Wednesday, October 11, 2017
"Hey America (and World) GDPR Applies to You To"
from lspitzner
Tuesday, October 10, 2017
SharePoint and OneDrive: security you can trust, control you can count on
This post is authored by Bill Baer, Senior Product Marketing Manager, SharePoint and OneDrive Team.
In todays complex and regulated environment, businesses need to focus on building more secure solutions that deliver value to their customers, partners, and shareholdersboth in the cloud and on-premises.
Microsoft has been building enterprise software for decades and running some of the largest online services in the world. We draw from this experience to keep making SharePoint and OneDrive more secure for users, by implementing and continuously improving security-aware software development, operational management, and threat-mitigation practices that are essential to the strong protection of your services and data.
SharePoint and OneDrive are uniquely positioned to help you address these evolving security challenges. To begin with, Microsoft has continued to evolve with new standards and regulations. This has been a guiding principle as we think about security for SharePoint and OneDrive. Right alongside that principle is this one: There is no security without usability. If security gets in the way of productivity, users will find a different, less secure way to do their work.
SharePoint and OneDrive allow your organization to go beyond its regular business rhythms and be nimbler in responding to market changes and opportunities. These solutions enable users to access the files and documents they need wherever they’re doing work while sharing and collaborating in real-time. And you control and own your data while Microsoft takes care of it. Explore the many options SharePoint and OneDrive provide to secure you and your information and then read our eBook Securing your content in the new world of work with SharePoint and OneDrive.
For businesses, the time is now to reevaluate security practices. In the modern communications and collaboration, landscape connectivity is ubiquitous and the ability to work remotely has become an ingrained part of the work practice. People have come to expect to be able to access email and documents from anywhere on any device – and for that experience to be seamless.
While this has been an enormous boost to productivity, it also presents huge challenges for security. Previously, businesses needed to concern themselves with a firewall that ended at the corporate boundary. Now that boundary has shifted to the end user. Businesses need to ensure sure that corporate data is safe while enabling users to stay productive in today’s mobile-first world, where the threat landscape is increasingly complex and sophisticated.
We know that data loss is non-negotiable, and overexposure to information can have legal and compliance implications. SharePoint and OneDrive provide a broad array of features and capabilities designed to make certain that your sensitive information remains that way with investments across our security and compliance principles to include compliance tools that span on-premises servers and Office 365 while providing a balance between enabling user self-service.
The rapidly-changing security landscape means that your organization’s content – its knowledge – is being shared more broadly, and accessed from more devices and more locations, than ever before. We’re committed to the security, privacy, and compliance of your data, and we continuously innovate intelligent ways to protect your content and to empower you to govern and manage information. Last month we announced label-based classification for information management policies, which enable a more dynamic governance of content across SharePoint, Exchange, and Skype, and Microsoft Teams. We’re continuously working to ensure content usage adheres to corporate policy defending your organization from todays growing and evolving advanced threats.
To learn more about security and compliance with SharePoint and OneDrive:
- Read more about how we secure your files
- Review Office 365 Trust where we share our commitments and information about security, privacy, and compliance
- Stay up to date with our security and compliance blogs
from Microsoft Secure Blog Staff
Monday, October 9, 2017
BruCON Network 0x09 Wrap-Up
BruCON 0x09 is over! It’s time to have a look at the data captured during the last Thursday and Friday. As the previous years, the setup was almost the same: An Internet pipe with a bunch of access-points, everything interconnected through a pfSense firewall. The guest network (dedicated to attendees) traffic is captured and processed by a SecurityOnion server + basic full packet capture. We also used our classic wall-of-sheep to track the web browsing activity of our beloved visitors.
Let’s start with a few raw numbers. With the end of the 3G/4G roaming costs in Europe since June, most European visitors avoid the usage of wireless networks and prefer to remain connected via their mobile phone. In a few numbers:
- 206 Gigabytes of PCAP files
- 50.450 pictures collected by the wall-of-sheep
- 19 credentials captured
- 500+ unique devices connected to the WiFi network
- 150 PE files downloaded (Windows executables)
- 3 blocked users
- 1 rogue DHCP server
We saw almost the same amount of traffic than the previous years (even if we had more people attending the conference!). What about our visitors?
Strange that we had some many “unknown” device. Probably due to an outdated MAC address prefixes databases.
Good to see that SSL is the top protocol detected! UDP reached the third-position due to the massive use of VPN connections. Which is also good!
