not only innocent users but successfully dupe big companies like Amazon.</p>
<p>Finally the money refunded by Amazon has appeared in my account.  I&#8217;m off to local <a href="http://www.argos.co.uk/">Argos</a> store to get my D90.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2009/06/21/amazon-marketplace-scam/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Sourcefire and SFCP Certification</title>
		<link>http://nirlog.com/2009/04/13/sourcefire-and-sfcp-certification/</link>
		<comments>http://nirlog.com/2009/04/13/sourcefire-and-sfcp-certification/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 11:59:02 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2009/04/13/sourcefire-and-sfcp-certification/</guid>
		<description><![CDATA[Hurray&#8230;! My intense work for last couple of weeks has finally paid off. Yeah, I&#8217;ve just passed my SFCP (Source Fire Certified Professional) Certification Exam. First briefly about the company &#8211; Sourcerfire was founded by the author of Snort (an open source network intrusion prevention and detection system). Snort is the most popular and widely [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://nirlog.com/wp-content/uploads/2009/04/sfcppin.jpg" height="206" width="250" border="1" align="right" hspace="4" vspace="4" alt="Sfcppin" />Hurray&#8230;! My intense work for last couple of weeks has finally paid off. Yeah, I&#8217;ve just passed my <a href="http://www.sourcefire.com/services/education#sfcp">SFCP</a> (Source Fire Certified Professional) Certification Exam.</p>
<p>First briefly about the company &#8211; <a href="http://www.sourcefire.com/">Sourcerfire</a> was founded by the author of <a href="http://snort.org/">Snort</a> (an open source network intrusion prevention and detection system). Snort is the most popular and widely deployed IDS/IPS and has become the de facto standard for the industry.</p>
<p>So, why do we need Sourcefire (very expensive) if Snort is the best and free?</p>
<p>Right, Snort is the best and free out there but it&#8217;s implementation, management and maintenance is not a piece of cake for everyone; that&#8217;s where sourcefire comes into play. Sourcefire uses snort at it&#8217;s heart to utilize it&#8217;s powerful IDS/IPS techonology, with added benefit of plug-n-protect simplicity (the purpose-built appliance is easy to install, maintain and manage), and it comes with tons of extra features that make it very powerful. Sourcefire adds an Adaptive IPS and Enterprise Threat Management (ETM) on top of the Snort IPS. It is managed via user-friendly and intuitive web interface, of course you can always do your advanced config from the shell because it&#8217;s a snort installed in a linux box anyway.</p>
<p><strong>Components of</strong><strong><a href="http://www.sourcefire.com/products/3D"> Sourcefire 3D System</a></strong></p>
<p>Sourcefire 3D System is comprised of two appliances (Sourcefire Defense Center and Sourcefire 3D Sensor).</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/defense_center">Sourcefire Defense Center (DC)</a></strong> is a centralized management console to manage the sensors, centralized event aggregation and sensor policy administration.</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/sensor">Sourcefire 3D Sensors</a></strong> are purpose-built network security appliances that passively aggregate network and user intelligence while defending the network against internal and external threats.</p>
<p><strong>3D Sensor Modules<br />
</strong><br />
Each Sourcefire 3D Sensor is capable of running any combination of the following four software components (you need to buy them separately):</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/ips">Sourcefire IPS (Intrusion Prevention System)</a></strong> it&#8217;s the mighty snort running in background, where you can use rules-based detection engine and utilize the acclaimed <a href="http://www.snort.org/vrt/">Vulnerability Research Team (VRT)</a> to protect your network. The IPS component is included in the base system.</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/rna">Sourcefire RNA (Real-time Network Awareness)</a></strong><strong> </strong>passively monitors real-time network traffic and gathers network intelligence, it can detect operating systems, services, applications, protocols, and potential vulnerabilities that exist on your network. This is a very useful component of Sourcefire but you&#8217;ll need to buy the RNA license separately.</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/rua">Sourcefire RUA (Real-time User Awareness)</a></strong> helps to identify the user identity and contact information, it pairs Active Directory and LDAP usernames with host IP addresses involved in security and compliance events. You&#8217;ll need to buy the RUA license separately.</p>
<p><strong><a href="http://www.sourcefire.com/products/3D/netflow">Sourcefire NetFlow Analysis</a></strong> is an optional component of Sourcefire’s Network Behavior Analysis (NBA) solution. It gives additional insight to network threats by aggregating and analyzing NetFlow from routers and switches.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2009/04/master-defence-center.jpg" height="221" width="420" border="1" hspace="4" vspace="4" alt="Master-Defence-Center" /><br />
Sourcefire 3D System deployment with Master Defense Center</p>
<p>OK that was about sourcefire. Here&#8217;s how you go about getting certified.</p>
<p><span id="more-292"></span><br />
<strong>Training Course</strong></p>
<p>Sourcefire offers several <a href="http://www.sourcefire.com/services/education/courses">instructor-led classroom training</a> for Sourcfire 3D systems, out of which <a href="http://www.sourcefire.com/elqNow/elqRedir.htm?ref=http://www.sourcefire.com/resources/downloads/public/training/SF3D_360_Bundle.pdf?a=1%26b=2%23go">SF3D 360 Bundle</a> is the one I took.</p>
<p>Sourcefire 3D™ 360 Bundle Includes:</p>
<blockquote><p>• Instructor-led Training Sourcefire 3D™ (4 days)<br />
• Sourcefire Certified Professional (SFCP) Certification Exam<br />
• Sourcefire Guarantees<br />
• CPE Credits 32 (for CISSPs)</p></blockquote>
<p><strong>Course Outline<br />
</strong></p>
<blockquote><p>• Sourcefire 3D System Sensor Deployment and Communications Architecture<br />
• Sourcefire 3D System Overview &#38; Product Installation<br />
• Interface Navigation and Dashboard views<br />
• Sensor Configuration and Management with the Defense Center<br />
• Configuring Interface Sets and Detection Engines<br />
• Administration, Maintenance and System Policy<br />
• System Health Monitoring and Alerting<br />
• Real-time User Awareness<br />
• Adaptive Profiles<br />
• User Account Management<br />
• IPS &#38; RNA Detection Policy Configuration<br />
• Compliance Policy, White Lists and Host Attributes<br />
• Event Analysis and Reporting<br />
• End-Point Intelligence<br />
• Flow Data Analysis and Network Profiling<br />
• Nmap and Nessus Scanning<br />
• Basic Rule Structure and Syntax<br />
• IPS Features and Configuration<br />
• Trouble Shooting and Behind-The-GUI Navigation and Architecture</p></blockquote>
<p><strong>Certification Exam</strong></p>
<blockquote><p>The following products and skill areas are assessed through this process:</p>
<p>• Intrusion Management System<br />
• Intrusion Sensors<br />
• Defense Center<br />
• RNA Sensor<br />
• Installation and Deployment<br />
• Administration and Management<br />
• Policy Configuration and Management<br />
• Policy Non-compliance and Remediation<br />
• User Administration and Management<br />
• Reporting Creation and Management<br />
• Effective and Performance Oriented Rule Writing</p></blockquote>
<p>The certification exam itself consists of 200 multiple choice questions, which you&#8217;ll have to complete within 4 hours. Passing score is 75%, you&#8217;ll immediately know whether you pass or fail and if you pass the exam certificates are available online for you to print.</p>
<p>I found the instructor-led course very helpful. I have worked with snort before but this was my first introduction to Sourcerfire. After the 4 day course, you&#8217;ll have 60 days to prepare and take the exam. Every student is given a second attempt if a passing grade of 75% or better is not achieved on the first attempt.</p>
<p>To prepare for the exam, I went through the training material (page by page) one more time. I also had an access to sourcefire boxes installed in our office lab so, it was very useful. It&#8217;s an open book exam, you&#8217;ll have slightly more than a minute to answer each question, so you won&#8217;t have enough time to go through your materials during the exams. You&#8217;ll need to know your stuff to pass it, but having an access to sourcefire box at the time of exam will be very handy (for the user interface questions).</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2009/04/13/sourcefire-and-sfcp-certification/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>facebook&#8217;s new terms of service: &#8220;anything you upload can be used by facebook&#8221;</title>
		<link>http://nirlog.com/2009/02/16/facebooks-new-terms-of-service-anything-you-upload-can-be-used-by-facebook/</link>
		<comments>http://nirlog.com/2009/02/16/facebooks-new-terms-of-service-anything-you-upload-can-be-used-by-facebook/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 22:29:43 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2009/02/16/facebooks-new-terms-of-service-anything-you-upload-can-be-used-by-facebook/</guid>
		<description><![CDATA[Thanks to facebook I&#8217;ve come in contact with many of my childhood buddies, neighbors, old school mates to university friends. It&#8217;s a place to be. Even when you&#8217;re busy, you just login once a day to check what your friends and families are up to. It provides sleek, friendly and relatively non-intrusive environment to interact. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://nirlog.com/wp-content/uploads/2009/02/fb.jpg" height="56" width="150" border="1" align="left" hspace="4" vspace="4" alt="Fb" />Thanks to facebook I&#8217;ve come in contact with many of my childhood buddies, neighbors, old school mates to university friends. It&#8217;s a place to be. Even when you&#8217;re busy, you just login once a day to check what your friends and families are up to. It provides sleek, friendly and relatively non-intrusive environment to interact.</p>
<p>I&#8217;ve to say that I&#8217;ve been quite reluctant to install third-party apps and post family photos due to privacy concerns, but this new <a href="http://www.facebook.com/terms.php?ref=pf">terms of service</a> makes it worse. Now anything you post or upload can be used by facebook even after you close your account. In previous terms of service, facebook&#8217;s rights on your content would expire after you closed your account, but not any more.</p>
<p>via: <a href="http://consumerist.com/5150175/facebooks-new-terms-of-service-we-can-do-anything-we-want-with-your-content-forever">Consumerist</a></p>
<p><strong>Update (17Feb09):</strong> facebook ceo, Zuckerberg has <a href="http://blog.facebook.com/blog.php?post=54434097130">written a blog post</a> about the issue, trying to explain why they need this TOS.</p>
<blockquote><p>Our philosophy that people own their information and control who they share it with has remained constant. A lot of the language in our terms is overly formal and protective of the rights we need to provide this service to you. Over time we will continue to clarify our positions and make the terms simpler.</p></blockquote>
<p><strong>Update (18Feb09):</strong> After a global complain facebook has returned to previous terms of service (until they find a new language to clarify their position). Zuckerberg explains it in his <a href="http://blog.facebook.com/blog.php?post=54746167130">Update on Terms</a></p>
<blockquote><p>We concluded that returning to our previous terms was the right thing for now. As I said yesterday, we think that a lot of the language in our terms is overly formal and protective so we don&#8217;t plan to leave it there for long.</p></blockquote>
<p><strong>Update (27Feb09):</strong> Finally, democracy has come to facebook, it&#8217;s allowing users to <a href="http://www.facebook.com/press/releases.php?p=85587">review comment and vote over it&#8217;s future policies</a>. That the way to go, well done facebook!</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2009/02/16/facebooks-new-terms-of-service-anything-you-upload-can-be-used-by-facebook/feed/</wfw:commentRss>
		<slash:comments>-3</slash:comments>
		</item>
		<item>
		<title>I&#8217;ve joined Vanco (Reliance Globalcom &#8211; Anil Dhirubhai Ambani Group)</title>
		<link>http://nirlog.com/2008/11/03/ive-joined-vanco-reliance-globalcom-anil-dhirubhai-ambani-group/</link>
		<comments>http://nirlog.com/2008/11/03/ive-joined-vanco-reliance-globalcom-anil-dhirubhai-ambani-group/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 21:37:32 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://nirlog.com/2008/11/05/ive-joined-vanco-reliance-globalcom-anil-dhirubhai-ambani-group/</guid>
		<description><![CDATA[After a vigorous job hunt of little more than a week, I&#8217;m glad to let you all know that I&#8217;ve joined Vanco (Reliance Globalcom, Anil Dhirubhai Ambani Group) as a Security Engineer, which provides global managed network solutions with assets and expertise of FLAG, Vanco and Yipes: Delivering customer-focused managed network and application delivery solutions [...]]]></description>
			<content:encoded><![CDATA[<p>After a vigorous job hunt of little more than a week, I&#8217;m glad to let you all know that I&#8217;ve joined <a href="http://www.vanco.com/">Vanco</a> (Reliance Globalcom, Anil Dhirubhai Ambani Group) as a Security Engineer, which provides global managed network solutions with assets and expertise of <a href="http://www.flagtelecom.com/">FLAG</a>, <a href="http://www.vanco.com/">Vanco</a> and <a href="http://www.relianceglobalcom.com/index.php">Yipes</a>:</p>
<blockquote>
<p style="text-align:right;"><img src="http://nirlog.com/wp-content/uploads/2008/11/Reliance-GCOM-3D-Horizontal.gif" height="56" width="332" border="1" align="centre" hspace="4" vspace="4" alt="Reliance-Gcom-3D-Horizontal" />Delivering customer-focused managed network and application delivery solutions that leverage a global network with unrivalled reach, depth and breadth to multinational, service provider and global carrier clients. Over 1400 enterprise customers and 200 carriers depend upon Reliance Globalcom to manage business-critical network solutions and address complex requirements for their businesses and partners throughout the world</p></blockquote>
<p>Vanco is now Reliance Globalcom, Anil Dihrubhai Ambani group, which is also well known because of it&#8217;s chairman<a href="http://www.forbes.com/lists/2008/10/billionaires08_Anil-Ambani_VX6G.html"> Anil Ambani</a>, currently 6th on The World&#8217;s Billionaires List.</p>
<p>I feel myself privileged and honored to have this opportunity. At Vanco my role will be exclusively focusing on security, I&#8217;m really excited about it. This is a perfect opportunity for me to bring forward my previous network/security expertise as well as learn and grow at this truly global organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2008/11/03/ive-joined-vanco-reliance-globalcom-anil-dhirubhai-ambani-group/feed/</wfw:commentRss>
		<slash:comments>-4</slash:comments>
		</item>
		<item>
		<title>GFI LANguard Network Security Scanner 8</title>
		<link>http://nirlog.com/2008/01/21/gfi-languard-network-security-scanner-8/</link>
		<comments>http://nirlog.com/2008/01/21/gfi-languard-network-security-scanner-8/#comments</comments>
		<pubDate>Sun, 20 Jan 2008 16:39:22 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://nirlog.com/2008/01/21/gfi-languard-network-security-scanner-8/</guid>
		<description><![CDATA[GFI LANguard Network Security Scanner is a very easy to use yet powerful commercial Network vulnerability scanning, patch management and auditing tool. If you have a small network with few computers then it&#8217;s easy to keep track of the softwares installed and do the patching manually, but for larger networks it would be a nightmare [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gfi.com/lannetscan/">GFI LANguard Network Security Scanner</a> is a very easy to use yet powerful commercial Network vulnerability scanning, patch management and auditing tool. If you have a small network with few computers then it&#8217;s easy to keep track of the softwares installed and do the patching manually, but for larger networks it would be a nightmare to do everything manually. This is where tools like GFI LANguard NSS come in to help network/system admins. GFI LANguard NSS makes use of the vulnerability check databases based on <a href="http://oval.mitre.org/repository/index.html">OVAL</a> and <a href="http://www.sans.org/top20/">SANS Top 20</a>, providing over 15,000 vulnerability assessments when your network is scanned. It is one of the best commercial network security scanner and patch management tool available.</p>
