Sunday, July 12, 2015

Like PuTTY In a Hacker’s Hands

 Be careful where you get your PuTTY...

http://blog.fortinet.com/post/like-putty-in-a-hacker-s-hands

Monday, July 6, 2015

US jets intercepted Russian bombers off the California and Alaska coasts on July 4


On July 4th, two pairs of Russian Tupolev Tu-95 bombers approached the US West coast, causing the Air Force to scramble to intercept the planes before they breached US airspace, two senior defense officials told Fox News.

The first incident reportedly occurred at 10:30 am ET off the coast of Alaska, when NORAD identified the Russian planes and two F-22s hurried to intercept them. Another incident occurred at 11 am ET off the coast of central California, and was responded to by two F-15s.

The Russian bombers they intercepted are capable of carrying nuclear weapons, but sources do not indicate whether or not they were armed.

More:

Thursday, June 4, 2015

Sourceforge Hijacks the Nmap Sourceforge Account




From: Fyodor <fyodor () nmap org>
Date: Wed, 3 Jun 2015 00:56:23 -0700

Hi Folks!  You may have already read the recent news about Sourceforge.net  hijacking the GIMP project account to distribute adware/malware.  Previously GIMP used this Sourceforge account to distribute their Windows  installer, but they quit after Sourceforge started tricking users with fake  download buttons which lead to malware rather than GIMP.  Then Sourceforge  took over GIMP's account and began distributing a trojan installer which  tries to trick users into installing various malware and adware before  actually installing GIMP. 

More:
http://seclists.org/nmap-dev/2015/q2/194

Monday, May 25, 2015

Google: Security questions across websites are very easy to guess


FTA:

For example using a single guess an attacker would have a 19.7% success rate at guessing English-speaking users' answers for the question "Favorite food?"

… With 10 guesses an attacker would be able to guess 39% of Korean-speaking users' answers to "City of birth?"

As for English-speakers favorite food, the most common answer is, not too surprisingly, "pizza."

More:

http://bgr.com/2015/05/22/google-security-passwords-secure-easy-guess/

Thursday, April 16, 2015

First time at RSA Conference? How to have the most fun. #RSAC


I'm missing RSA this year. :( 
My rude advice to one of our less senior guys. I think this works for nearly everyone except the Sales guys. Sorry Sales guys.

I would pack your typical office clothes. Khaki/grey/black pants. Dress shirts (not white) or Polos are best. Definitely no ties.

There will be lots of guys in suits. Those guys are all Sales guys. Avoid them unless they are from something you use or you really want info about.  Unless, of course, they are handing out invites for after parties.  

You identify yourself as a potential customer (and get invites to parties and dinners) by not looking like another Sales guy. 

There will also be guys that look like they run the EFF and just left DefCon or CCC. You know what I mean.  Those guys will have either sandals with socks or Doc Martins. They either don't own a comb or don't care.  Embrace these guys and engage with them. They are usually the smartest guys there and have tons to tell you and killer stories. That said, Sales guys think they don't actually plan to buy anything, so they don't get invited to parties, except maybe to add some credibility to the company. You don't want to be identified as those guys either. 

If you connect with any wireless network check it out beforehand.  RSA typically provides one. It will be well advertised.  Don't get suckered in to using anything that you aren't sure about.  Right now, remove all of the default wireless networks (linksys, dlink, etc.) SSIDs from your phone and laptop. There are security "researchers" who will set up rouge networks and will snag all the Sales guys.  Who knows what they plan to do.  Not as bad a DefCon or CCC, but still…

Last advice.  Set up a Google Voice number and only hand that out when asked for it by Sales guys.  Don't plan to ever use that number again.  If you can, change the phone on your registration as well. You will get inundated with calls for years after the show if you give them your desk number.  All the companies buy the lists of attendees and contact everyone.  They are pretty adamant that they need to talk to you and demo their stuff.

Have fun!  Send me some pictures.

Tuesday, February 24, 2015

VA Secretary Robert McDonald apologizes for misstating military record - The Washington Post


You can be outraged if you can state, without looking it up, the difference between Special Forces and Rangers. How many of us can do that?  Some Special Forces don't think this is that big of a deal either. 

From the article:

Wood quoted retired Army Col. Gary Bloomberg, a former Special Forces commander, calling McDonald's claim "a boneheaded statement." But Bloomberg said he and other former special ops officers did not consider it as egregious as some other misrepresentations.

"No one got really crazy about the whole thing, compared to some of what we've seen," he told the Huffington Post. "It's a lot different from guys running around faking their special forces credentials. … I can see [other former special forces soldiers] going, 'Hey, check out this boneheaded remark,' but I don't see the gravitas that I would with a guy wearing medals he didn't earn.'"

Monday, February 23, 2015

What Good is Tor in 2014?

 Tor is not a privacy slam dunk. #NewAmCyber

It's probable, especially in the wake of the recent NSA revelations, that government agencies such as the NSA and CSIS sniff traffic on many exit nodes.


More:
http://resources.infosecinstitute.com/good-tor-2014/

Friday, February 20, 2015

Replacements - The Ledge Lyrics

 I have heard this song at least a thousand times, but I've never looked at the lyrics.

Wow. Strong and sad. I think I knew that kid.

I'm glad I was able to get tickets today.

See you guys in DC in May.

http://www.metrolyrics.com/the-ledge-lyrics-replacements.html

Thursday, February 12, 2015

Jeb Bush just revealed the social security numbers of a bunch of former constituents


Dear "eGovernor" Bush,
Privacy protection is an important part of the job. Who is your security officer? You have a security officer, right?

In a ham-handed effort at transparency, the likely 2016 Republican presidential candidate Jeb Bush just released a trove of emailsfrom his time as Florida's governor—but the emails included confidential messages, personal information and even social security numbers from thousands of people. What was he thinking?

The un-redacted email dump was first identified by the Verge, which found emails that, among other things, discussed the firings of public employees. In some emails, petitioners sent their social security numbers to Bush, who was famously responsive to email inquiries from his constituents.


Friday, January 30, 2015

I was quoted in an FCW article on mobile device security.



Striking a balance with mobile device security


Agencies face a delicate balancing act when it comes to providing mobile security.

On the one hand, IT departments seek to extend endpoint security to a growing population of mobile devices. It's easy to see why: Smartphones can go missing along with agency data, and mobile devices in general can introduce malware to enterprise networks. On the other hand, employees want the ease of use of consumer technology, and agency managers covet the potential productivity boost.

More:
http://fcw.com/articles/2014/12/08/striking-a-balance-with-mobile-device-security.aspx


Saturday, January 24, 2015

Best Alternatives to Tor: 12 Programs to Use Since NSA, Hackers Compromised Tor Project

 Here are a list of programs you can use now that Tor has been breached (Note that some of them like Disconnect and Peerblock are not full-scale replacements for Tor and Tails uses Tor):

More:
http://www.idigitaltimes.com/best-alternatives-tor-12-programs-use-nsa-hackers-compromised-tor-project-376976

Thursday, January 15, 2015

New CISSP Domains



CISSP Domains, Effective April 15, 2015

  • Security and Risk Management (Security, Risk, Compliance, Law, Regulations, Business Continuity)
  • Asset Security (Protecting Security of Assets)
  • Security Engineering (Engineering and Management of Security)
  • Communications and Network Security (Designing and Protecting Network Security)
  • Identity and Access Management (Controlling Access and Managing Identity)
  • Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
  • Security Operations (Foundational Concepts, Investigations, Incident Management, Disaster Recovery)
  • Software Development Security (Understanding, Applying, and Enforcing Software Security) 

Saturday, December 6, 2014

Crews maintaining 450 ICBMs had just one wrench with which to attach nuclear warheads



Staff at bases in North Dakota, Wyoming and Montana had to send the toolkit to each other via FedEx, the review found. Mr Hagel said that problem had now been rectified.

Inspectors reportedly ignored the fact that ageing blast doors at nuclear silos would no longer seal shut.

On staffing, the reviews found that a culture of micromanagement and extreme exam-testing distracted from major problems with equipment and nuclear readiness.


Thursday, December 4, 2014

Sony Kept Thousands of Passwords in a Folder Named "Password"


I especially like ALL_SSL_Certs_2012.xlsx!

The second trove of data snuck out sometime yesterday, and it didn't take long for Buzzfeed to stumble upon the Facebook, MySpace (an ancient form of Facebook), YouTube, and Twitter "usernames and passwords for major motion picture social accounts." Likely due to the fact that they were saved in a huge file called "Password." Which contained even more passwords called things like "Facebook login password." So they would know that that was the password. Because who needs encryption or security or common sense or even the vaguest attempt at grade-school level online safety.

Friday, November 28, 2014

Cheap Black Friday Android tablets: Security threats found

 "Bluebox Labs purchased over a dozen of these Black Friday 'bargain' Android tablets from big name retailers like Best Buy, Walmart, Target, Kmart, Kohl's and Staples, and reviewed each of them for security," the company wrote on its blog. "What we found was shocking: most of the devices ship with vulnerabilities and security misconfigurations; a few even include security backdoors. What seemed like great bargains turned out to be big security concerns. Unfortunately, unsuspecting consumers who purchase and use these devices will be putting their mobile data and passwords at risk."

More:
http://bgr.com/2014/11/26/cheap-black-friday-android-tablets/

Tuesday, November 11, 2014

New Attack Method Can Hit 95% Of iOS Devices

 FireEye recommends that organizations warn users to protect themselves three ways. One, users shouldn't install apps from third-party sources other than Apple's official store or an enterprise app store. Two, users shouldn't click on install buttons on a pop-up from third-party web pages. Three, if iOS shows an alert with an "Untrusted App Developer" warning, users should click "Don't Trust" and uninstall the app immediately.

More:
http://www.darkreading.com/new-attack-method-can-hit-95--of-ios-devices/d/d-id/1317359