Pages

Friday, May 18

Icons are so 1995

Something else I noticed today, I was interested in how the new Finder desktop looks, in ref: the menu bar, the dock, Stacks...etc.. and I noticed something else

There are no icons on the Desktop.

Now, Steve said that one of the reasons that our desktops are so cluttered is because, when we download something, it falls on our Desktop. (True). So they created a Stack to manage all the downloads.

Which, if you strip all the other stuff off the Desktop, (Your Hard-drive icon, your CD/DVD icon (if you have something in the drive), your iDisk icon (if you have one), your other hard-drives, mounted shares...etc.. can all be found in the new Finder, which, can be launched from the most left button on the Dock.

Personally I like this. I don’t use my Desktop icons anyway, I actually shut them off and use my menu bar (at the top) and the Dock (at the bottom) like you are supposed to.

Which it looks like Apple is going to have you do in Leopard. Nice.

Icons are so 1995

Something else I noticed today, I was interested in how the new Finder desktop looks, in ref: the menu bar, the dock, Stacks...etc.. and I noticed something else

There are no icons on the Desktop.

Now, Steve said that one of the reasons that our desktops are so cluttered is because, when we download something, it falls on our Desktop. (True). So they created a Stack to manage all the downloads.

Which, if you strip all the other stuff off the Desktop, (Your Hard-drive icon, your CD/DVD icon (if you have something in the drive), your iDisk icon (if you have one), your other hard-drives, mounted shares...etc.. can all be found in the new Finder, which, can be launched from the most left button on the Dock.

Personally I like this. I don’t use my Desktop icons anyway, I actually shut them off and use my menu bar (at the top) and the Dock (at the bottom) like you are supposed to.

Which it looks like Apple is going to have you do in Leopard. Nice.

Tuesday, May 8

The Snort Book

Finally got my copies of my book today from the publisher. (Only took them a month!) There are alot of comments I could make about the book, positive and negative, but overall, it’s a great resource. In particular the preprocessors chapter (i know, I wrote it) has some good tuning steps and hints that you won’t find elsewhere.

Some chapters are better than others. Some chapters have errors in them (even mine! I mean, really, who begins a TCP conversation with a FIN, ACK? I swear, it was correct in the proof copy!)

I make mention of Stream5 in my chapter at one point, saying that we ‘took a peek at it’, even though I didn’t discuss it at all. At the time of writing Stream5 wasn’t out yet, so I couldn’t really put much in there about it since it was still in beta. I originally had some stuff in there about UDP session tracking being in Stream5, but I took it out. Hence why I “refer” back to it later.

I edited/rewrote another chapter in the book (which shall remain unknown for now), but none of my edits got in the book. When I asked the publisher why, turns out the publisher for this particular book quit in the middle of the book’s publish, so alot of edits didn’t get in there. Hm.. That sucks. Maybe they’ll do an edition two to add in that stuff.

I really like the book overall, I really liked the writing experience, however next time, if asked to write a book, or if I write my own book... i’d like more control over it. Our editors, did a GREAT job with the task that was set before them. I wrote my chapter on my laptop on flights and in hotels. I always got interesting looks when people would look over in a plane and see me just goin to TOWN on the keyboard. (You know how some people just work on excel spreadsheets and what not, it’s always interesting to see people going nuts on their keyboard.)

Go buy the book. You’ll learn alot. I promise. If you read the book, alot of the most common questions are answered. If that doesn’t work, then pop into #snort on irc.freenode.net and ask your question, or pop onto the snort-users mailing list. Chances are, your question not only has been asked already, but we’ll get you the answer right away. See you online!

Addendum --

It was pointed out in a blog comment here that my title was neither “Director” nor did I “develop” an IDS at my last job. (As listed in my bio.) Both true. I’ll admit it. The commenter even went so far as to call me a LIAR. (Yes all in caps). Let me correct/clarify. As I most definitely didn’t mean to ‘lie’.

There was no such thing as “Director” in my last job. My title was “Section Manager”. Originally the title given me at my was “Section Lead”, however, in the politics that ensued after I was ‘promoted’ to the position, it was pointed out to me that “Lead” was reserved for Government employees. I was a contractor. When I sent my bio to a couple of people for proofread, I also sent it to the publisher because of a deadline we had to meet. When the people I sent it to for proofread pointed out “Director”, I said, ‘ah yes’ and emailed the publisher with the correction. Why did I write it in there? In my present job, the equivalent title of the position would have been Director. No one knows what ‘Section Manager’ is. It’s not a real title. ‘Manager’ is a real title, ‘Section Manager’ is one of those made up Government titles. What were my responsibilities? I attended a weekly ‘managers’ meeting, and compiled a weekly report of what the guys did who ‘worked’ for me did. First of all, the guys that worked for me were on a different contract, so I couldn’t tell them what to do anyway. You didn’t get into our section unless you didn’t need to be managed. (You had to be self-sustainable) So, the title really meant nothing. Second of all, no one had one boss. Working on one project, a friend named Jamey was the lead on, Working for the section, I was the lead on, but then my contract lead (Joe) was my boss and wrote my reviews, except he didn’t give me my jobs, another person named Harry did that, his title was “Lead Contractor”, and he was everyones boss, but everyone reported to him directly. Then on top of all that, our Government rep at the office was our boss as well and she was over everyone. After I left, it just got worse with one more layer of boss in the middle there somewhere. As I said, the title didn’t mean much.

That’s what causes people to get other jobs. Some of the best employees I know have left that place because of all the politics.


As to the second point -- Developing an IDS. I did NOT develop an IDS. I DID develop a IDS system of tools that worked together (yes, of course, with some assistance from a couple of friends, mainly on the db side), for passive os fingerprinting, full traffic capture, and then yes, the IDS. Which was Snort. I developed how the tools worked together, and automated all the pieces and parts to keep them all up and running on the multiple sensors I had. When I was asked to help develop the system that is currently in place on a much much larger scale at a sister office, I did. That system is still in place today exactly how I designed it (at the sister office).

The system I developed at my home office has been dismantled and pieced apart and not all the pieces on it are running anymore, mainly because no one knew how it all worked after I left. Why? I am not sure. It was all documented. For the best comparison that I can make to the system I made is sguil. Except without the tcl/tk frontend.

Did I write ‘Director’? Yes. I sure did. To make myself look better and over-inflated and to lie? No, that was not the intention. The intention was to convert my ‘made up’ title into a commercial equivalent. When it was pointed out to me, I did make the correction, and the correction wasn’t published. (add that to the list of things that didn’t get corrected)

Now, the thing that concerns me is, only a few people knew the exact nature of my title while at the RCERT, and out of those people, only a couple would be rude enough to try and bust me out publicly. On my own blog nonetheless. All of those people, both the people I think it is, and the rest of the people at the RCERT have my email address and could have wrote me an email telling me the deal. Everyone has my email address. Hell, it’s on the front page of this blog.

I didn’t appreciate it, even though you were correct, it was rude.

Unresponsive Finder

Okay. A long time ago (If you read my old blog), you’ll know that my powerbook froze up, accessing files in Finder was unresponsive, and searching with Spotlight was impossible. (Spinning beachball from hell). Well I figured out how to fix it then, and yesterday, my PowerMac Dual G5 started the same exact thing, and I was able to reproduce the fix, so here it is for your problem solving pleasure:

As I stated, Finder and Spotlight become unresponsive. I have no idea what causes this, but I noticed it yesterday when I’d try to open a file, or attach a file to an email, I’d click on the file in Finder’s ‘column’ view, and it would literally take about 20 minutes to get the details of the file in the next column. (Spinning beachball, machine and Finder completely frozen)

Open Terminal, type:
$sudo mdutil -s /

mdutil is the utility that manages your Spotlight store for each drive. You can use mdutil to even index network shares. (which is quite handy) For more information on mdutil, either read the man page, or type:
$sudo mdutil -h

Anyway -- I got sidetracked there. If mdutil -s / takes a long time to run and gives you some crap about not being able to lookup the index status of the “/” drive, then you are experiencing the same problem I was. For some reason OSX’s Spotlight index gets fubar’ed, and when that happens, no more information store (Finder) for you! So let’s fix it. Back in your terminal type:
$sudo mdutil -i off / (This turns off indexing for your drive)
$sudo mdutil -E / (This erases the information store for your drive)

If either one of these two error out, you will have to do it manually, skip the next step then read further down.

Now reboot. When your computer comes back up, open a Terminal window and type:
$sudo mdutil -i on /
$top -o cpu

This will bring up top and sort it by cpu usage. If you see ‘mds’ and ‘mdimport’ being in the top 3 or 4 or so, that’s good. OSX is rebuilding your Spotlight cache. Let it do this, and hopefully everything will return to normal. Now, if at any point your command errors out (“Can’t find index status, Can’t erase index” or similar, go to this:)

Now, if all that stuff didn’t work, so let’s fix it manually.
Step 1: Open System Preferences -> Sharing. At the top you will see the hostname of your computer. (Yes, this is the HOSTNAME.) Change this. To anything you want, for some reason Finder is tied to the hostname of your computer and if you change the hostname it magically fixes this problem.
Step 2: Back in your Terminal Window, descend to “/”. ($cd /)
Step 3: Erase your Spotlight cache. (Sounds dangerous doesn’t it? Don’t worry it’ll be rebuilt)
$sudo rm -rf /.Spotlight-V100/ (NOTICE THE DOT, it’s a hidden directory, you’d have to add a -a to your ‘ls’ to see it)

Now reboot. When your computer comes back up, your Spotlight cache will be rebuilt (may take awhile, it took about 3 hours on my Powermac (But it has 3 harddrives in it), then everything should be good to go.

Remember, changing that hostname is the magic step. Don’t forget it.

If this helps you, please leave a comment and let me know. If you have an suggestions to add to this, please leave a comment and let me know.

Unresponsive Finder

Okay. A long time ago (If you read my old blog), you’ll know that my powerbook froze up, accessing files in Finder was unresponsive, and searching with Spotlight was impossible. (Spinning beachball from hell). Well I figured out how to fix it then, and yesterday, my PowerMac Dual G5 started the same exact thing, and I was able to reproduce the fix, so here it is for your problem solving pleasure:

As I stated, Finder and Spotlight become unresponsive. I have no idea what causes this, but I noticed it yesterday when I’d try to open a file, or attach a file to an email, I’d click on the file in Finder’s ‘column’ view, and it would literally take about 20 minutes to get the details of the file in the next column. (Spinning beachball, machine and Finder completely frozen)

Open Terminal, type:
$sudo mdutil -s /

mdutil is the utility that manages your Spotlight store for each drive. You can use mdutil to even index network shares. (which is quite handy) For more information on mdutil, either read the man page, or type:
$sudo mdutil -h

Anyway -- I got sidetracked there. If mdutil -s / takes a long time to run and gives you some crap about not being able to lookup the index status of the “/” drive, then you are experiencing the same problem I was. For some reason OSX’s Spotlight index gets fubar’ed, and when that happens, no more information store (Finder) for you! So let’s fix it. Back in your terminal type:
$sudo mdutil -i off / (This turns off indexing for your drive)
$sudo mdutil -E / (This erases the information store for your drive)

If either one of these two error out, you will have to do it manually, skip the next step then read further down.

Now reboot. When your computer comes back up, open a Terminal window and type:
$sudo mdutil -i on /
$top -o cpu

This will bring up top and sort it by cpu usage. If you see ‘mds’ and ‘mdimport’ being in the top 3 or 4 or so, that’s good. OSX is rebuilding your Spotlight cache. Let it do this, and hopefully everything will return to normal. Now, if at any point your command errors out (“Can’t find index status, Can’t erase index” or similar, go to this:)

Now, if all that stuff didn’t work, so let’s fix it manually.
Step 1: Open System Preferences -> Sharing. At the top you will see the hostname of your computer. (Yes, this is the HOSTNAME.) Change this. To anything you want, for some reason Finder is tied to the hostname of your computer and if you change the hostname it magically fixes this problem.
Step 2: Back in your Terminal Window, descend to “/”. ($cd /)
Step 3: Erase your Spotlight cache. (Sounds dangerous doesn’t it? Don’t worry it’ll be rebuilt)
$sudo rm -rf /.Spotlight-V100/ (NOTICE THE DOT, it’s a hidden directory, you’d have to add a -a to your ‘ls’ to see it)

Now reboot. When your computer comes back up, your Spotlight cache will be rebuilt (may take awhile, it took about 3 hours on my Powermac (But it has 3 harddrives in it), then everything should be good to go.

Remember, changing that hostname is the magic step. Don’t forget it.

If this helps you, please leave a comment and let me know. If you have an suggestions to add to this, please leave a comment and let me know.

Thursday, April 19

Helping Users with Snort

Recently Paul Melson (PaulM) made some posting to the Snort-users group about a problem he was having with Snort. A couple of us helped him fix it, and now he’s off and running. Paul posted this to his blog:

“Finally, a big thank you to Jason, Joel, and Adam at Sourcefire for being so helpful with this issue. Yes, I'm a paying Sourcefire customer, but they probably didn't know that and it didn't matter to them. That's awesome.”

No Paul, we didn’t know. No Paul, we didn’t care. Yes Paul, we were glad to help. You see, it’s not just about making money. We make money. We’re a vendor. It’s about keeping the customer happy. Whether you are just a Snort user, or an actual customer. If you keep people happy, they like you. Sometimes a question is so stupid you want to beat your head against the wall (that’s in any profession), but it doesn’t mean we don’t want to help. If you have questions about Snort, write in! We’ll help!

Friday, March 2

Vista




Now, I have heard that Vista isn’t all it’s cracked up to be.

No surprise. I did play with it at CompUSA for a few minutes. It’s still Windows. All the GUI stuff you do Bill, can only make it better. But it’s still STINKOWS!!!

This ad from Apple says it best IMO:
apple-getamac-security_480x376.mov

Yeah it’s a bit exaggerated, but dude, annoying.

OSX does require you to put in a password, but to change SYSTEM stuff, and and things like that. That’s what I hear Vista is trying to be like, but I’ve heard it’s much more annoying. Anyone that has both want to weigh in on it?


Classic

Solaris Worm



Okay, so Sun made a whoopsie and committed some code to Login that apparently introduced a vulnerability that existed waaaay back in 1994. (Awesome)

Well it wasn’t long before someone coupled together a shell script and the exploit, packaged it up, and send it flying across the internet.

Now.

1) If you got infected, IMO, it’s your own dumb fault. If you are running Solaris (or ANYTHING) with a publicly facing open port 23 (telnet), you are nuts. Mmmkay?
2) If you didn’t patch or shutoff the vulnerable service when the vulnerability came out. You are just nuts..

Jose Nazario over at Arbor sent this into the Internet Storm Center: this article That outlines it.

If you look at the port graph over at the ISC: Check it out You can see the amount of port 23 scans have shot up.




The thing I want you to pay attention to, is the number of targets shot up to around 50K, but the sources were very very low. An isolated subnet in France. Hmmm..

Anyway, Sun made a “Worm removal script” here that you can use, but lets take a look at it.

The worm creates files in /var/adm and /var/spool/lp called “.profile” -- okay, makes sense.

/var/spool/lp/admins/.lp <-- okay.
/var/adm/sa/.adm <-- okay..

Heres the processes the worm spawns, and how to kill them:

/bin/pkill -9 -u lp 'lpshut|lpsystem|lpadmin|lpmove|lpusers|lpfilter|lpstat|lpd|lpsched|lpc'

/bin/pkill -9 -u adm 'devfsadmd|svcadm|cfgadm|kadmind|zoneadmd|sadm|sysadm|dladm|bootadm|routeadm|uadmin|acctadm|cryptoadm|inetadm|logadm|nlsadmin|sacadm|syseventadmd|ttyadmd|consadmd|metadevadm'

Have fun. While you are at it. get rid of Solaris.

Vista




Now, I have heard that Vista isn’t all it’s cracked up to be.

No surprise. I did play with it at CompUSA for a few minutes. It’s still Windows. All the GUI stuff you do Bill, can only make it better. But it’s still STINKOWS!!!

This ad from Apple says it best IMO:
apple-getamac-security_480x376.mov

Yeah it’s a bit exaggerated, but dude, annoying.

OSX does require you to put in a password, but to change SYSTEM stuff, and and things like that. That’s what I hear Vista is trying to be like, but I’ve heard it’s much more annoying. Anyone that has both want to weigh in on it?


Classic

Solaris Worm



Okay, so Sun made a whoopsie and committed some code to Login that apparently introduced a vulnerability that existed waaaay back in 1994. (Awesome)

Well it wasn’t long before someone coupled together a shell script and the exploit, packaged it up, and send it flying across the internet.

Now.

1) If you got infected, IMO, it’s your own dumb fault. If you are running Solaris (or ANYTHING) with a publicly facing open port 23 (telnet), you are nuts. Mmmkay?
2) If you didn’t patch or shutoff the vulnerable service when the vulnerability came out. You are just nuts..

Jose Nazario over at Arbor sent this into the Internet Storm Center: this article That outlines it.

