Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 2 September 2010

Crunch risk numbers or fix the obvious?

Posted on 04:46 by Unknown
My colleague Ben Rothke (@benrothke) recently wrote a good piece on basing information security decisions on good data. I like his approach - it'll make you think. It's true we do need good data so we can make better decisions. Sadly, we often don't have the data or, if we do, we're not qualified to interpret it.

Maybe it's just me but I don't believe my degrees in computer engineering and management of technology qualify for "enterprise statistician". That still doesn't make information security oversights okay. The dilemma reminds of something that Gilbert Arland once said: "Failure to hit the bullseye is never the fault of the target." We do need good data. It's just not that simple in the world of information security.

The problem is similar to the underlying principle of goal setting and leadership: how are you going to know where to go if you don't know where you're going, much less how to get there?

The reality is, we're never - at least for the foreseeable future - going to have all the right data to make good information security decisions. We have to do the best with what we've got. But that shouldn't keep us from focusing on what's obviously important. Case in point I can say based on experience that the majority of organizations I've seen (both small and large) haven't even addressed the basics of information security. Why burden ourselves with complex risk calculations when the bleeding and the cure are right before our eyes?

Don't get me wrong. Quantifiable risk calculations have their place in our industry. But unless and until we get the basic stuff under control, what's the point of making things even more complicated? I'm just saying.

Staying tuned for Part 2 of Ben's article...
Read More
Posted in back to basics, great quotes, information security quotes, low-hanging fruit, risk analysis, security assessments | No comments

The case for zero-day testing

Posted on 04:28 by Unknown
Here's a good piece by David Maynor regarding penetration testing and whether or not zero day exploits should be used. I agree with David. With penetration testing, ethical hacking, vulnerability assessments - whatever you want to call them - anything should be fair game. That is if you want a real-world view of what's at risk. Limiting your tests could skew the results and you'll end up with a false sense of security when nothing big turns up.
Read More
Posted in penetration testing, vulnerability assessments | No comments

Tuesday, 31 August 2010

NetScan Tools LE - a must-have for investigators

Posted on 09:57 by Unknown
Have you ever had a need to run a program and get a relatively small amount of data just to do your job but end up getting caught in the complexity of the application and not getting what you need after all? That's happened to me a bunch.

Well, NorthWest Performance Software (makers of a long-time favorite of mine: NetScanTools Pro) has a new tool that helps resolves this problem called NetScanTools LE. Designed for law enforcement investigators (hence the "LE"), prosecutors, corporate security folks and the like, NetScanTools packages the ability to gather information on IP addresses, domain names, hostnames, and email addresses all in one concise program. It's for the non-technical types who just want the basics...get in and get out. Given its investigative approach, the tool is case driven and includes timestamps and even packet capturing to help investigators prove they did what they say they did while gathering their data. It's really inexpensive to boot.

Included functions are:
  • ping sweeping
  • port scanning
  • IP to country mapping
  • email validation
  • Whois lookups
  • RBL checks
  • text-only Web page grabber (I really like this)
The following screenshot shows the clean interface of NetScanTools LE:






























While I'm on the subject of cool tools, if you've never checked out NetScanTools Pro, you really should. It's chock full of even more utilities (all in one place, albeit bordering on the complex) those of us in IT and security can benefit from. I have a need for such tools on practically a daily basis.

Furthermore, Kirk Thomas who heads up NorthWest Performance Software is very attentive and eager to get feedback on his products in order to make them better. And based on our conversations I like how he thinks.
Read More
Posted in cool products, forensics, incident response, network analysis, network security, security tools | No comments

Monday, 30 August 2010

"New" Web security content to check out

Posted on 07:38 by Unknown
Here are several new links to some recent (and, due to my crazy year, not so recent) articles I've written for various TechTarget sites on the subjects of Web application and server security:

Web server weaknesses you don't want to overlook
(the "rest of the story" of Web flaws)

SQL injection tools for automated testing (a must-have for your toolkit)

Beefing up SSL to ensure your applications are locked down (good for some of those often-reported PCI DSS compliance gotchas)

Common security flaws to check for on your Linux-based Web systems
(overlooked Linux systems are a great facilitator of Web vulnerabilities)

Enjoy!
Read More
Posted in Kevin's security content, Linux, pci dss, SQL injection, ssl, web application security, web server security | No comments

Friday, 27 August 2010

HIPAA & HITECH: new requirements + same approaches = new book

Posted on 07:51 by Unknown
My colleague and co-author Becky Herold and I are working on the second edition of our HIPAA book and I'm realizing, wow, not much has changed in the way of managing information risks since we first wrote it in 2003. Yet, the protected health information breaches keep on occurring (look at the two latest ones from this week).

Stay tuned though...we've got lots of good updates and new info forthcoming on HIPAA and the HITECH Act that can help you forge your way through the compliance mess.
Read More
Posted in compliance, hipaa, hitech act, Kevin's books | No comments

Work harder on yourself than you do on your job

Posted on 07:43 by Unknown
Many people want to take the easy path that promises to lead them to their riches rather than work hard over the long term and earn it the good old-fashioned way. It's the lottery mentality. James Allen said it best:

"Men are anxious to improve their circumstances, but are unwilling to improve themselves; they therefore remain bound."


Want to get begin improving your circumstances in your life and in your IT/security career? Here are some pieces I've written and an audio program I recorded that can help you get started.
Read More
Posted in careers, goal setting, great quotes, information security quotes, personal responsibility | No comments

Thursday, 26 August 2010

Good new book on security awareness

Posted on 05:47 by Unknown
I have to admit, when my colleague Marcos Christodonte first approached me about reviewing his new security awareness book, Cyber Within, I thought here's yet another book on boring old security awareness. I was wrong. Cyber Within takes a very unique (suspense novel-like) approach to address the problem we have with employees and information security. And it works.

The book is a quick read - just 47 pages - but it's just enough to help drive home the message that employees are our worst enemy when it comes to security. The book also has some cut-out forms in the back for reporting incidents and employee quick tips you can use during your security training.

The argument could be made that everything in the book falls into place too easily but I still think it's a good read and a good resource. Kudos to Marcos. Heaven knows we need some original - and non-plagiarized - material in our field these days!

You can check it out Cyber Within on Amazon by clicking the book cover below:


Read More
Posted in cool products, recommended books, rogue insiders, scary stuff, security awareness, stupid security, user awareness | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile