Blog
Keeping compliant with the myriad of regulations that currently abound is one of the major challenges facing the enterprise and its leaders today.

Tevora Blog

  • Archives

Tevora has offices at the following locations:

Southern California: (Headquarters)

One Spectrum Pointe Drive, Suite 200
Lake Forest, California 92630.
Tel: 949.250.3290
Fax: 949.250.9993
Email: info@tevora.com
Driving directions

Northern California

7485 Rush River Drive, Suite 710
Sacramento, CA. 95831
Tel: (888) 4-TEVORA
Fax: 925.369.0307
Email: norcal@tevora.com
Driving directions

International Locations:

Tevora South America
Alameda Jau
1742 / 8 Andar
CJ 81 - Sao Paulo - Brasil
Tel:+55 11 3063-1853
www.tevora.com.br

How to Parse Firewall Configs with Nipper.

Thursday, 12 February 2009 by

Who
said analyzing firewalls and network devices was something tedious and cumbersome?
Well your problems are over: Introducing Nipper, the network device configuration
parser. I have found that nipper aids tremendously in helping audit and analyze network
devices during our assessments, reducing tremendously the time it takes to analyze
a network device configuration file. Nipper offers comprehensive and detailed reports
which anyone can understand. Nipper helps security administrators to check their network
devices for known vulnerabilities and configuration flaws, and attending the need
for industry standards and compliance controls such as PCI, HIPAA, ISO and BITS, and
the best part of using Nipper is the fact that this tool is absolutely free.

(continue reading…)

10 steps to harden Windows Server 2008

Tuesday, 2 December 2008 by

(continue reading…)

Security Event Log Forwarding on Windows 2008 servers

Monday, 1 December 2008 by

The use of a centralized log server has often been highlighted in many of today’s security
best practices. The constant need to collect, retain and protect these sensitive security
event log files sometimes overwhelm security and systems administrators, especially
in large corporate environments. When properly configured, security event logs are
used to track user activity and access on specific systems or objects, and is a key
element when tying to piece up the chain of events leading to a security incident.
Many security administrators might know how cumbersome it is to manage such security
event log files, and sometimes seek third party vendors to help them manage their
security log files. The truth is that
many of these problems can be solved using native features of your server operating
system.

(continue reading…)

How to Secure your DNS Server

Friday, 7 November 2008 by

While conducting most of our penetration
tests, we often find a very common DNS vulnerability. In order for us to understand
this vulnerability, we first need to know what a DNS server is. DNS servers are responsible
for name resolution, convertingName Addressesto IP addresses. It is true
that a company’s DNS server contains records of a variety of objects such as hosts,
server and services. In order to synchronize and update, DNS servers transfer
their records to other requesting DNS servers. DNS servers should only transfer zone
information between authorized servers. This
is where the problem resides; sometimes these servers are configured to allow “anonymous”
transfers, meaning that anyone can request a zone transfer without proper authentication
or authorization. By not restricting Anonymous Zone Transfers, companies sometimes
jeopardize the overall security of their infrastructure.

(continue reading…)

SPAM: You Have Mail!

Friday, 7 November 2008 by

Trick or Treat: What lurks beneath a Public Access Point?

Friday, 17 October 2008 by

< ?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" />




(continue reading…)

Red November: Understanding the Red Flag Rule.

Friday, 3 October 2008 by

Red
November
:
Understanding the Red Flag Rule.

(continue reading…)