Secure Coding Questions


Dos attack
I have been receiving security alert messages from our firewall nearly everyday. e.g TCP Packet – Source:144.120.8.89,39341 Destination:192.168.1.1,25 – [DOS] TCP Packet – Source:210.7.0.36,3473 Destination:210.7.12.23,135 – [DOS] Thu, 2006-10-19 16:30:03 – UDP Packet – Source:192.168.1.111,1443 Destination:202.62.124.238,53 – [Any(ALL) match] can someone help me… Thanks in advance Wanz.

Answer Question   |  July 8, 2009  4:36 PM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Running Syantec Antivirus on a Windows Domain Controller
I am currently in the process of deploying Symantec AntiVirus Corporate edition in my Windows-based network. In the manual it states, Do not install the primary management server on the following: Miscrosoft Exchange Server, Web server, or programs that prevent you from restarting the computer at any given time. I assume the last one would [...]

Answer Question   |  November 24, 2007  9:53 AM
Access control, Application security, backdoors, Biometrics, Browsers, configuration, Current threats, Database, Desktops, Development, Digital certificates, Encryption, Exchange, filtering, Hacking, human factors, Identity & Access Management, Instant Messaging, Management, Microsoft Windows, Networking, OS, patching, PEN testing, Platform Security, provisioning, Secure Coding, Security, Security tokens, Servers, Single sign-on, Spyware, SQL Server, SSL/TLS, Trojans, Viruses, vulnerability management, Web security, worms
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

Caching of previous Internet Passwords on Domino Server
I know that there is quite a bit in the discussion groups about cached Domino internet passwords but nothing seems to really point to a definitive solution, so I am turning to this group to see if an answer has been found. 2 Questions: - do you know how to force the clearing or know [...]

Answer Question   |  August 18, 2006  4:49 PM
Application security, Database, Encryption, Exchange, Instant Messaging, Lotus Domino, Secure Coding
asked by:
0 pts.

asked by:
0 pts.

Best authentication method
I’m researching authentication methods, trying to determine what method is best for allowing customers to make payments online. Which, in your opinion, is best?

Answer Question   |  May 28, 2008  5:31 PM
Access control, Application security, Biometrics, Browsers, Database, Digital certificates, Encryption, Exchange, filtering, Identity & Access Management, Instant Messaging, provisioning, Secure Coding, Security tokens, Servers, Single sign-on, SSL/TLS, Web security
asked by:
0 pts.

Installation and updates
Howdy folks, Tryin to keep things going around here….need some advice. I have Win2003 servers and Active Directory…..single domain….approx. 100 client computers…..one location. Am upgrading all computers from Office XP to Office 2003. My project: Install Office 2003 and all updates remotely without going to each machine. My progress: I tried the method of creating [...]

Answer Question   |  April 23, 2008  9:36 PM
Access control, Active Directory, Application security, backdoors, Bandwidth, Browsers, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, DataCenter, Desktop management applications, Desktops, Development, DHCP, Disaster Recovery, Distribution/logistics applications, DNS, Encryption, Ethernet, Exchange, filtering, Firewalls, Forensics, General Directories, Hacking, Hardware, Help Desk, Hubs, human factors, Incident response, Instant Messaging, Intrusion management, Lotus Domino, Management, Microsoft Office, Microsoft Operations Manager, Microsoft Systems Management Server, Microsoft Windows, Network applications management, Network management software, Network monitoring, Network protocols, Network security, Networking, Networking services, OS, Patch management, patching, PEN testing, Platform Security, Policies, Project management, Protocol analysis, Remote management, Risk management, Routers, Secure Coding, Security, Security Program Management, Servers, Software, Software testing, Spyware, SQL Server, SSL/TLS, Switches, Systems management software, TCP, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Network Connection Freezes
For some reason, at random, among 20 PCs on my network, in the morning or during the day, the network connection stops responding for both intranet and internet communications. The only solution thus far is to remove the NIC from the Device Manager, reboot the PC, and let Windows XP Pro find the network card [...]

Answer Question   |  September 1, 2010  11:31 AM
3Com, Access, Access control, Active Directory, Application security, Availability, Avaya, backdoors, Bandwidth, Bind, Biometrics, Browsers, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, DataCenter, Dell, Desktops, DHCP, Digital certificates, Disaster Recovery, DNS, Encryption, Enterasys, Ethernet, Exchange, FDDI, filtering, Firewalls, Forensics, Foundry, Frame Relay, General Directories, H.323, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, Identity & Access Management, Incident response, Instant Messaging, Interoperability, Intrusion management, IPv4, IPv6, Juniper Networks, LDAP, Lotus Domino, Lucent, Management, Microprocessors, Microsoft Office, Microsoft Windows, MPLS, NetBIOS, Network monitoring, Network protocols, Network security, Networking, Networking services, NFS, NIC, Nortel, Novell IPX/SPX, Novell NDS, OS, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Printers, provisioning, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, SIP, Software, Spyware, SQL Server, SSL/TLS, Switches, TCP, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, WINS, Wireless, worms
asked by:
0 pts.

USB Flash Drives Not Installing On XP
Hello All! I’ve been noticing recently that certain USB drives have not been installing automatically to windows XP pro. I’m working on one right now and have not found a solution to it yet. A user needs to install a Sandisk Cruzer Mini USB Drive to her machine which uses XP Pro. Instead of installing [...]

