Archive for July 2009

0

Forefront Update Error 0×80080005

July 21, 2009

Had a Forefront client that displayed the annoying* orange alert icon. The system was refusing to get the current Forefront definitions update with a 0×80080005. No updating for me A quick search of the web got me no-where.  Back to proper troubleshooting. Check services (Automatic Updates & Background Intelligent Transfer Service) and WindowsUpdate.log details are [...]

0

Changing the management group to which an FCS client reports

July 19, 2009

Was doing a bit of house keeping in a lab and had to re-point the Forefront MOM agents for a whole pile of machines. I remembered that FCS Nerds’ Craig Wiands had done a great post on it, so it dug it out and kicked of a simple batch script. Boom – redirected all the  [...]

0

Cisco’s Ironport blocks email to Offensive Security

July 19, 2009

Damian, Senior facilitator, is embarking on the Penetration Testing with BackTrack  PWB Online course from  the Offensive Security guys. He applied and did not receive any email response. This was a bit strange. Damian discovered that his Ironport has classified the Offensive Security domain as bad (-2 rating). As he is an Iron Port guru, [...]

1

Blocking web sites on ISA 2006

July 14, 2009

A quick and simple ISA rule to block dangerous web sites and URLs Overview: Create a URL set of all sites and block them. In this case I want to stop users being re-directed to the malware sites of the day. The sites I want to blocked are taken from the Internet Storm Center story [...]

0

Re-educating the Board on where our borders end

July 12, 2009

Catching up on the weekly security news, this headline caught my eye, “US and South Korean Sites Under Attack; Late Data Says Attacking PCs to Self Destruct (July 8 & 9, 2009)” from the SANS weekly newsbites. The piece covers recent attacks on US and South Korean government, military and private industry, with some nice [...]