<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cupfighter.net &#187; Schuberg Philis</title>
	<atom:link href="http://www.cupfighter.net/index.php/tag/schuberg-philis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cupfighter.net</link>
	<description>A blog by Schuberg Philis colleagues</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>What is a cupfighter?</title>
		<link>http://www.cupfighter.net/index.php/2011/05/what-is-a-cupfighter/</link>
		<comments>http://www.cupfighter.net/index.php/2011/05/what-is-a-cupfighter/#comments</comments>
		<pubDate>Mon, 30 May 2011 15:55:43 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[CUpfighter]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=1335</guid>
		<description><![CDATA[In order to better explain what a Cupfighter is, our employer Schuberg Philis created this video: We are always looking for more Cupfighters.]]></description>
			<content:encoded><![CDATA[<p>In order to better explain what a Cupfighter is, our employer Schuberg Philis created this video:</p>
<p><a href="http://www.cupfighter.net/index.php/2011/05/what-is-a-cupfighter/"><em>Click here to view the embedded video.</em></a></p>
<p>We are always <a title="http://www.schubergphilis.com/careers/campaigns/cupfighter-mentaliteit/vacature/" href="http://">looking for more Cupfighters</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2011/05/what-is-a-cupfighter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My take on MS10-070 &#8211; A tricky patch</title>
		<link>http://www.cupfighter.net/index.php/2010/09/ms10-070/</link>
		<comments>http://www.cupfighter.net/index.php/2010/09/ms10-070/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 08:00:17 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WSUS]]></category>
		<category><![CDATA[.net]]></category>
		<category><![CDATA[32-bit]]></category>
		<category><![CDATA[32bit]]></category>
		<category><![CDATA[64-bit]]></category>
		<category><![CDATA[64bit]]></category>
		<category><![CDATA[ASP.net]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[Download center]]></category>
		<category><![CDATA[Frank Breedijk]]></category>
		<category><![CDATA[Juliana Rizzo]]></category>
		<category><![CDATA[MachineKey]]></category>
		<category><![CDATA[MS10-070]]></category>
		<category><![CDATA[msftsecresponse]]></category>
		<category><![CDATA[Netifera]]></category>
		<category><![CDATA[oob]]></category>
		<category><![CDATA[Out of band]]></category>
		<category><![CDATA[Padding Oracle]]></category>
		<category><![CDATA[Padding Oracle Vulnerability]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Scott Gurthrie]]></category>
		<category><![CDATA[Thai Duong]]></category>
		<category><![CDATA[webcast]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=1158</guid>
		<description><![CDATA[Last night I attended the Microsoft Security Response Team webcast regarding the Out Of Band patch for the ASP.net padding Oracle vulnerability discovered by Juliana Rizzo and Thai Duong 11 days before. My main objective in watching the webcast (which is not my usual habit) was to find out if systems that have the described [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cupfighter.net/wp-content/uploads/2010/09/asp.not_.png"><img class="alignright size-full wp-image-1159" title="ASP.not" src="http://www.cupfighter.net/wp-content/uploads/2010/09/asp.not_.png" alt="ASP.Net logo, broken" width="207" height="155" /></a>Last night I attended the <a title="@msftsecresponse on Twitter" href="http://twitter.com/msftsecresponse" target="_blank">Microsoft Security Response Team</a> <a title="Recorded WebCast" href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032464131&amp;culture=en-us" target="_blank">webcast</a> regarding the Out Of Band patch for the <a title="Scott Guthrie's blog" href="http://weblogs.asp.net/scottgu/archive/2010/09/24/update-on-asp-net-vulnerability.aspx" target="_blank">ASP.net padding Oracle vulnerability</a> discovered by <a title="@julianor on Twitter" href="http://twitter.com/julianor" target="_blank">Juliana Rizzo</a> and <a title="@thaidn on Twitter" href="http://twitter.com/thaidn" target="_blank">Thai Duong</a> 11 days before.</p>
<p>My main objective in watching the webcast (which is not my usual habit) was to find out if systems that have the described workaround applied still need to apply the patch. The webcast did not give a definitive answer but <a title="YouTube video of POET compromising an Asp.net installation with workaround applied" href="http://www.youtube.com/watch?v=mP6mKLh1FBw" target="_blank">this YouTube video</a> and the <a title="Netifera website" href="http://netifera.com/research/" target="_blank">Netifera website</a> and the twitter accounts <a title="@thaidn on should I apply the patch or not..." href="http://twitter.com/thaidn/status/25832618846" target="_blank">Thai Duong</a> provide the answer: <strong>Yes you should apply the patch a.s.a.p!</strong></p>
<p><p><a href="http://www.cupfighter.net/index.php/2010/09/ms10-070/"><em>Click here to view the embedded video.</em></a></p><strong><br />
</strong></p>
<p>However the Q&amp;A section of the talk did give me, as a security operations guy, quite some food for thought. I made some notes in my own <a title="@Seccubus on Twitter" href="http://twitter.com/seccubus" target="_blank">Twitter feed</a>, which I have summarized here.</p>
<p>Q: Why did Microsoft release and OOB update for a vulnerability rated “only” as important?<br />
A: The vulnerability itself is rated as Important because it is not a vulnerability that directly leads to remote code execution on the vulnerable system, however exploitation of the vulnerability will lead to disclosure of all information in the webroot including web.config. This information can be used for session hijacking, compromising backend databases and to attack associations between websites, e.g. the association of a website with PayPal. Hence an out of band patch was warranted.</p>
<p>Q: Why only release to the download center and not to WSUS etc?<br />
A: We felt we needed to get this update out quickly, the people that need to apply this patch quickly are mainly enterprises who are capable of applying patches without the aid of WSUS. Developing the WSUS capabilities would add another few days of delay to the deployment of this patch.</p>
<p>Q: Is the attack actively used?</p>
<p><span id="more-1158"></span></p>
<p>A: We have seen limited attacks against this vulnerability as well as continuous efforts to to bypass installed workarounds.</p>
<p>Q: Can the patch be uninstalled, does it require a reboot?<br />
A: The patch can be uninstalled and does require a reboot.</p>
<p>Q: If you have multiple versions of .Net installed on the system, do you need to install all patches for each version of .Net?<br />
A: Yes.</p>
<p>Q: If you have 64bit and 32bit version of Asp.Net installed, do you need to apply both 64bit and 32bit patches?<br />
A: No, the 64bit patch will patch the 32bit versions as well.</p>
<p>Q: Should we regard the ASP.NET <a title="MSDN article about the Machine Key" href="http://msdn.microsoft.com/en-us/library/ff649308.aspx" target="_blank">MachineKey</a> as compromised?<br />
A: Yes, if you have set a static MachineKey it is recommended to <a title="ASP.Net MachineKey generator application" href="http://www.codeproject.com/KB/aspnet/machineKey.aspx" target="_blank">replace this key with a new key</a>. (Information on AutoGenerated MachineKeys was not provided)</p>
<p>Q: Will the patch have an effect on end-users?<br />
A: Yes, information stored on the client that is protected by the MachineKey can no longer be validated. This can e.g. mean that users whoo used a ‘remember me’ function will have to login in again.</p>
<p>Q: Does the patch need to be applied to all nodes of a cluster?<br />
A: Yes, because the patch changes the way data in transit (such as e.g. viewstate) is encrypted, this patch needs to be applied to all nodes in a cluster as the same time or users may experience unexpected results.</p>
<p>Q: Does the patch change IIS?<br />
A: No, the patch only changes ASP.NET, not IIS.</p>
<p>Q: Does the patch change the way encrypted data is stored on the server?<br />
A: No, the patch changes the way data in transit is cryptographically protected, both encryption and signing is now applied. It does not effect any encrypted data stored on the server.</p>
<p>Q: Are the patches in the download center “smart” enough to know if they are applicable for the machine you apply them to?<br />
A: No, detection capabilities will be built into the patches once they are deployed to WSUS.</p>
<p>Q: Should the update be applied to all .net installation, not just web servers?<br />
A: The vulnerability only manifests itself via web servers. For now it is recommended to only install patches there, and way for the patches to appear in WSUS before patching other .net installs. But remember a system with an unpatched .net installation will become vulnerable as soon as a webserver is installed.</p>
<p>Q: Should the workaround be removed prior to patching?<br />
A: No, you can apply the patch with the workaround in place. If you need to do so you can then remove the workaround after the patch has been applied. CustomErrors generally does not hurt and neither does UrlScan all though UrlScan is known to break SharePoint and may break other web applicaitons as well</p>
<p>Q: Do customer applications need to be recompiled?<br />
A: No.</p>
<p><a title="Scott Guthrie’s blog" href="http://weblogs.asp.net/scottgu/archive/2010/09/28/asp-net-security-update-now-available.aspx" target="_blank">Scott Guthrie’s blog</a> has an excellent overview of which patch is applicable to which platform.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2010/09/ms10-070/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>CA will not start&#8230; What do you mean, cannot download CRL&#8230;</title>
		<link>http://www.cupfighter.net/index.php/2010/01/ca-will-not-start-what-do-you-mean-cannot-download-crl/</link>
		<comments>http://www.cupfighter.net/index.php/2010/01/ca-will-not-start-what-do-you-mean-cannot-download-crl/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 22:50:05 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[0x80092013]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[CertUtil]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[PKI view]]></category>
		<category><![CDATA[revocation]]></category>
		<category><![CDATA[Windows 2000]]></category>
		<category><![CDATA[windows 2003]]></category>
		<category><![CDATA[windows vista]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=860</guid>
		<description><![CDATA[As part of my work I was installing a Microsoft PKi infrastructure with two tiers. A root CA and an issuing CA. Since the root CA is in another domain then the issuing CA, it took some fiddling and tweaking around with my CDP and AIA extensions, but that is another blogpost all together. I [...]]]></description>
			<content:encoded><![CDATA[<p>As part of my work I was installing a Microsoft PKi infrastructure with two tiers. A root CA and an issuing CA.</p>
<p>Since the root CA is in another domain then the issuing CA, it took some fiddling and tweaking around with my CDP and AIA extensions, but that is another blogpost all together.</p>
<p>I knew I was in for some fun when when the following happened:</p>
<ul>
<li>I installed my Issuing CA and generated the certificate request</li>
<li>I issued the request to my Root CA and generated the Issuing CA certificate</li>
<li>I tried to install the Issuing CA certificate and got the following error:</li>
</ul>
<div id="attachment_861" class="wp-caption alignnone" style="width: 421px"><a href="http://www.cupfighter.net/wp-content/uploads/2010/01/Revokation-function-error.JPG"><img class="size-full wp-image-861" title="The revocation function was unable to check revocation because the revocation server was offline. 0x80092013" src="http://www.cupfighter.net/wp-content/uploads/2010/01/Revokation-function-error.JPG" alt="Cannot verify certificate chain. Do you whish to ignore the error and continue? The revocation function was unable to check revocation because the revocation server was offline. 0x80092013 (-2168885613)" width="411" height="166" /></a><p class="wp-caption-text">Cannot verify certificate chain. Do you whish to ignore the error and continue? The revocation function was unable to check revocation because the revocation server was offline. 0x80092013 (-2168885613)</p></div>
<p>My first reaction was to call one of the network guest and notify him that I needed http access to the Issuing CA to the CDP location. But whil on the phone, I decided to try and to my surprise I was actually able to manually pull down the crl.</p>
<p>Intregued, I decided to check a few things:</p>
<ul>
<li>I could download the CRL from both CDP locations with Internet Exporer</li>
<li>I could open the downloaded CRLs</li>
<li>I could telnet to port 80 of the both webservers</li>
<li>I could telnet to port 80 manually issue the GET /crl/CRLname.crl HTTP/1.0 command and get data back</li>
</ul>
<p>O.K. what is going on here&#8230; Lets open PKI view, which is now included in Windows 2008 and Vista and can be downloaded for Windows 2000 and 2003.</p>
<p>It seemed that PKI view as in agreement, it too could not download the CRL from the CDP location</p>
<div id="attachment_862" class="wp-caption alignnone" style="width: 467px"><a href="http://www.cupfighter.net/wp-content/uploads/2010/01/PKI-view.JPG"><img class="size-full wp-image-862" title="PKI view shows &quot;unable to Download&quot;" src="http://www.cupfighter.net/wp-content/uploads/2010/01/PKI-view.JPG" alt="PKI view shows &quot;Unable To Download&quot; for both CDP locations" width="457" height="91" /></a><p class="wp-caption-text">PKI view shows &quot;Unable To Download&quot; for both CDP locations</p></div>
<p>This did sent me on a wild goose chase:</p>
<ul>
<li><a title="Troubleshooting Certificate Validation Errors" href="http://technet.microsoft.com/en-us/library/bb331963.aspx" target="_blank">Microsoft own documentation</a>, clearly blames it on unavailability of the CDP location, something I, by now, had triple checked four times and refused to believe</li>
<li><a title="Netowrk Builders forum post suggesting to turn off revocation checking" href="http://www.network-builders.com/certificate-services-t11895.html" target="_blank">This &#8220;Network Builders&#8221; forum</a> and <a title="Another post suggesting to turn revocation checking off" href="http://www.spywarepoint.com/windows-2003-ca-0x80092013-t40183.html" target="_blank">many</a> others, simply suggest to turn off revocation checking, but that is clearly not a worthy solution either.</li>
<li>Apparently there is also an issue with <a title="Technet forum post about double escaping" href="http://social.technet.microsoft.com/Forums/en-US/windowsserver2008r2webtechnologies/thread/83be4ffb-439e-4d3f-9377-0d23e4307d86" target="_blank">serving delta CRLs threw IIS</a> because the + sign at the end of the basename of a delta CRL file leads to so called &#8220;double escaping&#8221;. I could rule this out by looking at the IIS logs.</li>
<li>In the end <a title="Technet forum post about OSCP responders" href="http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/d6e871e0-3687-4cb5-9591-c1459911f433" target="_blank">this technet forum post, about OCSP reponders</a> Brian Komar points out:</li>
</ul>
<blockquote><p>But, as stated, I would use certutil to get the &#8220;best&#8221; answer on how is my configuration.<br />
Certutil -verify -urlfetch &#8220;certfile.cer&#8221; will check *every* CDP and AIA URL (including OCSP) and tell you how they are all doing *at that specific instance in time&#8221; since it goes to the URLs immediately.<br />
Brian</p></blockquote>
<p>I exported the Issuing CA certificate from the certificate database of the Root CA and ran the command against is and this is what I found</p>
<blockquote><p>E:\&gt;certutil -verify -urlfetch &lt;certfile&gt;.cer<br />
Issuer:<br />
CN=Root CA<br />
Subject:<br />
CN=Issuing CA<br />
Cert Serial Number: 115d5f6400020000000b<br />
&lt;snip&gt;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-  Certificate AIA  &#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Verified &#8220;Certificate (0)&#8221; Time: 0<br />
[0.0] http://IIS1.domain1local/crl/Root-CA.crt</p>
<p>Verified &#8220;Certificate (0)&#8221; Time: 0<br />
[1.0] http://IIS2.domain1.local/crl/Root-CA.crt</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-  Certificate CDP  &#8212;&#8212;&#8212;&#8212;&#8212;-<br />
<strong>Wrong Issuer &#8220;Base CRL (13)&#8221;</strong> Time: 0<br />
[0.0] http://IIS1.domain1.local/crl/Root-CA.crl</p>
<p><strong>Wrong Issuer &#8220;Base CRL (13)&#8221;</strong> Time: 0<br />
[1.0] http://IIS2.domain1.local/crl/Root-CA.crl</p>
<p>&lt;snip&gt;<br />
E:\&gt;</p></blockquote>
<p>So while PKI view and the other error messages I was getting all pointed to the most common cause, it actually turned out that the CRl did get downloaded, but <a title="Technet articale about certificate revocation checking" href="http://technet.microsoft.com/en-us/library/bb457027.aspx" target="_blank">was not cryptographically relevant to what the system believes is the Root CA certificate</a>.</p>
<p><span style="text-decoration: underline;"><strong>Root cause</strong></span></p>
<p>Inspection of the CRLs generated and the Root certificates installed showed what had caused the problem. In order to test the CDP extensions I had reissued the Root CA certificate, causing the Root CA to have three active certificates. Each with a different key.</p>
<div id="attachment_866" class="wp-caption alignnone" style="width: 359px"><a href="http://www.cupfighter.net/wp-content/uploads/2010/01/Three-CA-certs.JPG"><img class="size-full wp-image-866" title="CA authority with Three CA certificates" src="http://www.cupfighter.net/wp-content/uploads/2010/01/Three-CA-certs.JPG" alt="This CA has three CA certificates" width="349" height="163" /></a><p class="wp-caption-text">This CA has three CA certificates</p></div>
<p>When validating the Issuing CA certificate, validation would end at the last certificate issued, however the CA still signs its CRLs with the key pair of the first certificate.</p>
<p>I guess for me there is nothing left but to reinstall the entire chain.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2010/01/ca-will-not-start-what-do-you-mean-cannot-download-crl/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Seccubus the new name for AutoNessus</title>
		<link>http://www.cupfighter.net/index.php/2009/11/seccubus/</link>
		<comments>http://www.cupfighter.net/index.php/2009/11/seccubus/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:20:04 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Confidence 2009.02]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[AutoNessus]]></category>
		<category><![CDATA[confidence0902]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Seccubus]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=782</guid>
		<description><![CDATA[Since it became apparent that the next version of AutoNessus was going to outgrow the reference to Nessus, Tennable’s Network Security Scanner, due to the inclusion of other scanners such as OpenVAS, NMAP and Nikto, the author of the program, Frank Breedijk, decided to start a contest for a new name. On the 19th of [...]]]></description>
			<content:encoded><![CDATA[<p>Since it became apparent that the next version of AutoNessus was going to outgrow the reference to Nessus, Tennable’s Network Security Scanner, due to the inclusion of other scanners such as OpenVAS, NMAP and Nikto, the author of the program, Frank Breedijk, decided to start a contest for a new name.</p>
<p>On the 19th of November Frank Breedijk announced that Jason Mansfield, who runs the website http:/clinicallyawasome.com, has won the contest by sending in the name Seccubus. A bottle of Vueve Clinquot champaing will be sent to him shortly.</p>
<p>The author has provided the following explanation of the name Seccubus:<br />
<span id="more-782"></span><br />
Seccubus is a mythical creature that helps security professionals analyze and report the results of, repeated, vulnerability scans. Like its distant cousins the <a title="Wikipedia article" href="http://en.wikipedia.org/wiki/Succubus" target="_blank">Succubus</a> and <a title="Wikipedia article" href="http://en.wikipedia.org/wiki/Incubus" target="_blank">Incubus</a> the Seccubus is also a creature of the night. At night, or any other scheduled time, the Seccubus draws its energy from repeatedly performing vulnerability scans  of infrastructures until the vulnerabilities become exhausted or die.<br />
The Inseccubus is the male counterpart of the Seccubus. While the Inseccubus draws his life energy from the assessor by repeatedly requiring him to (re-)analyse the same findings, the Seccubus get her energy from pleasing the assessor by reducing the number of findings by means of delta reporting.</p>
<p>The name Seccubus was chosen from a list of over 50 ideas sent after the contest was announced via the AutoNessus.com website, <a title="Hacker Public Radio" href="http://www.hackerpublicradio.com" target="_blank">Hacker Public Radio</a>, <a title="Paul dot com" href="http://www.pauldotcom.com" target="_blank">Paul dot com</a> and various other social media outlets like Twitter, Facebook and LinkedIn.</p>
<p>“I wanted a name that was completely different from AutoNessus” said Frank Breedijk, explaining why suggestions like AutoVAS and AutoVAMP where turned down. Other suggestions where turned down because their name was already taken on media like twitter (e.g. VAsak, Vulnerability Assessment Swiss Army Knife) or “simply because I didn’t like them” (e.g. Mick Douglass is awesome).</p>
<p>Now that the new name has been announced the “rebranding” will be complete before the end of the year. The website <a title="Seccubus website" href="http://www.seccubus.com" target="_blank">www.seccubus.com</a> is already live but still points to the AutoNessus.com site. Also Frank’s twitter account, <a title="@AutoNessus on Twitter" href="http://twitter.com/autonessus" target="_blank">@autonessus</a>, will be renamed to <a title="@seccubus on Twitter" href="http://twitter.com/seccubus" target="_blank">@seccubus</a> soon.</p>
<p>The response to the renaming contest was overwhelming and we would like to thank everybody who participated.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/11/seccubus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Assessment Agreement Outsourcing</title>
		<link>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/</link>
		<comments>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 11:55:35 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Agreement]]></category>
		<category><![CDATA[ITsec]]></category>
		<category><![CDATA[Madison Gurkha]]></category>
		<category><![CDATA[Ousourcing]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security asessment agreement outsourcing]]></category>
		<category><![CDATA[word]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=627</guid>
		<description><![CDATA[My work as security engineer for Schuberg Philis often requires me to deal with the following situation. A customer of our requires us to facilitate a security assessment or the infrastructure we manage on their behalf. More of often then not, the contractual agreements between assessor and client and client and service provider together with [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.schubergphilis.com"><img class="alignright size-full wp-image-630" title="Schuberg Philis logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/schuberg-philis-met-wit-ruimte.png" alt="Schuberg Philis logo" width="149" height="39" /></a>My work as security engineer for Schuberg Philis often requires me to deal with the following situation. A customer of our requires us to facilitate a security assessment or the infrastructure we manage on their behalf.</p>
<p><a href="http://www.itsec.nl"><img class="alignright size-full wp-image-628" title="ITSEC logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/ITSEC.jpg" alt="ITSEC logo" width="72" height="96" /></a>More of often then not, the contractual agreements between assessor and client and client and service provider together with a &#8220;third party waivers&#8221; or similar documents do not cover everything that the three parties want to commonly agree upon. After reviewing quite a number of these documents, I decided to write a template agreement (which can be downloaded below) for exactly this situation. This document is not a replacement for the agreement between the client and the assessor, but as an additional agreement between all three parties.</p>
<p><a title="Madison Gurkha webiste" href="http://www.madison-gurkha.com" target="_blank"><img class="alignright size-full wp-image-629" title="Madison Gurkha logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/madison-gurkha-logo.png" alt="Madison Gurkha logo" width="103" height="48" />Madison Gurkha</a> and <a title="ITsec website" href="http://www.itsec.nl" target="_blank">ITsec</a> have both reviewed and contributed to this agreement and we will use it in our future dealings.</p>
<p>The agreement  covers the following topics.</p>
<p><span id="more-627"></span>Scope of the assessment:</p>
<ul>
<li> What will be tested?</li>
<li>When will the test take place?</li>
<li>What kind of tests will be conducted?</li>
</ul>
<p>Contractual agreements:</p>
<ul>
<li>Does the assessor have a contract with the client?</li>
<li>Does the client have a contract with the service provider?</li>
</ul>
<p>Legal liability:</p>
<ul>
<li>Do both the client and the service provider waive prosecution of the assessor?</li>
</ul>
<p>Risks:</p>
<ul>
<li>Are all parties aware of and agree to the risks of a security assessment?</li>
</ul>
<p>Practical matters:</p>
<ul>
<li>The client requests the service provider to support the assessment</li>
<li>Who are the points of contact?</li>
<li>Where will the assessment take place?</li>
<li>How will the results be reported?</li>
</ul>
<p>Confidentiality:</p>
<ul>
<li>All parties agree to confidentiality</li>
</ul>
<p>The agreement template is released without any reservations of rights. This means you can use and adapt this agreement as you see fit, but completely at your own risk.</p>
<p>You can download the agreement here:</p>
<ul>
<li><a href="http://www.cupfighter.net/wp-content/uploads/2009/10/Security-Assesment-Agreement-Outsourcing-v1.0.doc">Security Assessment Agreement Outsourcing v1.0 (Word document)</a></li>
<li><a href="http://www.cupfighter.net/wp-content/uploads/2009/10/Security-Assesment-Agreement-Outsourcing-v1.0.pdf">Security Assessment Agreement Outsourcing v1.0 (PDF)</a></li>
</ul>
<p>I would like to thank the following people for their contribution:</p>
<ul>
<li>Madison Gurkha: Hans van de Looy and Arjan de Vet</li>
<li>ITsec: Tjerk Nan and Jan van Ek</li>
<li>Fox-It: Mark Koek</li>
<li>Arron Finnon (aka <a title="Arron Finnon onTwitter" href="http://twitter.com/f1nux" target="_blank">@f1nux</a>)</li>
<li>Colin McLean</li>
<li>Robert Ladyman</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Justice will feature Cupfighter.net author Frank Breedijk</title>
		<link>http://www.cupfighter.net/index.php/2009/09/security-justice-1st-bbq/</link>
		<comments>http://www.cupfighter.net/index.php/2009/09/security-justice-1st-bbq/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 07:42:02 +0000</pubDate>
		<dc:creator>Cupfighter</dc:creator>
				<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[AutoNessus]]></category>
		<category><![CDATA[Frank Breedijk]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Justice]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=523</guid>
		<description><![CDATA[This afternoon/evening, Security Justice will hold their 1st Annual International Podcast BBQ to celebrate US labor day. The BBQ will feature our Schuberg Philis colleague Frank Breedijk as blogger for cupfighter.net and author of AutoNessus At 15:00 EST (20:00 GMT) they will kick off by firing up the grill and opening the (probably not first) [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://securityjustice.com/"><img class="alignright" title="Security Justice logo" src="http://hak5radio.com/securityjustice.png" alt="Security Justice Logo" width="300" height="162" /></a></p>
<p>This afternoon/evening, Security Justice will hold their <a title="Security Justice first international Podcast BBQ" href="http://securityjustice.com/archives/76" target="_blank">1st Annual International Podcast BBQ</a> to celebrate US labor day.</p>
<p>The BBQ will feature our Schuberg Philis colleague Frank Breedijk as blogger for <a title="CupFighter.net" href="http://www.cupfighter.net" target="_self">cupfighter.net</a> and author of <a title="AutoNessus website" href="http://www.autonessus.com" target="_blank">AutoNessus<br />
</a></p>
<p>At 15:00 EST (20:00 GMT) they will kick off by firing up the grill and opening the (probably not first) beers. After this there will be a series of interviews:</p>
<p>16:00 EST (21:00 GMT)  – Our own Frank Breedijk (<a title="Frank Breedijk (@autonessus) on twitter" href="http://twitter.com/autonessus" target="_blank">@autonessus</a>)<br />
17:00 EST (22:00 GMT) – Chris John Riley (<a title="Chris John Riley's (@ChrisJohnRiley) twitter feed" href="http://twitter.com/ChrisJohnRiley" target="_blank">@ChrisJohnRiley</a>) and Robin Wood (<a title="Robin Woods's (@digininja) twitter feed" href="http://twitter.com/digininja" target="_blank">@digininja</a>)<br />
18:00 EST (23:00 GMT) – James Arlen (<a title="James Arlen (@myrcurial)'s twitter feed" href="http://twitter.com/myrcurial" target="_blank">@myrcurial</a>)<br />
19:00 EST (00:00 GMT) – Nick Owen (<a title="Nick Owen (@myrcurial)'s twitter feed" href="http://twitter.com/myrcurial" target="_blank">@wikidsystems</a>)<br />
20:00 EST (01:00 GMT) – Clean-up and the usual banter…</p>
<p>The podcast will be streamed live via <a title="Hak5Radio.com live stream" href="http://hak5radio.com/" target="_blank">hak5radio.com</a> and IRC: irc.freenode.net #securityjustice will be used for audience participation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/09/security-justice-1st-bbq/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PowerShell: Comparing Version numbers</title>
		<link>http://www.cupfighter.net/index.php/2009/06/powershell-comparing-version-numbers/</link>
		<comments>http://www.cupfighter.net/index.php/2009/06/powershell-comparing-version-numbers/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 07:33:49 +0000</pubDate>
		<dc:creator>Hans van Veen</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=209</guid>
		<description><![CDATA[Comparing version numbers can be tricky from time to time, before you know it you end up in auto-casting issues comparing strings to integers etc. The most common format of a version number in Windows is &#8220;Major. Minor. Build. Revision&#8221; where each individual item is a figure, but because of the separating dots PowerShell will treat [...]]]></description>
			<content:encoded><![CDATA[<p>Comparing version numbers can be tricky from time to time, before you know it you end up in auto-casting issues comparing strings to integers etc. The most common format of a version number in Windows is &#8220;Major. Minor. Build. Revision&#8221; where each individual item is a figure, but because of the separating dots PowerShell will treat each item as a string.</p>
<p>The .Net System.Version assembly offers a CompareTo method which can do the trick, as shown in the figure below.</p>
<p><img class="alignnone size-full wp-image-210" title="versions" src="http://www.cupfighter.net/wp-content/uploads/2009/06/versions.jpg" alt="versions" width="637" height="309" /></p>
<p>The CompareTo method will return 1, 0 or -1  depending whether the compare to version  is higher, equal or lower.</p>
<p><span style="color: #0000ff;">Thanks to Shay Levi (see the comment) I now know a better/faster method for comparing version numbers (thaks Shay). PowerShell has its own [vesion] type. This removes the need of loading the assembly and using New-Object. It still allows for using the CompareTo method and direct compare via -ge, -gt, etc.</span></p>
<p><span style="color: #0000ff;"><img class="alignnone size-full wp-image-227" title="versions-2" src="http://www.cupfighter.net/wp-content/uploads/2009/06/versions-2.jpg" alt="versions-2" width="624" height="321" /></span></p>
<p><span style="color: #0000ff;">The CompareTo method will distinguish between the 3 possibilities (&gt;, &lt; or =), but direct comparison might be sufficient in a script.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/06/powershell-comparing-version-numbers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Slowloris and Nkiller2 vs. the Cisco CSS load balancer</title>
		<link>http://www.cupfighter.net/index.php/2009/06/slowloris-css/</link>
		<comments>http://www.cupfighter.net/index.php/2009/06/slowloris-css/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 20:55:52 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Fun]]></category>
		<category><![CDATA[Load Balancer]]></category>
		<category><![CDATA[NKiller]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Slowloris]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[webserver]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=185</guid>
		<description><![CDATA[Today I spent most of my time analyzing the Slowloris and Nkiller2 denial of service (DoS) tools together with my colleague Gert Kremer. Slowloris (name after the slow moving primates is a httpd DoS tool written by RSnake of ha.ckers. It works by tying up the httpd worker processes by slowly sending more and more [...]]]></description>
			<content:encoded><![CDATA[<p>Today I spent most of my time analyzing the Slowloris and Nkiller2 denial of service (DoS) tools together with my colleague Gert Kremer.</p>
<p>Slowloris (name after the <a title="Wikipedia article" href="http://en.wikipedia.org/wiki/Slow_loris" target="_blank">slow moving primates</a> is a <a title="Original source of Slowloris" href="http://ha.ckers.org/slowloris/" target="_blank">httpd DoS tool written by RSnake of ha.ckers</a>. It works by tying up the httpd worker processes by slowly sending more and more headers of an httpd request.</p>
<p>Nkiller2 is a TCP/IP DoS attack tool which was published in <a title="Phrack magazine" href="http://www.phrack.org/issues.html?issue=66&amp;id=9#article" target="_blank">issue 66 of Phrack magazine</a>. It works by tying up httpd worker processes by requesting a file then stalling, mimicking the behavior of a client with full TCP/IP receive buffers.</p>
<p>Cisco CSS is a <a title="Cisco CSS" href="http://www.cisco.com/en/US/products/hw/contnetw/ps792/" target="_self">load balancer produced by Cisco</a>.</p>
<p>In nearly all of the infrastructures built by my employer Schuberg Philis, the web servers are located behind a load balancer. In most cases a Cisco CSS. Because some of our customers were worried, I set out together with my colleague Gert Kremer to see if having a CSS load balancer in front of the web server provides any protection.</p>
<p><strong>Slowloris</strong></p>
<p>First we just had to try and find out what Slowloris did with an unprotected Apache server. The first video shows what happens when you run slowloris against a webserver. The window on the top left shows the number of apache processes, the top right window shows the scoreboard. This shows what the http processes are actually doing. The bottom window shows the slowloris output.</p>
<p><strong>Slowloris vs Apache (No load balancer)</strong><br />
<p><a href="http://www.cupfighter.net/index.php/2009/06/slowloris-css/"><em>Click here to view the embedded video.</em></a></p></p>
<p>When slowloris is using 100 sockets, you can see 100 httpd workers in state “R”, meaning it is reading requests. The same is the case when running with 200 and 250 sockets. When running with 300 sockets the apache worker processes pool is exhausted and the web server can no longer service requests.</p>
<p><strong>Slowloris vs Apache behind a Cisco CSS load balancer</strong><br />
<p><a href="http://www.cupfighter.net/index.php/2009/06/slowloris-css/"><em>Click here to view the embedded video.</em></a></p></p>
<p>Slowloris is running against the webserver with 3000 sockets (should be more then enough). As you can see on the top two windows the load balancer does not forward any of the incomplete requests to the webserver. We have stress tested the loadbancer up to 10,000 sockets and it had no effect on the loadbancer.</p>
<p><strong>NKiller</strong></p>
<p><strong>Nkiller vs Apache (No load balancer)<br />
</strong><p><a href="http://www.cupfighter.net/index.php/2009/06/slowloris-css/"><em>Click here to view the embedded video.</em></a></p></p>
<p>In the video we see for windows. Top left and right show the number of apache processes and the apache dashboard. The middle window displays the NKiller output and the bottom window TCPdump.</p>
<p>When NKiller starts we see the it exhausts the httpd workers processes by putting them in a state where they are hanging while writing their reply back to the client.<br />
<strong>Nkiller vs Apache behind a CSS load balancer<br />
</strong><p><a href="http://www.cupfighter.net/index.php/2009/06/slowloris-css/"><em>Click here to view the embedded video.</em></a></p><strong><br />
</strong><em></em></p>
<p>When NKiller was used against a server protected by a Cisco CSS load balancer the packets received from the load balancer do not match the expections of the Nkiller tool and the tool crashed producing a segmentation fault.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/06/slowloris-css/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>PowerShell: Controlling Cmdlet parameters</title>
		<link>http://www.cupfighter.net/index.php/2009/06/powershell-controlling-cmdlet-parameters/</link>
		<comments>http://www.cupfighter.net/index.php/2009/06/powershell-controlling-cmdlet-parameters/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 13:52:19 +0000</pubDate>
		<dc:creator>Hans van Veen</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[cmdlet]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=167</guid>
		<description><![CDATA[PowerShell allows for inline parameter control for some of its cmdlet parameters. Based upon commandline and/or inputfile content you might want to turm some of the cmdlet parameters on or off. For example: scripts manipulating files will often use the Get-ChildItem cmdlet in combination with the -recurse parameter, but not allways the subfolder files are required. Instead [...]]]></description>
			<content:encoded><![CDATA[<p>PowerShell allows for inline parameter control for some of its cmdlet parameters. Based upon commandline and/or inputfile content you might want to turm some of the cmdlet parameters on or off.</p>
<p>For example: scripts manipulating files will often use the Get-ChildItem cmdlet in combination with the -recurse parameter, but not allways the subfolder files are required. Instead off having multiple Get-ChildItem commandlines (each with their own set of parameters) a single line might be possible.</p>
<p>The following examples use the Get-ChildItem cmdlet to show what I mean.</p>
<p>The command in figure below will display all *.tmp files in the current folder and its subfolders.</p>
<p><img class="alignnone size-full wp-image-170" title="image11" src="http://www.cupfighter.net/wp-content/uploads/2009/06/image11.bmp" alt="Get-ChildItem without parameter control" width="552" height="226" /></p>
<p>By extending -recurse with :$false recursive lookup will be turned off.</p>
<p><img class="alignnone size-full wp-image-173" title="image2" src="http://www.cupfighter.net/wp-content/uploads/2009/06/image2.bmp" alt="Get-ChildItem with recures lookup turned off" width="557" height="213" /></p>
<p>On the otherhand, replacing $false with $true will turn recursive lookup on again.</p>
<p>So using a boolean variable we can turn recursive lookup on or off from within the script (-recurse:$RecurseOnOff). And of course this method also works for other parameters.</p>
<p><img class="alignnone size-full wp-image-174" title="image3" src="http://www.cupfighter.net/wp-content/uploads/2009/06/image3.bmp" alt="Get-ChildItem with multiple controls" width="556" height="238" /></p>
<p>And it does get stranger&#8230;.. in some occasions you can also reverse the default action of a parameter. Hence the following figure.</p>
<p><img class="alignnone size-full wp-image-175" title="image4" src="http://www.cupfighter.net/wp-content/uploads/2009/06/image4.bmp" alt="Reverse parameter action" width="560" height="195" /></p>
<p>The 1st command will show all files with exception of the *.tmp files. By appending :$false to -exclude, we turn -exclude into -include as demonstrated by the 2nd command.</p>
<p>This form of parameter manipulation offers a scala of possibilities. Using script parameters to control cmdlet behaviour can both decrease script size and complexity.</p>
<p>Have fun experimenting with this little trick</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/06/powershell-controlling-cmdlet-parameters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Schuberg Philis hosts CAcert Assurer Training Event Amsterdam</title>
		<link>http://www.cupfighter.net/index.php/2009/06/schuberg-philis-hosts-cacert-assurer-training-event-amsterdam/</link>
		<comments>http://www.cupfighter.net/index.php/2009/06/schuberg-philis-hosts-cacert-assurer-training-event-amsterdam/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 16:11:14 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[CaCert]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Event]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=118</guid>
		<description><![CDATA[From: http://blog.cacert.org/2009/05/388.html Much has happened during the past year. A list of up till now mostly “orally transmitted” rules have been cast in policies. New procedures (e.g. the Assurer Challenge) and obligations (e.g. in the CAcert Community Agreement) have been decided. The Assurer Training Events try to bring all this informations to “the people”: - [...]]]></description>
			<content:encoded><![CDATA[<p>From: <a href="http://blog.cacert.org/2009/05/388.html" target="_blank">http://blog.cacert.org/2009/05/388.html</a></p>
<p>Much has happened during the past year. A list of up till now mostly “orally transmitted” rules have been cast in policies. New procedures (e.g. the Assurer Challenge) and obligations (e.g. in the CAcert Community Agreement) have been decided. The Assurer Training Events try to bring all this informations to “the people”:<br />
- To what, does the CCA protect every CAcert-Community-Member and as such also you?<br />
- Can you recount the 5 statements of the “Purpose of Assurance”?<br />
- Can you at least recount 10 security marks of the Dutch passport/Identity card?<br />
Answers to these and following questions are given at the Assurer Training Events (ATE’s).<br />
Participation in the events is free, Contributions are however appreciated.Amsterdam:<br />
—————<br />
The <a href="http://wiki.cacert.org/wiki/Events/20090615ATE-Amsterdam" target="_blank">ATE-Amsterdam</a> takes place on:<br />
- Monday, June 15th from 20:00 till 22:00<br />
- at <a href="http://www.schubergphilis.com/contact/" target="_blank">SCHUBERG PHILIS</a><br />
Star Parc<br />
Boeing Avenue 271<br />
1119 PD Schiphol-Rijk<br />
—————<br />
The <a href="http://wiki.cacert.org/wiki/Events/20090620ATE-Eemnes" target="_blank">ATE-Eemnes</a> takes place on:<br />
- Saturday, June 20th from 10:30 till 12:30, followed by normal assurances till 15:30<br />
- in <a href="http://www.dehilt.nl/" target="_blank">de Hilt</a><br />
Hasselaarlaan 1c<br />
3755 AV Eemnes<br />
The Event-Team is already excited about your participation.<br />
<a href="mailto:events@cacert.org?subject=ATE-attend-Amsterdam&amp;body=I%20will%20attend:%20Amsterdam" target="_blank">Registration ATE-Amsterdam</a><br />
<a href="mailto:events@cacert.org?subject=ATE-attend-Eemnes&amp;body=I%20will%20attend:%20Eemnes" target="_blank">Registration ATE-Eemnes</a><br />
contact: events@cacert.org</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/06/schuberg-philis-hosts-cacert-assurer-training-event-amsterdam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Christ; is it that late already !? :-)</title>
		<link>http://www.cupfighter.net/index.php/2009/06/christ-is-it-that-late-already/</link>
		<comments>http://www.cupfighter.net/index.php/2009/06/christ-is-it-that-late-already/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 00:17:33 +0000</pubDate>
		<dc:creator>Dennis Silva</dc:creator>
				<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[DTAP]]></category>
		<category><![CDATA[RFP]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=50</guid>
		<description><![CDATA[Working on a technical proposal for an RFP from a large financial instituation.]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re working our butts off on a technical proposal for an RFP from a large financial institution. We already have them in our data center, and they are asking us to do more&#8230; sure why not!?</p>
<p>Our proposal has to be delivered to them before the weekend.  But we still have several hours of quality time ahead of us. <img src='http://www.cupfighter.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>I&#8217;d love to share all the details, but erhm, since this is all hush-hush stuff I can&#8217;t.</p>
<p>But to give a general idea: DTAP hosting platform for enterprise application, internal use only, user population (&gt;5,000 employees) located around the globe, highly confidential and secure, twin versus dual data center setup located in Amsterdam area, partially virtualized in network and server layers, internet as well as Corporate connectivity, authenticated against corporate user repositories, Windows based, maximum data loss of 1hr (RPO), 10TByte data, IDS/IPS, the lot.</p>
<p>And then suddenly find myself working &gt; 2am. Geeh. Time to take a nap and kick ass again tomorrow.</p>
<p>Grtz,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/06/christ-is-it-that-late-already/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

