<<SBS News this week -- July 27th 2003>>

[Sorry Kevin this is more important]

AND WINDOWS.  It's a matter of time before a worm/virus is built to take
advantage of this vulnerability.  Patch.

His justification.... "Releasing *functional* exploit code to
the public is one of the few methods that actually make a difference
when it comes to improving the overall security of the Internet."

[Full-Disclosure] DCOM RPC exploit (dcom.c):

It sets up a remote shell and connects via port 4444.
Uninstall the hotfix and wait until further notice
MS03-029: A Flaw in a Windows Function Might Allow a Denial of Service:
breaks the SBS 4.5 boxes  [RRAS falls over and you have to remove the
Now back to our regularly scheduled News of the week...
Kevin's song of the week.....
SMB-Nation SBS Conference!
Visit the SMB Nation site at www.smbnation.com for details and online
registration. You may also register via telephone at: Domestic USA
1-800-461-1931, International 1-800-688-4890

FREE Advanced SBS Workshops in USA

Here is the current list of cities where SBS author Harry Brelsford will
be presenting a free 2-hour Advanced SBS Workshop.  This is a lecture
format similar to a Microsoft TS2 event but in-depth SBS content.  This
workshop has already been presented in 15 USA cities in 2003!

Lecture topics include SBS-specific security matters, advanced Microsoft
Exchange functionality, and advanced SBS administration.  It is
recommended you bring a copy of "Small Business Server 2000 Best
Practices" to the event for reference (please purchase in advance from
book resellers as book copies will not be sold at event).

Advanced Small Business Server 2000 Workshops
(2-hours, 7pm-9pm, FREE)

Chicago, IL                8-20-03
Cleveland, OH            8-21-03
Columbus, OH           8-22-03
Dayton, OH               8-23-03* (read important note below for this
Indianapolis, IN          8-24-03

* This is part of ComputerFest (www.computerfest.com) and will be
presented at 2pm (Saturday). Note that ComputerFest has a modest two-day
admission charge you will need to pay: $10.00. Details at:

To register, send e-mail to r**********lthmon.com and
put a city name from the above list in the e-mail Subject line.
Just in case you think those of us in Microsoft land are having all the
MandrakeSoft withdraws 'unsafe' Linux update
The Linux distributor has advised users not to install
a recent update to the Mandrake Linux 9.1 kernel, after
discovering a serious flaw MandrakeSoft has advised
users of its Mandrake Linux 9.1 operating system not
to install a security update released on Sunday due
to a serious security bug in the update. If users
have already installed the update, MandrakeSoft
urged them to downgrade to a previous version
if possible.

I think in general... it's just safe to say we're screwed no matter what
OS we pick  ;-)
I think it's also safe to say that we aren't just IT consultants around
here anymore...in our own little way we're all security consultants
Easiest to change
Hardest to convince bosses
First level of defense

Question ... which of these is the best password and will take L0ftcrack
and other password cracking programs the longest to crack?


answer at the bottom......
- - - - - - - - - -
Turn off the LanMan Hash... see the bottom...

Windows Passwords Cracked in Record Time
With the advances detailed in Oechslin's paper,
a hacker with even modest resources can compromise
alphanumeric Windows passwords quickly. Exposing
a weakness in Windows encryption Latest News about
encryption technology, Swiss researchers have published
a paper detailing how to crack Windows computers
protected by alphanumeric passwords in an average
of 13.6 seconds. The paper's lead author, Philippe
Oechslin, told NewsFactor that his research is not
specifically about Windows software. "I'm looking
for encryption systems where there is no random
information for security encryption," he said.

- - - - - - - - - -
Code could unleash Windows worm
Hackers release code to exploit flaw announced last
week. A hacker group released code designed to exploit
a widespread Windows flaw, paving the way for a major
worm attack as soon as this weekend, warned security
researchers. The warning came Friday, after hackers
from the Chinese X Focus security group forwarded
source code to several public security lists. The
code is for a program designed to allow an intruder
to enter Windows computers.

Week in review: Cracking codes
- - - - - - - - - -
Credit card hackers swap tricks online
Chatrooms used for sharing hints and tips in growing
business of ID theft. Thieves are using chat rooms to
sell stolen credit card details and advise others how
to hack websites containing credit information, security
experts have warned. Groups using internet relay chat
(IRC) are playing a growing role in online credit
card fraud.

ISP alleviates risk of unauthorised bank account access
- - - - - - - - - -
Microsoft studying multilevel security desktops
The effort is seen as critically important to
homeland security and information-sharing efforts
Microsoft Corp. is working with the government in
studying one of the most pressing challenges in
federal information security, one that is critically
important to future homeland security and information
sharing efforts: multilevel security workstations.

- - - - - - - - - -
Online Identity-Theft Tactic Targeted
A Los Angeles 17-year-old has settled charges that he
used fake Web pages to lure consumers to provide credit
card numbers and other personal data, the Federal Trade
Commission announced yesterday in a crackdown on a growing
form of Internet fraud. The case against the teenager,
who was not identified, is the first brought by the FTC
that targets "phishing," a pernicious scam that marries
e-mail spam with identity theft. The term is used by
computer vandals who go fishing for information. The
FBI and Justice Department also investigated the case.
- - - - - - - - - -
Oracle warns of three new flaws
Database maker Oracle warned customers on Wednesday
of three new flaws in its products and reiterated
its warning to businesses of a fourth flaw that uses
the company's application server. The two most serious
vulnerabilities were in the firm's E-Business Suite,
Oracle's set of server applications for managing
everything from accounting to Intranets. Both were
given the highest of three threat ratings assigned
by Oracle to its products' vulnerabilities.

- - - - - - - - - -
10.2.6 Security update posted
Apple has released Security Update 2003-07-23
v.1.0 for Mac OS X 10.2.6 client and server systems.
The company describes the update as: "Improving
the security of your system by assigning a disabled
password to a new account created by Workgroup Manager
until that account has been saved for the first time.
This ensures the new account cannot be accessed by
an unauthorized individual."

See.... told you we're screwed no matter what OS we choose....
- - - - - - - - - -
PestScan: free spyware checker
Review A free online spyware detection service,
which its developers claim is the first of its
kind, was launched yesterday. PestScan from security
software outfit PestPatrol is a Web-based program
that runs from the PestPatrol Web site, downloading
just a few small ActiveX components to a user's
computer. In this respect the service can be
compared to McAfee FreeScan.
- - - - - - - - - -
The Hackers Who Broke Windows
The Last Stage of Delirium, the hacking group that
laid open nearly every version of the Windows operating
system last week, could use a little sleep. Since going
public with the RPC buffer overflow bug that some are
describing as the worst Windows security hole in history,
the group has been caught in a media frenzy. The hubub
has been just as bad as when, in April, 2001, LSD broke
Argus Systems' PitBull security software in a contest
for $50,000 in cash.
- - - - - - - - - -
Australia to ban spam
Australia's government will ban unsolicited commercial
email later this year. The federal government intends
to introduce legislation later this year that will
ban unsolicited commercial email, the minister for
communications and information technology, senator
Richard Alston announced today. The legislation is
in response to a report by the National Office for
the Information Economy, released in April this
year, which advocated a multi-layered approach
to spam prevention.

Study: Do-not-spam plan winning support
Spam clients outed, credit card details published


Password Length Does Matter
You want your users to select passwords that cannot be easily cracked,
right? You worry that your users are selecting dictionary words as
passwords. An attacker can crack a dictionary term in less than a minute
without breaking a sweat. To prohibit users from selecting passwords
that can be easily cracked, it's important to note that password length
is often more important in password strength than the character set
used. For example, mathematically speaking, it's much harder to crack a
30-character password than it is to crack a 7-character password that
uses a bunch of funky characters. Therefore, consider configuring your
systems so that passwords have a minimum length of 20 or more
characters. To stop your users from revolting, get them to think of
passphrases, such as "This is my difficult-to-guess passphrase," (which
is very difficult to crack) instead of passwords, such as
"p@55w0rd"(which can be cracked in a few days).

Weak Windows Password Hashes Still Plague Us
By default, Windows NT, 2000, and XP store two different representations
of each password locally and on servers: the LanMan hash and the NTLM
hash. The LanMan hash is stored for backward compatibility all the way
back to Microsoft's ancient LanMan product, vintage early 1990's. It's
not really needed on a network where only Windows NT, 2000, and XP
systems live. The LanMan password representation is extremely weak, and
can be easily cracked. No matter how complex and obscure your password
is, an attacker can crack it in under a week due to the incredibly
feeble encryption used to formulate the LanMan hash.

To significantly improve your security, your best bet is to eliminate
the LanMan hashes altogether. On Windows 2000, you can accomplish this
by creating the registry key
HKEY_LOCAL_MACHINE\System\CurentControlSet\Control\LSA\NoLMHash. On
Windows XP, use regedit to create the registry key
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\NoLMHash as a
"REG_DWORD � Number" and give it the value of 1.

Note that these registry entries only stop the creation of new LanMan
hashes when user passwords are changed. Your current LanMan hashes will
still hang around until your users select new passwords, which they
should be doing when their passwords expire every 90 days or so (you did
set a maximum password lifetime, right?). Also, note that these fixes
break interoperability with Window 95 and Windows 98 machines.
Well?  Which password is the hardest to crack?  If you guessed
I!Like!Mountain!Dew You are right! And that's pretty easy to remember
isn't it?  [well for me anyway]

Batten down the hatches and let's be careful out here....

Susan Bradley, CPA aka Ebitz SBS Rocks [MVP]
7/28/2003, 5:08:28 AM

