<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Path Security &#187; Updates</title>
	<atom:link href="http://www.pathsecurity.com/category/updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pathsecurity.com</link>
	<description>Security is a Journey, not a destination.</description>
	<lastBuildDate>Fri, 18 Jun 2010 21:43:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.4" -->
		<copyright>Copyright &#xA9; 2010 Path Security </copyright>
		<managingEditor>Webmaster@pathsecurity.com ()</managingEditor>
		<webMaster>Webmaster@pathsecurity.com ()</webMaster>
		<category>posts</category>
		<itunes:keywords></itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary>Security is a Journey, not a destination.</itunes:summary>
		<itunes:author></itunes:author>
		<itunes:category text="Society &amp; Culture"/>
		<itunes:owner>
			<itunes:name></itunes:name>
			<itunes:email>Webmaster@pathsecurity.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://www.pathsecurity.com/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<image>
			<url>http://www.pathsecurity.com/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
			<title>Path Security</title>
			<link>http://www.pathsecurity.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>So you got: Clampi/Ilomo</title>
		<link>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/</link>
		<comments>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 21:43:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=218</guid>
		<description><![CDATA[So you got one of the most interesting pieces of Malware I have every had the displeasure of doing IR on&#8230;
Multi-Stage, evolving, silent&#8230; 
It seems to always come from drive-by attacks and silently waits for the C&#038;C to provide instructions&#8230;
I drops onto the system and creates a number of registry keys with difficult to anticipate [...]]]></description>
			<content:encoded><![CDATA[<p>So you got one of the most interesting pieces of Malware I have every had the displeasure of doing IR on&#8230;</p>
<p>Multi-Stage, evolving, silent&#8230; </p>
<p>It seems to always come from drive-by attacks and silently waits for the C&#038;C to provide instructions&#8230;</p>
<p>I drops onto the system and creates a number of registry keys with difficult to anticipate keys, and files with semi random names. That can make it hard to find, but the one key you can count on appearing is,</p>
<p> &#8211; <strong>HKCU\Software\Microsoft\Internet Explorer\Settings\Gateslist</strong></p>
<p>The most important thing you can do to prevent the spread of Clampi/Ilomo once it is on your network is to do no work with Domain Administrator privileges.  One of the most dangerous aspects of Clampi/Ilomo is its ability to log user credentials and use them to spread across your network using legitimate tools like PSEXEC.</p>
<p>@echo off &#038;&#038; reg query HKCU\Software\Microsoft\Internet Explorer\Settings\Gateslist /s || echo Does not Exist!!!!</p>
<p><a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/ilomo_external.pdf">Ilomo Botnet analyzation by TrendMicro</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Cheat Sheet</title>
		<link>http://www.pathsecurity.com/2010/06/cisco-cheat-sheet/</link>
		<comments>http://www.pathsecurity.com/2010/06/cisco-cheat-sheet/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 21:43:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=257</guid>
		<description><![CDATA[Deny WAN HTTP/S to all systems except Proxy:
!Permit HTTP port 80 traffic
access-list 102 deny tcp any any eq 80
access-list 102 permit tcp any {proxy address} eq 80
!Permit HTTPS port 443 traffic
access-list 102 deny tcp any any eq 443
access-list 102 permit tcp any {proxy address}  eq 443
Deny WAN DNS to all systems except DNS server:
 [...]]]></description>
			<content:encoded><![CDATA[<p>Deny WAN HTTP/S to all systems except Proxy:</p>
<blockquote><p>!Permit HTTP port 80 traffic<br />
access-list 102 deny tcp any any eq 80<br />
access-list 102 permit tcp any {proxy address} eq 80</p>
<p>!Permit HTTPS port 443 traffic<br />
access-list 102 deny tcp any any eq 443<br />
access-list 102 permit tcp any {proxy address}  eq 443</p></blockquote>
<p>Deny WAN DNS to all systems except DNS server:</p>
<blockquote><p> access-list 101 permit tcp any any<br />
access-list 101 permit udp any any<br />
access-list 101 deny 53 any any<br />
access-list 101 deny 55 any any<br />
access-list 101 deny 77 any any<br />
access-list 101 deny 103 any any<br />
!&#8212; insert any other previously applied ACL entries here<br />
!&#8212; you must permit other protocols through to allow normal<br />
!&#8212; traffic &#8212; previously defined permit lists will work<br />
!&#8212; or you may use the permit ip any any shown here<br />
access-list 101 permit ip any any</p></blockquote>
<p>Does &#8220;IP helper-address&#8221; help to much?</p>
<blockquote><p>! We want this protocol.<br />
ip forward-protocol udp bootpc<br />
!<br />
! We don&#8217;t want these.<br />
no ip forward-protocol udp biff<br />
no ip forward-protocol udp bootps<br />
no ip forward-protocol udp discard<br />
no ip forward-protocol udp dnsix<br />
no ip forward-protocol udp domain<br />
no ip forward-protocol udp echo<br />
no ip forward-protocol udp isakmp<br />
no ip forward-protocol udp mobile-ip<br />
no ip forward-protocol udp nameserver<br />
no ip forward-protocol udp netbios-dgm<br />
no ip forward-protocol udp netbios-ns<br />
no ip forward-protocol udp netbios-ss<br />
no ip forward-protocol udp non500-isakmp<br />
no ip forward-protocol udp ntp<br />
no ip forward-protocol udp pim-auto-rp<br />
no ip forward-protocol udp rip<br />
no ip forward-protocol udp snmp<br />
no ip forward-protocol udp snmptrap<br />
no ip forward-protocol udp sunrpc<br />
no ip forward-protocol udp syslog<br />
no ip forward-protocol udp tacacs<br />
no ip forward-protocol udp talk<br />
no ip forward-protocol udp tftp<br />
no ip forward-protocol udp time<br />
no ip forward-protocol udp who<br />
no ip forward-protocol udp xdmcp</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2010/06/cisco-cheat-sheet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Boot VM from USB</title>
		<link>http://www.pathsecurity.com/2010/06/boot-vm-from-usb/</link>
		<comments>http://www.pathsecurity.com/2010/06/boot-vm-from-usb/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 21:43:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=324</guid>
		<description><![CDATA[USB-TestVM -> http://www.mediafire.com/?oydn0xngdlz
VMware Player -> http://www.vmware.com/products/player/
VMware Player (DDL) -> http://download3.vmware.com/software/vmpla&#8230;.5.3-185404.exe
PLoP Bootmanager -> http://www.plop.at/en/bootmanager.html
]]></description>
			<content:encoded><![CDATA[<p>USB-TestVM -> http://www.mediafire.com/?oydn0xngdlz<br />
VMware Player -> http://www.vmware.com/products/player/<br />
VMware Player (DDL) -> http://download3.vmware.com/software/vmpla&#8230;.5.3-185404.exe<br />
PLoP Bootmanager -> http://www.plop.at/en/bootmanager.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2010/06/boot-vm-from-usb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>For your Consideration: Please Comment</title>
		<link>http://www.pathsecurity.com/2009/12/for-your-consideration-please-comment/</link>
		<comments>http://www.pathsecurity.com/2009/12/for-your-consideration-please-comment/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 02:34:48 +0000</pubDate>
		<dc:creator>Richard E. Baker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=280</guid>
		<description><![CDATA[I and effort to expand the fuctionality of this site Ive added a pair of video players.
Hopefully this will allow me to record short demos and howto&#8217;s and make them available to the community.
Please reveiw the two player types and let me know which you like better&#8230;
Thank you ahead of time.

]]></description>
			<content:encoded><![CDATA[<p>I and effort to expand the fuctionality of this site Ive added a pair of video players.<br />
Hopefully this will allow me to record short demos and howto&#8217;s and make them available to the community.<br />
Please reveiw the two player types and let me know which you like better&#8230;</p>
<p>Thank you ahead of time.<br />
<span id="more-280"></span><br />
[See post to watch Video]<br />
Video not found!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/12/for-your-consideration-please-comment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>To the 9&#8217;s (my rant)</title>
		<link>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/</link>
		<comments>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 02:00:27 +0000</pubDate>
		<dc:creator>Richard E. Baker</dc:creator>
				<category><![CDATA[Random Rants]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=264</guid>
		<description><![CDATA[System Uptime&#8230;
The 9&#8217;s&#8230;
We all know it&#8230;
We all love it&#8230;
But can we ever really reach the holy grail&#8230;.
Can we get dressed up for all 5 mythical 9&#8217;s?
Let&#8217;s look at exactly what we are shooting for.



 9&#8217;s Rating 
 Percentage Uptime 
 Annual Downtime 
 Downtime Per Day 


 2 
 99.000 
 3 days, 15 hours, [...]]]></description>
			<content:encoded><![CDATA[<p>System Uptime&#8230;<br />
The 9&#8217;s&#8230;<br />
We all know it&#8230;<br />
We all love it&#8230;<br />
But can we ever really reach the holy grail&#8230;.<br />
Can we get dressed up for all 5 mythical 9&#8217;s?<br />
Let&#8217;s look at exactly what we are shooting for.<br />
<span id="more-264"></span></p>
<table border="5" bordercolor="" width="480" bgcolor="">
<tr>
<td> 9&#8217;s Rating </td>
<td> Percentage Uptime </td>
<td> Annual Downtime </td>
<td> Downtime Per Day </td>
</tr>
<tr>
<td> 2 </td>
<td> 99.000 </td>
<td> 3 days, 15 hours, 36 minutes </td>
<td> 8.4 minutes</td>
</tr>
<tr>
<td> 3 </td>
<td> 99.900 </td>
<td> 8 hours, 46 minutes </td>
<td> 1.4 Minutes</td>
</tr>
<tr>
<td> 4 </td>
<td> 99.990 </td>
<td> 53 minutes </td>
<td> 8.7 seconds </td>
</tr>
<tr>
<td> 5 </td>
<td> 99.999 </td>
<td> 5 minutes </td>
<td> 0.8 Seconds </td>
</tr>
</table>
<p>Thats right we are trying for less then 0.8 seconds of down time per day.</p>
<p>Lets face it customers don&#8217;t care if its your fault that they cant reach you&#8230; they just cant reach you&#8230; They dont know if its your server or a router or your firewall or your internet WAN provider&#8230; all that they see is a service that cannot be connected to&#8230; </p>
<p>So&#8230;</p>
<p>Lets make some assumptions, average ping 50ms, from anywhere to anywhere, thats a 16 packet window&#8230; if only one user was utilizing the &#8220;stream&#8221;&#8230; thats insane&#8230; how do you guaranty that you wont lose 16 packets. Now I know any Company that thinks it needs a 5 9 service is going to have more then ONE user at a time&#8230; </p>
<p>So maybe 16 packets is so small that customers wont notice&#8230; but it still happened&#8230; and you&#8217;ve already blown your 9&#8217;s&#8230;</p>
<p>To often small and medium companies focus on making sure that their back end and servers have the 9&#8217;s but forget to factor in the rest of the world, the tubes that connect us all are not under our control&#8230; accidents and congestion happens&#8230; (<a href="http://arstechnica.com/old/content/2008/02/insecure-routing-redirects-youtube-to-pakistan.ars">occasionally black holes appear the suck up all the traffic from Youtube</a>).  Unless you&#8217;ve got the power and cash of Google your never gonna reach more then 3 9&#8217;s&#8230; if you&#8217;re moving a Million USD a minute then maybe you have a business case&#8230; </p>
<p>Downtime is never acceptable&#8230; but ask your self can you afford to be truly dressed to the 9&#8217;s?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OK&#8230; I&#8217;m Back</title>
		<link>http://www.pathsecurity.com/2009/08/ok-im-back/</link>
		<comments>http://www.pathsecurity.com/2009/08/ok-im-back/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 00:49:35 +0000</pubDate>
		<dc:creator>Richard E. Baker</dc:creator>
				<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=221</guid>
		<description><![CDATA[The world moves in crazy ways&#8230;
I&#8217;ve been a busy boy and not posting here near as much as I would like&#8230; but I think I have caught up.  I was to ambitious earlier with my once a day post idea&#8230; so my new goal is to write one quality article a week.  Hopefully [...]]]></description>
			<content:encoded><![CDATA[<p>The world moves in crazy ways&#8230;<br />
I&#8217;ve been a busy boy and not posting here near as much as I would like&#8230; but I think I have caught up.  I was to ambitious earlier with my once a day post idea&#8230; so my new goal is to write one quality article a week.  Hopefully this can work towards my goal of teaching.  Maybe do videos like Irongeek  (<a href="http://www.irongeek.com/">LINK</a>) or some cheat sheets like Packetlife. (<a href="http://www.packetlife.net">LINK</a>) I would also like to either start, or participate in a regular podcast.  Maybe related to the weekly article, So many Ideas&#8230; so little time&#8230; </p>
<p>I&#8217;m sorry this is such a stream of consciousness.</p>
<p>I welcome your comments, your ideas, please let me know what you think in the comments below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/08/ok-im-back/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I am Ronin</title>
		<link>http://www.pathsecurity.com/2009/07/i-am-ronin/</link>
		<comments>http://www.pathsecurity.com/2009/07/i-am-ronin/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 17:30:21 +0000</pubDate>
		<dc:creator>Richard E. Baker</dc:creator>
				<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=209</guid>
		<description><![CDATA[Well its official&#8230;
I am a Security consultant.  In the last two weeks I  conducted my first official incident response and policy gap analysis.  It wasn&#8217;t a glamourous pen testing gig, nor was it something worthy of bragging about, but it was a most excellent opportunity.  During the time I was conducting [...]]]></description>
			<content:encoded><![CDATA[<p>Well its official&#8230;</p>
<p>I am a Security consultant.  In the last two weeks I  conducted my first official incident response and policy gap analysis.  It wasn&#8217;t a glamourous pen testing gig, nor was it something worthy of bragging about, but it was a most excellent opportunity.  During the time I was conducting these contracts I was offered a pretty decent desk job.  The job presented its own opportunities,  but I just couldn&#8217;t bring myself to accept it.  It wasn&#8217;t what I truly wanted.  I am still finding my niche in the security field, but I know Im not built to do the same job day in and out.</p>
<p>I look forward to future contracts, and the challenges that will come my way.  A short post, but maybe someday my Path will inspire someone else.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/07/i-am-ronin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Portable Power: Fun with SD Cards</title>
		<link>http://www.pathsecurity.com/2009/06/portable-power/</link>
		<comments>http://www.pathsecurity.com/2009/06/portable-power/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 23:10:02 +0000</pubDate>
		<dc:creator>Richard E. Baker</dc:creator>
				<category><![CDATA[In Progress]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=197</guid>
		<description><![CDATA[I have been reading a support article by Apple about the SD slot on the new MacBook Pro&#8217;s (LINK), and I think I have come up with an excellent way to use it.
Most netbooks feature a SD card slot that can be booted from&#8230; why not load an OS onto the SD card that is [...]]]></description>
			<content:encoded><![CDATA[<p>I have been reading a support article by Apple about the SD slot on the new MacBook Pro&#8217;s (<a href="http://support.apple.com/kb/HT3553">LINK</a>), and I think I have come up with an excellent way to use it.</p>
<p>Most netbooks feature a SD card slot that can be booted from&#8230; why not load an OS onto the SD card that is tweaked for both the boot camp/fusion/parallels environment and the native netbook.  Then you can take the netbook for IR and such&#8230; collect your data&#8230; and then easily come back to a more powerful rig for analysis.  </p>
<p>Also with the ease of swapping SD cards you can keep different responses separate and cataloged for future review&#8230;</p>
<p>Its all just floating in my head&#8230; but more will come of this&#8230;</p>
<p>Let me know what you think in the comments.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/06/portable-power/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