If you look at the port graph over at the ISC: Check it out You can see the amount of port 23 scans have shot up.




The thing I want you to pay attention to, is the number of targets shot up to around 50K, but the sources were very very low. An isolated subnet in France. Hmmm..

Anyway, Sun made a “Worm removal script” here that you can use, but lets take a look at it.

The worm creates files in /var/adm and /var/spool/lp called “.profile” -- okay, makes sense.

/var/spool/lp/admins/.lp <-- okay.
/var/adm/sa/.adm <-- okay..

Heres the processes the worm spawns, and how to kill them:

/bin/pkill -9 -u lp 'lpshut|lpsystem|lpadmin|lpmove|lpusers|lpfilter|lpstat|lpd|lpsched|lpc'

/bin/pkill -9 -u adm 'devfsadmd|svcadm|cfgadm|kadmind|zoneadmd|sadm|sysadm|dladm|bootadm|routeadm|uadmin|acctadm|cryptoadm|inetadm|logadm|nlsadmin|sacadm|syseventadmd|ttyadmd|consadmd|metadevadm'

Have fun. While you are at it. get rid of Solaris.

Saturday, February 3

OSX, Vista, and Bill Gates




So, here I am, rocking my baby to sleep, and I read some thing that Bill Gates said about Vista vs. Mac security, and how people are breaking into OSX every day....

Here’s what the guy said.

"Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine."
Alrighty.. Surely he was referring to the Month of Apple Bugs, which, granted, had some hacks in it. Now, as any Mac zealot would (me), I said, wtf BILL! You have thrown the Gauntlet. Then I thought about it.

Was it irresponsible for him to say that? To say, bring it on? Endanger my customers, I dare you? Um.. Yup. But is Vista really that much more secure than OSX? Time will tell. Wait until the attacks and the vuln researchers get their fingers on it and autopsy the thing.

Then I read this blog. Which, on Slashdot I would have marked “Insightful”. This page is great. He explains, why, right now, Vista IS more secure than OSX. (yes, I said it). Too bad it took MSFT 5 years and billions of dollars to get it there. As a security professional, which one will I stick with? OSX.

OSX, Vista, and Bill Gates




So, here I am, rocking my baby to sleep, and I read some thing that Bill Gates said about Vista vs. Mac security, and how people are breaking into OSX every day....

Here’s what the guy said.

"Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine."
Alrighty.. Surely he was referring to the Month of Apple Bugs, which, granted, had some hacks in it. Now, as any Mac zealot would (me), I said, wtf BILL! You have thrown the Gauntlet. Then I thought about it.

Was it irresponsible for him to say that? To say, bring it on? Endanger my customers, I dare you? Um.. Yup. But is Vista really that much more secure than OSX? Time will tell. Wait until the attacks and the vuln researchers get their fingers on it and autopsy the thing.

Then I read this blog. Which, on Slashdot I would have marked “Insightful”. This page is great. He explains, why, right now, Vista IS more secure than OSX. (yes, I said it). Too bad it took MSFT 5 years and billions of dollars to get it there. As a security professional, which one will I stick with? OSX.

Thursday, December 28

The Snort Top 10

I work with SNORT®..... constantly. It's my job to do so. I've been using Snort for many years, I teach classes on how to configure it, I teach classes on how to write Snort rules. I've been using Snort and setting up Sourcefire and Snort devices on hundreds of different networks for years on end now.
 
I am frequently asked questions, many of the questions are the same things over and over again, and I always see the same mistakes being made when setting it up. So, i've compiled a list of the top ten mistakes and commonly misconfigured or overlooked things when configuring everyone's favorite IDS.
 
None of these override the necessity to read the Snort manual, however. The manual supersedes all Snort books, because as great as these books are, they can't keep up with the fast-paced updates at which Snort is updated. So here goes...
 
1. The Snort.conf file.
Almost all your options are set in this file. This file should be read line by line, from top to bottom, taking the time to fully understand what each one of the configuration options are. 90% of all the questions I get can be answered by just reviewing the documentation in the snort.conf file.
 
2. Variables.
At the very top of the Snort.conf file there are variables to be set. The very least of which is "HOME_NET". HOME_NET should ALWAYS be configured. Depending on the placement of your IDS, your HOME_NET is loosely interpreted as "whatever the Snort box is protecting". For instance, on my network, it's 192.168.1.0/24. The whole network is controlled by my router, and no other IP addresses should be on the network unless it has this range. If I *had* other IP's pop on my network, I would definitely not want them treated as mine! Common settings for HOME_NET may be your whole internal network range, such as any RFC 1918 addresses. Depending upon the placement of your sensor (such as at your border) you many want to have your public IP address space in your HOME_NET as well. Remember that only CIDR notation is accepted within the variable notation. 192.168.1.1:254 won't work, neither will 192.168.1.1-254. Only 192.168.1.0/24 will. Another big thing to note is your setting for EXTERNAL_NET. By default, EXTERNAL_NET is set to "any". "Any" includes your HOME_NET. In order to make Snort treat traffic that is NOT in your HOME_NET as EXTERNAL, you can set your EXTERNAL_NET to "!$HOME_NET". Which setting applies to you is dependent upon the placement of your sensor.
 
3. Frag3 preprocessor.
Snort is able to avoid many different types of evasions. One of the big ones that people think they can slip by on any IDS is through IP fragmentation, or using malicious overlapping and underlapping fragments in order to slip the payload past your IDS's, but have it reassembled correctly on the target.
 
Okay.. I realized I may have just thrown a big ball at you... Let's back up.
 
IP fragmentation is when Packet A on Network A is too big to go onto Network B. So the router on the Network A side splits Packet A into Packet A.1, A.2, A.3, and so on, so it's able to fit onto Network B. However, these smaller packets aren't put back together until they reach the final destination IP. Still with me so far right? Cool...
 
The problem with that is, different operating systems put fragmented packets back together in different orders depending on the type of operating system. (and you thought they were all the same!) Well, the problem with IDS's is, they have absolutely not idea what the Operating Systems are that they are protecting. Frag3 allows you to tell it. Now, without writing a book about the subject, you need to go into the docs/ directory that is enclosed with your Snort tarball and read the README on frag3. (As well as the accompanying section in the Snort manual.)
 
However, in order to FULLY understand what I am talking about, go read the whitepaper written by Judy Novak. (You have to register to download it) She's one of the authors of the SANS 503 IDS course, one of the designers behind frag3, and currently a Vulnerability Research Team (VRT) employee at Sourcefire.
 
4. HTTP Inspection preprocessor.
The most misunderstood preprocessor there is. This preprocessor analyzes, normalizes, and alerts on http traffic. The thing to remember is, it's SERVER based. It's meant to analyze traffic coming inbound to your http SERVERS. It basically has two settings, the "global default" setting, which you should set to the majority of your web servers. For instance, are most of your web servers IIS, on port 80?  Then you need to set that to the global setting.  If only some of your web servers are not IIS, or  only some of them are not on port 80,  then those need to be specified INDIVIDUALLY, by IP! Does that mean you will have to create a separate line for each of your "non-standard" web servers? Yes! That's the way it's SUPPOSED to work!
 
5. Portscan preprocessor.
Also very mis-understood piece of code. You need to read the README for the "sfportscan" preprocessor in the docs/ directory. There is no better explanation on how to configure this preprocessor.
 
6. The rest of the preprocessors, to include the new "dynamic" preprocessors.
All of the preprocessors have configuration lines. Each need to be configured to the networks you are protecting with Snort. Review the documentation for each of them extensively. All the documentation is well written, and is written with the user in mind.
 
7. Rules.
The Rules in Snort are key. At the bottom of the Snort.conf you will see a bunch of "include" lines. "include $RULE_PATH/web-iis.rules" for example. This line will call the rules file web-iis.rules and load it in at runtime. Alot of people ask "what is the best ruleset to run?" Well, by far the first and foremost ruleset to run the VRT ruleset available after registration here. However, does this mean that you need to run every rule in that ruleset? NO! Take a look at the categories.. pop3.rules, imap.rules, oracle.rules, web-coldfusion.rules, pop2.rules, mysql.rules.. etc... Do you run these services on your network? Do you run pop3? Do you run pop2? Do you run imap? No? Then turn the rule category off! There is no sense in running rules that have no application to your network! All you are doing is potentially creating more work for yourself through false positives, as well as making the Snort engine work harder then it needs to.
 
"But I hear there are other rulesets besides the VRT set!" YES! There are. There are basically two. The BleedingThreats set available at www.bleedingthreats.com and the Community ruleset. Each of these rulesets is contributed to regularly by YOU the Snort community and each have their own pros and cons. Should you run all three rulesets? Sure! However, you need to go through each rule file, and turn on/off what you are not interested in or what does not apply to your network. For example, do you have Vertias on your network? No? Then go into exploit.rules and shut off the Veritas rules.
 
8. Output.
Snort can output to syslog, to pcap format (default), to a database, or lastly, to Unified. The "official" recommendation is to unified. The unified file format is the fastest output format coming out of the backend of Snort. Especially when you are trying to output to database! When Snort has to output to a database directly, it has to perform an INSERT into the db... doing so is CPU intensive. Do you want your IDS to be an IDS? Or a database insertion tool?  So use Unified! Well, the problem with unified is, you need something that reads unified file format and outputs it into the db, or tcpdump file format you want....
 
9. Barnyard (or FLoP)
Barnyard reads the unified file format and inserts what it finds into a db, or outputs into tcpdump file format. FLoP is another tool that also reads Snort's output (albeit in a different method) and does what you want with it. Both are excellent tools and both need to be checked out and use the one that's appropriate to you.
 
10. Rule updates.
However you choose to update your rules is up to you, I recommend Oinkmaster. Nice perl proggie to keep your rules up to date. Just don't forget to register on Snort.org and get your oinkmaster code if you wish to download the VRT registered user set.
 
Notice that I didn't put a recommendation for any type of Snort log reviewing tool. BASE, Sguil, Placid, etc.. all have their merits and you will want to check out the one that is most appropriate to your situation. However, I do have one recommendation that I will make here... and it's turning into more of a "RULE" now. Do NOT use ACID. Don't get me wrong, ACID was great for it's day, however, with over 200+ bug fixes, feature implementations, and the fact that ACID hasn't been updated in.. going on 4 years now... go with BASE if all you are looking for is an Alert browser. BASE works with your existing ACID db, and is very easy to upgrade to.
 
So there you go. I hope this helps a bit to get you started down the correct path of tuning Snort. Don't forget to hit the mailing list archives, post to the mailing lists with any questions, look for your local Snort User Group, visit the Snort Forums, or even write into us here at the ISC (several of us use Snort constantly, not just me).. or drop into irc.freenode.net into #snort and say hello! Thanks!
 
Stay tuned for another article on Snort in the future.. If you have suggestions about what I should write about as far as Snort goes, feel free to write in!
 
/** Joel Esler **/
 
Sourcefire and Snort are registered trademarks of Sourcefire.

Thursday, December 21

Are CAC (Common Access Cards) worth it?

A buddy of mine Richard Bejtlich, a known security blogger and consultant, had this article on his blog... I made a big long comment about it.. displayed below, and linked above...

--- begin ---

Yes. The CAC is used for signing on, email signing and encryption, web authentication, basically anything that can be done, or is done with a certificate.

It's only being used in NIPR (Unclassified) systems. It has a magnetic strip on the back that is blank, and can be coded for swipe doors at whatever location you are currently working at.. (problem is, most DOD facilities have proximity cards).

Could this be implemented in a commercial setting? Yes. But at what cost? What what expense? What do you gain out of it? When I worked for DOD, all I got out of the deal was a headache... implementation, it became our ID, which.. only SOME people accepted (like, the gate guards on post wanted our Drivers License sometimes -- grrrr) going to get a new one every three years, using it for sign-on, using it to get in the building. Here's the kicker. Say you left it in your computer at night, your computer would screensaver lock after a while, no problem.. but you couldn't get back in the building the next day!

Annoying is the key. I never liked it. The Email signing and authentication never worked across all platforms with ease. Doesn't work with ALL email clients. (and IMO, trying to say something like "well everyone MUST use OUTLOOK" is not an answer, it's a 'way out'.) Ours didn't work with sign on to the network. The only feature about the CAC that I DID like, is when I walked away from my computer, I took the CAC out of the reader, and viola... my computer locked.

That was about it. Now. You know whats kinda cool (but involves us going back to terminals), is Sun's (yes Sun Microsystems, as much as I hate Sun...) card that you can carry from machine to machine and wherever you plug it in.. you can call up YOUR desktop. That's a descent idea. However, no one likes dummy terminals. I digress.

Could it be done? Yes. Is it worth it? No. Not in my opinion.

Are CAC (Common Access Cards) worth it?

A buddy of mine Richard Bejtlich, a known security blogger and consultant, had this article on his blog... I made a big long comment about it.. displayed below, and linked above...

--- begin ---

Yes. The CAC is used for signing on, email signing and encryption, web authentication, basically anything that can be done, or is done with a certificate.

It's only being used in NIPR (Unclassified) systems. It has a magnetic strip on the back that is blank, and can be coded for swipe doors at whatever location you are currently working at.. (problem is, most DOD facilities have proximity cards).

Could this be implemented in a commercial setting? Yes. But at what cost? What what expense? What do you gain out of it? When I worked for DOD, all I got out of the deal was a headache... implementation, it became our ID, which.. only SOME people accepted (like, the gate guards on post wanted our Drivers License sometimes -- grrrr) going to get a new one every three years, using it for sign-on, using it to get in the building. Here's the kicker. Say you left it in your computer at night, your computer would screensaver lock after a while, no problem.. but you couldn't get back in the building the next day!

Annoying is the key. I never liked it. The Email signing and authentication never worked across all platforms with ease. Doesn't work with ALL email clients. (and IMO, trying to say something like "well everyone MUST use OUTLOOK" is not an answer, it's a 'way out'.) Ours didn't work with sign on to the network. The only feature about the CAC that I DID like, is when I walked away from my computer, I took the CAC out of the reader, and viola... my computer locked.

That was about it. Now. You know whats kinda cool (but involves us going back to terminals), is Sun's (yes Sun Microsystems, as much as I hate Sun...) card that you can carry from machine to machine and wherever you plug it in.. you can call up YOUR desktop. That's a descent idea. However, no one likes dummy terminals. I digress.

Could it be done? Yes. Is it worth it? No. Not in my opinion.

Tuesday, December 19

A Question for my readers

Please describe to me.. At what point does security become an operational burden?

When too many passwords, authentication mechanisms, log-on tokens, segmentation..etc... mount up.. what what point do you just say "hey, you know, this sucks!"

Please leave comments.

A Question for my readers

Please describe to me.. At what point does security become an operational burden?

When too many passwords, authentication mechanisms, log-on tokens, segmentation..etc... mount up.. what what point do you just say "hey, you know, this sucks!"

Please leave comments.

Monday, December 18

Christmas, and the holiday spirit, and Internet security

Recently, since we've all been shopping, out there paying attention to gifts, what we are going to get, and what we aren't going to get. An attack has been going on. Apparently, against my web server.

I review my weblogs (I review all my logs) on a weekly basis. Because really, what's the point in having logs if you're not going to look at them? A log that isn't looked at is a pointless log. You might as well shut off syslog if you aren't going to look at the logs. But I digress.

I review my weblogs. I have mod_security installed on my apache webserver here, so through my custom mod_security rules, I am provided with audit_log in my logging directory.

I usually get about 200 to 300 entries a week in that file. All denied.

Last week that number jumped to almost 9000. As of this morning (my logs roll over on Sunday), I had over 3000.

As I am on my blackberry I don't have a copy of the logs, so I'll post a sample entry later.

But the string I see a lot is "x-aaaaaaaaaaa" in the header.

Anyone else seeing these?

Friday, December 15

Two words for Delta....

In reference to your Crown Rooms, take a note from your partner Continental...

FREE INTERNET

who makes up these rules?

On some flights, you can't have your phones with the wireless turned on.
Then some you can't have them on at all.
On ASA you can't fly with the windows shades down, but on delta you can.
Today we were told that laptop computers had to be completely off, and NOT in the standby mode.

Why can't we just have one set of rules? Everyone the same. The flight attendants all having the same info, so we don't have flight attendants just making stuff up arbitarily?

FAA -- is this so hard?

Two words for Delta....

In reference to your Crown Rooms, take a note from your partner Continental...

FREE INTERNET

who makes up these rules?

On some flights, you can't have your phones with the wireless turned on.
Then some you can't have them on at all.
On ASA you can't fly with the windows shades down, but on delta you can.
Today we were told that laptop computers had to be completely off, and NOT in the standby mode.

Why can't we just have one set of rules? Everyone the same. The flight attendants all having the same info, so we don't have flight attendants just making stuff up arbitarily?

FAA -- is this so hard?

Monday, December 4

Excellent Patent Article

This article is an excellent article on patents concerning Apple and the GUI and stuff. Really interesting stuff.

Excellent Patent Article

This article is an excellent article on patents concerning Apple and the GUI and stuff. Really interesting stuff.

Friday, December 1

Apple needs to go to a subscription model? Pullleeezz

Hey dude, Apple owns 75%+ Market share. I am pretty sure that they know what the hell they are doing.

Apple go to a subscription model?

Apple needs to go to a subscription model? Pullleeezz

Hey dude, Apple owns 75%+ Market share. I am pretty sure that they know what the hell they are doing.

Apple go to a subscription model?

Tuesday, November 28

Okay New rule

Okay, New (old) rule.

When responding to a post on a mailing list, and you want to start a new thread, don't reply to someone else's thread and change the subject. Make a new email.

It messes up my threading in mutt and Mail.

Okay New rule

Okay, New (old) rule.

When responding to a post on a mailing list, and you want to start a new thread, don't reply to someone else's thread and change the subject. Make a new email.

It messes up my threading in mutt and Mail.

Monday, November 20

Plane captains in the cockpit

Why does every captain of a palne think they are a tour guide? "If you look out the right side of the plane"

What is a "seat area"? "Look around your immediate seat area for any items you may have brought on board.". What the hell is a seat area? And 'may' have brought on board?

(Yes I know that's part of a Carlin bit, but it's true!)

I hate it when people (flight attendants, gate agents, whatever) treat me like I am stupid, AFTER they thank me for being a Platinum member. Obviously if I am a platinum member I fly a lot, and obviously know that I have to take my shoes off to go through security (or something like that).

Crown rooms that are BEFORE security? Now what kind of sense does that even make?

Ah... The frustrations of travel.

-sent from 30,000 feet.

Plane captains in the cockpit

Why does every captain of a palne think they are a tour guide? "If you look out the right side of the plane"

What is a "seat area"? "Look around your immediate seat area for any items you may have brought on board.". What the hell is a seat area? And 'may' have brought on board?

(Yes I know that's part of a Carlin bit, but it's true!)

I hate it when people (flight attendants, gate agents, whatever) treat me like I am stupid, AFTER they thank me for being a Platinum member. Obviously if I am a platinum member I fly a lot, and obviously know that I have to take my shoes off to go through security (or something like that).

Crown rooms that are BEFORE security? Now what kind of sense does that even make?

Ah... The frustrations of travel.

-sent from 30,000 feet.

Wednesday, November 15

Smartphone switching

Okay, so for about a year and a half now, I've been using the Treo 650. It's a nice phone, except that:

A) The battery sucks.
B) Email SUCKS
C) Useability sucks

So recently, I switched to the Blackberry 8700. YES. now THIS is a nice phone. I've never used a Blackberry before, and always looked down on those who do as being "Crackberry" addicts. But now I see why. This is a nice damn phone. Battery life is excellent (lasts about 3 days while using Cell phone and email regularily), bluetooth, and the EMAIL!! OOOOH the email!!! Push technology is so freaking great.

Things I miss:

The IR port.
The extensive amount of Applications for the Palm Platform (although I haven't found a program yet that I haven't found a blackberry equivalent for)
The ability for it to charge from my laptop (Yes, I know some people have done this with their Palm [points to Roesch], but I didn't so I suck okay?)
Auto Sync.


Blackberry 10, Palm 5. 4th Quarter.

Idiot commenting

Okay, so I read ALOT of news, blogs, and websites. As does everyone now adays I suspect, we all read our share of blogs.

So why, when I read stuff like.. Digg, like Slashdot, like the Crazy Apple Rumors site, and any number of other sites that I frequent on a repetative basis, do these damn morons who make the first post, have to announce to the world that they did so?

We CAN SEE IT'S YOUR FIRST POST PEOPLE, QUIT TELLING US. You're killing me.

1. Frist post!! OMGWTF!!!!111!!ponies!!!

Go choke.

Idiot commenting

Okay, so I read ALOT of news, blogs, and websites. As does everyone now adays I suspect, we all read our share of blogs.

So why, when I read stuff like.. Digg, like Slashdot, like the Crazy Apple Rumors site, and any number of other sites that I frequent on a repetative basis, do these damn morons who make the first post, have to announce to the world that they did so?

We CAN SEE IT'S YOUR FIRST POST PEOPLE, QUIT TELLING US. You're killing me.

1. Frist post!! OMGWTF!!!!111!!ponies!!!

Go choke.

Dvorak says something right

John Dvorak finally said something I agree with. Zune will be a flop.

Reading the first sentence of this article is correct as hell.
"If anything is doomed to failure, it is the Microsoft Zune" Go John. (at least on this article)

Tuesday, November 14

San Francisco

Alrighty, so I'm here in San Francisco. Again.

I like this town, not as much as I like Chicago, but San Fran is cool. I'm staying in Chinatown at the Hilton Financial District. I highly recommend this hotel if you are a Hilton Gold or Diamond member. (and you achieve Executive level floor). I don't know what the regular rooms are like, but the desk in this one is bad ass.

Anyway, so I am teaching this Sourcefire 3D class for my company. I really like teaching. Allows me to interact and share my thoughts on topics with several people. I like being able to get and give opinions about topics with me. Lots of fun.

The new Snort book is coming up. Should be soon. I think everything is being finalized getting ready for print. Go pick up a copy.

Dvorak says something right

John Dvorak finally said something I agree with. Zune will be a flop.

Reading the first sentence of this article is correct as hell.
"If anything is doomed to failure, it is the Microsoft Zune" Go John. (at least on this article)

Thursday, November 9

Delta

Following up on my post to Delta: I had someone email me and ask me how it went...

1. They refunded my ticket from ATL to AGS
2. They also gave me 10,000 miles for my problems.

However, I made Platinum Medallion in the meantime, so I don't know if they did all that stuff because I am Platinum now, or were they just being nice.

We'll see how things are different for Platinum. As much as I have flown over the past many years, I have never made Platinum, (I could have done it a couple times, but could never dedicate to one airline). I've have flown (almost) exclusively Delta in the past 9 months, and I have achieved over 85K miles in those 9 months.

I'll probably break 100K by the end of the year.

All I know is, I have a flight booked for my butt to fly to San Francisco on Monday, and I already have a First Class seat. (Delta upgrades Medallion members based on status, ticket fare, standbys...etc.. there's a bunch of criteria.) But I do know that I have the last seat in First Class, which means, when the 3 day marker rolls around for Gold members (Saturday), no Gold members will get upgraded.

So I guess my Platinum Status is paying off already. We'll see if I get my upgrade on my return flight. So for now, has saved face.

(Image copyright Delta)

Delta

Following up on my post to Delta: I had someone email me and ask me how it went...

1. They refunded my ticket from ATL to AGS
2. They also gave me 10,000 miles for my problems.

However, I made Platinum Medallion in the meantime, so I don't know if they did all that stuff because I am Platinum now, or were they just being nice.

We'll see how things are different for Platinum. As much as I have flown over the past many years, I have never made Platinum, (I could have done it a couple times, but could never dedicate to one airline). I've have flown (almost) exclusively Delta in the past 9 months, and I have achieved over 85K miles in those 9 months.

I'll probably break 100K by the end of the year.

All I know is, I have a flight booked for my butt to fly to San Francisco on Monday, and I already have a First Class seat. (Delta upgrades Medallion members based on status, ticket fare, standbys...etc.. there's a bunch of criteria.) But I do know that I have the last seat in First Class, which means, when the 3 day marker rolls around for Gold members (Saturday), no Gold members will get upgraded.

So I guess my Platinum Status is paying off already. We'll see if I get my upgrade on my return flight. So for now, has saved face.

(Image copyright Delta)

Wednesday, November 8

Baby Pictures

So, the Wife and I go and get 3D Ultrasound pictures of our baby done. It's pretty cool I think. They are hard to see IMO, but click on them to make them bigger.



Here's a picture of the baby sleeping, kinda curled up in there.

Baby Pictures

So, the Wife and I go and get 3D Ultrasound pictures of our baby done. It's pretty cool I think. They are hard to see IMO, but click on them to make them bigger.



Here's a picture of the baby sleeping, kinda curled up in there.

Monday, November 6

An OSX Background

I like Wallpapers. I'm not really a fan of any of the OSX ones that are out there, so I found one that was sort of what I wanted, ran it through a bit of Photoshop, and out popped this:

I tend to like it (i'm biased), feel free to use:

An OSX Background

I like Wallpapers. I'm not really a fan of any of the OSX ones that are out there, so I found one that was sort of what I wanted, ran it through a bit of Photoshop, and out popped this:

I tend to like it (i'm biased), feel free to use:

Sunday, November 5

DCR-SR40 on OSX

How to get your Sony Handycam DCR-SR40 to work on OSX:

When you purchase the DCR-SR40 Sony Handycam, it has a link in the instruction book on where to go to purchase software to be able to use the camera with OSX. It is NOT free, and second of all, the software is absolutely horrible.

