Fixing Weak SSL for The Slacker Admin

IIS Crypto is a great free tool produced by Nartac Sotware that allows Windows Server/IIS admins to easily enable/disable weak SSL cryptos and ciphers. This is a PCI requirement, and I’ve seen it show up on many scan using tools designed to probe for compliance. It’s usually a tedious process of adding/changing registry keys, right up to today’s current Windows OSes.

I recently had two fully patched Win Server 2008 R2 servers that were failing PCI scans using the McAffee Secure online service. IIS Crypto made short work out of what would’ve been a longer after hours change. It even has a PCI button that you can just click and it configs the server for compliance. Saved me a ton of work. Microsoft needs to start turning this off by default though and maybe even ask if you want it turned on, just a thought for the guys at Redmond.

In a unique twist, even after verifying the registry keys were correct after running the tool, McAffee still complained about the problem after a post-change scan. Qualy’s SSL Site Analyzer, a nifty and free online tool, actually passed it with flying colors. Another interesting venture of theirs is the HTTP Client Fingerprinting Using SSL Handshake Analysis project, which produced a mod for Apache and some other interesting reads at the bottom of the page, enjoy.

 

Microsoft Covets Yahoo?

I mean seriously…does Microsoft need to be any bigger than it already is? As far as ad revenue goes, Google almost has the entire pie, has had it for a long time, and is simply a better company, to work for at least.

Fortunately Yahoo had the foresight to tell Gates and Co. to go suck an egg, but I wonder if it will become a hostile takeover. Somehow that doesn’t make a really good image for Redmond does it? Submit to their bidding or be assimilated.

 

Access Based Enumeration

So um, don’t enable ABE on a file server with files you copied from an old domain and server. Apparently the old file attributes will make certain user files disappear…even if you’ve given them full control..isn’t that fun boys and girls?