Niche Konsult  Newsletter

October 2007 Edition

This email message is being sent to all individuals who have expressed interest in Niche Konsult or Niche Konsult partner products and solutions in accordance with Niche Konsult’s privacy policy. You may opt out of future mails by sending a mail to newsletter@nichekonsult.com with “Unsubscribe” in the Subject line.

View in Browser   Privacy Policy

Feature Story: Introducing RouterStudio

- Network Traffic Management Toolkit for Microsoft Windows

RouterStudio

RouterStudio is a professional, advanced and integrated Network Traffic Management Toolkit for Microsoft Windows. Both licenses for commercial and non-commercial usage are available.

Functionality

Basically, RouterStudio provides the following solutions in one integrated software-package.

  • Multiple ISPs: Local Area Networks (and stand-alone PC's) can be connected to the internet using multiple internet connections at the same time. Internet network traffic is load-balanced dynamically among the multiple Internet connections available. Support for failover provides a cost-effective solution to environments that rquire high availability for internet connectivity.
  • Powerful Bandwidth Management for complete Local Area Networks: The generic structure of the bandwidth limitation rules makes configuration easy and shortens configuration time
  • Advanced filtering of network traffic on a per-Network-Interface-Card basis
  • Source-dependent redirection of network traffic

Future Planned Extensions 

In the very near future, RouterStudio is planned to be extended with at least the folowing two (2) modules:

  • Multi-Link IP Concentrator:The Multi-Link IP Concentrator will make it possible to load-balance network traffic between pairs of 2 hosts over multiple internet links. So, for example, VPN-connections can be set up over multiple internet links (DSL lines) in parallel. The Multi-Link IP Concentrator will support multiple pairs of hosts being handled by one server running RouterStudio. Support for failover (in case one of the internet links fails) will also be included to increase the availability of the connections. Note: This feature is currently under development.
  • Inbound Load Balancing:Using this module, requests from hosts located on the internet can be load-balanced among multiple servers. Suiting the lvel of genericity of the other RouterStudio modules, appliance of this module will not be limited to web-servers only. Note: This feature is planned to be developed.

Interested?

Then you might like to consider 15 reasons why you need Router Studio and your free trial is just a click away!

Database Security – Making the Case

David Litchfield, security researcher and managing director of NGSSoftware recently found out that there are nearly half a million databases on the internet without firewall protection. Litchfield is someone in a position to know given that in 2005 he conducted similar research. The 2007 version of similar research findings will go live on November 19, 2007

Exploit code for a recently disclosed vulnerability in Oracle Database 10GR2 is now in the wild and Oracle plans to patch this vulnerability on January 15, 2008 which is its next scheduled quarterly critical patch update.

Email Security – MP3 Spam

During the month of October, GFI became the first email security company to discover the existence of a new kind of spam – MP3 spam. Here is a link to get up to speed on this.

 

Email Security – New GFI MailEssentials Video Released

The  video may be viewed here. A recent phishing incident involving salesforce.com demonstrates why GFI MailEssentials is a must-have.

Email Security – Free Email Account for Official Communication? Yes or No

Does your corporate email policy permit the use of free email accounts for official purposes? or even at work at all? or the forwarding of official communication to free email accounts? Well, whichever is the case, the hyperlinked news story about MediaDefender Inc, a firm employed by record companies to seed the internet with phony files of pirated movies and albums should prove quite instructive. It might be what you have waiting for as conclusive proof to make your point to management that free email is a corporate risk!

A while ago Niche Konsult prepared a position paper on why free email accounts are bad for business.

Enterprise Security– Digital Archiving

Business Continuity! Disaster Recovery! These two concepts should be of great concern to the IT department, given the strategic role of IT in many if not all industries.

And if it wasn't,  disasters such as the January 14, 2003 fire at the Kaduna Refinery & Petrochemicals Company; the March 7, 2004 fire at the Federal Secretariat Complex, Phase II, Ikoyi, Lagos with NAFDAC as the major target;  the structural defect occasioning collapse on March 20, 2006 of the Bank of Industry headquarters in Lagos; as well as the sabotage during May/June 2006 at the National Agency for the Prevention of Trafficking  in Persons (NAPTIP) should serve to put these issues foremost on the map. 

Mrs. Christy Obiazikwor, the Public Relations Officer of NAFDAC was quoted to say on the above occassion: "All the official equipment including the recently installed ocmputer network was not spared. NAFDAC's automated regulated product administration database was also destroyed. We estimate the loss to be billions of naira."

Another NAFDAC source was reported to say:"The Ikoyi office is the hub of our operational activities. We suspect that the unfortunate incident was targetted at frustrating our efforts in carying out our mandatory functions. "

The morale? To be forewarned is to be forearmed! With Genie-Soft you can be begin putting in place practical low-cost disaster recovery and business continuity measures.

Genie-Soft's line of backup solutins are targeted at the home and home office, small & medium business, corporate and enterprise users.

For the Home and Home Office, the solutions include Genie Backup Manager Home v8.0, Genie Mail Backup (for Outlook 2007), Genie Archive for Outlook, Genie Eyes-Only,Genie Online Backup.

For the Small and Medium Businesses, the solutions include Genie Backup Manager Pro v8.0, Genie Backup Manager Server v 8.0, Genie Archive for Outlook, Genie Eyes-Only,Genie Online Backup.

For corporate and enterprise users, the solutions include Genie Backup Manager Server v 8.0, Genie Archive for Outlook, Genie Eyes-Only,Genie Online Backup.

We encourage you try these out, we have and we can recommend their solutions anytime anyday.

General Security- Internet Access Control in the Workplace

Recently, GFI Webmonitor for ISA Server version 4 was released. GFI WebMonitor for ISA server gives administrators comprehensive control over corporate web usage and what employees are downloading from the internet, and is available in 3 editions.

 

These are: the WebFilter Edition, the WebSecurity Edition and the UnifiedProtection Edition.

This month the Report Pack for GFI WebMonitor for ISA Server is in beta, we encourage you to try it out.

Should you require a comparison of GFI WebMonitor with the other solutions on the market, please send an email to info@nichekonsult.com, and will send you the whitepaper.

Government Security– US CyberSecurity not tight enough

If it could be said that America is not yet there, what of countries like Nigeria

Instant Messaging Security – The Good, the Bad and the Ugly

The two way real-time communication, easy collaboration  and presence information that instant messaging provides has made many to prefer it to email. Instant messaging technology began over thirty years old with the UNIX operating system. But instant messaging as we know it today is just 11 years old.

Popular instant messaging clients include Windows Messenger, MSN Messenger ( now Live Messenger), AOL Instant Messenger, Yahoo Instant Messenger, IBM Lotus Sametime, Sun Java System Instant Messenger, Google Talk and Skype.

Some major problems with consumer-grade instant messaging are first, that ordinary all transmissions are sent in the clear which means anyone with a sniffer can monitor  conversations, and secondly, ,lack of control over the logging feature, thirdly, lack of control by the IT department over the middle-man server at the consumer-grade instant messaging company which is used for authentication and message relays.

To this end, Niche Konsult recommends that if instant messaging is mission-critical to your operations, then enterprise-grade instant messaging is the real answer.

Microsoft recently posted some 10 tips for safer instant messaging.

Office Security - 2007 Microsoft Office Security Guide

On November 11, 2007, Microsoft released the 2007 Microsoft Office Security Guide. According to Microsoft, the 2007 Microsoft® Office release is designed to help defeat attacks that target e-mail and desktop documents.

 

Hundreds of security and privacy settings are available that allow you to ensure your deployment of the 2007 Office release balances your organization’s needs for security and functionality. The 2007 Microsoft Office Security Guide provides IT professionals with best practices and automated tools to help strengthen the security of computers that run either Windows Vista™ or Windows® XP SP2 and the following applications:

  • Microsoft Office Access™ 2007
  • Microsoft Office Excel® 2007
  • Microsoft Office InfoPath® 2007
  • Microsoft Office Outlook® 2007
  • Microsoft Office PowerPoint®2007
  • Microsoft Office Word 2007

Portable Device Security– CheckPoint/PointSec Protector

Should you be considering portable device control coupled with media encryption, then CheckPoint/PointSec Protector should be top on your list, it is a very mature product and is used nu al of Fortune 100.

Portable Device Security - – GFI EndPointSecurity 4 in BETA

On the other hand, if you require purely portable device control, then GFI EndPointSecurity is it

GFI EndPointSecurity 4 is currently in beta. This new version includes support for Windows Vista (both x32 and x64 versions), Windows XP x64, Windows 2003 x64 and Windows Server 2008.

 

New features include:  file security policies can now be defined by file type, for example, allowing the user to read  *.doc files but blocking access to all *.exe files, device blockage by the physical port on which they are connected, device blocking by serial number ( unique Hardware ID) and device discovery. For a complete list of what's new and what's changed, click here

Web Security- The Overlooked Threat

Recently, the Microsoft UK Events website was hacked, here is a link that explains in detail how the hack occured.

 

For more information on the topic, here are some links that might prove to be useful:

Web Hacking - An Under-Estimated threat

Black Box Scanners - Their Role and Functions

Ajax Security

Web Services Security whitepaper

Windows Security -Microsoft Windows Vista Service Pack 1 Coming

For an overview, please click here 

Other News

To take advantage of GFI's Q4 Promotional Offers, visit http://www.nichekonsult.com/

GFI FaxMaker 14 released

GFI MailArchiver 5 released

Microsoft gives away Search Server 2008 Express. Read the original press release here. Get it here.

Radmin Remote Control 3.1 released

The Insider Threat is real!

Tips and Tricks

1. Thinking of upgrading to the Windows Vista operating system and the 2007 Microsoft Office System, then the Windows Vista Hardware Assessment 2.1 is what you need. 

2. With the Microsoft Office Outlook connector, you can use Microsoft Office Outlook 2003 or Microsoft Office Outlook 2007 to access and manage your Microsoft Windows Live Hotmail or Microsoft Office Live mail acounts and contacts for free.

About Niche Konsult

Niche Konsult is an information technology security firm with expertise in content, messaging, network and web application security.

Niche Konsult provides software and solutions that help individuals, small and medium size businesses, large companies and governments optimize and secure their information technology infrastructure. For more information, please visit http://www.nichekonsult.com.

Having trouble viewing this NIche Konsult Newsletter? Visit http://www.nichekonsult.com/Company/Newsletters/10_17_07.aspx or copy it into your browser. If you no longer wish to receive these emails simply click on the following link: Remove Me.

You're receiving this message because you've either subscribed  to receive timely security news and product/company updates from Niche Konsult or have indicated interest in Niche Konsult partner solutions in the past.

Newsletter Reminder

We hope that you have found this issue to be informative and useful. Subscription is entirely free (although 'opt-in' only). Please feel free to pass this copy on to your friends and colleagues. If your friends or colleagues wish to receive the newsletter directly, they should simply send an email to: newsletter@nichekonsult.com with a title of 'Subscribe'.

Niche Konsult

43 Cotonou Crescent

Wuse Zone 6

Abuja

© 2007 Niche Konsult. All rights reserved worldwide. Reproduction in whole or in part of any text, photograph or illustration without permission of the publisher is prohibited.

GFI MailDefense Suite Lanched

GFI Software recently announced the release of the GFI MailDefense Suite, offering comprehensive anti-virus, anti-spam and anti-phishing protection for SMBs at an unbeatable price.

GFI MailDefense Suite

GFI EventsManager 8.1 Released

In the latest version, 8.1, the level of alerting when key events or intrusions are detected on the network has been expanded through support for SNMPv2 traps alerting.