Do NOT for one second think that you can use firewire with this camera either. Nope. Also, do not assume that this camera will work with iMovie or iDVD, because it won't. Why? Well, first of all it's USB, (OSX needs firewire with Digital Video Cameras, even HDD based ones)

It won't work, it won't work, it won't work. Don't buy the crappy software suggested in the manual.

The problem is, the video that is stored on the camera is in Mpeg-2. Well. That sucks.

Steps to get it to work:

1. Plug the Camera's dock into the Mac.
2. Plug the Camera's dock into the electricty.
3. Record something
4. Plug the camera into the dock.
5. Turn the camera on, and put it in VCR mode (the bottom LCD light)
6. Press the "Burn to DVD" button on the Dock.

This will mount the Video Camera into OSX.

7. Open the "NO_NAME" drive, present on your desktop.
8. Navigate through the folders until you find the mp2 files that are named something like "M2U00001.MPG".
9. Drag and drop this file to your desktop (you can erase it off the camera if you want)

Quicktime will NOT play this file, you have to up convert it mp4

10. Download and install "ffmpegX", a free program, and all the tools that go with it. (You will need mplayer)
11. Drop "M2U00001.MPG" file into ffmpegX, and then select what file type to convert it to on the right (I suggest 2-pass option for H.264)
12. Click "Encode"
13. Whenever later (a long time if you have a slow puter...) it will spit out a file, that file you can do whatever you want with (into iMovie, iDVD whatever)

OR!!!!

Return the camera, pay the restocking fee, and go buy the Panasonic PV-GS300.

I suggest the latter.

DCR-SR40 on OSX

How to get your Sony Handycam DCR-SR40 to work on OSX:

When you purchase the DCR-SR40 Sony Handycam, it has a link in the instruction book on where to go to purchase software to be able to use the camera with OSX. It is NOT free, and second of all, the software is absolutely horrible.

Do NOT for one second think that you can use firewire with this camera either. Nope. Also, do not assume that this camera will work with iMovie or iDVD, because it won't. Why? Well, first of all it's USB, (OSX needs firewire with Digital Video Cameras, even HDD based ones)

It won't work, it won't work, it won't work. Don't buy the crappy software suggested in the manual.

The problem is, the video that is stored on the camera is in Mpeg-2. Well. That sucks.

Steps to get it to work:

1. Plug the Camera's dock into the Mac.
2. Plug the Camera's dock into the electricty.
3. Record something
4. Plug the camera into the dock.
5. Turn the camera on, and put it in VCR mode (the bottom LCD light)
6. Press the "Burn to DVD" button on the Dock.

This will mount the Video Camera into OSX.

7. Open the "NO_NAME" drive, present on your desktop.
8. Navigate through the folders until you find the mp2 files that are named something like "M2U00001.MPG".
9. Drag and drop this file to your desktop (you can erase it off the camera if you want)

Quicktime will NOT play this file, you have to up convert it mp4

10. Download and install "ffmpegX", a free program, and all the tools that go with it. (You will need mplayer)
11. Drop "M2U00001.MPG" file into ffmpegX, and then select what file type to convert it to on the right (I suggest 2-pass option for H.264)
12. Click "Encode"
13. Whenever later (a long time if you have a slow puter...) it will spit out a file, that file you can do whatever you want with (into iMovie, iDVD whatever)

OR!!!!

Return the camera, pay the restocking fee, and go buy the Panasonic PV-GS300.

I suggest the latter.

Thursday, October 26

San Diego, CA

So here I am. Tired as hell, in San Diego. I have to fly back to Georgia tomorrow. Then fly to Pheonix on Friday.



I travel too much.

Picture of my wife and I in San Antonio




My boss took this picture of my wife and I on the one of the tour boats that goes around the Riverwalk in San Antonio, TX. Good times.

"But Joel, you went to San Antonio, did you take a picture of The Alamo?"

yes.

Picture of me teaching



One of my guys in my class I was teaching in Rhode Island not too long ago took this snap shot. The picture is of me assisting the screen in showing all the words. You can see the projection over running the right hand side of the screen. Heh. oh well.

Wednesday, October 25

Apple Store visits

Well I added a couple more to the Apple Store Visits list.

See for yourself

San Diego, CA

So here I am. Tired as hell, in San Diego. I have to fly back to Georgia tomorrow. Then fly to Pheonix on Friday.



I travel too much.

Picture of my wife and I in San Antonio




My boss took this picture of my wife and I on the one of the tour boats that goes around the Riverwalk in San Antonio, TX. Good times.

"But Joel, you went to San Antonio, did you take a picture of The Alamo?"

yes.

Apple Store visits

Well I added a couple more to the Apple Store Visits list.

See for yourself

Fun in Texas



As if I needed another example of why I don't live in Texas, my wife's uncle sent me these pictures of a snake inside of the motor box that controls their boat lifter. (Raises the boat up and down into the water)

Avis is stupid



I was in the line at Avis in ATL recently. I saw this sign and thought it was funny and yet dumb. Who are the advertising/marketing people that should be shoved off a cliff for this one?

Tuesday, October 24

Fun in Texas



As if I needed another example of why I don't live in Texas, my wife's uncle sent me these pictures of a snake inside of the motor box that controls their boat lifter. (Raises the boat up and down into the water)

Avis is stupid



I was in the line at Avis in ATL recently. I saw this sign and thought it was funny and yet dumb. Who are the advertising/marketing people that should be shoved off a cliff for this one?

The Macbook Pro finally gets updated

Link It's about time.

YEAH!

The Macbook Pro finally gets updated

Link It's about time.

YEAH!

American Airlines

I wound up flying First Class in American Airlines today. Let me just compliment AA. Best two flights I have ever had. Aside from being late out of ATL (which was ATL's fault, I am sure), I sat in first class, I got a meal, (vegetable pizza and a salad. it was good!), and aside from the lady who had a panic attack on the plane and had to be given oxygen.

American Airlines rox. I'd fly American Airlines if I could everytime if their service was that good every time.

Monday, October 23

American Airlines

I wound up flying First Class in American Airlines today. Let me just compliment AA. Best two flights I have ever had. Aside from being late out of ATL (which was ATL's fault, I am sure), I sat in first class, I got a meal, (vegetable pizza and a salad. it was good!), and aside from the lady who had a panic attack on the plane and had to be given oxygen.

American Airlines rox. I'd fly American Airlines if I could everytime if their service was that good every time.

More Airport fun

So, I get to the airport today, and they cancel my flight when it was almost here.

Quick Story: I am currently sitting in the Augusta, GA (AGS) airport. I was booked on flight 4293 out of Augusta to Atlanta. They apparently cancelled the connecting flight from ATL to AGS, thusly canceling the return 4293.

Since flying at 2 was going to miss my connecting flight on flight 397 from ATL to SAN. (Where I had a first class upgrade) So Delta rebooked me through American Airlines. (Where i am sitting in coach!) and I wind up getting to SAN 4 hours later.

Just another late flight where the customers get screwed going from ATL to AGS or AGS to ATL. How can ASA possibly be against the customer (stay in business doing this to their customers) this much?

Delta's response

Delta wrote me back. I believe this to be an UNACCEPTABLE response.


Dear Mr. Esler,

Thank you for your e-mail and for sharing your disappointing travel
experience with us. We welcome your comments as they assist us in the
continuous evaluation of our performance.

We regret you were inconvenienced because of a missed flight connection.
Delaying a flight for a confirmed passenger is a difficult situation for
the airlines. In the past our policy was to wait for passengers whenever
possible even at the expense of on-time performance. Now, our customers
tell us that being on time is a high priority, and we have changed our
practices to better meet these expectations.

We expect our people to do everything they can to help customers
transfer between flights; however, they have been instructed not to make
guarantees about connections. The operations supervisors in each city
are responsible for the final decision to delay a flight. They have
access to all necessary information, such as flight times, the number of
customers already on board, and the availability of alternate flights.
Nevertheless, we regret your inconvenience and and we will continue to
make efforts to improve in this area. Customer service is very
important to us, and we are working hard to transform our company.

We have reviewed your e-ticket, xxxxxxxxxxxx, and have determined an
adjustment is due for the unflown segment. A copy of your e-mail has
been forwarded to our Refunds Department for processing. As you paid
with a credit card, the adjustment will appear on your statement within
1-2 billing cycles.

Please accept our apology for the unfavorable impression you received in
this instance. We appreciate your selection of Delta and will always
consider it a privilege to be of service.

Delta sucks

Okay. I could write this big long post about how Delta sucks. But I already did. Here an email I wrote to Delta:

------------

Yesterday, October 21, 2006, I was traveling from Denver, CO to Augusta,GA and had a connection in Atlanta Hartsfield-Jackson Airport. My flight from Denver was approximately 7 minutes late in arrival (the plane had to be de-iced in DEN), so I had hustle from one gate to the next. When I got to the original gate, I was notified of a gate change of just a few more gates down the concourse.

When I arrived at the gate at 2:55 p.m., I was told by the gate attendant that the flight had already left. I was disappointed to hear that the flight was already packed up and gone, yet the scheduled departure was not until 3:07 p.m. What bothered me the most is that I could still see the baggage crew loading the plane and the gate attendants were still printing out the passenger manifest.

I contacted the customer service department for Medallion members and expressed my concern with one of the Delta representatives. She informed me that according to gate check-in rules, a plane is allowed to leave up to 15 minutes prior to scheduled departure if everyone is accounted for. However, they are aware of those who have connections and should have allowed for more time. Apparently, that was not the case and they closed out early. The customer representative was quite confused as she looked further and found that flight 4103 was not even a full flight when they left.

After doing additional research I found that DL flight 4103 never pushed back from the gate until 3:30 p.m (23 minutes later than scheduled departure) and took off at 3:40. They arrived in Augusta, GA at 4:16 p.m.

I am a Delta Gold Medallion member and will achieve Platinum status by the end of this year. Unfortunately, I have not yet seen many benefits with Delta in being such a dedicated member. Flying out of Augusta, GA where my flights almost always originate, I have a choice of two airlines.
Depending on cost of flight and convenience I can pick from Delta or US Air/United.
Since I started to achieve Medallion status, I almost always pick Delta, spending well over 40K a year with your airline, for just business travel. Whether my employer pays for my travel or it is a personal purchase, this kind of service is unacceptable.

Please consider my frustration and address such issues with the Delta staff and crew.

Thank you!

-------

More Airport fun

So, I get to the airport today, and they cancel my flight when it was almost here.

Quick Story: I am currently sitting in the Augusta, GA (AGS) airport. I was booked on flight 4293 out of Augusta to Atlanta. They apparently cancelled the connecting flight from ATL to AGS, thusly canceling the return 4293.

Since flying at 2 was going to miss my connecting flight on flight 397 from ATL to SAN. (Where I had a first class upgrade) So Delta rebooked me through American Airlines. (Where i am sitting in coach!) and I wind up getting to SAN 4 hours later.

Just another late flight where the customers get screwed going from ATL to AGS or AGS to ATL. How can ASA possibly be against the customer (stay in business doing this to their customers) this much?

Delta's response

Delta wrote me back. I believe this to be an UNACCEPTABLE response.


Dear Mr. Esler,

Thank you for your e-mail and for sharing your disappointing travel
experience with us. We welcome your comments as they assist us in the
continuous evaluation of our performance.

We regret you were inconvenienced because of a missed flight connection.
Delaying a flight for a confirmed passenger is a difficult situation for
the airlines. In the past our policy was to wait for passengers whenever
possible even at the expense of on-time performance. Now, our customers
tell us that being on time is a high priority, and we have changed our
practices to better meet these expectations.

We expect our people to do everything they can to help customers
transfer between flights; however, they have been instructed not to make
guarantees about connections. The operations supervisors in each city
are responsible for the final decision to delay a flight. They have
access to all necessary information, such as flight times, the number of
customers already on board, and the availability of alternate flights.
Nevertheless, we regret your inconvenience and and we will continue to
make efforts to improve in this area. Customer service is very
important to us, and we are working hard to transform our company.

We have reviewed your e-ticket, xxxxxxxxxxxx, and have determined an
adjustment is due for the unflown segment. A copy of your e-mail has
been forwarded to our Refunds Department for processing. As you paid
with a credit card, the adjustment will appear on your statement within
1-2 billing cycles.

Please accept our apology for the unfavorable impression you received in
this instance. We appreciate your selection of Delta and will always
consider it a privilege to be of service.

Delta sucks

Okay. I could write this big long post about how Delta sucks. But I already did. Here an email I wrote to Delta:

------------

Yesterday, October 21, 2006, I was traveling from Denver, CO to Augusta,GA and had a connection in Atlanta Hartsfield-Jackson Airport. My flight from Denver was approximately 7 minutes late in arrival (the plane had to be de-iced in DEN), so I had hustle from one gate to the next. When I got to the original gate, I was notified of a gate change of just a few more gates down the concourse.

When I arrived at the gate at 2:55 p.m., I was told by the gate attendant that the flight had already left. I was disappointed to hear that the flight was already packed up and gone, yet the scheduled departure was not until 3:07 p.m. What bothered me the most is that I could still see the baggage crew loading the plane and the gate attendants were still printing out the passenger manifest.

I contacted the customer service department for Medallion members and expressed my concern with one of the Delta representatives. She informed me that according to gate check-in rules, a plane is allowed to leave up to 15 minutes prior to scheduled departure if everyone is accounted for. However, they are aware of those who have connections and should have allowed for more time. Apparently, that was not the case and they closed out early. The customer representative was quite confused as she looked further and found that flight 4103 was not even a full flight when they left.

After doing additional research I found that DL flight 4103 never pushed back from the gate until 3:30 p.m (23 minutes later than scheduled departure) and took off at 3:40. They arrived in Augusta, GA at 4:16 p.m.

I am a Delta Gold Medallion member and will achieve Platinum status by the end of this year. Unfortunately, I have not yet seen many benefits with Delta in being such a dedicated member. Flying out of Augusta, GA where my flights almost always originate, I have a choice of two airlines.
Depending on cost of flight and convenience I can pick from Delta or US Air/United.
Since I started to achieve Medallion status, I almost always pick Delta, spending well over 40K a year with your airline, for just business travel. Whether my employer pays for my travel or it is a personal purchase, this kind of service is unacceptable.

Please consider my frustration and address such issues with the Delta staff and crew.

Thank you!

-------

Friday, October 20

Blogging Amount

Obviously lately, I haven't been blogging alot. I've been on the road straight now for about 6 weeks. I'm a bit tired, and don't get the chance to blog as much as I wish I could.

I will be off in a week or so, then I might be able to catch up a bit with all the stuff going on. In the meantime, enjoy Star Wars parodies.

Blogging Amount

Obviously lately, I haven't been blogging alot. I've been on the road straight now for about 6 weeks. I'm a bit tired, and don't get the chance to blog as much as I wish I could.

I will be off in a week or so, then I might be able to catch up a bit with all the stuff going on. In the meantime, enjoy Star Wars parodies.

Monday, October 9

IE7 and how much it sucks

I wrote this article on isc.sans.org... i got lots of MS zealot feedback saying that I was bashing.

---
Thanks to one of our readers that wrote in to tell us that IE7, will be released this month via Automatic Update according to Microsoft's "IEBlog".

Unfortunately, it's still based on a similar code base, and will still hold the majority of market share. So, this brings me to the point of the article which I had originally intended..

My advice? Diversify. Use other browsers. I use Safari, Firefox, and Opera. I own zero Windows based computers, but I have access to thousands. I suggest you out there in 'reader land' switch to something else. Unless we see empirical evidence that IE7 is vastly more secure and superior.. it will wind up like its predecessors.

Yes, I know that on some corporate environments, its impossible to switch. There are applications that are dependent on IE. But I blame the Application Developers. Code to more open standards, try not to use ActiveX controls. Other browsers don't use them, and they work fine. I had a reader write in and say that in their environment (healthcare), they are dependent on IE. My wife works in healthcare, so I feel your pain. I know, I know, its unfortunate, sometimes corporate rollouts of Firefox..et all.. are not possible, however, give it a shot.

I used to work in an environment where IE was necessary for a couple of things. So, we used IE for those two things, and Firefox for the rest. My whole diary entry can be summed up in one line: "Where you don't HAVE to use IE, don't."

II have received alot of feedback since I wrote the initial article. Most people don't like the fact that I am saying that IE's security is lacking. It's fact. Everything has vulnerabilities. Every OS, every product, every browser. I have been cited, publicly stating that if Apple was 95% of market share and Microsoft was 5%, who is to say that the roles wouldn't be reversed. Hackers target the 70% of the browser market (IE) because that's the MAJORITY of what is out there. However, if the roles were reversed, who is to say that it wouldn't be backwards? Who is to say that there wouldn't be hundreds of thousands of vulnerabilities for Apple out there? Yes, I think that Apple is inherently more secure, (I use macs), but that's not to say that if the tables weren't turned we wouldn't have a different result.

In other Microsoft News:
Microsoft rewards Adware programmer with MVP status. Link here

Reader Dan writes in to tell us:
"You may also want to note that Firefox even has a plug-in available to open certain links in IE. This makes it even easier to follow your advice of only using IE when you absolutely must." -- https://addons.mozilla.org/firefox/35/

Update #1
Mentioned native apps.

Update #2
Mentioned Feedback

Update #3
Clarifying the article for it's original intention: Diversification.

Update #4
Added MS MVP article

Updated #5
Added Firefox plugin

----

I still say I'm right.

SANS article

I wrote an article about my recent trip to Vegas over at isc.sans.org. Since I am too lazy to copy and paste it, or retype it.. here is a direct link. Go read it here.

SANS article

I wrote an article about my recent trip to Vegas over at isc.sans.org. Since I am too lazy to copy and paste it, or retype it.. here is a direct link. Go read it here.

Tuesday, October 3

Marty Roesch strikes again

Marty made a post on his blog here about the new weapon on the war on terror.

A Ziploc Baggie.

Hilarious

Friday, September 29

tf green airport providence.

more about this later, because I am on a plane. but the providence ri airport. tf green. is THE WORST airport on Earth.

tf green airport providence.

more about this later, because I am on a plane. but the providence ri airport. tf green. is THE WORST airport on Earth.

Tuesday, September 26

Blog entries around

During my daily blog reads, I was reading David Weiss's blog, and he mentions some recent customer service he received from Apple. Turns out he, like me, bought the three free episodes of ABC's finalies of last season, and was accidentally charged for them. Read his entry here.

Not only did Apple refund his money, but they GAVE HIM MONEY.

Now THAT'S customer service. That's why I buy Apple products, that's why I am a loyal customer. Everything I have EVER needed from Apple was immediate and responsive. When I had to send my iBook back to Apple for the Logic Board recall. They overnighted me a box, gave me packing instructions, tape, and everything. I overnighted the box back to them, (at their expense), they fixed it in about 4 days, and overnighted it back. Everything was intact, the data was there. Everything. and it didn't take forever. I wasn't without my laptop very long.

THAT's why I buy Apple products, and the fact that they are awesome, but, the customer service rocks too.

Blog entries around

During my daily blog reads, I was reading David Weiss's blog, and he mentions some recent customer service he received from Apple. Turns out he, like me, bought the three free episodes of ABC's finalies of last season, and was accidentally charged for them. Read his entry here.

Not only did Apple refund his money, but they GAVE HIM MONEY.

Now THAT'S customer service. That's why I buy Apple products, that's why I am a loyal customer. Everything I have EVER needed from Apple was immediate and responsive. When I had to send my iBook back to Apple for the Logic Board recall. They overnighted me a box, gave me packing instructions, tape, and everything. I overnighted the box back to them, (at their expense), they fixed it in about 4 days, and overnighted it back. Everything was intact, the data was there. Everything. and it didn't take forever. I wasn't without my laptop very long.

THAT's why I buy Apple products, and the fact that they are awesome, but, the customer service rocks too.

Tuesday, September 19

Starbucks + Apple

Here's an idea Steve Jobs. Partner with Starbucks. Sell iPods, sell iTunes cards, encourage people to bring in their laptops. I don't know. Something...

Look at that potential for money...

iTunes 7 feature

You know, I found an unpublished (or maybe it was, and I didn't see it) feature of iTunes 7.

Especially useful for large libraries that may have multiple copies of the same song. (say you imported a bunch of mp3's and CD's)

Click on View -> Show Duplicates.

It finds all the Duplicates in your iTunes DB. This is a really nice feature.

I ran it on my huge iTunes library, and it found alot of dups. It also found some dups that I didn't want to get rid of, for example, two copies (or three) of the same song, one album, one live, or two live.

Kinda nice.

Starbucks + Apple

Here's an idea Steve Jobs. Partner with Starbucks. Sell iPods, sell iTunes cards, encourage people to bring in their laptops. I don't know. Something...

Look at that potential for money...

0-day

Okay. I've been receiving emails like mad through isc.sans.org internal lists, full-disclosure, security, irc, jabber rooms I'm in, blah blah...

About all these "0-day's" in MS Windows. (As if we were surprised!?). I am just ranting to the point of... I am REALLY getting tired of hearing "0-day" every three seconds, frankly, it's getting annoying.

Please security professionals, I know that 0-day gets your bosses attention, because 0day has went from 'hax0r' term to freaking Marketing. bleh. Marketing (Yes, I know it has a purpose.. I just don't like it sometimes)

So... security guys... lets develop a new term. 0-day is dead.

P.S. It's pronounced "ZERO-DAY" not "O-day" like in the "O-jays". get it right.

iTunes 7 feature

You know, I found an unpublished (or maybe it was, and I didn't see it) feature of iTunes 7.

Especially useful for large libraries that may have multiple copies of the same song. (say you imported a bunch of mp3's and CD's)

Click on View -> Show Duplicates.

It finds all the Duplicates in your iTunes DB. This is a really nice feature.

I ran it on my huge iTunes library, and it found alot of dups. It also found some dups that I didn't want to get rid of, for example, two copies (or three) of the same song, one album, one live, or two live.

Kinda nice.

Monday, September 18

Apple to update Laptops?

Apple Insider link

Friend of mine, Jim, pointed this article out to me. Looks like Apple is about to update their MacBook Pros. I'm not really prone to blogging rumors, however, I really hope this one is true.

Pcap Checksum fixer

This program was NOT WRITTEN BY ME. Just so we're all clear on that.

Brian Caswell wrote this program and posted it on his blog. However, I find it very useful.

Sometimes when people have problems with their pcap's when they are trying to run them through Snort, I would say 90% of the time, it's because of bad chksums. Now, that's not a bad thing, it's just that people forget to check them.

So this little proggie takes a pcap, rewrites the checksum so its correct, and spits it back out. THEN you can run it through Snort. (Or whatever)

Here is the program that I did not write.

It requires Net::Pcap and Net::Ethereal. Install these through cpan. If you don't know how to do that, well, May God have mercy on your soul. (see link for a judge actually using that quote in a filing. That's awesome. /me claps for that judge.

Credit goes to Brian Caswell. He wrote it. and it rox.

Apple to update Laptops?

Apple Insider link

Friend of mine, Jim, pointed this article out to me. Looks like Apple is about to update their MacBook Pros. I'm not really prone to blogging rumors, however, I really hope this one is true.

Thursday, September 14

Free downloads of LOST, Desperate Housewives and Grey's Anatomy on iTunes

It's promo time! In an attempt to woo new customers ABC is giving away free copies of last season's finales of Lost, Desperate Housewives and Grey's Anatomy

read more | digg story

Free downloads of LOST, Desperate Housewives and Grey's Anatomy on iTunes

It's promo time! In an attempt to woo new customers ABC is giving away free copies of last season's finales of Lost, Desperate Housewives and Grey's Anatomy

read more | digg story

Monday, September 11

September 11th & How Google Changed.

An intresting article on how Google changed their website so many times on September 11th. How many hits, and for what.

Check this out

September 11th & How Google Changed.

An intresting article on how Google changed their website so many times on September 11th. How many hits, and for what.

Check this out

Wednesday, September 6

New iMac's

Quietly this morning, Apple introduced some new iMac's The new iMac's are advertised as being "Faster, Brighter, and Bigger".

First thing I noticed was the 24in iMac. That's cool, looks like a brighter screen, bigger video card..

Also looks like a new processor (64 bit).

The 24in model gets (instead of two 400 firewire) gets one 400 and one 800. Also comes standard with a 250 Gb harddrive, 24 watt digital amplifier, and NVIDIA GeForce 7300 GT graphics processor with 128MB of GDDR3 SDRAM using PCI Express.

Prices are here, but also, look at the picture at the bottom there... Doesn't the new 24in look thinner?

New iMac's

Quietly this morning, Apple introduced some new iMac's The new iMac's are advertised as being "Faster, Brighter, and Bigger".

First thing I noticed was the 24in iMac. That's cool, looks like a brighter screen, bigger video card..

Also looks like a new processor (64 bit).

The 24in model gets (instead of two 400 firewire) gets one 400 and one 800. Also comes standard with a 250 Gb harddrive, 24 watt digital amplifier, and NVIDIA GeForce 7300 GT graphics processor with 128MB of GDDR3 SDRAM using PCI Express.

Prices are here, but also, look at the picture at the bottom there... Doesn't the new 24in look thinner?