Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 21 January 2013

Student information systems rife with security flaws

Posted on 06:35 by Unknown
Here's an interesting story from Slashdot today about a college student being expelled after pointing out flaws in his college's student information system.

What he's seeing is no surprise. Starting with my days working for IBM's EduQuest division, for the past 20 years or so I've seen numerous K-12 and higher education student information systems chock full of security flaws. Stupid, silly security flaws like SQL injection, cross-site request forgery, URL manipulation, no passwords - you name it...none of which should've been around 10 years ago, much less today. But they're there.

Folks, if you work for a K-12 school, university, or you're a parent curious about how your student's information is being handled (and protected), start asking questions like:
  • When was the last time this application was tested for security flaws? (their vendor's SSAE 16 report won't cut it)
  • What was done about the flaws that have been discovered up to this point? (even when flaws are found, many people still have political, financial, and time management hurdles that get in the way of improvements)
Someone needs to be in charge of managing these risks.

Certain people at the school level will tell you that student information is secure because their auditor ran Nessus and everything checked out okay. Need I say more?

The student information system vendors will tell you their applications are secure because they have good programmers. Again, based on what I've seen, they're most definitely not.

Even if the vendors delivered flawless code, there's still integration and customization unique to each school that can introduce some ugly stuff that puts student information at risk.

Be wary and don't be afraid to push the people responsible for making things right.
Read More
Posted in automated scanner oversights, FERPA, government regulations, pii, scary stuff, student information systems, third-party applications, web application security, web server security | No comments

Friday, 18 January 2013

Dear Neal Boortz,

Posted on 13:07 by Unknown
With this being your final day on the air, I thought it would be appropriate for me to send you a note of thanks for all you've done for me the past 20 years or so that I've listened to your radio show. Rather than wax poetic in paragraph format I want to list out the things you've taught me that have greatly enhanced my life.

Neal, you have taught me:

  • To be an independent thinker
  • To question liberals and conservatives - especially those who want to force their ideals upon us and control us using the police power of government
  • To work hard, really hard - and then keeping on working some more (the 40 hour work week is for losers indeed)
  • To take care of my health
  • To appreciate every moment with the people I really like to be around (I really miss Royal too)
  • To not be afraid to speak my mind if I feel strongly about something (you helped inspire the name of my company, Principle Logic)
  • To read, read, read and take in as much knowledge as possible
  • To be a better writer
  • To hold people accountable
  • To laugh
  • To go all out

My late mother, Linda Beaver, used to call me Neal Boortz Junior...all the time. She loved you too. I know she's happy for you as well.
 
With each day that passed this week, I got a bit choked up knowing that I was one day closer to losing the very inspiration and insight that has helped me reach such a great point in my life. Around 11:58am today, as you were signing off, it all came to a head and I broke down.

I owe you a debt of gratitude Neal. A big one. I wish I could repay you somehow.

Most importantly Neal, e n j o y  y o u r  r e t i r e m e n t. You're a very lucky man because of all the luck you've created - now go have some fun! Just know that you'll be greatly missed.

Adios MFer! ;-)

Sincerely,
Kevin Beaver
Read More
Posted in message from Kevin | No comments

Monday, 14 January 2013

How are you getting your points across?

Posted on 07:54 by Unknown
Here's a great point to remember regarding information security:

"A mediocre person tells. A good person explains. A superior person demonstrates. A great person inspires others to see for themselves." -Harvey Mackay
Read More
Posted in careers, security leadership, selling security, thinking long term, user awareness | No comments

Friday, 21 December 2012

IT security careers, committees, and corruption

Posted on 02:37 by Unknown
Here are some new pieces I've written on IT and security leadership (or lack thereof). Enjoy!

What to do when the CIO gets in the way of enterprise IT security

How to form a functional enterprise IT security committee

Understanding management gets your IT department what it needs

Five Concepts for IT Security Success

As always, check out principlelogic.com/resources for links to all of my information security whitepapers, podcasts, webcasts, books, and more.
Read More
Posted in careers, Kevin's security content, personal responsibility, scary stuff, security leadership, security management, selling security, stupid security, success | No comments

Sunday, 9 December 2012

What do credibility, BYOD, & mobile security have in common?

Posted on 13:41 by Unknown
They're the topics of three new pieces I've written!

I can't believe I've been writing more than ever lately but haven't kept up with my posts accordingly. In the interest of catching up, here's some new content I've written on mobile security, BYOD, and IT/security careers:

Credibility is the cornerstone of your career

As BYOD, cloud change networking, VPN management still indispensible

Top 10 reasons we have our heads in the sand over mobile security

By the way, you'll need to register with TechTarget to access the content but their membership is worth it - lots of great resources on practically every IT topic imaginable.

Enjoy!

As always, check out principlelogic.com/resources for links to all of my information security whitepapers, podcasts, webcasts, books and more.
Read More
Posted in BYOD, careers, Kevin's security content, mobile security, security leadership | No comments

Monday, 26 November 2012

Fix for painful authenticated web vulnerability scans requiring MFA

Posted on 07:12 by Unknown
Authenticated web security scans are one of the most frustrating parts of web security assessments. I mean they're downright painful, oftentimes seemingly impossible - especially if multi-factor authentication (MFA) technology is in use. Yet authenticated scans are critically important. It's scary how many times I uncover serious flaws (i.e. SQL injection) while logged-in as a typical user of a web site/application. That is if I can get my web vulnerability scanners to login and work properly!

Side note I have to bring up: I hate to think how many web security flaws are overlooked because people aren't testing their applications as authenticated users. Who am I to question it...

You see, the problem is that web vulnerability scanners are often tripped up with form-based logins. Why? Because they struggle to determine and maintain session state (the browser's/scanner's ongoing communication with the web application). Newer web technologies such as Flash and AJAX are big contributors to the problem, but web applications using MFA can be especially troublesome.

During a recent web security assessment, I struggled - hours on end - to get two different commercial vulnerability scanners to work with Oracle's Bharosa multi-factor authentication technology. I literally lost a day's worth of work trying to get these scanners to record login macros and properly maintain their session state so they could complete their scans.

What a frustrating scenario. The solution was simpler than I thought it'd be. I ended up using a third scanner - NTOSpider, which I've leaned on before to get me out of a bind in such situations - and it worked like a charm! What took me 6+ hours of pain and hassle with the other scanners (with no results, mind you), took just 6 minutes with NTOSpider.

I recorded the login macro, tested it, and got the scan rolling. It was amazingly simple. Given how much NTOSpider got logged out and had to log back in to the application, I could tell it was struggling a bit to maintain state, but it still WORKED! NTOSpider's feature that shows whether or not the scanner is current logged-in to the application is especially nice in these situations.

Side note I have to bring up: I can't imagine how many web security scans are deemed "complete" when they, in reality, failed to authenticate and properly test the application. I suspect this is a huge problem that's being overlooked all the time and people wonder why their web applications are hacked. Who am I to question it...

I'm a big advocate of using multiple scanners when testing web applications...just not in this context! But you've got to do what you've got to do in order to get good results. If you're testing web applications as authenticated users (you should!) and end up struggling to get your login macros to work, know that NTOSpider might just get you out of a bind like it did for me. Or, if it's one of your main scanners, prevent these problems in the first place.

Whether your applications use MFA, form-based logins, or good old-fashioned NTLM pop-up windows, just make sure you're using multiple scanners to test your web applications as they all tend to find unique flaws you probably can't afford to overlook. Oh, and never rely on scanners alone...do that and you'll surely get bitten.
Read More
Posted in automated scanner oversights, cool products, multi-factor authentication, penetration testing, scary stuff, security testing tools, web application security | No comments

Tuesday, 13 November 2012

Are you doing enough to protect your secrets? It's unlikely.

Posted on 07:25 by Unknown
If the person who heads the CIA can't keep his "secrets"; nothing's secret. It's as simple as that.

What are you doing to ensure your intellectual property is protected?

Lawyers will claim their contracts are enough. Management will leave their heads in the sand and claim their IT folks are handling it. Neither are enough.

Fix the silly/ridiculous/inexcusable low-hanging fruit on your network and then put the proper technologies and procedures in place to build things out from there. No matter how much money you've spent, how good your IT staff is, and how much you trust your employees, there's always room for improvement.
Read More
Posted in back to basics, intellectual property, low-hanging fruit, personal responsibility, scary stuff, stupid security, thinking long term | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile