Welcome Guest. | Log In | Register | Membership Benefits

Overlook The Obvious And Risk Everything


Posted by Amy DeCarlo @ 10:08 AM ET | May 21, 2012

Failure to follow fundamental common-sense security policies can produce disastrous results, as the state of Utah discovered

Continue reading "Overlook The Obvious And Risk Everything"


Topics:   Security Services Tech Center : Security Views



Effective Security Policy: Emphasis On Execution


Posted by Amy DeCarlo @ 09:12 AM ET | May 02, 2012

When it comes to mounting a successful defense in what is a fast-changing threat environment, best practices require consistent execution

Continue reading "Effective Security Policy: Emphasis On Execution"


Topics:   Security Services Tech Center : Security Views



Trusting 'Trusted' Sites Again


Posted by John H. Sawyer @ 01:18 PM ET | Apr 27, 2010

I've been teaching a user security awareness and training course to faculty and staff at our university. One of the great aspects of the class is the discussions that develop out of the participants' questions, like the security of social networks and how to use wireless securely while on the road. Lately, I've been getting one question more and more often: How do I know if a site is safe?

Continue reading "Trusting 'Trusted' Sites Again"


Topics:   Evil Bytes : Security Services Tech Center



New Year Will Put New Pressure On Security Services Decisions


Posted by Tim Wilson @ 01:58 PM ET | Jan 07, 2010

Security, as many consumers have recently discovered, is a matter of perspective. Many consumers carefully lock their houses each night and turn off their computers. They keep their AV products up to date, their wireless connections encrypted, and their passwords in their heads.

Continue reading "New Year Will Put New Pressure On Security Services Decisions"


Topics:   Dark Dominion : Security Services Tech Center



Cybercriminals: Taking The Road Less Traveled


Posted by Tim Wilson @ 03:26 PM ET | Aug 27, 2009

If you were a criminal, what data would you be looking for? The most obvious answer is to look for the types of data that give you direct access to cash: bank accounts, brokerage accounts, credit cards. Like Willie Sutton, you'd go where the money is, right? And that's why some of the stiffest security defenses surround this sort of account data.

Continue reading "Cybercriminals: Taking The Road Less Traveled"


Topics:   Dark Dominion : Security Services Tech Center



Hacking Challenge Shows XSS Still King


Posted by John H. Sawyer @ 02:12 PM ET | Jun 08, 2009

Last week, another company got egg on its face by running a "we're-so-secure-you-can't-hack-our-stuff contest." When are companies going to learn claims like that always backfire?

Continue reading "Hacking Challenge Shows XSS Still King"


Topics:   Evil Bytes : Security Services Tech Center



For SMBs, Being Security-Savvy Doesn't Always Mean Doing It Yourself


Posted by Tim Wilson @ 02:28 PM ET | Jun 04, 2009

When it comes to security, most security professionals -- indeed, most Dark Reading readers -- are do-it-yourselfers. They do their own research, find their own bugs, and remediate their own systems. It's almost a rite of passage -- if you have to ask for help, you can't be a real security pro. But I wonder, sometimes, if this attitude doesn't hurt small and midsize businesses, in which having even one full-time security professional is more than many can afford. Such businesses are just as concerned about security as their larger counterparts, but when their people attempt to ask questions or get the tools they need to build strong defenses, they are treated as "neophytes" or given tools they simply do not have the time or skills to learn to use properly. And because they don't have tools that work at their skill levels or have the support of the elite security community, they are sometimes left with no easy way to access the best defenses and tools available.

Continue reading "For SMBs, Being Security-Savvy Doesn't Always Mean Doing It Yourself"


Topics:   Dark Dominion : Security Services Tech Center



Security Incident Ratings Made Easy


Posted by John H. Sawyer @ 02:45 PM ET | Jun 03, 2009

Management likes numbers. They get the the warm fuzzies when numbers can be graphed in a way that they can quickly discern what's going on. Of course, if the numbers are bad, then they may not feel those warm fuzzies. In the IT security world, we try to provide useful numbers to show what a great job we're doing, but it's hard to quantify thwarted attacks -- other than relying on numbers from an IPS and anti-malware system.

Continue reading "Security Incident Ratings Made Easy"


Topics:   Evil Bytes : Security Services Tech Center



Java Trouble Brewing For Apple


Posted by David Maynor @ 10:20 AM ET | Jun 02, 2009

Like most computer geeks with the latest toys, I can always find a way to play rather than work. My procrastination tendencies can sometimes lead to troubling results (just ask my girlfriend), so I often give vendors some leeway when it comes to patching vulnerabilities. But some vendors just don't get it.

