<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The FYRM Blog &#187; Uncategorized</title>
	<atom:link href="http://blog.fyrmassociates.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fyrmassociates.com</link>
	<description></description>
	<lastBuildDate>Tue, 10 Aug 2010 14:50:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.fyrmassociates.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/29bd7a6974e2b2222578faa640e336b0?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>The FYRM Blog &#187; Uncategorized</title>
		<link>http://blog.fyrmassociates.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.fyrmassociates.com/osd.xml" title="The FYRM Blog" />
	<atom:link rel='hub' href='http://blog.fyrmassociates.com/?pushpress=hub'/>
		<item>
		<title>Nmap&#8217;s New Math? 9 = 8 but does 3,674 = 65,536?</title>
		<link>http://blog.fyrmassociates.com/2008/11/13/nmaps-new-math-9-8-but-does-3674-65535/</link>
		<comments>http://blog.fyrmassociates.com/2008/11/13/nmaps-new-math-9-8-but-does-3674-65535/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 01:29:20 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[Scanning]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://fyrmassociates.wordpress.com/?p=28</guid>
		<description><![CDATA[Fyodor&#8217;s inclusion of the results from the Top Ports Project into the latest version (4.76) of Nmap is a welcome addition to information security professionals who need to perform port scans of large networks in short periods of time. **cough*** Consulting Firms ***cough** However, the claim that using the &#8220;&#8211;top-ports&#8221; switch to scan only the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=28&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Fyodor&#8217;s inclusion of the results from the Top Ports Project into the latest version (4.76) of Nmap is a welcome addition to information security professionals who need to perform port scans of large networks in short periods of time. **cough*** Consulting Firms ***cough**</p>
<p>However, the claim that using the &#8220;&#8211;top-ports&#8221; switch to scan only the top 3,674 TCP ports is 100% effective opens the door for yet another false sense of security. I wholeheartedly believe that it was NOT Fyodor&#8217;s intention for organizations to rely solely on port scans using this configuration to determine which ports are open. However, it does not require a leap of faith to believe that some less &#8220;offensive minded&#8221; security professionals will now use this configuration to get a &#8220;complete picture&#8221; of their networks.</p>
<p>Why is this a problem? If you are reading this blog, you probably already know where I am going with this. It doesn&#8217;t require another leap of faith to believe that an attacker or offensive minded individual would examine the &#8220;Top Ports&#8221; list and code their malware or configure their tools to operate on ports that are not included in the list. The result? Those who subscribe to this complete picture mentality will not discover the open ports.</p>
<p>So how do we effectively leverage the hard work of the Top Ports Project? I&#8217;m not entirely sure yet. Perhaps we use the &#8220;&#8211;top-ports&#8221; switch to perform differential scans and continue to use &#8220;-p-&#8221; to perform baseline scans? Or maybe we use the &#8220;&#8211;top-ports&#8221; switch to perform discovery scans and &#8220;-p-&#8221; to perform enumeration?</p>
<p>I do know that the information that has been provided as a result of the Top Ports Project is valuable. How do you think we can effectively use this information?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=28&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2008/11/13/nmaps-new-math-9-8-but-does-3674-65535/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Tim Bobanic</media:title>
		</media:content>
	</item>
		<item>
		<title>Remediating Common PCI SSL Vulnerabilities with a Simple Windows Registry File</title>
		<link>http://blog.fyrmassociates.com/2008/11/12/remediating-common-pci-ssl-vulnerabilities-simplified-with-windows-registry-file/</link>
		<comments>http://blog.fyrmassociates.com/2008/11/12/remediating-common-pci-ssl-vulnerabilities-simplified-with-windows-registry-file/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 00:42:37 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[remediation]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Web Servers]]></category>

		<guid isPermaLink="false">http://fyrmassociates.wordpress.com/?p=16</guid>
		<description><![CDATA[Recently I was working with a client who was struggling to remediate two vulnerabilities identified by their quarterly perimeter PCI scans. Specifically, they needed to remediate the following vulnerabilities: SSLv2 Enabled Weak SSL Encryption Ciphers Enabled With these vulnerabilities being so common amongst those bound to the PCI DSS, I would have hoped that better [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=16&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently I was working with a client who was struggling to remediate two vulnerabilities identified by their quarterly perimeter PCI scans. Specifically, they needed to remediate the following vulnerabilities:</p>
<ul>
<li>SSLv2 Enabled</li>
<li>Weak SSL Encryption Ciphers Enabled</li>
</ul>
<p>With these vulnerabilities being so common amongst those bound to the PCI DSS, I would have hoped that better remediation information existed beyond Microsoft&#8217;s overcomplicated Knowledgebase Article,</p>
<ul>
<li><a href="http://support.microsoft.com/kb/245030/en-us" target="_blank">How to Restrict the Use of Certain Cryptographic Algorithms and Protocols in Schannel.dll</a></li>
</ul>
<p>In response to this lack of quality remediation information, I created the following Windows Registry file that aims to simplify the remediation of both vulnerabilities. This file has been tested on IIS 6.0 (Windows 2003) and disables the following weak ciphers, hashing functions, and protocols associated with SSL:</p>
<ul>
<li>Weak Ciphers &#8211; DES 56, NULL, RC2 40/128, and RC4 40/56/128</li>
<li>Weak Hash Functions &#8211; MD5</li>
<li>Weak Protocols &#8211; PCT 1.0, and SSL 2.0</li>
</ul>
<p>You can download the registry file from our website, <a href="http://www.fyrmassociates.com/tools/PCI_IIS_SSL_Tweaks_v1.reg.txt">here</a>.</p>
<p>The standard &#8220;Backup your registry first&#8221; and &#8220;Test on non-production systems first&#8221; rules apply. Happy remediating! (and more importantly&#8230;SECURING!!!)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=16&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2008/11/12/remediating-common-pci-ssl-vulnerabilities-simplified-with-windows-registry-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Tim Bobanic</media:title>
		</media:content>
	</item>
	</channel>
</rss>