<p>I&#8217;ve installed and tested it in my WinXP SP2 running on my MacBook Pro Vmware Fusion, and this is what I found.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2008/01/gfi-nss.jpg" height="211" width="319" border="1" hspace="4" vspace="4" alt="Gfi-Nss" /></p>
<p><span id="more-277"></span><br />
<strong>Installation and usage</strong><br />
The installation is easy and straightforward. You just need to follow the on screen instruction. You&#8217;ll require: a domain administrator account, a smtp server address to send alerts via email and have to choose either Microsoft Access or MS SQL Server for the back-end database.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2008/01/nss-install.jpg" height="291" width="379" border="1" hspace="4" vspace="4" alt="Nss-Install" /></p>
<p><strong>Scanning, Reporting and Patching</strong><br />
The user interface is intuitive and easy to use. After the scanning is completed, it gives a nice report of the scan (you can choose to scan a single computer, group or the whole network). In the first scan it let me know that my Office and Windows need some critical patches. If you expand each vulnerabilities then it&#8217;ll give the Microsoft ID, download link and the patch release date. You can apply the patch or choose to ignore it by right clicking on it.  There&#8217;s a handy feature to mass deploy the Microsoft updates on selected computers or all computers in the network. Other notable features in patch deployment are:</p>
<p>- Custom Software deployment<br />
- Uninstallation of Microsoft updates<br />
- Detailed Patch Deployment log</p>
<p>Besides the vulnerabilities the scan reports on open tcp/udp ports, open shares, installed applications, password policies, groups and users (with their privilege, last logon and password age).</p>
<p>You can buy an extra ReportPack to create vulnerabilities scanning reports and system information reports for your managers and bosses. I think it would have been great to have this reporting built in to NSS.</p>
<p><a href="http://nirlog.com/wp-content/uploads/2008/01/nss-main-big.png" rel="lightbox"><img src="http://nirlog.com/wp-content/uploads/2008/01/nss-main-small.png" height="140" width="420" border="1" hspace="4" vspace="4" alt="Nss-Main-Small" /></a><br />
<strong><br />
Useful Tools</strong><br />
GFI LANguard NSS comes with very handy tools that a network/security admin uses every day</p>
<p><img src="http://nirlog.com/wp-content/uploads/2008/01/nss-tools.png" height="354" width="252" border="1" hspace="4" vspace="4" alt="Nss-Tools" /></p>
<p><strong>Conclusion</strong><br />
I&#8217;ve tried the GFI LANguard N.S.S 8 for few days and think that it is a very useful tool for network and security administrators. I liked the fact that it has all three useful tools i.e. network vulnerability scanning, patch management and auditing integrated into one. It&#8217;s also easy to use and manage. The lack of built-in ReportPack is the only down side of it. Here, I&#8217;ve just scratched few features of the product, if you&#8217;re interested you can try it for free with <a href="http://www.gfi.com/downloads/downloads.aspx?pid=lanss&amp;lid=EN">30 days evaluation version</a> before buying it.</p>
<p><strong>Update:</strong> GFI have now included the ReportPack for free with GFI LANguard N.S.S. and all other ReportPack-powered software titles on top of the <a href="http://www.gfi.com/news/en/newpricing.htm">45% price cut</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2008/01/21/gfi-languard-network-security-scanner-8/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Load balancing web servers with Pound</title>
		<link>http://nirlog.com/2007/11/28/load-balancing-web-servers-with-pound/</link>
		<comments>http://nirlog.com/2007/11/28/load-balancing-web-servers-with-pound/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 22:26:12 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[HowTo]]></category>
		<category><![CDATA[Linux/Unix]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2007/11/28/load-balancing-web-servers-with-pound/</guid>
		<description><![CDATA[If you&#8217;re running a web site and have come to a point where a single web server cannot handle the traffic, then it&#8217;s time to get multiple web servers and share the loading. To do that you&#8217;ll need a load balancer which distributes the web traffic among multiple web servers. Basically you&#8217;ve two choice &#8212; [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re running a web site and have come to a point where a single web server cannot handle the traffic, then it&#8217;s time to get multiple web servers and share the loading. To do that you&#8217;ll need a load balancer which distributes the web traffic among multiple web servers.</p>
<p>Basically you&#8217;ve two choice &#8212; go for the hardware solutions (expensive with many nice features) or software solutions (possibly free but with limited features). If you want a free and open source solution then Pound is the choice.</p>
<p><a href="http://www.apsis.ch/pound/">Pound is a Free Open Source reverse-proxy, load balancer, SSL wrapper, http/https sanitizer, fail over server and a request redirector</a>:</p>
<blockquote><p>1. a reverse-proxy: it passes requests from client browsers to one or more back-end servers.<br />
2. a load balancer: it will distribute the requests from the client browsers among several back-end servers, while keeping session information.<br />
3. an SSL wrapper: Pound will decrypt HTTPS requests from client browsers and pass them as plain HTTP to the back-end servers.<br />
4. an HTTP/HTTPS sanitizer: Pound will verify requests for correctness and accept only well-formed ones.<br />
5. a fail over-server: should a back-end server fail, Pound will take note of the fact and stop passing requests to it until it recovers.<br />
6. a request redirector: requests may be distributed among servers according to the requested URL.</p></blockquote>
<p>Pound is built with security in mind, it can run as setuid/setgid and/or in a chroot jail. It&#8217;s a very small, robust and efficient program.</p>
<p>It&#8217;s very easy to install and configure.</p>
<p><img src="http://nirlog.com/wp-content/uploads/2007/11/simple-pound.jpg" height="529" width="320" border="1" hspace="4" vspace="4" alt="Simple-Pound" /></p>
<p><span id="more-271"></span><br />
<strong>Installation</strong></p>
<p>pound can be installed from the source or the binary depending on your os distribution.</p>
<p><strong>Configuration</strong></p>
<p>Here&#8217;s an example of simple configuration to share the loading between two web servers behind the Pound load balancer</p>
<blockquote><p>ListenHTTP<br />
Address &lt;real ip address&gt;<br />
Port 80<br />
End<br />
ListenHTTPS<br />
Address &lt;real ip address&gt;<br />
Port 443<br />
Cert &#8220;/etc/pound/ssl-cert.pem&#8221;<br />
End</p>
<p>Service<br />
BackEnd<br />
Address 192.168.1.2<br />
Port    80<br />
End<br />
BackEnd<br />
Address 192.168.1.3<br />
Port    80<br />
End<br />
End </p></blockquote>
<p>Pound can keep track of sessions between a client and a back-end server by client address, Basic authentication, URL parameter, cookie or header value. Here&#8217;s how we keep the session by cookies</p>
<blockquote><p>Session<br />
Type    Cookie<br />
ID      &#8220;sess&#8221;<br />
TTL     300<br />
End</p></blockquote>
<p>Pound is straight forward to configure and understand. It&#8217;s a perfect choice for free and open source load balancer.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2007/11/28/load-balancing-web-servers-with-pound/feed/</wfw:commentRss>
		<slash:comments>-2</slash:comments>
		</item>
		<item>
		<title>Online Password Managers</title>
		<link>http://nirlog.com/2007/07/16/online-password-managers/</link>
		<comments>http://nirlog.com/2007/07/16/online-password-managers/#comments</comments>
		<pubDate>Mon, 16 Jul 2007 10:40:46 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2007/07/16/online-password-managers/</guid>
		<description><![CDATA[After switching to a mac, I tried many desktop password managers, and had written about Password Managers for OS X, which got a lot of attention. It&#8217;s needless to mention the importance of using a password manager since we use passwords to protect almost everything digital, and we&#8217;ve so many of them today. Currently we [...]]]></description>
			<content:encoded><![CDATA[<p>After switching to a mac, I tried many desktop password managers, and had written about <a href="http://nirlog.com/2006/07/19/password-managers-for-os-x/">Password Managers for OS X</a>,  which got a lot of attention. It&#8217;s needless to mention the importance of using a password manager since we use passwords to protect almost everything digital, and we&#8217;ve so many of them today. Currently we trust most of our private data like, emails, bookmarks, documents, spreadsheets and calendar events to some online providers like Google, Yahoo or Microsoft. So, how about your secrets and passwords stored online, somewhere in the cloud? I know what your immediate response is, passwords? No way I&#8217;m going to store my passwords online! But you might want to give a second thought because now the technology is secure enough. Thanks to <a href="http://ajaxpatterns.org/Host-Proof_Hosting">Host-Proof Hosting</a>. If the owners of the servers wanted to mess around with your information, or even if the server gets hacked, they won&#8217;t be able to recover your data. In Host-Proof Hosting the sensitive data is always transmitted to the server in encrypted from using a pass-phrase. The good thing is that, this pass-phrase is never transmitted to or stored in the server. The server can never access the stored data in it&#8217;s plain form. All the encryption and decryption takes place in the client side, inside the browser. This is basically a &#8220;Zero-Knowledge&#8221; web application, where the provider knows nothing about your actual data.</p>
<blockquote><p>* User enters pass-phrase to begin using the system. Browser retains the pass-phrase as a global variable.<br />
* User requests a list of all data belonging to him.<br />
* For each record, the system stores the associated user ID in plain-text, the record ID in plain form, and the record content only in encrypted form. (The message content is one or more database columns, each encrypted.) Thus, system is able to return a list of record IDs for this user.<br />
* User selects one of the record IDs.<br />
* System checks that this user ID is associated with the record ID, and returns the corresponding message content.<br />
* Browser uses stored pass-phrase to decrypt the contents.</p></blockquote>
<p>Ok, with that background if you&#8217;re ready to store your sensitive information online, here are few choices for you.</p>
<p><span id="more-262"></span><br />
<strong><a href="http://aaronboodman.com/halfnote/">Halfnote</a></strong><br />
Halfnote is a very simple and secure notepad. Easy to register &#8212; provide your email address, choose a password, and you&#8217;re done. A simple blank notepad is presented, where you can write your secret passwords or documents. It&#8217;s very fast and the information is auto-saved as you type. The information you send is encrypted with your pass-phrase but it lacks SSL protection, which could have provided extra security by encrypting the session information.<br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/halfnote.png" height="150" width="385" border="1" hspace="4" vspace="4" alt="Halfnote" /></p>
<p><strong><a href="https://www.passlet.com/">Passlet</a></strong><br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/passlet-logo.png" height="65" width="177" border="1" align="left" hspace="4" vspace="4" alt="Passlet-Logo" />Passlet is a typical online password manager, currently in beta. It has an easy to input entry from where you can input: Title, Username, Password, and Notes. It encrypts the data by deriving 128-bit AES key from your master password. The key derivation is completely performed within the browser. In addition to secure data, Passlet uses SSL for session encryption, we can be sure of connecting to Passlet server by viewing the SSL Certificate.<br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/passlet.png" height="169" width="420" border="1" hspace="4" vspace="4" alt="Passlet" /></p>
<p><strong><a href="http://esecurekey.com">eSecureKey</a></strong><br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/esecurekey-logo.gif" height="49" width="300" border="1" align="right" hspace="4" vspace="4" alt="Esecurekey-Logo" />eSecureKey is another online password manager, currently in beta. It has a Portlet, which can be accessed with a Secure Key. This Secure Key is different from your login password, and is never transmitted to the server. This is the key used to encode and decode data. The portlet lists the existing entries and allows to add new information with tags for easy listing and searching. eSecureKey sends encrypted data to the server but lacks SSL for the session encryption.<br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/esecurekey.png" height="176" width="420" border="1" hspace="4" vspace="4" alt="Esecurekey" /></p>
<p><strong><a href="http://www.passpack.com">PassPack</a></strong><br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/passpack-logo.png" height="59" width="200" border="1" align="left" hspace="4" vspace="4" alt="Passpack-Logo" />PassPack is currently in beta.  It uses Packing Key to pack/unpack (encrypt/decrypt) data, which is all done in client side, inside the browser, no keys are sent to the server. It uses AES encryption and special security techniques, like disposable logins, which can be created in advance. Disposable logins are good for one time login only. This is useful when you access your data using a public computer. PassPack has taken the fight against phishing to a new level by allowing users to setup their custom Greeting Message after login, and ip address restriction, where users can choose to allow only certain ip address to have login access. PassPack uses SSL to encrypt session data as well. Other useful features in PassPack are import/export from/to a csv file. You can make an encrypted backup of your secret data using the packing key, and the restoration from the backup file is very easy too.<br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/passpack-1.png" height="187" width="420" border="1" hspace="4" vspace="4" alt="Passpack-1" /></p>
<p><strong><a href="http://www.clipperz.com/">Clipperz</a></strong><br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/clipperz-logo-1.png" height="54" width="180" border="1" align="right" hspace="4" vspace="4" alt="Clipperz-Logo-1" />Clipperz uses local encryption within the browser so, your data is safe like all other online password managers. But Clipperz has some useful features that other online password managers lack.  For example, it has a cool feature called direct login, which allows to quickly create a &#8220;direct login&#8221; link: just one click to authenticate and access the online service without typing any username and password. Another good feature is offline copy, which allows users to dump their encrypted data from Clipperz servers to a local hard disk or USB drive and create a read-only version of Clipperz to be used when there&#8217;s no internet connection available. Clipperz is currently available in English, Japanese and Chinese. It stores the passwords and other confidential data in predefined templates called cards. Clipperz has several predefined templates for storing websites, banking, credit card, address book and custom card. There&#8217;re some new features coming soon, among them Import and Sharing should be very useful.<br />
<img src="http://nirlog.com/wp-content/uploads/2007/07/clipperz.png" height="187" width="420" border="1" hspace="4" vspace="4" alt="Clipperz" /></p>
<p><strong>Conclusion</strong><br />
I think online password managers are handy and secure enough to store the username/passwords of many websites that we visit on daily basis like, digg, delicious, flicker, etc &#8230;. but for myself, I wouldn&#8217;t store critical secrets and financial data online yet!  If you&#8217;re a system admin you might want to check <a href="http://keepass.info/">KeePass</a> that works across all platforms. Having said that, if you&#8217;re ready to take a plunge into online password managers then technology is ready and there&#8217;re excellent choices available. So, if you love simplicity, Halfnote is for you, if you want cool features like direct login or multiple language support, then go for Clipprez, if you want extra security like disposable logins and phishing protection go for PassPack.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2007/07/16/online-password-managers/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>4 simple measures to keep your system and network secure</title>