Answer Question   |  July 28, 2006  8:57 PM
Access control, Application security, Availability, backdoors, Backup & recovery, Browsers, Career development, Current threats, Database, DataCenter, Desktop management applications, Desktops, Development, Encryption, Exchange, filtering, Hacking, Hardware, Hewlett-Packard, human factors, Instant Messaging, Management, Microsoft Office, Microsoft Windows, Networking, OS, Patch management, SCSI, Secure Coding, Security, Servers, Software, Software testing, Spyware, SQL Server, SSL/TLS, Storage, Storage management, Storage products and equipment, Tape drives/Libraries, Tech support, Training, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Tracking the computer or source of an email
system: Ex 2003 back-end cluster, Ex 2003 Network Load Balanced Front end. Hi there, A user’s account has become comprimised. They have since changed their password, but there are a few mails sent from their account that they did not send. Is it possible to find out the source ie PC hostname or IP address [...]

Answer Question   |  August 11, 2011  3:55 AM
Application security, Biometrics, Database, Digital certificates, Encryption, Exchange, Exchange security, Firewalls, Forensics, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, provisioning, Secure Coding, Security tokens, Single sign-on, VPN, Wireless
asked by:
0 pts.

Resticting QPGMR from selected objects (SOX related)
Our security level is 30, but I have not found a way to restrict QPGMR from deleting a member in an audit file. Any help on this.

Answer Question   |  July 21, 2006  8:11 PM
Application security, Database, DataCenter, Encryption, Exchange, Instant Messaging, Secure Coding
asked by:
0 pts.

Passwords
Hi all, What do you recommend for initial password issue, that is, provided a new user with a password for the first time without compromising it. I find the entire help desk giving password initially or sysadmins doing that is not save enough even though the user will be prompted to change it at first [...]

Answer Question   |  November 24, 2007  8:11 AM
Access control, Application security, backdoors, Biometrics, Browsers, Business/IT alignment, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, Exchange security, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

Laptop Security…
Hi, I am the head of my department and by the nature of the job I hold some confidential information on my laptop. How do I ensure that 1. Nobody can access any files on my laptop from the LAN or the internet (not even sys admins) 2. If somebody tries to access, can I [...]

Answer Question   |  June 27, 2006  9:31 AM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, DataCenter, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

CLASP guidelines
My company is considering implementing the CLASP (Comprehensive, Lightweight, Application, Security Process) in our development cycle. Has anyone done this? How was it handled? How did it affect production? Any info you can share would be extremely helpful.

Answer Question   |  August 3, 2006  3:42 PM
Application security, Database, Development, Encryption, Exchange, Instant Messaging, Lifecycle development, Project management, Secure Coding
asked by:
0 pts.

Opinions about firewalls and VPN
I currently have watchguard firewalls and IPSec tunnels between them and the other watchguard firewalls. We also have remote users VPN into the firewall for access to our network. Our firewalls are fine but we haven’t been that happy with the support over the last 5 or so years. We are joining together with another [...]

Answer Question   |  June 28, 2006  9:56 AM
Active Directory, Application security, Budgeting, Cabling, Cisco, Database, Dell, Desktops, DHCP, DNS, Encryption, Exchange, Firewalls, Forensics, Foundry, Hardware, Hubs, Incident response, Instant Messaging, Intrusion management, Juniper Networks, Management, Microsoft Windows, Network security, Networking, Networking services, OS, Project management, Routers, Secure Coding, Security, Servers, SQL Server, Switches, VPN, Wireless
asked by:
0 pts.

How to Block Chat in the Network
Dear All, I am wrting this mail to you all, to know if any you have been successfull in Blocking Chats on your networks, and if so, then how have you acheived it? Could you please tell me which Ports to Block for MSN, Yahoo, Rediff, ICQ, Skype. I am using a NetAPPs Net Cache [...]

Answer Question   |  February 25, 2010  4:13 AM
Application security, Database, DataCenter, Encryption, Exchange, Firewalls, Forensics, Incident response, Instant Messaging, Intrusion management, Network security, Secure Coding, VPN, Wireless
asked by:
0 pts.

SAVACTWAIT time on SAVLIB, etc.
Hi, Has anyone experimented with the SAVACTWAIT time on the SAVLIB command. The default on 120 second seems rather long. What I am looking for is a realistic value based on fact such as that if an object does not become available after 5 second the change that it will become available after 120 seconds [...]

Answer Question   |  November 30, 2010  8:19 AM
Application security, AS/400, Backup & recovery, Data analysis, Database, DataCenter, DB2, DB2 Universal Database, Encryption, Exchange, Instant Messaging, Oracle, Secure Coding, Security
asked by:
5 pts.

Local LAN Vulnerabilities and Open Ports NAT
QUESTION: How someone would go about exploiting a vulnerability within a LAN sitting behind a router running NAT/NAPT…where would you start? Hacking the open port? Routing Tables? Accessing remote administration on the modem? (disable NAT)?? bah… MY SYSTEM/SETUP: I have 1 XP SP2 Machine running providing PPTP VPN connections and a Webcam Security System (webcamxp) [...]

Answer Question   |  May 26, 2006  7:43 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.