Friday, October 18, 2013

'Jump boxes' improve security, if you set them up right



With malicious hackers and malware infesting nearly every enterprise network these days, "jump boxes" have become very popular. A jump box is a specially secured computer that administrators must (or should) log on to in order to gain access to other computers and administrate them. The hope is that these jump boxes are specially secured -- and are less likely to get exploited by hackers or malware.


Jump boxes can decrease risk, but you need to implement their special protections properly. Many enterprises start with the best of intentions, but when I audit jump boxes, I often see a jumble of weak security policies and high-risk behaviors that make them just as insecure as a regular user's PC.


[ Take a tour of the latest threats and what you can do to stop them in InfoWorld's Malware Deep Dive Report. | Learn how to secure your systems with InfoWorld's Security Central newsletter. ]


In the computer security world, a basic premise underlies setting up a "secure environment": Systems of lower trust should never be able to modify or control systems of higher trust or importance. Most jump boxes tend to break this basic rule because the computers people use to connect to jump boxes are less trustworthy than the jump boxes themselves.


Often, PCs that connect to jump boxes are open to the Internet all day long and can be as infected and exploited as any other computer in your environment. What good is a jump box if the computer connecting to it has a keylogging Trojan copying every password or smartcard token you use? Your jump box and the computer linking to it -- let's call it the "originating computer" for this discussion -- should both be highly secure systems.


Here are the protective measures you should take for jump boxes and the systems that connect to them.


Security hardened
Most of today's operating systems and applications come fairly well secured. Don't mess it up. Consider configuring the originating computer and jump server with the "high security" settings if they exist. You want to enforce only the best and most secure protocols and options.


Strong authentication
If you use regular passwords, they should be long and complex (15 characters or more). Try to require smartcards or other two-factor authentication methods for all elevated users. If you're managing multiple environments (that is, different forests), make sure logon credentials are not shared among environments. If you use smartcards, key fobs, or other two-factor authentication, make sure those aren't shared, either. Yes, it'll be harder to administrate multiple environments. But if you share that stuff, why have different environments in the first place?


No browsing the Internet
If I check your jump box and see it has a browser installed or can browse to the Internet unhindered, then you've failed the audit. Browsing the Internet is a high-risk activity that should not be allowed either on the jump box or the originating computer. I know many of you probably use your regular workstation to connect to jump boxes. This is a bad idea. Use a separate computer (or VM) to connect to your jump box. That originating computer should not be able to browse the Internet to any site; if you allow it to connect only to vendor sites and legitimate driver download sites, that's OK.


Source: http://www.infoworld.com/d/security/jump-boxes-improve-security-if-you-set-them-right-228742?source=rss_infoworld_top_stories_
Tags: amanda knox   once upon a time   college football   Riley Cooper   detroit  

Users hit by Blue Screen, 0xC1900101 - 0x40017 error with Windows 8.1 update



The Microsoft Answers forum is abuzz with a problem that seems to affect many people trying to update from Windows 8 to Windows 8.1. It's a show-stopper that throws up two Blue Screens when the Win 8.1 installer reboots. Microsoft has a couple of suggestions for recovering from the problem, but at this point it doesn't look like the solutions fix the problem. Further confounding the situation, the problem existed back in June, with the Windows 8.1 Preview Milestone, and apparently hasn't been fixed.


Martin Dixon posted the seminal question shortly after Microsoft released the Windows 8.1 bits. Here's how he describes his update:



I have downloaded the Windows 8.1 update from the store but cannot get it to install. Each time I try, I get to the point where it is "getting my devices ready", then the PC restarts to a blue screen with error message. It then tries to recover the installation, fails, then restores Windows 8. When the system boots up after this, I get a message saying:

"Couldn't update to Windows 8.1

Sorry, we couldn't complete the update to Windows 8.1. We've restored your previous version of Windows to this PC.

0xC1900101 - 0x40017"

There is no explanation as to why the update could be completed.



Microsoft Support Engineer Ravish Govind posted two different methods for trying to work around the problem -- unplug external devices and try again; and update all drivers. Neither approach worked, for any of the people posting on the Answers forum.


Suspicions have turned to graphics drivers, but nobody's figured out the source of the problem, much less its cure. Parris at EpicReviewsTech posted a video explaining how to recover from the problem in Windows 8.1 Preview Milestone -- but he didn't find a fix, and the bug manifests itself differently with the Windows 8.1 RTM online update.


If you're encountering BSODs with 0xC1900101 - 0x40017, it would be a very good idea to hop over to the Answers forum and post details about your hardware configuration. Maybe Microsoft can find a solution.


This story, "Users hit by Blue Screen, 0xC1900101 - 0x40017 error with Windows 8.1 update," was originally published at InfoWorld.com. Get the first word on what the important tech news really means with the InfoWorld Tech Watch blog. For the latest developments in business technology news, follow InfoWorld.com on Twitter.


Source: http://www.infoworld.com/t/microsoft-windows/users-hit-blue-screen-0xc1900101-0x40017-error-windows-81-update-229058?source=rss_infoworld_blogs
Related Topics: American Horror Story   Miley Cyrus Wrecking Ball   Sloane Stephens   Brickyard 400   Best Song Ever  

Jamie Foxx Slated to Take on Role of Martin Luther King Jr.

Confirming to the Wall Street Journal that Dr. Martin Luther King’s “Dream” will live on, “Wall Street: Money Never Sleeps” director Oliver Stone just announced today (October 17) that Jamie Foxx will play the iconic Civil Rights leader on the big screen.


"We're looking for a way to relate to this extraordinary man," Stone told the Journal of the film, which is described by the paper as an "authorized version" of MLK's life story. According to The Wrap, several members of the King family are expected to serve as executive producers.


The director/screenwriter has long been attracted to scripts with historical and political significance, previosuly directing 1991's “JFK,” 1995's “Nixon,” and 2008's “W.” He also worked together with Foxx on the 1999 football drama, "Any Given Sunday."


Winning an Oscar for bringing Ray Charles to life in the 2004 biopic “Ray,” Jamie Foxx is by no means a stranger to the biopic genre.


Source: http://celebrity-gossip.net/jamie-foxx/jamie-foxx-slated-take-role-martin-luther-king-jr-944928
Tags: mlb   Cody Rhodes   Farmers Almanac   meteor shower   Derek Medina  

Thursday, October 17, 2013

San Francisco rail workers plan strike barring last-minute deal: union


SAN FRANCISCO (Reuters) - Commuter rail workers in San Francisco will go on strike on Friday unless a last-minute deal with management on a contract is reached before midnight on Thursday, an employee union said in a statement.


The plan for a strike on Friday follows a series of marathon bargaining sessions between the Bay Area Rapid Transit (BART) and employee unions. The Service Employees International Union Local 1021 said the two sides had reached an understanding on economic issues but remained at odds over workplace rules.


(Reporting by Laila Kearney, Writing by Alex Dobuzinskis; Editing by Cynthia Johnston)



Source: http://news.yahoo.com/san-francisco-rail-workers-plan-strike-barring-last-232156643--finance.html
Similar Articles: elton john   jadeveon clowney   Delbert Belton   Whitey Bulger   Baby I Ariana Grande  

Incoming comet ISON appears intact to NASA's hubble

[unable to retrieve full-text content]A new image of the sunward plunging Comet ISON taken by NASA's Hubble Space Telescope on October 9, 2013, suggests that the comet is intact despite some predictions that the fragile icy nucleus might disintegrate as the Sun warms it. The comet will pass closest to the Sun on November 28.Source: http://www.sciencedaily.com/releases/2013/10/131017144412.htm
Tags: new orleans saints   elton john   US News college rankings   apple   joe flacco  

Verizon third quarter earnings, revenue beat Wall Street estimates


NEW YORK (Reuters) - Verizon Communications Inc on Thursday posted stronger- than-expected third-quarter earnings and revenue on strong wireless growth, sending its shares up 2.4 percent in early trade.


While the company's wireless customer growth numbers were slightly below Wall Street estimates, its Verizon Wireless venture with Vodafone Group Plc posted good profit and revenue growth as customers spent more on their services.


"The numbers were fine but it wasn't a blowout quarter. It was a good third quarter," said Hudson Square analyst Todd Rethemeier.


Verizon Wireless added 927,000 net retail subscribers in the quarter, compared with Wall Street expectations of about 1 million customers, according to eight analysts, with estimates ranging from 900,000 to 1.2 million. Verizon has agreed to buy out Vodafone's 45 percent share of the mobile venture.


Verizon said it expects wireless customer growth to improve sequentially in the fourth quarter.


Verizon reported a third-quarter profit of $2.2 billion, or 78 cents per share, compared with $1.59 billion, or 56 cents per share, a year ago.


Excluding unusual items, Verizon earned 77 cents per share in the quarter, compared with Wall Street expectations of 74 cents, according to Thomson Reuters I/B/E/S.


Its wireless profit margin was 51.1 percent, based on earnings before interest, taxes, depreciation and amortization(EBITDA) as a percentage of service revenue, and above its target range of 49 percent to 50 percent for the full year.


Rethemeier said the profit margin would likely come down in the fourth quarter due to steep holiday season costs, since the company kept its wireless margin target for the year despite the strong third-quarter number.


Revenue rose 4.4 to $30.28 billion from $29.01 billion. Wall Street expected $30.16 billion, according to Thomson Reuters I/B/E/S.


A 7.2 percent increase in wireless revenue for the quarter was offset by a slower 4.3 percent rise in wireline revenue.


Verizon shares rose 2.4 percent to $48.40 in premarket trading after closing at $47.25 in the regular New York Stock Exchange session.


(Reporting by Sinead Carew; Editing by Jeffrey Benkoe)



Source: http://news.yahoo.com/verizon-posts-higher-quarterly-revenue-114734155--finance.html
Similar Articles: Hiroshi Yamauchi   USA VS Mexico   powerball winning numbers   cote de pablo   Tropical Storm Flossie  

Katy Perry Releases Prism's Second Single, "Unconditional!"

Hitting us hard with a brand new single from her album, Prism, Katy Perry just released "Unconditional" today (October 16).


The tune is featured on the 28-year-old singer’s new Prism album. She stated that it is her favorite song of the entire track list.


“It’s a love song and it’s different from ‘Roar’ — it’s not eighth-notey,” Katy told MTV about the song. “I think it’s a universal love song that everyone’s going to be able to relate to no matter the age, no matter male or female. It’s my favorite song off the record.”


The song possesses an epic, adventurous vibe, and the chorus reads:

"Unconditional, unconditionally

I will love you unconditionally

There is no fear now

Let go and just be free

I will love you unconditionally."


Listen to Katy Perry's brand new single, and stay linked to GossipCenter for the latest updates on the further release of Prism's singles!



Source: http://celebrity-gossip.net/katy-perry/katy-perry-releases-prisms-second-single-unconditional-944225
Related Topics: Capitol shooting   Seaside Heights   sons of anarchy   fox sports   ny times