Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 12 August 2010

Apple's iPad - a forensic investigation in the making?

Posted on 05:59 by Unknown
Here's a new piece I wrote for SearchCompliance.com on regarding the realities and risks of iPads in the enterprise.
Enterprise iPads: Compliance risk or productivity tool?

Simply put, they're not all that different that other mobile computing devices but they do bring something unique to the table...

Speaking of "i" devices in the enterprise, here's a great read I saw recently in Information Week that outlines a scenario that's at the root of this problem:
Secret CIO: Deliver Strategic IT ... And My iPhone On Monday
Read More
Posted in forensics, Kevin's security content, mobile security, security leadership, stupid security | No comments

Metasploit enters the Web arena

Posted on 02:30 by Unknown
OK, Metasploit has had several Web-related exploits for years but HD and company are now getting serious about taking Web application scanning and exploitation to the next level.

As with Metasploit and Metasploit Express, there's only so much you can do with scanner and exploit tools so the verdict is still out. I love this innovation nonetheless.
Read More
Posted in cool products, metasploit, penetration testing, vulnerability assessments, web application security | No comments

Wednesday, 11 August 2010

Is car hacking the next big thing?

Posted on 11:45 by Unknown
For years I've been telling close friends who share my motorsports passion that we're going to start seeing cars getting hacked. I believe this to be especially true once cars are online and communicating with the "smart highway" system we're slowly approaching.

Well, we're now starting to see the beginning of such hacks. Some research was uncovered earlier this year on how a car's ECU (electronic control unit) can be manipulated in ways ranging from merely annoying the driver all the way to making them crash. The latest car hack uncovered involves the wireless tire pressure sensors in 2008+ automobiles (something the government mandated because of irresponsible drivers ignoring the maintenance required of their vehicles).

As with any computer system, if there's a hardware port, a wireless signal, or an IP address, then it's going to be exploitable/exploited. I just hope it doesn't start happening to me and my colleagues and on the racetrack! Wouldn't that be a fine how do you do?...

Can't wait to see the evolution of this. Sure, car hacking doesn't involve sensitive information...instead it involves something of much greater value: people's lives. I think this is going to be big, really big. Stayed tuned for more.
Read More
Posted in car hacking, personal responsibility, scary stuff, thinking long term | No comments

Great information security quote (don't believe the hype)

Posted on 06:37 by Unknown
There's a Japanese proverb that fits nicely into infosec:

"If you believe everything you read, perhaps it's better not to read."

Be it F.U.D., vendor hype, or "experts" who claim the sky is falling with every new exploit they uncover - you ultimately need to focus on doing what's best in your environment under your terms.
Read More
Posted in information security quotes, personal responsibility, security leadership, stupid security | No comments

Avoid the temptation to go nowhere

Posted on 06:30 by Unknown
The cancellation of Tony Robbins show after just two episodes underscores how many people aren't interested in learning more about getting ahead in life. Instead, mindless drivel is the "norm" of today.

If you want to make things happen, dare to be different.
Read More
Posted in careers, personal responsibility, success | No comments

Monday, 9 August 2010

How you can get developers on board with security starting today

Posted on 16:42 by Unknown
Some people - including a brilliant colleague of mine - think security is not the job of software developers. In the grand scheme of things I think such an approach is shortsighted and bad for business. It's kind of like an auto assembly line worker not being responsible for the quality of his work or citizens not being responsible for their own healthcare (oh wait!) or why the bottom 50% of income earners in the U.S. shouldn't be responsible for paying their fair share. It's always someone else's problem. Sadly, "responsibilities" without ramifications is the way things are in most societies today.

Getting back to the point, getting developers on board with security - as we've seen over the past decade - is most certainly NOT one of those things that's going to magically happen. So is it even possible to get developers on board with security? I think so. But you have to be smart about it. You can't just say "You! Write secure code!" Ha, if it were only that easy. There are many gotchas along the way so you have to come up with a solid game plan. I wrote about the problem and some solutions in a new piece you may want to check out:

Getting developers on board with security – once and for all

Speaking of developers and security flaws, here are some more articles I've written recently for TechTarget's SearchSoftwareQuality.com that you may be interested in:

Application security checklist: Finding, eliminating SQL injection flaws

Finding cross-site scripting (XSS) application flaws checklist

Happy reading and most of all, good luck!
Read More
Posted in cross-site scripting, Kevin's security content, personal responsibility, sdlc, security leadership, selling security, software development, SQL injection, web application security | No comments

A bit of inspiration

Posted on 12:14 by Unknown
I'm back from my last break of the summer and thought I'd share this quote I came across for a bit of inspiration:

"A successful life is one that is lived through understanding and pursuing one's own path, not chasing after the dreams of others." -- Chin-Ning Chu

This reminds me of another great quote which says "If you don't have goals for yourself you're doomed forever to achieve the goals of someone else."

Whether you're in need of some focus for your career or for your internal information security initiatives, here are some other pieces I've written on goal setting that may help...studying this subject has certainly helped me.

Eight steps to accomplishing your IT career goals (can be applied to all types of goal setting)
My blog posts on goal setting and IT and information security careers
Related articles I've written on IT and information security careers
My Security On Wheels audio programs providing security learning for IT professionals on the go
Read More
Posted in audio programs, careers, goal setting, great quotes, information security quotes, security leadership | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile