Recommended Posts

you do understand that both wannacry and petyas are just exploits to something the user did not patch and most likely should not have been running for years anyway.  SMBv1 should of been disabled on your machines years ago ;)  Especially from a security point of view.

 

What you should take away from such things is, keep your stuff up to date with security patches.  Do not run old protocols that you do not actually need/use..  And make sure you have valid and current backup plan ;)

 

edit: From a IDS/IPS point of view that would run at your edge or at your core router in your network, not really on the host..  There are HIDS, or Host intrusion Detection Systems.  The two opensource or free versions that I am aware of are OSSEC and Tripwire had/has an opensource version and there is AIDE as well..

 

https://ossec.github.io/

 

Is the only one that I know of that would run on windows would be ossec, but then only as an agent.  You could also run and agent on alienvaults OSSIM, but this is more really a SIEM and also has a windows agent.  A SIEM would be part of any actual network..  But your not really going to find many deployed in a typical home setup ;)  While I run one - my home network is not in any way or form "typical" hehehe

 

For your typical home users yeah your best sort of solution would be something like malwarebytes.. But I would not really classify that as any sort of IDS or HIDS even..

 

If you ran say a router/firewall distro like pfsense, or ipcop or smoothwall, etc.. Then they have IDS/IPS that run on them snort and suricata.  Keep in mind that running such systems have a huge learning curve and if not correctly setup and maintain will either flood you with false positive (noise) or can pretty much break your network from being to do the stuff you want to do ;)

 

 

  • Like 4
9 hours ago, Mindovermaster said:

Otherwise, use Linux! :laugh:

Just last month, there were reports or Erebus resurfacing as a Linux variant of ransomware. Every OS has their flaws, it is a matter of staying up to date and doing your due diligence as the user. Just because you're using linux, doesn't make you impenetrable. Ever heard of Linux.Encoder.1?

40 minutes ago, Circaflex said:

Just last month, there were reports or Erebus resurfacing as a Linux variant of ransomware. Every OS has their flaws, it is a matter of staying up to date and doing your due diligence as the user. Just because you're using linux, doesn't make you impenetrable. Ever heard of Linux.Encoder.1?

That was a joke, if you didn't notice. Every OS is vulnerable. I wasn't boasting...

  • Like 1

Hello,


Malware-based (or derived) intrusion detection/prevention has been a basic feature of most security suites for years.  The name of the feature set(s) which provide it vary between vendors, but pretty much every vendor out there has some kind of security layer which does this.

 

Regards,

 

Aryeh Goretsky

 

  • Like 1

What the security suites need to do is stop the user from doing what they want and force them to PATCH Their systems ;)

 

Sorry that is enough p0rn for you now - time to reboot to patch!

  • Like 2

Hello,

 

The anti-malware software that I use warns me when one of my systems is missing Windows updates.  I suspect it isn't unique in this, though I don't know how common a feature it is.

Regards,

Aryeh Goretsky

 

 

20 hours ago, BudMan said:

What the security suites need to do is stop the user from doing what they want and force them to PATCH Their systems ;)

 

Sorry that is enough p0rn for you now - time to reboot to patch!

 

On 7/17/2017 at 8:33 PM, BudMan said:

you do understand that both wannacry and petyas are just exploits to something the user did not patch and most likely should not have been running for years anyway.  SMBv1 should of been disabled on your machines years ago ;)  Especially from a security point of view.

 

What you should take away from such things is, keep your stuff up to date with security patches.  Do not run old protocols that you do not actually need/use..  And make sure you have valid and current backup plan ;)

 

edit: From a IDS/IPS point of view that would run at your edge or at your core router in your network, not really on the host..  There are HIDS, or Host intrusion Detection Systems.  The two opensource or free versions that I am aware of are OSSEC and Tripwire had/has an opensource version and there is AIDE as well..

 

https://ossec.github.io/

 

Is the only one that I know of that would run on windows would be ossec, but then only as an agent.  You could also run and agent on alienvaults OSSIM, but this is more really a SIEM and also has a windows agent.  A SIEM would be part of any actual network..  But your not really going to find many deployed in a typical home setup ;)  While I run one - my home network is not in any way or form "typical" hehehe

 

For your typical home users yeah your best sort of solution would be something like malwarebytes.. But I would not really classify that as any sort of IDS or HIDS even..

