<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>mcwresearch.com &#187; Security Tips</title>
	<atom:link href="http://mcwresearch.com/archives/category/security-tips/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com</link>
	<description>Things I think I've thought about</description>
	<lastBuildDate>Mon, 28 Dec 2009 22:10:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>I have no sympathy&#8230;</title>
		<link>http://mcwresearch.com/archives/419</link>
		<comments>http://mcwresearch.com/archives/419#comments</comments>
		<pubDate>Thu, 15 Feb 2007 17:07:23 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/419</guid>
		<description><![CDATA[If you are still allowing executable attachments past your mail server then you deserve what ever malware gets into your systems. Yesterday, VNUNET.com reported the following (possibly FUD?): Security experts today warned that a &#8220;widespread worm&#8221; posing as a Valentine&#8217;s greeting is spreading fast across the internet. According to Sophos, as reported by VNUNET; The [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/419/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why system hardening is critical</title>
		<link>http://mcwresearch.com/archives/382</link>
		<comments>http://mcwresearch.com/archives/382#comments</comments>
		<pubDate>Fri, 19 Jan 2007 18:17:07 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>
		<category><![CDATA[Hardening]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/382</guid>
		<description><![CDATA[Jeremiah Grossman has made a good point that your public-facing web servers shouldn&#8217;t be secured using the &#8216;low hanging fruit&#8217; technique. In this technique, you scan your network and remedy all the obvious vulnerabilities like old patches not installed, unnecessary services listening on the network, etc. While this works great as a starting point in [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/382/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learning from our mistakes</title>
		<link>http://mcwresearch.com/archives/367</link>
		<comments>http://mcwresearch.com/archives/367#comments</comments>
		<pubDate>Thu, 28 Dec 2006 23:00:40 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/367</guid>
		<description><![CDATA[One of my favorite quotes is; &#8220;Those who cannot learn from history are doomed to repeat it.&#8221; 90% of the malware floating around the internet today is regurgitated, canned attacks with only slight variations. So if we learn from history we&#8217;ll know that; Windows RPC will be a target of self-propogating malware for the foreseeable [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/367/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Defense in depth</title>
		<link>http://mcwresearch.com/archives/293</link>
		<comments>http://mcwresearch.com/archives/293#comments</comments>
		<pubDate>Mon, 28 Aug 2006 16:57:08 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/293</guid>
		<description><![CDATA[Sifting through the logs of my HIPS software this morning revealed an odd application on one of my hosts trying to get out to the Internet. The file &#8216;C:\windows\system32\svohost.exe&#8221; is associated with a couple of different trojans but our AV software wasn&#8217;t picking it up as anything malicious so I uploaded it to VirusTotal.com and [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/293/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pay It Forward:  Don&#8217;t get lazy!</title>
		<link>http://mcwresearch.com/archives/281</link>
		<comments>http://mcwresearch.com/archives/281#comments</comments>
		<pubDate>Tue, 22 Aug 2006 14:22:47 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/281</guid>
		<description><![CDATA[I was brutally reminded yesterday how important it is to keep an eye on things when you are updating systems rapidly. I&#8217;ve been updating my vulnerability scanners almost as quickly as the vendor has been releasing updates. To date I&#8217;ve run numerous scans using one of their canned scanning policies. However, with one of their [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/281/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pay It Forward: Unorthodox patching techniques</title>
		<link>http://mcwresearch.com/archives/272</link>
		<comments>http://mcwresearch.com/archives/272#comments</comments>
		<pubDate>Wed, 09 Aug 2006 15:26:58 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Patch-Tuesday]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/272</guid>
		<description><![CDATA[Yes, &#8216;pay it forward&#8217; was originally a week-long deal, but it is a lot of fun and turned out to be pretty successful so I&#8217;ve made it a permanent fixture of the site. This month&#8217;s security bulletins from Microsoft include a bulletin and patch regarding a vulnerability in the Server service. The server service is [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/272/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>MS06-040 (updated)</title>
		<link>http://mcwresearch.com/archives/271</link>
		<comments>http://mcwresearch.com/archives/271#comments</comments>
		<pubDate>Tue, 08 Aug 2006 20:35:30 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Patch-Tuesday]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/271</guid>
		<description><![CDATA[Patch for this one now and troubleshoot the problems later. It&#8217;s nasty and in a week or less a million cable/DSL users will be spewing scans all over the Internet. http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx Why am I making such a prediction? Glad you asked: The Server service is enabled by default On many servers, you can&#8217;t firewall it [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/271/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pay it forward:  Success!</title>
		<link>http://mcwresearch.com/archives/269</link>
		<comments>http://mcwresearch.com/archives/269#comments</comments>
		<pubDate>Tue, 08 Aug 2006 01:37:46 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/269</guid>
		<description><![CDATA[The whole point of &#8216;pay it forward&#8217; was exactly what Johannes Ullrich sought in his diary post here. That is to get the security community sharing information and that&#8217;s exactly what some of us did. We got the following sites sharing tips: An Information Security Place Still Secure After All These Years Anton Chuvakin Personal [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/269/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Pay it forward:  Wrap Up</title>
		<link>http://mcwresearch.com/archives/265</link>
		<comments>http://mcwresearch.com/archives/265#comments</comments>
		<pubDate>Fri, 04 Aug 2006 13:12:35 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/265</guid>
		<description><![CDATA[So today is the last day of the &#8216;Pay It Forward&#8217; experiment. I&#8217;m not sure what the other guys saw on their sites but I did see a fair amount of interest in the tips, so I hope they were helpful to some. Anton Chuvakin at Chuvakin.blogspot.com joined in the fun and posted a tip [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/265/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Pay it forward:  Know Your Network</title>
		<link>http://mcwresearch.com/archives/264</link>
		<comments>http://mcwresearch.com/archives/264#comments</comments>
		<pubDate>Thu, 03 Aug 2006 16:56:05 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tips]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/264</guid>
		<description><![CDATA[Alan over at Still Secure, After All These Years posted a tip today about using a secure OS on your network, utilizing a host-based firewall, and automating OS patching. Michael Farnum at An Information Security Place posted a tip today about due diligence (my post today ties into &#8216;due diligence&#8217; nicely). The ISC posted a [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/264/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

