Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 14 August 2013

Municipal information security weaknesses, hacking, careers, & committees

Posted on 03:31 by Unknown
Here's some new content I've written recently on various information security topics you might be interested in:

Government Security: Uncovering Your Weaknesses (common vulnerabilities I see when performing security assessments for municipalities)

Eight questions to ask yourself before moving to C-suite management (are you really sure you want to do this!?)

IT career paths: Working for yourself is an attainable dream (if you want to stop working for the man)

Top 9 ways to prevent hacking in your enterprise (seriously, you can if you get these basics in check)

How to form a functional enterprise IT security committee (okay, I use the word 'functional' loosely, but it's nowhere but up from here right!?)

In the meantime, check out my website for links to all of my other information security-related content.

Cheers!

Well, in the spirit of my book Hacking For Dummies (be sure to check out the new 4th edition), here are some tips I've written for my friends at TechTarget and Acunetix on some important web and mobile application security issues you need to be tuned in to beyond all the noise that's out there:

Don’t Let Problems Stop You From Carrying Out Web Application Testing  (before 'Too Scared to Scan' was cool ;-)

Mobile app software: Avoid the perpetual cycle of insecurity

Hybrid security: Beyond pen testing and static analysis

Mac Malware Underscores Why You Can’t Ignore Web Security Threats

Do You Scan with Network Security Controls Enabled or Disabled?

Take Care in Handling the Results of Your Web Application Testing

Much more to come on web and mobile security testing...It's what I love doing and I've learned a tremendous amount while doing it over the past decade.

In the meantime, check out my website for links to all of my other information security-related content.


Cheers!
- See more at: http://securityonwheels.blogspot.com/#sthash.tO6G2DOv.dpuf
Well, in the spirit of my book Hacking For Dummies (be sure to check out the new 4th edition), here are some tips I've written for my friends at TechTarget and Acunetix on some important web and mobile application security issues you need to be tuned in to beyond all the noise that's out there:

Don’t Let Problems Stop You From Carrying Out Web Application Testing  (before 'Too Scared to Scan' was cool ;-)

Mobile app software: Avoid the perpetual cycle of insecurity

Hybrid security: Beyond pen testing and static analysis

Mac Malware Underscores Why You Can’t Ignore Web Security Threats

Do You Scan with Network Security Controls Enabled or Disabled?

Take Care in Handling the Results of Your Web Application Testing

Much more to come on web and mobile security testing...It's what I love doing and I've learned a tremendous amount while doing it over the past decade.

In the meantime, check out my website for links to all of my other information security-related content.


Cheers!
- See more at: http://securityonwheels.blogspot.com/#sthash.tO6G2DOv.dpuf
Read More
Posted in careers, consulting, low-hanging fruit, personal responsibility, security committees, security leadership, thinking long term, vulnerability assessments | No comments

Monday, 12 August 2013

You can't see the light 'til you open your eyes...

Posted on 06:15 by Unknown
I noticed a lot of interesting topics/news coming from the Black Hat conference last week such as:
  •  SSH Communications Security Unveils General Availability Of SSH Risk Assessor Tool
  • Preparing For Possible Future Crypto Attacks
  • Crack of mobile SIM card crypto and virtual machine features could let an attacker target and clone a phone 
  • HTTPS Hackable In 30 Seconds: DHS Alert
No doubt, these are all worthy topics that will help improve information security over the long haul...researched and presented by people who are much smarter than me.

Yet, given where most businesses are with information security today, we've got *much* bigger things to be concerned with such as:
  1. Network shares - open to anyone on the network - providing unfettered access to sensitive information
  2. No proactive event monitoring using the proper tools and expertise (outsource it!)
  3. Firewalls with no passwords or a complex rulebase with a lot of redundancy and risky rules
  4. Phones and tablets with zero security controls
  5. Laptops with no drive encryption (I know most laptops, according to business executives who know more about security than their IT staff, have "nothing of value"...like the ones listed here, but still)
  6. Database servers without passwords, or with default passwords, serving up PII and more to anyone with simple curiosity and a copy of SQL Server Management Studio or Heidi SQL.
  7. Physical security access control and IP video systems that are accessible to anyone on the LAN (sometimes even Wi-Fi) for track covering, system disabling, video deletione, tc.
  8. Operating systems with patch management software that are *still* missing critical updates that are exploitable using free tools to provide full admin access to the system without the attacker ever having to "log in"
  9. Web apps with SQL injection, rampant cross-site scripting, and login mechanisms that are easily manipulated
  10. Mobile apps that have yet to see an iota of security testing
These are all things I find on a consistent basis...Not because I'm smart but because they're very predictable and often go ignored.

"Can't see the light 'til you open your eyes" ...minimal yet insightful lyrics from one of my favorite bands, Black Country Communion. The "light" that people aren't seeing because they're being distracted by flashy headlines, sky is falling "exploits", valueless auditor mandates, or IT execs who are (ironically) "threatened" by information security is the very light that's going to end up biting them if they're not careful...such as the items listed above.

I read something recently from sales/achievement expert Jeffrey Gitomer that said "People who are cocky and arrogant say, I know that and move along. People who are confident and positive ask themselves How good am I at that? and seek to improve."

Great tie-in to the point I'm making. Which side are you on?

Concentrate on the fundamentals and nothing else for now and as long as it takes to ensure you have true control over the information security basics that have been around for decades. Otherwise, you're ignoring the obvious that will rear its head at some point. As we see time again in the research studies (Verizon DBIR, etc.), odds are much greater that you'll get bitten by something silly rather than a niche exploit that hits a relative few.

Finding and fixing the low-hanging fruit (the 20% of vulnerabilities that cause 80% of the problems) is something I've been advising for years and I'm going to keep doing it because that is where the risk is.
Read More
Posted in back to basics, compliance, incident response, low-hanging fruit, scary stuff, security leadership, stupid security, thinking long term | No comments

Thursday, 18 July 2013

Authenticated vulnerability scan pains...Rapid7 to the rescue.

Posted on 08:22 by Unknown
Apparently the folks at Rapid7 have people working on their Nexpose team that have actually performed security assessments for a living. You see, Nexpose has this seemingly trivial feature that can create a world of difference in the life of a security practitioner - it's part of the Site Configuration (i.e. scan settings) called Test Credentials as seen in the following screenshot:
 
Sanity brought about by people who use their own tools in real-world tests

Yep, with Nexpose you can actually test your login credentials before running authenticated vulnerability scans. Imagine that! The last time I remember seeing this feature was in Harris Corporation's STAT scanner about 10 years ago. Now, granted, I haven't used *every* vulnerability scanner out there but why don't we see this feature more often? Is it that difficult to implement programatically? Am I alone in the quest to work more efficiently?

Please, the common response of "Just because you can login doesn't mean you have the privileges to get the results you need" won't cut it...


It's clear - the payoffs of being able to test login credentials in a vulnerability scanner are huge. Some benefits include:
  • confirmation, in advance (key phrase: in advance), that your authenticated scans will actually run
  • less time spent waiting to see what vulnerabilities lie behind the login prompt (there's a LOT more than meets the eye)
  • no reduction in your available scan count (if you happen to be using a tool that charges on a per-scan basis)
  •  no time spent re-running scans (this can be worth hours of time, hassle, and embarassment)
  •  less cussing

I know...it seems trite and many vendors have shown that they're not interested in making such basic improvements to their scanners. I'm sorry - time is money. Given the all the complexities and pressures associated with performing security testing today, the last thing you need is a tool that actually creates more work.

Nexpose saves the day on this one. Kudos Rapid7. Whoever was responsible for this feature, I want to hug their neck.
Read More
Posted in cool products, security audits, security testing tools, stupid security, thinking long term, vulnerability assessments | No comments

Tuesday, 16 July 2013

Never forget this

Posted on 05:59 by Unknown
Although we strive to get others on our side, here's a good reminder from the late Richard Carlson that applies to IT and information security that we should always keep in mind:

"The sooner we accept the inevitable dilemma of not being able to win the approval of everyone we meet, the easier our lives will become".

Speaking of building your confidence and independence, here are some new articles I've written that can help:

Four steps to become a leader in IT problem-solving

Prioritize your IT tasks and finally conquer your to-do list 

Working in IT? Simple steps to get users on your side

In IT planning, try zero-based thinking

Getting hired in IT: How to stand out

As always, check out my website for links to all of my other information security-related content.
Much more to come on web and mobile security testing...It's what I love doing and I've learned a tremendous amount while doing it over the past decade.

In the meantime, check out my website for links to all of my other information security-related content.


Cheers! - See more at: http://securityonwheels.blogspot.com/#sthash.rbih1iU4.dpuf
Much more to come on web and mobile security testing...It's what I love doing and I've learned a tremendous amount while doing it over the past decade.

In the meantime, check out my website for links to all of my other information security-related content.


Cheers! - See more at: http://securityonwheels.blogspot.com/#sthash.rbih1iU4.dpuf
Much more to come on web and mobile security testing...It's what I love doing and I've learned a tremendous amount while doing it over the past decade.

In the meantime, check out my website for links to all of my other information security-related content.


Cheers! - See more at: http://securityonwheels.blogspot.com/#sthash.rbih1iU4.dpuf
Read More
Posted in careers, great quotes, information security quotes, Kevin's security content, politics, security leadership, selling security, thinking long term, time management | No comments

Monday, 15 July 2013

Infosec-related quote that strikes a chord

Posted on 06:43 by Unknown
I always love bringing philosophy, leadership, and personal responsibility into the information security discussion and here's one of the best quotes I've come across that resonates across all industries and businesses large and small:

"To see what is right and not do it is a lack of courage." - Confucius


What can you say to that...?

Let this be the fire within that you use to get (and keep) the right people on your side with security the second half of the year so you can have a stellar 2014.
Read More
Posted in careers, great quotes, information security quotes, personal responsibility, security leadership, thinking long term | No comments

Tuesday, 4 June 2013

The root of every infosec failure is...

Posted on 06:44 by Unknown
Time management expert Alec McKenzie once said what could be the most profound statement ever that applies directly to what we do (or don't do) in information security:

"Errant assumptions lie at the root of every failure."

How's your security program looking today?
Read More
Posted in great quotes, information security quotes, security leadership, stupid security, thinking long term | No comments

Friday, 24 May 2013

Quoted in the Wall Street Journal this week

Posted on 04:57 by Unknown
I was quoted in the Wall Street Journal (Tuesday May 21 edition)...it's a piece written by Gregory Millman talking about how senior executives are often at the root of information security problems. Check it out:

Corporate Security's Weak Link: Click-Happy CEOs 
Top Bosses, Exempt From Companywide Rules, Are More Likely to Take Cyber-Attackers' Bait

As I've written in the past, this is a big problem in businesses both large and small based on what I see in my work:

The BYOD Security Loophole


What to do when the CIO gets in the way of enterprise IT security

Read More
Posted in BYOD, careers, Kevin's interviews, kevin's quotes, Kevin's security content, malware, mobile security, security leadership, stupid security | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile