Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, July 05, 2014

TIPS & TRICKS: Trusting A Computer from iOS 7

Apple introduced concept of Trusted Computers in iOS 7. The idea is that if a iOS device (i.e. iPhone) is plugged into a computer for charging purposes only, the data on the iOS device can be kept safe from the computer while still allowing charging of the device.

I found a situation where I allowed the device to trust a computer and then needed to remove that trust relationship. Apple doesn't have an easy way to remove that trust relationship on the phone because it seems that the trust token is stored only on the computer that the device is connected. However, there is a way to remove that relationship, as outlined by Apple: http://support.apple.com/kb/TS5335. I've only tried these steps on Windows 7:


  • Choose Start, type %ProgramData% in the search bar, and press Return.
  • Double-click the Apple folder.
  • Double-click the Lockdown folder 
  • Find the appropriate token (I based it on date, if there are multiple tokens) and choose Delete. Admin credentials may need to be provided if the currently logged in user is a non-admin. 




Thursday, July 18, 2013

TIPS & TRICKS: Windows Logon Types



As a sysadmin, I spend some time looking at logs. To someone who doesn't look at logs, the amount and type of information provided by logs can look like a foreign language. It helps me to have more information, a running legend in my head so to speak, about logs I sift through.

Windows keeps track of who logs into the computer, but I found out that it also keeps track of how a user logs on (or off). There are, at least, 9 different methods to logging into a computer:

  • Logon Type 2 - Interactive
  • Logon Type 3 - Network
  • Logon Type 4 - Batch (or scheduled tasks)
  • Logon Type 5 - Service
  • Logon Type 7 - Unlock 
  • Logon Type 8 - NetworkCleartext
  • Logon Type 9 - NewCredentials (or RunAs...)
  • Logon Type 10 - RemoteInteractive (RDP, TS)
  • Logon Type 11 - CachedInteractive
Given the date of the article (first link below) where this information originated for me, I'm betting that there are more types now for more granular logging.

Looking at logs help to troubleshoot problems, but it also helps to keep an eye out for malicious activity. Hopefully, understanding the different Windows Logon Types will help me keep the environments I manage that much more secure too. 

For additional information on the above Logon Types, see this site: 


Here's a more recent article on the different logon types:

http://www.eventtracker.com/newsletters/following-a-users-logon-tracks-throughout-the-windows-domain/

Though I think the title of the article is misleading, there's some useful information on different logon/logoff events. 

Wednesday, March 20, 2013

TIPS & TRICKS: Browser and Other Security Tests

With all the recent 0-day exploits and other vulnerabilities making news, I thought it would be helpful to have some resources to test out your environment.

First, browser security checks:
Next, router and computer security checks:

As always, security is like an onion. A well secured computing environment will have lots of layers. These tools are another layer of protection.

Tuesday, September 11, 2012

RANTS & RAVES: Fingerprint Reader Software by UPEK

I have my reservations about fingerprint readers. This article about how the UPEK software stores a users passwords in a very insecure way, serves to make me more wary about anything that stores passwords.

http://blog.crackpassword.com/2012/08/upek-fingerprint-readers-a-huge-security-hole/

Fortunately, the silver lining I'm pulling out of this story rests with the great advantage of using disk encryption such as BitLocker. If the disk is encrypted, then the not so securely stored password for the fingerprint reader turns out the encrypted just by virtue of being stored on the same disk. If you've got multiple drives or volumes, then make sure that the separate drives are encrypted too.

Lesson learned before I get into any trouble.

Thursday, July 28, 2011

NEWS: Sniffer hijacks secure traffic from unpatched iPhones

Unpatched iPhones can be exploited even with availability of SSL. One of the methods, published 9 years ago, is so easy that "my mother could actually use this", says Chet Wisniewski, a security researcher with Sophos.

Moral of the story, unless you have iOS 5 with over-the-air-updates, make sure to plug in your iPhone and get it updated.

Friday, July 16, 2010

RANTS / TIPS: Vulnerable Home Routers

Home routers have been vulnerable in the past and will likely be vulnerable in the future, especially when most people don't know how to secure them right out of the box. This article:

http://www.notebooks.com/2010/07/15/how-to-secure-your-router-against-a-hack-compromising-many-popular-routers/

talks about how a vulnerability in many home routers makes them susceptible to a potential attack. The interesting thing about this particular method is that it can affect so many different routers, rather than target a particular make or model.

The gist:
1. Make sure your router has a very strong password. Remember this password is the one used to access the controls of the router and not necessarily your wifi password.
2. Make sure firmware on the router is the latest from the manufacturer.

Happy Computing.

Wednesday, May 05, 2010

RANT: Got hacked.

Not me, thankfully. But, I did feel the effects of someone else getting hacked. Does the name Fred Cabasa ring a bell for anyone? I have no recollection about how I know this person. I even have this person in my contacts, but it was before I started noting down how I met people. Thus, this person had his information (i.e. email account(s), phone, computer, etc.) compromised in some way and I received some of the consequences.

How do I know that this person was compromised? I've got a fairly good idea of how spammers work and an email that seems like it's coming from someone I know is no real indicator. In this case, however, I received additional information leading me to believe that this person should really be careful about his personal information from here on out. Here's the message:



First, the email message only contained a link and no other text in the body of the message. The sender was Fred Cabasa using an email address I had on file for him, separately. The message also looked like it was sent to a small number of people at the beginning of the alphabet. Finally, the real tell-tale-sign about this message was that it included another email address of mine that I no longer use.

There's one other way that indicated Fred got hacked. I received a junk text message on my cell phone. This was no ordinary text message. This text message contained the same link as in the email I described earlier.

There are a million ways people could have obtained this information: from hacking his computer, to something as simple as finding his old cell phone or other device that contains this information Fred might have disposed of without properly wiping the data.

Moral of the story? Don't give your personal contact information out to anyone, ever. Wait, check that comment. Some times my paranoia gets the best of me. Seriously though, I think the moral of the story here is to make sure you protect your data and your devices. It's too easy to obtain information these days. If we all do our part (even if we don't care about our own information), we'll also protect those people who could be affected by information theft.

Hope this helps you. Happy Computing.