		<link>http://nirlog.com/2007/07/01/4-simple-measures-to-keep-your-system-and-network-secure/</link>
		<comments>http://nirlog.com/2007/07/01/4-simple-measures-to-keep-your-system-and-network-secure/#comments</comments>
		<pubDate>Sun, 01 Jul 2007 09:44:13 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2007/07/01/4-simple-measures-to-keep-your-system-and-network-secure/</guid>
		<description><![CDATA[There are many things you can and should do to keep your system and network secure. As the saying goes &#8212; &#8220;Security is not a single event or a product, it&#8217;s a process&#8221;. So, you&#8217;ve to keep up with all the changes, installing firewalls, IDS/IPS, network security monitoring, auditing, making security policies, password policies, email [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://nirlog.com/wp-content/uploads/2007/07/keepass.png" height="128" width="128" border="1" align="right" hspace="4" vspace="4" alt="Keepass" />There are many things you can and should do to keep your system and network secure. As the saying goes &#8212; &#8220;Security is not a single event or a product, it&#8217;s a process&#8221;. So, you&#8217;ve to keep up with all the changes, installing firewalls, IDS/IPS, network security monitoring, auditing, making security policies, password policies, email policies and so on&#8230; Yes, all of them are very important and you&#8217;ll be dealing with most them depending on your security requirements. But there&#8217;re some basic things every network and system admin should follow. Personally, I&#8217;ve found 4 things that are very simple yet effective in securing your systems.</p>
<p><span id="more-259"></span><br />
<strong>1. Passwords</strong></p>
<p>Cryptographic methods, biometrics, and two-factor authentication are becoming popular these days, but in reality we still have to deal with passwords most of the time. So, proper management of password is absolutely critical to the security. It doesn&#8217;t have to be complicated. Here are few simple things I recommend to do with the passwords:</p>
<p><strong>Use password manager</strong><br />
Manually keeping up with 100s of login ids and passwords is very difficult, impractical and sometimes impossible. So, use some kind of password management tool. With a proper password manager you don&#8217;t have to worry about generating secure passwords, you&#8217;ll stop writing passwords in paper, and you don&#8217;t have to remember any of them. The password manager will help you with all of these tasks. I use <a href="http://keepass.info/">KeePass</a> to manage the passwords. It&#8217;s an excellent multi-platform password manager available for Windows, Linux, Mac OS X and Windows Mobile.</p>
<p><strong>Change passwords regularly</strong><br />
Never use same password for two servers or devices, and change them regularly, at least once every 3 months. By using an unique passwords per system you&#8217;ll reduce the damage in case a single password is compromised, and by changing the passwords regularly you&#8217;ll make the guessing and attacking for the bad guys much harder.</p>
<p><strong>Never send naked passwords<br />
</strong>What I mean is, never send a clear-text password over the network. The packets can be easily captured with many freely available tools and packet sniffers. Always use some form of protection when you need to transmit the passwords, e.g. SSL, SSH or VPN connection. You should never use HTTP or Telnet to manage anything over the network. Replace them with HTTPS (SSL) and SSH.</p>
<p><strong>2. Security Updates</p>
<p></strong>Keeping your systems up-to-date is very important, there&#8217;re new security patches released by most of the vendors all the time. Sometimes the security updates negatively affect production environment, so it&#8217;s recommended to first test the fixes and then only apply to production environment. Anyway, patching the known security holes is critical to stay secure. The longer you take to patch a known security hole the more you&#8217;re exposed to attacks.</p>
<p><strong>3. Changes</p>
<p></strong>There&#8217;s a nice saying about the change &#8212; &#8220;Change is the only constant&#8221;. I think that&#8217;s true for life, and for systems, and networks. We make changes all the time, change firewall rules, add users, delete users, install security patches and so on. The system and network environment keeps changing. It is very important to keep a backup of the last known working configuration of everything, and maintain a change document. So, if suddenly after changing a firewall rule everyone in the network complains about not being able to access a server in DMZ, we should be able to fall back to the previous rule-set easily. If you&#8217;ve made some manual changes to a config file to improve the performance of a linux server, you should note it down because after few months you won&#8217;t remember the exact changes you&#8217;ve made. Knowing what changes you&#8217;ve made and being able to fall back keeps you and your environment productive and secure.</p>
<p><strong>4. Stop unnecessary services<br />
</strong>Most of the Operating Systems and security devices come with a lot of services installed and running by default. The more services that are running, the more your system is exposed to attack. So, you need to identify all the services running in the system and stop the unnecessary ones. If it&#8217;s a firewall, explicitly deny everything first, and start allowing the necessary connection and services. If it&#8217;s an operating system, find and stop all the unnecessary services.</p>
<p>By following these 4 simple measures you&#8217;ll be able to keep your system and network secure and stable. I&#8217;m not saying that just these measures would be enough in all environments, but they&#8217;re the basic foundation. I think not only admins but normal users should be following these 4 measures to keep themselves secure in todays wild internet.</p>
<p>Any other simple measures that you take to keep your system and network secure? Comments and emails are welcome.</p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2007/07/01/4-simple-measures-to-keep-your-system-and-network-secure/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Snort: Intrusion Detection/Prevention Management</title>
		<link>http://nirlog.com/2007/06/21/snort-intrusion-detectionprevention-management/</link>
		<comments>http://nirlog.com/2007/06/21/snort-intrusion-detectionprevention-management/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 07:57:58 +0000</pubDate>
		<dc:creator>Niranjan Kunwar</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Linux/Unix]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://nirlog.com/2007/06/21/snort-intrusion-detectionprevention-management/</guid>
		<description><![CDATA[Snort has always been, and still is my favorite IDS (Intrusion Detection System) although I manage many UTM (Unified Threat Management) Firewalls with built in IPS/IDS (Intrusion Detection/Prevention) now. The commercial UTM Firewalls with IPS/IDS are easy to use and configure but they come with a high price tag and aren&#8217;t easy to customize. Even [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://nirlog.com/wp-content/uploads/2007/06/snort-1.gif" height="60" width="128" border="1" align="right" hspace="4" vspace="4" alt="Snort-1" /><a href="http://www.snort.org/">Snort</a> has always been, and still is my favorite IDS (Intrusion Detection System) although I manage many <a href="http://en.wikipedia.org/wiki/Unified_threat_management">UTM</a> (Unified Threat Management) Firewalls with built in IPS/IDS (Intrusion Detection/Prevention) now. The commercial UTM Firewalls with IPS/IDS are easy to use and configure but they come with a high price tag and aren&#8217;t easy to customize. Even though snort is not that easy to install, configure and manage it still is the most popular IDS/IPS today because of the fact that it is open source, free, easily customizable, easy to create rules, signatures are always kept up-to-date by its community and plenty of excellent documentation, guides and books.</p>
<p>Snort captures enormous amount of data from the network and generates alert based on the rules and signatures. There&#8217;re currently 3 excellent and relatively user friendly ways to manage and analyze the snort data:<br />
<span id="more-258"></span><br />
1. <a href="http://acidlab.sourceforge.net/">ACID</a> (Analysis Console for Intrusion Databases)</p>
<blockquote><p>The Analysis Console for Intrusion Databases (ACID) is a PHP-based analysis engine to search and process a database of security events generated by various IDSes, firewalls, and network monitoring tools.</p></blockquote>
<p><a href="http://www.andrew.cmu.edu/user/rdanyliw/snort/acid_config.html">ACID: Installation and Configuration</a></p>
<p>2. <a href="http://base.secureideas.net/">BASE</a> (Basic Analysis and Security Engine).</p>
<blockquote><p>It is based on the code from the Analysis Console for Intrusion Databases (ACID) project. This application provides a web front-end to query and analyze the alerts coming from a SNORT IDS system.</p></blockquote>
<p><a href="http://www.snort.org/docs/setup_guides/Snort_Base_Minimal.pdf">Snort, Apache, SSL, PHP, MySQL, and BASE Install on CentOS 4, RHEL 4 or Fedora Core</a> (pdf)</p>
<p>3. <a href="http://sguil.sourceforge.net/">Sguil</a> (Snort GUI for LamerZ)</p>
<blockquote><p>Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil&#8217;s main component is an intuitive GUI that provides access to realtime events, session data, and raw packet captures.</p></blockquote>
<p><a href="http://www.vorant.com/nsmwiki/index.php?title=Sguil_on_RedHat_HOWTO" title="Sguil_on_RedHat_HOWTO">Sguil on RedHat HOWTO</a></p>
<p>If you&#8217;re asking what&#8217;s the difference between them, then <a href="http://www.mcabee.org/lists/snort-users/Nov-04/msg00367.html">here&#8217;s five reasons why Sguil is different from ACID, BASE, and similar products</a>.</p>
<p>Currently I&#8217;m trying Sguil to see how good it is. I&#8217;ve <a href="http://www.vorant.com/nsmwiki/index.php?title=Sguil_on_RedHat_HOWTO" title="Sguil_on_RedHat_HOWTO">installed Sguil Server and Sensor in CentOS 4.x </a>and <a href="http://sguil-client.darwinports.com/" title="Sguil_on_RedHat_HOWTO">Sguil-Client in my Mac OS X</a>. The server installation was not that easy but once installed, it runs smoothly. I must say that there are many good features in Sguil, among them I like: alerts in near real-time, escalation and accountability features, collection of session data using SANCP and summaries of conversations.</p>
<p><a href="http://nirlog.com/wp-content/uploads/2007/06/sguil-big.png" title="Sguil_on_RedHat_HOWTO" rel="lightbox"><img src="http://nirlog.com/wp-content/uploads/2007/06/sguil-small.png" height="303" width="420" border="1" hspace="4" vspace="4" alt="Sguil-Small" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://nirlog.com/2007/06/21/snort-intrusion-detectionprevention-management/feed/</wfw:commentRss>
		<slash:comments>-25</slash:comments>
		</item>
	</channel>
</rss>