Continue reading "Java Trouble Brewing For Apple"


Topics:   Hacked Off : Security Services Tech Center



BackTrack4 Sneak Peek Shows New Forensic Capabilities


Posted by John H. Sawyer @ 02:50 PM ET | Jun 01, 2009

BackTrack 4 Pre Final Sneak Peek was released to Informer Blog subscribers last week. Informer, created by Johnny Long and his Hackers For Charity organization, is a fundraising program to help feed children in East Africa, and its blog "is designed to give subscribers a 'backstage pass' to the world of Information Security" by providing access to prereleases of tools, papers, and book chapters.

Continue reading "BackTrack4 Sneak Peek Shows New Forensic Capabilities"


Topics:   Evil Bytes : Security Services Tech Center



Backdoors In The Network: Modems, WiFi, & Cellular


Posted by John H. Sawyer @ 04:02 PM ET | May 06, 2009

War-dialing received a revival in March with HD Moore's release of WarVOX, a tool that leverages VoIP to speed up the calling of phone numbers to find modems, faxes, and voice systems. Finding modems can help enterprises find backdoors into their network setup by a rogue employee. Likewise, it can help penetration testers find forgotten or lesser-known ways into a target's network through a poorly secured modems.

Continue reading "Backdoors In The Network: Modems, WiFi, & Cellular"


Topics:   Evil Bytes : Security Services Tech Center



Dark Reading Launches Security Services Tech Center


Posted by Tim Wilson @ 12:50 AM ET | Apr 01, 2009

Today Dark Reading launches a new feature: the Security Services Tech Center, a subsite of Dark Reading devoted to bringing you news, product information, opinion, and analysis of the "outsourced" security services and technologies available to augment your organization's IT defenses.

Continue reading "Dark Reading Launches Security Services Tech Center"


Topics:   Dark Dominion : Security Services Tech Center



A Cloud Might Save You Money...But What If The Cloud Goes Broke?


Posted by Sara Peters @ 12:29 PM ET | Mar 25, 2009

I've been talking quite a bit about whether or not (not) users of cloud services can prove compliance with security, privacy, and e-discovery laws. Now a story from The Register has me thinking about yet another issue -- the inescapable question of a service provider's financial stability.

Continue reading "A Cloud Might Save You Money...But What If The Cloud Goes Broke?"


Topics:   CS Island : Security Services Tech Center



DIY Pentesting Lab


Posted by John H. Sawyer @ 05:04 PM ET | Mar 24, 2009

In Friday's Tech Insight, I provided arguments for creating your own internal security lab and some of the benefits to both the business and the IT security professionals. This week, I want to provide more direction on what you'll need depending on your goal and focus of the lab. Today, we'll be looking at suggestions for security teams looking to learn more about and get their hands dirty with some in-house penetration testing.

Continue reading "DIY Pentesting Lab"


Topics:   Evil Bytes : Security Services Tech Center



Acrobat Antics Here To Stay


Posted by John H. Sawyer @ 03:10 PM ET | Mar 12, 2009

Adobe has a bit of a problem on its hands, and it is sitting in a spotlight usually reserved for a company like Microsoft. Adobe is currently responsible for a vulnerability that could allow mass pwnage of the Internet. Even though the company finally released a patch for version 9 of Acrobat and Acrobat Reader, two more versions are due to be patched. In other words, this is a bug that's going to be around for a long time.

Continue reading "Acrobat Antics Here To Stay"


Topics:   Evil Bytes : Security Services Tech Center



Hazy Forecast For Cloud Computing Forensics


Posted by John H. Sawyer @ 03:29 PM ET | Mar 09, 2009

The security of cloud computing is an area I've been following at a distance because I don't currently have any clients who have seriously considered moving any of their data and services into the "cloud." Something caught my eye on Friday, however, that piqued my interest in how security and forensic investigators may handle incidents that involve data and systems in the cloud.

Continue reading "Hazy Forecast For Cloud Computing Forensics"


Topics:   Evil Bytes : Security Services Tech Center



PHPBB Password Analysis


Posted by Robert Graham @ 05:56 PM ET | Feb 06, 2009

A popular Website, phpbb.com, was recently hacked. The hacker published approximately 20,000 user passwords from the site. This is like candy to us security professionals because it's hard data we can use to figure out how users choose passwords. I wrote a program to analyze these passwords looking for patterns, and came up with some interesting results.

Continue reading "PHPBB Password Analysis"


Topics:   Security Services Tech Center



Get Your Pentesting Permission Slip


Posted by John H. Sawyer @ 03:19 PM ET | Jan 26, 2009

As infosec professionals, we are often tasked with performing duties that would be considered illegal if we did not receive proper authorization beforehand. For example, if you were performing a penetration test against a system that you or your employer doesn't own, or for which you don't have authorization to access, then you could be violating a number of laws leading to termination and possible criminal prosecution.

Continue reading "Get Your Pentesting Permission Slip"


Topics:   Evil Bytes : Security Services Tech Center




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports