<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dragos Lungu Dot Com &#187; Uncategorized</title>
	<atom:link href="http://www.dragoslungu.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dragoslungu.com</link>
	<description>Security Tools and Tips</description>
	<lastBuildDate>Tue, 25 Oct 2011 08:16:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Animated Presentation on Sony PSN Hack</title>
		<link>http://www.dragoslungu.com/2011/06/01/animated-presentation-on-sony-psn-hack/</link>
		<comments>http://www.dragoslungu.com/2011/06/01/animated-presentation-on-sony-psn-hack/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 23:25:24 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=389</guid>
		<description><![CDATA[&#160; Last weekend I delivered a presentation in a new graphic way and I must say I got very good feedback. Here it is : &#160; &#160; How to prevent another SONY PS3 Attack .prezi-player { width: 500px; } .prezi-player-links { text-align: center; } How to prevent another SONY PS3 Attack on Prezi]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p>&nbsp;</p>
<p>Last weekend I delivered a presentation in a new graphic way and I must say I got very good feedback. Here it is :</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h1 class="group" style="text-align: center;"><span class="prezi-title">How to prevent another SONY PS3 Attack </span></h1>
<div class="prezi-player">
<p style="text-align: center;">
<style media="screen" type="text/css">.prezi-player { width: 500px; } .prezi-player-links { text-align: center; }</style>
<p><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" height="400" id="prezi_pmqlso3walog" name="prezi_pmqlso3walog" width="550"><param name="movie" value="http://prezi.com/bin/preziloader.swf" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="bgcolor" value="#ffffff" /><param name="flashvars" value="prezi_id=pmqlso3walog&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0" /><embed allowfullscreen="true" allowscriptaccess="always" bgcolor="#ffffff" flashvars="prezi_id=pmqlso3walog&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0" height="400" id="preziEmbed_pmqlso3walog" name="preziEmbed_pmqlso3walog" src="http://prezi.com/bin/preziloader.swf" type="application/x-shockwave-flash" width="550"></embed></object></p>
<div class="prezi-player-links">
<p><a href="http://prezi.com/pmqlso3walog/how-to-prevent-another-sony-ps3-attack/" title="">How to prevent another SONY PS3 Attack</a> on <a href="http://prezi.com">Prezi</a></p>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2011/06/01/animated-presentation-on-sony-psn-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ArcSight Tip #1 &#8211; arcsight managersetup notification test</title>
		<link>http://www.dragoslungu.com/2011/05/11/arcsight-tip-1-arcsight-managersetup-notification-test/</link>
		<comments>http://www.dragoslungu.com/2011/05/11/arcsight-tip-1-arcsight-managersetup-notification-test/#comments</comments>
		<pubDate>Wed, 11 May 2011 12:02:02 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ArcSight]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=383</guid>
		<description><![CDATA[ArcSight tips and tricks ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="" height="73" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/hp-arcsight_weblogo_colorwt[1].gif" vspace="5" width="179" /></p>
<p>In my <a href="http://www.metanet.io/">new job</a> I encounter all sort of issues concerning <a href="http://www.arcsight.com">ArcSight </a>products and I was thinking to post my tips and observations here . </p>
<p><strong>Tip #1 &#8211; careful what address you set as ArcSight Manager sender. </strong><br />
	So, today&#39;s tip is about <strong>managersetup </strong>command. After you&#39;ve set the notification details for the Whine daemon, the config script tests the outgoing email setup. All ok except the fact that this script will send a test email to the same email address set as notification sender and it will ignore all destination addresses you&#39;ve set. I have the SMTP pcap capture to prove it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2011/05/11/arcsight-tip-1-arcsight-managersetup-notification-test/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I&#8217;m a CISSP</title>
		<link>http://www.dragoslungu.com/2010/12/20/im-a-cissp/</link>
		<comments>http://www.dragoslungu.com/2010/12/20/im-a-cissp/#comments</comments>
		<pubDate>Mon, 20 Dec 2010 18:14:02 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=379</guid>
		<description><![CDATA[Dragos Lungu, CISSP]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="Dragos Lungu, CISSP" height="120" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/CISSP.png" vspace="5" width="120" />I just received my CISSP exam results and I passed!&nbsp; Best Christmas present I could get ! </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/12/20/im-a-cissp/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Operation:Payback or Social Vendetta is Here</title>
		<link>http://www.dragoslungu.com/2010/12/08/operationpayback-or-social-vendetta-is-here/</link>
		<comments>http://www.dragoslungu.com/2010/12/08/operationpayback-or-social-vendetta-is-here/#comments</comments>
		<pubDate>Wed, 08 Dec 2010 22:07:14 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Offtopic]]></category>
		<category><![CDATA[Open Mike]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=376</guid>
		<description><![CDATA[In the current DDOS attack on www.visa.com there might be obscure interests and classic botnets involved, but what strikes me is the first ever voluntary botnet made of thousands of home user computers running a bot which is controlled via IRC channels by the attackers. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img align="left" alt="" height="97" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/vendetta.jpg" vspace="5" width="111" />Since <a href="http://en.wikipedia.org/wiki/WikiLeaks">WikiLeaks </a>started their epic disclosure, I have witnessed a lot of new stuff being shaped under our own eyes : socially, technically and nevertheless politically. </p>
<p>Since I&#39;m more of a technical guy, I have seen more <a href="http://www.computerworld.com/s/article/9200481/WikiLeaks_nearly_immune_to_takedown_says_researcher?source=CTWNLE_nlt_security_2010-12-08">DDOS countermeasures</a> than in any &quot;peace-time&quot; projects and today, actually right now I&#39;m watching a live attack on www.visa.com called <strong>Operation:Payback</strong> .</p>
<p>It&#39;s like watching live TV on an ongoing natural disaster, only it&#39;s man made and it gives me the creeps. Or like seeing the movie <a href="http://www.imdb.com/title/tt0434409/">V for Vendetta</a> happening live. </p>
<p>In the current <a href="http://www.huffingtonpost.com/2010/12/08/visa-down-wikileaks-suppo_n_794039.html">DDOS attack on www.visa.com</a> there might be obscure interests and classic botnets involved, but what strikes me is <strong>the first ever voluntary botnet</strong> made of thousands of home user computers running a bot which is controlled via IRC channels by the attackers. </p>
<p>If you want to get involved, the attackers have presented <a href="http://pastehtml.com/view/1c8i33u.html">detailed instructions</a> on how to turn our PC into a voluntary-bot. This is a very scary phenomenon if you think of the combined broadband access available to the current US home computer which is online most of the time.</p>
<p>The result can be seen live on attacker&#39;s <a href="http://twitter.com/#!/anon_operation">twitter page</a></p>
<p>If the twitter account is closed, here&#39;s a live screenshot : </p>
<p style="text-align: center;"><img alt="" height="266" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/cyberwar.jpg" vspace="5" width="361" /></p>
<p>Call me old fashioned but I think something is not right &#8230;&nbsp; distributed computing started with seti@home and cancer research and now&nbsp; ended up on cyber -warfare . maybe this is what we know to do best. </p>
<p>I love and support freedom of speech but I don&#39;t support cyber-vandalism, no matter which is the cause it fights for. There has to be a better way .. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/12/08/operationpayback-or-social-vendetta-is-here/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>I got owned by Malware Destructor 2011 Virus</title>
		<link>http://www.dragoslungu.com/2010/10/22/i-got-owned-by-malware-destructor-2011-virus/</link>
		<comments>http://www.dragoslungu.com/2010/10/22/i-got-owned-by-malware-destructor-2011-virus/#comments</comments>
		<pubDate>Fri, 22 Oct 2010 15:44:55 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Security Incidents]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=372</guid>
		<description><![CDATA[Short post .. After more than 5 years of virus free-happy windows-system I got infected by Malware Destructor 2011 Virus &#8230; In 5 minutes I had no computer anymore. I could not believe this is happening to me but it did.. so I&#39;m in the process of re-installing everything. Mad as hell&#8230; beware of this [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p>Short post .. After more than 5 years of virus free-happy windows-system I got infected by Malware Destructor 2011 Virus &#8230; In 5 minutes I had no computer anymore.</p>
<p>I could not believe this is happening to me but it did.. so I&#39;m in the process of re-installing everything. Mad as hell&#8230;</p>
<p>
	beware of this nasty virus : Malware Destructor 2011 Virus . Very good writeup here :</p>
<p><a href="http://www.articlesbase.com/security-articles/is-malware-destructor-2011-installed-via-automatic-updates-system-security-pack-upgrade-legit-get-rid-malware-destructor-2011-virus-3260021.html"><br />
	http://www.articlesbase.com/security-articles/is-malware-destructor-2011-installed-via-automatic-updates-system-security-pack-upgrade-legit-get-rid-malware-destructor-2011-virus-3260021.html <br />
	</a></p>
<p>that&#39;s life..</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/10/22/i-got-owned-by-malware-destructor-2011-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Downtime Cost Calculator by Storagepipe.com. What if ?</title>
		<link>http://www.dragoslungu.com/2010/09/10/new-downtime-cost-calculator-by-storagepipe-com-what-if/</link>
		<comments>http://www.dragoslungu.com/2010/09/10/new-downtime-cost-calculator-by-storagepipe-com-what-if/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 16:07:46 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=369</guid>
		<description><![CDATA[The lost sales revenue is coupled with the lost productivity so you can instantly get a glimpse of the total accumulated cost as well as predicted hourly loss. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="Downtime Cost Calculator" height="48" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/logo.jpg" vspace="5" width="136" /></p>
<p><em>The Annualized Loss Expectancy (ALE) is the product of the annual rate of occurrence (ARO) and the single loss expectancy. It is mathematically expressed as:</p>
<p>	Annualized Loss Expectancy (ALE) = Annual Rate of Occurrence (ARO) X Single Loss Expectancy (SLE)</em> (<a href="http://en.wikipedia.org/wiki/Annualized_Loss_Expectancy">wikipedia</a>)</p>
<p>	Yes, we all know that famous formula which is used in every Risk Management project. But how accurate is the estimation of the Single Loss Expectancy (SLE)? </p>
<p>	If we speak about downtime, the impact on business processes varies for each company and for each process. One thing is for sure though: if you provide IT services, better deliver an uptime around 99.x% or have a very flexible and loose SLA with your customers. </p>
<p>	You know that uptime is many times a decisive factor in customer retention and in acquiring new business. But what is your actual loss caused by downtime ? I bet you asked this question many times and maybe you even started to draw some complicated math equations. </p>
<p>	That&#39;s one way to do it, if you have time and energy to spend. Another way to do a proper Downtime Cost Simulation is to use the brainpower of computers like I did. </p>
<p>	I just discovered the <a href="http://downtimecost.com/">Downtime Cost Calculator</a> developed by <a href="http://www.storagepipe.com">Storagepipe.com</a> and I must say it does exactly what it&#39;s name says.</p>
<p>	You can test it in the widget below (go on, press the PANIC button) <br />
	<script type="text/javascript" src="http://downtimecost.com/swfobject.js"></script></p>
<div id="flashcontent" style="width: 100%; height: 100%;"><strong>Please upgrade your Flash Player</strong> This is the content that would be shown if the user does not have Flash Player 6.0.65 or higher installed.</div>
<p><script type="text/javascript">
// < ![CDATA[
// version 9.0.115 or greater is required for launching AIR apps.
var so = new SWFObject("http://downtimecost.com/calculator.swf", "calculator", "400px", "500px", "10.0.0.0", "#FFFFFF");
so.useExpressInstall('http://downtimecost.com/expressinstall.swf');
so.addParam("wmode", "normal");
so.addVariable("public", "false");
so.addParam("allowScriptAccess", "always");
so.write("flashcontent");
// ]]&gt;
</script>
<p>
	By using a complex math formula it allows you to see instantly how your dollars are flying out the window in case of a downtime. </p>
<p>	The lost sales revenue is coupled with the lost productivity so you can instantly get a glimpse of the total accumulated cost as well as predicted hourly loss. </p>
<p>	It&#39;s like a stopwatch for the bleeding money so it should raise an alarm about the potential impact of a downtime. Fixing the IT systems and processes is a different story and there are no automated tools to do that in the real world. It takes time and effort or you can outsource this task to Storagepipe, the creators of the <a href="http://downtimecost.com/">Downtime Cost Calculator.</a></p>
<p>	<a href="http://http://www.storagepipe.com">Storagepipe</a> is a company focused on corporate data protection solutions including online backup and recovery, electronic archiving and business continuity. They can assist you trough the whole Risk Assessment process in order to identify and classify data which really matters for your company.</p>
<p>Offiste backup and recovery services will provide you the peace of mind about corporate data because, as we know the risk can be mitigated, accepted or transferred . Transferring seems a good option in this case. </p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/09/10/new-downtime-cost-calculator-by-storagepipe-com-what-if/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Your Network from Web Threats</title>
		<link>http://www.dragoslungu.com/2010/09/09/securing-your-network-from-web-threats/</link>
		<comments>http://www.dragoslungu.com/2010/09/09/securing-your-network-from-web-threats/#comments</comments>
		<pubDate>Thu, 09 Sep 2010 08:40:21 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[GFI]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=366</guid>
		<description><![CDATA[With this post, I make another step into blogging by publishing a guest post written by the kind folks at GFI Software, a great security vendor and friends. Here it goes : Securing Your Network from Web Threats There is a price to pay for everything &#8211; while the Internet has proven to be an [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="GFI Web Monitor" height="30" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/webmon-logo-30-116[1].png" vspace="5" width="264" /></p>
<p>With this post, I make another step into blogging by publishing a guest post written by the kind folks at GFI Software, a great security vendor and friends. Here it goes :</p>
<p><strong>Securing Your Network from Web Threats</strong></p>
<p>	There is a price to pay for everything &ndash; while the Internet has proven to be an indispensable communication, research and promotional tool for most organizations, with it come a series of web threats and security risks.</p>
<p>	<em>What are the risks involved?</em></p>
<p>Studies have shown that a good amount of employee daily Internet activity is spent on non work-related sites. <a href="http://www.morse.com/division_home_2.htm">Morse PLC</a>, for example, reported that 57% of office workers use social networking sites for an average of 40 minutes a day. Moreover <a href="http://http://uk.nielsen.com/site/index.shtml">Nielsen research</a> revealed that the greatest number of Internet videos watched was on weekdays between 12.00pm and 2.00pm, meaning when most people were at work.</p>
<p>This not only reflects one of the primary side effects of employee Internet use, cyberslacking, which results in lost productivity, but it also indicates that the corporate network is exposed to a series of web threats throughout the day. Harmless-looking websites could be hosting malware and, as a result, if an employee carelessly accesses such sites or downloads files from them, the network is then exposed to a series of security risks. Google Advisory, for example, has shown that frequently visited social networking sites, such as Facebook and Twitter, are regular victims of malware (<a href="http://www.gfi.com/blog/google-advisory-facebook-twitter-regularly-victims-malware/">read more</a>).</p>
<p>Once a company network is infected with malware or spyware, depending on the damage caused, the business experiences a series of negative repercussions which can interrupt, or even halt, its daily operations. Furthermore, in certain cases data could also be compromised or stolen, meaning the company could also end up facing serious legal charges.</p>
<p><em>What should be done?<br />
	</em></p>
<p>Enforcing web security is therefore essential for organizations to protect their systems from web threats. The first step an organization should take is to set an Internet usage policy with clear guidelines as to what type of web use is considered acceptable, while also informing employees that their Internet usage is being controlled.&nbsp; Controlling employee Internet usage is possible using web monitoring software; the knowledge that their web activities are being monitored encourages employees to curb their non work-related browsing; this in turn &ndash; decreases the possibility of accessing dangerous sites.</p>
<p>The next, and most important, step is to make use of a solid web filtering solution which offers protection to the corporate network by checking downloads for malicious payloads and quarantining or deleting infected files. The chosen web filtering solution should also offer the ability to examine websites and scan for hidden files or scripts that are covertly downloaded when the user opens a link to that particular page.</p>
<p><em>The Way Forward<br />
	</em></p>
<p>Businesses need to understand the concept that prevention is better than cure &ndash; the savings made in worker productivity, IT labor, and bandwidth &#8211; not to mention the cost of defending the organization in court &#8211; not only compensate for the investment in a web monitoring and filtering solution but also provides ongoing value.</p>
<p><em>This guest post was provided by Christina Goggi on behalf of GFI Software Ltd. GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging needs. More information: GFI <a href="http://www.gfi.com/internet-monitoring-software">internet monitoring software</a>.</p>
<p>	All product and company names herein may be trademarks of their respective owners.<br />
	</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/09/09/securing-your-network-from-web-threats/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-07-25</title>
		<link>http://www.dragoslungu.com/2010/07/25/my-twitter-notes-on-2010-07-25/</link>
		<comments>http://www.dragoslungu.com/2010/07/25/my-twitter-notes-on-2010-07-25/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/07/25/my-twitter-notes-on-2010-07-25/</guid>
		<description><![CDATA[Qualys BrowserCheck &#8211; nice client side security check tool http://bit.ly/ccAqMN # McAfee Risk Management; What threat data if they deploy only vulnerability managers and one correlation engine ? http://bit.ly/bWWGxD # New @NetWitness Visualize : Welcome To The Future! http://bit.ly/8XvbnX # FireEye and Solera Networks Partner to Provide In-depth Security Analytics for Proactive Cyber Attack Mitigation [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>Qualys BrowserCheck  &#8211; nice client side security check tool <a href="http://bit.ly/ccAqMN" rel="nofollow">http://bit.ly/ccAqMN</a> <a href="http://twitter.com/dragosl/statuses/18933058637" class="aktt_tweet_time">#</a></li>
<li>McAfee Risk Management; What threat data if they deploy only vulnerability managers and one correlation engine ? <a href="http://bit.ly/bWWGxD" rel="nofollow">http://bit.ly/bWWGxD</a> <a href="http://twitter.com/dragosl/statuses/18933349269" class="aktt_tweet_time">#</a></li>
<li>New @<a href="http://twitter.com/NetWitness" class="aktt_username">NetWitness</a> Visualize : Welcome To The Future!   <a href="http://bit.ly/8XvbnX" rel="nofollow">http://bit.ly/8XvbnX</a> <a href="http://twitter.com/dragosl/statuses/19006222344" class="aktt_tweet_time">#</a></li>
<li>FireEye and Solera Networks Partner to Provide In-depth Security Analytics for Proactive Cyber Attack Mitigation  <a href="http://bit.ly/bAljDO" rel="nofollow">http://bit.ly/bAljDO</a> <a href="http://twitter.com/dragosl/statuses/19261933952" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/07/25/my-twitter-notes-on-2010-07-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New NetWitness Visualize : Welcome To The Future!</title>
		<link>http://www.dragoslungu.com/2010/07/20/new-netwitness-visualize-welcome-to-the-future/</link>
		<comments>http://www.dragoslungu.com/2010/07/20/new-netwitness-visualize-welcome-to-the-future/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:25:10 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[NetWitness]]></category>
		<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=360</guid>
		<description><![CDATA[I would like to present you the most advanced network traffic visualization system I've ever seen, the NetWitness Visualize. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="NetWitness Visualize" height="50" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/image/nw_logo.png" vspace="5" width="290" /></p>
<p>I have already written about how awesome NetWitness is so I won&#39;t repeat what i said in this <a href="http://www.dragoslungu.com/2009/06/24/netwitness/">NetWitness review</a> ; instead I would like to present you the most advanced network traffic visualization system I&#39;ve ever seen, the <a href="http://www.networkforensics.com/2010/07/19/visualize/">NetWitness Visualize</a>.</p>
<p>Imagine you need to file a report on all <em>confidential </em>PDF files which passed trough the network&nbsp; between 1am and 3am on a Saturday morning. On a multi Gigabyte wire. And you only have one hour to file your report. What a nightmare!</p>
<p>Sorting trough terrabytes of data <em>it is</em> a daunting task to say the least and no matter what file carving tool you use, you still end up with hundreds of PDF files which have to be analyzed <em>by hand</em>.</p>
<p>Now, imagine you can swipe your fingers trough 1:1 renderization of all PDFs which were recorded between 1am and 3am just like Tom Cruise did in Minority Report movie. How cool is that.. in seconds you are able to spot classified watermarked blueprints and other juicy corporate documents.</p>
<p>NetWitness Visualize got it right about human perception of information. It will take a while until we, as humans will be able to read binary (remember Neo in Matrix, the movie?) and until then we need to examine the data reconstructed so that it reflects back&nbsp; the reality captured in those zero and ones.</p>
<p>And even though I gave a visual example with the PDFs, the same applies to audio data as well. Wouldn&#39;t it be cool to be able to instantly listen to each VoIP conversation which was recorded during a 24hrs surveillance ops?&nbsp; Again, NetWitness Visualize makes this real, only one click away.&nbsp;</p>
<p>If you want to check for yourselves, there is a <a href="http://visualize.netwitness.com/">live demo of NetWitness Visualize </a>on this website but I strongly recommend you to watch <a href="http://www.youtube.com/watch?v=p4nIqIWKiMo">this short YouTube video </a>first .</p>
<p>And, for a good laugh, try to listen to an <em>easter-egg </em>burried as a phone call conversation between the french president Nikolas Sarkozy and Sarah Palin. Sarkozy is singing about Joe the plumber which he takes for Palin&#39;s husband and that <em>is</em> priceless.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/07/20/new-netwitness-visualize-welcome-to-the-future/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-07-18</title>
		<link>http://www.dragoslungu.com/2010/07/18/my-twitter-notes-on-2010-07-18/</link>
		<comments>http://www.dragoslungu.com/2010/07/18/my-twitter-notes-on-2010-07-18/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/07/18/my-twitter-notes-on-2010-07-18/</guid>
		<description><![CDATA[fuzzdb : Attack and Discovery Pattern Database for Application Fuzz Testing http://bit.ly/aoerjm # Symantec Positioned as a Leader in Three Recent Magic Quadrants &#8211; Secure Email GW, SIEM and DLP http://bit.ly/aRrysP # Amazing new product by @imperva : File Security &#8211; Audit file rights and file access http://bit.ly/an1n72 # &#34;GFI Software Acquires Sunbelt Software&#34; ( [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>fuzzdb : Attack and Discovery Pattern Database for Application Fuzz Testing  <a href="http://bit.ly/aoerjm" rel="nofollow">http://bit.ly/aoerjm</a> <a href="http://twitter.com/dragosl/statuses/18376266824" class="aktt_tweet_time">#</a></li>
<li>Symantec Positioned as a Leader in Three Recent Magic Quadrants &#8211; Secure Email GW, SIEM and DLP   <a href="http://bit.ly/aRrysP" rel="nofollow">http://bit.ly/aRrysP</a> <a href="http://twitter.com/dragosl/statuses/18376369509" class="aktt_tweet_time">#</a></li>
<li>Amazing new product by  @<a href="http://twitter.com/imperva" class="aktt_username">imperva</a> :  File Security &#8211; Audit file rights and file access  <a href="http://bit.ly/an1n72" rel="nofollow">http://bit.ly/an1n72</a> <a href="http://twitter.com/dragosl/statuses/18502770742" class="aktt_tweet_time">#</a></li>
<li>&quot;GFI Software Acquires Sunbelt Software&quot; ( <a href="http://bit.ly/c0mYdR" rel="nofollow">http://bit.ly/c0mYdR</a> ) <a href="http://twitter.com/dragosl/statuses/18502855113" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/07/18/my-twitter-notes-on-2010-07-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-07-11</title>
		<link>http://www.dragoslungu.com/2010/07/11/my-twitter-notes-on-2010-07-11/</link>
		<comments>http://www.dragoslungu.com/2010/07/11/my-twitter-notes-on-2010-07-11/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/07/11/my-twitter-notes-on-2010-07-11/</guid>
		<description><![CDATA[Angry researchers disclose Windows zero-day bug http://shar.es/mUibS # Google confirms attack on YouTube http://shar.es/mUigF # Antivirus Marketshare June 2010 Report — OESIS OK ( http://bit.ly/biB7AA ) # Powered by Twitter Tools]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>Angry researchers disclose Windows zero-day bug <a href="http://shar.es/mUibS" rel="nofollow">http://shar.es/mUibS</a> <a href="http://twitter.com/dragosl/statuses/17890375422" class="aktt_tweet_time">#</a></li>
<li>Google confirms attack on YouTube <a href="http://shar.es/mUigF" rel="nofollow">http://shar.es/mUigF</a> <a href="http://twitter.com/dragosl/statuses/17890454314" class="aktt_tweet_time">#</a></li>
<li>Antivirus Marketshare June 2010 Report — OESIS OK ( <a href="http://bit.ly/biB7AA" rel="nofollow">http://bit.ly/biB7AA</a> ) <a href="http://twitter.com/dragosl/statuses/18062720228" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/07/11/my-twitter-notes-on-2010-07-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-06-27</title>
		<link>http://www.dragoslungu.com/2010/06/27/my-twitter-notes-on-2010-06-27/</link>
		<comments>http://www.dragoslungu.com/2010/06/27/my-twitter-notes-on-2010-06-27/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/06/27/my-twitter-notes-on-2010-06-27/</guid>
		<description><![CDATA[I always find inspiration and motivation reading biographies of successful people: @Qualys CEO Philippe Courtot http://bit.ly/9CmbVK # &#34;Fidelis Security Systems Integrates Cyber Intelligence from Cyveillance to Provide Advanced Situational Awareness&#34; ( http://bit.ly/9ywqt6 ) # nwmap v0.1 Released – Map Network From PCAP File ( http://bit.ly/9BNFEe ) # Powered by Twitter Tools]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>I always find inspiration and motivation reading biographies of successful people: @<a href="http://twitter.com/Qualys" class="aktt_username">Qualys</a> CEO Philippe Courtot   <a href="http://bit.ly/9CmbVK" rel="nofollow">http://bit.ly/9CmbVK</a> <a href="http://twitter.com/dragosl/statuses/16766997471" class="aktt_tweet_time">#</a></li>
<li>&quot;Fidelis Security Systems Integrates Cyber Intelligence from Cyveillance to Provide Advanced Situational Awareness&quot; ( <a href="http://bit.ly/9ywqt6" rel="nofollow">http://bit.ly/9ywqt6</a> ) <a href="http://twitter.com/dragosl/statuses/16800100283" class="aktt_tweet_time">#</a></li>
<li>nwmap v0.1 Released – Map Network From PCAP File  ( <a href="http://bit.ly/9BNFEe" rel="nofollow">http://bit.ly/9BNFEe</a> ) <a href="http://twitter.com/dragosl/statuses/16853582415" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/27/my-twitter-notes-on-2010-06-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Qualys and Imperva Integration: Natural Evolution</title>
		<link>http://www.dragoslungu.com/2010/06/22/qualys-and-imperva-integration-natural-evolution/</link>
		<comments>http://www.dragoslungu.com/2010/06/22/qualys-and-imperva-integration-natural-evolution/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 12:38:02 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Imperva]]></category>
		<category><![CDATA[qualys]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=353</guid>
		<description><![CDATA[The integration of QualysGuard Web Application vulnerability scanner and Imperva’s SecureSphere Web Application Firewall (WAF) significantly reduces the need for disruptive patching of vulnerabilities.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img alt="" height="44" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/qualys_impevra.jpg" vspace="5" width="269" /></p>
<p>I&#39;ve just read today about the natural integration between Qualys and Imperva, two of the&nbsp; vendors that I work with and I highly appreciate.</p>
<p>Timing is great for Imperva because the proactive services offered by <a href="http://www.imperva.com/products/discovery-and-assessment-server.html">Imperva&#39;s Discovery and Assessment Server</a> had no real correspondence in web application world and that&#39;s why<a href="http://www.qualys.com/products/qg_suite/was/"> QualysGuard Web Application vulnerability scanner</a> fits like a glove.</p>
<p>To put it in their words,</p>
<blockquote style="text-align: justify;"><p>The integration of QualysGuard Web Application vulnerability scanner and Imperva&rsquo;s SecureSphere Web Application Firewall (WAF) significantly reduces the need for disruptive patching of vulnerabilities. Organizations can use QualysGuard to scan their Web applications for vulnerabilities and then import the scan results into SecureSphere WAF. SecureSphere WAF provides instant mitigation for imported vulnerabilities using a &ldquo;virtual patch,&rdquo; which limits the window of exposure and reduces the security risk on the business.</p></blockquote>
<p>On the other hand QualysGuard gets a couple of benefits suchs as : <br />
	- World wide recognition for it&#39;s new Web Application Scanner which is the latest addition to the QualysGuard scanner family .</p>
