2

“Don’t need AV, we have a firewall”

July 12, 2010

A friend stopped by to ask if security suite x was any good or not. This led onto a conversation about a place she was working that wasn’t running any AV on windows machines. The rational behind this came from a 3rd party IT support guy  who said “you don’t need AV on the Windows machines,  the firewall will protect them”.

When I say firewall, I mean a good, old layer 3 packet filtering device. The things that cost $100 new and are, well, ADSL routers with added security aren’t able to protect a small office by themselves. Added security  equals access control lists in a pretty GUI, so not really the poster boy for defense in depth.

Amazing that some IT “professionals” actually believe having a firewall will stop pc’s from getting malicious software. Thanks goodness the USB device fad never took off.

If you do not have anti-virus software on your home or small office computer, Microsoft provides a free copy you can download from here: http://www.microsoft.com/security_essentials/

It does the job, is simple to use and doesn’t cost a penny. You want something with all the whistles and bells, pick a security suite package from any of the big names.

We now return to our regular programme.

  • 0

    Netsh commands

    July 11, 2010

      This is nothing new or exciting, I just keep forget the syntax so I’m leaving here to make it much easier to find/remember. Interface Configuration Interface named Local Area Connection with the static IP address 192.168.66.100, the subnet mask of 255.255.255.0, and a default gateway of 192.168.66.1: netsh interface ip set address name=”Local Area [...]

  • 2

    Regaining reputation after defacement

    June 23, 2010

    After the defacement and clean up, I was going about my normal business when a couple of friends noted that select pieces of reputation software are highlighting the site as either a phishing site or malicious content. This means folks would be blocked or have WARNING EVIL signs as they attempted to connect to this [...]

  • 1

    From SANS 709: brute-forcing Address Space Layout Randomization (ASLR) on Linux

    June 22, 2010

    In my other rush to get up to speed for SANS 709 Developing Exploits for Penetration Testers and Security Researchers I’m looking for any material that will easy that learning curve. Steve Sims has just posted up two YouTube videos on brute-forcing Address Space Layout Randomization (ASLR) on Linux straight out of the 709 courseware. [...]

  • 1

    From China with Love

    June 20, 2010

    I received two gifts from a family member returning from China. It was a lovely though and I was touched by the gesture. Both items are of the geek variety and bought from stalls, one a ball point pen with a built in 2GB USB stick that can act as a voice recorder and the [...]