 

If you ran say a router/firewall distro like pfsense, or ipcop or smoothwall, etc.. Then they have IDS/IPS that run on them snort and suricata.  Keep in mind that running such systems have a huge learning curve and if not correctly setup and maintain will either flood you with false positive (noise) or can pretty much break your network from being to do the stuff you want to do ;)

 

 

Now this was helpful. And yes I also agree that patching mostly does the purpose but I also think that a normal not so techy user must have a system installed that alerts any malware detection since they are becoming so much common. 

On 2017-07-17 at 5:33 PM, BudMan said:

If you ran say a router/firewall distro like pfsense, or ipcop or smoothwall, etc.. Then they have IDS/IPS that run on them snort and suricata.  Keep in mind that running such systems have a huge learning curve and if not correctly setup and maintain will either flood you with false positive (noise) or can pretty much break your network from being to do the stuff you want to do ;)

+1.

I am in the middle of planning to replace my ASA5505 to a pfSense, as this little ASA doesn't have Gig ports, though I haven't found the suitable Mini PC yet. (don't wannt spend too much on it)

4 minutes ago, BudMan said:

What is your budget?

Don't want to hijack this thread but if you meant my budget, I am thinking between 100/150$. I want one of those little mini-itx fanless box with at least 2 gig ports.

Well for $149 you could buy the sg-1000, official box from pfsense, that has 2 gig nics ;)   If your thinking of running pfsense anyway would be good option.

 

https://www.netgate.com/products/sg-1000.html

I have heard it's laggy and if I remember correct it doesn't support traffic shaping, not that I will do traffic shaping, but I like to have that option for learning purposes. ;)

  • Like 1

They resolved that a while ago I do believe, in the 2.4 beta's  Had to do with the drivers not supporting altq

https://redmine.pfsense.org/issues/7199

 

but you could of worked around it with vlans..

On 7/19/2017 at 3:32 PM, wendy oltman said:

Now this was helpful. And yes I also agree that patching mostly does the purpose but I also think that a normal not so techy user must have a system installed that alerts any malware detection since they are becoming so much common. 

now if only windows forced security patches....... :) combined with something along the lines of Sophos home AV/UTM 

https://home.sophos.com/ 

 

its free for home use.

 

i use my isps ability to filter websites also at the ISP level to sites that are deemed "risky" combined with Webroot Secure anywhere personally. As well as running each users account as a limited user and UAC when and if i need elevated privs.

I kept wannacrypt etc outside of work and at home by 1) patching regularly 2) disabling SMb 1.0 and 3) end user UTM. 4) up to date AV from a good vendor. 5) denying anyone (especially other IT staff) running as adm 24/7.

 

item 5 was the hardest to  implement at work, someone who should know better, but doesn't, same mindset as dont patch Ms stuff, they just break things..../faceplant. Wannacrypt demonstrated how wrong they were.

Edited by Mando
  • Like 1

 

On 7/25/2017 at 1:52 AM, BudMan said:

They resolved that a while ago I do believe, in the 2.4 beta's  Had to do with the drivers not supporting altq

https://redmine.pfsense.org/issues/7199

 

but you could of worked around it with vlans..

Have you been using it? 

On 7/25/2017 at 2:12 AM, Mando said:

5) denying anyone (especially other IT staff) running as adm 24/7.

What impact does this make? 

I have been using the 2.4 beta's for quite some time at home update to current snap every few days, week at the most.  I have no need for any traffic shaping on my network.. So no I have not played with it in 2.4 beta's... I don't have a sg-1000 to play with I run my pfsense at home VM.  I could play with a sg-2440 at work, we are planning on replacing all our old juniper firewall/routers in branch locations here in the US with those..  First 1 has been running in NY office for a while.. Been rock solid, but it has no need for traffic shaping either they have a pretty fat pipe for what its used for and have never seen any issues or need for traffic shaping..  The old juniper couldn't even do 100mbps - now with the pfsense actually getting what we are paying for on that pipe, over even testing we did was over 300mbps.

 

If your not saturating your pipe - traffic shaping can be pointless.  And just cause you slowness and pain when there is no call for it.. If the pipe was new capacity and it carried traffic that needed to be prioritized then ok.  But that is not the case for these connections.

 

What impact does not running admin on your box for doing day to day?  This can be HUGE protection.. You should not be using god account for your day to day stuff.  Say your account is domain admin, which your logged into your machine with... While sure it makes it easy to access pretty much anything at any time.  If you get hit, whatever hit you now can hit anything on your network as god.. Not a good thing ;)  Shoot for that matter a simple mistake on your part and there goes all the user files on a share because you hit the wrong key ;)

 

Min security needed to perform the function is security 101, using your root/god account when your not in god mode is bad idea from any way you look at it..

  • Like 2
2 hours ago, wendy oltman said:

 

What impact does this make? 

Wannacrypt and most ransomware requires admin rights to encrypt systemwide, running as limited users minimises the amount of files it can encrypt, if it gets past other layers of protection, its also good security practise never to run with elevated privs day to day, When elevated rights are required, right click run as and enter an admin accounts creds.

 

 in the enterprise it could mean the difference between a minimal number of encrypted files and system wide domain encryption, if the multtiered, multivendor protection is compromised.

  • Like 1
This topic is now closed to further replies.
  • Posts

    • If they ever come out and say the AI is no longer accessible to the gen pop people aren't going to know how to tie their own shoelaces.
    • It's hard not to when they are shoehorning Ai into EVERYTHING. Some are active users by choice, I bet a lot of them are because it's shoved in their face the entire time.
    • Thunderbird 152.0 by Razvan Serea Thunderbird is a free, open-source, cross-platform application for managing email and news feeds. It is a local (rather than a web-based) email application that is powerful yet easy-to-use. Thunderbird is clean and elegant by default, but easily customizable to match your workflow and visual preferences. It is loaded with unique and powerful features. Thunderbird is developed, tested, translated and supported by the folks at Mozilla Corporation and by a group of dedicated volunteers. Thunderbird gives you control and ownership over your email. There are lots of add-ons available for Thunderbird that enable you to extend and customize your email experience. Thunderbird gives you IMAP/POP support, a built-in RSS reader, support for HTML mail, powerful quick search, saved search folders, advanced message filtering, message grouping, labels, return receipts, smart address book LDAP address completion, import tools, and the ability to manage multiple e-mail and newsgroup accounts. Thunderbird 152.0 changelog: SecurityDevices enabled in enterprise policies One-click account setup for Thundermail accounts What’s Changed Use 'Add' instead of 'New' for account, calendar, address book creation buttons GMail OAuth updated to use PKCE Mail server hostname also checked when detecting address books and calendars Updated about:rights to replace local with hosted url 'Hide completed tasks' now also hides cancelled tasks What’s Fixed New mail alerts appeared on wrong monitor in three-monitor setup Spam messages triggered new mail notifications before being moved to Spam folder Filtered IMAP or NNTP subscriptions were lost after closing Subscribe dialog 'Download Headers' dialog for newsgroups failed to open Messages nested deeper than 255 levels disappeared from threading view Performing Delete followed by Undo on thread parent message could corrupt view Single messages still appeared collapsible after thread members were deleted Updated threads remained misordered until folder refresh or resort Non-threaded subject sorting separated 'RE:' replies from original messages BCC recipients were included in signed email headers Filter search on Body missed draft messages containing German umlauts Thunderbird could crash during local message search Blocked file warning showed without 'Unblock File' button in compose window Forwarding/Redirecting Exchange messages failed with NS_ERROR_OUT_OF_MEMORY Compose window closed early and send progress dialog hung after NNTP failure Compose window stayed open after sending when mailnews.sendInBackground set Microsoft OAuth2 failed when HTTPS localhost redirect was not intercepted Pasting contact photos stopped working when photo button had focus Filter dialog lacked focus ring and had poorly distinguishable buttons Subfolder kept stale accessibility unread count after unread messages were deleted 'Edit as New Message' and inline 'Forward' not possible with PGP-signed messages Various MIME improvements EWS messages could go missing from folder view IMAP "Show only subscribed folders" could not be changed without restart Unable to delete more than 1000 messages at a time on Microsoft 365 EWS folders in Trash were moved to Trash again instead of being hard deleted IMAP notifications repeated for emails read on another device after sleep wake POP3 deadlocked when server went silent without closing socket Calendar acceptance no longer distinguished between single occurrence and series Transparent popups on macOS made calendar event editing difficult Duplicate attendees were added to invitations instead of being filtered out Task percentage complete was not preserved separately from status in tooltips Visual and UX improvements Security fixes Download: Thunderbird 152.0 for Windows (EN/US) | 32-bit | ~70.0 MB (Open Source) Download: Thunderbird 152.0 for Mac OS (EN/US) | 145.0 MB Download: Thunderbird 152.0 in other languages View: Thunderbird Website | Screenshot | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Nearly half of American adults now use AI, but concerns are also growing by Hamid Ganji Since the launch of ChatGPT in 2022, the way people research, get their news, and perform routine tasks has changed dramatically. Now, almost everything around us has a touch of AI, and companies are trying to embed it into nearly every product and service they offer. With that in mind, new research shows how Americans are actually adopting this change and using AI in their everyday lives. According to new research conducted by the Pew Research Center, 49% of American adults now use AI chatbots like ChatGPT or Gemini. This marks a significant increase over last year, when only 33% of American adults reported using AI. Additionally, four in ten U.S. adults (42%) said they use AI tools to research information, while 38% said they use these tools to handle tasks at work. Entertainment, image and video editing, and getting medical advice are among the other ways Americans are using AI. Moreover, ChatGPT dominates the U.S. AI market, with 44% of respondents saying they use OpenAI's chatbot. Gemini follows at 24%, while Copilot and Meta AI account for 17% and 14%, respectively. Respondents also said that AI chatbots generally have a positive impact on their productivity and how informed they are. But when it comes to AI’s impact on society, Americans remain largely skeptical. About 40% of American adults believe AI will be more harmful than beneficial to society over the next 20 years. Additionally, 31% expect AI to have a negative effect on them personally. Another 31% of respondents say AI could be equally positive and negative. As for data security, pessimism remains high: 71% of respondents say AI will make their personal information less secure, while only 3% believe it will make their data more secure. American adults also largely lack confidence in both the government and AI companies when it comes to regulating and developing AI. About 67% of Americans have little to no confidence in the U.S. government’s ability to regulate AI effectively. Six in ten adults are also not confident that U.S. companies will develop and use these tools responsibly.
    • MultiOS-USB 0.11.1 by Razvan Serea MultiOS-USB is a versatile, open-source utility designed to create multiboot USB drives capable of hosting multiple operating systems on a single portable device. The project simplifies the process of building a bootable USB by automating the configuration of various boot loaders and file systems, enabling users to install and run diverse operating systems, including Windows, Linux distributions, and diagnostic tools, directly from one drive. It supports ISO booting and persistence, which allows changes made during live sessions to be retained, making it ideal for testing, troubleshooting, or system recovery. Features: BIOS and UEFI support Secure Boot support (boot, manage uefi keys) Load UEFI drivers Launch .efi executables and other boot loaders Boot Linux from .iso images Boot WinPE from bootable .wim images Boot Windows 10/11 installer from ISO (currently, SB must be disabled during installation) Boot Linux installer from network (experimental) Boot locally installed systems: Linux, Windows Automatically update configuration files Without background services exFAT file system support Automatic detection of compatible ISO images (GRUB loopback) Support for systems without loopback support Allows customisation of ISO boot menu (for example: custom kernel options) Support for USB, SSD, nvme, mmcblk, loop, nbd and virtual disks Support for x86, x86_64 A list of tested ISO images can be found here MultiOS-USB 0.11.1 changelog: 68122b7: Fixed-release AUR package #63 fba0283: Update shim to 16.1 8c2ae95: Update grub to v2.14-1 ea15c1d: Update Memtest86+ to v8.10 162f4e6: Add secureblue (#71) b2da8ae: Add AerynOS (#74) ac6640e: Bump config.version 34e9ca6: Add Bluefin (#72) 7a10edd: Add Aurora (#66) cab701b: Update wimboot to v2.9.0-1 90da7f7: Fix Windows error: 0x80070001 - 0x4002F (#52) 2dea73d: Add Microsoft certificates 01f479e: Remove old efi_uga module Download: MultiOS-USB 0.11.1 | 5.3 MB (Open Source) View: MultiOS-USB Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      89
    4. 4
      Steven P.
      76
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!