Commentary

Content posted in July 2009
Page 1 / 2   >   >>
New iPhone SMS Threat No Reason To Panic
Commentary  |  7/31/2009  | 
You may have heard that researcher Charlie Miller has released details about a vulnerability that allows an attacker to take over an iPhone remotely with a SMS message. Now everyone is rushing to offer homegrown advice on how to fix the problem. But I'm going to offer a different point of view.
Corporate Patch Management Lags In Maturity
Commentary  |  7/30/2009  | 
If one of the most important disciplines necessary for keeping systems secure is a systematic vulnerability management program, why have so few organizations reached a decent level of maturity in their patch management efforts?
Pwnie Awards Bring Fame And Shame
Commentary  |  7/30/2009  | 
The third annual Pwnie Awards at Black Hat in Las Vegas, hosted by Alex Sotirov, Dino Dai Zovi, HD Moore, Halvar Flake, and Rich, celebrated the highs and lows in the security industry. As Dino said, "First we reward for great work, then we shame."
Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View
Commentary  |  7/30/2009  | 
When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.
Small Businesses Should Move To Shared Storage Sooner
Commentary  |  7/30/2009  | 
With the cost of direct attached storage (DAS) dropping and the capacity that it can deliver for those dollars increasing, you would think that the demand for shared storage is dwindling. Reality is that shared storage is on the rise and the biggest reason for its growth has little to do with storage management or even data protection. Those are nice side benefits, however the real motivator is server virtualization.
Metasploit Meterpreter For Mac Coming Soon
Commentary  |  7/29/2009  | 
Meterpreter is by far one of the most powerful and most advanced payloads included in the Metasploit Framework. It's been the joy of penetration testers and the bane of incident responders and until now, it's only been a payload targeted at Windows systems, while Mac users have dodged a bullet. But that won't be the case for much longer, as demonstrated by Dino Dai Zovi in a 20-minute breakout session at Black Hat today titled "Macsploitation with Meterpreter."
Serious Internet Server Exploit Widely Available
Commentary  |  7/29/2009  | 
The ubiquitous DNS server standard, Bind 9, is vulnerable to an exploit that has already been made public, the Internet Systems Consortium warned.
UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts
Commentary  |  7/29/2009  | 
UPDATE: The rumor here is that the attacks did indeed happen, but the significance of it is actually quite small--not worth paying attention to, since attention is clearly what the attackers are seeking. More to come. BlackHat, Kinda: Yesterday a hacking group released details (http://sh0dan.org/zf05.txt) of a number of successful attacks they conducted, apparently with the principal purpose of embarrassing some of the security industry's most wel
Obama Administration Going Soft On Cybersecurity
Commentary  |  7/28/2009  | 
Viruses, botnets with international botmasters, denial-of-service attacks on government properties, cyberbullying, and the increasing threat of identity theft plague every resident, from child to adult, regardless of whether they are actually ever online -- U.S. cybersecurity has been little more than a bad joke.
Unifying The Infrastructure
Commentary  |  7/27/2009  | 
We've spent the last several entries discussing the unification of storage and there is one aspect of unification that I have not discussed; unifying the infrastructure. I do currently have a series of videos currently running with Information Week on FCoE so in this entry I'll just touc
Close To Half Of SMBs Defenseless Against Cybercrime: Panda
Commentary  |  7/27/2009  | 
44% of U.S. small and midsized businesses have suffered at least one incident of cybercrime, according to a study just out from Panda Security. And considering how spotty, inconsistent and just plain missing SMB defenses are, it's a wonder the figure isn't any higher than it is.
Congress Taking Steps To Secure Electric Grid
Commentary  |  7/25/2009  | 
So the theory goes: one strategic Electromagnetic Pulse explosion (EMP) detonation over the mid-west United States could cripple the power grid, and even stop most electronic devices from a car's ignition to medical devices to radios and TVs to PCs from functioning. So what, if anything, are we doing about it?
6,000 New Malware Threats A Day: McAfee
Commentary  |  7/24/2009  | 
Think you've seen explosive growth in the number of threats your business faces? Think again. New figures from McAfee indicate that the malware makers have put their creations on a growth curve aimed at flooding cyberspace with cybertraps, as many as 6,000 new ones a day. Every day. All year long (so far).
Malware Counts: Uncomfortably Numb
Commentary  |  7/23/2009  | 
McAfee's security research group Avert Labs shows a more than doubling of malware from the first half of 2009 compared with the same period in 2008: that's 1.2 million unique malware applications up from about 500,000 in 2008. With the numbers now reaching the millions in a six-month period -- does virus and malware counting really provide us any value anymore?
The BlackBerry 'Trojan Horse'
Commentary  |  7/23/2009  | 
Research In Motion's announcement that users in the United Arab Emirates (UAE) who installed an update on their BlackBerrys ended up with a surveillance application raises some key questions.
The Encryption Gap
Commentary  |  7/23/2009  | 
Things that make us say "hmmm" include these stats: The percentage of respondents to our 2009 Strategic Security Survey who rated encrytion as effective in reducing risk dropped from 57% in 2008 to 48% in 2009. Use of disk, file, and backup media encryption ALL fell year over year by at least five percentage points. Backup encryption usage is down 10 points.
Un-Unified Storage
Commentary  |  7/22/2009  | 
The last few entries we have been covering aspects of unified storage. The bottom line is that unified storage has it's place and many organizations can benefit by having these systems, but where does this leave storage platforms that essentially do one thing and do it well?
Using Malware In Penetration Testing
Commentary  |  7/22/2009  | 
Huh? That's the exact reaction I had when I first read the title for the blog entry "Pentest Evolution: Malware Under Control."
News We Already Know: Federal Agencies' Faltering IT Security Efforts
Commentary  |  7/22/2009  | 
The Government Accountability Office has found "persistent weaknesses" that may leave federal agencies open to cyber-attacks, the GAO reported today.
Little URLs Becoming Bigger Spammer Target
Commentary  |  7/21/2009  | 
URL-shrinking services such as TinyURL.com, bit.ly, and cli.gs are convenient for turning long addresses into short ones. They're also convenient for helping spammers and malware makers hide their identities and guide unwary clickers astray.
Data Breach Laws Drive IR, Preparation Is Key
Commentary  |  7/20/2009  | 
Fellow Dark Reading blogger Gadi Evron had an interesting take on the relationship between incident response and forensics in his post "Incident Response Is Not Forensics." I agree with him for the most part, but I don't think forensics is the most common course of action depending on who is responding to the incident.
The Forgotten Part Of Storage Unification
Commentary  |  7/20/2009  | 
The focus of storage unification has for the most part been protocols. Leveraging a NAS to also serve up a SAN protocol (fibre or iSCSI) and as I discussed in my last entry there is definitely a place for that. The forgotten part of storage unification however is unifying all the storage that already exists in the data center; this is typically done through a form of storage virtualization.
Firewall for Virtual Machines Adds Speed and an IDS
Commentary  |  7/20/2009  | 
Startup Altor Networks launches a new version of its VM firewall that's built for speed and includes an intrusion detection engine from Sourcefire.
Defensible Network Architecture Ideal For Incident Response
Commentary  |  7/17/2009  | 
In my last blog, I talked about how incident response is more than just preparing your first responders by training them and providing them with the tools. Your network and systems need to set up in preparation, too, so that you have the information you need when handling an incident. It wasn't until yesterday that I remembered what I think is one of the best models of network design that fits the mold of what I mean by having your environment ready for an incident.
Anti-Virus Firms Investigating Sexy-View Smartphone Worm
Commentary  |  7/16/2009  | 
In yet another example of how mobile malware is gaining momentum, a new variant of the Wily worm is making the rounds. It's spreading through text messages and researchers warn it may be a smartphone botnet in the making.
Incident Response Is Not Forensics
Commentary  |  7/16/2009  | 
Professionals who handle computer security incident response traditionally have also been charged with forensics. They find the evidence of wrongdoing, and preserve it in a court-approved fashion. This best practice is a good one, even when saving data for law enforcement is not a necessity or a priority.
Do You Need Unified Storage?
Commentary  |  7/16/2009  | 
As discussed in our last entry, unified storage is all the rage right now in the storage industry; it is essentiality the combining of NAS with a block protocol, like iSCSI or traditional fibre channel. The question is however do you need unified storage?
SonicWall Adds Ambitious Anti-Spam Tools To SMB Firewalls
Commentary  |  7/16/2009  | 
Firewall company SonicWALL has added high-level anti-spam features to the features and services integrated in its Unified Threat Management Firewalls, aiming to block spam at the network gateway, as well as at remote or mobile locations using the company's firewalls.
Incident Response Prep Extends Beyond Tools, Training
Commentary  |  7/15/2009  | 
Whenever you read information on how to perform forensics and incident response, there is a preparation phase that comes before anything else. Preparation steps cover how to prepare for dealing with an incident in your environment -- but what about making sure your environment is ready for an incident?
The Security 'Unconference' In Vegas
Commentary  |  7/15/2009  | 
Most of the security action happening later this month will be in Vegas' Caesars Palace and the Riviera Hotel, where Black Hat USA and Defcon will convene. But at a rented house at a thus-far undisclosed location a few miles off of the Las Vegas Strip, a handful of hackers will host SecurityBSides, a homegrown "unconference" alternative to the more structured format of Black Hat.
Will Unemployed IT Workers Turn To Cybercrime?
Commentary  |  7/15/2009  | 
A weak IT market may create a boom in IT-trained criminals, a report from Cisco suggests.
Cisco Says Hackers Going Corporate
Commentary  |  7/14/2009  | 
Partnerships are usually not something associated with hackers, but a growing number of them are pooling their resources to make their tricks more effective. In addition, the crooks are keeping up on current events and instantly developing new ruses based on them. Those are a few of the findings Cisco outlined in its midyear security report.
SteelEye Offers SMB Business Continuity And Disaster Recovery Tools
Commentary  |  7/14/2009  | 
Aiming at the small and midsized business markets, data protection firm SteelEye's latest version of its Protection Suite offers disaster recovery and business continuity tools for Windows Server 2003 and Windows Server 2008.
Browser Security Takes Center Stage This Patch Tuesday
Commentary  |  7/13/2009  | 
Microsoft today issued a Security Advisory about a previously undisclosed vulnerability in Office Web Components Spreadsheet ActiveX control (OWC 10 and OWC11). The flaw is exploitable without any user interaction required, and attacks are underway.
What Is Unified Storage?
Commentary  |  7/13/2009  | 
What started as a whisper has now become a roar. All of a sudden every storage vendor you talk to has Unified Storage and all of a sudden you MUST have it. All of which begs the question, what is unified storage and do you need it?
Internet Explorer Hit With 1-2 Punch Of Zero-Day Attacks
Commentary  |  7/13/2009  | 
It's Monday: Do you know what Web browser your users are running? If it's Internet Explorer, don't look now, but for two weeks in a row, IE has taken two jabs straight to the face with ActiveX zero-day exploits that let attackers stomp all over users who are tricked into clicking on a malicious link or get redirected from a compromised site. Browser alternatives starting to look a little more enticing?
Target Requires Driver's License Scan For Restricted Items
Commentary  |  7/11/2009  | 
Sure, I traded my smoking habit for a Nicorette gum habit, but does that mean I should be forced to have my driver's license physically swiped through the register to buy an age restricted item? I don't think so, but retailing giant Target certainly does.
Social Network Security: Koobface Is Back And Twitter Is Now In Its Sights
Commentary  |  7/10/2009  | 
Koobface, the social networking worm that seeks to turn networkers' machines into zombies has generated more than 500 variants in the past month, according to security company Kaspersky Labs. The worm, which got its start on FaceBook and MySpace, now includes Twitter users among its targets.
DDoS Cyberwarfare Hurts Us All
Commentary  |  7/9/2009  | 
A distributed denial of service (DDoS) attack has been in the news in recent days due to attacks against the U.S. government -- with fingers pointed at North Korea. But people forget a few basic truths people when it comes to information warfare (or cyberwarfare) and DDoS attacks.
Where To Start With SSD
Commentary  |  7/9/2009  | 
Solid State Disk is a mature, stable technology poised for widespread adoption in enterprises of all sizes. It solves performance and power issues that mechanical drives can not. Most data center managers, large and small, have an eye on this technology but are not exactly sure where to start with SSD.
Hacking And Exploit Site Milw0rm Closes Its Doors
Commentary  |  7/8/2009  | 
Milw0rm is by far one of the best-known public sites to get the latest proof-of-concept exploit code. Or at least it was until it closed its doors today. The closing comes as a shock to the security community given that milw0rm had become a valuable resource for proof-of-concept and weaponized exploit code, demonstration videos, and papers on all areas of information security.
ActiveX Bug Could Open Doors For Bigger, Badder Confickers
Commentary  |  7/8/2009  | 
The latest ActiveX vulnerability could create big problems in the form of big opportunities for hackers. How big? The Conficker worm exploited a vulnerability that was long-patched, taking advantage of unpatched computers. The new vulnerability hasn't been patched yet. You do the math.
Trojans Now 70% Of New Security Threats
Commentary  |  7/7/2009  | 
Nearly three-quarters of malware is now comprised of Trojans, according to a new report from PandaLabs. The security company's figures for the quarter ending this past June showed that 70% of new malware was Trojans. There's a reason for this: Trojans work, and Trojans work because so many computers (and their users, and the businesses that use them) don't take even the most basic precautions against them.
Placing Former Employees On Legal Hold
Commentary  |  7/7/2009  | 
Legal hold is a term used to set aside certain data to make sure it is not altered while a legal case is being settled. One of those situations is employee termination. The chances are there for the employee to file a wrongful termination lawsuit and for the data center that means placing exiting employees' data on legal hold.
Zero-Day Hits Microsoft DirectShow
Commentary  |  7/6/2009  | 
Microsoft today issued an advisory to its customers warning them that a new vulnerability in Microsoft Video ActiveX Control affecting Windows XP and Windows Server 2003 is currently being actively exploited. The software vendor has issued a work-around.
Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate
Commentary  |  7/6/2009  | 
We've been saying for a while now that better identity management -- more so than secure Web app coding or even more secure browsers -- could fuel a quantum leap in Web security. The "Identity 2.0" community can be credited with wonderful research and truly significant advancements in identity management technology. In many ways, we're poised for an identity revolution. However, the efforts have been hampered by a lack of public awareness, a lack of interoperable standards, usability concerns, a
Would Your Users Take The Bait?
Commentary  |  7/6/2009  | 
Military leaders would never send their troops into war without preparing them for the threats they'd be facing on the battleground. Likewise, you shouldn't let your users go about their daily activities without educating them about the dangers they face when opening an e-mail or clicking on a link returned from a seemingly innocuous Google query.
Enjoyed The July 4th Fireworks? Skip The Waledac Movie
Commentary  |  7/5/2009  | 
After a few weeks of low activity, the infamous Waledac botnet is lighting things up once again. This time, its hook is the promise of a "fabulous" July 4 video on YouTube.
The Only Two Reliable Cloud Security Controls
Commentary  |  7/2/2009  | 
It seems that we in the information technology profession are just as fickle as the fashionistas strutting around Milan or New York. While we aren't quite as locked to a seasonal schedule, we do have a tendency to fawn over the latest technology advances as if they were changing colors or hem lengths. Some are new, some are old, some are incredibly useful, and others are completely frivolous, but we can't deny their ability to enter and steer our collective consciousness -- at least until the ne
Practical Analysis: Why Aren't We Better At Protecting Data?
Commentary  |  7/2/2009  | 
Knowing where your peers have failed to protect data is the first step in crafting an effective data protection policy.
Page 1 / 2   >   >>


1.9 Billion Data Records Exposed in First Half of 2017
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/20/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Jan, check this out! I found an unhackable PC.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The Dark Reading Security Spending Survey
The Dark Reading Security Spending Survey
Enterprises are spending an unprecedented amount of money on IT security where does it all go? In this survey, Dark Reading polled senior IT management on security budgets and spending plans, and their priorities for the coming year. Download the report and find out what they had to say.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.