...my lovely email security provider has chosen to work part-time apparently. If you need to reach me, email my full name (1 word) at gmail dot com.
Tuesday, 13 October 2009
Latest version of LANguard worth considering
Posted on 07:45 by Unknown
Have you seen the new - OK, it's not that new any more - version of LANguard (formerly LANguard Network Security Scanner)? It's certainly a tool worth checking out if you do vulnerability scanning.
I've been using LANguard for years for share finding and authenticated scanning and it does both very well. The biggest change in the latest version is the user interface. I've never been a big fan and I'm still not, but I'm getting used to it. Many of the improvements in the latest version involve authenticated scans. The quick-view dashboard is a nice improvement and I really like the scan progress.
When performing untrusted/unauthenticated scans I've found that LANguard won't find nearly the number of vulnerabilities than QualysGuard especially with regards to missing patch vulns that are exploitable via Metasploit. Hopefully that'll continue to evolve. But it does a very good job with this during authenticated scans (as would be expected if you have login credentials).
I'm still waiting for the ability to test your authentication credentials like what Sunbelt Network Security Inspector offers - at least used to, haven't used it lately. You have to plug in your credentials and hope that your login works. It'd also be nice to be able to sort through the network share finder results and filter based on permissions found (i.e. shares where Everyone has full access).
Here's a screenshot of the main interface:

In the interest of getting you hooked on good tools, here's a link to GFI's free version of LANguard. Hope this helps!
I've been using LANguard for years for share finding and authenticated scanning and it does both very well. The biggest change in the latest version is the user interface. I've never been a big fan and I'm still not, but I'm getting used to it. Many of the improvements in the latest version involve authenticated scans. The quick-view dashboard is a nice improvement and I really like the scan progress.
When performing untrusted/unauthenticated scans I've found that LANguard won't find nearly the number of vulnerabilities than QualysGuard especially with regards to missing patch vulns that are exploitable via Metasploit. Hopefully that'll continue to evolve. But it does a very good job with this during authenticated scans (as would be expected if you have login credentials).
I'm still waiting for the ability to test your authentication credentials like what Sunbelt Network Security Inspector offers - at least used to, haven't used it lately. You have to plug in your credentials and hope that your login works. It'd also be nice to be able to sort through the network share finder results and filter based on permissions found (i.e. shares where Everyone has full access).
Here's a screenshot of the main interface:

In the interest of getting you hooked on good tools, here's a link to GFI's free version of LANguard. Hope this helps!
Proper password length
Posted on 07:09 by Unknown
Probably late to the game but just had to post this:
During a recent password audit, it was found that a blonde was using the following password:
MickeyMinniePlutoHueyLouieDeweyDonaldGoofy
When asked why such a big password, she said that it had to be at least 8 characters long.
During a recent password audit, it was found that a blonde was using the following password:
MickeyMinniePlutoHueyLouieDeweyDonaldGoofy
When asked why such a big password, she said that it had to be at least 8 characters long.
Monday, 12 October 2009
Cool tool for cracking/resetting SQL Server passwords
Posted on 10:47 by Unknown
Elcomsoft has a neat - and relatively new - tool called Advanced SQL Password Recovery I thought you may be able to benefit from. It can be used to change any SQL Server databases protected by a password included SQL Server 2000, 2005 and 2008. All you need is access to the master.mdf file. SQL Server optional.
I was going to show a screenshot but there's not that much to show...you load the program, you point it to the master.mdf file and it'll crack the passwords - simple as that. Very cool.
Yet another reason to keep your Windows systems patched and your share/file permissions in check.
I was going to show a screenshot but there's not that much to show...you load the program, you point it to the master.mdf file and it'll crack the passwords - simple as that. Very cool.
Yet another reason to keep your Windows systems patched and your share/file permissions in check.
Posted in cool products, database security, passwords, security testing tools, sql server
|
No comments
Friday, 9 October 2009
My latest security content
Posted on 04:41 by Unknown
Here are a couple of new articles of mind that were just published. Many more to come. Enjoy!
Balancing Windows security with reasonable password policies
Storage encryption essentials
Be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts, Twitter updates, and more.
Balancing Windows security with reasonable password policies
Storage encryption essentials
Be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts, Twitter updates, and more.
Thursday, 8 October 2009
Asking the right questions
Posted on 09:16 by Unknown
One of the elements of being successful in security is asking the right questions - and not being afraid to do so. As information security professionals we can, and should, question the funding of security projects, management being on board with the business risks at hand, and so on.
I recently came across two great quotes regarding questioning. First, Anthony Robbins said "Quality questions create a quality life. Successful people ask better questions, and as a result, they get better answers." Second, Albert Einstein said "The important thing is to not stop questioning."
We don't have to be pests and we certainly need to be careful and not do more harm than good when getting people on our side. But if you approach your security initiatives with enough finesse and confidence and show how you're concerned about the business your questioning might be just what the doctor ordered.
I recently came across two great quotes regarding questioning. First, Anthony Robbins said "Quality questions create a quality life. Successful people ask better questions, and as a result, they get better answers." Second, Albert Einstein said "The important thing is to not stop questioning."
We don't have to be pests and we certainly need to be careful and not do more harm than good when getting people on our side. But if you approach your security initiatives with enough finesse and confidence and show how you're concerned about the business your questioning might be just what the doctor ordered.
Tuesday, 6 October 2009
Don't give up
Posted on 09:31 by Unknown
Napoleon Hill once said "The majority of men meet with failure because (they don't create) new plans to take the place of those that fail."
I see this a lot: people with big plans who are met with a setback, they get discouraged, and give up. If you feel strongly about doing something - writing a book, changing careers, getting a degree, whatever - don't be this person.
I see this a lot: people with big plans who are met with a setback, they get discouraged, and give up. If you feel strongly about doing something - writing a book, changing careers, getting a degree, whatever - don't be this person.
Subscribe to:
Posts (Atom)