<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>lensblog &#187; Security</title>
	<atom:link href="http://blog.lensbox.za.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.lensbox.za.net</link>
	<description>a geek’s mark on the wired world while exploring media and gaming metaverses</description>
	<lastBuildDate>Wed, 11 Aug 2010 20:46:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>So much to do, so little time to do it in&#8230;</title>
		<link>http://blog.lensbox.za.net/2008/02/25/so-much-to-do-so-little-time-to-do-it-in/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2008/02/25/so-much-to-do-so-little-time-to-do-it-in/#comments</comments>
		<pubDate>Mon, 25 Feb 2008 19:31:53 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Design and Multimedia]]></category>
		<category><![CDATA[Freelance]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Online Communities]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[World of Warcraft]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/2008/02/25/so-much-to-do-so-little-time-to-do-it-in/</guid>
		<description><![CDATA[Or so it seems, most days&#8230; The last few days/weeks have been busy for most people. For me, they&#8217;ve been filled with work, social events, issues at home and a general need for downtime in which it&#8217;s either just me, my PC and some uplifting music or my bed and a good book. Let&#8217;s see, [...]]]></description>
			<content:encoded><![CDATA[<p>Or so it seems, most days&#8230;</p>
<p>The last few days/weeks have been busy for most people. For me, they&#8217;ve been filled with work, social events, issues at home and a general need for downtime in which it&#8217;s either just me, my PC and some uplifting music or my bed and a good book.</p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_018.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_018_thumb.jpg" alt="My desk at work..." align="right" border="0" height="184" hspace="15" vspace="15" width="244" /></a>Let&#8217;s see, where to begin&#8230;</p>
<p>May as well begin with work as it is where I seem to spend most of my time these days!</p>
<p>I love my job. People think I&#8217;m odd, but I look forward to going to work, to see what new challenges await me. And they often do!</p>
<p>You see, I&#8217;m a relative newcomer to the security industry&#8230; having been primarily involved with systems administration, web development and design, ANSI development and some minor DBA work before this&#8230; And when I joined, I was initially there to look after one of our anti-virus products more than anything else. Except, me being me, I had to go and stick my nose into other things and jump feet first into the firewall tickets and try my hand at log analysis&#8230;</p>
<p>Now, I spend most of my time abusing my workstation&#8217;s processor and memory, building pivot tables, running SQL queries and pulling reports from client log files, trying to make head or tale of what I see before me&#8230; is this a botnet I see before me? A portscan perhaps?</p>
<p>Management have also gotten me involved in some of the research and development projects, which makes for some interesting times as I sit and research topics that I may have glossed over before or never even thought of.</p>
<p>I work with a good bunch of people as well. On the AV side of things, I have Reshan to lean on when my own knowledge of F-Secure fails me. On the Checkpoint side of things there are many talented and knowledgeable people, like Matt, our technical manager and primary Checkpoint trainer, Gary, Clive, Marcel and Teper. All of these guys have helped me when I&#8217;ve gotten stuck with an issue and have been patient enough to explain it to me without treating me like an idiot.</p>
<p>We all work hard. And we play hard as well; Matt provides music during the day and we often take breaks for coffee or cooldrinks, go stand in the bar area and play a round or two of pool, throw some darts or discuss World of Warcraft, something many of us play, though Marcel and Reshan are supposedly rehabilitated&#8230; We&#8217;re trying to rope them back in though. Those breaks afford us a well-deserved mental break from the stresses of concentrating on some rather intricate configurations and mystifying security incidents.</p>
<p>Between work and play though, we end up working long hours, seeing to the demands of clients&#8230; I think most nights the tech team leave work well after 6:30pm, if not later.</p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/F1000024.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/F1000024_thumb.jpg" alt="Awakened Guardians : Gauteng Chapter" align="right" border="0" height="165" hspace="15" vspace="15" width="244" /></a>For folks like Matt, Gary and myself, it&#8217;s then time to drive home and log into World of Warcraft, to our guild, &#8220;Thunderwalkers&#8221; on Dath&#8217;Remar, US Oceanic. That keeps up busy until the next morning when our work cycle begins anew.</p>
<p>Beside &#8220;Thunderwalkers&#8221; though, I still belong to &#8220;Awakened Guardians&#8221; on US Stormrage, where I have most of my characters and play a role in guild management by running their website and forum which I host under this domain.</p>
<p>We&#8217;ve gotten together a few times offline, as the photo to the right shows. Interesting to put faces to names and voices&#8230;</p>
<p>Aside from my usual routine of work and play though, I also have the dubious honour of living with 4 women who keep me on my toes. Sharlene and Cari have stayed with me before, as two of the original tenants that moved into the commune shortly after I did. The two newcomers, Renee and Tarryn, have brought their own chaos to the party.</p>
<p>Some folks joke with me that I must be a very lucky man to live with 4 women&#8230; My response usually surprises them&#8230; It&#8217;s certainly not the ideal many would think, as there have been some spectacular blowups and unspoken issues&#8230; but for the most part it&#8217;s peaceful and it&#8217;s company&#8230; Something I&#8217;d gotten used to  since I moved out of my bachelor flat and moved in with other people in a sharing arrangement. It&#8217;s taken some getting used to, but for those that cannot afford to get their own house just yet or cannot stand the idea of being alone 24/7, it&#8217;s not that bad.</p>
<p>It&#8217;s actually quite nice to come home, sit with someone and have a cup of tea or coffee, hear about their day, relate your own experiences, etc. This is great most of the time, but I&#8217;ll admit there are some days when I am feeling less than sociable and all I want to do is make myself some supper and go lock myself in my room, put on my headphones and forget about the world outside.</p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/F1050026.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/F1050026_thumb.jpg" alt="Sheelagh and Andrew" align="right" border="0" height="165" hspace="15" vspace="15" width="244" /></a> Something I need to do again is get back into my photography. I&#8217;m still working through a backlog of photos for Sheelagh&#8217;s wedding, my company&#8217;s last year-end function and several other spools I&#8217;ve had lying around and finally had developed.</p>
<p>And I&#8217;ve found some new subjects to photograph as well&#8230; just need to make the time to go and take some proper shots that aren&#8217;t shot with my little HTC P4350 smartphone&#8230;</p>
<p>The shots below were taken one evening when Rob was up from Cape Town and we&#8217;d gone to see Alien vs Predator 2&#8230; we stood outside the movie theatre area in Brightwater Commons and were treated to this colourful little display, though the accompanying music was badly distorted through very tinny and bass-intolerant speakers.</p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_003.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_003_thumb.jpg" style="border-width: 0px" alt="IMAGE_003" border="0" height="184" width="244" /></a> <a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_011.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/IMAGE_011_thumb.jpg" style="border-width: 0px" alt="IMAGE_011" border="0" height="184" width="244" /></a></p>
<p>Makes me realise that I really need to get back into things again&#8230; I haven&#8217;t managed to beat shots like these and some of them are well over 3-4 years old now.</p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Inferno_by_medraught.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Inferno_by_medraught_thumb.jpg" style="border-width: 0px" alt="Inferno_by_medraught" border="0" height="244" width="244" /></a> <a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Silhouettes___Traffic_Sign_by_medraught.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Silhouettes___Traffic_Sign_by_medraught_thumb.jpg" style="border-width: 0px" alt="Silhouettes___Traffic_Sign_by_medraught" border="0" height="244" width="167" /></a></p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Sea_of_Stars_by_medraught.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Sea_of_Stars_by_medraught_thumb.jpg" style="border-width: 0px" alt="Sea_of_Stars_by_medraught" border="0" height="150" width="244" /></a> <a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Falling.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Falling_thumb.jpg" style="border-width: 0px" alt="Falling" border="0" height="162" width="244" /></a></p>
<p><a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Down_at_Street_Level.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Down_at_Street_Level_thumb.jpg" style="border-width: 0px" alt="Down_at_Street_Level" border="0" height="116" width="244" /></a> <a href="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Lucky_Strike_2_by_medraught.jpg"><img src="http://www.lensbox.za.net/journalimages/Somuchtodosolittletimetodoitin_12DBC/Lucky_Strike_2_by_medraught_thumb.jpg" style="border-width: 0px" alt="Lucky_Strike_2_by_medraught" border="0" height="111" width="244" /></a></p>
<p>Time to get back into the habit, I think&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2008/02/25/so-much-to-do-so-little-time-to-do-it-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Late Night Geek Blues</title>
		<link>http://blog.lensbox.za.net/2008/01/15/late-night-geek-blues/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2008/01/15/late-night-geek-blues/#comments</comments>
		<pubDate>Tue, 15 Jan 2008 09:40:24 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Anime and Manga]]></category>
		<category><![CDATA[Design and Multimedia]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Online Communities]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[World of Warcraft]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/2008/01/15/late-night-geek-blues/</guid>
		<description><![CDATA[Last few nights have been somewhat busy for me&#8230; and I think the lack of sleep is catching up to me today. For anyone that works in the IT industry, the old saying, “no rest for the wicked” could not be truer&#8230; You work your allotted time at work and perhaps a little more than [...]]]></description>
			<content:encoded><![CDATA[<p>Last few nights have been somewhat busy for me&#8230; and I think the lack of sleep is catching up to me today.</p>
<p>For anyone that works in the IT industry, the old saying, “no rest for the wicked” could not be truer&#8230; You work your allotted time at work and perhaps a little more than necessary (I know I do, as does Rob and Rozz) and then go home and generally do one of two things&#8230; either sit down in front of a PC again to play games or surf the ‘net or try and switch off in front of the TV or some other distraction.</p>
<p>Usually I watch some anime or whatever is playing on the TV for a bit, research a little and maybe update this blog a bit, browse deviantART for new wallpapers or inspiration, then try get an early (or earlier than usual) night, knowing the next morning I need to be up before most people, a) to avoid traffic and b) to get a head start on the day’s tasks.</p>
<p>Lately though, I’ve been doing upgrades on my forums, from <strong>phpBB</strong> version 2.0.22 to 3.01, fighting with South African latency while uploading a million and one small files to my internationally hosted server, creating backups (just in case, you know!) and trying to puzzle through the documentation to see where I am going wrong&#8230;</p>
<p>Or building an old server up into a general workstation for the girls at home to use, as Tarryn is starting her new job soon and will lose her old laptop, and frankly, I’m a little wary of letting anyone other than a work colleague, that I trust, use mine. Last night I managed to get a majority of the work done on the server, but it was painstakingly slow-going as it’s an old Pentium III, with 512MB RAM and two SCSi 20GB drives&#8230; Windows XP runs on it&#8230; or should I say, it ‘jogs’.</p>
<p>I’ve loaded all the chat programs they could want on there&#8230; <strong>MSN</strong>, <strong>GoogleTalk</strong>, <strong>Yahoo</strong>&#8230; and most importantly, antivirus. <strong>AVG</strong> is perhaps not the best, but hell, it works&#8230; And I made each of them their own limited privilege profile so they don’t have to stress about anyone else reading their mail from the dating sites they’re so fond of frequenting.</p>
<p>Need to sit down with Tarryn as well, sometime, and teach her <strong>Adobe Photoshop</strong>. Think the poor girl has jumped into her new job without really knowing what is expected of her&#8230; if she’s going to be doing design work, I think she may be in over her head&#8230;</p>
<p>Other than that, now that my one set of forums are upgraded, I need to tackle the other one. And then figure out how to integrate all the other php packages  such as <strong>phpRaid</strong>, etc back into the new boards&#8230;</p>
<p>When I will get a chance to play again, I don’t know&#8230; we’ll see what happens end of the month. By then things should have settled a bit more. Right now, all I seem to be able to manage is getting home, feeding myself, showering then collapsing onto my bed, watching a few episodes of anime (recently finished &#8220;<strong>Eureka Seven</strong>&#8221; and &#8220;<strong>Fate / Stay Night</strong>&#8221; and about half way through &#8220;<strong>Ergo Proxy</strong>&#8220;) then drifting off into an uneasy sleep, only to wake up a few hours later, feeling like a truck has hit me&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2008/01/15/late-night-geek-blues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2008</title>
		<link>http://blog.lensbox.za.net/2008/01/02/2008/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2008/01/02/2008/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 09:59:07 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/2008/01/02/2008/</guid>
		<description><![CDATA[A new year, one which, I think, many of us are hoping will be an improvement on last year&#8230; 2007 was a tough year for many. Actually, in hindsight, it seems for many of us, each preceding year seems to feel that way until we&#8217;re done with the next year and looking back, wonder to ourselves how [...]]]></description>
			<content:encoded><![CDATA[<p>A new year, one which, I think, many of us are hoping will be an improvement on last year&#8230;</p>
