Dr. Tom Shinder’s Blog

All Blogs  »  Dr. Tom Shinder's Blog  »  Archive: January 2009

Google Flags Entire Internet As Malware

Got up this morning and found that every site returned by Google on a search was flagged as malware. Check out this link for details:

http://www.techcrunch.com/2009/01/31/google-flags-...lware/

image

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Why You Need an ISA Firewall Behind an ASA

Excellent post by Richard Hick on why ASA security gateways can’t replace the protection provided by ISA firewalls.

Check out Richard’s excellent post at:

http://tmgblog.richardhicks.com/2009/01/22/isa-beh...o-asa/

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Developers — Test Your Security IQ

Nice article that covers 10 questions for developers to see if you’re up to snuff in your secure coding practices.

http://msdn.microsoft.com/en-us/magazine/cc982154.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Creating a Strong Password Policy

You’ve heard the drill — you need to enforce a strong password policy. Makes sense, but exactly how should you go about it? Here’s a nice article that can get you up to speed on password policies in a matter of minutes.

Check it out at:

http://technet.microsoft.com/en-us/library/cc736605.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Deployment of the Microsoft Windows Malicious Software Removal Tool in an enterprise environment

“Microsoft has released the Microsoft Windows Malicious Software Removal Tool to help you remove specific, prevalent malicious software from a computer.
The information that is contained in this article is specific to the enterprise deployment of the tool. We highly recommend that you review the following Microsoft Knowledge Base article. It contains general information about the tool and about the download locations.
For more information, click the following article number to view the article in the Microsoft Knowledge Base:

890830 (http://support.microsoft.com/kb/890830/ ) The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Vista, Windows Server 2003, Windows XP, or Windows 2000

The tool is primarily intended for noncorporate users who do not have an existing, up-to-date antivirus product installed on their computers. However, the tool can also be deployed in an enterprise environment to enhance existing protection and as part of a defense-in-depth strategy. To deploy the tool in an enterprise environment, you can use one or more of the following methods:

  • Windows Server Update Services
  • Microsoft Systems Management Software (SMS) software package
  • Group Policy-based computer startup script
  • Group Policy-based user logon script

For more information about how to deploy the tool through Windows Update and Automatic Updates, click the following article number to view the article in the Microsoft Knowledge Base:

890830 (http://support.microsoft.com/kb/890830/ ) The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Vista, Windows Server 2003, Windows Server 2008, Windows XP, or Windows 2000″

Head on over to http://support.microsoft.com/kb/891716 for more information

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Centralized Information About The Conficker Worm

Everything you need to know about the Conficker Worm can be found here:

http://blogs.technet.com/mmpc/archive/2009/01/22/c...m.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Evaluate Microsoft Identity Lifecycle Manager “2” RC today

Identity Lifecycle Manager (ILM) ”2” delivers an integrated identity management solution with powerful self-service capabilities for Office end-users, rich administrative tools and enhanced automation for IT professionals and .NET and WS-* based extensibility for developers.  ILM “2″ provides organizations with unique workflow driven solutions to manage user accounts, passwords, groups and distribution lists as well as certificate-based credentials such as smart cards, using identity-based policies that can span across Windows and heterogeneous environments. And when you download the latest beta software, you’re automatically registered to access valuable beta resources assembled in one convenient location.

Get it here:

http://technet.microsoft.com/en-us/evalcenter/cc87...1.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Responding to Security Incidents

In addition to managing security vulnerabilities, the Microsoft Security Response Center (MSRC) leads an unparalleled worldwide response process, the Software Security Incident Response Process (SSIRP). The SSIRP was designed to help the MSRC quickly gain a thorough understanding of security incidents—situations that arise when malicious users deliberately exploit vulnerabilities—then effectively investigate, analyze, and resolve them.

For more information, check out:

http://www.microsoft.com/security/msrc/incident_re...e.mspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Improving Network Security and Operational Effectiveness with Office Groove 2007

Learn how Office Groove 2007 can aid you in improving security and operational effectiveness at a very low cost. Topics include auditing capabilities, implementing securities, handling data, and identity securities.

Check out this video Webcast from TechEd at:

http://mfile.akamai.com/14853/wmv/microsofttec.dow...ow.asx

 

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Safeguarding Remote Access in a Connected World

Nice article by Security MVP Dana Epp that discusses the various options for secure remote access to Microsoft networks. He’s even kind enough to mention the article I did with Yuri Diogenes on how to securely publish TSGateway using the ISA Firewall.

Check out his article at:

http://technet.microsoft.com/en-us/library/dd323621.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center