Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, July 9, 2012

Use OpenVAS to Enhance Security

OpenVAs is open source pen testing software. It scans machines for vulnerabilities and offers suggestions for fixing problems. there are over 12,000 plugins that are included and many more available as updates. Virtually every type of attack can simulated with a little know how, but the default settings can help home users tune their firewalls and seal up common vulnerabilities in a snap.

When I ran this program against my Windows 7 machine with Comodo installed, the firewall lit up with notifications. I was able to block ports that otherwise would be left wide open. It was able to detect VNC service, the lack of SMB, and even an ssh server that I wasn't aware of. It made other suggestions about packet filtering to help shore up my network's security. When run against my Linux box, it was able to determine my kernel version, another ssh server I was unaware of, and determine there were no SMB clients running on my computer.

After doing some research and really getting to know OpenVAS this software will become a goto in my security arsenal. It's relatively easy to setup and use, but it's only for Linux users. Windows users may take advantage of the Backtrack live cd with includes many more pentesting programs. If you are serious about network security, this one's for you ;).

Friday, July 6, 2012

Use Login Approvals To Secure Your Facebook Account

After recently finding suspicious Active Sessions on my Facebook page, I decided to secure my page with the "Login Approvals" feature. I never dreamed anyone would want to gain access to my FB account, there isn't any sensitive information stored that will greatly impact my life or provide any financial reward for anyone. Nevertheless, I'm a stickler for security. Especially after my security has been breached. Best practices dictate proactivity, but even I find it difficult to be proactive when the threat to my security is infinitesimal. I regularly change my passwords and use strong passwords at every turn. Even if someone happens to gain access to my email account, all they will find is a couple of emails from mom and WHOLLOTTA spam. Want to find out where I live? Great, c'mon over. It's no big secret. My name address is on multiple websites, mailing lists, and millions of telemarketers have my phone number. Even the clerk at the local gas station knows my name and where to find me. Big deal. For me, the fact that someone has accessed a lot of useless information about me doesn't bother me. The fact that there are suspicious sessions on my FB account does.

Login Approvals is quick and easy to setup. After a couple of "are you sure" screens, you will be sent a text with a code to enter into confirmation box. After verifying the device, it is added to the recognized device list. After that, every time you use an unrecognized device to access your account, you will be sent a text containing a code to enter instead of your password. The downside is you have to wait for the code. It arrives pretty quickly, though. The upside is if anyone else tries to access your account you will be notified.

And that's what I'm looking for. Control over my account. I now feel like the balance power has shifted back to my court. I would recommend using this feature to every FB user. Even if you use a hundred (or a million) different devices to get your FB fix, it would be well worth the time it takes to register every one.

Wednesday, July 4, 2012

Insecurity Of Information

I don't want this post to be misconstrued as a dump on system administrators. They have a difficult job with many different facets that limit control over their networks. They are charged with keeping information flowing, not slowing it down. The job can be a stressful one. One hiccup with internet service is met with a flood of angry calls and emails. They have to deal with support issues, employee issues, vendor issues, security issues, budget issues, the list goes on. It really is a difficult and thankless job in many ways, But........

IMHO, security boils down to one simple thing: standard (or "best") practices. The industry is based on them, therefore bound to them. Most system admins were taught from the same curriculum, inherit practices from their predecessors, and tend to utilize only what they understand. Very few want or need to be more. Hackers are not bound to any protocol, learn as they go, and aren't burdened with long term data integrity, shareholders, or profits. They are fluid creatures limited only by their imagination and sheer technical ability. In short, there isn't a contest.

For example: If I but three red cars, you could assume with reasonable certainty that my fourth car would be red, too. A lot of protocols that corporations follow are similar in estimation. It's very predictable. Some system admins are happy to place Youtube at a higher priority level than reading logs or checking equipment. A breach can happen anytime, and a network device sending an email isn't going to cut it. It's difficult to stay vigilant when that critical moment will seemingly never arrive. I'm sure there a few admins that take pride in their security knowledge and implement it well, but many don't have a good grasp of attack vectors (both virtual and physical) or how to secure them.

In fact, employee information is the easiest to obtain. It's not very well guarded and is made available for the asking. Try calling a company and asking to speak with a salesman. Mr. John Smith will happily assist you. Visit us on the web at http://mycompany.com, here's my email jsmith@mycompany.com if I can assist you further. That's more than enough to begin planning the stage of attack, and no elaborate trickery was involved. It was all given for the asking (or completely volunteered), and even more can be obtained with a little imagination.

Contrary to popular belief, customer information isn't very high on the security food chain. It's usually stored in a database server accessed by a surprising number of people often from different segments. Salesmen, managers, data entry clerks, IT personnel, customer support, as well as outside contractors have direct, or indirect, access to that information. I often asked myself why they bother using passwords or securing the server room, other than to protect hardware configuration. In comparison, only a select few have access to proprietary or sensitive information pertaining to the company or R and D.

Corporate networks are compromised because they are a wealth of profitable information with plenty of soft targets. These networks are constantly hacked, but reported very little. Every American that has used a debit or credit card can rest assured that their financial information has been in the wrong hands quite possibly more times than you want to know. Can more be done to stop it? Not without rethinking everything we know about networking and doing business.

Thursday, June 28, 2012

Cybersecurity and IP Law

**This article was published prior to this date**

These subjects are currently being debated as Congress begins the process of beefing up IP law and cybersecurity. While we do have a need to protect our infrastructure, there is little (if any) real dialogue about actually securing national resources. The bills that have been introduced revolve around censoring the internet in an attempt to protect the IP (intellectual property) interests of Hollywood, the recording industry, patent holders, and major software manufacturers. They seem to be using critical infrastructure as a convenient excuse to create new legislation. No one involved in drafting these bills seem to have even a passing understanding of IT or network security.

After reading this 3 part article and this one on Forbes.com, I have serious reservations about the drafting process and the people involved in it. Any hacker worth their salt knows corporate naming conventions. AV programs and firewalls are good for scanning files and traffic control, but they offer no protection against a pointed attack. These attacks can be launched in many different ways using common ports, applications, and protocols. They may or may not leave any evidence behind, other than empty log files. Any hacker will tell you the only sure fire defense is to disconnect your machine from the network and shut it down. To assert that any serious security firm would prescribe AV and firewalls as a serious defense against these types of attacks is laughable. The fact that these attorneys don't get it is disturbing. How can people with such a poor understanding of corporate IT draft legislation to deal with cyber threats? Do they actually know what they are doing?

How is blocking pirated media, websites, or stiffening intellectual property going to secure the national power grid? The problem with the proposed legislation is the lack of protection for internet users from over zealous and tyrannical policing of content that may not be popular with the powers that be. Websites could be taken offline on a whim. It could take years to get a site back online, if at all. It could also potentially keep new technological break throughs, in virtually every field of science, from ever being used outside of the select few that develop or own them. These laws could potentially be used to erase or cripple other technologies.

The cybersecurity and IP legislation in their current form are being created to protect corporate profits, and nothing more. I'm not against turning a profit, it's the American way. But when does IP become more valuable than our rights as American citizens? I have a feeling we're about to find out.