Monday, December 28, 2009

Should Employers Ban Facebook at Work?

2009 has indeed been the year of social networks like Facebook, Twitter, and LinkedIn. But some say that social networking at work has become too costly in terms of lost productivity and too risky from a security standpoint. Is it time for a complete ban on social networking in the office, or are guidelines and productivity goals a better solution?

Should employers ban access to social networking sites like Facebook at work? If you look at the potential security risks alone, the answer would be resounding yes for most enterprises. Aside from the security risk, there's the huge hit that social networking has had on employee productivity One estimate -- from IT consulting company Morse -- figures employee use of social-networking sites cost employers $2.25 billion a year in lost productivity.

Yet even with the productivity and security challenges caused by social media, there is no still easy answer to the Facebook ban question. There are, however, plenty of opinions and guidelines that can help your company make a sound decision around the use of social networking from 9 to 5.

Read more about this @

http://www.enterprise-security-today.com/story.xhtml?story_id=12300AYS00HU

Wednesday, December 23, 2009

Hackers block Microsoft Cofee law enforcement software

Hackers have released software designed to attack a Microsoft tool used by law enforcement agencies.

According to a report on The Register the hack known as Decaf automatically launches countermeasures to Computer Online Forensic Evidence Extractor (Cofee), which provides tools used in the collection of digital evidence.

Last month copies of Cofee appeared on file sharing websites.

Microsoft said last month it does not expect cyber criminals to be able to use the software to their advantage. It said Cofee is just a collection of digital forensic tools which are already available.

Read More about this @

http://www.computerweekly.com/Articles/2009/12/15/239700/Hackers-block-Microsoft-Cofee-law-enforcement-software.htm

Illegal copies of Microsoft Cofee spills onto the web

Microsoft software that is designed to help the police access encrypted data is loose on the web.

The software, known as Computer Online Forensic Evidence Extractor (Cofee), has been put on file-sharing site, according to reports on the web. It is illegal for unauthorised people to use the software or download it.The software helps law enforcement agencies access details about crimes before criminals can wipe the information.

"Cofee brings together a number of common digital forensics capabilities into a fast, easy-to-use, automated tool for first responders. And Cofee is being provided [free] to law enforcement around the world," said Microsoft.

Read More about this @

http://www.computerweekly.com/Articles/2009/11/09/238474/Illegal-copies-of-Microsoft-Cofee-spills-onto-the-web.htm

Friday, December 18, 2009

Twitter hacked by 'Iranian Cyber Army'

The popular microblogging Web site Twitter was hacked overnight, leaving the millions who use the site tweetless.Those who tried to access Twitter were redirected to a site that had a green flag and proclaimed "This site has been hacked by Iranian Cyber Army."

Read more @ http://www.cnn.com/2009/TECH/12/18/twitter.hacked/

Take a Little Care While Christmas Shopping Online

Legitimate businesses use encryption that protects your credit card data as it travels from your computer to the merchant. This means the Web address for sending in the order will begin with https instead of the familiar http. The change from http to https may not happen until you move to the page that actually processes your order.

So today we'll talk about a shopping topic where I can truly help -- showing you how to dodge some of the hazards of shopping online. This is the peak time of the year for online shopping and, for those of us who get a little dizzy just thinking about navigating mall crowds, online shopping can be an attractive notion. 

There are ways to do it that reduce the chance of broken hearts and busted bank accounts.

Read more about this article @ 

http://www.enterprise-security-today.com/story.xhtml?story_id=101003HE7GX5

Tuesday, December 8, 2009

The world’s top 5 riskiest top-level domains

McAfee’s 3rd Annual “Mapping the Mal Web” report highlights the top-level domains with the most road hazards. 

Like the auto industry, the Internet wasn’t designed with seatbelts and airbags. It took years and some determined people to get the auto industry to make safety changes. McAfee’s latest report highlight’s why so many security vendors are offering add-on safety features to protect your browsing experience. In today’s Web, attackers are poking holes in legitimate websites to set up drive-by downloads, typosquatters are waiting for someone’s fat fingers to mistype a URL and many are using search engine optimization to get their mischievous sites listed prominently in search results.

Read More about this @

http://itknowledgeexchange.techtarget.com/security-bytes/the-world’s-top-5-riskiest-top-level-domains/

Yahoo login credentials at risk to hijacking attack

A new phishing attack attempts to steal Web hosting login credentials from Yahoo Inc. and other service providers.

Read more @ 

http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1376209,00.html?track=sy160&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29

Monday, December 7, 2009

Putting a Fair Internet Use Policy in Place

There are real security problems and many, many threats, not only from e-mail but also from web browsing. Your employee could be browsing online, come across a link, click on it, and download a little file. That's how some piece of malware finds its way onto the machine and from there it gets into all the machines on the network.

More than half of employees who have Internet access at work say they will shop for holiday gifts from the office, according to a November poll conducted for Shop.org, a division of the National Retail Federation. While online shopping may be more efficient than braving the crowds at lunch hour, employee shopping can compromise both security and productivity, says David Kelleher of GFI Software, which sells remote monitoring and management software primarily to small and medium firms. He spoke recently about this topic with Smart Answers columnist Karen E. Klein. Edited excerpts of their conversation follow.

Read more about this @

http://www.enterprise-security-today.com/story.xhtml?story_id=012000108410

Monday, November 9, 2009

Wednesday, November 4, 2009

HP-UX System Getting restarted on scan

Details for HP-UX system I did the scan.

HP-UX OS Version -11.31 Integrity superdome and Itanium CPU.

Cluster version: Service Guard version 11.19

I have further checked and found that this problem is caused by a missing patch PHSS_40145 on HP-UX 11.31 server which I scanned. During the port scanning phase, Nessus/(any port scan can cause) initiated the reboot of the server.

PHSS_40145: 11.31 Serviceguard A.11.19.00
ABORT PANIC If cmcld receives unexpected data cmcld may hang
resulting in a node TOC. The following messages will be logged in flight
recorder
log SEC:01: Event - Unknown message version

Fix is available via below patches
PHSS_40144 Serviceguard A.11.19 on HP-UX 11.23
PHSS_40145 Serviceguard A.11.19 on HP-UX 11.31

So it is recommended to apply these patches before doing any scans and Please ensure the scans are conducted during the non-bussiness hours.

https://discussions.nessus.org/message/3808#3808


Tuesday, October 13, 2009

METASPLOIT UNLEASHED - MASTERING THE FRAMEWORK

A free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals.

Source: http://www.offensive-security.com/metasploit-unleashed/

Need of Social Engineering Tests

Social engineering is an art by which trick the working class or an organization and getting comply with your wishes. The basic goals of social engineering are to get unauthorised access to systems or information in order to commit fraud, industrial espionage, identity theft, or simply to interrupt the system or network.
Social engineering is in essence the practice of obtaining confidential information or coercing people into performing a particular action from users of your network. Social engineering techniques are also used to gain access to premises and other company assets.
'Social Engineering' is a threat, often overlooked but regularly exploited; to take advantage of what has long been considered the 'weakest link' in the security chain of an organization – the 'human factor'.
Everyone should want to be security conscious because not only does the company benefit from being aware, but that mentality will carry over into their personal lives as well, which will help prevent them becoming a victim of identity theft and a number of other crimes.

A company can spend billions of dollars on all kinds of security equipment, but it only takes one person for a company’s security to be compromised.

It is important to be familiar with Social Engineering techniques to reduce the likelihood of success. By having this knowledge, one can ensure appropriate (preventative, detective and corrective) measures are implemented to protect the staff and assets of an organization.

Information Gathering, observing human behavior, Shoulder surfing, Checking the rubbish (Dumpster diving), By acting like an helpless user or by acting like an user from technical support or by acting like an important user, By sending fake mails to get important information like credit card details, phishing, Telephone etc.

A company will obviously have to have a social engineering training plan made to fit the Company’s needs. A great social engineering strategy plan may be short lived if it is not reinforced with occasional mock social engineering attempts or short little tips emailed or posted regularly in a bulletin that everyone receives. Procedures and guidelines should be in place specific to your companies function to minimize the threat of social engineering.
Everyone should want to be security conscious because not only does the company benefit from being aware, but that mentality will carry over into their personal lives as well, which will help prevent them becoming a victim of identity theft and a number of other crimes.
                                                                   - Ratheesh Kannan

Tuesday, October 6, 2009

No Emergency Patch For Latest Windows Exploit

Another reason for Windows users to hate the Microsoft Patch Tuesday policy,

The exploit isn’t 100% reliable but it’s still fairly significant, as it is a critical vulnerability and can be used for code execution.

To read more, click on the link below:

Microsoft Confirms Hotmail Data Posted on Web Site

Thousands of usernames and passwords from hotmail.com, msn.com and live.com accounts were posted on a third-party site (http://pastebin.com), Microsoft has confirmed. The Windows Live Hotmail data leak was not due to a phishing scheme and not a data breach, Microsoft said. The Hotmail users affected appeared to be mostly based in Europe.

Wednesday, September 30, 2009

XSS Worm on Reddit.com

Reddit (reddit.com) is a social news website, and it's much better than Digg or Slashdot.

However, it got hit  by a XSS worm that was spreading via comments on the site.

Read more about this at: http://www.securityfocus.com/blogs/2318

Effectively Protecting Your Customers' Data

Contact center staff are on the data security front lines. Properly trained they can thwart intrusion. Unfortunately contact centers too frequently have environments that foster data loss and theft. Employees are typically low-paid and have minimal or no benefits, are often poorly supervised, rushed to meet metrics, and face enormous stress.

Today's organizations depend and thrive on data for marketing, customer service and staff management, and like anything that is valuable, criminals have been seeking it to commit ID theft, blackmail or other crimes. 

The 2009 Identity Fraud Survey Report by Javelin Strategy and Research reports that the number of identity fraud victims has increased 22 percent to 9.9 million adults in the U.S., while the total annual fraud amount increased by seven percent to $48 billion over the past year. The reasons include profitability, safety and simplicity, explains Greg Young, research vice president, Gartner.

Read more about this article at: http://www.enterprise-security-today.com/story.xhtml?story_id=131004IMXRIW

Microsoft Security Essentials Available for Download

Microsoft has released its Security Essentials antivirus software as a free download to protect against malware, viruses and spyware. Microsoft said its goal is to remove cost barriers that leave PCs unprotected. The free Microsoft Security Essentials could result in wiping out software from competitors, including Arbor Networks, Symantec and McAfee.
After introducing its antivirus software to 75,000 beta testers in June as Microsoft Security Essentials Beta, Microsoft has made its Security Essentials antivirus software available as a free download.
Click on the below link to download MS Secuirty Essential :>

Tuesday, September 22, 2009

Security challenges with cloud computing services

If you entrust a cloud provider with your data, how is encryption handled, if at all? What about user authentication? What about data breach liability? 

Those were some of the issues raised during a panel discussion on the security challenges with cloud computing services at last week's Bay Area SecureWorld in Santa Clara, Calif. "We're not saying the cloud is bad. There is a lot of good there, but we want to bring the challenges to your attention," said panelist Tim Mather, a security advisor and a founding member of the Cloud Security Alliance (CSA). 

One of the major cloud security issues is encryption, he said. If data is processed in the cloud it needs to be decrypted, while some providers don't even offer encryption. And if encryption is used, key management becomes a big issue, he said: "Who manages the keys"?
Read more at:

Thursday, September 17, 2009

Brute force attacks target Yahoo email accounts

Attackers, willing to do anything to hijack webmail accounts to boost their spam campaigns, are bypassing the traditional Web login interface page to seek out a backdoor into accounts. 

Those attackers have targeted Yahoo and are successfully cracking account passwords by focusing automated password cracking scripts on a Yahoo Web services-based authentication application thought to be used by Internet service providers (ISPs) and third-party Web applications.
That was the finding of the Web Application Security Consortium Distributed Open Proxy Honeypot project, maintained by researchers at Breach Security Inc. The honeypot is tracking an extensive series of brute force attacks successfully targeting account credentials of Yahoo email users.
Read more about this at:-

Tuesday, September 15, 2009

Microsoft Telnet Vulnerable to Remote Code Execution

The vulnerability reported for Microsoft Telnet could allow an attacker to obtain credentials and then use them to log back into affected systems.The vulnerability could allow an attacker to obtain credentials and then use them to log back into affected systems. The attacker would then acquire user rights on a system identical to the user rights of the logged-on user. This scenario could ultimately result in remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Click on the below link for more information:-