For all my Small Business friends:
Secunia, one of the big names in Patch Management (software that makes sure your computer is up to date) has just launched a cloud based service for small businesses with fewer than 50 PCs.
Secuina Personal Software Inspector (PSI) has always been free, but only for personal use. (and I highly recommend everyone install it as one of those must have bits of free software)
Corporate Software Inspector (CSI), thier main product line, has always been just out of reach for a lot of small businesses both from a price point and because it requires you to install and maintain a server for it. They recognized this limitation and put together this new Small Business solution.
Read about it here: http://www.net-security.org/secworld.php?id=14476
Sign up for the free trial here: http://secunia.com/products/smb/smallbusiness/
After the beta ends the first 5 machines will still be free and additional machines less than $5/month each.
I have been a user of PSI on my home computers for years and couldn't be happier. Now with this I have something to recommend that can protect small business machines as well.
Tuesday, February 26, 2013
Sunday, February 24, 2013
The Blackberry Z10 is a nice phone that runs the new Blackberry 10 OS.
I have had one for a few days, and there are 2 downsides I see with it. #1 terrible battery life compared to older blackberries. (the best I have achieved so far is 17 hours with Wifi and Bluetooth both on)
#2 is the lack of Apps. My old BlackBerry had Kindle, RSA SecurID, and Google Authenticator. None of these are available for my new BB10 phone.
They are available on Android though, and Blackberry 10 kind of, sort of supports Android software. What you need to do to load android software is somehow get your hands on a .bar file of it and sideload from your PC.
You would use DDPB on your PC to sideload apps.
Sideloading can only put the app in the personal side of the BB10 device.
Instructions on how to do that are here in this video from GoodEReader.com:
Once you have that program installed on your PC you can download already tested .bar files from GoodEReader.com
If you can't find the files you want you can get the .apk from any android device by installing airdroid on the android phone/tablet and connecting to it's webpage from a PC This will let you download the apps that are installed on the android device.
Once you have the .apk file you can convert it to a .bar file here.
I have converted the Google Authenticator for Gmail 2 factor authentication. The converted .bar version does not scan the QR code like it does on Android, but that's OK with me, I had to type the key code into the one on the old blackberry too.
I have had one for a few days, and there are 2 downsides I see with it. #1 terrible battery life compared to older blackberries. (the best I have achieved so far is 17 hours with Wifi and Bluetooth both on)
#2 is the lack of Apps. My old BlackBerry had Kindle, RSA SecurID, and Google Authenticator. None of these are available for my new BB10 phone.
They are available on Android though, and Blackberry 10 kind of, sort of supports Android software. What you need to do to load android software is somehow get your hands on a .bar file of it and sideload from your PC.
You would use DDPB on your PC to sideload apps.
Sideloading can only put the app in the personal side of the BB10 device.
Instructions on how to do that are here in this video from GoodEReader.com:
Once you have that program installed on your PC you can download already tested .bar files from GoodEReader.com
If you can't find the files you want you can get the .apk from any android device by installing airdroid on the android phone/tablet and connecting to it's webpage from a PC This will let you download the apps that are installed on the android device.
Once you have the .apk file you can convert it to a .bar file here.
I have converted the Google Authenticator for Gmail 2 factor authentication. The converted .bar version does not scan the QR code like it does on Android, but that's OK with me, I had to type the key code into the one on the old blackberry too.
Friday, January 11, 2013
Internet Down :(
Right now my internet is down.
Yes, I'm blogging and my internet is down. And the sad news is because it's a phone company problem it'll probably be down for days.
My DSL modem dropped off the internet at about 6PM EST. This also means my home phone is down because I have it set up as a Voice Over IP connection. That, as you can tell, didn't keep me off the internet. Not even for a heartbeat. As I determined that the trouble was the DSL line. (the outside line, beyond the DSL modem in my basement) I grabbed my cell phone and looked up their number in the built-in web browser, and called my ISP. As I waited on hold I switched it to the Facebook app to tell my friends that our planned movie night was off as I had no Netflix if I had no internet. Truth is I already knew how I could set up Netflix, and I may at some point this weekend if we're really bored, but it would not have be very enjoyable at the time with the on-hold music playing over the phone.
Having sent the message to my friends I continued to wait on hold, with the cell phone plugged into a charger to keep it from dying before I got through to a live body. Once I did get through to Mark at Tech Savvy (Thanks for taking me seriously Mark, the first person I spoke to wasn't willing to help me until I turned the computer off and on again. Seriously, that was what she asked me to do, and refused to help me because I insisted that the computer was not the problem as I could clearly see that the modem's DSL interface did not have sync... I didn't catch her name, did you guys hire Jen from IT Crowd?) ...anyway, once I got through to Mark and explained the situation, stepped through some troubleshooting of connecting a phone to the dry loop only to hear a bunch of static. (sounds like water in the line, it is raining out. I'm guessing a squirrel chewed the drop) We then plugged the modem into the demarcation jack outside (in the rain at night, but it proves a point to the phone company that will come to fix it... that the trouble isn't in the 6 feet of indoor wiring between the outside wall and the modem.
Once the busy work of setting up a work order for a Bell tech to come out was done, I sat down and my wife was chatting online via the "experimental" browser in her Kindle. I proceeded to plug the Blackberry back into the USB port of my laptop to charge and launched the BB Desktop to connect to the internet. Anna asked if she could borrow my computer, I asked "Why? I'll just share my internet with you." A couple of clicks later, and we were both sitting comfortably on the couch with our laptops, surfing the internet as usual.
It's amazing the connected lives we live these days. I kind of anticipated this sort of development when I was in high-school suffering from BBS withdrawal on a week-long camping trip in Algonquin Provincial Park. I could see a day coming when I'd probably always be connected. Well, at some point that just happened.
[Edit: 2:25 PM 13/01/2013 :
Bell guy came and switched us to another pair, one of the wire in our pair on te drop was broken. Damned squirrels!]
Yes, I'm blogging and my internet is down. And the sad news is because it's a phone company problem it'll probably be down for days.
My DSL modem dropped off the internet at about 6PM EST. This also means my home phone is down because I have it set up as a Voice Over IP connection. That, as you can tell, didn't keep me off the internet. Not even for a heartbeat. As I determined that the trouble was the DSL line. (the outside line, beyond the DSL modem in my basement) I grabbed my cell phone and looked up their number in the built-in web browser, and called my ISP. As I waited on hold I switched it to the Facebook app to tell my friends that our planned movie night was off as I had no Netflix if I had no internet. Truth is I already knew how I could set up Netflix, and I may at some point this weekend if we're really bored, but it would not have be very enjoyable at the time with the on-hold music playing over the phone.
Having sent the message to my friends I continued to wait on hold, with the cell phone plugged into a charger to keep it from dying before I got through to a live body. Once I did get through to Mark at Tech Savvy (Thanks for taking me seriously Mark, the first person I spoke to wasn't willing to help me until I turned the computer off and on again. Seriously, that was what she asked me to do, and refused to help me because I insisted that the computer was not the problem as I could clearly see that the modem's DSL interface did not have sync... I didn't catch her name, did you guys hire Jen from IT Crowd?) ...anyway, once I got through to Mark and explained the situation, stepped through some troubleshooting of connecting a phone to the dry loop only to hear a bunch of static. (sounds like water in the line, it is raining out. I'm guessing a squirrel chewed the drop) We then plugged the modem into the demarcation jack outside (in the rain at night, but it proves a point to the phone company that will come to fix it... that the trouble isn't in the 6 feet of indoor wiring between the outside wall and the modem.
Once the busy work of setting up a work order for a Bell tech to come out was done, I sat down and my wife was chatting online via the "experimental" browser in her Kindle. I proceeded to plug the Blackberry back into the USB port of my laptop to charge and launched the BB Desktop to connect to the internet. Anna asked if she could borrow my computer, I asked "Why? I'll just share my internet with you." A couple of clicks later, and we were both sitting comfortably on the couch with our laptops, surfing the internet as usual.
It's amazing the connected lives we live these days. I kind of anticipated this sort of development when I was in high-school suffering from BBS withdrawal on a week-long camping trip in Algonquin Provincial Park. I could see a day coming when I'd probably always be connected. Well, at some point that just happened.
[Edit: 2:25 PM 13/01/2013 :
Bell guy came and switched us to another pair, one of the wire in our pair on te drop was broken. Damned squirrels!]
Tuesday, January 08, 2013
Ubuntu Phone
Years ago I imagined a time when I would have a PDA/Phone size devices I could carry in my pocket, but when i was at home I could dock it and it would be my desktop computer.
That device has finally arrived.
While Android and iPhone battle it out over which will claim the hordes of users fleeing the sinking ship of RIM BlackBerry, and Microsoft struggles to claim chunk of the market for themselves, a new player enters the game. It is Ubuntu Linux, and the phone is a full featured Linux machine. Connect it to a docking station at home and it is your Desktop, or your media centre, or whatever you want it to be. It is a truly portable computer.
That device has finally arrived.
While Android and iPhone battle it out over which will claim the hordes of users fleeing the sinking ship of RIM BlackBerry, and Microsoft struggles to claim chunk of the market for themselves, a new player enters the game. It is Ubuntu Linux, and the phone is a full featured Linux machine. Connect it to a docking station at home and it is your Desktop, or your media centre, or whatever you want it to be. It is a truly portable computer.
Monday, January 07, 2013
Wake on LAN
Ever wished you could click a button and a computer in another room would boot itself up? Maybe you want to stream your iTunes media from a computer in the bedroom to the media center HTPC in the living room, but you didn't turn the bedroom computer on when you were last upstairs. Maybe you want computers to wake up in the middle of the night so they can get that 3am scheduled update... Maybe you manage a whole network of computers and there are a few that just don't get used often and you want to boot them up so you can check on them over the network. This is what Wake on LAN (WOL) is made to do. Any computer that is Advanced Configuration Power Interface
(ACPI) compliant can be turned on remotely. You might have to go into the BIOS/UEFI firmware to set the WOL option to enabled, but it should be there. In the old days (around 1999) they used to sell PCI add-on network cards that had a Wake-on-LAN cable, a little twisted pair of wires that ran from the LAN card to the motherboard to send a wake-up signal. These days the wire is no longer needed (heck the card is no longer needed) WOL has become so common-place that it's just built-in.
Some home routers have WOL software built into them to wake the computers on your home network. Some corporate patch management software lets you WOL machines as needed.
Linux has a command line program called wakeonlan.
It is used by typing:
wakeonlan [-i IP_address] [-p port] [hardware_address]
Windows has this too, called wolcmd (well, sort of, you have to download it from the 3rd party website www.depicus.com)
It is used by typing:
wolcmd [mac address] [ip address] [subnet mask] [port number]
Either of these can be put into a script to do more complex things like scheduling.
You can get WOL on your phone from Depicus too, and wake up your computers right from the palm of your hand. For iPhone/iPad/iPod Touch, Android and even Windows Phone! He also has a little GUI version, but because it doesn't remember details, it's less useful than the command line version, but it's not as scary to some users.
Personally, I wanted an easy way in windows to create groups of computers that wake up at a given scheduled time, so I've thrown together a little program over the holidays that I can use to wake PCs up on a schedule.
My program is called OgounWOL and you can download it here. (requires free registration to use)
OgounWOL comes in 2 parts. A little program that you can schedule to run once every 15 minutes, and a GUI manager (shown below) that you use to edit the program's database.
In OgounWOL you first create a list of all of your computers, then group the computers into groups that you want to wake up together, and then set up schedules to wake groups of computers up at a given time.
You don't need to keep this manager open, every 15 minutes the scheduled task will run a program silently in the background to look up if anyone needs waking and if so, send them the WOL Magic Packet to wake them up.
I have another version, that runs from a command line and takes a .csv file listing computers that you want to wake up. I call this one WOLCSV It is free and does not require registration. I wrote that one for use at work back in 2011.
Some home routers have WOL software built into them to wake the computers on your home network. Some corporate patch management software lets you WOL machines as needed.
Linux has a command line program called wakeonlan.
It is used by typing:
wakeonlan [-i IP_address] [-p port] [hardware_address]
Windows has this too, called wolcmd (well, sort of, you have to download it from the 3rd party website www.depicus.com)
It is used by typing:
wolcmd [mac address] [ip address] [subnet mask] [port number]
Either of these can be put into a script to do more complex things like scheduling.
You can get WOL on your phone from Depicus too, and wake up your computers right from the palm of your hand. For iPhone/iPad/iPod Touch, Android and even Windows Phone! He also has a little GUI version, but because it doesn't remember details, it's less useful than the command line version, but it's not as scary to some users.
Personally, I wanted an easy way in windows to create groups of computers that wake up at a given scheduled time, so I've thrown together a little program over the holidays that I can use to wake PCs up on a schedule.
My program is called OgounWOL and you can download it here. (requires free registration to use)
OgounWOL comes in 2 parts. A little program that you can schedule to run once every 15 minutes, and a GUI manager (shown below) that you use to edit the program's database.
You don't need to keep this manager open, every 15 minutes the scheduled task will run a program silently in the background to look up if anyone needs waking and if so, send them the WOL Magic Packet to wake them up.
I have another version, that runs from a command line and takes a .csv file listing computers that you want to wake up. I call this one WOLCSV It is free and does not require registration. I wrote that one for use at work back in 2011.
Monday, December 31, 2012
Microsoft EMET
Over the holidays some of you may have seen some version of this story:
http://thenextweb.com/microsoft/2012/12/29/criminals-use-adobe-flash-and-new-ie-vulnerability-in-targeted-attacks-ie9-and-ie10-users-are-safe/
or if you are a security geek, this one:
https://community.rapid7.com/community/metasploit/blog/2012/12/29/microsoft-internet-explorer-0-day-marks-the-end-of-2012
Once again, a new 0-day Internet Explorer vulnerability was discovered that affects IE7 and IE8. On the 29th an exploit for it was introduced into Metasploit, and you know they say, crimeware advances at the pace of Metasploit. (Metasploit is open source, so any programmer can see exactly what they did to expolit the bug and copy that if they have not already figured it out for themselves.)
You may note that aside from upgrading to IE9/IE10 there is a suggestion that you could mitigate this vulnerability by running EMET. The only realistic action for many businesses to take would be EMET.
This is not the first time you might have seen this suggestion, but most people I have talked to who are not well read on IT security have never even heard of EMET.
The tl;dr executive summary is:
EMET stops malicious programs running in the context of legitimate programs by killing the whole process before the malicious code can do it’s damage. This allows us to protect against some unpatched vulnerability exploits. It is free and MS supports it.
What does EMET do?
EMET (Enhanced Mitigation Experience Toolkit, I think that’s a rather poor name, so I will always refer to it as EMET) is a free program from Microsoft (fully supported by MS) that allows you to specify various security mitigations that are built into Windows, but not often implemented in software.
DEP, ASLR, and SEHOP can be turned on at a system level (although they are not by default)
DEP, SEHOP, NULL Page, Heap Spray, Mandatory ASLR, EAF, and Bottom-up ASLR protections can be turned on for individual applications. (see manual for more info)
DEP is already mandatory on 64bit Windows for all 64 bit processes, but not for 32bit programs. All of the rest are optional, and often not implemented by software developers even if there is no reason they need to avoid them. EMET allows you to turn these abilities on even for programs that were not designed for them. (Caution, some of these may break things for some programs, but they are easy to switch on and off)
EMET has 3 lists of defaults that can be set for applications. These defaults have already been tested by engineers at Microsoft. They can be set by importing one of the 3 default lists that come with it, or via GPO (more details below)
http://thenextweb.com/microsoft/2012/12/29/criminals-use-adobe-flash-and-new-ie-vulnerability-in-targeted-attacks-ie9-and-ie10-users-are-safe/
or if you are a security geek, this one:
https://community.rapid7.com/community/metasploit/blog/2012/12/29/microsoft-internet-explorer-0-day-marks-the-end-of-2012
Once again, a new 0-day Internet Explorer vulnerability was discovered that affects IE7 and IE8. On the 29th an exploit for it was introduced into Metasploit, and you know they say, crimeware advances at the pace of Metasploit. (Metasploit is open source, so any programmer can see exactly what they did to expolit the bug and copy that if they have not already figured it out for themselves.)
You may note that aside from upgrading to IE9/IE10 there is a suggestion that you could mitigate this vulnerability by running EMET. The only realistic action for many businesses to take would be EMET.
This is not the first time you might have seen this suggestion, but most people I have talked to who are not well read on IT security have never even heard of EMET.
The tl;dr executive summary is:
EMET stops malicious programs running in the context of legitimate programs by killing the whole process before the malicious code can do it’s damage. This allows us to protect against some unpatched vulnerability exploits. It is free and MS supports it.
What does EMET do?
EMET (Enhanced Mitigation Experience Toolkit, I think that’s a rather poor name, so I will always refer to it as EMET) is a free program from Microsoft (fully supported by MS) that allows you to specify various security mitigations that are built into Windows, but not often implemented in software.
DEP, ASLR, and SEHOP can be turned on at a system level (although they are not by default)
DEP, SEHOP, NULL Page, Heap Spray, Mandatory ASLR, EAF, and Bottom-up ASLR protections can be turned on for individual applications. (see manual for more info)
DEP is already mandatory on 64bit Windows for all 64 bit processes, but not for 32bit programs. All of the rest are optional, and often not implemented by software developers even if there is no reason they need to avoid them. EMET allows you to turn these abilities on even for programs that were not designed for them. (Caution, some of these may break things for some programs, but they are easy to switch on and off)
EMET has 3 lists of defaults that can be set for applications. These defaults have already been tested by engineers at Microsoft. They can be set by importing one of the 3 default lists that come with it, or via GPO (more details below)
Labels:
Anti-Virus,
EMET,
Firefox,
Internet Explorer,
Security,
Virus,
Windows
Friday, December 14, 2012
SANS's New Monthly Awareness Video Page
Securing The Human is a corporate security awareness training program based around a bundle of 2-6 minute computer animated videos that each highlight an aspect of computer security. The full corporate training program costs $3000 or more per year (unless you are in the government or education sectors), and includes tracking employee views to allow for completion certificates to be e-mailed out and to give managers a log of employee completion of the training so that you can use that for compliance purposes. It also allows custom content such as policy documents to be attached to the training materials.
The good news for really small organisations that cannot afford even the $3000 small business package (which allows you to have upto 750 seats) is that they now offer one video per month for free, but obviously you'd have to track who watched it yourselves. Maybe you could hold a monthly staff meeting and review the video together. Better yet, this allows private individuals who are not employed by a company that subscribes to the Securing the Human program to have access to the materials at home.
The good news for really small organisations that cannot afford even the $3000 small business package (which allows you to have upto 750 seats) is that they now offer one video per month for free, but obviously you'd have to track who watched it yourselves. Maybe you could hold a monthly staff meeting and review the video together. Better yet, this allows private individuals who are not employed by a company that subscribes to the Securing the Human program to have access to the materials at home.
Monday, December 03, 2012
Secure Browser Settings
I know this is going to be long and technical, but it is important for everyone regardless of your technical ability to look at.
The one line TLDR version (TLDR is internet speak for "too long, didn't read") is this:
Secure sites use SSL. TLS is the newer SSL. You should be using the newest one you can.
Ok, so for a while now webmasters, IT people, developers etc, have been slowly transitioning the internet away from SSL 2.0 to newer versions of the protocol. SSL is the s in https:// it is the secure part of secure websites. Version 1 was phased out before most folks even knew there was an internet, but version 2.0 has stuck with us, despite being broken in many different ways, for a long time. The payment card industry, via their PCI-DSS rules by which individual merchants have to run their payment networks, and banking systems have to communicate with merchants across data networks like the internet, has outlawed the use of SSL 2.0
TLS 1.0 was first introduced back in 1999. In 2002 a theoretical exploit was discovered. About a year ago that exploit, dubbed the BEAST (Browser Exploit Against SSL and TLS) was made easy to do. It allows a person who can insert themselves between the user's browser and the secured web server to pick and choose what bits of encrypted data get sent and use the chosen length bits of ciphered text to get a head start on decrypting the conversation. This is effective only against SSL 3.0 and TLS 1.0, and only when they use block ciphers like AES and 3DES not stream ciphers like RC4. Because they have decided that we've had enough time, the payment card industry is starting to insist that merchants protect against the BEAST attack. This can cause someone with inadequate security settings on their browser to get a blank page when trying to connect to a secure website.
So far TLS 1.1 and 1.2 are still quite secure, but not used everywhere yet and not supported by every browser.
I'm going to show you how to turn on the best protocol available to you in the most popular browsers and then if you are also a techie running a server, I'll go into how to do the server side.
First Internet Explorer:
For Internet Explorer: In internet options, under the advanced tab, scroll almost all the way to the bottom and you will find these settings.
By default SSL 2.0, SSL 3.0 and TLS 1.0 should be on, I am recommending that all users switch off SSL 2.0 as no sites on the internet rely on that anymore, and it is a very broken protocol.
Also, if available (if you have Windows 7 or higher) you should turn on TLS 1.1 and TLS 1.2 as well.
Now Firefox:

Firefox already should have only SSL 3.0 and TLS 1.0 enabled. If it does not have TLS 1.0 checked please make sure you enable it.
Again, TLS 1.0 dates back to 1999 there has been over a decade of use ensuring that all sites and browsers are compatible.
The only reason to have it turned off is if you are US Government and required to use only 1.1 and 1.2 :) but as we can see with the Firefox example, not having anything older than 1.1 means breaking compatibility.
On the server side...
IIS:
IIS uses the Microsoft SChannel settings. The protocol versions it supports are turned on in the registry. Paste the following code into a file called saferSSL.reg or something like that. then double click on your new .reg file to import those settings.
And optionally (this one will break compatibility with IE6):
Then go into the group policy editor (type gpedit.msc into the run box or command line)
Find the section: Local Computer Policy -> Administrative Templates -> Network -> SSL Configuration Settings
edit the Cipher Order value to include only RC4 ciphers for SSL 3.0 and TLS 1.0.
Move "TLS_RSA_WITH_RC4_128_SHA" to the top of the priority list, and get rid of any SSL 3.0 or TLS 1.0 ciphersuites with CBC in the name. You can keep whatever TLS 1.1 or 1.2 ciphers you need (hint anything with SHA256 or higher is fine). If you are not sure what to include just copy this string into that box and click OK.
IIS 7.5:
IIS 7.0:
Apache:
Put this into your config
The one line TLDR version (TLDR is internet speak for "too long, didn't read") is this:
Secure sites use SSL. TLS is the newer SSL. You should be using the newest one you can.
Ok, so for a while now webmasters, IT people, developers etc, have been slowly transitioning the internet away from SSL 2.0 to newer versions of the protocol. SSL is the s in https:// it is the secure part of secure websites. Version 1 was phased out before most folks even knew there was an internet, but version 2.0 has stuck with us, despite being broken in many different ways, for a long time. The payment card industry, via their PCI-DSS rules by which individual merchants have to run their payment networks, and banking systems have to communicate with merchants across data networks like the internet, has outlawed the use of SSL 2.0
. A while back. And so, most websites and some browsers (I think all browsers except Internet Explorer) have abandoned the old clunker of a security protocol. By default most newer web browsers support SSL 3.0 and TLS 1.0 (which can be thought of as SSL 3.1 or 4.0).TLS 1.0 was first introduced back in 1999. In 2002 a theoretical exploit was discovered. About a year ago that exploit, dubbed the BEAST (Browser Exploit Against SSL and TLS) was made easy to do. It allows a person who can insert themselves between the user's browser and the secured web server to pick and choose what bits of encrypted data get sent and use the chosen length bits of ciphered text to get a head start on decrypting the conversation. This is effective only against SSL 3.0 and TLS 1.0, and only when they use block ciphers like AES and 3DES not stream ciphers like RC4. Because they have decided that we've had enough time, the payment card industry is starting to insist that merchants protect against the BEAST attack. This can cause someone with inadequate security settings on their browser to get a blank page when trying to connect to a secure website.
So far TLS 1.1 and 1.2 are still quite secure, but not used everywhere yet and not supported by every browser.
I'm going to show you how to turn on the best protocol available to you in the most popular browsers and then if you are also a techie running a server, I'll go into how to do the server side.
First Internet Explorer:
For Internet Explorer: In internet options, under the advanced tab, scroll almost all the way to the bottom and you will find these settings.
By default SSL 2.0, SSL 3.0 and TLS 1.0 should be on, I am recommending that all users switch off SSL 2.0 as no sites on the internet rely on that anymore, and it is a very broken protocol.
Also, if available (if you have Windows 7 or higher) you should turn on TLS 1.1 and TLS 1.2 as well.
Now Firefox:
Firefox already should have only SSL 3.0 and TLS 1.0 enabled. If it does not have TLS 1.0 checked please make sure you enable it.
Again, TLS 1.0 dates back to 1999 there has been over a decade of use ensuring that all sites and browsers are compatible.
The only reason to have it turned off is if you are US Government and required to use only 1.1 and 1.2 :) but as we can see with the Firefox example, not having anything older than 1.1 means breaking compatibility.
On the server side...
IIS:
IIS uses the Microsoft SChannel settings. The protocol versions it supports are turned on in the registry. Paste the following code into a file called saferSSL.reg or something like that. then double click on your new .reg file to import those settings.
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 64/128] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server] "Enabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server] "Enabled"=dword:00000000
And optionally (this one will break compatibility with IE6):
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server] "Enabled"=dword:00000000
And then to enable TLS 1.1 and 1.2:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\client] "Enabled"=dword:00000001 "DisabledByDefault"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server] "Enabled"=dword:00000001 "DisabledByDefault"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\client] "Enabled"=dword:00000001 "DisabledByDefault"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server] "Enabled"=dword:00000001 "DisabledByDefault"=dword:00000000
Then go into the group policy editor (type gpedit.msc into the run box or command line)
Find the section: Local Computer Policy -> Administrative Templates -> Network -> SSL Configuration Settings
edit the Cipher Order value to include only RC4 ciphers for SSL 3.0 and TLS 1.0.
Move "TLS_RSA_WITH_RC4_128_SHA" to the top of the priority list, and get rid of any SSL 3.0 or TLS 1.0 ciphersuites with CBC in the name. You can keep whatever TLS 1.1 or 1.2 ciphers you need (hint anything with SHA256 or higher is fine). If you are not sure what to include just copy this string into that box and click OK.
IIS 7.5:
TLS_RSA_WITH_RC4_128_SHA,TLS_RSA_WITH_RC4_128_MD5,SSL_CK_RC4_128_WITH_MD5,TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P521
IIS 7.0:
TLS_RSA_WITH_RC4_128_SHA,TLS_RSA_WITH_RC4_128_MD5,SSL_CK_RC4_128_WITH_MD5
Apache:
Put this into your config
SSLHonorCipherOrder On
SSLCipherSuite ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH
Subscribe to:
Posts (Atom)

