<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security</title>
	<atom:link href="http://www.halbheer.info/security/rss.xml" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.info/security</link>
	<description>I am the Chief Security Advisor for Microsoft EMEA and would like to discuss Information Security</description>
	<lastBuildDate>Fri, 12 Mar 2010 13:30:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hacking Incidents 2009 &#8211; Interesting Data</title>
		<link>http://www.halbheer.info/security/2010/03/12/hacking-incidents-2009-interesting-data</link>
		<comments>http://www.halbheer.info/security/2010/03/12/hacking-incidents-2009-interesting-data#comments</comments>
		<pubDate>Fri, 12 Mar 2010 13:30:12 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[criminals]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1455</guid>
		<description><![CDATA[There is a project called the web hacking incident database (WHID), which collects data and statistics on web-application related security incidents. I was just looking into their report called The Web Hacking Incident Database 2009 which has some pretty interesting statistics in.
In order to judge the results and statistics of this database, we have to [...]]]></description>
			<content:encoded><![CDATA[<p>There is a project called the web hacking incident database (WHID), which collects data and statistics on web-application related security incidents. I was just looking into their report called <a href="http://www.breach.com/resources/whitepapers/downloads/WP_TheWebHackingIncidents-2009.pdf" target="_blank">The Web Hacking Incident Database 2009</a> which has some pretty interesting statistics in.</p>
<p>In order to judge the results and statistics of this database, we have to make sure we understand the contributors and where they come from:    <br /><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3275626/original.aspx" target="_blank"><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="500x297[1]" border="0" alt="500x297[1]" src="http://www.halbheer.info/security/wp-content/uploads/2010/03/500x2971.png" width="500" height="297" /></a> Therefore the output will definitely have some US-centricity but is nevertheless interesting.</p>
<p>There is no secret that the attackers go for money. <em>Cybercrime came from cool to cash</em>! If you look what the attacker did after a successful attack, this proves this statement once more: </p>
<p><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3275629/original.aspx" target="_blank"><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="500x323[1]" border="0" alt="500x323[1]" src="http://www.halbheer.info/security/wp-content/uploads/2010/03/500x3231.png" width="500" height="323" /></a></p>
<p>But how do they get in? How does a hacker actually attack a Web-Application? Again, not a lot of surprise here, more a confirmation of what we know already:</p>
<p><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3275631/original.aspx" target="_blank"><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="500x262[1]" border="0" alt="500x262[1]" src="http://www.halbheer.info/security/wp-content/uploads/2010/03/500x2621.png" width="500" height="262" /></a> </p>
<p>I think, having SQL Injection on top should not surprise anybody who is working in this space.</p>
<p>So, looking at it is definitely worth in order to get a better picture from a security intelligence point of view</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/12/hacking-incidents-2009-interesting-data/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insider Threat of Cloud Computing</title>
		<link>http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing</link>
		<comments>http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing#comments</comments>
		<pubDate>Thu, 11 Mar 2010 09:22:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Considerations]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[Insider Threat]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing</guid>
		<description><![CDATA[Tonight I got this article forwarded to me: Afraid of outside cloud attacks? You&#8217;re missing the real threat. David Linthicum (the author) claimed that if you are looking at the hackers attacking “your” cloud from the outside, you are missing the real problem as the insider threat is still bigger.
When I read the article, I [...]]]></description>
			<content:encoded><![CDATA[<p>Tonight I got this article forwarded to me: <a href="http://www.infoworld.com/d/cloud-computing/afraid-outside-cloud-attacks-youre-missing-real-threat-894?source=IFWNLE_nlt_daily_2010-03-10" target="_blank">Afraid of outside cloud attacks? You&#8217;re missing the real threat</a>. David Linthicum (the author) claimed that if you are looking at the hackers attacking “your” cloud from the outside, you are missing the real problem as the insider threat is still bigger.</p>
<p>When I read the article, I agreed but on the other hand I was quite surprised. The article actually tends to reduce the risks of the cloud to the hacking attack from the outside. As we know, the problem space is much, much bigger as we outlined in our <a href="http://www.halbheer.info/security/2010/01/30/cloud-security-paper-looking-for-feedback" target="_blank">Cloud Computing Security Considerations</a> paper as did others in numerous other papers on the web.</p>
<p>However, there is one fundamental thing I agree with the article: When people talk about the Cloud and security they tend to forget the past. It seems to me when I read the blog sphere and article on the web like it the cloud is something completely new and the threat landscape is completely new and the risks are completely new. To me, it is “just” a variation of the theme. We had outsourcing in the past and we had virtualization in the past. Now, we combine the two, add some salt and pepper and have Cloud computing (I know that I am oversimplifying now).</p>
<p>I am completely aware and supportive of the fact that the Cloud is adding a lot of business opportunities &#8211; and new risks. But we definitely have to make sure that we do not forget what we learned in the last few years – the last two decades &#8211; of information security as the “old” risks – like the insider threat – do not go away because we move to the Cloud. Nor will the responsibility for securing our information being transferred to a cloud provider. And this is probably the most important thing we have to consider, when we plan the cloud. </p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Protection Heat Map</title>
		<link>http://www.halbheer.info/security/2010/03/10/data-protection-heat-map</link>
		<comments>http://www.halbheer.info/security/2010/03/10/data-protection-heat-map#comments</comments>
		<pubDate>Wed, 10 Mar 2010 09:00:46 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/09/data-protection-heat-map</guid>
		<description><![CDATA[I was looking at some research done by Forrester which could be interesting for you as well. They try to lay out the landscape with regards to data protection for you and it looks fairly compelling. So if you are interested in the situation of the different Privacy laws across the globe and how Forrester [...]]]></description>
			<content:encoded><![CDATA[<p>I was looking at some research done by Forrester which could be interesting for you as well. They try to lay out the landscape with regards to data protection for you and it looks fairly compelling. So if you are interested in the situation of the different Privacy laws across the globe and how Forrester sees them, the map you can access there is fairly good (even though I cannot judge whether the content is accurate). </p>
<p><a href="http://www.forrester.com/cloudprivacyheatmap" target="_blank"><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="clip_image001[6]" border="0" alt="clip_image001[6]" src="http://www.halbheer.info/security/wp-content/uploads/2010/03/clip_image0016.jpg" width="500" height="320" /></a></p>
<p>The real interactive map can be found here: <a href="http://www.forrester.com/cloudprivacyheatmap" target="_blank">Do You Know Where Your Data Is In The Cloud?</a></p>
<p>Roger   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/10/data-protection-heat-map/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Challenges of International Business and the Cloud</title>
		<link>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud</link>
		<comments>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud#comments</comments>
		<pubDate>Tue, 09 Mar 2010 07:10:41 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[behavior]]></category>
		<category><![CDATA[citizens]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[criminals]]></category>
		<category><![CDATA[harmonization]]></category>
		<category><![CDATA[International]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[jurisdiction]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[MLAT]]></category>
		<category><![CDATA[Policy Makers]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/08/legal-challenges-of-international-business-and-the-cloud</guid>
		<description><![CDATA[To start with: I am an engineer not a lawyer – and this might be part of the problem…
When I started to think about the Cloud and security and thought about all the work I do with Law Enforcement and the challenges they face. Additionally, I started to think about the legal challenges we – [...]]]></description>
			<content:encoded><![CDATA[<p>To start with: I am an engineer not a lawyer – and this might be part of the problem…</p>
<p>When I started to think about the Cloud and security and thought about all the work I do with Law Enforcement and the challenges they face. Additionally, I started to think about the legal challenges we – as an industry – already had. Or better, the legal challenges I knew about. Our <a href="http://www.halbheer.info/security/2010/01/30/cloud-security-paper-looking-for-feedback" target="_blank">Cloud Security Challenges</a> paper just touches a little bit on this but to me it is a big challenge (to big for an engineer <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ?)</p>
<p>Let me give you an example: A case which happens often is that Law Enforcement is approaching any mail-provider with the request to access the content of a mailbox because they have a case where the suspect is expected to have mails which can be used as evidence. This is actually fairly standard and within the legal boundaries of a country straight-forward if the law enforcement officer has a court decision. Now, with international providers it gets more complicated as a case in Belgium showed: The Belgium policed asked Yahoo! to give them access to a mailbox of a person living in Belgium based on a Belgium court decision. However, this data is hosted in the United States. Pretty normal: The police then should the FBI for help, they issue the corresponding papers (together with the court) and Yahoo! would hand over the data – this process is called <a href="http://en.wikipedia.org/wiki/Mutual_Legal_Assistance_Treaty" target="_blank">MLAT (mutual legal assistance treaty)</a>. Belgium refused to do that as it was their position that a Belgium decision is good enough because the suspect lives in Belgium. Yahoo! now had two choices: Violate the US law by handing over the data or violate the Belgium court decision by not handing over the data – a lose-lose position they were in <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> . </p>
<p>And the worst thing to me is that we all have just one goal: <strong>We want to get the criminals arrested – this is a battle where law enforcement, policy makers and the industry are on the same side!</strong> If you want to read more: <a href="http://techcrunch.com/2009/03/02/yahoo-fined-by-belgian-court-for-refusing-to-give-up-e-mail-account-info/">Yahoo Fined By Belgian Court For Refusing To Give Up E-Mail Account Info</a></p>
<p>And there are a lot of cases like this. Cases where the data retention policy in one country asks for data up to 12 months and another country tells you that you are not allowed to keep data for longer than 8 months because of the Data Protection law – if you operate in both, what do you do?</p>
<p>The longer I work in this space the more complicated it gets for me and more of such challenges pop up. This morning I read the following article: <a href="http://blog.uncommonsensesecurity.com/2010/03/step-in-right-direction.html">A step in the right direction</a>. Basically this blog post covers a privacy law put in place in Massachusetts which has broad impact as it is valid not only if you are located in Massachusetts but if the company <em>owns or licenses, receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment</em>. In other words – if you “run the risk” of selling to somebody in Massachusetts, you are subject to this law! </p>
<p>As I said, the situation gets incredible complex.</p>
<p>Where does this lead us to? To me there are a few things which should be done:</p>
<ul>
<li>Governments and the industry have to work much closer together. The industry has to have the ability to show the stumbling blocks for the businesses and together &#8211; the government and the industry &#8211; have to find solutions which protects the citizens’ rights, helps to grow the economy and helps to go after the criminals. </li>
<li>Governments have to think globally and act locally. Today’s cybercrime environment does not allow anymore for “local only” solutions. There needs to be a certain level of harmonization of laws across the countries and the willingness to collaboration fast. As there is not a global jurisdiction on that level, the willingness to have harmonized legislation will be key. The challenge however is that governments are re-elected locally – not globally… </li>
<li>The Industry has to behave responsibly. In order to make this happen, the industry has to be seen as a partner for the government. The only way to get there – in my opinion – is to act responsibly. If I look at certain behaviors I see in the industry, it is sometimes too much focused on the short-term revenue, rather than a responsible behavior. </li>
</ul>
<p>This will definitely be the basis for a better collaboration and an environment where the legal challenges (see the Yahoo! case above) do not have to be solved on the shoulders of the businesses “just because” of legal deficiencies between countries. As I said above, we all want to fight crime as it is necessary and as it is the only way to grow the Internet in the future. And this all helps us I think</p>
<p>Roger   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Development Lifecycle &#8211; Website!</title>
		<link>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website</link>
		<comments>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:30:13 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[ecosystem]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[Threat Modeling]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website</guid>
		<description><![CDATA[I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as well. One of the ways is to communicate through our website. Not, that this is [...]]]></description>
			<content:encoded><![CDATA[<p>I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as well. One of the ways is to communicate through our website. Not, that this is really new news – it is actually a few weeks old but still… We renewed our <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle site</a>. </p>
<p>If you are developing software internally you should definitely look at the site and think how to implement SDL in your organization. If you want help, there is the <a href="http://www.microsoft.com/security/sdl/getstarted/pronetwork.aspx" target="_blank">SDL Pro Network</a> here to help you to implement SDL. Or <a href="http://www.microsoft.com/security/sdl/getstarted/tools.aspx" target="_blank">leverage the tools</a> we make available. Or much more…</p>
<p>If you are “just” buying software, look at the lifecycle and start to ask your vendors a few questions like:</p>
<ul>
<li>How do you engineer security into the products? (I am not talking about the classical software engineering processes – I am talking about security…) </li>
<li>How do you do Threat Modeling (to me a key piece of the engineering process) </li>
<li>… </li>
</ul>
<p>Roger   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why it pays to be secure &#8211; Chapter 5 &#8211; I need tools!</title>
		<link>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools</link>
		<comments>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools#comments</comments>
		<pubDate>Sat, 06 Mar 2010 23:23:56 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[standardization]]></category>
		<category><![CDATA[Tool]]></category>
		<category><![CDATA[Update Detection]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools</guid>
		<description><![CDATA[Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use.

So far, in the first 4 chapters, we have addressed the usual excuses for not Managing Your IT [...]]]></description>
			<content:encoded><![CDATA[<p>Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use.</p>
<hr />
<p>So far, in the first 4 chapters, we have addressed the usual excuses for not Managing Your IT Environment and Security Updates:</p>
<ol>
<li>Security is not worth it, nothing ever happens and if it does it will be “no big deal” </li>
<li>I installed the Microsoft updates, but my network was still compromised </li>
<li>OK now I understand why Security is important but no idea how I start </li>
<li>I now know what I want to do, I just don’t know how, I need training </li>
</ol>
<p>Here we address the need for automation, cost reduction and standardization, Microsoft has literally hundreds of tools to help management assess risk and administrators implement security updates and policies.</p>
<p><strong>Security Update Management Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EPC">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EPC</a></p>
<p><strong>Security Update Detection Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EID">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EID</a></p>
<p><strong>Security Risk Assessment Tool:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EUD">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EUD</a></p>
<p><strong>Lockdown, Auditing, Intrusion Detection, Remediation Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#E2D">http://technet.microsoft.com/en-gb/security/cc297183.aspx#E2D</a></p>
<p><strong>Virus and Malware Protection and Removal Tools &amp; Apps:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#E1E">http://technet.microsoft.com/en-gb/security/cc297183.aspx#E1E</a></p>
<p><strong><font color="#ff0000">Reduce Your Risk: 10 Security Rules To Live By</font></strong></p>
<p>This is from 2006 but it demonstrates on a conceptual level how the technology can change but the rules remain the same.&#160; <u>Yet again we learn that Security is a Process, not a Product!</u></p>
<p><a href="http://technet.microsoft.com/en-us/magazine/2006.05.reducerisk.aspx">http://technet.microsoft.com/en-us/magazine/2006.05.reducerisk.aspx</a></p>
<hr />Henk and Roger </p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Migrating My Blog</title>
		<link>http://www.halbheer.info/security/2010/03/06/migrating-my-blog</link>
		<comments>http://www.halbheer.info/security/2010/03/06/migrating-my-blog#comments</comments>
		<pubDate>Sat, 06 Mar 2010 14:54:56 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Codeplex]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SUSE]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/06/migrating-my-blog</guid>
		<description><![CDATA[If you are a regular reader of my blog, you might have been surprise today – but yes, it is still my blog  
From time to time I am looking into different ways of doing things. I ran my blog until now on SharePoint 2007 and an extension I found on Codeplex, which is [...]]]></description>
			<content:encoded><![CDATA[<p>If you are a regular reader of my blog, you might have been surprise today – <strong>but yes, it is still my blog <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </strong></p>
<p>From time to time I am looking into different ways of doing things. I ran my blog until now on SharePoint 2007 and an extension I found on Codeplex, which is part of the <a href="http://cks.codeplex.com/" target="_blank">Community Kit for SharePoint</a> called <a href="http://cks.codeplex.com/wikipage?title=Enhanced%20Blog%20Edition&amp;referringTitle=Home" target="_blank">Enhanced Blog Edition</a>. The reason for that was that I did not like the blog offered by SharePoint natively. </p>
<p>Now, I wanted to do a real revolutionary thing – for a Microsoftie <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> : I wanted to migrate the blog on a Linux server with OpenSource software. I have to admit I failed. I started to play with the SUSE Enterprise Server (remember, we have a partnership with Novell). I set it up on my Hyper-V and it worked fairly soon without too much problems. The problems came as a Microsoftie wanted to add what is needed to run a blog and integrate the SUSE Server into Active Directory. I just gave up after spending a couple of hours and rolled back my plan – at least for the OS. </p>
<p>So, I decided to install Windows Server 2008 R2 and from there on wanted to experience the OpenSource side. Now, the blog runs in Windows Server 2880 R2, PHP, MySQL and WordPress. Until now, I really like WordPress as it gives me a lot of flexibility with all the PlugIns – more than I actually need. The only real hassle I had was the migration of the blog posts but finally even that worked….</p>
<p>So, for you nothing should change. Basically even the RSS-feed should still work even though the default feed now has a new URL but I used URL Rewriter to map.</p>
<p>So, if you experience any issue, please get in touch with me (see the About page)</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/06/migrating-my-blog/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Security Essentials are not Microsoft Security Essentials</title>
		<link>http://www.halbheer.info/security/2010/03/01/when-security-essentials-are-not-microsoft-security-essentials</link>
		<comments>http://www.halbheer.info/security/2010/03/01/when-security-essentials-are-not-microsoft-security-essentials#comments</comments>
		<pubDate>Mon, 01 Mar 2010 17:01:32 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">/security/archive/2010/03/01/when-security-essentials-are-not-microsoft-security-essentials.aspx</guid>
		<description><![CDATA[It is so old: Software telling you that you are infected and that you have to install this latest security software immediately. You can bet that this then installs malware on your PC instead of cleaning it. We mentioned this problem already in the first chapters of our Security Intelligence Report v7. 
And it was [...]]]></description>
			<content:encoded><![CDATA[<p>It is so old: Software telling you that you are infected and that you have to install this latest security software immediately. You can bet that this then installs malware on your PC instead of cleaning it. We mentioned this problem already in the first chapters of our <a href="http://www.microsoft.com/sir" target="_blank">Security Intelligence Report v7</a>. </p>
<p>And it was to be expected that the success of the Microsoft Security Essentials will be leveraged by criminals as well to do exactly what I just mentioned – it happened last week. Read yourself: <a href="http://blogs.technet.com/mmpc/archive/2010/02/24/if-it-calls-itself-security-essentials-2010-then-it-s-possibly-fake-innit.aspx" target="_blank">If it calls itself “Security Essentials 2010”, then it’s possibly fake, innit?</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/01/when-security-essentials-are-not-microsoft-security-essentials/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Latest Internet Explorer 0Day</title>
		<link>http://www.halbheer.info/security/2010/03/01/the-latest-internet-explorer-0day</link>
		<comments>http://www.halbheer.info/security/2010/03/01/the-latest-internet-explorer-0day#comments</comments>
		<pubDate>Mon, 01 Mar 2010 10:33:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>

		<guid isPermaLink="false">/security/archive/2010/03/01/the-latest-internet-explorer-0day.aspx</guid>
		<description><![CDATA[As it happens: I have been skiing last week (the weather was gorgeous) and now I am back (unfortunately) and confronted with the next Internet Explorer 0Day vulnerability, which already causes noise – in my opinion too much for the real technical problem. If you read the blog post of the Microsoft Security Response Center [...]]]></description>
			<content:encoded><![CDATA[<p>As it happens: I have been skiing last week (the weather was gorgeous) and now I am back (unfortunately) and confronted with the next Internet Explorer 0Day vulnerability, which already causes noise – in my opinion too much for the real technical problem. If you read the blog post of the Microsoft Security Response Center called <a href="http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx" target="_blank">Investigating a new win32hlp and Internet Explorer issue</a>, you will find the following facts – as far as we know them by now:</p>
<ul>
<li>The user has to be tricked into pressing F1 in response to a Pop-Up (no automation) </li>
<li>We are not aware of any attacks exploiting this issue </li>
<li>It is Windows XP “only” </li>
</ul>
<p>This leads me back to the discussions I had with customers over the last few weeks: Windows XP was released 31. December 2001 – 8 years ago. If you would give it 2 years development and engineering time, we are talking of a 10 year old operating system. During a discussion a friend of mine said “your are not driving a 10 years old car neither” – which is not accurate. If you look how the threat landscape developed on the Internet over the last 10 years, you should probably compare it with a 50 years old car. The real problem with Windows XP in my opinion is, that it is rock-solid – but in my opinion not suited anymore for today’s threats. As you have a great alternative now – <strong>you should definitely consider moving to Windows 7. And you should move from IE 6 (if you are still there) to IE8!!</strong></p>
<p>If I would have one wish to you from a security perspective: Move to the latest version of your software – everywhere (knowing that this is not an easy task to do)</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/01/the-latest-internet-explorer-0day/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Making the Management of Security Compliance Easier!</title>
		<link>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier</link>
		<comments>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier#comments</comments>
		<pubDate>Thu, 18 Feb 2010 14:26:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>

		<guid isPermaLink="false">/security/archive/2010/02/18/making-the-management-of-security-compliance-easier.aspx</guid>
		<description><![CDATA[As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about how we can make it easier for our customers to manage compliance in their networks.
So, [...]]]></description>
			<content:encoded><![CDATA[<p>As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about how we can make it easier for our customers to manage compliance in their networks.</p>
<p>So, basically it is about helping you to plan, deploy, operate, and manage the baselines in your environment. As you might know, we provide free tools, which we call <a href="http://technet.microsoft.com/en-us/solutionaccelerators/cc835245.aspx" target="_blank">Solution Accelerators</a> since quite a while (if you did not know, shame on us), we provide a Security Compliance Manager in this program as well and have the new version just in Beta now. </p>
<p>Basically the new Security Compliance Manager Solution Accelerator helps you to provides you a few pretty exciting features:</p>
<ul>
<li>Centralized management and baseline portfolio</li>
<li>You can customize the security baselines</li>
<li>You can compare them and export them (e.g. to GPOs)</li>
<li>You can verify and monitor them</li>
</ul>
<p>As a picture shows more than a thousand words, here are a few (cool!!) screenshots of the tool:</p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313647/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x303[1]" border="0" alt="500x303[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x303[1]_1.png" width="500" height="303"></a> <em>Check for Baselines</em></p>
<p align="center"><em><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313648/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x268[1]" border="0" alt="500x268[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x268[1]_1.png" width="500" height="268"></a> Compare Baselines</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313649/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="521x480[1]" border="0" alt="521x480[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/521x480[1]_1.png" width="521" height="480"></a> <em>Customize the Baseline</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313650/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="535x480[1]" border="0" alt="535x480[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/535x480[1]_1.png" width="535" height="480"></a> <em>Export it (to enforce it through GPOs)</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313651/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x285[1]" border="0" alt="500x285[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x285[1]_1.png" width="500" height="285"></a><em> Merge different Baselines</em></p>
<p>So, if you are as excited as I am, you should join the Beta program, which is now open. That’s the way to give feedback and influence it now! Therefore my “call to action” for you is:</p>
<ul>
<li><a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&#038;InvitationID=SUN-TJKJ-7XWY&#038;SiteID=715">Join the Security Compliance Manager Beta.</a> Then tell the development team what you think!</li>
<li>Already a member? <a href="https://connect.microsoft.com/content/content.aspx?ContentID=10295&#038;SiteID=715">Bookmark this link for access to the program page.</a></li>
<li>Help us spread the word—<a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&#038;InvitationID=SUN-TJKJ-7XWY&#038;SiteID=715">share the beta invitation link with your friends</a>. </li>
<li>Want to see where it all started? <a href="http://download.microsoft.com/download/B/2/4/B24D224D-054A-46A2-BB30-925B943F00E1/Security Compliance Management Toolkit - All.zip">Download the current version: Security Compliance Management Toolkit.</a></li>
</ul>
<p>The beta will run through March 2010. That means now is the time to join the beta program, take an early look at this tool, and provide the Security Solution Accelerators team with your feedback. </p>
<p>Want the facts straight from the development team? <a href="http://www.youtube.com/user/SATSASC">Check out this series of short videos!</a> Better yet, post your own video response sharing your favorite feature. </p>
<p>Want more information on a specific feature? Interested in speaking with the development team? Please contact <a href="mailto:marney@microsoft.com?subject=SCM blogger's kit inquiry">Michelle Arney</a>. </p>
<p>Have a lot of fun!!</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