<p>- Sales support from Imperva&#39;s Channel . I know I will present this combination (Qualys and Imperva) to all my Imperva customers, whenever possible because I believe I&#39;s an effective web application security solution</p>
<p><a href="http://www.qualys.com/docs/Imperva.pdf">Here </a>is a short whitepaper (pdf) on this topic.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/22/qualys-and-imperva-integration-natural-evolution/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-06-20</title>
		<link>http://www.dragoslungu.com/2010/06/20/my-twitter-notes-on-2010-06-20/</link>
		<comments>http://www.dragoslungu.com/2010/06/20/my-twitter-notes-on-2010-06-20/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/06/20/my-twitter-notes-on-2010-06-20/</guid>
		<description><![CDATA[RT @ArcSight &#34;Entrepreneur of the Year&#34; &#8211; Hugh Njemanze, ARST CTO &#38; VP of R&#38;D &#8211; new post from blogger Lisa Kost &#124; http://bit.ly/9JKCWf # &#34;Pro CERT – First Romanian Commercial CERT &#124; Dragos Lungu Dot Com&#34; ( http://bit.ly/9I00pF ) # RT @pentestit UPDATE: Maltego v3! &#8211; get it at &#8211; http://pentestit.com/2010/06/17/update-maltego-v3/ # RT @securitypro2009 [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>RT @<a href="http://twitter.com/ArcSight" class="aktt_username">ArcSight</a> &quot;Entrepreneur of the Year&quot; &#8211; Hugh Njemanze, ARST CTO &amp; VP of R&amp;D &#8211; new post from blogger Lisa Kost | <a href="http://bit.ly/9JKCWf" rel="nofollow">http://bit.ly/9JKCWf</a> <a href="http://twitter.com/dragosl/statuses/16253430430" class="aktt_tweet_time">#</a></li>
<li>&quot;Pro CERT – First Romanian Commercial CERT | Dragos Lungu Dot Com&quot; ( <a href="http://bit.ly/9I00pF" rel="nofollow">http://bit.ly/9I00pF</a> ) <a href="http://twitter.com/dragosl/statuses/16305935130" class="aktt_tweet_time">#</a></li>
<li>RT @<a href="http://twitter.com/pentestit" class="aktt_username">pentestit</a> UPDATE: Maltego v3! &#8211; get it at &#8211; <a href="http://pentestit.com/2010/06/17/update-maltego-v3/" rel="nofollow">http://pentestit.com/2010/06/17/update-maltego-v3/</a> <a href="http://twitter.com/dragosl/statuses/16368004749" class="aktt_tweet_time">#</a></li>
<li>RT @<a href="http://twitter.com/securitypro2009" class="aktt_username">securitypro2009</a> MANDIANT Unveils Web Historian 2.0 <a href="http://bit.ly/dBLjL3" rel="nofollow">http://bit.ly/dBLjL3</a> <a href="http://twitter.com/dragosl/statuses/16535294196" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/20/my-twitter-notes-on-2010-06-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pro CERT &#8211; First Romanian Commercial CERT</title>
		<link>http://www.dragoslungu.com/2010/06/16/pro-cert-first-romanian-commercial-cert/</link>
		<comments>http://www.dragoslungu.com/2010/06/16/pro-cert-first-romanian-commercial-cert/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 13:25:41 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Pro CERT]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=348</guid>
		<description><![CDATA[Pro CERT offers assistance and coordination in early detection and handling of computer and network security incidents for all its constituents.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p>It brings me great pride and joy to announce the public release of <a href="http://www.pro-cert.ro">Pro CERT</a> ( Provision Computer Emergency Response Team), the first commercial CERT structure in Romania.</p>
<p>Quoting from <a href="http://www.pro-cert.ro/RFC2350.pdf">Pro CERT RFC2550 charter</a> :</p>
<p>Pro CERT is a project initiated and sponsored by <a href="http://www.provision.ro/">Provision Software Division SRL</a>, the largest privately owned Romanian IT security company.</p>
<p>	&quot;Pro CERT offers assistance and coordination in early detection and handling of computer and network security incidents for all it&rsquo;s constituents. Pro CERT primary constituency include all networks and systems belonging to Provision Software Division SRL and it&rsquo;s customers.A secondary goal in terms of constituency is represented by the Romanian TLD : .ro for which Pro CERT aims to be a certified&nbsp; point of contact for incidents targeting or initiated from Romania. </p>
<p>	Pro CERT is dedicated to preventing security incidents by offering direct proactive measures and security quality management services. Pro CERT operates under the authority of Provision&rsquo;s Managed Security Services business division, which manages the operational authority between Pro CERT and each of its constituents trough individual SLAs.&nbsp; </p>
<p>	Pro CERT core activities imply close cooperation with all large ISP&#39;s abuse teams from Romania and abroad, direct contact and data exchange in order to prevent and recover from security incidents that affect Pro CERT&rsquo;s constituents.</p>
<p>	Pro CERT operates under the restrictions imposed by Romanian law. This involves careful handling of personal data as required by Romanian Data Protection laws, but it is also possible that &#8211; according to Romanian law &ndash; Pro CERT may be forced to disclose information due to a Court&#39;s order. &quot;</p>
<p>Just like the Oscar winners, I would like to thank my team without whom none of this could have happened <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  . It&#39;s a young project but we are very ambitious and we have set our goals high !&nbsp; Please contact me directly,leave comments or register on <a href="http://www.pro-cert.ro">www.pro-cert.ro</a>&nbsp; if you would like to cooperate with Pro CERT.</p>
<p>Please find below the opening presentation I gave on Provision Security Days conference about Pro CERT.<br />
	&nbsp;</p>
<div id="__ss_4416831" style="width: 425px;"><strong style="display: block; margin: 12px 0pt 4px;"><a href="http://www.slideshare.net/dragoslungu/pro-cert" title="Pro CERT ">Pro CERT </a></strong></p>
<p style="text-align: center;"><object height="355" id="__sse4416831" width="425"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=dragosprocert-100605060130-phpapp02&amp;stripped_title=pro-cert" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><embed allowfullscreen="true" allowscriptaccess="always" height="355" name="__sse4416831" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=dragosprocert-100605060130-phpapp02&amp;stripped_title=pro-cert" type="application/x-shockwave-flash" width="425"></embed></object></p>
