Author Archive

03/20/2011: Lick Creek Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 34' 01.47" / W 96° 12' 40.06" Heart: - Ele.: 76 m
0.000 mi 0s 0s - - - - -
2 N 30° 33' 31.68" / W 96° 12' 39.37" Heart: 0 Ele.: 63 m
5.005 mi 26m 57s 26m 57s 11.14 mph 11.14 mph 17.18 mph 492 ft 535 ft
3 N 30° 33' 37.59" / W 96° 13' 12.80" Heart: 0 Ele.: 68 m
5.012 mi 31m 29s 31m 29s 9.55 mph 9.55 mph 16.72 mph 440 ft 423 ft
4 N 30° 34' 01.60" / W 96° 12' 40.25" Heart: 0 Ele.: 66 m
2.763 mi 16m 00s 16m 00s 10.36 mph 10.36 mph 16.88 mph 427 ft 433 ft
12.780 mi

1h 14m 26s 1h 14m 26s 10.30 mph

10.30 mph 17.18 mph 1358 ft

1391 ft
Average Heartrate: 0 Max / Min Elevation: 272 ft 135 ft

Download GPX file: 03-20-2011.gpx

3/18/2011: Austin Town Lake Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 15' 05.85" / W 97° 44' 04.10" Heart: - Ele.: 128 m
0.000 mi 0s 0s - - - - -
2 N 30° 15' 49.12" / W 97° 45' 08.32" Heart: 0 Ele.: 135 m
5.004 mi 31m 45s 31m 45s 9.46 mph 9.46 mph 34.24 mph 564 ft 541 ft
3 N 30° 14' 52.30" / W 97° 43' 26.03" Heart: 0 Ele.: 142 m
5.004 mi 36m 22s 36m 22s 8.26 mph 8.26 mph 18.60 mph 479 ft 456 ft
4 N 30° 15' 05.67" / W 97° 44' 09.76" Heart: 0 Ele.: 137 m
0.804 mi 4m 46s 4m 46s 10.12 mph 10.12 mph 18.42 mph 39 ft 56 ft
10.812 mi

1h 12m 53s 1h 12m 53s 8.90 mph

8.90 mph 34.24 mph 1083 ft

1053 ft
Average Heartrate: 0 Max / Min Elevation: 509 ft 413 ft

Download GPX file: 03-18-2011.gpx

How to Disable Weak SSL Protocols and Ciphers in IIS

I recently undertook the process of moving websites to different servers here at work. This required that university networking group scan the new webserver with a tool called Nessus. Unfortunately this turned up several errors, all of them had to do with Secure Sockets Layer or SSL which in Microsoft Windows Server 2003 / Internet Information Server 6 out of the box support both unsecure protocols and cipher suites. These problems would have to be solved before they would allow the new server though the firewalls. The report they university sent me was generated by Nessus generated errors like this:

SSL Version 2 (v2) Protocol Detection
 
Synopsis :
 
The remote service encrypts traffic using a protocol with known
weaknesses.
 
Description :
 
The remote service accepts connections encrypted using SSL 2.0, which
reportedly suffers from several cryptographic flaws and has been
deprecated for several years. An attacker may be able to exploit
these issues to conduct man-in-the-middle attacks or decrypt
communications between the affected service and clients.
 
See also :
 
http://www.schneier.com/paper-ssl.pdf
http://support.microsoft.com/kb/187498
http://www.linux4beginners.info/node/disable-sslv2
 
Solution :
 
Consult the application's documentation to disable SSL 2.0 and use SSL
3.0 or TLS 1.0 instead.
 
Risk factor :
 
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
 
Nessus ID : 20007
----------------------------------------------------------
SSL Medium Strength Cipher Suites Supported
 
Synopsis :
 
The remote service supports the use of medium strength SSL ciphers.
 
Description :
 
The remote host supports the use of SSL ciphers that offer medium
strength encryption, which we currently regard as those with key
lengths at least 56 bits and less than 112 bits.
 
Note: This is considerably easier to exploit if the attacker is on the
same physical network.
 
Solution :
 
Reconfigure the affected application if possible to avoid use of
medium strength ciphers.
 
Risk factor :
 
Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
 
Plugin output :
 
Here are the medium strength SSL ciphers supported by the remote server :
 
Medium Strength Ciphers (>= 56-bit and < 112-bit key)
SSLv2
DES-CBC-MD5 Kx=RSA Au=RSA Enc=DES(56) Mac=MD5
SSLv3
DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1
TLSv1
EXP1024-DES-CBC-SHA Kx=RSA(1024) Au=RSA Enc=DES(56) Mac=SHA1 export
EXP1024-RC4-SHA Kx=RSA(1024) Au=RSA Enc=RC4(56) Mac=SHA1 export
DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1
 
The fields above are :
 
{OpenSSL ciphername}
Kx={key exchange}
Au={authentication}
Enc={symmetric encryption method}
Mac={message authentication code}
{export flag}
 
Nessus ID : 42873
--------------------------------------------------------------------
SSL Weak Cipher Suites Supported
 
Synopsis :
 
The remote service supports the use of weak SSL ciphers.
 
Description :
 
The remote host supports the use of SSL ciphers that offer either weak
encryption or no encryption at all.
 
Note: This is considerably easier to exploit if the attacker is on the
same physical network.
 
See also :
 
http://www.openssl.org/docs/apps/ciphers.html
 
Solution :
 
Reconfigure the affected application if possible to avoid use of weak
ciphers.
 
Risk factor :
 
Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
 
Plugin output :
 
Here is the list of weak SSL ciphers supported by the remote server :
 
Low Strength Ciphers (< 56-bit key)
SSLv2
EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2(40) Mac=MD5 export
EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export
SSLv3
EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2(40) Mac=MD5 export
EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export
TLSv1
EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2(40) Mac=MD5 export
EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export
 
The fields above are :
 
{OpenSSL ciphername}
Kx={key exchange}
Au={authentication}
Enc={symmetric encryption method}
Mac={message authentication code}
{export flag}
 
Other references : CWE:327, CWE:326, CWE:753, CWE:803, CWE:720
 
Nessus ID : 26928
-----------------------------------------------------------------

These three error messages pretty much mean that you need to turn off SSL 2.0 due to exploits that were found after the standard was created. You need to turn off any encryption suites lower than 128bits. The third error message says we need to turn off anything for less than 56bits, but this will be accomplished by turning of anything less than 128bits. Basically your are modifying the settings that restrict the use of specific protocols and ciphers that are used by the schannel.dll. More detailed information can be found at Micorsoft’s KB187498 or KB245030

How do we do this?

Disabling SSL 2.0 on IIS 6

  1. Open up “regedit” from the command line
  2. Browse to the following key:
    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server
  3. Create a new REG_DWORD called “Enabled” and set the value to 0
  4. You will need to restart the computer for this change to take effect. (you can wait on this if you also need to disable the ciphers)

Disable unsecure encryption ciphers less than 128bit

  1. Open up “regedit” from the command line
  2. Browse to the following key:
    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56
  3. Create a new REG_DWORD called “Enabled” and set the value to 0
  4. Browse to the following key:
    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128
  5. Create a new REG_DWORD called “Enabled” and set the value to 0
  6. Browse to the following key:
    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128
  7. Create a new REG_DWORD called “Enabled” and set the value to 0
  8. Browse to the following key:
    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128
  9. Create a new REG_DWORD called “Enabled” and set the value to 0
  10. You will need to restart the computer for this change to take effect.

How to verify the changes?

Now that you have made these changes how can you be sure that they have taken place without having to go to your boss or higher authority just to find that you did them wrong. Well I found a nice tool called SSL-SCAN which you can download at http://code.google.com/p/sslscan-win/ for the Windows port or you can download an compile for your favorite operating system at the original project SSL-SCAN siteĀ http://sourceforge.net/projects/sslscan/. This tool provides some great detail about what is allows and not allows plus some analysis of the SSL certificate itself.

Below the screen shot shows that we have disabled any ciphers that attempt to use the SSL 2.0 protocol and we’ve disabled all ciphers that less than 128bit.

Death of the Zune

It’s sad to hear that the only major competitor to Apple’s Ipod is pulling out of the game. I am all about more competition within product market, but this section of the market being replaced by faster, larger smartphones. And you don’t have to be a genius to begin to wonder how much longer Apple will continue to make Ipods. Microsoft’s Zune was late to the party but I found that I was much happier using it than having to deal with iTunes and paying the standard Apple Tax. I wonder what use I can find for my old Zune 30 considering I just purchased the new Motorola Atrix which can hold all the music I need plus stream some over the cell network. Thanks for all the good times Zune.

3/10/2011: Windy Downtown Bryan

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 37' 54.28" / W 96° 19' 30.59" Heart: - Ele.: 113 m
0.000 mi 0s 0s - - - - -
2 N 30° 37' 15.09" / W 96° 19' 26.58" Heart: 0 Ele.: 93 m
5.016 mi 23m 48s 23m 47s 12.65 mph 12.66 mph 23.38 mph 213 ft 279 ft
3 N 30° 39' 21.80" / W 96° 20' 28.98" Heart: 0 Ele.: 104 m
4.995 mi 20m 13s 20m 13s 14.82 mph 14.82 mph 23.20 mph 223 ft 187 ft
4 N 30° 39' 00.10" / W 96° 22' 34.01" Heart: 0 Ele.: 106 m
5.040 mi 21m 37s 20m 34s 13.99 mph 14.70 mph 20.19 mph 167 ft 161 ft
5 N 30° 36' 09.25" / W 96° 19' 54.59" Heart: 0 Ele.: 97 m
4.959 mi 19m 16s 19m 16s 15.44 mph 15.44 mph 20.52 mph 102 ft 131 ft
6 N 30° 37' 53.58" / W 96° 19' 30.70" Heart: 0 Ele.: 90 m
5.006 mi 27m 30s 27m 30s 10.92 mph 10.92 mph 24.85 mph 141 ft 164 ft
7 N 30° 37' 54.32" / W 96° 19' 30.89" Heart: 0 Ele.: 91 m
0.016 mi 9s 8s 6.48 mph 7.29 mph 8.50 mph 3 ft 0 ft
25.031 mi

1h 52m 33s 1h 51m 28s 13.34 mph

13.47 mph 24.85 mph 850 ft

922 ft
Average Heartrate: 0 Max / Min Elevation: 377 ft 246 ft

Download GPX file: 03-10-2011.gpx

3/2/2011: Indian Lakes Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 37' 54.18" / W 96° 19' 31.03" Heart: - Ele.: 92 m
0.000 mi 0s 0s - - - - -
2 N 30° 35' 27.88" / W 96° 17' 34.66" Heart: 0 Ele.: 75 m
5.028 mi 24m 10s 24m 10s 12.48 mph 12.48 mph 19.37 mph 161 ft 217 ft
3 N 30° 32' 05.94" / W 96° 15' 30.73" Heart: 0 Ele.: 79 m
4.989 mi 18m 03s 18m 03s 16.58 mph 16.58 mph 19.47 mph 171 ft 157 ft
4 N 30° 32' 11.13" / W 96° 15' 30.76" Heart: 0 Ele.: 77 m
5.007 mi 17m 19s 17m 19s 17.35 mph 17.35 mph 22.08 mph 151 ft 157 ft
5 N 30° 34' 17.13" / W 96° 18' 01.90" Heart: 0 Ele.: 88 m
5.020 mi 17m 37s 17m 37s 17.10 mph 17.10 mph 23.15 mph 161 ft 125 ft
6 N 30° 37' 05.93" / W 96° 19' 03.18" Heart: 0 Ele.: 86 m
4.964 mi 32m 29s 32m 29s 9.17 mph 9.17 mph 26.36 mph 141 ft 148 ft
7 N 30° 37' 54.27" / W 96° 19' 30.86" Heart: 0 Ele.: 98 m
1.523 mi 5m 35s 5m 35s 16.36 mph 16.36 mph 21.51 mph 85 ft 46 ft
26.530 mi

1h 55m 13s 1h 55m 13s 13.82 mph

13.82 mph 26.36 mph 869 ft

850 ft
Average Heartrate: 0 Max / Min Elevation: 322 ft 223 ft

Download GPX file: 03-02-2011.gpx

2/26/2011: Mountain Bike Lake Bryan

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 42' 18.40" / W 96° 27' 59.42" Heart: - Ele.: 112 m
0.000 mi 0s 0s - - - - -
2 N 30° 42' 33.67" / W 96° 26' 58.78" Heart: 0 Ele.: 99 m
5.003 mi 49m 53s 49m 53s 6.02 mph 6.02 mph 21.16 mph 1385 ft 1427 ft
3 N 30° 42' 12.92" / W 96° 27' 44.09" Heart: 0 Ele.: 109 m
5.011 mi 51m 28s 51m 28s 5.84 mph 5.84 mph 14.01 mph 863 ft 830 ft
4 N 30° 42' 18.55" / W 96° 27' 59.42" Heart: 0 Ele.: 111 m
0.537 mi 4m 00s 4m 00s 8.06 mph 8.06 mph 13.81 mph 98 ft 92 ft
10.551 mi

1h 45m 21s 1h 45m 21s 6.01 mph

6.01 mph 21.16 mph 2346 ft

2349 ft
Average Heartrate: 0 Max / Min Elevation: 413 ft 279 ft

Download GPX file: 02-26-2011.gpx

2/24/2011: Traditions Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 37' 54.21" / W 96° 19' 30.97" Heart: - Ele.: 94 m
0.000 mi 0s 0s - - - - -
2 N 30° 36' 54.59" / W 96° 20' 00.94" Heart: 0 Ele.: 95 m
5.038 mi 22m 31s 22m 29s 13.42 mph 13.44 mph 20.31 mph 259 ft 256 ft
3 N 30° 35' 51.93" / W 96° 22' 59.05" Heart: 0 Ele.: 93 m
4.984 mi 21m 21s 21m 21s 14.01 mph 14.01 mph 18.56 mph 154 ft 161 ft
4 N 30° 37' 57.51" / W 96° 22' 23.43" Heart: 0 Ele.: 95 m
4.986 mi 19m 34s 19m 34s 15.29 mph 15.29 mph 26.95 mph 259 ft 253 ft
5 N 30° 35' 58.38" / W 96° 21' 25.34" Heart: 0 Ele.: 93 m
5.032 mi 19m 36s 19m 36s 15.40 mph 15.40 mph 19.19 mph 115 ft 121 ft
6 N 30° 36' 31.53" / W 96° 19' 10.40" Heart: 0 Ele.: 87 m
4.964 mi 28m 12s 28m 12s 10.56 mph 10.56 mph 21.49 mph 151 ft 171 ft
7 N 30° 37' 54.34" / W 96° 19' 30.92" Heart: 0 Ele.: 96 m
2.477 mi 11m 08s 11m 07s 13.35 mph 13.37 mph 23.28 mph 89 ft 59 ft
27.481 mi

2h 02m 22s 2h 02m 19s 13.47 mph

13.48 mph 26.95 mph 1027 ft

1020 ft
Average Heartrate: 0 Max / Min Elevation: 358 ft 240 ft

Download GPX file: 02-24-2011.gpx

2/22/2011: Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 37' 54.21" / W 96° 19' 30.95" Heart: - Ele.: 99 m
0.000 mi 0s 0s - - - - -
2 N 30° 37' 21.92" / W 96° 19' 48.50" Heart: 0 Ele.: 88 m
5.005 mi 32m 48s 32m 46s 9.16 mph 9.16 mph 23.24 mph 253 ft 289 ft
3 N 30° 34' 45.09" / W 96° 17' 07.52" Heart: 0 Ele.: 84 m
5.003 mi 22m 06s 22m 05s 13.58 mph 13.59 mph 24.70 mph 167 ft 180 ft
4 N 30° 36' 00.54" / W 96° 19' 43.11" Heart: 0 Ele.: 96 m
5.004 mi 19m 12s 19m 12s 15.64 mph 15.64 mph 22.40 mph 167 ft 128 ft
5 N 30° 37' 54.23" / W 96° 19' 31.00" Heart: 0 Ele.: 95 m
3.026 mi 13m 24s 13m 24s 13.55 mph 13.55 mph 23.32 mph 108 ft 112 ft
18.038 mi

1h 27m 30s 1h 27m 27s 12.37 mph

12.38 mph 24.70 mph 696 ft

709 ft
Average Heartrate: 0 Max / Min Elevation: 348 ft 240 ft

Download GPX file: 02-22-2011.gpx

2/12/2011: Ride

Elevation Profile
Speed Profile

Distance Time Moving Time Average Speed Moving Speed Maxspeed Climb Up

Climb Down

1 N 30° 37' 54.12" / W 96° 19' 30.95" Heart: - Ele.: 95 m
0.000 mi 0s 0s - - - - -
2 N 30° 35' 09.83" / W 96° 18' 50.57" Heart: 0 Ele.: 78 m
5.011 mi 22m 20s 22m 20s 13.46 mph 13.46 mph 22.31 mph 180 ft 236 ft
3 N 30° 32' 12.94" / W 96° 20' 45.90" Heart: 0 Ele.: 72 m
4.995 mi 19m 22s 19m 22s 15.47 mph 15.47 mph 22.16 mph 207 ft 226 ft
4 N 30° 35' 22.47" / W 96° 20' 02.72" Heart: 0 Ele.: 89 m
5.000 mi 27m 16s 27m 16s 11.00 mph 11.00 mph 24.29 mph 269 ft 213 ft
5 N 30° 36' 17.90" / W 96° 18' 41.51" Heart: 0 Ele.: 83 m
4.995 mi 26m 34s 26m 21s 11.28 mph 11.37 mph 24.03 mph 269 ft 289 ft
6 N 30° 37' 54.23" / W 96° 19' 30.97" Heart: 0 Ele.: 93 m
3.864 mi 23m 49s 23m 48s 9.73 mph 9.74 mph 24.15 mph 230 ft 197 ft
23.864 mi

1h 59m 21s 1h 59m 07s 12.00 mph

12.02 mph 24.29 mph 1155 ft

1161 ft
Average Heartrate: 0 Max / Min Elevation: 404 ft 197 ft

Download GPX file: 02-12-2011.gpx

Twitter Delicious Facebook Digg Stumbleupon Favorites More