<p>2007 was a tough year for many. Actually, in hindsight, it seems for many of us, each preceding year seems to feel that way until we&#8217;re done with the next year and looking back, wonder to ourselves how we managed to live through yet another year of utter chaos.</p>
<p>I won&#8217;t harp on about the aspects of 2007 that upset me. What&#8217;s done is done, and I&#8217;m done with living with regrets and what-if&#8217;s. Tempus fugit&#8230; time flies&#8230; time moves forward inexorably.</p>
<p>A lot of good came from that time of turmoil though. A new job. New friends. New opportunities and knowledge gained.</p>
<p>This year, I intend to expand on that. To grow, both socially and mentally. To accelerate and move forward once more and leave behind the stagnation of the past.</p>
<p>Looking at my journal today, the quote at the bottom of the page reads <em>&#8220;My father gave me the greatest gift anyone could give another person; he believed in me.&#8221; &#8211; Jim Valvano.</em></p>
<p>My father has always hoped and prayed that I would excel and do well in my chosen field of work. From my college days and beyond, he&#8217;s always encouraged me to do better, to push myself, work hard&#8230; &#8220;Someday, Tim, someone will take notice of you and you will be rewarded for your efforts&#8230;&#8221;</p>
<p>Sadly, some of my past employers have not lived up to that expectation. And perhaps I hoped for too much from them.</p>
<p>For now, I am content. For the first time in 7 years, I feel like I have a career again, instead of just a job. I have a support base, people of knowledge and experience I can turn to when I get stuck, people willing to teach instead of criticising me regarding the gaps in my knowledge.</p>
<p>I hope your dreams and hopes for 2008 are fulfilled. I know I will certainly be working to fulfill mine. Perhaps we&#8217;ll meet somewhere along the way and work together.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2008/01/02/2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Traffic ordeals and standing in for colleagues&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/10/30/traffic-ordeals-and-standing-in-for-colleagues/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/10/30/traffic-ordeals-and-standing-in-for-colleagues/#comments</comments>
		<pubDate>Tue, 30 Oct 2007 14:04:58 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/2007/10/30/traffic-ordeals-and-standing-in-for-colleagues/</guid>
		<description><![CDATA[Funny how things work out&#8230; You get up in the mornings, get ready for the day, get started along what you think will be a series of events for the day, then get sideswiped by real life. I was supposed to go on MailMarshall training today in Sandton&#8230; got up early to try and miss [...]]]></description>
			<content:encoded><![CDATA[<p>Funny how things work out&#8230;</p>
<p>You get up in the mornings, get ready for the day, get started along what you think will be a series of events for the day, then get sideswiped by real life.</p>
<p>I was supposed to go on MailMarshall training today in Sandton&#8230; got up early to try and miss the traffic on the freeway, though it took me about 30 minutes to get onto it in any case&#8230; busy listening to my music on my headset&#8230; then I get an SMS alert. Look around for Metro Police goonsquad&#8230; no-one nearby, so let&#8217;s check the phone&#8230;</p>
<p>The SMS is from my technical director. A change in plans. My colleague that was supposed to stand in for another colleague at one of our onsite posts in the CBD, has called in, with what we eventually found out was kidney stones&#8230; poor bugger. I know how he feels, as I was in the same position this time last year.</p>
<p><img src="http://www.lensbox.za.net/journalimages/deviantart/downatstreetlevel.jpg" align="right" border="5" height="139" hspace="15" vspace="5" width="300" />So I now need to go through to town&#8230; if anyone knows Johannesburg well, you know that trying to get anywhere in traffic after 7:30am is a nightmare&#8230; William Nicol is a gauntlet, Jan Smuts is worse&#8230;</p>
<p>At least I remembered the route. The last time I had to do this, it&#8217;d had been my first time venturing into the CBD and if I hadn&#8217;t had Rozz (who works in the CBD) to follow, I would have gotten hopelessly lost.</p>
<p>The day itself has been pretty quiet. Ran into some old colleagues and friends from my time as a contractor at SecureData so I had someone to chat to. Other than that, just been answering the phone and checking mail for tasks. And remoting into the main office and updating my tickets.</p>
<p>Now to try get home in one piece. Already dreading the return traffic.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/10/30/traffic-ordeals-and-standing-in-for-colleagues/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Change Control Jitters</title>
		<link>http://blog.lensbox.za.net/2007/10/22/change-control-jitters/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/10/22/change-control-jitters/#comments</comments>
		<pubDate>Mon, 22 Oct 2007 20:01:07 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/2007/10/22/change-control-jitters/</guid>
		<description><![CDATA[Tomorrow night, at 8pm, I do my first firewall maintenance at a client before the 3rd Party (banking institution) they&#8217;re trying to interact with, go into change-freeze at the end of the week&#8230; It&#8217;s one thing to sit in the office and do changes where you can (hopefully) reverse them or ask for some advice [...]]]></description>
			<content:encoded><![CDATA[<p>Tomorrow night, at 8pm, I do my first firewall maintenance at a client before the 3rd Party (banking institution) they&#8217;re trying to interact with, go into change-freeze at the end of the week&#8230;</p>
<p>It&#8217;s one thing to sit in the office and do changes where you can (hopefully) reverse them or ask for some advice from a colleague before committing the changes to the firewall. It&#8217;s an entirely different story to be at a client with them looking over your shoulder while you &#8216;tinker&#8217; with their firewall.</p>
<p>What makes this particular change even more nerve-wracking is that the client cannot really explain the changes that I need to make to me upfront&#8230; we&#8217;re sort of winging it, trying to get something to work.</p>
<p>Hopefully it&#8217;s not too big a job. I need to route traffic from one network to another over two Microsoft ISA servers&#8230; how hard can it be? <img src='http://blog.lensbox.za.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/10/22/change-control-jitters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do security engineers dream of firewall logs&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/09/28/do-security-engineers-dream-of-firewall-logs/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/09/28/do-security-engineers-dream-of-firewall-logs/#comments</comments>
		<pubDate>Fri, 28 Sep 2007 10:56:31 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=49</guid>
		<description><![CDATA[I know I&#8217;m starting to. And I haven&#8217;t consciously recalled a dream since about 18 years ago. My head is filling up with terminology and jargon, from both the Checkpoint Firewall-1 side of things and our own internally developed monitoring systems that we deploy at client sites. This morning, I woke up, with the word [...]]]></description>
			<content:encoded><![CDATA[<p><font size="2">I know I&#8217;m starting to. And I haven&#8217;t consciously recalled a dream since about 18 years ago.</font></p>
<p><font size="2">My head is filling up with terminology and jargon, from both the Checkpoint Firewall-1 side of things and our own internally developed monitoring systems that we deploy at client sites.</font></p>
<p><font size="2">This morning, I woke up, with the word &#8220;CACT&#8217;s&#8221; on my mind&#8230; Complex ACTions. Packets being dropped by the firewall. My staple diet of support tickets, these days. And something that is often difficult to interpret. I sometimes spend an hour or two to retrieve the logs, format them in Excel and Access, then do SQL queries to filter out the &#8220;trash&#8221; data to determine the culprits. And even then, I cannot always be sure of my analysis until I verify some facts with the network diagram or ask a colleague to double check my findings.</font></p>
<p><font size="2">Thus far, I&#8217;ve found some DDOS attacks, some portscans, a virus infection, peer to peer software abuse and some really dodgy DNS systems.</font></p>
<p><font size="2">Anyway&#8230; this weekend is <a href="http://www.rage.co.za">rAge</a>. First one that I will be attending. Looking forward to see what we here in South Africa call a gaming expo, seeing as we always see coverage of the overseas expo&#8217;s but never our own.</font></p>
<p><font size="2">Hope you all have a good weekend. See you on the other side.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/09/28/do-security-engineers-dream-of-firewall-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A steep learning curve</title>
		<link>http://blog.lensbox.za.net/2007/09/23/a-steep-learning-curve/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/09/23/a-steep-learning-curve/#comments</comments>
		<pubDate>Sun, 23 Sep 2007 06:52:07 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=48</guid>
		<description><![CDATA[My first month at ISA (Information Security Architects) draws to a close soon, and looking back at the past few weeks, I&#8217;m surprised at how the time has flown. Not that I&#8217;ve been so hectically busy that I never noticed the time, but rather that I&#8217;ve been engaged at a level that I haven&#8217;t experienced [...]]]></description>
			<content:encoded><![CDATA[<p>My first month at ISA (Information Security Architects) draws to a close soon, and looking back at the past few weeks, I&#8217;m surprised at how the time has flown. Not that I&#8217;ve been so hectically busy that I never noticed the time, but rather that I&#8217;ve been engaged at a level that I haven&#8217;t experienced in a very long time.</p>
<p>Initially I was just supposed to get up to speed with F-Secure, their AV product range, and refresh my knowledge of Trend Micro as well, but seeing as we haven&#8217;t received many tickets for either set of products, I&#8217;ve kept myself occupied by jumping in the deep end with Checkpoint firewall support.</p>
<p>Well, not so much the support side of things just yet. Changes, I leave to those a little more qualified than I am, for the moment. No, my major task these past two weeks has been firewall log forensics. Breaking down thousands upon thousands of lines of logged events to spot trends, looking for attacks, potential network issues, etc.</p>
<p>I found it funny that I ended up using some of my old development tools in order to do so. SQL queries are amazing at breaking things down into manageable chunks of data&#8230;</p>
<p>I must admit, though, that I feel really stupid sometimes, having to ask my colleagues for advice all the time, but considering I haven&#8217;t yet gone on training for the product, I think I&#8217;m doing the best I can under the circumstances.</p>
<p>My other project has been building a MS ISA server for testing purposes, collecting browsing data for our Dev Team. And learning Websense again.</p>
<p>All in all, feeling a little overloaded, information-wise, but still enjoying it. The people at work are great, the environment is pleasant and I hardly notice the time there, in fact, I leave most evenings well after my finishing times. Mostly to miss traffic, but it&#8217;s also great to sit and chat with fellow geeks, play some pool, etc until such time as we all head our different ways.</p>
<p>For the first time in a long time, I feel at home in the IT industry again.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/09/23/a-steep-learning-curve/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New beginnings&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/09/09/new-beginnings/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/09/09/new-beginnings/#comments</comments>
		<pubDate>Sun, 09 Sep 2007 10:18:00 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[World of Warcraft]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=47</guid>
		<description><![CDATA[Well, I&#8217;ve survived my first week at the new company. No, survived is the wrong word, I think. Enjoyed, is a better choice. Granted, I haven&#8217;t started any of the real hard work yet, rather, I&#8217;ve been studying their products, getting to know the staff, building my PC and subsequently my virtual PC&#8217;s to run [...]]]></description>
			<content:encoded><![CDATA[<p>Well, I&#8217;ve survived my first week at the new company. No, survived is the wrong word, I think. Enjoyed, is a better choice.</p>
<p>Granted, I haven&#8217;t started any of the real hard work yet, rather, I&#8217;ve been studying their products, getting to know the staff, building my PC and subsequently my virtual PC&#8217;s to run and test the products.</p>
<p>I&#8217;ve been made to feel very welcome by all involved and have met some very interesting people. Amogst them, I&#8217;ve found some kindred spirits that share my passion for certain things in life: photography, esoteric studies, music, even gaming. It was very amusing to find that at least two of my colleagues are playing or have played World of Warcraft.</p>
<p>Next week the pace will increase somewhat&#8230; but I&#8217;m ready and looking forward to it. For all the obstacles that I felt were in front of me on leaving the old company, I feel the path ahead is now the right one.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/09/09/new-beginnings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Change&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/08/02/change/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/08/02/change/#comments</comments>
		<pubDate>Thu, 02 Aug 2007 13:25:28 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=36</guid>
		<description><![CDATA[Change is one of those many constants in life. Or at least it should be, to avoid being left behind, stagnating and losing touch with the ever-evolving, ever changing universe around us. This month for me, brings change. A necessary one, but not one without it&#8217;s repercussions. At the end of this month, I leave [...]]]></description>
			<content:encoded><![CDATA[<p>Change is one of those many constants in life.</p>
<p>Or at least it should be, to avoid being left behind, stagnating and losing touch with the ever-evolving, ever changing universe around us.</p>
<p>This month for me, brings change. A necessary one, but not one without it&#8217;s repercussions.</p>
<p>At the end of this month, I leave my position as a system administrator for a junior position at an information security architect, to begin studying towards being a senior security engineer, or some such mouthful.</p>
<p>7 years ago, I was a system administrator. Then the company I was with retrenched a good many of us. It was a big setback for my career. From then till now, I&#8217;ve stagnated,  barely creeping forward, trying to regain that original status and now that I have it again, I find myself unhappy, needing change.</p>
<p>Change found me, this time around, in the form of one of the vendors at the company I was contracted to. He then suggested I meet with the security firm in question and did some &#8216;selling&#8217; on my behalf, to ease my way in.</p>
<p>I just wish I had more time to exit gracefully from where I am now. My timing is not the best for those involved and I&#8217;m afraid I may have lost more than just an employer in the process, but also one of my oldest colleagues.</p>
<p>Nothing to do now but finish what I started and move on. I cannot afford regrets anymore.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/08/02/change/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>And once again, IT is the harbinger of doom&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/07/25/and-once-again-it-is-the-harbinger-of-doom/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/07/25/and-once-again-it-is-the-harbinger-of-doom/#comments</comments>
		<pubDate>Wed, 25 Jul 2007 10:03:02 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=35</guid>
		<description><![CDATA[Today, I think, I made a few enemies at work. How? 3 words. Websense Remote Filtering. What does this mean? It means that no matter where you are, what connection you are using, etc on your company laptop, this service will poll the Websense policy server to see what you are and what you are [...]]]></description>
			<content:encoded><![CDATA[<p>Today, I think, I made a few enemies at work. How? 3 words. <strong>Websense Remote Filtering</strong>.</p>
<p>What does this mean? It means that no matter where you are, what connection you are using, etc on your company laptop, this service will poll the Websense policy server to see what you are and what you are not allowed to browse.</p>
<p>So the guys using company laptops, their 3G cards or phones, etc to bypass the proxy restrictions at work, have suddenly found themselves back where they began. Filtered and blocked.</p>
<p>I&#8217;ve been called everything from the Grim Reaper, to the Bastard Operator from Hell, to a Harbinger of Doom&#8230; Guess one has to just shrug it off as having to follow orders from above.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/07/25/and-once-again-it-is-the-harbinger-of-doom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fastforward to April 2007&#8230;</title>
		<link>http://blog.lensbox.za.net/2007/04/05/fastforward-to-april-2007/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://blog.lensbox.za.net/2007/04/05/fastforward-to-april-2007/#comments</comments>
		<pubDate>Thu, 05 Apr 2007 11:27:41 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Design and Multimedia]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[World of Warcraft]]></category>

		<guid isPermaLink="false">http://www.lensbox.za.net/?p=24</guid>
		<description><![CDATA[And so 3 months pass with no blog entries&#8230; Well, work has been, well, interesting at times. The joys of corporates : politics, backstabbing, favouritism, brain-trusts, ducking and diving&#8230; I&#8217;ve met an old IRC acquaintance at work though, so all is not lost. Makes things a bit easier when you have someone to chat to [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">And so 3 months pass with no blog entries&#8230;</p>
<p class="MsoNormal"><o></o>Well, work has been, well, interesting at times. The joys of corporates : politics, backstabbing, favouritism, brain-trusts, ducking and diving&#8230;<o></o></p>
<p class="MsoNormal">I&#8217;ve met an old IRC acquaintance at work though, so all is not lost. Makes things a bit easier when you have someone to chat to during the day.<o></o></p>
<p class="MsoNormal">Other than that, life at the Big Brother house, as we&#8217;ve come to call our little commune, has hopefully settled down finally. We&#8217;ve had an interesting past few weeks, having to ask one of the girls to leave due to her abusive nature towards the other housemates, her alcohol problem and her cat. On top of that, one of the other girls&#8217;  ex-boyfriends has made an appearance and threatened us all with violence, phoning us on the house phone, stalking her, forcing his way onto the property, etc.<o></o></p>
<p class="MsoNormal">Let&#8217;s see, what else. Ah, yes, I&#8217;m back online playing World of Warcraft, now in The Burning Crusade, with my little slicer and dicer rogue. Been listening to a lot of game related podcasts from the folks over at <a href="http://www.wcradio.com" title="http://www.wcradio.com">WC Radio</a>. Ah yes, that was other thing. The iPod. I love my little iPod. It&#8217;s my precious!<o></o></p>
<p class="MsoNormal">Hmm. Ok. Think that&#8217;s about it. Ah yes&#8230;<o></o></p>
<p class="MsoNormal">It&#8217;s Easter Weekend this weekend so hooray for public holidays and long weekends. Time to relax, play some games with friends, watch a movie (I think 300 is on the menu), drink some Amaretto, lime and lemonade, turn up the volume and unwind.<o></o></p>
<p class="MsoNormal">Catch you on the flip side!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lensbox.za.net/2007/04/05/fastforward-to-april-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
