We have all embraced online searching and shopping. The days of driving around town to compare costs or referring to the most current newspaper advertisement for a bargain have long gone. Today’s consumer reaches out via the Internet on a variety of devices to check product reviews, find discount coupons, locate attractions, and read email sales notices from their favorite companies. Click Here To Continue Reading
Author Archives: Mike
Nemucod Adds Ransomware Routine
It came to our attention that a new, rather peculiar version of Nemucod has been recently landing on users. Nemucod is a well-known JavaScript malware family that arrives via spam email and downloads additional malware to PCs. Most recently, Nemucod has been known to download TeslaCrypt ransomware variants.
However, the last few weeks saw a shift in Nemucod variants–it now has a code to drop ransomware from its body. The sample arrives via a typical Nemucod spam with encrypted JavaScript attachment.
Upon decrypting the JavaScript, we can see that it attempts to download a file on the user’s temporary directory from compromised websites. The downloaded file is an executable file that is later on used to encrypt the user’s files: Click Here To Read The Rest of The Article
Enable date and time voicemail was recorded
Question: Is it possible to configure time stamps for voicemail when they are recorded enabling you to know when a user left the message?
Answer: Absolutely, in fact, it comes on by default. The only real thing you need to do is ensure that the date and time are properly set on your system. Below is a list of means to access the time stamps.
Timestamp for voice messages can be viewed in three different ways:
1) voicemail to email will include timestamp info, i.e.
Voice Mailbox 451 – Sales
New message from XXX XXX XXXX IRON OAK IT INC
Received: Friday, March 20 at 11:52am
Length: 40 seconds
Total un-reviewed messages: 1
Total saved messages: 6
2) When listening to messages on a local or remote phone, press 5 to listen to message info including date and timestamp
3) You can open the Voicemail Manager option in the management console.
From there you can download all the messages from a mailbox, and the filenames will include date and time info, i.e.:
– [NEW][PRO LINK MORTG][1403xxxxxxx]~150401084901.wav
the number at the end shows 2015 april 1st at 8:49:01 AM
Site to Site VPN Performance issues
Question: Was asked this a while back and while surfing the net it jogged my memory. A user was experiencing pretty poor performance when using site to site VPN’s. This is going to show the age of the question as they were using FortiOS 5.0.5. Normally, this is because of a bug relating to NPU acceleration on the tunnel experiencing the degraded performance. You can disable NPU acceleration for said tunnel and you will usually resolve the issue. Use the commands below.
config vpn ipsec phase1-interface
edit <tunnel name>
set npu-offload disable
end
Replacing hardware that is logging to a FortiAnalyzer
I am sure you have all come across this issue. You are logging your FortiGates (or other devices) to the FortiAnalyzer and you experience a failure of said hardware. You have a backup of the config so you move the config over to the replacement device but now your new firewall or device is listed as an unregistered device in the FortiAnalyzer. This is actually a pretty easy issue to fix as you only have to replace the serial number of the original device with the serial of the new device. Below is the config steps to perform this via CLI of the FortiAnalyzer:
execute device replace <old serial number> <name> <new serial number>
FortiAuthenticator SCAP Auto-Enroll
Connecting To The Web Based Manager – FortiAnalyzer 5.2
Connecting to the Web-based Manager
The FortiAnalyzer unit can be configured and managed using the Web-based Manager or the CLI. This section will step you through connecting to the unit via the Web-based Manager.
To connect to the Web-based Manager:
- Connect the unit to a management computer using an Ethernet cable.
- Configure the management computer to be on the same subnet as the internal interface of the FortiAnalyzer unit:
- IP address: 192.168.1.2
- Netmask: 255.255.255.0.
- On the management computer, start a supported web browser and browse to https://192.168.1.99.
- Type admin in the User Name field, leave the Password field blank, and select Login.
You should now be able to use the FortiAnalyzer Web-based Manager.
System Requirements – FortiAnalyzer 5.2
System requirements
Web browser support
The FortiAnalyzer Web-based Manager supports the following web browsers:
- Microsoft Internet Explorer versions 10 and 11
- Mozilla Firefox versions 30 and 31
- Google Chrome version 36
Other web browsers may function correctly, but are not supported by Fortinet.
Screen resolution
Fortinet recommends setting your monitor to a screen resolution of 1280×1024. This allows for all the objects in the Web-based Manager to be properly viewed.