<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Puts Hold on Forefront Security Product Range</title>
	<atom:link href="http://www.darknet.org.uk/2009/04/microsoft-puts-hold-on-forefront-security-product-range/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/04/microsoft-puts-hold-on-forefront-security-product-range/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Fri, 20 Nov 2009 20:21:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/04/microsoft-puts-hold-on-forefront-security-product-range/#comment-142458</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Sun, 12 Apr 2009 12:52:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1691#comment-142458</guid>
		<description>@Anonymous: I am sure you could do it with incognito

@Darknet: I have used ISA a bit and am even certified in 2004. In all realism it isn&#039;t a half bad firewall and proxy, though you need third party apps to get the proxy bit to do anything other than cache.
I heard from a colleague MS did their usual trick and poached some Checkpoint guys to build ISA, so its security is fairly high on the charts for that alone.
From what I have heard of MS endpoint security it is also pretty decent, nothing as bad as one-care, and it integrates into the OS and into the domain with ISA/Forefront to allow policies to lock down a box even off the network. It&#039;s heuristics engine I think was bought from someone else (symantec?) and is pretty damned good. They are also putting ips/ids and deep packet inspection into the new ISA IIRC, which is where they maybe getting there will stop 0-days. I guess we will see.
All that being said though it sort of goes against my ethos, which is basically if you are trying to protect one OS use another OS as a firewall to at least make the knowledge the attacker needs that little bit greater.</description>
		<content:encoded><![CDATA[<p>@Anonymous: I am sure you could do it with incognito</p>
<p>@Darknet: I have used ISA a bit and am even certified in 2004. In all realism it isn&#8217;t a half bad firewall and proxy, though you need third party apps to get the proxy bit to do anything other than cache.<br />
I heard from a colleague MS did their usual trick and poached some Checkpoint guys to build ISA, so its security is fairly high on the charts for that alone.<br />
From what I have heard of MS endpoint security it is also pretty decent, nothing as bad as one-care, and it integrates into the OS and into the domain with ISA/Forefront to allow policies to lock down a box even off the network. It&#8217;s heuristics engine I think was bought from someone else (symantec?) and is pretty damned good. They are also putting ips/ids and deep packet inspection into the new ISA IIRC, which is where they maybe getting there will stop 0-days. I guess we will see.<br />
All that being said though it sort of goes against my ethos, which is basically if you are trying to protect one OS use another OS as a firewall to at least make the knowledge the attacker needs that little bit greater.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.darknet.org.uk/2009/04/microsoft-puts-hold-on-forefront-security-product-range/#comment-141202</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 08 Apr 2009 22:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1691#comment-141202</guid>
		<description>I&#039;ve used ISA for a few years now.  The one feature I&#039;ve always liked is the NTLM integrated proxy authentication.  As long as you&#039;re blocking egress traffic, it seems to stop any piece of malware looking for a second payload or botnet.  I&#039;m sure it wouldn&#039;t be hard to replay compromised NTLM hashes through the proxy, I just haven&#039;t see it done...</description>
		<content:encoded><![CDATA[<p>I&#8217;ve used ISA for a few years now.  The one feature I&#8217;ve always liked is the NTLM integrated proxy authentication.  As long as you&#8217;re blocking egress traffic, it seems to stop any piece of malware looking for a second payload or botnet.  I&#8217;m sure it wouldn&#8217;t be hard to replay compromised NTLM hashes through the proxy, I just haven&#8217;t see it done&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
