<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Real-time AntiSpam protection, automated and self-managed content filtering &#187; securities issue</title>
	<atom:link href="http://veriat.com/tag/securities-issue/feed" rel="self" type="application/rss+xml" />
	<link>http://veriat.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 May 2010 23:10:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>User Securities Lapses Open pcAnywhere Hosts to Prying Eyes</title>
		<link>http://veriat.com/user-securities-lapses-open-pcanywhere-hosts-to-prying-eyes-2.html</link>
		<comments>http://veriat.com/user-securities-lapses-open-pcanywhere-hosts-to-prying-eyes-2.html#comments</comments>
		<pubDate>Sat, 01 Aug 2009 15:36:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-spam techniques]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[HTTP]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[NDS]]></category>
		<category><![CDATA[Novell Bindery]]></category>
		<category><![CDATA[NT Domain]]></category>
		<category><![CDATA[public key encryption]]></category>
		<category><![CDATA[securities issue]]></category>

		<guid isPermaLink="false">http://veriat.com/?p=259</guid>
		<description><![CDATA[pcAnywhere 10: Remote Access Not a Remote Risk (Update)
Symantec recently contacted ?regarding its April 11th, 2001 analysis of pcAnywhere securities issues and pointed out several features we glossed over in our (albeit brief) discussion of pcAnywhere 10.0. To summarize Symantec&#8217;s claims and our responses:?
1. pcAnywhere 10.0 client-host traffic can be encrypted using internal pcAnywhere, symmetric, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>pcAnywhere 10: Remote Access Not a Remote Risk (Update)</strong></p>
<p>Symantec recently contacted ?regarding its April 11th, 2001 analysis of pcAnywhere securities issues and pointed out several features we glossed over in our (albeit brief) discussion of pcAnywhere 10.0. To summarize Symantec&#8217;s claims and our responses:?<span id="more-259"></span></p>
<p>1. pcAnywhere 10.0 client-host traffic can be encrypted using internal pcAnywhere, symmetric, or public key encryption.</p>
<p>The encryption Symantec refers to prevents network monitors or &#8220;sniffers&#8221; from capturing a remote pcAnywhere session. But unless you select public key encryption, and then do not publish the key, it will not provide any additional protection from other pcAnywhere users. A login attempt will report the level of security being used.</p>
<p>2. pcAnywhere 10.0 requires that users password protect their pcAnywhere hosts. A &#8220;null&#8221; password is not accepted.</p>
<p>pcAnywhere 10.0 requires that users password protect new Callers, not new hosts. Password protection of the host is optional. And both levels of password protection can be defeated via the .CIF file &#8220;back door.&#8221;</p>
<p>3. Authentication options offered with pcAnywhere 10.0 include Active Directory, NDS, Novell Bindery, LDAP, FTP, HTTP, and NT Domain.</p>
<p>4. Random searches for pcAnywhere hosts can be prevented by going to Tools &gt; Options &gt; Host Communications and clicking the &#8220;Do not display host in TCP/IP search results&#8221; box.</p>
<p>This is an important feature for pcAnywhere users wishing to ensure their privacy over local area networks and the Internet.</p>
<p>5. pcAnywhere users can add a further level of security by limiting connections to within a specific subnet or even a specific TCP/IP address or host name.</p>
<p>This is perhaps the easiest-to-implement safety feature for both home/small business and corporate users. Go to Tools &gt; Options &gt; Host Communications. In the TCP/IP options box you can enter a list of valid connections. Callers from addresses other than those listed will be rejected, regardless of permissions and passwords.</p>
<p>6. If you use the pcAnywhere 10.0 Packager to create custom pcAnywhere hosts, &#8220;Integrity Checking&#8221; will check the installation every time pcAnywhere is launched for changes in the registry, pcAnywhere objects, executables and DLL&#8217;s. Integrity Checking prevents .CIF files from being copied into the pcAnywhere data directory and circumventing security settings.</p>
<p>&#8220;Integrity Checking&#8221; applies only to Packager-created hosts. Packager installation requires Windows NT or Windows 2000. Otherwise, pcAnywhere 10.0 does not distinguish between a CIF file generated by its own host and a .CIF file generated elsewhere. In fact, you can copy a foreign .CIF file to the \pcAnywhere directory while the host is running and the host will incorporate the new password and login &#8220;on the fly.&#8221; Subsequently (until and unless either the new Caller or the .CIF file is deleted), all new hosts will incorporate that .CIF file&#8217;s defined Caller.</p>
<p>This porous &#8220;back door&#8221; necessitates careful attention to all the other security measures pcAnywhere offers and incorporates.</p>
]]></content:encoded>
			<wfw:commentRss>http://veriat.com/user-securities-lapses-open-pcanywhere-hosts-to-prying-eyes-2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

