Showing posts with label Scorpion. Show all posts
Showing posts with label Scorpion. Show all posts

Monday, 2 April 2012

Global Payments Inc. Breached: How Many Credit Card Numbers (says 1.5 Million) This Time?

NOTE: This is a _very_ opinionated post.

When are our government representatives going to stand up for us when it comes to data breaches that impact our day to day lives?!?

We can’t seem to embed the Bloomberg video at the following URL:

It is a good discussion of the unknown status around the hacking of payment processor Global Payments Inc.

We had our issues around the breach of Heartland Payment Systems (blog Breach category) given the way the whole thing played out. We were directly impacted by that particular breach.

Whether or not we are impacted by this current breach has yet to be seen but rest assured that we will be watching our CC online statements daily, as we regularly do anyway, for any fraudulent activities!

It is time to have legislation in place that does not allow breaches like this to fly under the radar or remain undisclosed as is the case here for _weeks_ after the breach. Our governments need to step up to protect their constituents.

It is _NOT_ up to the CEO of Global Payments Inc. to weigh things out with regards to breach disclosure.

Good on VISA for pulling their support of Global Payments Inc. Now, MasterCard, American Express, Discover, and others need to follow suit.

It is time for the credit card industry to start outright punishing payment processors for not having proper security elements in place to protect our credit card information.

Multi-Tier type authentication like AuthAnvil is not that expensive to implement. Training folks up and beyond the lowest common denominator is also a good step. That’s the cost of doing business in today’s hostile online environment.

And, no, there is NO excuse for a payment processor to not have our data protected using the best possible methods. Period.

Just ask the people that lose their life to trying to recover their identity, credit, and any other aspect of getting things straightened out after their credit card(s) and/or identity have been stolen.

Original Hat Tip: Susan Bradley

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 13 November 2009

Scorpion Software AuthAnvil Authentication Keyfob Tokens Have Arrived

While at the SMB Nation Fall Conference we took advantage of Scorpion Software’s bundled special.

We had a package arrive not long after we did that with five AuthAnvil tokens in it. Though they are not on the integration To Do list yet.

Once we have migrated our SBS to 2008, we will get in touch with Scorpion to schedule an installation training session that they are providing as part of the package.

Once we have done that, we will then have two factor authentication in place for our own network.

We will then begin to talk to our clients about augmenting their security setup with the AuthAnvil.

Scorpion Software has a good demonstration video here:

Check out some of the auditing features that are demonstrated near the end of the demo video. For folks that have one username for many tasks, AuthAnvil can actually track which user logged in using that account and from where.

This is a pretty neat product and should be a serious consideration for any organization dealing with sensitive client data.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 26 June 2009

Windows 7 – Remote Desktop Multi-Monitor Goodness

The TS Gateway service allows us direct access to our desktops.

The new RDP version allows us to /mulitmon to use the two monitors we have connected to this workstation on the remote desktop:

image

Here is a list of the new RDP version’s command line switches:

image

Just remember that the TS Gateway service does allow for direct connections to any TS enabled system inside the SBS network. As a result, it would be a good idea to look at AuthAnvil by Scorpion Software to provide another level of authentication protection.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Monday, 27 April 2009

Some Thoughts on SBS 2008 and Branch Offices

When looking to deploy SBS 2008 into a situation where SBS will reside in the main office and there will be a branch office or offices.

If there are only a few seats at the branch offices, then a simple solution is the have SBS 2008 Premium at the main office with either a Terminal Server serving remote desktops or a Hyper-V box serving desktop OS based virtual machines.

The catch would be the requirements of the Line of Business (LoB) applications that are needed.

Using the Remote Web Workplace in this manner, we can eliminate the need for a server at the branch office.

If the Line of Business applications allow for Terminal Services installation, then another option would be to publish the LoB via Terminal Services RemoteApps. The user can get to the Lob app via RWW or via an icon on their desktop.

In either case, Scorpion Software’s AuthAnvil should be seriously considered to protect those TS Gateway sessions with another layer of security. The expense is relatively minor compared to the peace of mind we would have knowing that our client’s TS Gateway is protected.

For larger installations where there are a number of users at the branch office or offices, then a hardware based VPN setup would be a consideration. Keep in mind that bandwidth considerations and ISP stability are important when looking to a VPN as part of the overall solution.

A Read-Only Domain Controller on Server Core along with the needed Roles could provide local users with authentication, file, print, and centralized backup services. Server Core provides the opportunity to really slim down the needed hardware, or even repurpose existing server hardware for the branch office.

Install the full Server 2008 install, then WSUS can be installed on the branch office server and Group Policy can be customized to facilitate the local clients getting their updates from the local WSUS. This setup can be tweaked for more than one branch office with a server in each too.

Ultimately, our solution direction would depend on the client’s industry their LoB needs, compliance, retention, and remote access needs. It is our preference to have remote users connect via RWW and work with all data stored on the main office’s network.

This preference is due to the reduction in complexity that happens as a result of keeping everything relatively centralized. KISS (Wikipedia) is the operating principle behind our preference.

However, ultimately the solution we tailor will be with the client’s best interests in mind.

We will run through some actual configurations in our upcoming SBS 2008 Advanced Blueprint book too.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Tuesday, 17 March 2009

Outlook Error – The name cannot be resolved and SBS 2008 with Vista Hosting

We had a user on our hosted SBS 2008 service accidentally copy a bunch of folders into the Outbox in Outlook 2007.

The call to us came in that they were unable to send anything and were not sure why.

Once we connected to the Vista VM, we found the folders nested in the Outbox.

We removed the folders from the Outbox but the Send/Receive dialogue was still stuck.

So, we deleted the Outlook profile, deleted the OST file, and attempted to reconnect to their mailbox, but were not able to do so:

09-03-17 Outlook - Name Cannot Be Resolved

Microsoft Office Outlook

The name cannot be resolved. The name cannot be matched to a name in the address list.

Currently, the SBS hosting services are low key for a few clients that do not have network infrastructure in place but need a secure desktop and data sharing experience for their Line of Business applications.

The Microsoft licensing is provided through SPLA.

When we initially run the SBS Add a new user account wizard, there were no problems with configuring the Outlook profile.

The problem came after the fact:

09-03-17 SBS 2008 - Exchange 2007 User Properties

Exchange 2007: Philip Elder Properties

Note the setting below the Alias: Hide from Exchange address lists. Once the user’s profile has been set up, we enable this setting to remove them from the GAL.

The error in this case was due to the Hide from Exchange address lists setting being enabled. Once we removed the check mark and clicked the Apply button, we were able to complete the Outlook profile set up.

SBS 2008 and Windows Vista Hosting

On the hosting side of the business, we have set up a custom User Role for new hosting users on the SBS 2008 server that tightens up the group membership and quota structures.

Access-based Enumeration is used for any needed shares to keep them hidden from users with no permissions to them and Standard User profiles are used on the Windows Vista VMs with no Network Discovery enabled to keep them isolated.

Customized GPOs are then used to tighten up the security settings on the desktops.

As this side of our business grows, we will look to incorporate another rung on the redundancy ladder by including OWN’s Hosted Exchange solution into the mix.

Scorpion Software’s AuthAnvil is also on the To Do list to incorporate another level of security for the hosting environment as we grow.

The key to making the SBS 2008 and Vista hosting viable for small business is catching the balance between the cost of installing a server setup for the client versus the low monthly cost of having someone else do it for them.

As a result, we need to partner up with key Cloud services providers to augment our own services to provide the best balance between cost and availability.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Saturday, 14 March 2009

AuthAnvil – Want to See a Neat Security Demo Video?

With the advent of the TS Gateway service on SBS 2008, the only thing protecting our production SBS 2008 networks is a password.

Even  with a passphrase in place, there are some pretty sophisticated password dictionaries out there.

We will be looking to providing another layer of protection to our SBS 2008 networks.

That protection will be provided by Dana Epp’s (Security MVP blog link) AuthAnvil security product.

Check out the video that demonstrates AuthAnvil in action:

09-03-14 AuthAnvil

Scorpion Software: AuthAnvil Demonstration Video

Something to keep in mind is that TSGrinder (Live Search) has been reworked to now be able to attack the new TS setup on Windows Server 2008.

The video link: Scorpion Software: AuthAnvil Demonstration Video

Scorpion Software also offers a partner program: Scorpion Software Partner Program.

Much like Vlad’s OwnWebNow, Scropion Software is another reputable product vendor that delivers on a great business relationship and a great product set that is well supported.

Do check out Dana’s blog. It is a good read!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Thursday, 3 July 2008

SBS - Quick Companyweb Internet Access Link

When we have published the Companyweb site to the Internet via the CEICW and the Remote Web Workplace, there is a very quick way to gain access: Create an Internet shortcut.

Here are the quick links to the Companyweb root site:
  • SBS 2003
    • https://rww.mysbsdomain.com:444
  • SBS 2008:
    • https://rww.mysbsdomain.com:987
With this knowledge in hand, we can setup a number of interesting data sharing scenarios based on the built-in SharePoint setup in both versions of SBS.

We could create a document library that only a particular set of domain and non-domain (Extranet) restricted users have access to such as ExternalCompany.

In the above example, we would have the following links:
  • SBS 2003
    • https://rww.mysbsdomain.com:444/ExternalCompany
  • SBS 2008:
    • https://rww.mysbsdomain.com:987/ExternalCompany
One could also go so far as to create a SharePoint site that uses the above URL or another set by the domain admin with the appropriate permissions set for that site.

Depending on the situation, an Active Directory OU, Group Policy, and NTFS ACL setups could be utilized to restrict a particular group to the SharePoint site only.

For those that require a distinct separation from their Active Directory domain, the External Collaboration Toolkit for SharePoint would work well. The setup in this case would require us to have a second server setup with IIS6/7 and SharePoint V3 installed.

If the extranet business relationship and data security warrants it, a second level authentication setup could be utilized in the form of AuthAnvil from Scorpion Software. This method of security would completely restrict access to any Internet facing resources to those who hold an AuthAnvil hardware token and a valid user name and password. The cost for the product is very inexpensive relative to the extra level of security it provides.

Some SharePoint related links: Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.