<div style="padding: 5px 0pt 12px;">View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/dragoslungu">dragoslungu</a>.</div>
</div>
<p>
	Do you like my presentation ? <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thanks !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/16/pro-cert-first-romanian-commercial-cert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GFI EventsManager 2010 Review</title>
		<link>http://www.dragoslungu.com/2010/06/15/gfi-eventsmanager-2010-review/</link>
		<comments>http://www.dragoslungu.com/2010/06/15/gfi-eventsmanager-2010-review/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 13:32:22 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[GFI]]></category>
		<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=339</guid>
		<description><![CDATA[GFI EventManager 2010 is a very efficient and effective log and event management tool which covers most of the daily security monitoring activities.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><a href="http://www.gfi.com/eventsmanager"><img alt="" height="36" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/esm-logo-30-104[1].png" vspace="5" width="300" /></a></p>
<p>For a long time I wanted to write a review on <a href="http://www.gfi.com/eventsmanager">GFI EventsManager 2010</a> and I&#39;m glad I&#39;m doing it because for me it&#39;s a very good example of software built the right way for the right job at the right time.</p>
<p>Having spent my last 5 years working with SIEM giants like ArcSight and RSA EnVision, I have experienced first hand the benefits and sometimes the downfall of&nbsp; <a href="http://en.wikipedia.org/wiki/Security_event_manager">SIEM / ESM</a> solutions.</p>
<p>GFI EventsManger takes a simple and robust aproach to log and event management and this is shown in the way it does the collection of data, the analysis, storage and reporting.</p>
<p>The <strong>collection </strong>of data is done <strong>agentless </strong>which is a big plus and the solution&nbsp; can collect and process Windows events, W3C event logs, Syslog messages, SNMP Trap and SQL Server logs.&nbsp; This allows one to collect more data from the different hardware and software systems that are most commonly available on a typical corporate network.</p>
<p>GFI EventsManager offers one of the best asset management interface allowing one to group assets (servers, workstations, netowrk devices) and quickly display events filtered by numerous criteria.</p>
<p>The list of supported devices can be found <a href="http://kbase.gfi.com/showarticle.asp?id=KBID003302">here </a>(a bit outdated, needs an update to 2010 version) and it includes top vendors in all major security domains :access control, perimeter, endpoint , directory services, content filtering, IDS / IPS, operating systems and much more.</p>
<p>The solution uses two collection engines, the Event Retrieval Engine and the Event Receiving Engine which cover all supported log formats, either passively such as Syslog and SNMP or actively connecting systems handling W3C and Windows events.</p>
<p>Once the events have reached them main processing unit, GFI EventsManager will run a set of event processing rules on the collected events. The solution ships with a rich set of out-of-the-box rules such as :</p>
<ul>
<li>Classifying the events as Critical, High, Medium, Low or Noise (which are discarded)</li>
<li>Filtering events based on specific criteria</li>
<li>Triggering email, SMS and network alerts on key events</li>
<li>Triggering remediation actions such as the execution of executable files or scripts on key events</li>
<li>Optionally archiving collected events in the database backend.</li>
</ul>
<p>GFI EventsManager uses a MS-SQL database backend which can quickly fill up so the solution provides functionality to disk-archive the main stream of events and save only the important alerts in the database.</p>
<p><strong>Accessing </strong>the data is straight forward using Event Browsing which does a great job at presenting the events is an easy-to-read format. Event Browser can also be used as a forensics analysis tool because of it&#39;s ease of use in drilling into recorded events.</p>
<p><strong>Reporting </strong>is done via&nbsp; the GFI ReportCenter framework which offers consistent reporting features for many GFI products. There is a dedicated ReportPack for GFI EventManager which loads in the reporting framework so you can benefit from the framework powerful reporting features tailored to the specific data provided by EventManager.</p>
<p>Reports can be scheduled and can be sent by email or exported as to various formats including HTML, Adobe Acrobat (PDF), Excel (XLS), Word (DOC), and Rich Text Format (RTF).</p>
<p><strong>Conclusion</strong><br />
	<a href="http://www.gfi.com/eventsmanager">GFI EventManager 2010</a> is a very efficient and effective log and event management tool which covers most of the daily security monitoring activities. However, there is room for expanding this product by adding support for more log formats (ODBC, flat text, vendor specific protocol like CheckPoint OPSEC, etc). Also event normalization and aggregation could improve the in-memory correlation for more complex AI alerts .</p>
<p><a href="http://www.gfi.com/page/13789/products/gfi-eventsmanager/pricing/licensing/licensing ">Licensing </a>is very affordable for this class of products and it&#39;s based on number of nodes reporting events. Also, don&#39;t forget that you can always download a full working evaluation version from <a href="http://www.gfi.com/downloads/register.aspx?pid=esm">here </a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/15/gfi-eventsmanager-2010-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-06-13</title>
		<link>http://www.dragoslungu.com/2010/06/13/my-twitter-notes-on-2010-06-13/</link>
		<comments>http://www.dragoslungu.com/2010/06/13/my-twitter-notes-on-2010-06-13/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/06/13/my-twitter-notes-on-2010-06-13/</guid>
		<description><![CDATA[SC Magazine US awards perfect score to Netgear ProSecure. Good content filtering for less than 3k USD . Cool ( http://bit.ly/aDzC5M ) # RT @agent0x0 RT @securitymonks: RIPS – A static source code analyser for vulnerabilities in PHP scripts http://goo.gl/H65C # Powered by Twitter Tools]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>SC Magazine US awards perfect score to Netgear ProSecure. Good content filtering for less than 3k USD . Cool   ( <a href="http://bit.ly/aDzC5M" rel="nofollow">http://bit.ly/aDzC5M</a> ) <a href="http://twitter.com/dragosl/statuses/15769214071" class="aktt_tweet_time">#</a></li>
<li>RT @<a href="http://twitter.com/agent0x0" class="aktt_username">agent0x0</a> RT @<a href="http://twitter.com/securitymonks" class="aktt_username">securitymonks</a>: RIPS – A static source code analyser for vulnerabilities in PHP scripts <a href="http://goo.gl/H65C" rel="nofollow">http://goo.gl/H65C</a> <a href="http://twitter.com/dragosl/statuses/15959624068" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/13/my-twitter-notes-on-2010-06-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help with JavaScript Malware !</title>
		<link>http://www.dragoslungu.com/2010/06/10/help-with-javascript-malware/</link>
		<comments>http://www.dragoslungu.com/2010/06/10/help-with-javascript-malware/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 07:42:24 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Web Applications]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/?p=335</guid>
		<description><![CDATA[Help me read this JavaScript malware ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img align="left" alt="" height="64" hspace="5" src="http://www.dragoslungu.com/wp-content/uploads/Malware Detection.jpg" vspace="5" width="64" />I just received today a phishing email which had an HTML attachment and of course it asked me to click the attached file. </p>
<p>By opening the attached file as text I noticed it&#39;s packed with scrambled / encoded JavaScript which unfortunately I don&#39;t speak fluently. </p>
<p>I have uploaded the file on my webserver and I scanned with <a href="http://www.qualys.com/products/qg_suite/malware_detection/">QualysGuard Malware Detection </a>service which runs the discovered malware in a sandbox OS to detect the effects on an ordinary PC but unfortunately I didn&#39;t get any results. </p>
<p>By unscrambling some URLs I found remote calls to http://onnoe.ru:8080/index.php?pid=10 which gave me a hint that this malware might be used as trojan / botnet harvester. </p>
<p>So, I would appreciate if anybody could take a look at the malware JavaScript and share the results with me .. I&#39;m extremely curious on what it does. </p>
<p>Anyways, <a href="http://www.dragoslungu.com/malware/malware.txt">here </a>is the culprit JS code saved as txt.</p>
<p>Thank you! </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/10/help-with-javascript-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-06-06</title>
		<link>http://www.dragoslungu.com/2010/06/06/my-twitter-notes-on-2010-06-06/</link>
		<comments>http://www.dragoslungu.com/2010/06/06/my-twitter-notes-on-2010-06-06/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/06/06/my-twitter-notes-on-2010-06-06/</guid>
		<description><![CDATA[dotDefender busted by Sandro Gauci of EnableSecurity ( http://bit.ly/cLN9Uy ) # RT @Hfuhs: WordPress user: Be careful where you get your theme from &#8211; http://fuhs.eu/16h # RT @Imperva: History of Hacking in One Cool Graphic http://bit.ly/bQYUim # attending Provision Security Days at seaside in Olimp, Romania .. cold, windy. Hopefully that will keep the guests [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>dotDefender busted by Sandro Gauci of EnableSecurity  ( <a href="http://bit.ly/cLN9Uy" rel="nofollow">http://bit.ly/cLN9Uy</a> ) <a href="http://twitter.com/dragosl/statuses/15180768204" class="aktt_tweet_time">#</a></li>
<li>RT @<a href="http://twitter.com/Hfuhs" class="aktt_username">Hfuhs</a>: WordPress user: Be careful where you get your theme from &#8211; <a href="http://fuhs.eu/16h" rel="nofollow">http://fuhs.eu/16h</a> <a href="http://twitter.com/dragosl/statuses/15181735997" class="aktt_tweet_time">#</a></li>
<li>RT @<a href="http://twitter.com/Imperva" class="aktt_username">Imperva</a>: History of Hacking in One Cool Graphic <a href="http://bit.ly/bQYUim" rel="nofollow">http://bit.ly/bQYUim</a> <a href="http://twitter.com/dragosl/statuses/15193514607" class="aktt_tweet_time">#</a></li>
<li>attending Provision Security Days at seaside in Olimp, Romania .. cold, windy. Hopefully that will keep the guests focused on the conference <a href="http://twitter.com/dragosl/statuses/15278364650" class="aktt_tweet_time">#</a></li>
<li>Just released  Pro CERT : ProVision Computer Emergency Response Center <a href="http://slidesha.re/cMYcDC" rel="nofollow">http://slidesha.re/cMYcDC</a> <a href="http://twitter.com/dragosl/statuses/15480834423" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/06/06/my-twitter-notes-on-2010-06-06/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>My Twitter Notes on 2010-05-30</title>
		<link>http://www.dragoslungu.com/2010/05/30/my-twitter-notes-on-2010-05-30-4/</link>
		<comments>http://www.dragoslungu.com/2010/05/30/my-twitter-notes-on-2010-05-30-4/#comments</comments>
		<pubDate>Mon, 31 May 2010 01:15:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweets]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2010/05/30/my-twitter-notes-on-2010-05-30-4/</guid>
		<description><![CDATA[&#34;Patch management for non-Microsoft software products with new release of GFI LANguard&#34; ( http://bit.ly/9CcODJ ) # &#34;BBC News &#8211; First human &#39;infected with computer virus&#39;&#34; ( http://bit.ly/96Lhg4 ) .. amazing ! # Powered by Twitter Tools]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<ul class="aktt_tweet_digest">
<li>&quot;Patch management for non-Microsoft software products with new release of GFI LANguard&quot; ( <a href="http://bit.ly/9CcODJ" rel="nofollow">http://bit.ly/9CcODJ</a> ) <a href="http://twitter.com/dragosl/statuses/14781472919" class="aktt_tweet_time">#</a></li>
<li>&quot;BBC News &#8211; First human &#39;infected with computer virus&#39;&quot; ( <a href="http://bit.ly/96Lhg4" rel="nofollow">http://bit.ly/96Lhg4</a> ) .. amazing ! <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  <a href="http://twitter.com/dragosl/statuses/14851866669" class="aktt_tweet_time">#</a></li>
</ul>
<p class="aktt_credit">Powered by <a href="http://alexking.org/projects/wordpress">Twitter Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2010/05/30/my-twitter-notes-on-2010-05-30-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

