<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>yurisk.info &#187; Esafe</title>
	<atom:link href="http://yurisk.info/tag/esafe/feed/" rel="self" type="application/rss+xml" />
	<link>http://yurisk.info</link>
	<description>Technical Blog about IT Security and Networking</description>
	<lastBuildDate>Tue, 07 Sep 2010 12:42:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Website/malware categorization in eSafe</title>
		<link>http://yurisk.info/2009/06/12/websitemalware-categorization-in-esafe/</link>
		<comments>http://yurisk.info/2009/06/12/websitemalware-categorization-in-esafe/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 08:41:02 +0000</pubDate>
		<dc:creator>Yuri</dc:creator>
				<category><![CDATA[Esafe]]></category>

		<guid isPermaLink="false">http://yurisk.info/?p=162</guid>
		<description><![CDATA[If some website gets blocked by eSafe for being categorized wrongly you may fix it actually very simple. You enter the link below and change the website category; this takes some time , usually from few hours up to a day,for the change to take effect. If website has no category already then update takes [...]]]></description>
			<content:encoded><![CDATA[<p>If some website gets blocked by eSafe for being categorized wrongly you<br />
may fix it actually very simple. You enter the link below  and change the website category; this takes some time , usually from few hours up to a day,for  the change to take effect. If website  has no category already then update takes effect fast.</p>
<p><a href="http://filterdb.iss.net/urlcheck/">filterdb.iss.net/urlcheck/</a></p>
<p>To see what each category includes:<br />
<a href="http://www-935.ibm.com/services/us/index.wss/detail/iss/a1029077?cntxt=a1027244">www-935.ibm.com/services/us/index.wss/detail/iss/a1029077?cntxt=a1027244 </a></p>
<p>When you want to report an item that was falsely detected as virus/malware by<br />
eSafe you should send your request to :</p>
<p><img src="http://yurisk.files.wordpress.com/2009/06/info1.jpg" alt="info" title="info" width="383" height="49" class="alignnone size-full wp-image-167" /></p>
]]></content:encoded>
			<wfw:commentRss>http://yurisk.info/2009/06/12/websitemalware-categorization-in-esafe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eSafe Certified Professional</title>
		<link>http://yurisk.info/2009/03/07/esafe-certified-professional/</link>
		<comments>http://yurisk.info/2009/03/07/esafe-certified-professional/#comments</comments>
		<pubDate>Sat, 07 Mar 2009 15:30:52 +0000</pubDate>
		<dc:creator>Yuri</dc:creator>
				<category><![CDATA[Esafe]]></category>

		<guid isPermaLink="false">http://yurisk.info/?p=89</guid>
		<description><![CDATA[Recently I&#8217;ve taken the 2-day course and then successfully passed eSCP certification and here are some impressions about that. First, for serial certification obtainers,for the main question &#8211; what is the gain here? &#8211; I will frankly say &#8211; I don&#8217;t know. This cert isn&#8217;t found under &#8216;most wanted/hot/industry leading&#8217; headings anywhere, so whether it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I&#8217;ve taken the 2-day course and then successfully passed eSCP certification and here are some impressions about that. First, for serial certification obtainers,for the main question &#8211; what is the gain here? &#8211; I will frankly say &#8211; I don&#8217;t know. This cert isn&#8217;t found under &#8216;most wanted/hot/industry leading&#8217; headings anywhere, so whether it&#8217;s gonna get you an advantage in  promotion/job search/etc remains an open question.<br />
The course was fully funded by my work and I took part in it for the benfit  of the knowledge I would gain there only. And to take test is possible only after you passed the course. So , let&#8217;s head over to the course.<br />
The course was administered at 3rd-part learning center but by folks from Aladdin  itself ONLY &#8211; one of the strong points of the course. As I understood even if  the course would be given in the heart of Amazonia,Brazil it still would be presented by Aladdin folks, no &#8216;certified instructors&#8217; are employed.<br />
There were 2 instructors , one doing talking and helping in labs , and the other helping in labs . While first instructor  is from Presale team, she could answer any technical questions I had (&#8220;- Can you remind me name of the file to add Ip address to the interface so it survives reboot, unlike ifconfig ?&#8221;).</p>
<p>The overall course consisted of approximately 20% presentations/talks and  80% hands-on labs. The contents can be seen here, only that we dealt with  version 7 only, not 6.2 as in pdf: <a href="ftp://ftp.aladdin.com/pub/marketing/eSafe/Agenda/Expert_Agenda.pdf"><br />
ftp://ftp.aladdin.com/pub/marketing/eSafe/Agenda/Expert_Agenda.pdf</a> .<br />
Every pair of students was given Hellgate appliance to play with. And we used it to the full &#8211; our team even succeeded to push beyond the limit,crash and do RMA on our HellGate &#8211; fastest  RMA ever seen &#8211; took 5 mins to bring new Hellgate.</p>
<p>Everyone was given a book-sized course material including presentations we heard  and labs. The flow was &#8211; presentation then lab. Started with reimaging eSafe from usb, then all config labs as per pdf above. The LDAP lab took much more then was allocated for it as many (including me) are not good fiends with all the AD/LDAP/OU/CN/DN stuff ,eventhough the AD server was preconfigured and we had to  just(?) connect eSafe to it.<br />
Due to time shortage we haven&#8217;t done Web SSL/Reporter/Proxy (not a big deal for me as I am yet to see any of them in the wild) labs.<br />
All setup had access to the Internet , so URL-filtering we could test real-time.</p>
<p>To conclude &#8211; I enjoyed the course, learned lots of new things (my job involves  supporting already installed and working eSafe, so I don&#8217;t do  installing/configuring from scratch the appliance, something our integration department always do) and therefore it was worthwhile.<br />
Upon completion we were given link to password-protected CBT, possibility to open  personal account with portal.aladdin.com , link to download eSafe 7.1 ISO disk  (every eSafe has built-in evaluation license for 30 days), nice bag, and user/pass and link to the website to take exam.</p>
<p>Now to exam &#8211; it is a web based test, with 50 questions and 90 minutes to do it.<br />
The test is pretty easy given you took active part in the course before as it recaptures the same topics. So I did it in about 30 mins, got the web page  &#8220;Congradulations you passed&#8221; and a week later received by a courier framed certificate that I am now eSafe Certified Professional.</p>
]]></content:encoded>
			<wfw:commentRss>http://yurisk.info/2009/03/07/esafe-certified-professional/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eSafe download &#8211; demo, docs</title>
		<link>http://yurisk.info/2009/01/28/esafe-download-demo-docs/</link>
		<comments>http://yurisk.info/2009/01/28/esafe-download-demo-docs/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 18:48:10 +0000</pubDate>
		<dc:creator>Yuri</dc:creator>
				<category><![CDATA[Esafe]]></category>

		<guid isPermaLink="false">http://yurisk.info/?p=69</guid>
		<description><![CDATA[Today newcomer to our department asked me how he should start learning eSafe &#8211; should he install Mail or Gateway on VMware ? Erm &#8230; May be docs and manuals (as I did) ? No ,old-fashioned, in our age of CBTs/virtualization/Camtasia-everywhere buzzwords it needs to be with GUI and interactive, so &#8230; The best way [...]]]></description>
			<content:encoded><![CDATA[<p>Today newcomer to our department asked me how he should start learning eSafe &#8211; should he install Mail or Gateway on VMware ? Erm &#8230; May be docs and manuals (as I did) ? No ,old-fashioned, in our age of<br />
CBTs/virtualization/Camtasia-everywhere buzzwords it needs to be with GUI and interactive, so &#8230;<br />
The best way to start learning a product is first to see it <img src='http://yurisk.info/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  &#8211; for this Aladdin made a <strong>demo econsole. </strong><br />
After you run it it presents you with dosen of eSafe &#8221;machines&#8221; to any of which you can login by double clicking and feel like you are configuring a real eSafe machine &#8211; all GUI and options are exact copy of real<br />
product. You can get it here after filling form with (ir)relevant details.<br />
<a href="http://www.esafe.com/esafe/demo.aspx">Demo econsole </a></p>
<p>Here is the link for econsole download eSafe 7.1, be aware that is quite important that  you use econsole verison matching <span style="text-decoration:underline;">exactly </span>the<br />
eSafe software version you are trying to connect to. I once had client that installed eSafe 7.0 (some beta release) and downloaded locally econsole from the machine, all worked fine.Then he upgraded eSafe software to 7.1 but did  NOT reinstall  new econsole , as the  result<br />
he couldn&#8217;t find bunch of options in the econsole. In worst scenario using non-matching version of econsole to make configuration changes might cause substantial damage to the eSafe software, up to complete reinstall/reimage.<br />
<a href="http://rapidshare.com/files/278956115/esg_gui.exe" title="eSafe econsole 7.1"> eSafe econsole 7.1 </a><br />
<strong>Docs</strong> Also freely available at :<br />
<a href="http://www.esafe.com/support/esafe_documentation.aspx">eSafe Documenation</a><br />
<strong>Knowledgebase</strong> &#8211; if you work for Aladdin partner you will have access to<br />
complete knowledgebase , while anyone else can see a smaller part of it (that will suffice for few long<br />
weeks of studying nevertheless ).<br />
<a href="https://kb.aladdin.com">kb.aladdin.com </a></p>
]]></content:encoded>
			<wfw:commentRss>http://yurisk.info/2009/01/28/esafe-download-demo-docs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Esafe defaults and some debug commands</title>
		<link>http://yurisk.info/2008/09/06/esafe-defaults-and-some-debug-commands/</link>
		<comments>http://yurisk.info/2008/09/06/esafe-defaults-and-some-debug-commands/#comments</comments>
		<pubDate>Sat, 06 Sep 2008 08:50:57 +0000</pubDate>
		<dc:creator>Yuri</dc:creator>
				<category><![CDATA[Esafe]]></category>

		<guid isPermaLink="false">http://yurisk.wordpress.com/?p=9</guid>
		<description><![CDATA[As any other box esafe comes with some default configs , to much of my surprise it takes too long to find them in the Esafe docs, so here they are: eConsole TCP port: 43970 eConsole UDP port: 43982 Webmin TCP port: 37233    -    https to eSafe, when installed on linux  [last eSAfe to support Windows [...]]]></description>
			<content:encoded><![CDATA[<p>As any other box esafe comes with some default configs , to much of my surprise it takes too long to find them in the Esafe docs, so here they are:</p>
<p>eConsole TCP port: 43970<br />
eConsole UDP port: 43982<br />
Webmin TCP port: 37233    -    https to eSafe, when installed on linux  [last eSAfe to support<br />
Windows was eSafe 6 FR2]   (<a href="https://ip_address_of_esafe:37233">https://ip_address_of_esafe:37233</a>)</p>
<p> <br />
default  username: root<br />
default  password: kn1TG7psLu<br />
Webmin username: admin<br />
Webmin password: esafe<br />
econsole default username: admin<br />
econsole default pasword: no such, you will be asked to set on first login or during Webmin configuration<br />
 </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Product Configuration file:<br />
/opt/eSafe/eSafeCR/esafecfg.ini<br />
 <br />
Nitroinspection Configuration file:<br />
/opt/eSafe/esafenipca.ini<br />
 </p>
<p>eSafe Machine Configuration file:<br />
/opt/eSafe/esafe.ini<br />
eSafe Applifilter Configuration file:<br />
/opt/eSafe/eSafeCR/applifilter2.ini</p>
<p> &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Spool Directory:<br />
/opt/eSafe/eSafeCR/SPOOL/</p>
<p> Advanced antispam and URL filtering (cobion) database Directory:<br />
/var/esafe/ofdb/</p>
<p> Session log files:<br />
/opt/eSafe/eSafeCR/SessionLog/</p>
<p>Machine logs &#8211; when debug mode enabled logs get written here:<br />
/var/esafe/log/eSafeCR</p>
<p>Debugging procedure , quite standard procedure, provided load on the machine permits<br />
(High Debug mode loads the machine a lot!) you may shorten the time of troubleshooting<br />
when opening ticket in Aladdin.<br />
You need to re-create the problem first in high debug level (you can do it with eConsole: Options &gt; Troubleshooting&#8230; &gt; Clear Log Files &gt; choose High troubleshooting level &gt; re-create the problem &gt; choose &#8220;Off&#8221; to turn off troubleshooting level)</p>
<p>How to create support file:</p>
<p>cd /opt/eSafe<br />
./esafeinf<br />
Collecting eSafe info and log files, Please wait &#8230;</p>
<p>Information successfully logged in<br />
/var/log/1004562_xxxxxxx3430esglog.tar.gz.</p>
<p>or:</p>
<p>enter Webmin (<a href="https://ip_address_of_esafe:37233">https://ip_address_of_esafe:37233</a>) &gt; Support &gt; Create and download eSafe Support Info file<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>eSafe Machine configuration script (script has same functionality  as Webmin does):</p>
<p>cd /opt/eSafe<br />
./esgmenu</p>
]]></content:encoded>
			<wfw:commentRss>http://yurisk.info/2008/09/06/esafe-defaults-and-some-debug-commands/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
