When Social Networking Clashes with Security

From Crystal Craven

Information Security Gurus and Marketing Professionals are often at odds with each other in the business realm. Marketing used to primarily be a print and face to face business function.

Thanks to the over-haul of standard marketing strategies, marketing has grown new roots on the web and has found itself buried deep within social networking sites like LinkedIn, Facebook and Twitter.

The need for businesses to have an online foot print is critical to reach the masses in today’s competitive environment, but the potential loss of client data and security threats to your network are daunting…

Continued:  https://www.infosecisland.com/blogview/3298-Clash-of-Security-and-Social-Network-Marketing-.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Spam Block: Public Servants or Vigilantes?

From Wayde York

No one likes SPAM (the email variety.) Every responsible user of the Internet and surely every responsible information security professional would agree that anti-spam efforts are needed and likely should be expanded.

What happens, however, when the Internet-based anti-spam agents become a hindrance to business? While there over 70 anti-spam “service providers” that live on the Internet, a handful provide most of the information to business, government and academics users.

The service provided is usually a list of IP addresses from which to block SMTP or other email activity. One of the larger providers noted that their customers are “the few thousand corporations taking twice-hourly block list transfers.”

Most of these organizations publish block lists regarding open SMTP relays which can be used by spammers. One provider looks for email Non-Delivery Reports (bounces) that go further than local users of the email server.

In the words of one spam blocker, “A single infected machine sending spam out through a network utilizing NAT can result in blocked email from the whole LAN.”

So I ask, does building block lists of IP addresses that are “apparently” spammers and distributing this list without notifying the offending party vigilantism or service provision?

I lean toward them being vigilantes. Perhaps if a mechanism was in place to warn the alleged spammer they are about to be blocked, the service would seem more friendly…

Continued:  https://www.infosecisland.com/blogview/3294-Vigilantes-or-Public-Servants.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Sticky Situations in Social Media

From Robert Siciliano

The Internet has made our personal and professional lives very transparent. We now live in the fishbowl. Despite what many will argue, your privacy is no longer fully in your control. What you say, do and post can live forever. You are being judged in the process. And there are repercussions for those choices you make more now than ever…

Maybe you’re a Mom or a Dad, a Student or a Grad. No matter what you are, you have a reputation to protect. How we are viewed in society matters to most people. Being viewed as someone who is respectable, responsible, someone who has integrity and is generally a decent person is what most people strive for.

To be considered otherwise, would have negative repercussions. People who are viewed as irresponsible, out of control or someone who favors ill will, doesn’t allow that person to progress effectively in a civilized society. Life is harder for people who are destructive or make bad choices.

Continued:  https://www.infosecisland.com/blogview/3283-Social-Media-Sticky-Situations.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Quick Tips for Using Secure Shell

From Mourad Ben Lakhoua

SSH is a perfect security alternative to Telnet and has been used by system administrators and IT managers to configure, implement servers and network devices.

Here I wanted to list a manual on Secure Shell usage. First let’s start by choosing SSH client.

We will find no problem because generally there are two accepted solutions PuTTY and SecureCRT, both are really good.

But while SecureCRT is not a free solution we find that many IT Technician prefer to use PuTTY.

With using PuTTY you can connect to your server via: Raw, Telnet, Rlogin, FTP (SFTP), SSH1, SSH2.

In addition to supporting all these protocols you can find more TOOLS…

Continued:  https://www.infosecisland.com/blogview/3277-Quick-Tips-on-Secure-Shell.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Consolidate Compliance With Open Source

From Ted LeRoy

Many organizations have to comply with multiple regulatory requirements for their information security infrastructures.

Fragmented efforts to comply Sarbanes-Oxley (sarbox or SOX), Gramm Leach Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA),  Payment Card Industry - Data Security Standard (PCI-DSS), and ISO 27000 series, to name a few, can result in costly duplication of efforts, or worse, security holes due to the confusion of so many resources trying to tackle similar or the same problems.

Although many commercial tools are available to unify compliance efforts and to audit them, they come with a price tag that is too high for many small to medium sized businesses.

Continued:  https://www.infosecisland.com/blogview/3266-Need-to-consolidate-information-security-compliance-efforts-Try-open-source.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

DoS Attack Reveals Widespread Vulnerabilities

By Anthony M. Freed, Director of Business Development, Infosec Island Network

There is an UNEQUAL amount of good and bad in most things, the trick is to work out the ratio and act accordingly… The Jester

Infosec Island has once again gained exclusive access to a video demonstration of the XerXeS DoS attack recently developed by the infamous patriot-hacker known only as The Jester (th3j35t3r).

This new video shows a little more of the XerXeS dashboard, and reveals even more about the attack technique – watch the text box on the left as Jester mentions “Apache” for the first time outside of our private conversations.

As noted below in an analysis of DoS vulnerabilities by security consultant Michael Menefee, more than half of all the websites in the world use Apache, which means this exploit potentially poses a very serious problem should it ever be utilized by nefarious elements…

Continued: See the video and more at InfosecIsland.com

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

*   *   *

Anthony is a researcher, analyst and freelance writer living in beautiful Eugene, Oregon. Anthony founded Information-Security-Resources.com in 2008, and merged forces with the Infosec Island Network in January of 2010. Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies, educational organizations, and the infosec community at large. Contact Anthony at afreed@wireheadsecurity.com regarding all aspects of business development, client and community relations. Many opportunities are currently available for business and strategic alignment at Infosec Island.

The Publisher gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com

Study Shows Employees Put Data at Risk

From www.databreaches.net

From the press release, results of the annual “Human Factor in Laptop Encryption” study by Absolute Software and the Ponemon Institute:

This year’s expanded study was conducted in the United Kingdom, Canada, France, Germany and Sweden, in addition to the United States.

The study found that 15% of German and 13% Swedish business managers have disengaged their encryption solution. In contrast, 52% of Canadian, 53% of British, and 50% of French business managers have disengaged their encryption, while U.S. business managers are the most likely to circumvent company data security policy – topping the survey at 60%.

Other key findings for the U.S. in this year’s study include the following:…

Continued:  https://www.infosecisland.com/articleview/3244-Analyst-Study-Shows-Employees-Continue-to-Put-Data-at-Risk.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Tracking Google’s Script Kiddie Hackers

By Aeon Group

If you choose believe the writings of Mandiant, you’re under the impression that Chinese hackers are hellbent on taking over every large corporation in the United States.

If you choose to follow the writings of McAfee[2], you’re under the impression that “Chinese hackers only wanted Google’s secret sauce” – their source code.

If you choose to follow Damballa’s writings[3], the attackers who penetrated Google are amateur script kiddies. Take your pick, there is no lack of speculation.

News surrounding the attacks at Google and other companies are a dime a dozen and, while we have not seen any evidence publicly disclosed, we too can speculate along with everyone else.

My first thoughts surrounding the news of the attack led me to believe that the compromise may have been an inside job. The notion that Google was compromised via “spearphishing” [4] makes little sense.

The theory that IE6 [5] was the attack vector used makes even less sense. What we do know is that this entire Google fiasco is a learning experience that many will learn little from…

Continued: https://www.infosecisland.com/articleview/3235-Even-Einstein-Cant-Track-Googles-Script-Kiddie-Hackers.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Newbie Introduction to Digital Forensics Part 2

By Juan Granados

Up to this point in my career Digital Forensic Analysis consisted of a basic scan for documents from the exited employees hard drive.

Given the extensive nature of my past investigations, I was convinced that I could easily impress the executives at my company by doing more.

So, the research part of my journey began!

The information available on the internet can be a blessing and a curse at the same time. The multitude of information can be overwhelming for the newly annointed Padawan learner.

One thing was clear….Forensic analysis was an art rather than a science. My hope of finding a Cliff’s Notes version of Digital Forensics would prove to be impossible…

Continued:  http://information-security-resources.com/wp-admin/post-new.php?posted=8369

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Simple Log Review Checklist Released

By Anton Chuvakin

Today, many people are looking for very simple solutions to big and complex problems – and the area of logging and log management is no exception.

Following that theme, we have created a “Critical Log Review Checklist for Security Incidents” which is released to the world today.

In addition to HTML, PDF or DOC versions are available as well (alternative hosting location is here).

Feel free to modify the checklist for your own purposes or for internal distribution in your organization - but please keep the attribution to the authors.

Continued: https://www.infosecisland.com/blogview/3220-Simple-Log-Review-Checklist-Released.html

All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:

We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.

The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.

Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!

Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.

Prizes include:

• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.

• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.

• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.

Register now and win! https://www.infosecisland.com/

We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.

Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!

Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.

Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.

*   *   *

Stay Informed With ISR News Alerts:

Email:

by FeedBurner

*   *   *

Follow us on Twitter

Next Page »