Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 25 guests and 3 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
EH-Net
News Items and General Discussion About EH-Net
Wonderful update
EH-Net
May 25, 2013, 08:19:50 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
News Items and General Discussion About EH-Net
(Moderator:
don
) >
Wonderful update
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Wonderful update (Read 4238 times)
0 Members and 1 Guest are viewing this topic.
3xban
Hero Member
Offline
Posts: 608
Wonderful update
«
on:
October 24, 2010, 09:54:03 AM »
So last time I posted I had started a new consulting gig. Well the honeymoon ended and I realized it was going to be a dead end. Spent more time worrying about billable hours than actually concentrating on work and study topics. Luckily a job posting came up from a recruiter friend of mine. The job was for a Network Security Admin. After reviewing the position I thought to myself, wow I actually have most of these skills for a change. And figured what the hell!
So the recruiter helped me get my resume much more beefy looking so it actually reflected my abilities better. Next thing I know they bring me in for the first interview. Cool part was they accommodated my work schedule so I didn't need to take any time off. Infrastructure manager liked me and I got the call for a second right away. Again they accommodated my schedule. The recruiter was also feeling very positive about it. After another week or 2 I get the offer. As a bonus it was more than I was asking for. I didn't want to be too greedy with my first official Info Sec job.
So here I am 2 weeks into the job, well 3 but again they accommodated me by allowing me to take time off for a pre-scheduled wedding trip for a good friend of mine. My current duties, for now, revolve around Patch Management and Anti-virus management. Might seem like a glorified Sys Admin but for one very little if any desktop work, and two, lots of room to grow the duty list. The team is cool as well and all pretty knowledgeable.
After talking with a friend of mine, he told me I was heading into Information Assurance. That led me to GIAC and GCWN. So my current path will be to obtain GCWN. New boss said he will approve SANS SEC505 for next year's budget. Its nice having a boss that says "go pick a training course." So for now its back on my MCITP track, then GCWN. After that I may go back to CCNA. Eventually I would like to pick up the CISSP. They seem to be very supportive for education so why not take advantage?
I would welcome any advice from anyone in this area of expertise. I think my biggest hurdle will be getting a good patch management policy and procedure in place. We have a virtual lab for testing, but I don't think they use it very often.
Sorry about the length of this
Logged
Certs: GCWN
(@)Dewser
hayabusa
Hero Member
Offline
Posts: 1633
Re: Wonderful update
«
Reply #1 on:
October 24, 2010, 04:39:36 PM »
Well, congrats to you, Triban, for getting into a position you'll hopefully enjoy. Sometimes, these things come out of nowhere, but they're sure worth it, when they do.
Good luck!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
3xban
Hero Member
Offline
Posts: 608
Re: Wonderful update
«
Reply #2 on:
October 25, 2010, 09:23:30 AM »
Thanks man! Looking forward to the adventure.
Logged
Certs: GCWN
(@)Dewser
mallaigh
Jr. Member
Offline
Posts: 65
Re: Wonderful update
«
Reply #3 on:
October 25, 2010, 12:12:07 PM »
Congrats on the position and best of luck.
Based on the alphabet soup of MS certs you named, I'm guessing you are working in a predominately (if not all) Windows environment. Windows Server Update Services (WSUS) is an awesome server snap in for permitting and monitoring MS Update. Check this link for more details (but I will give a basic breakdown):
http://technet.microsoft.com/en-us/wsus/default.aspx
Install WSUS on a server (I find an LDAP or AV server to work pretty well). You then write some group policies that control when MS Updates are installed and that they get the approval from the WSUS update server (LDAP is awesome for this if you have it). Login to the WSUS server and approve updates, and the workstations can download and install the updates at the specified time. You can also assign groups if you are worried about certain updates breaking peoples computers. You can monitor which workstations have installed the updates via WSUS as well.
«
Last Edit: October 25, 2010, 12:14:14 PM by mallaigh
»
Logged
3xban
Hero Member
Offline
Posts: 608
Re: Wonderful update
«
Reply #4 on:
October 25, 2010, 09:31:31 PM »
Thanks Mallaigh. I've worked with WSUS for a bit. Found it to be useful half the time
Mostly found that if there was an update to the updater, it would cause problems. So one of the solutions we are implementing is a method to force updates using a management appliance.
Unfortunately the previous admins have left the AD in shambles, so I recommended we straighten that out before we worry about why some machines don't always update. My idea is, can't patch it if we don't know if it really exists.
I am looking forward to our new patch management appliance. I'm hoping it works a bit faster at discovery than a GFI scan/assessment.
Logged
Certs: GCWN
(@)Dewser
impelse
Hero Member
Offline
Posts: 565
Re: Wonderful update
«
Reply #5 on:
October 25, 2010, 10:56:41 PM »
Congrats
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
mallaigh
Jr. Member
Offline
Posts: 65
Re: Wonderful update
«
Reply #6 on:
October 26, 2010, 01:25:35 PM »
Quote from: Triban on October 25, 2010, 09:31:31 PM
Thanks Mallaigh. I've worked with WSUS for a bit. Found it to be useful half the time
Mostly found that if there was an update to the updater, it would cause problems. So one of the solutions we are implementing is a method to force updates using a management appliance.
Unfortunately the previous admins have left the AD in shambles, so I recommended we straighten that out before we worry about why some machines don't always update. My idea is, can't patch it if we don't know if it really exists.
I am looking forward to our new patch management appliance. I'm hoping it works a bit faster at discovery than a GFI scan/assessment.
You're welcome Triban. Sometimes I wish I had AD for my network, other times I'm glad I don't (I run a mixed environment). Yeah, WSUS isn't perfect but it certainly helps, although I haven't had the chance to fully roll it out due to other projects (rolling out the group polices for WSUS is certainly something I wish I had AD for).
Logged
3xban
Hero Member
Offline
Posts: 608
Re: Wonderful update
«
Reply #7 on:
October 26, 2010, 07:27:49 PM »
honestly, WSUS isn't much to roll-out. Install on server then you just configure the options for what software to download (Office, Windows, and other Microsoft Apps). Then configure synchronization times, set your default listening ports. It usually uses 443 and/or 80. Unless it is on SBS. After that you control the clients via GPO. And even then it only tells them what to do. They look at WSUS and either download, download and install or schedule install. All controlled through GPO. WSUS just gathers the updates so you don't have all your Windows machines trying to update at once. You can configure auto-approve rules for critical and security and even designate what groups of computers you want. But if the client systems are not updated with their Automatic Update engine, they will not communicate properly. Luckily Microsoft has a few diagnostic tools to assist in troubleshooting.
Once it is in and running, it is pretty cut and dry. But right now organization is key. They have little documentation and what they do have it needs severe updating. So first things first, straighten everything out! you can't protect it if you don't know it exists.
Logged
Certs: GCWN
(@)Dewser
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.