Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 31 May 2011

An unintended consequence of fast food "going green"

Posted on 09:54 by Unknown
I was just pondering the negative side-effects and unintended consequences of many of the fast food restaurants who are "going green" (I use that term loosely because it's so overused in the name of marketing). The thing is so many restaurants like Panera and Moe's as well as countless others I've visited in my travels this year have these flimsy plastic Solo (and other brand) cups that aren't worth a flip.

You see, you can't put on a lid on these paper-thin nuisances without crushing the entire thing...and spilling your drink, and using a half-dozen napkins to clean up your mess, and having to get a new cup and then having to refill your drink...you get my drift. When this happens - and it's happening to me and others a lot (witnessed it 3 times in the past 2 days) - just how much is that flimsy plastic cup truly impacting the environment!?

Instead of hopping on the "going green" for show bandwagon and bowing at the altar of "global warming", how about these businesses start placing some darned recycle bins in their restaurants!? I may be wrong (I often am) - it just seems like that'd be a wiser solution. Selfishly speaking, if anything it'd keep me from having to haul my cups home every time so I can recycle them myself.
Read More
Posted in global warming, scary stuff | No comments

Ever heard of "gruntled" workers?

Posted on 07:05 by Unknown
We always hear about "disgruntled workers" wreaking havoc on computer systems and sensitive information. Interestingly we never hear about "gruntled" workers and how they can help improve security...

Thanks to a Merriam Webster's "Word of the Day" I came across I now know that there's another side to the overused word "disgruntled". Interestingly, according to M-W, the prefix "dis-" usually means "to do the opposite of," hence the assumption that if there is a "disgruntle," there must have first been a "gruntle" with exactly the opposite meaning. Apparently "dis-" doesn’t always work that way...

No matter how old we get we learn something new every day...Here's to happy, content, and gruntled workers contributing more to information security than they take away! ;-)
Read More
Posted in security awareness, security leadership, user awareness | No comments

Wednesday, 25 May 2011

Web appsec compliance & low-hanging fruit - it's all up to us!

Posted on 14:02 by Unknown
Here are some recent pieces I wrote on Web application security common sense for my colleagues at Acunetix that you may be interested in:

But Compliance is Someone Else’s Job!


Low-hanging fruit becomes big news with the 2011 Verizon Data Breach report

Going Beyond Confirmed Web Security Flaws

Enjoy!

As always, be sure to check out www.principlelogic.com/resources.html for links to my 500+ articles, whitepapers, podcasts, webcasts, books and more.
Read More
Posted in back to basics, compliance, Kevin's security content, low-hanging fruit, security leadership, stupid security, web application security | No comments

Texas Comptroller's Office IT woes = security breach

Posted on 11:45 by Unknown
Here's a Dallas Morning News story I was interviewed for - interesting IT woes in the Texas comptroller's office:

Texas comptroller’s tech office had high turnover, employee complaints before breach

Thanks go out to Kelly Shannon and my colleagues over at Focus.com for getting me involved.
Read More
Posted in Kevin's interviews, scary stuff, stupid security | No comments

If you don't have NetScanTools Pro v11, you're missing out

Posted on 06:53 by Unknown
It's been a long time coming but the latest incarnation of one of my favorite network/security tools - NetScanTools Pro v11 - is out. Kirk Thomas at Northwest Performance Software has done a bang-up job on the user interface in the new version...something that's gotten better - albeit slowly - over the years. Not that I could do any better - I can't imagine having to know network protocols at this level AND be good at UI design at the same time. ;) Anyway, here's a sample of the new user experience:


















NetScanTools Pro v11 also has the following new features that stood out to me:
  • support for IPv6 (pretty cool, now we just need businesses that use it!)
  • SNMP Scanner (which has an SNMP dictionary attack tool for cracking community strings for further system enumeration)
  • Connection Monitor (a neat tool that listens for incoming connections - great for all sorts of network and security stuff)
The Promiscuous Mode Scanner (for finding sniffers on the network), Packet Generator (for, well, generating network packets) and Email Validate (for email testing) tools are nice as well.

Probably the most under-rated tool of all developed by Northwest Performance Software is the Switch Port Mapping Tool which can help take the pain out of figuring out what's where.

I'm not crazy about the lack of automation during the initial setup and licensing process when getting NetScanTools Pro up and running. That said Kirk was very responsive with the registration code I needed to complete the process.

For $249 ($299 for the portable USB version) there's no reason to *not* have an all-in-one network toolset like NetScanTools Pro. The time savings and convenience factors alone that come with having the tools you need in one location will pay for the program over and over again. Check it out.
Read More
Posted in cool products, network analysis, network protocols, security testing tools | No comments

Monday, 23 May 2011

Sony PlayStation discussion download

Posted on 05:48 by Unknown
In case you missed our Sony PlayStation Security Fiasco roundtable discussion last week, here's a link to the MP3 recording.

Enjoy!
Read More
Posted in data breaches, hacking, Kevin's interviews, Kevin's security content, podcasts | No comments

Recap of TechEd 2011: more of the same, but you need to go

Posted on 05:07 by Unknown
Given that TechEd was held in my neck of the woods this year I couldn't resist the opportunity to check it out. It's funny, I've been working with/around Microsoft products for some 22 years now and I've *never* attended this show. Maybe it's my ingrained Novell bigotry that I've yet to shed.

My main goal was to catch up with some clients and see the latest happenings with Security Compliance Manager (SCM). I say that because I'm working with Microsoft on the development of this product and wanted to see/hear the team cover the new version 2.0 currently available as a CTP. If you're not familiar with SCM, you really should check it out....it's a good tool/resource that can help you fine tune your configuration baselines for various Microsoft products (Windows, SQL Server, IE, etc.). I know security standards are boring and unsexy but, seriously, how are you going to support your policies, please your auditors and manage your risks otherwise?

I also spoke with some other clients and colleagues at/after the show who said they grew tired of Microsoft's cloud push all week. Oh well, TechEd is as much about marketing Microsoft than anything else, no? And given the money they must drop on such an event, can you blame them? That said I did hear from a few people that they loved the technical detail of some of the sessions. It reminded me of when I used to do network administration/management early on in my career and attended Novell's BrainShare conference. Going to that show every year and hearing/seeing the technical details of Novell's software that weren't available otherwise no doubt made me a sharper IT guy. The same goes for TechEd - if you're hands-on with Microsoft products on a daily basis (really who isn't in IT?) then you really need to check it out.

Overall, the conference was not all that different than other IT/security shows. You know how the marketers and bloggers often make things out to be new and exciting and then once you're there you see that's not really the case...? TechEd was the same old type of show we've all attended: tons of vendor glitz, tons of sessions (some good, some bad) and tons of information that the human brain is really not capable of absorbing in such a short period time (at least not my feeble brain)....but it was still worth it.

Attending TechEd made me realize that I need to keep attending TechEd. If anything just so I can keep up with the current tools, products and trends from Microsoft and see everything up close. The vendor chachkis aren't bad either. Maybe I'll see you there next year?
Read More
Posted in compliance, conferences, security tools, Windows | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile