• What I am doing...

  • IM Status

  • Tag Catalog

  • Categories

  • Archives

Patch Management Best Practices Resources »

Tony Soper has a pretty good list of Patch Management Best Practices resources. In light of the recent Zotob explosion, it makes sense to bone up on some of the different patch management techniques.
Fortunately, we weren’t hit at all at my office. I would like to say it is because I always keep [...]

Updated Windows 2003 IPSEC Documentation »

Microsoft has updated its Internet Protocol Security for Microsoft Windows Server 2003 documentation. I haven’t checked out what has changed as of yet, so YMMV…

Tags: IPSEC

Remote Desktop Security Vulnerability - DOS Attack »

Microsoft released a security bulletin this past weekend concerning a vulnerability in the Remote Desktop Protocol that may lead to a Denial of Service (DoS) attack.. Note that this vulnerability will not allow remote access to your computer.
At the present time, there is no hotfix or patch to correct this vulnerability.
From the bulletin:

In which [...]

Trustworthy Administrators »

Over at Technet, Steve Riley has a good discussion on security and “trustworthy administrators.” As a network administrator for a mid-sized business, I can agree with many of his points.
I will add more to this later today… (Time to get back to work)
Tags: Security, TrustworthyComputing

Kerberos Security Flaw »

If you are running a UNIX variant out there - note that there are two fairly serious security flaw in the Kerberos authentication scheme…
Note that this doesn’t affect the Microsoft Kerberos variant…
See here for more information and here for the advisories…

Tags: Kerberos

IAS FAQ posted… »

From the public groups:
Check out this new Web page that provides fast answers to common questions
about the Internet Authentication Service (IAS), the Windows implementation
of a Remote Authentication Dial-In User Service (RADIUS) server and proxy.
IAS provides authentication, authorization, and accounting (AAA) for
different types of network connections such as remote access (dial-up and
virtual private network) and 802.11 [...]

Good Advice for Sven Jaschan »

Stephen Toulouse has some pretty good advice in his open letter for Sven Jaschan (creator of the Sasser virus)
(Off-Topic: This blog is the first one I have ever seen being run on Sharepoint…. That is weird…)

Tags: Sasser, Jaschan

Info on WEP Cracking »

John in Oregon has posted a few links to some articles on Tom’s Networks that describe how easy it is to crack the WEP encryption many people use on their SOHO routers…

Tags: WEP

Small Business Server 2003 SP1 Released »

Per many sources on the net - SP1 for Small Business Server 2003 has been released.
Susan Bradleyhas some practical and important advice before you install it…

Tags: SBS2003, SBS2K3

New Tool: SSL-Explorer »

OK, while I was browsing Sourceforge this evening, I came across a new release for a tool that I haven’t seen before - SSL-Explorer. Per the project website:
SSL-Explorer is a fully-featured, web-based SSL VPN server. This practicable remote access security solution includes SSL tunneling, intranet website proxying, Microsoft Windows file sharing and Java application [...]