Showing posts with label hacks. Show all posts
Showing posts with label hacks. Show all posts

Tuesday, August 9, 2011

Security Never Takes a Vacation

We’ve all seen the auto-out-of-office replies, ‘Thanks for your message but I’m out until I return – contact my boss/subordinate/someone else if you need or want anything.’  If you’ve emailed me over the last couple weeks, you’ve seen a similar note.  I took some time off, then participated in F5’s awesome Agility Conference for partners and customers and then took a few more days off.  I am challenged, like many of us, to avoid work, recharge and let the brain-drain occur while ‘out of the office.’  As humans, we need to escape from our daily grind to give the mind, body and soul a chance to recharge but I do try to keep informed about security stuff since I’m personally interested it. 

riffraffbuttonIT Security cannot ever take a vacation.  Imagine if you went to your favorite website and when you typed the URL, you got, ‘This website’s content is on vacation and will not be available this week.  It’s been working hard to keep you safe but needs a week to recuperate from blocking all those malicious types.’  Now certainly, we see similar messages when a site is down and most, if not all, websites have maintenance windows, but to put a site on vacation is unheard of and absurd.  The IT Security staff also needs time-off but their equipment and the sites they manage need to always be available, secure and performing at their peak.  The obvious reason is that riff-raff never takes a vacation nor does the need to protect against online threats.  There were a few stories that caught my eye over the last couple weeks.  

Of course there was the BlackHat and DEFCON conferences in Vegas and there has been a bunch of news stories surrounding these…and it’s about time. It has taken a while but Information Security is now covered almost daily in the mainstream media – probably due to the high profile attacks over the last couple years and certainly due to the rash of breaches over the last several months.  You can Meet Dark Tangent, the hacker behind Black Hat and DEF CON or understand why the Feds Turn To Hackers To Defend Nation In Cyberspace.  There were also articles covering DEF CON: The event that scares hackers and how to stay off the Wall of Sheep in one of the most dangerous places to use a computer along with Defcon: The lesson of Anonymous? Corporate security sucks where, as one InfoSec practitioner said, ‘It's no coincidence that hack insurance is up,’ and that ‘he'd heard at the conference that a major corporation laid off security staff and bought hack insurance instead.’   Another, Big companies need to train staff about security is something I’ve written about numerous times… there’s a fun one that looks at how Photos show the cultural difference between Black Hat and Defcon hacker events and…a real scary one that talks about how a Black hat hacker can remotely attack insulin pumps and kill people

There was interesting data coming from Lookout Inc, a mobile security vendor who released its 2011 Mobile Threat Report.  With mobile devices being the fastest growing consumer technology and many of those being used in corporate environments, the report is something to check out.  They review both iOS and Android based platforms along with the various threats whether they be Application-based, Web-based, Network based or simply physical loss.  Lots of data and graphs to absorb but worth a read.  As a side note, I use Lookout on my personal Blackberry and really like it.

A few others that caught my eye while travelling included hackers compromising various police agencies, including departments in Missouri and Arizona…that the Cost of Cybercrime is Soaring up 56% in a year – anywhere from $1.5 million to $36.5 million for the median cybercrime cost.  At least, those that did take proper preventative measures realized a 25% cost savings verses those that didn’t…folks are wondering if Facial-Recognition Software the Next Security Threat…and you know it’s bad when Hackers breach chocolate recipe on Hershey website.

Lastly, if you didn’t see it, The First Website Ever Celebrates Its 20th Birthday.  Welcome back.

ps

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, lookout, blackhat, cyber-threat, defcon, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, November 22, 2010

Giving Thanks for the Hackers, Crackers and Thieves

This holiday season, give you friendly neighborhood hacker (black or white hatted) and nice pat on the back.  ‘Why?’ you may ask.  ‘Aren’t they responsible for the nasty botnets, malware, SQL injections, stolen identities, government infiltration, Stuxnet, and all the malicious things you warn against in this very blog?’  Yes, but over the years it’s been the very same folks attempting to and successfully gaining access to systems to infect, steal, snoop and causing general havoc that have made security better.  All the new variants of worms, viruses, trojans or the all encompassing ‘malware’ force security professionals to stay alert, review risks and come up with solutions to thwart such attacks.  It is a great battle of wits in this game of chess that’s played out over the internet.  Patch one hole, find another; lock one system, infiltrate another; fix one vulnerability, expose another.

As an aside, I’m using the term ‘hacker’ to mean both the good and the bad.  In the media, the term hacker has grown to mean someone with bad intentions who breaks into computers with malicious intent, but within the programming world, it’s also considered a compliment.  A hacker is just someone with exceptional computer skills that can, essentially, make a system do what they want.  Even the term ‘hack’ can be good and bad; a compliment or insult.  If you ‘hack’ something with criminal intentions, then it is bad but if you come up with a clever way or a brilliant ‘hack’ to accomplish something, then you are praised.  Both break the rules - either the law or the accepted way of doing something.

Over the years, while software firms, financial institutions, retailers, travel outlets, ISPs and others would deny the fact that there might be something wrong or a vulnerability within their code, systems and infrastructure, it would be the ‘hacker’ that would prove to the world and force the manufacturer to both admit and fix the weak link.  As the years have passed and the hackers are often proven right, companies now (to some extent) welcome the insight of how to make their products more secure.  ‘Welcome’ might not be the most accurate term but there is less denial and more acceptance, with quicker fixes, patches and other remedies.  They have also made the individual user more aware of the things that might harm their computers and compromise their identity.  They have made the casual user more savvy to avoiding those pitfalls, tricks and methods to steal personal information.  They have taught us to be more careful about the links we click, the things we publish on social media sites and how we navigate the internet.  Imagine how open

If you haven’t figured it out by now, there has always been the Great Battle between Good and Evil – those who want to help and those who want to hurt; those with good intentions and those with bad; those with kindness and those who are cruel.  Granted, it is not as black and white as depicted and there are many, many grey areas when it comes to doing what is right.  If the bad guys have, by their actions, forced providers to bestow better solutions and make us, as users, safer, then have at it!  With anything, if you can pull whatever good out of a bad situation and learn from it, then you are living a fruitful life – and that, you should be thankful for.

ps

Related:

twitter: @psilvas

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Friday, June 18, 2010

Audio White Paper - Manageable Application Security

Information security personnel suffer from information overload on a nearly daily basis, but need to sift through myriad articles, reports, blogs, logs, and scans to do their jobs. Information is vital to successful web application security strategies, whether it be information about a new attack, a new twist on an existing attack, or identifying weak points in web applications. Investments in security solutions have to provide a clear value, which equals additional time spent collecting and documenting proof of this value. The latest version of F5 BIG-IP Application Security Manager(tm) (ASM), v10.1, addresses information overload and the need for agility in implementation. Read full whitepaper here.  And click here for more F5 Audio.

ps
twitter: @psilvas
Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet

Thursday, June 3, 2010

CSRF Prevention with F5's BIG-IP ASM v10.2

Watch how BIG-IP ASM v10.2 can prevent Cross-site request forgery.  Shlomi Narkolayev demonstrates how to accomplish a CSRF attack and then shows how BIG-IP ASM stops it in it's tracks. The configuration of CSRF protection is literally a checkbox.

 

 

ps

Posted via web from psilva's prophecies