+ -

Pages

Monday, December 28, 2015

LogRhytm: How to recover SA password on Microsoft SQL Server 2008 R2

This article will come very handy if you ever end up in a situation like I did.
MS SQL Server installed (while installing LogRhythm) without prompting me to pick a password for SA account. Guess what - cant login.
Have a read, if you cant fins the article, DM, I'll send you a PDF.

http://v-consult.be/2011/05/26/recover-sa-password-microsoft-sql-server-2008-r2/


5 RakshaTec: December 2015 This article will come very handy if you ever end up in a situation like I did. MS SQL Server installed (while installing LogRhythm) withou...

Wednesday, December 23, 2015

SIEM - LogRhythm Installation

This document shows the installation process for LogRhythm XM after the MS SQL server has been completely
installed and updated to SP3.

Run the Installation Wizard





For XM, select ALL of the options and click on Install








  All Green. Click on Exit. 
5 RakshaTec: December 2015 This document shows the installation process for LogRhythm XM after the MS SQL server has been completely installed and updated to ...

Tuesday, December 22, 2015

New 'Invoice' phishing campaign

JavaScript Malware is always interesting - this one from earlier today executes a process that connects back to whatdidyaysay.com - block that for starters and then tell staff not to open any 'invoice' attachments!


DM for complete pcap. 

5 RakshaTec: December 2015 JavaScript Malware is always interesting - this one from earlier today executes a process that connects back to whatdidyaysay.com - block t...

RansomWare with bonus KeyLogger

So you think its all about encryption? Think again - this ransomware comes with a bonus keylogger. DM for complete pcap.



5 RakshaTec: December 2015 So you think its all about encryption? Think again - this ransomware comes with a bonus keylogger. DM for complete pcap.

RansomWare using myexternalip.com

Interesting... This piece of ransomware get's victim's external IP by making queries frommyexternalip.com - which will give the malactor (I think I just came up with a new term!) your location, among other things.


Here's  the pcap. 
5 RakshaTec: December 2015 Interesting... This piece of ransomware get's victim's external IP by making queries from myexternalip.com - which will give the ma...

Monday, December 21, 2015

Staples Invoice Phishing campaign

Tell your staff not to open invoices that they are not expecting - Staples Invoice Phishing campaign.


5 RakshaTec: December 2015 Tell your staff not to open invoices that they are not expecting - Staples Invoice Phishing campaign.
< >