Clarifying the technical findings on a weakness in RSA crypto keys and some recommendations on how to prepare and protect your assets from the next inevitable crypto weakness discovery
Continue reading "Ron Was Wrong, Whit Is Right, And What You Need To Know"
The hacker mindset can't be taught -- it must be developed and refined over time
Continue reading "Can You Train A Great Penetration Tester?"
How to pre-emptively secure systems against 0day attacks that, by definition, we know nothing about
Continue reading "Fighting 0days With Fundamentals"
Special care must be taken in a penetration test that locates targets with 'zero-knowledge'
Continue reading "Pro Pen Testing: The Zero-Knowledge Approach"
Tips for helping family members secure their computers for safe internet browsing and online shopping.
Continue reading "Thanksgiving IT Help"
Welcome to the first in a series of posts on professional penetration testing. During the course of the next few entries, I will shed light on the often confusing and rarely straightforward world of penetration testing based on my experience during the past decade as both a professional penetration tester and a manager of penetration testing teams.
Continue reading "The What And The Why Of Professional Penetration Testing"
During the Labor Day weekend, I got pulled in by friends and relatives (some remotely) to take care of their computer-related problems.
Continue reading "Keep Your Browser Updated"
Adobe has published its security updates for Adobe Reader and Adobe Acrobat.
Continue reading "No PDF Updates Anymore--Anyone Interested?"
A couple of months ago, Secunia's Stefan Frei published a great paper about the patching burden that the average PC user faces every week.
Continue reading "Shed Vulnerabilities With One Simple Rule"
Microsoft published Version 8 of its Security Intelligence Report (SIR) this week. The report covers the second half of 2009 and is a massive piece of information with almost 250 pages.
Continue reading "Microsoft SIR, Dissected"
In the past two weeks we have seen multiple problems with SSL, which is used in our Web browsers to protect the privacy and integrity of our electronic transactions.
Continue reading "In SSL We Trust? Not Lately"
Multiple vulnerabilities in the mainstream browsers and other widely installed software came to light at the CanSecWest conference in Vancouver.
Continue reading "How Safari Hacker Finds Bugs"
Along with the usual security alerts covering the March bulletins from Microsoft and various content management systems flaws, US CERT published an unusual security alert about a product from Energizer, the battery company.
Continue reading "Energizer Bunny Gone Bad"
In the past few weeks since the Google/China incident, we have seen a number of interesting blog posts and white papers that provide further details on some of the techniques used by the attackers.
Continue reading "Boosting Your Defenses Against Botnet Infections"
Microsoft's February 2010 Patch Tuesday was one of the bigger releases for Microsoft and its clients in the past two years -- 13 bulletins addressing 26 vulnerabilities.
Continue reading "Virtualization Vulnerabilities Up And Coming"
The latest update for Internet Explorer is out, and organizations are busy applying or at least certifying the patch on their testbeds.
Continue reading "IE 6 Aftermath: Time To Review Your Browser Strategy"
A co-worker forwarded me an e-mail in which the original sender was asking about running vulnerability scans on his own and stated he was concerned about the scans causing downtime while the servers were being tested.
Continue reading "The Inconvenient Truth Behind Security"
Next Tuesday, Jan. 12, is Microsoft Patch Tuesday. Beyond the usual patches from Microsoft, we will also get a critical update for a piece of software that increasingly plays a role in exploiting desktop systems -- the Adobe Reader from Adobe Systems.
Continue reading "Adobe Reader's Patch Tuesday"
Microsoft has made Office 2010 available in public beta. After playing around with it for a while, I am not yet sure I need any of the new functionality.
Continue reading "Improved Security In Microsoft Office 2010"
Security reports have consistently pointed out weak or default passwords as a major source for data breaches, similar to the recent Verizon Data Breach Study. Now there's a new service that tests the strength of passwords used in the encryption of wireless access points.
Continue reading "New Cloud-Based Wireless Password Cracker"
Last week saw the launch of Shodan, a search engine for machines (servers, routers, etc.) connected to the Internet.
Continue reading "The Futility Of Security By Obscurity"
Security professionals are intrigued by the fact that for approximately half of the data breach cases Verizon Business works, the victim doesn't realize there's a problem until more than six months after the incident occurred. Another stunning fact: More than two-thirds of incidents we work are discovered by a third-party.
Continue reading "Narrowing The Compromise-To-Discovery Breach Time Line"
I recently attended a presentation about the current state of the Conficker worm, delivered by Felix Leder and Tillman Werner, two German security researchers from the University of Bonn.
Continue reading "Conficker's Next Move"
This week Microsoft published volume 7 of its Security Intelligence Report (SIR), covering January 2009 through June 2009.
Continue reading "Dissecting Microsoft's Latest Security Intelligence Report"
I recently got back from a sizable IT security conference in London. As I've experienced countless times at shows, everyone was most intrigued by the war stories about organizations that were victims of a data breach. Security folks have an innate desire to learn what happened to others so they can prevent encountering the same fate -- or so they say. However, after personally investigating hundreds of data breaches for my clients, there seems to be a number of recurring themes that nobody seems to catch. One in particular is with respect to developing and maintaining an incident response plan.
Continue reading "Fundamental Failures With Incident Response Plans"