<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; networking</title>
	<atom:link href="http://www.system7.org/category/security/networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:56:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>do you know where your pr0n is?</title>
		<link>http://www.system7.org/2010/05/21/do-you-know-where-your-pr0n-is/</link>
		<comments>http://www.system7.org/2010/05/21/do-you-know-where-your-pr0n-is/#comments</comments>
		<pubDate>Fri, 21 May 2010 18:17:16 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=524</guid>
		<description><![CDATA[In 2008, Data Loss Prevention (DLP) was becoming the latest trend, hype, buzzword.  This slowed down in 2009 as with most technology because of everyone tightening their belt (purse strings).  I&#8217;ve been wondering how long it was going to take for an open source DLP solution to take off.  Please correct me if I&#8217;m wrong [...]]]></description>
			<content:encoded><![CDATA[<p>In 2008, Data Loss Prevention (DLP) was becoming the latest trend, hype, buzzword.  This slowed down in 2009 as with most technology because of everyone tightening their belt (purse strings).  I&#8217;ve been wondering how long it was going to take for an open source <a title="Data Loss Prevention" href="http://en.wikipedia.org/wiki/Data_Loss_Prevention">DLP </a> solution to take off.  Please correct me if I&#8217;m wrong but it appears <a href="http://code.google.com/p/opendlp/">opendlp </a>may be the first on the scene.  While still in its infancy (at a minor 0.2.1 release) it already has a web front end and a deployable agent for clients (monitoring data at rest).  It supports regular expressions which should make it flexible.  Without a WYSIWYG policy builder like you&#8217;re getting with off the shelf products you&#8217;re sacrificing ease of use vs. power and flexibility.</p>
<p>So far I&#8217;ve only used a pilot of Symantec&#8217;s (formerly Vontu) DLP product for my employer.  I had a blast testing it out on the network especially because of its flesh tone filter (if flesh_tone_filter then email me pr0n).  It&#8217;s a shame we may not see flesh tone filtering in opendlp any time soon; isn&#8217;t knowing where the pr0n is more important than the company&#8217;s lifeblood, intellectual property?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/05/21/do-you-know-where-your-pr0n-is/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Podcast about ICANN, root dns servers, Chinese domination and more!</title>
		<link>http://www.system7.org/2010/04/18/podcast-about-icann-root-dns-servers-chinese-domination-and-more/</link>
		<comments>http://www.system7.org/2010/04/18/podcast-about-icann-root-dns-servers-chinese-domination-and-more/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 16:13:07 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=506</guid>
		<description><![CDATA[I try to catch the weekly NPR Technology podcast.  This week there&#8217;s an interesting segment about ICANN, VeriSign and their root nameservers, as well as China&#8217;s desire to wrestle control of the internet.  You can get the podcast here: http://podcastdownload.npr.org/anon.npr-podcasts/podcast/1019/126006147/npr_126006147.mp3 *You need to advance to 5:00minutes into the podcast for this segment (unless you want [...]]]></description>
			<content:encoded><![CDATA[<p>I try to catch the weekly NPR Technology podcast.  This week there&#8217;s an interesting segment about ICANN, VeriSign and their root nameservers, as well as China&#8217;s desire to wrestle control of the internet.  You can get the podcast here: <a title="NPR Technology Podcast" href="http://podcastdownload.npr.org/anon.npr-podcasts/podcast/1019/126006147/npr_126006147.mp3">http://podcastdownload.npr.org/anon.npr-podcasts/podcast/1019/126006147/npr_126006147.mp3</a></p>
<p>*You need to advance to 5:00minutes into the podcast for this segment (unless you want to listen about Cuban bloggers)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/04/18/podcast-about-icann-root-dns-servers-chinese-domination-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pay to have your neighbor&#8217;s wireless cracked</title>
		<link>http://www.system7.org/2010/01/18/pay-to-have-your-neighbors-wireless-cracked/</link>
		<comments>http://www.system7.org/2010/01/18/pay-to-have-your-neighbors-wireless-cracked/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 14:24:52 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=431</guid>
		<description><![CDATA[I just found this article about a new service run by Moxie Marlinspike (from sslsniff fame).  He has created WPA Cracker which uses the cloud (his 100 cpu quad processor cluster) to crack WPA and WPA2 (PSK only) handshake captures.  So for $17 and the handshake capture you should have your password with 20 minutes. [...]]]></description>
			<content:encoded><![CDATA[<p>I just found this <a href="http://www.thewhir.com/web-hosting-news/120909_Security_Researcher_Moxie_Marlinspike_Starts_Cloud_Based_WPA_PSK_Checking_Service">article</a> about a new service run by Moxie Marlinspike (from sslsniff fame).  He has created <a href="http://www.wpacracker.com/index.html">WPA Cracker</a> which uses the cloud (his 100 cpu quad processor cluster) to crack WPA and WPA2 (PSK only) handshake captures.  So for $17 and the handshake capture you should have your password with 20 minutes.</p>
<p><a href="http://www.aircrack-ng.org/doku.php?id=cracking_wpa#step_2_-_start_airodump-ng_to_collect_authentication_handshake">Related</a>: Using airodump-ng to capture the authentication handshake.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/01/18/pay-to-have-your-neighbors-wireless-cracked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure your machine&#8230;Whitelist</title>
		<link>http://www.system7.org/2009/12/08/secure-your-machine-whitelist/</link>
		<comments>http://www.system7.org/2009/12/08/secure-your-machine-whitelist/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 11:12:31 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=340</guid>
		<description><![CDATA[I previously talked about a blacklisting method to reduce the number of ssh brute force attempts against your machine.  When you follow a blacklisting methodology, in theory, it could never end which is why people are screaming &#8216;whitelist&#8217; today.  If you&#8217;re not ready to deny all and not absolutely sure of which IP you&#8217;ll be [...]]]></description>
			<content:encoded><![CDATA[<p>I previously talked about a blacklisting method to <a href="http://www.system7.org/2009/07/26/reduce-ssh-brute-force-attempts/">reduce the number of ssh brute force attempts against your machine</a>.  When you follow a blacklisting methodology, in theory, it could never end which is why people are screaming &#8216;whitelist&#8217; today.  If you&#8217;re not ready to<strong> deny all</strong> and not absolutely sure of which IP you&#8217;ll be riding in on (back to home base) then you may want to take a look at the options below&#8230;</p>
<p>Most brute forcing today usually comes from Asia or Eastern Europe &#8212; blocking continents (if you can get away with it) is great practice.  Below are some links where you can copy &amp; paste <em>problematic</em> IP ranges into your .htaccess or hosts.deny file&#8230;.</p>
<p><a href="http://www.wizcrafts.net/chinese-blocklist.html">Apache .htaccess block format</a></p>
<p><a href="http://www.countryipblocks.net/">Country IP Blocks</a> &#8211; choose a country and select the output in many formats (CIDR, hosts.deny, etc)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/12/08/secure-your-machine-whitelist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sourcefire (Snort) Network Security Seminar</title>
		<link>http://www.system7.org/2009/07/02/sourcefire-snort-network-security-seminar/</link>
		<comments>http://www.system7.org/2009/07/02/sourcefire-snort-network-security-seminar/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 16:56:37 +0000</pubDate>
		<dc:creator>Andre Lenoge</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=251</guid>
		<description><![CDATA[Last week I attended a seminar by Sourcefire.  Their CTO, Martin Roesch, was the speaker.  The topic was &#8220;Your Network Security Isn’t Good Enough Anymore&#8220;.  This seminar was ultimately a sly sales pitch for Snort, their IDS product.  Roesch talked about how there are several equal quality IDS products available now &#8212; there is much [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I attended a seminar by Sourcefire.  Their CTO, <a title="Snort maker, Martin Roesch" href="http://en.wikipedia.org/wiki/Martin_Roesch">Martin Roesch</a>, was the speaker.  The topic was &#8220;<strong>Your Network Security Isn’t Good Enough Anymore</strong>&#8220;.  This seminar was ultimately a sly sales pitch for Snort, their IDS product.  Roesch talked about how there are several equal quality IDS products available now &#8212; there is much less market differentiation between them.</p>
<p>Two problems:</p>
<p>1) No one is taking the time to properly configure / tune the IDS for the environment it&#8217;s placed in &#8212;&gt; meaning thousands of events with many false positives.</p>
<p>2) The IDS events being generated are not monitored &#8212;&gt; the average breach to compromise time is down to minutes in some cases meaning you don&#8217;t have time to wait.</p>
<p>The next generation Snort intends to solve both of the problems above.  Their calling their new version &#8220;Adaptive IPS&#8221; which features their real time network awareness (RNA) technology.  This RNA module constantly surveys your network taking inventory of OSes, services, protocols, and potential vulnerabilities that exist.  The RNA module then pushes configuration changes to Snort &#8212; auto tuning the IDS for your network!  I haven&#8217;t tried RNA myself but Roesch claimed several customers seeing a 90+% reduction in the number of IDS generated events.  With this dramatic reduction in events to monitor it should mean no excuses to not monitor your network.</p>
<p>Now, if Sourcefire can create a module that will monitor and act on events we won&#8217;t need NoCs anymore&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/07/02/sourcefire-snort-network-security-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Great &#8220;defeating the firewall&#8221; article</title>
		<link>http://www.system7.org/2009/06/13/great-defeating-the-firewall-article/</link>
		<comments>http://www.system7.org/2009/06/13/great-defeating-the-firewall-article/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 17:22:41 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=231</guid>
		<description><![CDATA[I stumbled across an excellent article on freenode #security.  Does your employer use content filtering?  Are you sick of being restricted when using free wifi hotspots?  How about a hotel charging for wifi? The article talks about methods to circumvent all of the above scenarios.  I actually do the most vanilla technique to overcome my [...]]]></description>
			<content:encoded><![CDATA[<p>I stumbled across an excellent article on freenode #security.  Does your employer use content filtering?  Are you sick of being restricted when using free wifi hotspots?  How about a hotel charging for wifi?</p>
<p>The article talks about methods to circumvent all of the above scenarios.  I actually do the most vanilla technique to overcome my employer&#8217;s web filter: dynamic ssh tunneling back to a server I have running at home.</p>
<p>Read it here:  <a href="http://blog.sebastien.raveau.name/2009/06/internet-by-all-means.html">http://blog.sebastien.raveau.name/2009/06/internet-by-all-means.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/06/13/great-defeating-the-firewall-article/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DD-WRT and wireless observations</title>
		<link>http://www.system7.org/2009/06/03/dd-wrt-and-wireless-observations/</link>
		<comments>http://www.system7.org/2009/06/03/dd-wrt-and-wireless-observations/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 13:18:36 +0000</pubDate>
		<dc:creator>Andre Lenoge</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[dd-wrt]]></category>
		<category><![CDATA[linksys]]></category>
		<category><![CDATA[netstumbler]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=184</guid>
		<description><![CDATA[I installed DD-WRT over the weekend following this tutorial.  This is something I wish I would have done a lot sooner because of the additional features DD provides.  Unfortunately I have a v8 WRT54g which only has 2mb of flash memory.  This limited me to only being able to run the stripped down &#8220;micro&#8221; version. [...]]]></description>
			<content:encoded><![CDATA[<p>I installed DD-WRT over the weekend following this <a href="http://www.simplehelp.net/2008/09/11/how-to-flash-the-linksys-wrt54g-v8-with-the-dd-wrt-firmware/">tutorial</a>.  This is something I wish I would have done a lot sooner because of the additional features DD provides.  Unfortunately I have a v8 WRT54g which only has 2mb of flash memory.  This limited me to only being able to run the <a href="http://dd-wrt.com/wiki/index.php/What_is_DD-WRT%3F#File_Versions">stripped down &#8220;micro&#8221; version.</a> DD supports syslog but the micro version does not log firewall events.  I was hoping to pass these to my IDS.  Hopefully I can figure out a way to use iptables to replicate a span or tap port.</p>
<p>I tweaked the TX Power using DD.  Be warned you can overheat your router if you try to crank this up too high.  The biggest signal boost I was raising my access point 2&#8242;.  Try to keep your AP elevated as much as possible.  See my image below&#8230;.</p>
<p><img class="alignnone size-thumbnail wp-image-185" title="dd-wrt" src="http://www.system7.org/wp-content/uploads/2009/06/dd-wrt-150x150.jpg" alt="dd-wrt" width="150" height="150" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/06/03/dd-wrt-and-wireless-observations/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Your Thoughts: Ad-hoc Monitor Port on WRT54G</title>
		<link>http://www.system7.org/2009/02/10/your-thoughts-ad-hoc-monitor-port-on-wrt54g/</link>
		<comments>http://www.system7.org/2009/02/10/your-thoughts-ad-hoc-monitor-port-on-wrt54g/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 00:58:31 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=107</guid>
		<description><![CDATA[I would like to run Snort and Bot Hunter on a spare Linux machine on my home LAN.  My local network uses the very common Linksys WRT54G wireless router.  Therefore I have a switched network which makes it very difficult to perform any type of network sniffing. I&#8217;m asking for your thoughts and feedback to [...]]]></description>
			<content:encoded><![CDATA[<p>I would like to run <a href="http://www.snort.org/">Snort</a> and <a href="http://www.bothunter.net">Bot Hunter </a>on a spare Linux machine on my home LAN.  My local network uses the very common Linksys WRT54G wireless router.  Therefore I have a switched network which makes it very difficult to perform any type of network sniffing.</p>
<p>I&#8217;m asking for your thoughts and feedback to solve this problem.  Right now I&#8217;ve come up with the following solutions:</p>
<ul>
<li>Connect a hub to the router&#8217;s WAN port.  Connect my cable modem and linux machine to the hub.</li>
<li>Install <a href="http://www.dd-wrt.com">DD-WRT</a> on the Linksys router.  Does DD-WRT yet support <a href="http://en.wikipedia.org/wiki/Port_mirroring">span / tap (monitor) ports</a>?</li>
<li>Install two (2) NICs on the linux machine and route my cable modem through that before connecting to the router.</li>
<li>Buy an affordable Cisco 2600 router off of eBay.</li>
</ul>
<p>Please share your ideas and thoughts on the subject.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/02/10/your-thoughts-ad-hoc-monitor-port-on-wrt54g/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
