Passwords … a little bit of help

The difficulty in keeping up with your passwords can seem a daunting task so for this post I wanted to share a great, free, open source program to use to do just that. The program is called KeePass.

So, what is KeePass? From their site…

“KeePass is a free open source password manager, which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file. So you only have to remember one single master password or select the key file to unlock the whole database. The databases are encrypted using the best and most secure encryption algorithms currently known (AES and Twofish).”

I’ve been using this program for the last few years and love it. It is a native Microsoft Windows program but others have ported it to a multitude of operating systems including MacOSX, Palm, WindowCE, PocketPC, Linux, Blackberry and more. So what this means is, you set-up one master password linked to this one file. You share this encrypted file among all your systems (including your smart phone) and you have all your usernames, passwords and associated websites all at your fingertips. Neat, huh?

I’m very much looking forward to their 2.0 release which is currently in beta. The added features (like sharing a password database and having it sync and merge changes) look like they could be a big help.

Find KeePass for Windows here and its Mac version here.

Posted under Information/Advisories

This post was written by Aaron on January 7, 2009

Tags: , , , ,

Interview With Michael Santarcangelo Part 1

In this Episode Aaron and Tim interview Michael Santarcangelo The Security Catalyst Securitycatalyst.com, author http://www.intothebreach.com/.  We have a few copies of the book to give away.  I will be announcing how to win one of my copies shortly.

Interview MP3
– Tim Krabec

Posted under Podcasts

This post was written by tkrabec on October 27, 2008

Tags:

More Information on MS08-067 the SMB Problem

Here is a collection of information in a nice write up for technical and non-technical people.  This was a group effort from many people in the security community.

http://docs.google.com/Presentation?id=dghttrwg_26c47c5xcx

– Admin

Posted under Information/Advisories

This post was written by admin on October 24, 2008

Major Security Patch Released by Microsoft

Today 8-23-08 Microsoft released an out of cycle patch to fix a problem in their implementation of RPC(Remote Procedure Call).  This flaw is reported to be very exploitable, and there is talk of “weaponizing” this to produce a worm.  This flaw has the potential to rival the Blaster worm which exploited a similar problem back in 2003.  Whether or not a worm is developed, this flaw will be exploited, and used for Penetration testing, and smaller scale directed attacks on individual companies and unpatched machines.

What does this mean to you as a Business owner or employee?  It means that you should take steps to get your systems patched, quickly.  You should probably aim to have this done with in a week, possibly push it to November 1st or 2nd to check that patch does not negatively affect your systems.

Here is a link to the microsoft advisory http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

Update

This affects Most versions of windows, and is available on windows update.

– Admin

Reblog this post [with Zemanta]

Posted under Information/Advisories

This post was written by admin on October 23, 2008

Tags: , , , ,

Changes are comming

After our first 2 episodes, we have take taken some of the feedback we received and are making some changes to the show.   The show is going to be a bit more structured and provide more information and we aim to provide more detailed information about what we discuss in the show.

Up coming show are scheduled to include an action plan to help kickstart your IT stragety, Backups, Choosing a computer, and Computer Use policies.

Posted under Podcasts

This post was written by admin on September 25, 2008

Episode 2

http://media.libsyn.com/media/tkrabec/SMB_Minute_Episode_2.mp3

Aaron & Tim Discuss
http://www.Opendns.com
and
http://en.wikipedia.org/wiki/Domain_Name_System

Please Bear with us as we’re new to podcasting.  We are aiming at one episode per week.  If you have any questions, comments, or topics you’d like to see discussed, please email us at SMBMinute@gmail.com

Thanks
Aaron & Tim

Posted under Podcasts

This post was written by tkrabec on September 4, 2008

Tags: , ,