Monday, April 29, 2013

MACCDC 2013, A Blue Teamer's Lessons Learned: Part 2 - Staging a Lab

No comments :

This is the second part of a series of blog posts I'm writing to relate the various things I learned from getting to experience the glory that is MACCDC.  Here is a "table of contents" which I'll update with relevant posts:


#2 - Preparation (staging a lab)


#4 - Game Time


Preparation: Staging a Lab

If possible, teams should stage ESXi servers with VMs emulating the systems they can expect to see at MACCDC.  These VMs are nothing more than basic installations including Windows 2000 (yes, really), Windows XP, Windows Server 2008, Ubuntu and more with web applications or other services.  These systems can be staged and a scenario could be executed similar to that for MACCDC to get an idea of what's involved in securing each system.

Speaking from experience, if the centralized lab cannot be easily worked out or it turns out to be unreliable, team members should fall back on using VM Workstation and working with the VMs one at a time.  The independent work can be performed between sessions where the main ESXi server is available or if there isn't an ESXi server at all.

Continue reading MACCDC 2013, Part 3
Read More

MACCDC 2013, A Blue Teamer's Lessons Learned: Part 1 - Team Selection

No comments :

MACCDC 2013, A Blue Teamer's Lessons Learned

This is the first part of a series of blog posts I'll be writing to relate the various things I learned from getting to experience the glory that is MACCDC.  Here is a "table of contents" which I'll update with relevant posts:

#1 - Team selection



#4 - Game Time

And so we begin number one...

Team Selection

For this year's competition, schools were allowed to have eight people to a Blue Team.  The teams were organized by having a captain and co-captain oversee the other six.  During the competition, the captain is responsible (among other things) for communicating business injects to the team members and is the team liaison with the white cell.  Because the team captain can be asked to step away for interviews or captain-specific business injects, the co-captain should be capable of fulfilling those same duties.  

The team members need to be comprised of people with a good mix of skills between Linux, Windows, Web Applications, and Firewalls.  This means that every person on the team needs to be technically capable, or trained to be, by competition time.  There were several instances at MACCDC 2013 where someone was pulled away to help another team member on something or complete an inject, leaving a laptop open.  Ideally there should never be a time when someone's not working on a laptop (injects notwithstanding), which means that each person should be technically capable or comfortable with picking up where someone else left off.

Continue reading MACCDC 2013, Part 2


Read More

Friday, April 26, 2013

Dell PowerEdge 2950: Silence the Noise, Part 2

29 comments :
First, a thank you to Neil for spurring my renewed energy into finding a solution to the 2950's noise level.  For the background of this project, check out Silence the Noise, Part 1.  In this post, I relate my research findings from my search for suitable fan replacements.



The Fans

To find a suitable replacement, we must first analyze the existing fans so we know the baseline for comparison.  Dell PowerEdge 2950's come with Delta brushless, axial fans in a 60mm x 60mm x 38mm form factor.  Dell appeared to utilize three variants, with Dell-approved replacement part numbers including JC972, PR272, YW880, and DC471.  The ones in my 2950 are JC972, for which the corresponding Delta model number is PFC0612DE.  It should be noted that some sites report the thickness as 35mm instead of 38mm, but according to the spec sheet, the proper thickness to keep in mind is 38mm.

Here's a recap and quick reference for the 2950 fans:

  • Dell Part Numbers: JC972, PR272, YW880, DC471 
  • Delta Part Number: PFC0612DE (I'm sure there are others)
  • Form Factor: 60mm x 60mm x 38mm
  • Air Flow: up to 67.8 CFM
  • RPM: up to 12,000
  • NOISE: 61.5 dB (one fan!!)
  • Voltage: 12V
  • Termination: 4 wire
  • Features: PWM Control
The key elements we need to keep in mind for the replacement are the size (60mm x 60mm), air flow, noise, termination, and features.  

To see like-manufacturer replacements, I checked Delta's website. Delta has a list of currently available fans in a similar form factor if you put in the correct search parameters.  However, in the comments section of the hacking the BMI post, other PowerEdge 2950 owners reported that they swapped the 38mm thickness for thinner fans and they worked fine as long as the replacements had PWM control and a 4-wire termination.  Here are some photos for reference:

Fan Label
4-Pin Connector

Now, if you've read my previous post, you know that I removed two fans leaving me a max of 120 CFM (~63 per fan).  During that time, my CPU temp did not increase above 25 degrees.  That means that across all four replacement candidates I can lower the CFM to 30 CFM max for each fan.  Your mileage may vary.


On arnuschky's blog, in the comments someone reportedly fitted 60mm x 60mm x 25mm fans, so we don't have to stay with the 38mm thickness.  A forum post at overclock.net provides insight into re-mapping the power pins from different fans into Dell's power connectors.

Keeping that mind, here is a list of potential replacements:

As you can see by visiting the links to these fans, all the power connectors are different with maybe the exception of the last one and would need to be re-pinned.  Also, note that they're all thinner, coming in at a 25mm thickness instead of 38mm.  Instead of trying to re-pin the power connector, I decided to check Delta's list of model numbers to see if they had a fan that I could use to more easily replace the JC972.  To be posted in part 3...


Read More

Friday, March 29, 2013

Verizon's Android 4.2.2 Update and Battery Drain

No comments :

UPDATE: After re-adding the email settings, it no longer drains my battery.  It may be different for other phones, so your mileage may vary.  Try re-adding the email account to see what happens.  Good luck!

Original post:

On Tuesday night, I received a notification that Verizon published the 4.2.2. update for the Samsung Galaxy Nexus.  Having read about the features, I was excited to install the update immediately.  The very first thing I noticed was that the phone began getting very hot.  I rebooted my phone just before I went to bed, deciding that I would deal with it on Wednesday.

Wednesday was a day of me searching for outlets to keep my phone charged.  Within an hour of removing the charging cable, my phone was down to around 10% battery.  Looking at the battery usage, "Exchange Services" was eating over 60%!  I tried various settings to adjust the sync intervals, all to no avail.  Reluctantly, I then removed my corporate email account.  I noticed an immediate difference in temperature - or should I say lack thereof; it was no longer burning hot!  Monitoring the phone all day Thursday, I can confirm it seems that was the fix.

So, if anyone out there is running a Verizon SCH-i515 Samsung Galaxy Nexus, and your battery drain is as rampant as mine was, delete/remove your corporate email profile.

I haven't tried re-adding it yet.  I'll give that a shot Friday and update the post with the test results.
Read More

Wednesday, March 27, 2013

Best Way to Get Your New House in Google Maps

No comments :
Update (7/12/2014): If after you get your house listed following the instructions below you're uncomfortable with the street view photo, you can use the same steps to blur it out!  Original post follows:

A colleague recently bought a newly constructed home, and experienced the problem of people not being able to find his address in Google Maps.  I found it irritating myself when I was trying to visit him and had to use the GPS coordinates (long-press) of the location.  So, we set to the task of finding a way to get his house listed.

Attempt #1: Google Map Maker (FAIL)

When you begin researching how to do this, you'll run across guidance suggesting to use Google Map Maker to submit the address to Google Map Reviewers.  Once you open Map Maker, you'll see something like this:




Upon clicking the ADD NEW button, you'll see there are four options: Add A Place; Add Roads, Rivers, Railways; Add Building Outlines; and Add Natural Features and Political Boundaries.  Logically, a house seems to fit under "Add A Place."  Once selected, Map Maker asks you to zoom in to the area and position the marker over the spot.  After the marker is dropped, you'll see a pop-up asking you to identify a category to which this place belongs.  Going through all this, you'll see that there are no categories for residential addresses.

We decided to try neighborhood/community and see if the people moderating would check with the local post office for a complete street listing.  Although the community did get correctly listed, the address was based on the side street and the houses were not listed individually with the separate street names.  Tears...

Attempt #2: Google Maps - Report a Problem (SUCCESS!)

When opening Google Maps, there's a link in the lower right-hand corner as well as on the left titled "Report a Problem":



A menu will display offering choices.  You need to pick Address/Marker and drag the marker that appears on the map over to your house.  Once you let go of dragging the marker over, a box appears asking for input.  This is where you tell Google what the address for that location should be, and submit the report.

Attempt #2 took a week to get it resolved, whereas Attempt #1 took three months and was still incorrect.

Now I can type in his address in Google Maps!  

Happy Cartography-ing!
Read More

Thursday, March 21, 2013

Cloud Intelligence: Leverage the User Base!

No comments :
I'm not sure if other tech writers have already identified this trend, but it seems that every network security vendor identified by Gartner as one of the leading vendors in their areas of specialization is enabling their devices with "cloud intelligence."

First, what do I mean by cloud intelligence?  Others may have a different definition, but to me cloud intelligence means analysis of user-generated data in the cloud to glean something of value.  The benefit of doing so is baking the results of that analysis into feature updates or supplemental information to already embedded features to be used by that same user base.

So, where is this happening?  I can think of three off the top of my head:

  1. Blue Coat's WebPulse
  2. McAfee's Global Threat Intelligence
  3. Palo Alto's WildFire
Each of these solutions receive input from their deployed products that send information of varying types, depending on what data points the vendors consider important.  The goal of this "phone home" feature is so the vendor can leverage what is seen in the field to protect others.  So, if Company A sees malware X and it gets reported to the cloud, the vendor can protect all other companies using the feature.

Most of these products require an opt-in, because not every organization is comfortable sending the information to the vendor.  What are your thoughts?  Would you feel more comfortable leveraging cloud intelligence, or does it invoke paranoia?
Read More

Saturday, March 9, 2013

Dell PowerEdge 2950: Silence the Noise, Part 1

4 comments :


Background

Recently, I've accepted the task to build out a lab using donated equipment so people can practice for cyber security competitions.  This donated equipment includes four or five Dell PowerEdge servers; one 2950 and three or four 2850s.  After researching the system specs, the 2950 seemed like a good place to start since it was the model that could take the most additional memory.  It came with four 512 MB DIMMs (a whole gig!), but we swapped those out with  six 4GB DIMMs and an additional two 2GB DIMMs, enabling us to get to 28GB for memory.

Quick side note for others - the memory slots are paired 1-2, 3-4, 5-6, 7-8 so you can't have an odd man out.  I actually had five 4GB DIMMs, but I installed the fifth in slot 5 with a 2 GB stick in slot 6, and the start up checks kindly informed me of the mismatch.  Once I swapped out the 4GB so slots five through eight were homogeneous, I was good for memory and received no memory check errors.

The Issue

When powering on the 2950, it's idle fan sound is overbearing.  I live in a town home, and this server is placed in a closet in the basement 14 feet below the main floor yet I can still hear it whining away.  To say this server is loud isn't enough, it's LOUD.  

My first attempt at reducing the noise was to remove two of the four chassis fans, since this server isn't going to be heavily tested.  I put the cover on, powered it up, and went to the main floor to see the difference.  It was definitely an improvement, but I could still clearly hear the humming.    An audio meter indicates it's at about 70+ decibels, with two fans removed!

At this point, I figured I needed to take a look at these fans to see if there was a way to control their speed and/or look for acceptable replacements.  Research typically reveals one of three things:

  1. Brent Ozar's fine post about quieting a PowerEdge 1950
  2. Another author's post on hacking the BMI
  3. Multiple forums of people telling 2950 owners to buy a new box
Brent's post provides great advice on switching out the fans for a 1950, but the fans mentioned in his post are a different size than the 60mm x 60mm x 35mm of the 2950 fans.

Hacking the BMI seemed a little intimidating to start off with, so I decided to pursue that as the last option.

This equipment was donated expressly because of the lack of funds, so option 3 is out.

I decided to research alternate fans first...
Read More