<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security Videos - The Academy Pro</title>
	<atom:link href="http://www.theacademypro.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theacademypro.com/blog</link>
	<description>The ultimate resource for free infosec video tutorials</description>
	<lastBuildDate>Fri, 30 Jul 2010 00:28:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Initial setup of an Astaro Security Gateway v8</title>
		<link>http://www.theacademypro.com/blog/2010/07/29/initial-setup-of-an-astaro-security-gateway-v8/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/29/initial-setup-of-an-astaro-security-gateway-v8/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 00:28:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1390</guid>
		<description><![CDATA[Today we have five Astaro videos.                    The  featured video of the day demonstrates how to initially setup the Astaro Security Gateway v8 VMware image. We also take a look at altering the webadmin port, automatic [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have five <a href="http://www.astaro.com" target="_blank">Astaro</a> videos.                    The  <a href="http://www.theacademypro.com/theater.php?filename=astaro8setup&amp;videoid=973" target="_blank">featured</a> video of the day demonstrates how to initially setup the Astaro Security Gateway v8 VMware image. We also take a look at <a href="http://www.theacademypro.com/theater.php?filename=astaro8webadminport&amp;videoid=977" target="_blank">altering the webadmin port</a>, <a href="http://www.theacademypro.com/theater.php?filename=astaro8autobackups&amp;videoid=974" target="_blank">automatic backups</a>, <a href="http://www.theacademypro.com/theater.php?filename=astaro8licensing&amp;videoid=975" target="_blank">viewing licenses</a> and <a href="http://www.theacademypro.com/theater.php?filename=astaro8mailadminrole&amp;videoid=976" target="_blank">creating a mail administrator role</a>.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/29/initial-setup-of-an-astaro-security-gateway-v8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Performing a Windows hotfix scan with Rapid7 NeXpose</title>
		<link>http://www.theacademypro.com/blog/2010/07/28/performing-a-windows-hotfix-scan-with-rapid7-nexpose/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/28/performing-a-windows-hotfix-scan-with-rapid7-nexpose/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 22:33:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1387</guid>
		<description><![CDATA[Today we have five Rapid7 videos.                    The  featured video of the day demonstrates how to perform a Windows hotfix scan. We also take a look at scheduling scans, viewing scan history, generating CSV reports and [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have five <a href="http://www.rapid7.com" target="_blank">Rapid7</a> videos.                    The  <a href="http://www.theacademypro.com/theater.php?filename=rapid7nexposewindowshotfix&amp;videoid=968" target="_blank">featured</a> video of the day demonstrates how to perform a Windows hotfix scan. We also take a look at <a href="http://www.theacademypro.com/theater.php?filename=rapid7nexposeschedulescans&amp;videoid=969" target="_blank">scheduling scans</a>, <a href="http://www.theacademypro.com/theater.php?filename=rapid7nexposescanhistory&amp;videoid=970" target="_blank">viewing scan history</a>, <a href="http://www.theacademypro.com/theater.php?filename=rapid7nexposecsvreport&amp;videoid=971" target="_blank">generating CSV reports</a> and <a href="http://www.theacademypro.com/theater.php?filename=rapid7nexposelinuxscan&amp;videoid=972" target="_blank">scanning a linux system</a> with NeXpose.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/28/performing-a-windows-hotfix-scan-with-rapid7-nexpose/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browsing scan results with Nessus 4.2</title>
		<link>http://www.theacademypro.com/blog/2010/07/27/browsing-scan-results-with-nessus-4-2/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/27/browsing-scan-results-with-nessus-4-2/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 01:22:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1385</guid>
		<description><![CDATA[Today we have two Nessus videos.                    The  featured video of the day demonstrates how to browse your Nessus scan results with having to generate and download a report. We also take a look at generating [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have two <a href="http://www.nessus.org" target="_blank">Nessus</a> videos.                    The  <a href="http://www.theacademypro.com/theater.php?filename=nessusbrowsescan&amp;videoid=967" target="_blank">featured</a> video of the day demonstrates how to browse your Nessus scan results with having to generate and download a report. We also take a look at <a href="http://www.theacademypro.com/theater.php?filename=nessushtmlreport&amp;videoid=966" target="_blank">generating HTML reports with Nessus 4.2</a>.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/27/browsing-scan-results-with-nessus-4-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sourcefire Vulnerability Report 2009/2010</title>
		<link>http://www.theacademypro.com/blog/2010/07/26/sourcefire-vulnerability-report-20092010/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/26/sourcefire-vulnerability-report-20092010/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 00:00:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1381</guid>
		<description><![CDATA[Today we have five Sourcefire videos. Each video presents a vulnerability report from the Sourcefire VRT for October, November, December 2009 and January and February 2010. I have enjoyed watching the monthly release of these videos and decided to post them for everybody. Stay tuned for more next month!
You can follow The Academy Pro updates [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have five <a href="http://www.sourcefire.com" target="_blank">Sourcefire</a><a href="http://www.checkpoint.com" target="_blank"></a> videos. Each video presents a vulnerability report from the Sourcefire VRT for <a href="http://www.theacademypro.com/theater.php?filename=sourcefire-vr-october09&amp;videoid=961" target="_blank">October</a>, <a href="http://www.theacademypro.com/theater.php?filename=sourcefire-vr-november09&amp;videoid=962" target="_blank">November</a>, <a href="http://www.theacademypro.com/theater.php?filename=sourcefire-vr-december09&amp;videoid=963" target="_blank">December</a> 2009 and <a href="http://www.theacademypro.com/theater.php?filename=sourcefire-vr-january10&amp;videoid=964" target="_blank">January</a> and <a href="http://www.theacademypro.com/theater.php?filename=sourcefire-vr-february10&amp;videoid=965" target="_blank">February</a> 2010. I have enjoyed watching the monthly release of these videos and decided to post them for everybody. Stay tuned for more next month!</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/26/sourcefire-vulnerability-report-20092010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bullguard Internet Security 9.0 Review</title>
		<link>http://www.theacademypro.com/blog/2010/07/23/bullguard-internet-security-9-0-review/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/23/bullguard-internet-security-9-0-review/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 14:27:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1374</guid>
		<description><![CDATA[Here’s a review on the latest software from Bullguard Internet Security 9.0 system. This software release happens to be more than an upgrade of version 8.0 and the interface improvements and ease of use make it much more user friendly.
In one of Bullguard’s press releases they state that most people don’t really care how something [...]]]></description>
			<content:encoded><![CDATA[<p>Here’s a review on the latest software from <a href="http://www.bullguard.com/spyware_download_page.aspx" target="_blank">Bullguard Internet Security 9.0 system</a>. This software release happens to be more than an upgrade of version 8.0 and the interface improvements and ease of use make it much more user friendly.</p>
<p>In one of Bullguard’s press releases they state that most people don’t really care how something works, they just want it to work.  This seems to be a fair and accurate statement and Bullguard have actually come close to achieving this with the various simplifications they’ve made to Internet Security 9.0.</p>
<p>Version 9.0 has a simple stylish interface with a number of icons that let you choose what you want to do.  There are nine main icons on display: Scan for viruses, Backup your data, Allow/Block programs, Contact support, Online Drive, System status, Check for updates, Your Bullguard account, and Upgrade.  Everything is clear and simple to use, so if you want to scan your pc, simply click on the icon. Want to back up your pc, click the icon for this and so on.  Overall, the software has been designed with the user in mind, and the feel is friendly and relaxed.</p>
<p>The key features of the software are pretty much the same as you’d expect with most internet security software setups, with a few additions.  You get:<br />
·         <a href="http://www.bullguard.com/bullguard-security-center/antispyware---protecting-your-privacy.aspx" target="_blank">Anti-virus</a><br />
·         Anti-phishing<br />
·         Spam filter<br />
·         Instant messaging protection</p>
<p>Instant messaging protection which has been missing from many products is now included in the Bullguard Internet Security 9.0. Another major advantage is the 24/7 support and 5GB of backup space that&#8217;s included with the ability to create a customized scan of your system versus the traditional quick/complete scans that are offered by other products.</p>
<p>Overall, this software is easy to use, has a simple stylish user interface, and does everything you need it to prevent threats and secure your computer from viruses, hackers, spam and more. It’s an almost maintenance free software.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/23/bullguard-internet-security-9-0-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Testing my ISP bandwidth with Check Point Smartview Monitor</title>
		<link>http://www.theacademypro.com/blog/2010/07/22/testing-my-isp-bandwidth-with-check-point-smartview-monitor/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/22/testing-my-isp-bandwidth-with-check-point-smartview-monitor/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 01:30:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1372</guid>
		<description><![CDATA[Today we have a Check Point video.                    The  featured video of the day demonstrates how you can utilize Check Point&#8217;s Smartview Monitor to ensure that your ISP is providing the bandwidth that you pay for.
You [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have a <a href="http://www.checkpoint.com" target="_blank">Check Point</a> video.                    The  <a href="http://www.theacademypro.com/theater.php?filename=isp-smartview-monitor&amp;videoid=960" target="_blank">featured</a> video of the day demonstrates how you can utilize Check Point&#8217;s Smartview Monitor to ensure that your ISP is providing the bandwidth that you pay for<a href="http://www.theacademypro.com/theater.php?filename=pcipfilecontrol&amp;videoid=955" target="_blank"></a>.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/22/testing-my-isp-bandwidth-with-check-point-smartview-monitor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web 2.0 control with Panda Internet Cloud Protection</title>
		<link>http://www.theacademypro.com/blog/2010/07/21/web-2-0-control-with-panda-internet-cloud-protection/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/21/web-2-0-control-with-panda-internet-cloud-protection/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 00:23:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1369</guid>
		<description><![CDATA[Today we have five Panda Security videos.                    The  featured video of the day demonstrates how to control Web 2.0 with Panda Internet Cloud Protection. We also provide videos for a feature overview, quick start guide, [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have five <a href="http://www.pandasecurity.com" target="_blank">Panda Security</a> videos.                    The  <a href="http://www.theacademypro.com/theater.php?filename=pcipweb2control&amp;videoid=959" target="_blank">featured</a> video of the day demonstrates how to control Web 2.0 with Panda Internet Cloud Protection. We also provide videos for a <a href="http://www.theacademypro.com/theater.php?filename=pcipfeatureoverview&amp;videoid=958" target="_blank">feature overview</a>, <a href="http://www.theacademypro.com/theater.php?filename=pcipquickstart&amp;videoid=956" target="_blank">quick start guide</a>, <a href="http://www.theacademypro.com/theater.php?filename=pcipreporting&amp;videoid=957" target="_blank">reporting</a> and <a href="http://www.theacademypro.com/theater.php?filename=pcipfilecontrol&amp;videoid=955" target="_blank">file control</a>.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/21/web-2-0-control-with-panda-internet-cloud-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syncing RAM to disk with TippingPoint IPS</title>
		<link>http://www.theacademypro.com/blog/2010/07/20/syncing-ram-to-disk-with-tippingpoint-ips/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/20/syncing-ram-to-disk-with-tippingpoint-ips/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 01:15:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1366</guid>
		<description><![CDATA[Today we have a TippingPoint video.                    The  featured video of the day demonstrates how to force the sync of RAM to disk on a TippingPoint IPS device.
You can follow The Academy Pro updates on Twitter.
Test [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have a <a href="http://www.tippingpoint.com" target="_blank">TippingPoint</a> video.                    The  <a href="http://www.theacademypro.com/theater.php?filename=tpforcesync&amp;videoid=954" target="_blank">featured</a> video of the day demonstrates how to force the sync of RAM to disk on a TippingPoint IPS device.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                       drive GFI MAX        MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                       Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/20/syncing-ram-to-disk-with-tippingpoint-ips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analzying Cisco PIX logs for malware</title>
		<link>http://www.theacademypro.com/blog/2010/07/19/analzying-cisco-pix-logs-for-malware/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/19/analzying-cisco-pix-logs-for-malware/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 17:59:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1360</guid>
		<description><![CDATA[By: John Smith
The purpose of this post is to show people how I grabbed Syslog data from my pix allowing me to grab the URI Stem of all outgoing sessions and log them into a SQL Server.  Afterward, I will be able to run key queries to be able to troll for .exe, .dll, .tgz [...]]]></description>
			<content:encoded><![CDATA[<p>By: John Smith</p>
<p>The purpose of this post is to show people how I grabbed Syslog data from my pix allowing me to grab the URI Stem of all outgoing sessions and log them into a SQL Server.  Afterward, I will be able to run key queries to be able to troll for .exe, .dll, .tgz and any other problem extensions.  Also, I can upload the latest malware list data and cross reference it with the information in my database which will allow me to see if any of my systems are phoning home to a botnet master, malware distribution site, etc.  This is basically a take on my edgesightunderthehood.com post on monitoring APT with Edgesight.</p>
<p>The first order of business is to get the logs to the syslog server.  I start by creating a filter that will grab the logs.</p>
<p style="text-align: center;"><img class="aligncenter" title="pix1" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix1.jpg" alt="" width="470" height="340" /></p>
<p><span id="more-1360"></span></p>
<p>The next step is to parse the incoming data into separate columns in my database.  This is done by setting up a custom db format for the purpose of these logs.   The parse script is provided below:</p>
<p>Also, check all checkboxes below &#8220;Read&#8221; and &#8220;Write&#8221;</p>
<p style="text-align: center;"><img class="aligncenter" title="pix3" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix3.jpg" alt="" width="470" height="340" /></p>
<p>Parsing Script: (Cut and paste it to a text file then use that text file in the dialog box above)<strong><br />
</strong>################################<br />
Function Main()<br />
Main = &#8220;OK&#8221;<br />
Dim MyMsg<br />
Dim Source<br />
Dim Destination<br />
Dim Payload</p>
<p>With Fields<br />
Source = &#8220;&#8221;<br />
Destination = &#8220;&#8221;<br />
Payload = &#8220;&#8221;</p>
<p>MyMsg = .VarCleanMessageText</p>
<p>If ( Instr( MyMsg, &#8220;%PIX&#8221; ) ) Then<br />
SourceBeg = Instr( MyMsg,  &#8220;: &#8220;) + 2<br />
SourceEnd = Instr( SourceBeg, MyMsg, &#8220;Accessed&#8221;)<br />
Source = Mid( MyMsg, SourceBeg, SourceEnd &#8211; SourceBeg)<br />
DSTBeg = Instr( MyMsg,  &#8220;URL&#8221;) + 3<br />
DSTEnd = Instr( DSTBeg, MyMsg, &#8220;:&#8221;)<br />
Destination = Mid( MyMsg, DSTBeg, DSTEnd &#8211; DSTBeg)<br />
End IF<br />
.VarCustom01 = Source<br />
.VarCustom02 = Destination<br />
.VarCustom03 = Payload</p>
<p>End With<br />
End Function<br />
##################################</p>
<p>The last step is to write the data to SQL but first let&#8217;s do a few tasks to prepare the table.</p>
<p>1.  Set up an ODBC connection to a SQL Server and create a database called &#8220;Syslog&#8221; and connect to it with an account that has dbo privilages.</p>
<p>2.  Create the Custom DB Format for grabbing URL&#8217;s</p>
<ol></ol>
<p style="text-align: center;"><img class="aligncenter" title="pix4" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix4.jpg" alt="" width="470" height="340" /></p>
<p>Note that this table will have five columns, msgdatetime, msghostname, msgtext, source, destination and payload.  (The last column, payload, is not working yet but I will show you how to get the payload later)</p>
<p>3.  Once this is done, create an action called &#8220;Write to SQL&#8221; and select &#8220;PIX_URL&#8221; from the custom data fromat list and name the table &#8220;PIX_URL&#8221; then select &#8220;Create Table&#8221;</p>
<p style="text-align: center;"><img class="aligncenter" title="pix5" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix5.jpg" alt="" width="470" height="340" /></p>
<p>Okay, so now that we have the data writing to SQL Server,  let&#8217;s look at a month&#8217;s worth of data on one of my systems:</p>
<p>This query will give you the payload and the number of times the payload has been accessed.   Using the <em>having </em>function I am going to ask for every uri-stem that has been accessed more than 5 times in the last month.</p>
<p>select substring(msgtext,41, 2048) as &#8220;Payload&#8221;, count(substring(msgtext,41, 2048))</p>
<p>from pix_url</p>
<p>group by substring(msgtext,41, 2048)</p>
<p>having count(substring(msgtext,41, 2048)) &gt; 5</p>
<p>order by count(substring(msgtext,41, 2048)) desc</p>
<p>The idea behind this is that if you note 1000 records to &#8220;123.123.123.123:/botmaster/botnet.exe&#8221; you may want to do something about it.  You can also download the malwaredomainlist.com data, import it into SQL and cross reference that data to ensure that you are not communicating with any noted malware sites.  Depending on the response of this blog, I may post those instructions as well.</p>
<p>And here are what the results look like:</p>
<p style="text-align: center;"><strong><img class="aligncenter" title="pix6" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix6.jpg" alt="" width="470" height="340" /><br />
</strong></p>
<p>Another query I like to run is one looking for executable files in the URI-stem.</p>
<p>select Msghostname as &#8220;Firewall&#8221;, Source, Destination, substring(msgtext,41, 2048) as &#8220;Payload&#8221;</p>
<p>from pix_url</p>
<p>where msgtext like &#8216;%.exe%&#8217;</p>
<p>order by msgdatetime desc</p>
<p>This will allow me to troll for executables that my internal users are accessing, as with most versions of malware, this should show itself early on during the breach.</p>
<p>So how do you monitor?</p>
<p>Well, you don&#8217;t have to sit there with query analyzer open all day but you can set up SQL Server Reporting Services to do this chore for you and deliver a dashboard to operations personnel.  Here is a quick view of a dashboard that  refreshes ever 5 seconds and turns RED when &#8220;.exe&#8221; is in the URI-Stem.   In this scenario, you would be able to investigate the executable that is being downloaded by the client and ensure that it is not malware.    You can test this yourself once you set it up by going to any site and typing &#8220;/test.exe&#8221;  at the end.</p>
<p style="text-align: center;"><img class="aligncenter" title="pix7" src="http://www.theacademypro.com/blog/wp-content/uploads/2010/07/pix7.jpg" alt="" width="469" height="365" /></p>
<p>Conclusion:<strong><br />
</strong>Again, I am not a traditional security guy so this could be utterly useless, I am not the PIX guy at my job, I AM the PIX guy at home though.  Also, I have found it very useful to check for Malware and 0-Day&#8217;s that my anti-virus does not pick up.  While I cannot speak with as much authority as a number of CISSP&#8217;s and INFOSEC guru&#8217;s, I can say that the continued ignorance surrounding egress will allow malware to run amuck.  As I stated in a previous blog, it is foolish to beat your chest at the millions of packets you keep out while the few that get in can take anything they want, and leave unmolested.  Just like a store has to let some people in then focus on ensuring no one leaves with anything they didn&#8217;t pay for, IT Security needs to ease over to this mentality and keep track of what is leaving its networks and where it is being sent.   At any rate, if this has value to anyone let me know, I will include the RDL (Report File) online for download if anyone wants to set it up.  I know a lot of PIX guys aren&#8217;t necessarily web/database guys so if you have any questions, feel free to ask.</p>
<p>Thanks for reading,</p>
<p>John</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/19/analzying-cisco-pix-logs-for-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Creating a scan policy with Tenable Security Center 4</title>
		<link>http://www.theacademypro.com/blog/2010/07/15/creating-a-scan-policy-with-tenable-security-center-4/</link>
		<comments>http://www.theacademypro.com/blog/2010/07/15/creating-a-scan-policy-with-tenable-security-center-4/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 01:36:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.theacademypro.com/blog/?p=1357</guid>
		<description><![CDATA[Today we have a Tenable Network Security video.                    The  featured video of the day demonstrates how to create multiple scan policies using Tenable Security Center 4.
You can follow The Academy Pro updates on Twitter.
Test  [...]]]></description>
			<content:encoded><![CDATA[<p>Today we have a <a href="http://www.tenablesecurity.com" target="_blank">Tenable Network Security</a> video.                    The  <a href="http://www.theacademypro.com/theater.php?filename=tenable4scanpolicy&amp;videoid=953" target="_blank">featured</a> video of the day demonstrates how to create multiple scan policies using Tenable Security Center 4.</p>
<p>You can follow The Academy Pro updates on <a href="http://twitter.com/academypro" target="_blank">Twitter</a>.</p>
<p><a href="http://www.gfi.com/?adv=941&amp;loc=7" target="_blank">Test                                                      drive GFI MAX       MailProtection        today!</a></p>
<p>Thank you all for your on-going support and recommendations.</p>
<p>Peter  Giannoulis<br />
The Academy Pro<br />
<a href="http://www.theacademypro.com/" target="_self">www.theacademypro.com</a></p>
<p>This update has been brought to you by <a href="http://www.checkpoint.com/" target="_blank">Check Point Software Technologies</a>, <a href="http://www.sourcefire.com/" target="_blank">Sourcefire</a>, <a href="http://www.peer1.com/" target="_blank">Peer 1,</a> <a href="http://www.pandasecurity.com/" target="_blank">Panda Security, </a><a href="http://www.networkcritical.com/" target="_blank">Network                                                      Critical</a>,  <a href="http://www.saintcorporation.com/" target="_blank">SAINT</a> and <a href="http://www.rapid7.com/" target="_blank">Rapid7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.theacademypro.com/blog/2010/07/15/creating-a-scan-policy-with-tenable-security-center-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
