chalkboard_original with illustrations

IT-Talks, Pro-Exchange & Winsec are teaming up to bring you the first every Belgian IT-Pro Chalk Talk session, on Thursday 4 March 2010, the the Microsoft België offices.

During this event we will be bringing a panel of MVP’s and other leading industry experts together to answer any and all of your technical questions in a live and interative environment.

The purpose of this session is to show you how the panel thinks and analyses problems from there expertise and where possible formulate answers or research options to help you solve your real world issues.

The technologies that we will be covering during this event are:

· Exchange Server

· Office Communications Server

· Active Directory

· Security

· General networking TCP/IP

· Group policies

We offer you the option to send your questions / problems upfront by email or bring them in and ask them live.

· info@pro-exchange.be

· info@it-talks.be

· chalktalk@winsec.be

Pre-registration for this event is required at http://itprochalktalk.eventbrite.com/.

If you can’t physically make it to this event you will have the opportunity to join in through a live meeting. The details will be emailed to all registered users.

 

IT-Talks, Pro-Exchange & Winsec

 

Registratie via http://itprochalktalk.eventbrite.com/

Location

Kantoren Microsoft België

Corporate Village

Leonardo Da Vincilaan 3

1935 Zaventem (Route beschrijving)

Time

Thursday 4 March 2010 19h00 till +/- 21h00

Anyone that has been following the security landscape the past few days knows a zero day IE attack was used during the Gmail attack that took place the 12th of January and lead to the Google statement that they would consider pulling out of China.

Since then the Zero Day IE exploit that uses an invalid pointer in IE has been looked at in all detail by the good, the bad and the ugly. There is exploit code out in the wild for every to enjoy and as a result MS as released an out of band security update that you should install NOW!

Head out to your local MS update site and update your PC’s asap. It’s important to know that even though the initial issue was thought to be limited to IE6, this is not the case and you need to patch IE7 and 8 too.

 

http://www.update.microsoft.com

 

more info:

http://blogs.technet.com/sus/archive/2010/01/21/microsoft-security-bulletin-ms10-002-978207-released-today.aspx

http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx

Forefront Threat Management Gateway - Technisch overzicht

 

clip_image002

Deze sessie geeft een overzicht op de Forefront TMG - en de Forefront UAG features. Gesteund door de geïntegreerde Stirling beveiligingssuite en TMG’s geavanceerde beveiligingsfeatures krijgen organisaties geïntegreerde beveiliging die werkt in de praktijk. In deze sessie presenteren we de voordelen van deze geïntegreerde aanpak en gaan we dieper in op de belangrijkste features en de ‘high level’ architectuur. Daarnaast wordt ook ingegaan op de mogelijkheden binnen UAG zoals directe toegang, het publiceren van applicaties en veelvoudige authenticatie methoden.

 

clip_image00418 Februari – 14:00 Inschrijven

Well it’s been a while since i was on my blog but as you can see I had a good reason.

IMAG0019

Our first born is a great sun weighing in at 2850gr and measuring 48cm, he’s adorable and really worth all the painting and decorating i have been doing in his room for the past weeks and months.

We have called him Ernest and I hope he grows out to love computers as much as I do ;-)

The more you read and work with windows 7 (and windows vista for those still out there) the more you start to find the little things that make it great.

One of the features I have re-discovered is the advanced search and filter in explorer.

I’m a real command line geek and one of the things file explorer could never do for me is give me a great way to search and filter through files untill i know found the search documents field.

image

In every file explorer you have the Search Documents that gives you a very rich search syntax.

< Field>:<Value>

 

Lets try some examples: name:Pictures

image

Lets try some examples: size:<field>

image

When typing in a field you can set your own value or choose one of the auto completion values.

After completing a search string you can also see the interface gives you option to select additional fields.

image

a somewhat more complex string could look like:

size:<200 and type:.csv or type:.jpg and not name:H

image

If you have been using windows 7, this might be a feature you have not found yet but it’s well worth knowing:

To reduce distraction and clutter on the desktop you can minimize all other windows except the one you are actively using by shaking the window on our desktop. Let go and shake again and you restore all windows back to the original project.

Try it and see for yourself!

If you have not done so this month, it’s high time to put some priority down and to start patching for the SMBv2 vulnerability!

http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx

Again, i can only stress it has taken a full month before MS released the fix so make sure to read my post on how TMG protects you from 0-day vulnerabilities.

http://trycatch.be/blogs/decaluwet/archive/2009/09/29/how-tmg-protects-you-from-smbv2-0-day-vulnerability.aspx

Event Name: "Working with Forefront Threat Management Gateway 2010 "

Topic: During this event we will focus on TMG the follow up of ISA server and all its old and new features.

Speaker: Tom Decaluwé

Event dates:Event Dates:

Event

info

It-Short talk

Date and time: Monday 26 Oktober 2009 start at 19u00 – 21u30

Location: Contributiestraat 9, 9000 Gent

Entry: Free

Focus: During this event we will focus on the theory of the new features inside the TMG project and how and why to use them in your production networks.

Full day talk

Date and time: Saturday 21 November start at 10u00 – 17u30

Location: Spes Nostra - Koning Albertstraat 50 - 8520 Kuurne

Entry: 15€ for drinks and lunch

Focus: During this event we will focus on hands on practice lab around  implementing TMG in your network.

you can register for these event by sending an email to tom@decaluwe.eu, include what events you will attend, seats are limited so register ASAP!

If you have not done so yet, it’s high time to get the latest TMG RC

http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx

Windows 7 and windows 2008 R2 have some great new tools and one of the least know tools must be Problem Steps Recorder.

The tool itself was designed as an easy way for some one to record their steps and send off for trouble shooting. However I have found that this tool is also a great utility for creating very detailed documentation.

Give it a go and you’ll see it works better than any other screen grabbing utility!

Allow me to illustrate.

You can start the tool by typing PSR in the start > run window

image

image

Before you start you might want to bump up the amount of screen captures to include in the document depending on how many steps your install has

image

the value can be between 1 and 100 so if you have more than 100 steps in your install you will want to stop the recording > save and start an extra recording.

image

To start a recording press start record or what did you think ;-)

image

When recording you can see the time and the add comment pop up together with the pause and stop button.

You should now minimize the RPS screen and start executing the tasks you want to document.

By pressing the comment button you can add extra info into the documentation. It will be recorded as a separate step and then show up as illustrated in the following screenshot.

image

Continue to use the execute your tasks and add comments whenever you want.

When you have completed all tasks press stop and the system will ask you to save the file. The result will be a zip file containing a fully illustrated html file.

image

Open the zip file to access the document.

image

Double click the document and you will see the result.

As you can see below the screenshots are full screen pages and the active area is highlighted with green squares. Each step you have taken is in a separate screenshot and clearly marked with a timestamp.

image

Above each screenshot you will also find great illustration of what the exact action was that you did eg. left click, right click, press enter, input text,…

image

If you go above the set number of screenshots to save you will see this pop us like this

image

you can even easily copy/past or import into word if you want to add your own touch.

image

With PSR there really is no more reason why you would not have a fully documented environment.

I’m very keen on network segmentation as I really believe it’s the only way to really gain controle and secure your environment. However the major drawback to network segmentation is knowing what protocols, ports,… de allow for network traversal.

If you host a vmware virtual platform in your datacenter Vreference.com is what you need.

This create community effort site has some perfect 1 page sheets that give you a complete overview of all the things you always forget about vmware sytems.

have a look, and here are some examples,

=> ports overview is a great one pager to help you configure firewall access

 

image

=> vsphare 4.0 is a great reference to help you remember what the limits are on vSphere4.0
image

And you will find more of this on the site, let’s just hope some hyperV diagrams pop up soon ;-)

http://www.vreference.com

If you want the full story on NIS and TMG, watch my 30 minutes deep dive webcast at http://www.microsoft.com/belux/technet/nl/chopsticks/default.aspx?id=1416

you’ll learn all you need to know and see two vulnerabilities tested against the system including the SMBv2 0day attack.

A lot of posts have been written on the SMBv2 vulnerability and how this new bug in MS flagship products Windows Vista and Windows 2008 causes BSOD.

For those of you that have not been following security hell this month it all started on 7 September with this post: http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html

Where a 0day exploit was launched with a malformed SMBv2 packet sending an unexpected & character in the smbv2 NEGOTIATE PROTOCOL REQUEST packet

image

you can find the full details on the exploit packet down at  Laura Chappels project site http://www.chappellseminars.com/projects.html

A lot of negative news has been brought out to the internet about this exploit and it is certainly a big issue as the MS official fix at this time is to disable SMB2 a feature we have all come to love and a major driver to why we upgraded from Win2003 to 2008

http://www.microsoft.com/technet/security/advisory/975497.mspx

http://support.microsoft.com/kb/975497

However even in these darkest of time there is always a light at the end of the tunnel and I wanted to seize the opportunity to really illustrate the power of Microsoft's new Network Inspection System  being introduced in TMG the follow up product for ISA is really the answer the the 0-day treat that’s in our worst nightmares.

Once you’ve seen the power of NIS you certainly think twice and add an ISA as central firewall to your environment and start thinking of real network segmentation.

image

What is NIS:

NIS is a new technology based on GAPA that was developed by Microsoft research. This new technology allows TMG to “sniff / inspect” packets at the network layer with application intelligence and detect bad stuff passing over the network based on signatures created by Microsoft support.

The main benefit is that these signatures work just like anti virus data updates. This means you can enable/disable signatures on the fly without having to install “risky” updates on your production servers. It also allows Microsoft to bring protection to you networks much faster than the standard patch develop / test / deploy cycle.

When the SMBv2 vulnerability was launched it literally took  MS research hours to detect / create and deploy the TMG signature, while we are still waiting for the patch Tuesday fix.

Even tough this signature does not fix the issue, it does provide a level op protection we did not have be for NIS was invented.

The main difference between MS signatures and 3de party signatures is that MS developers have direct access to the code being exploited. They can base their signatures by analyzing the actual code being exploited taking into account any unknown vulnerabilities not yet know in the wild. While 3de parties need to relay on trial/error, reverse engineering, info disclosed by MS and  the actual exploit code. But there is no way for them to really look at the root cause of the issue.

What happens:

1) Be for the release of the signature TMG and any other firewall was unaware of the mal intent of the SMBv2 packets and packets passed the network and win2k8 systems BSOD.

image

 

2) Microsoft releases a signature file for the vulnerability and TMG downloads it with hours after the 0day was released. According to your setup the action is to detect only or detect and block. MS default of the SMBv2 vulnerability was of course to detect and block

image

3) After the NIS signature is installed TMG is smarter and can now actively detect the SMBv2 mall formed packet and saving your server from certain death

image

 

As you can see NIS is a very powerful technology that will certainly be worth you investment of time and money to keep you network safer than ever be for.

If you want the full story on NIS, watch my 30 minutes deep dive webcast at http://www.microsoft.com/belux/technet/nl/chopsticks/default.aspx?id=1416

you’ll learn all you need to know and see two vulnerabilities tested against the system including the SMBv2 0day attack.

Missed my live meeting on TMG secure webaccess? Don’t worry here is the online version:

http://www.microsoft.com/belux/technet/nl/chopsticks/default.aspx?id=1389

Dutch Live Meetings :

French Live Meetings :

English In-person event :

More Posts Next page »