Our visitors communicated with 118K+ IP addresses from all over the word:
Here is the top-20 of DNS requests logged:
|
Rank |
FQDN | Hits |
|
1 |
api.dataplicity.com |
59310 |
|
2 |
www.google.com |
20097 |
|
3 |
softwareupdate.vmware.com |
9050 |
|
4 |
auth.gfx.ms |
6766 |
|
5 |
swscan.apple.com |
6706 |
|
6 |
v10.vortex-win.data.microsoft.com |
5300 |
|
7 |
www.googleapis.com |
5252 |
|
8 |
www.icanhazip.com |
4402 |
|
9 |
www.google.be |
3831 |
|
10 |
clients4.google.com |
3721 |
|
11 |
play.google.com |
3562 |
|
12 |
win10.ipv6.microsoft.com |
3459 |
|
13 |
outlook.office365.com |
3267 |
|
14 |
ssl.gstatic.com |
3130 |
|
15 |
settings-win.data.microsoft.com |
3111 |
|
16 |
pingsl.avast.com |
2884 |
|
17 |
safebrowsing-cache.google.com |
2841 |
|
18 |
avast.com.edgesuite.net |
2533 |
|
19 |
graph.facebook.com |
2164 |
|
20 |
0x13.nl |
1990 |
As most of the traffic captured was web-based, I had a look at the different tools/applications used to access web resources. Here is the top-20:
|
Rank |
FQDN |
|
1 |
Firefox |
|
2 |
Chrome |
|
3 |
Microsoft-CryptoAPI |
|
4 |
Microsoft |
|
5 |
Safari |
|
6 |
Dalvik |
|
7 |
trustd |
|
8 |
MSIE |
|
9 |
cloudd |
|
10 |
Debian |
|
11 |
Windows-Update-Agent |
|
12 |
iPhone |
|
13 |
Unspecified |
|
14 |
Microsoft-WNS |
|
15 |
CaptiveNetworkSupport |
|
16 |
serer-bag |
|
17 |
MICROSOFT_DEVICE_METADATA_RETRIEVAL_CLIENT (1) |
|
18 |
Spotify |
|
19 |
Unknown |
|
20 |
Microsoft-Delivery-Optimization |
(1) https://docs.microsoft.com/en-us/windows-hardware/drivers/install/device-metadata-retrieval-client
I uploaded the 200+ gigabytes of PCAP data into my Moloch instance and searched for interesting traffic. What has been found:
- One visitor polled his network devices (172.16.x.x) during the two days (5995 SNMP connections detected)
- Two visitors performed RDP sessions to two external IP addresses
- Two visitors generated SIP (VoIP) traffic with two remote servers
- 29 remote IMAP servers were identified (strange, no POP3!
- SSH connections were established with 36 remote servers (no telnet!)
Finally, our wall-of-sheep captured web traffic during the whole conference:
Of course, we had some “p0rn denial of service attacks” but it’s part of the game right? See you for the 0x0A (10th edition) next year with, crossing fingers, more fun on the network!
[The post BruCON Network 0x09 Wrap-Up has been first published on /dev/random]
from Xavier
[SANS ISC] Base64 All The Things!
I published the following diary on isc.sans.org: “Base64 All The Things!“.
Here is an interesting maldoc sample captured with my spam trap. The attached file is “PO# 36-14673.DOC” and has a score of 6 on VT. The file contains Open XML data that refers to an invoice.. [Read more]
[The post [SANS ISC] Base64 All The Things! has been first published on /dev/random]
from Xavier
Thursday, October 5, 2017
"The Five Tenets of Cyber Security"
from lspitzner
Announcing support for TLS 1.1 and TLS 1.2 in XP POSReady 2009
This post is authored by Arden White, Senior Program Manager, Windows Servicingand Delivery.
As a follow-up to our announcement regarding TLS 1.2 support at Microsoft, we are announcing that support for TLS1.1/TLS 1.2 on Windows Embedded POSReady 2009 and Windows Embedded Standard 2009 is now available for download as of October 17th, 2017. Were offering this support in recognition that our customers have a strong demand for support for these newer protocols in their environment.
This update for Windows Embedded POSReady 2009 and Windows Embedded Standard 2009 will include support for both TLS 1.1 and TLS 1.2. For application compatibility purposes, these protocols will be disabled by default in a manner similar to the TLS 1.1/TLS 1.2 support that was disabled by default in Windows 7 and Windows Server 2008 R2. After downloading and installing the update these protocols can be enabled by setting the registry keys described in KB4019276.
This update is being made available on the following timeline:
| Release Date | Channels | Classification |
| October 17, 2017 | Microsoft Catalog | |
| January 16, 2018 | Windows Update/WSUS/Catalog | Optional |
| February 13, 2018 | Windows Update/WSUS/Catalog | Recommended |
from Microsoft Secure Blog Staff
Wednesday, October 4, 2017
"October OUCH! Newsletter - Something Special for #CyberAware Month"
from lspitzner




