If you are in the area (or even if you aren't, I know of people traveling a pretty good distance to get here) and you haven't got your ticket for Bsides DE yet, you may want to get on it.
The first round of tickets are all gone, and there are only 40 left of the extension tickets.
<plug>
I'm speaking at 1:00, right after lunch. See the speaker's schedule here. But anyway, if you haven't got your tickets yet, you might want to hurry up and grab them from here. Cost? Free.
Tuesday, November 2
Archiving Emails in Mail.app, there's an app for that.
If you are using Mail.app on OSX, this post is for you.
It's been well known to people that read my blog that I am an Inbox-Zero ninja, and generally pride myself on my ability to get through vast amounts of email quickly because of the system that I have refined over the past several years of experimenting.
One of the things about Inbox Zero is the ability to quickly move an email out of your "Inbox" and into another folder. If you sort your emails that come into your Inbox by topic or subject or whatever, different folders may do good things for you. For instance I have a folder where all Snort related email goes. The three Snort mailing lists go straight to my inbox where I read most of them and then file them away using a keyboard shortcut. Other Snort related mailing lists just go straight to this box, leaving me with only the important ones in my inbox.
Most listserver traffic of the 40 or so listservers that I belong to go straight to a "listserver" folder, where I can deal with it later. You get my point.
But everything that I don't filter, is in my inbox, which usually nets me about 200~ emails a day that I need to deal with. When I read an email I have possible outcomes.
Duh. I don't do enough of this.
This is the meat of the post, and kind of the point of writing this article. I am a firm believer in leaving your hands on the keyboard if possible. Learning the keyboard shortcuts in your favorite app will not only save time, but it also keeps your hands where you need to be doing work. On the keyboard (instead of continually reaching for your mouse). There are keyboard shortcuts for almost anything in OSX, and if you can't find it, or the menu command doesn't have a keyboard shortcut, you can make a keyboard shortcut to do what you want in Snow Leopard. Heck, there are keyboard shortcuts in Gmail (learn em!)
Now, how do you do this in Mail.app, well there is a little app called "Archive" that will allow you to do this.
Archive. Archive allows you to do exactly that. Archive the email that you are presently on. It creates a folder in your email accounts named "Archive", and when you mash the shortcut in your inbox, it puts the email that you have lighted in the appropriate Archive folder. Simple, clean, done.
There is also Mail Act-On, which I've talked about before here, is a nice little app if you need to do more advanced things than Archive, but for 99% of you, check out Archive, it does what you need.
If I think it'll take less than 2 minutes to respond to the email that I am currently reading, I'll bang out a response. I try to not bang out a "quick" response "just to keep the ball moving" as Kevin Rose says. I try to write out a through response. My point in doing this is to eliminate further email by providing any answers I can, by asking the appropriate question so that the response to my email is full of exactly what I need it to be, and so that people don't waste more time by me not wasting theirs with a "short terse banged-out email".
Otherwise known as the "Forward" button. I get a ton of email, not all appropriate for me to handle, some need to go to our web team, some need to go to our research team, but it comes to me, because I "handle" the email, as opposed to ignore it. I don't mind being the conduit to which people communicate, at least I know things are getting done, and I have a pulse on what is going on.
If the email contains an action that I need to perform, but I can't do it right now, I have a keyboard shortcut that allows me to highlight a section of text, mash a keyboard shortcut, and Omnifocus will grab the hightlight-ed input that I selected and makes a Todo out of it, along with a link in Omnifocus back to the email that generated it. (This is called "Clipping" for you Omnifocus nerds, get ON IT.) I quickly set a context (email) and a due date. Then I go onto the next email. Everyday, I get to the bottom of the "Todo"s that are due that day, and that includes the thoughtful emails.
Matter of fact, writing this post about "Archive" was a Todo.
Let me go mark it done.
BTW -- Inbox Zero comes from Merlin Mann. I'm not stealing his work. It's insightful. He rocks. MerlinMann.com and InboxZero.com
It's been well known to people that read my blog that I am an Inbox-Zero ninja, and generally pride myself on my ability to get through vast amounts of email quickly because of the system that I have refined over the past several years of experimenting.
Techniques in Archiving
One of the things about Inbox Zero is the ability to quickly move an email out of your "Inbox" and into another folder. If you sort your emails that come into your Inbox by topic or subject or whatever, different folders may do good things for you. For instance I have a folder where all Snort related email goes. The three Snort mailing lists go straight to my inbox where I read most of them and then file them away using a keyboard shortcut. Other Snort related mailing lists just go straight to this box, leaving me with only the important ones in my inbox.
Most listserver traffic of the 40 or so listservers that I belong to go straight to a "listserver" folder, where I can deal with it later. You get my point.
But everything that I don't filter, is in my inbox, which usually nets me about 200~ emails a day that I need to deal with. When I read an email I have possible outcomes.
- Delete it
- Archive it (if I need it later)
- Respond to it (if it takes shorter than 2 minutes to accomplish this task)
- Delegate it (if I am not the appropriate person to deal with "x" email)
- Make a todo to deal with it later.
Delete it
Duh. I don't do enough of this.
Archive it.
This is the meat of the post, and kind of the point of writing this article. I am a firm believer in leaving your hands on the keyboard if possible. Learning the keyboard shortcuts in your favorite app will not only save time, but it also keeps your hands where you need to be doing work. On the keyboard (instead of continually reaching for your mouse). There are keyboard shortcuts for almost anything in OSX, and if you can't find it, or the menu command doesn't have a keyboard shortcut, you can make a keyboard shortcut to do what you want in Snow Leopard. Heck, there are keyboard shortcuts in Gmail (learn em!)
Now, how do you do this in Mail.app, well there is a little app called "Archive" that will allow you to do this.
Archive. Archive allows you to do exactly that. Archive the email that you are presently on. It creates a folder in your email accounts named "Archive", and when you mash the shortcut in your inbox, it puts the email that you have lighted in the appropriate Archive folder. Simple, clean, done.
There is also Mail Act-On, which I've talked about before here, is a nice little app if you need to do more advanced things than Archive, but for 99% of you, check out Archive, it does what you need.
Respond to it
If I think it'll take less than 2 minutes to respond to the email that I am currently reading, I'll bang out a response. I try to not bang out a "quick" response "just to keep the ball moving" as Kevin Rose says. I try to write out a through response. My point in doing this is to eliminate further email by providing any answers I can, by asking the appropriate question so that the response to my email is full of exactly what I need it to be, and so that people don't waste more time by me not wasting theirs with a "short terse banged-out email".
Delegate It.
Otherwise known as the "Forward" button. I get a ton of email, not all appropriate for me to handle, some need to go to our web team, some need to go to our research team, but it comes to me, because I "handle" the email, as opposed to ignore it. I don't mind being the conduit to which people communicate, at least I know things are getting done, and I have a pulse on what is going on.
Todo It.
If the email contains an action that I need to perform, but I can't do it right now, I have a keyboard shortcut that allows me to highlight a section of text, mash a keyboard shortcut, and Omnifocus will grab the hightlight-ed input that I selected and makes a Todo out of it, along with a link in Omnifocus back to the email that generated it. (This is called "Clipping" for you Omnifocus nerds, get ON IT.) I quickly set a context (email) and a due date. Then I go onto the next email. Everyday, I get to the bottom of the "Todo"s that are due that day, and that includes the thoughtful emails.
Matter of fact, writing this post about "Archive" was a Todo.
Let me go mark it done.
BTW -- Inbox Zero comes from Merlin Mann. I'm not stealing his work. It's insightful. He rocks. MerlinMann.com and InboxZero.com
Tuesday, October 26
Snort Community Pig Roast
(If you read this on Twitter, please RT!)
Sourcefire is going to throw a community pig roast at our World Wide Headquarters on November 12, 2010. We'll have some talks by Marty Roesch (our fearless leader) and Matt Watchinski (or VRT fearless leader).
Date: Friday, November 12, 2010
Time: 12:00PM
Where: Sourcefire HQ
9770 Patuxent Woods Dr.
Columbia, MD 21046
The event is open to our community, and we'd like you to come on over and hang out!
Please RSVP at: http://now.sourcefire.com/?elqPURLPage=2?elqformname=101112_snort_bbq&URL=
Sourcefire is going to throw a community pig roast at our World Wide Headquarters on November 12, 2010. We'll have some talks by Marty Roesch (our fearless leader) and Matt Watchinski (or VRT fearless leader).
Date: Friday, November 12, 2010
Time: 12:00PM
Where: Sourcefire HQ
9770 Patuxent Woods Dr.
Columbia, MD 21046
The event is open to our community, and we'd like you to come on over and hang out!
Please RSVP at: http://now.sourcefire.com/?elqPURLPage=2?elqformname=101112_snort_bbq&URL=
Notes syncing between Mail.app and iPhone, finally
I've written several times over the years about the need for Notes to sync automatically between the iPhone and the Mac Mail.app Desktop application. Well, unbeknownst to me (because I stopped using Notes in Mail.app because of the lack of this feature), in iOS 4.0 Apple has built this in.
I didn't test it right away when the release came out, and just now that I haven't written about it either since they built this in. But it works.
If you have an IMAP account, you can go into your account settings on your iPhone and turn on "Notes" in that account's preferences. Mail will create a folder called "Notes" on the IMAP server, and your "Notes" on Mail.app will be sync'ed Over-the-Air with your iPhone.
I have my Mail.app set up like this:

So that all my notes and to-do's stay intact in one account, and not spread apart different accounts. But there is more than one advantage to MobileMe for this particular feature. If you set it to MobileMe, Notes are pushed. (As opposed to pull, as they would be with other IMAP accounts.)
In short, Apple enabled Notes syncing in iOS 4.0. It works. Give it a shot.
I didn't test it right away when the release came out, and just now that I haven't written about it either since they built this in. But it works.
If you have an IMAP account, you can go into your account settings on your iPhone and turn on "Notes" in that account's preferences. Mail will create a folder called "Notes" on the IMAP server, and your "Notes" on Mail.app will be sync'ed Over-the-Air with your iPhone.
I have my Mail.app set up like this:
So that all my notes and to-do's stay intact in one account, and not spread apart different accounts. But there is more than one advantage to MobileMe for this particular feature. If you set it to MobileMe, Notes are pushed. (As opposed to pull, as they would be with other IMAP accounts.)
In short, Apple enabled Notes syncing in iOS 4.0. It works. Give it a shot.
Facetime
Facetime, Apple’s new iPhone 4 to iPhone 4 video chat application got a bit of an update on Tuesday of this week.
Jobs said it himself, the biggest thing that people wanted when facetime was shown on the iPhone for the first time was the integration of the system into the Mac desktop. I talked about this back on this original post when the iPhone 4 came out. Finally, at Tuesday’s speech Jobs and Apple rolled out the Facetime client for the desktop.
It works.
You can call Mac to Mac using Facetime, you can also call Mac to iPhone or iPhone to Mac, likewise with the iPod Touch. The resolution is good (it’s scaled down a bit if you are used to iChat’s resolution), audio is excellent, and it works flawlessly. In fact, when it came out, I was on a hotel network. I tried to initiate an iChat connection to my Dad, and we couldn’t do it for lack of bandwidth, however, Facetime connected right away without a problem.
The only thing that I thought was a bit strange, and I know I'm not the only one, was that Apple released it as a separate application for the Mac.
However, after I thought about it for a bit, I came back to my original conclusion that this is a temporary step. The application is simple and easy to write, so that’s what Apple did. I imagine in order to build the feature into iChat, they'd have to rewrite the whole application, and while they didn’t at all indicate that this was going to happen in 10.7 Lion (which they also started talking about on Tuesday), it makes a lot of sense to have it built into the OS.
One of the other things that i noticed about facetime is that it doesn’t really give you any kind of “presence” notification. For instance, it would make sense that since Apple knows you are connected to the internet via $device, they would be able to provide some type of presence notification along with it, I assume this is going to come with 10.7 too.
Jobs said it himself, the biggest thing that people wanted when facetime was shown on the iPhone for the first time was the integration of the system into the Mac desktop. I talked about this back on this original post when the iPhone 4 came out. Finally, at Tuesday’s speech Jobs and Apple rolled out the Facetime client for the desktop.
It works.
You can call Mac to Mac using Facetime, you can also call Mac to iPhone or iPhone to Mac, likewise with the iPod Touch. The resolution is good (it’s scaled down a bit if you are used to iChat’s resolution), audio is excellent, and it works flawlessly. In fact, when it came out, I was on a hotel network. I tried to initiate an iChat connection to my Dad, and we couldn’t do it for lack of bandwidth, however, Facetime connected right away without a problem.
The only thing that I thought was a bit strange, and I know I'm not the only one, was that Apple released it as a separate application for the Mac.
However, after I thought about it for a bit, I came back to my original conclusion that this is a temporary step. The application is simple and easy to write, so that’s what Apple did. I imagine in order to build the feature into iChat, they'd have to rewrite the whole application, and while they didn’t at all indicate that this was going to happen in 10.7 Lion (which they also started talking about on Tuesday), it makes a lot of sense to have it built into the OS.
One of the other things that i noticed about facetime is that it doesn’t really give you any kind of “presence” notification. For instance, it would make sense that since Apple knows you are connected to the internet via $device, they would be able to provide some type of presence notification along with it, I assume this is going to come with 10.7 too.
Friday, October 22
The Mac App Store, why it's awesome.
On Tuesday this week, Steve Jobs got up in front of journalists and announced several things. I'd like to cover them all at once, but I realized the post was going to be way too long, so I thought I'd cover them in separate topics.
First let me talk about, what I thought was the biggest announcement of the entire press conference. The Mac App Store.
Similar to the iOS App store that you can find in iTunes, Apple will be rolling out a separate application onto the OSX platform where developers can upload their apps to Apple in order for them to be purchase-able through the "one-click" easy access of this app.

Apple is taking the same 'cut' that it takes for the iTunes app store, 70/30. 70% of the developers revenue for selling an app goes to the developer, the other 30% goes to Apple to pay for the store, the hosting, the bandwidth, etc. Some developers will think that this is Apple gouging into their profits, and while true, they have to think of a couple things:
1) I can raise the price of my app, just enough, to make it worthwhile for me.
2) The prices of the apps in the Mac App store will generally be higher, as they will be of higher quality. (Theory of mine, as they won't be just little fart apps for the iPhone.)
3) You would now be featured in the "showcase" as it were for Apps. This is a genius idea. Yes you have to sacrifice the 30% of your revenue, but your download count will go through the roof. Look at the developers that have made millions off of the iPhone app store in just a short amount of time after it's release.
Some people I've heard talk about the App store seem to think this is Apple's way of locking you into their platform. Let me share my opinion on this.
They already have you locked into their platform.
First off, if you buy your app from the app store, you click the button, it downloads over the internet (further reinforcing my theory that I wrote a couple years ago when the Macbook Air came out, I said that it was going to be the end of distributing software via physical medium), it installs by itself. Done. Easy.
If you want to update the app, you go to the "updates" section of the app store, and you click "update" or "update all" and all your apps are automagically updated. What I'd like to see Apple do is have all their updates take place through this system. I think "Software Update" and the "Updates in the App store" may be confusing for some users, but that will remain to be seen I guess.
At the same time yesterday we found out that Apple is depreciating Java on their system, and the new Macbook Air (which I'll talk about in a later post) is shipping without Adobe Flash. I think both of these are smart decisions, and would like to see both of these in the App Store. Oracle submits a Java build, and Adobe submits Flash. You download both of these with one click, from one place (instead of going all over the internet to find them and their updates), and that way when a new update comes out for Flash or Java, you just click "Update" in the app store. This does two things:
A) Makes security better, by providing an easy way for people to update their apps.
B) It absolves Apple from having to maintain older software on their system and keep it updated (such as Flash).
Great idea.
Yesterday on my drive home I was listening to the latest "MacBreak Weekly" podcast, and even though Alex Lindsay has been saying it for several months now, he reiterated it again in the latest broadcast. He thinks that the OS on the Mac is going to iOS.
I think he could not be more wrong, and let me explain why.
Steve Jobs said yesterday that they were bringing some of the things they have learned form the iPhone and iPad back to the Mac. Good idea. It's great to have a unifying experience across all your platforms.
Does that mean that the OSX Operating system will be all touch based? No. Jobs said that yesterday, trying to manipulate objects on a vertical surface doesn't work. Think about it as you are reading this right now, if you are reading this on a traditional computer. Think about not having your mouse, and moving the cursor or using gestures on your monitor. Play with that idea a second. Your arm would get so tired and you'd get frustrated after awhile. Heck, when I dock my iPad and use a regular keyboard with it, and I have to reach up and tap something on the screen when it's in a vertical configuration, it's annoying. This won't work. I agree.
Does that mean that OSX can't learn some multi-touch gestures? No. In fact, you can already scroll with two fingers (have been able to do for years on the Mac), three finger swipe forwards and back, even rotate photos and documents by the same rotation method that you use on the iPod Nano's screen. Add a few more of these and the system will not only be intuitive, but you'll be able to get a lot done, faster. That's why Apple invented the Magic Mouse, and that's why they invented the Magic Trackpad. Look at the direction of the Operating System and it makes sense.
OSX is not becoming iOS. It won't work. But there are advantages that iOS has that OSX does not have, again, let's come back to the App Store. The App Store on the iTunes/iPod touch/iPhone/iPad system is an easy one-click access to any app on the Apple store. The App store on the Mac is going to be the same way. However, what side effects does this provide that people may not have thought of yet?
1) Your Apps are tied to your iTunes account. Okay, that means that if I want to rebuild my computer, or buy a new one, all I have to do is open the App Store and I can suck down all the apps that I've already paid for without having to re-find them on the internet, or from a backup. Better yet, I don't have to keep track of licenses and other non-sense like that.
2) Easy updating. This is important, not only for functionality, but for security. I think this is one of the best features of the App Store.
3) Your Apps are tied to your iTunes account. Which means what? That's right. They are DRM'ed to your name. Which means what? That's right. You can't pirate the Apps.
Let me pause for effect.
Yup. That's just happened.
Genius. I buy all my applications anyway, so it doesn't affect me, but that's awesome.
The apps that are sold through the app store can't be packaged up and sent to your friend anymore.
Yes, you can still download apps and what not from the Internet in general (meaning that developers for the Mac don't HAVE to sell their apps through the app store), but then you are dealing with not being in front of tons of eyes through the App Store, licensing and purchasing schemes. You have to maintain all of that yourself. Whereas through the App Store, Apple has taken care of all of that for you and prevented the piracy of your Apps.
I also think this will totally increase the amount of apps available for the Mac platform. All of a sudden people will have easy access to a way to simply get their Mac Application out there without having to shrink wrap it and get it into the big-box stores.
Honestly, I see nothing but good things here. The only time I'll have a problem with the Mac App Store is when Apple says that the only place you can get the apps is from them. .....and they are still taking their 30% cut.
That's not really fair (which isn't happening, I'm just theorizing).
Although it would be interesting, because then all code would come from Apple, approved, and signed. Malware and what-not could be rendered totally non-existant.
Apple has also stated in their terms of service that "violent" video games can't be on the App Store.
That sucks. I think that'll hurt the store overall, but who knows, they may fix that.
The Mac App Store
First let me talk about, what I thought was the biggest announcement of the entire press conference. The Mac App Store.
Similar to the iOS App store that you can find in iTunes, Apple will be rolling out a separate application onto the OSX platform where developers can upload their apps to Apple in order for them to be purchase-able through the "one-click" easy access of this app.
Apple is taking the same 'cut' that it takes for the iTunes app store, 70/30. 70% of the developers revenue for selling an app goes to the developer, the other 30% goes to Apple to pay for the store, the hosting, the bandwidth, etc. Some developers will think that this is Apple gouging into their profits, and while true, they have to think of a couple things:
1) I can raise the price of my app, just enough, to make it worthwhile for me.
2) The prices of the apps in the Mac App store will generally be higher, as they will be of higher quality. (Theory of mine, as they won't be just little fart apps for the iPhone.)
3) You would now be featured in the "showcase" as it were for Apps. This is a genius idea. Yes you have to sacrifice the 30% of your revenue, but your download count will go through the roof. Look at the developers that have made millions off of the iPhone app store in just a short amount of time after it's release.
Conspiracy Theories
Some people I've heard talk about the App store seem to think this is Apple's way of locking you into their platform. Let me share my opinion on this.
They already have you locked into their platform.
First off, if you buy your app from the app store, you click the button, it downloads over the internet (further reinforcing my theory that I wrote a couple years ago when the Macbook Air came out, I said that it was going to be the end of distributing software via physical medium), it installs by itself. Done. Easy.
If you want to update the app, you go to the "updates" section of the app store, and you click "update" or "update all" and all your apps are automagically updated. What I'd like to see Apple do is have all their updates take place through this system. I think "Software Update" and the "Updates in the App store" may be confusing for some users, but that will remain to be seen I guess.
At the same time yesterday we found out that Apple is depreciating Java on their system, and the new Macbook Air (which I'll talk about in a later post) is shipping without Adobe Flash. I think both of these are smart decisions, and would like to see both of these in the App Store. Oracle submits a Java build, and Adobe submits Flash. You download both of these with one click, from one place (instead of going all over the internet to find them and their updates), and that way when a new update comes out for Flash or Java, you just click "Update" in the app store. This does two things:
A) Makes security better, by providing an easy way for people to update their apps.
B) It absolves Apple from having to maintain older software on their system and keep it updated (such as Flash).
Great idea.
More Conspiracy Theories
Yesterday on my drive home I was listening to the latest "MacBreak Weekly" podcast, and even though Alex Lindsay has been saying it for several months now, he reiterated it again in the latest broadcast. He thinks that the OS on the Mac is going to iOS.
I think he could not be more wrong, and let me explain why.
Steve Jobs said yesterday that they were bringing some of the things they have learned form the iPhone and iPad back to the Mac. Good idea. It's great to have a unifying experience across all your platforms.
Does that mean that the OSX Operating system will be all touch based? No. Jobs said that yesterday, trying to manipulate objects on a vertical surface doesn't work. Think about it as you are reading this right now, if you are reading this on a traditional computer. Think about not having your mouse, and moving the cursor or using gestures on your monitor. Play with that idea a second. Your arm would get so tired and you'd get frustrated after awhile. Heck, when I dock my iPad and use a regular keyboard with it, and I have to reach up and tap something on the screen when it's in a vertical configuration, it's annoying. This won't work. I agree.
Does that mean that OSX can't learn some multi-touch gestures? No. In fact, you can already scroll with two fingers (have been able to do for years on the Mac), three finger swipe forwards and back, even rotate photos and documents by the same rotation method that you use on the iPod Nano's screen. Add a few more of these and the system will not only be intuitive, but you'll be able to get a lot done, faster. That's why Apple invented the Magic Mouse, and that's why they invented the Magic Trackpad. Look at the direction of the Operating System and it makes sense.
OSX is not becoming iOS. It won't work. But there are advantages that iOS has that OSX does not have, again, let's come back to the App Store. The App Store on the iTunes/iPod touch/iPhone/iPad system is an easy one-click access to any app on the Apple store. The App store on the Mac is going to be the same way. However, what side effects does this provide that people may not have thought of yet?
1) Your Apps are tied to your iTunes account. Okay, that means that if I want to rebuild my computer, or buy a new one, all I have to do is open the App Store and I can suck down all the apps that I've already paid for without having to re-find them on the internet, or from a backup. Better yet, I don't have to keep track of licenses and other non-sense like that.
2) Easy updating. This is important, not only for functionality, but for security. I think this is one of the best features of the App Store.
3) Your Apps are tied to your iTunes account. Which means what? That's right. They are DRM'ed to your name. Which means what? That's right. You can't pirate the Apps.
Let me pause for effect.
Apple. Just figured out a way. To stop. Software piracy.
Yup. That's just happened.
Genius. I buy all my applications anyway, so it doesn't affect me, but that's awesome.
The apps that are sold through the app store can't be packaged up and sent to your friend anymore.
Yes, you can still download apps and what not from the Internet in general (meaning that developers for the Mac don't HAVE to sell their apps through the app store), but then you are dealing with not being in front of tons of eyes through the App Store, licensing and purchasing schemes. You have to maintain all of that yourself. Whereas through the App Store, Apple has taken care of all of that for you and prevented the piracy of your Apps.
I also think this will totally increase the amount of apps available for the Mac platform. All of a sudden people will have easy access to a way to simply get their Mac Application out there without having to shrink wrap it and get it into the big-box stores.
Problem?
Honestly, I see nothing but good things here. The only time I'll have a problem with the Mac App Store is when Apple says that the only place you can get the apps is from them. .....and they are still taking their 30% cut.
That's not really fair (which isn't happening, I'm just theorizing).
Although it would be interesting, because then all code would come from Apple, approved, and signed. Malware and what-not could be rendered totally non-existant.
Apple has also stated in their terms of service that "violent" video games can't be on the App Store.
That sucks. I think that'll hurt the store overall, but who knows, they may fix that.
Monday, October 18
Ray Ozzie leaving post as Microsoft's chief software architect
Ray Ozzie is the gentleman that took Bill Gates's place after he retired from his day to day duties at Microsoft, and unfortunately, this kinda makes me feel more confident in the opinion I had when that event took place.
Microsoft is losing their spirit.
Let's face it, it's quite obvious now that Bill Gates was the driver behind the Microsoft brand and direction. This is the third notable post that is being vacated since Bill Gates left (the first being the designer behind the Zune interface Robbie Bach, second being CFO Chris Liddell), and yet, somehow Ballmer stays in charge.
Don't get me wrong, Ballmer knows how to make money. Which is why he's a good CEO, but in my opinion, it doesn't feel like he is ushering in a strong "direction" for the company. But maybe I'm being a little critical, trying not to compare him to Steve Jobs, but hate him or love him, Steve Jobs is a great CEO.
It just feels to me that Microsoft is playing the catchup game. Saying "me too" to everything that is coming out. Windows Mobile Phone 7, (which was started a long time ago, but not until the iPhone came out was serious pressure put on this), the Xbox360 (which is probably Microsoft's best product), the Zune copied after the iPod, Windows's constant comparison to OSX, chasing after Google with Bing, and chasing after the iPad now with whatever-the-heck tablets (slate) they come out with.
Sad part is, Microsoft almost invented the tablet business. They pretty much pioneered it. However, they tried to shoe horn a Desktop OS into a tablet PC and wrote enough software to be able to use a pen. Well, it doesn't appear to have caught on en-masse. They didn't go back to the drawing board (like they did with Windows Mobile Phone 7) and design a new user interface, even if they copied the WMP7 interface from the Zune HD. Their current tablet offering does not bode well for touch, and it's unclear where their future direction is going as far as touch is concerned, but it doesn't look good right now. It still looks like they are trying to shoehorn Windows 7, the desktop operating system, into the tablet. It's not going to work! You tried that once, and it failed. So I refer to the current class of computing devices (the iPad, and all the competitors that are trying to come out now as "slate" devices.)
Ray Ozzie, as it states in the below linked article, is best known for creating Lotus Notes. Which really doesn't speak volumes to quality, but it does speak to success. Even a totally awful program can make tons of money. But Mr. Ozzie didn't seem to provide the direction that Gates did. Face it, Gates was the genius behind the Microsoft brand. Even if his tactic was to copy everything he saw, which I'm not saying he did, but even if his tactic was that, it was genius and it worked well.
I am not a Microsoft Shareholder, heck, I'm not even an Apple shareholder anymore, but I'd wonder why Ballmer was still in power considering the stock price hasn't moved much in over 10 years.
Ray Ozzie leaving post as Microsofts chief software architect.
Microsoft is losing their spirit.
Let's face it, it's quite obvious now that Bill Gates was the driver behind the Microsoft brand and direction. This is the third notable post that is being vacated since Bill Gates left (the first being the designer behind the Zune interface Robbie Bach, second being CFO Chris Liddell), and yet, somehow Ballmer stays in charge.
Don't get me wrong, Ballmer knows how to make money. Which is why he's a good CEO, but in my opinion, it doesn't feel like he is ushering in a strong "direction" for the company. But maybe I'm being a little critical, trying not to compare him to Steve Jobs, but hate him or love him, Steve Jobs is a great CEO.
It just feels to me that Microsoft is playing the catchup game. Saying "me too" to everything that is coming out. Windows Mobile Phone 7, (which was started a long time ago, but not until the iPhone came out was serious pressure put on this), the Xbox360 (which is probably Microsoft's best product), the Zune copied after the iPod, Windows's constant comparison to OSX, chasing after Google with Bing, and chasing after the iPad now with whatever-the-heck tablets (slate) they come out with.
Sad part is, Microsoft almost invented the tablet business. They pretty much pioneered it. However, they tried to shoe horn a Desktop OS into a tablet PC and wrote enough software to be able to use a pen. Well, it doesn't appear to have caught on en-masse. They didn't go back to the drawing board (like they did with Windows Mobile Phone 7) and design a new user interface, even if they copied the WMP7 interface from the Zune HD. Their current tablet offering does not bode well for touch, and it's unclear where their future direction is going as far as touch is concerned, but it doesn't look good right now. It still looks like they are trying to shoehorn Windows 7, the desktop operating system, into the tablet. It's not going to work! You tried that once, and it failed. So I refer to the current class of computing devices (the iPad, and all the competitors that are trying to come out now as "slate" devices.)
Ray Ozzie, as it states in the below linked article, is best known for creating Lotus Notes. Which really doesn't speak volumes to quality, but it does speak to success. Even a totally awful program can make tons of money. But Mr. Ozzie didn't seem to provide the direction that Gates did. Face it, Gates was the genius behind the Microsoft brand. Even if his tactic was to copy everything he saw, which I'm not saying he did, but even if his tactic was that, it was genius and it worked well.
I am not a Microsoft Shareholder, heck, I'm not even an Apple shareholder anymore, but I'd wonder why Ballmer was still in power considering the stock price hasn't moved much in over 10 years.
Ray Ozzie leaving post as Microsofts chief software architect.
Friday, October 15
MobileMe Calendar Comes out of Beta
Following up on this post that I wrote back in July, the MobileMe calendaring system has come out of Beta. Which means that if you are using the MobileMe service and you are on Snow Leopard (or Leopard) your iCal calendar should automatically switch over to WebDAV. As well as your iPhone's calendar if you are running 4.0.
The nicest part about the system is the ability to invite other people to events from your iPhone and iCal, as well as see their Free/Busy schedules.
Update: Apple's article on the subject.
The nicest part about the system is the ability to invite other people to events from your iPhone and iCal, as well as see their Free/Busy schedules.
Update: Apple's article on the subject.
Monday, October 11
I'm speaking at Security B-Sides Delaware
We have a lot going on in Delaware. Tax-free shopping, we elect crazy people, and we have the Security B-sides Delaware event happening in November.
I was asked if I would submit a talk to the conference, and lo and behold, it was accepted. (Along with a bunch of other great presenters, check out the first round of CFP accepts here. Hopefully lots of people will come. I actually have a confession to make, I've never actually been to a Security B-sides, although, from watching the Twitter, they are very popular.
Abstract of my talk:
I look forward you seeing many of you there, thanks for supporting B-sides. Okay, back to making slides.
Security B-Sides / BSidesDelaware.
I was asked if I would submit a talk to the conference, and lo and behold, it was accepted. (Along with a bunch of other great presenters, check out the first round of CFP accepts here. Hopefully lots of people will come. I actually have a confession to make, I've never actually been to a Security B-sides, although, from watching the Twitter, they are very popular.
Abstract of my talk:
Shining light into the "now what" arena of IDS and IPS tuning, I'll talk about what the next steps should be with the alerts, tuning, and maintenance of the ruleset and configuration deployed into an IDS or an IPS. General guidelines will be provided, however, all guidelines must be adapted to your specific environment.
I look forward you seeing many of you there, thanks for supporting B-sides. Okay, back to making slides.
Security B-Sides / BSidesDelaware.
Monday, October 4
Snort 2.9.0 has been released
Now available from Snort.org, Snort 2.9.0 and DAQ 0.2. I'll be writing some articles at some point to expand upon some of the functionality of Snort 2.9, but for now, know that there are some very nice new keywords in 2.9 and also an improved Stream model, as well as lots of improvements all over the place in the engine.
...and now some cut and paste from the release notes! Download it now!
http://www.snort.org/snort-downloads
[*] New Additions
* Feature rich IPS mode including improvements to Stream for
inline deployments. Additionally a common active response API is
used for all packet responses, including those from Stream,
Respond, or React. A new response module, respond3, supports the
syntax of both resp & resp2, including strafing for passive
deployments. When Snort is deployed inline, a new preprocessor
has been added to handle packet normalization to allow Snort
to interpret a packet the same way as the receiving host.
* Use of a Data Acquisition API (DAQ) that supports many different
packet access methods including libpcap, netfilterq, IPFW, and
afpacket. For libpcap, version 1.0 or higher is now required.
The DAQ library can be updated independently from Snort and is
a separate module that Snort links to.
* A new rule option 'byte_extract' that allows extracted values to
be used in subsequent rule options for isdataat, byte_test,
byte_jump, and content distance/within/depth/offset.
* Two new rule options to support base64 decoding of certain pieces
of data and inspection of the base64 data via subsequent rule
options.
* Added a new pattern matcher that supports Intel's Quick Assist
Technology for improved performance on supported hardware
platforms. Visit http://www.intel.com to find out more about
Intel Quick Assist.
[*] Improvements
* Updates to HTTP Inspect to extract and log IP addresses from
X-Forward-For and True-Client-IP header fields when Snort generates
events on HTTP traffic.
* Updates to SMTP preprocessor to support MIME attachment decoding
across multiple packets.
* Updates to the Snort packet decoders for IPv6 for improvements to
anomaly detection.
...and now some cut and paste from the release notes! Download it now!
http://www.snort.org/snort-downloads
[*] New Additions
* Feature rich IPS mode including improvements to Stream for
inline deployments. Additionally a common active response API is
used for all packet responses, including those from Stream,
Respond, or React. A new response module, respond3, supports the
syntax of both resp & resp2, including strafing for passive
deployments. When Snort is deployed inline, a new preprocessor
has been added to handle packet normalization to allow Snort
to interpret a packet the same way as the receiving host.
* Use of a Data Acquisition API (DAQ) that supports many different
packet access methods including libpcap, netfilterq, IPFW, and
afpacket. For libpcap, version 1.0 or higher is now required.
The DAQ library can be updated independently from Snort and is
a separate module that Snort links to.
* A new rule option 'byte_extract' that allows extracted values to
be used in subsequent rule options for isdataat, byte_test,
byte_jump, and content distance/within/depth/offset.
* Two new rule options to support base64 decoding of certain pieces
of data and inspection of the base64 data via subsequent rule
options.
* Added a new pattern matcher that supports Intel's Quick Assist
Technology for improved performance on supported hardware
platforms. Visit http://www.intel.com to find out more about
Intel Quick Assist.
[*] Improvements
* Updates to HTTP Inspect to extract and log IP addresses from
X-Forward-For and True-Client-IP header fields when Snort generates
events on HTTP traffic.
* Updates to SMTP preprocessor to support MIME attachment decoding
across multiple packets.
* Updates to the Snort packet decoders for IPv6 for improvements to
anomaly detection.
Tuesday, September 28
OpenFPC, in other words, Leon is a Ninja
I put this up to basically draw attention to this project. Leon (a fellow Sourcefire employee and Ninja over in the UK) can explain the project much better than I can, so I'll let him:
Full packet capture is something that has been suggest as the answer to all by many. I don't disagree, it does aid in the forensic investigation of traffic. Heck I do it at my house (full packet capture). I find this idea to very intuitive and interesting, especially the search capabilities.
To be honest, I've seen something like this before when I worked for the military. I don't want to disclose where or what agency was using this, but it was vastly helpful when we wanted to investigate something.
We used Snort and another IDS to prompt us to look for something and we'd start going through the full packet captures to investigate it. I got the idea for this from another Army agency that had a GUI for it, and the whole nine yards. I thought it was a beautiful system and it worked great. I was quite impressed.
Anyway, I'm glad to see that Leon is making a tool like this Open-Source. I think this is a phenomenal idea, and I'd like to see something like this used in a test-production network system somewhere, just to prove how useful it could be.
OpenFPC.
OpenFPC is a set of tools that combine to provide a lightweight full-packet network traffic recorder & buffering system. It's design goal is to allow non-expert users to deploy a distributed network traffic recorder on COTS hardware while integrating into existing alert and log management tools.OpenFPC is described as lightweight because it follows a different design model to other FPC/Network traffic forensic tools that I have seen. It doesn't provide a user with the ability to trigger automatic events (IDS-like functions), or set watch events for anomalous traffic changes (NBA-like functions) as it is assumed external open source, or comercial tools already provide this detection capability. OpenFPC fits in as a companion to provide extra (full packet/traffic stream) data as a bolt-on to these tools allowing deeper analysis of event data where required.
Full packet capture is something that has been suggest as the answer to all by many. I don't disagree, it does aid in the forensic investigation of traffic. Heck I do it at my house (full packet capture). I find this idea to very intuitive and interesting, especially the search capabilities.
To be honest, I've seen something like this before when I worked for the military. I don't want to disclose where or what agency was using this, but it was vastly helpful when we wanted to investigate something.
We used Snort and another IDS to prompt us to look for something and we'd start going through the full packet captures to investigate it. I got the idea for this from another Army agency that had a GUI for it, and the whole nine yards. I thought it was a beautiful system and it worked great. I was quite impressed.
Anyway, I'm glad to see that Leon is making a tool like this Open-Source. I think this is a phenomenal idea, and I'd like to see something like this used in a test-production network system somewhere, just to prove how useful it could be.
OpenFPC.
Monday, September 27
Let me tell you about my past two weeks
The past couple weeks I've had the opportunity to do some really amazing work, something that most people, if they could do, would understand a lot more of what goes on behind the veiled curtain.
The last two weeks I worked for Sourcefire's Vulnerability Research Team (VRT).
First I'd like to say that I've never worked with a more professional organization. Period. I came in to do some technical work with them, which consisted of analyzing hundreds of pcaps, tons of analysis, and as a result writing rules for those threats. We did, kind of a tech exchange type of thing.
Now, we weren't shooting in the dark. (even though there is no overhead lighting in the VRT offices, and you have to watch for getting hit in the head with a Nerf dart) The VRT doesn't take the random vulnerability or exploit found on exploit-db.com or milw0rm or whatever, and just bang out a rule for it. They do labor intensive work.
For instance, I had to write a rule for a vulnerability in a piece of software that had to do with email. In order to test of this vulnerability, could I have taken a piece of a malicious attachment, or looked for a malicious attachment and written a "signature" to check for the exploit here. Sourcefire's standard is higher than that. We try to not do that kind of thing. We try and write a rule to look for the vulnerability itself. For example: If the vulnerability is actually the fact that a certain field, if it's over 512 bytes, can be used to overflow a buffer in the software, looking for a series of "A"s isn't going to work. Looking to see if the field is bigger than 512 bytes is the correct way to do it.
But I digress….
The easiest way to emulate this problem is to send an email with an attachment on it, and capture the pcap, then pick it apart from there. The problem with that is, most email (well at least Sourcefire's) is encrypted. So, I got with one of the other VRT guys and we came up with a solution.
Write an email delivery system.
So he did. It's in ruby, and it allows you to send an email, just like any other email client would, unencrypted, and much faster and more reliable than a regular email client would, if we were trying to trick the client into doing something.
We took the ruby script that he wrote, made it attach a file in base64, and captured the pcap. Now, you may ask me a question, "Heck, why didn't you just make a new email with Outlook Express and make an attachment and send it?" Because Outlook Express uses a different attachment system, it's crackheaded, and it's non-standard. Don't believe me? Send an email with Outlook and then send an email with Outlook Express and compare the two pcaps.
So I captured the pcap -- that's all well and good, except that I noticed that the checksums in the pcap was wrong. Sometimes when you capture traffic on an interface, on certain OSes, it will capture the traffic before the checksum is computed, so it will write to disk incorrectly. So that has to be corrected before you can write a rule to look for the vulnerability.
So, I used tcprewrite to correct the checksums on the packet, and off I went from there.
Now, you come up with the realization that this happens, sometimes 10-20x a day for the VRT, and you come to realize that the rules that are written by these guys are very professional and come with a higher degree of accuracy and purpose.
I'd like to thank the VRT to allowing me to come in and learn and share with them. I hope I helped them out as much as they helped me.
Final thought -- Take your time when writing your rules. The time spent writing them makes for a much more reliable rule than just banging out a rule…. and I have seen a lot of "just banging out a quick rule" lately. A quick rule usually isn't a rule. It's a signature. There is a difference.
Oh, and whomever wrote the Microsoft Word and Excel standard is a crazy crack smoker.
Long live Razorback.
The last two weeks I worked for Sourcefire's Vulnerability Research Team (VRT).
First I'd like to say that I've never worked with a more professional organization. Period. I came in to do some technical work with them, which consisted of analyzing hundreds of pcaps, tons of analysis, and as a result writing rules for those threats. We did, kind of a tech exchange type of thing.
Now, we weren't shooting in the dark. (even though there is no overhead lighting in the VRT offices, and you have to watch for getting hit in the head with a Nerf dart) The VRT doesn't take the random vulnerability or exploit found on exploit-db.com or milw0rm or whatever, and just bang out a rule for it. They do labor intensive work.
For instance, I had to write a rule for a vulnerability in a piece of software that had to do with email. In order to test of this vulnerability, could I have taken a piece of a malicious attachment, or looked for a malicious attachment and written a "signature" to check for the exploit here. Sourcefire's standard is higher than that. We try to not do that kind of thing. We try and write a rule to look for the vulnerability itself. For example: If the vulnerability is actually the fact that a certain field, if it's over 512 bytes, can be used to overflow a buffer in the software, looking for a series of "A"s isn't going to work. Looking to see if the field is bigger than 512 bytes is the correct way to do it.
But I digress….
The easiest way to emulate this problem is to send an email with an attachment on it, and capture the pcap, then pick it apart from there. The problem with that is, most email (well at least Sourcefire's) is encrypted. So, I got with one of the other VRT guys and we came up with a solution.
Write an email delivery system.
So he did. It's in ruby, and it allows you to send an email, just like any other email client would, unencrypted, and much faster and more reliable than a regular email client would, if we were trying to trick the client into doing something.
We took the ruby script that he wrote, made it attach a file in base64, and captured the pcap. Now, you may ask me a question, "Heck, why didn't you just make a new email with Outlook Express and make an attachment and send it?" Because Outlook Express uses a different attachment system, it's crackheaded, and it's non-standard. Don't believe me? Send an email with Outlook and then send an email with Outlook Express and compare the two pcaps.
So I captured the pcap -- that's all well and good, except that I noticed that the checksums in the pcap was wrong. Sometimes when you capture traffic on an interface, on certain OSes, it will capture the traffic before the checksum is computed, so it will write to disk incorrectly. So that has to be corrected before you can write a rule to look for the vulnerability.
So, I used tcprewrite to correct the checksums on the packet, and off I went from there.
Now, you come up with the realization that this happens, sometimes 10-20x a day for the VRT, and you come to realize that the rules that are written by these guys are very professional and come with a higher degree of accuracy and purpose.
I'd like to thank the VRT to allowing me to come in and learn and share with them. I hope I helped them out as much as they helped me.
Final thought -- Take your time when writing your rules. The time spent writing them makes for a much more reliable rule than just banging out a rule…. and I have seen a lot of "just banging out a quick rule" lately. A quick rule usually isn't a rule. It's a signature. There is a difference.
Oh, and whomever wrote the Microsoft Word and Excel standard is a crazy crack smoker.
Long live Razorback.
Friday, September 10
Verizon Rumored To Replace Google With Bing On All Android Devices
Yesterday, Spetember 9th, Verizon gave a preview to their newest "Android" phone coming out for their network, Samsung's Galaxy S.
It has a 4-in AMOLED screen, 1GHZ Hummingbird Processor, and it has the ability to become a hotspot. However, Verizon has ruined the phone, and may ruin every phone on their network from now on. Why?
The thing that makes Android great is it's integration. Google built the OS, it's integrated into Google's infrastructure, and that's the way it works best. Just like the iPhone, which works best with Apple's infrastructure (MobileMe, iTunes, etc).
Verizon has decided to cripple this phone by instead of tying it to Google, they have tied it to Bing. Bing Search, Bing Maps, and instead of Google's awesome navigation app, they have replaced it with Verizon's own Navigation app, which, btw, they cleverly charge you 10 bucks a month to use.
Bloatware.. Blockbuster apps, Tetris apps that charge you money, etc.
To make it worse, Verizon has stated that they will be moving all of their "Droid" line to Bing. It won't be exclusive, (meaning you can switch everything back to Google), but this is basically how to ruin a franchise. (Verizon having Android on everything.)
This is where Verizon did it wrong with the iPhone as well. When Apple came to Verizon and said "We are going to make a phone, you can be the carrier, but you can't put any apps or logos or anything on it" Verizon said No. So Apple went to Cingular (which later was bought by AT&T). Cingular agreed, therefore the iPhone is on AT&T right now.
Apple's iPhone doesn't have bloatware (unless you count the apps that Apple puts on there themselves, which, I can understand your argument), it starts off with Google as the search engine by default, but you have the option to change it.
The iPhone doesn't force you to use a service, they force you to use the apps that are built in (unless you download new ones), like the "Maps" application, it's Google Maps and Google Search, but you'd almost never know it. So far Apple hasn't ruined it, but we'll see.
Verizon may be ruining a good thing here. Hopefully they don't.
Here's Gizmodo's review as well: here.
Verizon Rumored To Replace Google With Bing On All Android Devices | Markets | Minyanville.com.
It has a 4-in AMOLED screen, 1GHZ Hummingbird Processor, and it has the ability to become a hotspot. However, Verizon has ruined the phone, and may ruin every phone on their network from now on. Why?
The thing that makes Android great is it's integration. Google built the OS, it's integrated into Google's infrastructure, and that's the way it works best. Just like the iPhone, which works best with Apple's infrastructure (MobileMe, iTunes, etc).
Verizon has decided to cripple this phone by instead of tying it to Google, they have tied it to Bing. Bing Search, Bing Maps, and instead of Google's awesome navigation app, they have replaced it with Verizon's own Navigation app, which, btw, they cleverly charge you 10 bucks a month to use.
Bloatware.. Blockbuster apps, Tetris apps that charge you money, etc.
To make it worse, Verizon has stated that they will be moving all of their "Droid" line to Bing. It won't be exclusive, (meaning you can switch everything back to Google), but this is basically how to ruin a franchise. (Verizon having Android on everything.)
This is where Verizon did it wrong with the iPhone as well. When Apple came to Verizon and said "We are going to make a phone, you can be the carrier, but you can't put any apps or logos or anything on it" Verizon said No. So Apple went to Cingular (which later was bought by AT&T). Cingular agreed, therefore the iPhone is on AT&T right now.
Apple's iPhone doesn't have bloatware (unless you count the apps that Apple puts on there themselves, which, I can understand your argument), it starts off with Google as the search engine by default, but you have the option to change it.
The iPhone doesn't force you to use a service, they force you to use the apps that are built in (unless you download new ones), like the "Maps" application, it's Google Maps and Google Search, but you'd almost never know it. So far Apple hasn't ruined it, but we'll see.
Verizon may be ruining a good thing here. Hopefully they don't.
Here's Gizmodo's review as well: here.
Verizon Rumored To Replace Google With Bing On All Android Devices | Markets | Minyanville.com.
Wednesday, September 8
Friday, August 27
Why I haven't written
Thursday, August 12
Start with a cage containing five monkeys.
Start with a cage containing five monkeys.
Inside the cage, hang a banana on a string and place a set of stairs under it. Before long, a monkey will go to the stairs and start to climb towards the banana. As soon as he touches the stairs, spray all of the other monkeys with cold water. After a while, another monkey makes an attempt with the same result - all the other monkeys are sprayed with cold water. Pretty soon, when another monkey tries to climb the stairs, the other monkeys will try to prevent it.
Now, put away the cold water.
Remove one monkey from the cage and replace it with a new one. The new monkey sees the banana and wants to climb the stairs. To his surprise and horror, all of the other monkeys attack him. After another attempt and attack, he knows that if he tries to climb the stairs, he will be assaulted.
Next, remove another of the original five monkeys and replace it with a new one. The newcomer goes to the stairs and is attacked. The previous newcomer takes part in the punishment with enthusiasm! Likewise, replace a third original monkey with a new one, then a fourth, then the fifth. Every time the newest monkey takes to the stairs, he is attacked. Most of the monkeys that are beating him have no idea why they were not permitted to climb the stairs or why they are participating in the beating of the newest monkey.
After replacing all the original monkeys, none of the remaining monkeys have ever been sprayed with cold water. Nevertheless, no monkey ever again approaches the stairs to try for the banana.
Why not?
Because as far as they know that's the way it's always been done around here.
And that, my friends, is how policy begins.
-- Don't know the original author or where this came from, but it was posted on a Listserv I belong to, and I thought it was great. If anyone knows where this originally came from, please post in the comments so I can attribute it.
However, I think this really exemplifies some points that I've said for years. Just because "That's the way it's always been" doesn't mean that's the way it always needs to be done. Examine the status quo, and if you can try and make it better, do so.
Thursday, August 5
Security for the SMB makes sense, by Jason Brvenik
Security for the SMB makes sense.
I was off reading some older articles written on a couple of blogs that I follow looking for something in particular. Well, I never did find what i was looking for (in regards to the article itself), but I did reread this post by Jason Brvenik over at Snort.org.
This is a great article in response to another article about why small business shouldn't invest in IPS (which is a crazy view). Jason really does a nice job of laying out the reasons why its important. Definitely worth the read, or reread if you've seen it before.
Google Wave, it's dead. So sad.
In case you haven't heard.
So, on Google's "Official" Blog (which one guys? You have so many!) they announced yesterday that they are pulling the plug on Google Wave.
So sad.
I think Wave had some really good potential, but I'll say it here, as I have said it since the beginning, Wave would have never caught on unless it replaced something else. Wave was pretty neat, it was like a Wiki, Google Docs, Gmail, Gtalk, and god-knows-what-else all rolled into one. It worked, it worked pretty well. But it didn't replace anything for anyone. It was a "and also" technology.
Let's Hope
Google rolls some of the technology they developed for Wave into the rest of their products. For instance, simultaneous typing. That could be useful in Gmail and Gtalk.
I think the collaboration-on-documents idea was great. That would be most useful in a corporate setting. I would have loved to use it at Sourcefire.
Design
Some of their design ideas were great.
In a way, I'm kind of sad to see Wave go. There was a lot of really great ideas there. I enjoyed using it.
However, I can totally see how it didn't work for some people. It was confusing. People didn't understand how it was different from anything else they used. As I said, it didn't replace anything they already had, it didn't have a "need". When the iPhone was invented people immediately saw the "need" for it. A phone that is brilliantly easy to use. It also replaced things. It replaced their phone, it replaced their blackberry. It was simple.
Wave wasn't simple. It didn't replace anything, and that is why it failed. People don't need another email system. In fact, they need less.
Tuesday, August 3
Now that I have these IDS events, now what?
In my full-time job I work for Sourcefire, as a Sourcefire and Snort Professional Services Consultant. I deal with a different customer every week (sometimes every day), and with each customer comes a separate set of IDS events. Customers will often tell me "this network is unlike any you've ever seen before", and for the most part, they are right. While all networks consist of servers, desktops, switches, routers, firewalls, antivirus, and even IDSes, all networks are essentially the same in that respect. However, each of them pose their own unique set up and vulnerability attack-landscape. Each network is unique in this way, it doesn't matter if you have 300,000 users on your network or 10. All that does is make your life as a security person more difficult, this is essentially a number. That number may increase lots of things, people hired to handle them, number of sensors needed, the amount of bandwidth needed, etc.
So, in dealing with the hundreds, perhaps hundreds of thousands, perhaps millions of IDS events that I see during the day on different networks, how do I deal with them? How can I get into a customer engagement and turn 400,000 events a day into 100? How do I help my customers deal with this?
My answer is: One at a time.
How do I do it? Well, I take the same fundamentals as I have applied to Getting Things Done and Inbox Zero (mostly the latter) to IDS events. In other words, for each IDS or IPS event, there is at least one (maybe multiple) outcome(s) to that event. While yes, that may seem redundant, (and it is) my point in saying that is that there should always be an outcome to any IDS event. It shouldn't just sit. You shouldn't just be "moving events to archive".
You can kind of think this as a flow chart.
First -> Look at the event, let's use this event as an example:
Analyze it in context, what does this event mean? It means someone is watching a flash video on the internet. Okay, big deal right? Is that allowed by policy? Look at the packet data, is it from youtube? Is watching YouTube from the corporate network allowed? Perhaps if you are on a Government network, this isn't allowed, okay, so what next? Do I need to look at the flows around it recorded by Netflow or RNA? Do I need to look at my SIEM tool?
Second, Now comes where you ask "what relevancy does this have to my network?" If it's a Sourcefire protected network (read: not Snort) then you might have RNA to help you perform this function. How is the impact rating on the alert? Is it high? Is the end host vulnerable to this "exploit"? The impact rating for the above event is probably pretty high, since every browser on every OS (for the most part) can watch a flash video. How old is the rule or alert? Does it cover a CVE that was patched in 2002?
Now that we know what the event is, and what relevancy it has to our network, what are we going to do about it? Well, I view this has having about four possible outcomes. Of course, this is related to Snort, so your IPS may vary. But all IPSes get better with tuning, so...
This only works if you are in IPS mode, should you change the rule to drop? Do you want the traffic to go into the big bit bucket in the sky? Prevent that FLV file from being downloaded? Prevent that PDF from being downloaded, prevent that newest browser exploit? If you are in IPS mode, this is your second question after you analyze the event.
Thresholding in Snort essentially means you still want the rule to alert, but not as much. Or not until a certain threshold is reached (or both). Suppressing means you want to turn off alerting to a certain IP or CIDR block. Say for instance an SNMP alert going to your HP OpenView server. Legit traffic, so tune it out.
Probably something you want to stay away from as much as possible, unless you editing your own rules. But it's always an option to edit the rule manually to reduce false positives.
Is the rule out of date? Do none of the above apply? Has it no relevance to your network? For instance, using our above example, if watching flash videos is allowed on the network, and you don't want to track to see if people are doing that kind of thing, then shut the rule off. If you aren't going to use the final step in this process (DO SOMETHING) then do you need the rule?
Some rules will make no sense on their own, but they may provide a contextual awareness to other rules. For instance, if there was a rule to watch for vulnerabilities within a certain flash video file format to exploit older versions of the flash player, that rule coupled with the above example, may provide better contextually aware alerts. You know the video was bad, but now you can refer back to the above example and perhaps see where the alert came from. Kind of a bad example, because you could do it either way, but hopefully you grasp my point.
This requires you to go mitigate the problem. Whether that be to "file a ticket" for your helpdesk to clean off spyware, clean up a botnet, perhaps you'll need to pull forensics on the host machine, perhaps you'll need to pull web proxy logs to get better awareness. But this is the step where you actually have to use the alerts generated by your IDS to do your job. Find the bad guy, eradicate the badness from the network, and move onto the next alert. After all, that's the point of having an IDS or IPS right?
Following these simple steps should allow you to have a greater awareness of the alerts on the network, and perhaps actually do something about them. Getting an IDS alert and then "moving it to archive" or "marking it as reviewed" is doing nothing. Following the above ACTION steps should give you a more streamlined IDS or IPS, and then only cause your system to alerts when you need to conduct step 6, above. DO SOMETHING.
So, in dealing with the hundreds, perhaps hundreds of thousands, perhaps millions of IDS events that I see during the day on different networks, how do I deal with them? How can I get into a customer engagement and turn 400,000 events a day into 100? How do I help my customers deal with this?
My answer is: One at a time.
How do I do it? Well, I take the same fundamentals as I have applied to Getting Things Done and Inbox Zero (mostly the latter) to IDS events. In other words, for each IDS or IPS event, there is at least one (maybe multiple) outcome(s) to that event. While yes, that may seem redundant, (and it is) my point in saying that is that there should always be an outcome to any IDS event. It shouldn't just sit. You shouldn't just be "moving events to archive".
You can kind of think this as a flow chart.
First -> Look at the event, let's use this event as an example:
POLICY Adobe FLV file transferAnalyze it in context, what does this event mean? It means someone is watching a flash video on the internet. Okay, big deal right? Is that allowed by policy? Look at the packet data, is it from youtube? Is watching YouTube from the corporate network allowed? Perhaps if you are on a Government network, this isn't allowed, okay, so what next? Do I need to look at the flows around it recorded by Netflow or RNA? Do I need to look at my SIEM tool?
Second, Now comes where you ask "what relevancy does this have to my network?" If it's a Sourcefire protected network (read: not Snort) then you might have RNA to help you perform this function. How is the impact rating on the alert? Is it high? Is the end host vulnerable to this "exploit"? The impact rating for the above event is probably pretty high, since every browser on every OS (for the most part) can watch a flash video. How old is the rule or alert? Does it cover a CVE that was patched in 2002?
Now that we know what the event is, and what relevancy it has to our network, what are we going to do about it? Well, I view this has having about four possible outcomes. Of course, this is related to Snort, so your IPS may vary. But all IPSes get better with tuning, so...
- If you are in IPS mode, do you want to block it or not?
- Threshold or Surpress?
- Edit the rule manually?
- Shut the rule off?
- Does it provide relevance to other rules?
- DO something about the alert.
1. Set the rule to drop.
This only works if you are in IPS mode, should you change the rule to drop? Do you want the traffic to go into the big bit bucket in the sky? Prevent that FLV file from being downloaded? Prevent that PDF from being downloaded, prevent that newest browser exploit? If you are in IPS mode, this is your second question after you analyze the event.
2. Threshold or Suppress?
Thresholding in Snort essentially means you still want the rule to alert, but not as much. Or not until a certain threshold is reached (or both). Suppressing means you want to turn off alerting to a certain IP or CIDR block. Say for instance an SNMP alert going to your HP OpenView server. Legit traffic, so tune it out.
3. Edit the rule.
Probably something you want to stay away from as much as possible, unless you editing your own rules. But it's always an option to edit the rule manually to reduce false positives.
4. Turn the rule off.
Is the rule out of date? Do none of the above apply? Has it no relevance to your network? For instance, using our above example, if watching flash videos is allowed on the network, and you don't want to track to see if people are doing that kind of thing, then shut the rule off. If you aren't going to use the final step in this process (DO SOMETHING) then do you need the rule?
5. Is the rule providing you contextually aware information?
Some rules will make no sense on their own, but they may provide a contextual awareness to other rules. For instance, if there was a rule to watch for vulnerabilities within a certain flash video file format to exploit older versions of the flash player, that rule coupled with the above example, may provide better contextually aware alerts. You know the video was bad, but now you can refer back to the above example and perhaps see where the alert came from. Kind of a bad example, because you could do it either way, but hopefully you grasp my point.
6. DO SOMETHING.
This requires you to go mitigate the problem. Whether that be to "file a ticket" for your helpdesk to clean off spyware, clean up a botnet, perhaps you'll need to pull forensics on the host machine, perhaps you'll need to pull web proxy logs to get better awareness. But this is the step where you actually have to use the alerts generated by your IDS to do your job. Find the bad guy, eradicate the badness from the network, and move onto the next alert. After all, that's the point of having an IDS or IPS right?
Following these simple steps should allow you to have a greater awareness of the alerts on the network, and perhaps actually do something about them. Getting an IDS alert and then "moving it to archive" or "marking it as reviewed" is doing nothing. Following the above ACTION steps should give you a more streamlined IDS or IPS, and then only cause your system to alerts when you need to conduct step 6, above. DO SOMETHING.
Monday, August 2
New Digg Interface Invites
I have a couple posts brewing in my head that I need to get down on paper, but in the meantime, I have 5 invites for the new Digg.com interface if anyone wants them.
First five people to send me their email address get them.
First five people to send me their email address get them.
Subscribe to:
Posts (Atom)
-
Without going off the deep-end here and discussing every single Snort rule keyword, I just wanted to touch on a few modifiers that people so...
-
Let me start off by saying I'm not bashing the writer of this article, and I'm trying not to be super critical. I don't want to...
-
Recently I needed the ability to grab a domain name (specifically the hostname) out of a URL using Shortcuts. I wanted to integrate this f...