<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Syncio Blog - ISA</title>
    <link>http://sync-io.net/go/blog/</link>
    <description>fixitchris@twitter</description>
    <language>en-us</language>
    <copyright>Chris Misztur</copyright>
    <lastBuildDate>Wed, 18 Jun 2008 19:15:11 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.0.7226.0</generator>
    <managingEditor>chris@sync-io.net</managingEditor>
    <webMaster>chris@sync-io.net</webMaster>
    <item>
      <trackback:ping>http://sync-io.net/go/blog/Trackback.aspx?guid=ddb0e831-f195-42f0-8975-85851e39eb9f</trackback:ping>
      <pingback:server>http://sync-io.net/go/blog/pingback.aspx</pingback:server>
      <pingback:target>http://sync-io.net/go/blog/PermaLink,guid,ddb0e831-f195-42f0-8975-85851e39eb9f.aspx</pingback:target>
      <dc:creator>Chris</dc:creator>
      <wfw:comment>http://sync-io.net/go/blog/CommentView,guid,ddb0e831-f195-42f0-8975-85851e39eb9f.aspx</wfw:comment>
      <wfw:commentRss>http://sync-io.net/go/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=ddb0e831-f195-42f0-8975-85851e39eb9f</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Using the <a href="http://msdn.microsoft.com/en-us/library/ms816051.aspx">FPCCacheContents</a> Object
I was able to force-cache any file I wanted for any duration I wanted.  
</p>
        <p>
1.  I downloaded Cain&amp;Abel executable from source #1 and Kaspersky blocked
it.  I verified that traffic was coming from souce #1 with Wireshark. 
<br />
2.  I force-cached Cain&amp;Abel executable from source #2 to avoid IE caching
or anything that might invalidate this test.  The item now exists in ISA cache. 
<br />
3.  I downloaded Cain&amp;Abel executable from source #2 again.  I verified
that traffic was indeed coming from ISA Cache with Wireshark.  
<br />
I turned up KAV log files to Debug and verified that the Cain&amp;Abel executable
has not been flagged the first time it was downloaded.  Kaspersky blocked Cain&amp;Abel
from ISA Cache.<br />
  
<br />
Conclusion: 
</p>
        <ul>
          <li>
HTTP Kaspersky engine interfaces with cache and routed requests.  
</li>
          <li>
Anything can be forced into ISA cache. 
</li>
        </ul>
        <p>
See the ISA Monitor Utility for cache control.  <a href="http://sync-io.net/IsaTools.aspx">http://sync-io.net/IsaTools.aspx</a></p>
        <img width="0" height="0" src="http://sync-io.net/go/blog/aggbug.ashx?id=ddb0e831-f195-42f0-8975-85851e39eb9f" />
      </body>
      <title>ISA 2006 Cache and HTTP Kaspersky Antivirus</title>
      <guid isPermaLink="false">http://sync-io.net/go/blog/PermaLink,guid,ddb0e831-f195-42f0-8975-85851e39eb9f.aspx</guid>
      <link>http://sync-io.net/go/blog/2008/06/18/ISA2006CacheAndHTTPKasperskyAntivirus.aspx</link>
      <pubDate>Wed, 18 Jun 2008 19:15:11 GMT</pubDate>
      <description>&lt;p&gt;
Using the &lt;a href="http://msdn.microsoft.com/en-us/library/ms816051.aspx"&gt;FPCCacheContents&lt;/a&gt; Object
I was able to force-cache any file I wanted for any duration I wanted.&amp;nbsp; 
&lt;/p&gt;
&lt;p&gt;
1.&amp;nbsp; I downloaded Cain&amp;amp;Abel executable from source #1 and Kaspersky blocked
it.&amp;nbsp; I verified that traffic was coming from souce #1 with Wireshark. 
&lt;br&gt;
2.&amp;nbsp; I force-cached Cain&amp;amp;Abel executable from source #2 to avoid IE caching
or anything that might invalidate this test.&amp;nbsp; The item now exists in ISA cache. 
&lt;br&gt;
3.&amp;nbsp; I downloaded Cain&amp;amp;Abel executable from source #2 again.&amp;nbsp; I verified
that traffic was indeed coming from ISA Cache with Wireshark.&amp;nbsp; 
&lt;br&gt;
I turned up KAV log files to Debug and verified that the Cain&amp;amp;Abel executable
has not been flagged the first time it was downloaded.&amp;nbsp; Kaspersky blocked Cain&amp;amp;Abel
from ISA Cache.&lt;br&gt;
&amp;nbsp; 
&lt;br&gt;
Conclusion: 
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
HTTP Kaspersky engine interfaces with cache and routed requests.&amp;nbsp; 
&lt;li&gt;
Anything can be forced into ISA cache. 
&lt;/li&gt;
&lt;/ul&gt;
&gt;
&lt;p&gt;
See the ISA Monitor Utility for cache control.&amp;nbsp; &lt;a href="http://sync-io.net/IsaTools.aspx"&gt;http://sync-io.net/IsaTools.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://sync-io.net/go/blog/aggbug.ashx?id=ddb0e831-f195-42f0-8975-85851e39eb9f" /&gt;</description>
      <comments>http://sync-io.net/go/blog/CommentView,guid,ddb0e831-f195-42f0-8975-85851e39eb9f.aspx</comments>
      <category>ISA</category>
      <category>Malware</category>
    </item>
    <item>
      <trackback:ping>http://sync-io.net/go/blog/Trackback.aspx?guid=2e4ee447-abe3-4ba5-98c0-f8a8d1876179</trackback:ping>
      <pingback:server>http://sync-io.net/go/blog/pingback.aspx</pingback:server>
      <pingback:target>http://sync-io.net/go/blog/PermaLink,guid,2e4ee447-abe3-4ba5-98c0-f8a8d1876179.aspx</pingback:target>
      <dc:creator>Chris</dc:creator>
      <wfw:comment>http://sync-io.net/go/blog/CommentView,guid,2e4ee447-abe3-4ba5-98c0-f8a8d1876179.aspx</wfw:comment>
      <wfw:commentRss>http://sync-io.net/go/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=2e4ee447-abe3-4ba5-98c0-f8a8d1876179</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I recently came across MalwareDomains.com.  They provide a list of domain names
that have been associated with malware.  The list contains over 21000 valid entries
and I have decided to integrate it with ISA 2006 since it's rare to find such a free
resource that is actually kept up to date.
</p>
        <p>
The import tool is available here: <a href="http://sync-io.net/IsaTools.aspx">http://sync-io.net/IsaTools.aspx</a><a href="http://sync-io.net/Public/ISA_MalwareDomains_BETA.zip" target="_blank" rel="nofollow"><span class="yshortcuts" id="lw_1208912100_0"></span></a></p>
        <p>
Basically, you're able to import the domain.txt file into ISA as a URL or DNS set. 
Then you just set your deny access rule and away you go.  This utility can run
as a scheduled task.
</p>
        <img width="0" height="0" src="http://sync-io.net/go/blog/aggbug.ashx?id=2e4ee447-abe3-4ba5-98c0-f8a8d1876179" />
      </body>
      <title>Stopping Malware with ISA 2006</title>
      <guid isPermaLink="false">http://sync-io.net/go/blog/PermaLink,guid,2e4ee447-abe3-4ba5-98c0-f8a8d1876179.aspx</guid>
      <link>http://sync-io.net/go/blog/2008/04/23/StoppingMalwareWithISA2006.aspx</link>
      <pubDate>Wed, 23 Apr 2008 01:09:16 GMT</pubDate>
      <description>&lt;p&gt;
I recently came across MalwareDomains.com.&amp;nbsp; They provide a list of domain names
that have been associated with malware.&amp;nbsp; The list contains over 21000 valid entries
and I have decided to integrate it with ISA 2006 since it's rare to find such a free
resource that is actually kept up to date.
&lt;/p&gt;
&lt;p&gt;
The import tool is available here: &lt;a href="http://sync-io.net/IsaTools.aspx"&gt;http://sync-io.net/IsaTools.aspx&lt;/a&gt;&lt;a href="http://sync-io.net/Public/ISA_MalwareDomains_BETA.zip" target=_blank rel=nofollow&gt;&lt;span class=yshortcuts id=lw_1208912100_0&gt;&lt;/span&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Basically, you're able to import the domain.txt file into ISA as a URL or DNS set.&amp;nbsp;
Then you just set your deny access rule and away you go.&amp;nbsp; This utility can run
as a scheduled task.
&lt;/p&gt;
&lt;img width="0" height="0" src="http://sync-io.net/go/blog/aggbug.ashx?id=2e4ee447-abe3-4ba5-98c0-f8a8d1876179" /&gt;</description>
      <comments>http://sync-io.net/go/blog/CommentView,guid,2e4ee447-abe3-4ba5-98c0-f8a8d1876179.aspx</comments>
      <category>Malware</category>
      <category>VB.NET</category>
      <category>ISA</category>
    </item>
  </channel>
</rss>