Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 28 February 2013

Mobile app security assessments

Posted on 14:13 by Unknown
I wrote recently about performing source code analysis for mobile apps. I'm seeing some crazy stuff that I didn't think I'd see in mobile apps (but I'm not really surprised) related to session manipulation, hard-coded cryptographic keys and the like which underscores the importance of the exercise.

But there's another side to mobile app security assessments - it's simply manual analysis. That is poking around with the apps and the mobile devices using good tools and proper techniques to find and demonstrate security and forensic-related flaws that aren't uncovered in traditional user, functional, and QA testing. In recent application assessments, I've found things like:
  • login-related weaknesses
  • information mishandling
  • insecure interactions with external applications/systems
  • exploits in general functionality that put PII at risk
Odds are good that you or someone you know is rolling out a new mobile app. Or perhaps you were an early adopter and need to validate that your existing apps are reasonably secure. The question is: What are you doing to ensure things are in check? 

Like I say about a lot of things related to information security...do it yourself, allow me to help, or hire someone else - just do something.
Read More
Posted in message from Kevin, mobile apps, mobile security, penetration testing, source code analysis | No comments

Thursday, 21 February 2013

Yet another reason to get more in tune w/mobile & the cloud

Posted on 10:36 by Unknown
Here's a good post from Elcomsoft's Vladimir Katalov that underscores the dangers of many things I've written and spoken about in recent years:
  1. Cloud security - especially as it relates to mobile apps (and in the case of this piece, iCloud) 
  2. Mobile control - BYOD, MDM and all those buzzwords sound nice but what exactly are you doing to ensure the business information that's being carelessly handled by your employees is kept in check? What's going to happen when it's exposed via such backdoors? 
  3. Legal documents - you can have all the privacy laws, policies, and end user agreements in the world but, at the end of the day, they're basically worthless. If the imperial government wants something, especially control like I talked about here, they're going to get it.
It's time to wake up and take some action.
Read More
Posted in | No comments

Monday, 18 February 2013

Self-delusion + infosec= foolishness

Posted on 07:00 by Unknown
I thought this quote from Ronald Reagan was quite fitting for President's Day:

"If history teaches anything, it teaches that self-delusion in the face of unpleasant facts is folly."
Read More
Posted in careers, great quotes, information security quotes, security leadership, stupid security | No comments

Tuesday, 12 February 2013

Mobile app security testing - are you checking for all the flaws?

Posted on 13:54 by Unknown
I plan to write a related post soon on my mobile app security assessments. In the meantime, I wanted to share a tool with you that plays a key role in mobile app security: Checkmarx CxDeveloper (or perhaps more appropriately called CxSuite).

If you're a developer, QA professional, security manager, or IT generalist, this is a good tool to have for all of those gotta-have-now apps that everyone is throwing together getting in the app stores.

I've used CxDeveloper to find flaws in iOS and Android-based apps that may not be discovered via traditional testing such as:
  • Code injection
  • Session fixation
  • Path traversal
  • Weak passwords
  • Hard-coded cryptographic keys

...all things that I'm not smart enough to find on my own. Nor do I have the time.

For a few years now, I've dealt with the folks at Checkmarx and everyone from their CTO to their Director of Marketing - and a few others in between - has been super nice and responsive to my sometimes ridiculous requests.

Here's a guest blog post I've written for them:
Three compelling reasons to check your mobile app source code

And a webinar as well:
The Business Value of Partial Code Scanning

I also cover CxDeveloper in my Mobile Security chapter in the latest edition of my book Hacking For Dummies.

CxDeveloper isn't without its flaws. It's installation process and interface can be cumbersome but nothing that can't be overcome. It's certainly a worthy alternative to the big-box competitors...check it out if you want to find out the rest of the story with your mobile apps.
Read More
Posted in cool products, Kevin's security content, mobile apps, mobile security, security testing tools, source code, source code analysis, web application security, webcasts | No comments

Wednesday, 6 February 2013

Reactive security, eh? How’s that workin' for ya?

Posted on 12:10 by Unknown
Every time I browse the Chronology of Data Breaches and read the headlines coming out from Dark Reading, threatpost, and the like, I can't help but shake my head.

What is it really going to take to get people - mostly management, but some in IT - to fix the stupid, silly, low-hanging fruit that's plaguing so many networks today...? Well, here's a new piece I wrote for the nice folks at Lumension where I delve into this subject a little more.

As Thomas Jefferson said, Determine never to be idle. It is wonderful how much may be done if we are always doing. Our security problems can be fixed if we choose to fix them.


Read More
Posted in back to basics, great quotes, information security quotes, Kevin's security content, low-hanging fruit, stupid security, thinking long term | No comments

Wednesday, 30 January 2013

What's your communication style?

Posted on 07:12 by Unknown
Great IT & infosec-related quote:

"Wise men talk because they have something to say; fools, because they have to say something." -Plato

Good communication is arguably the most important factor for success.
Read More
Posted in careers, communication, great quotes, information security quotes | No comments

Tuesday, 29 January 2013

Introducing the brand new Hacking For Dummies, 4th edition

Posted on 06:18 by Unknown
Well, it's here...the fourth edition of my book Hacking For Dummies is officially available today!



Starting summer of 2012 and ending just before Christmas, I put in over 200 hours of blood, sweat, tears, and occasional cussing into this edition...more than any previous updates to the book. That said, my savvy technical editor, Peter Davis, and the wonderful editors at Wiley, Becky Huehls, Virginia Sanders, and Amy Fandrei were the real magic behind it all.

Thanks to everyone's hard work, I truly feel like Hacking For Dummies has finally come of age.

You're not going to learn every single technical detail of every possible security test. As I've said in the past, you need to use the proven time-management principle of focusing on the urgent and the important...eliminating the nasty, silly, and dangerous low-hanging fruit in your environment.That's exactly what Hacking For Dummies, 4th edition is all about.

In addition to walking you through, step by step, the entire information security assessment process (understanding the threats, planning, testing, reporting, and plugging the holes), I also talk about getting management buy-in and costly mistakes to avoid. I share my real-world experiences on what to do and what not to do in order to get the most out of your information security testing and risk management processes.

This edition has a lot of new content including coverage of Windows 8, mobile devices, and mobile apps. I've also fleshed out my chapters on hacking passwords, wireless networks, and web applications.

Hacking For Dummies is not the be-all end-all resource for information security testing. I wouldn't want to put myself out of business! And after all, there is no definitive resource on this subject.

What I can say is if you're looking for a no frills, common sense, street smart guide on the core essentials of ethical hacking, the key vulnerabilities to test for, and some hard lessons I've learned along the way, then Hacking For Dummies, 4th edition is for you. Check it out...I think you'll like it.


Read More
Posted in back to basics, ethical hacking, hacking, Kevin's books, low-hanging fruit, message from Kevin, penetration testing, security testing tools, vulnerability assessments | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile