Monday, December 7, 2009

Putting a Fair Internet Use Policy in Place

There are real security problems and many, many threats, not only from e-mail but also from web browsing. Your employee could be browsing online, come across a link, click on it, and download a little file. That's how some piece of malware finds its way onto the machine and from there it gets into all the machines on the network.

More than half of employees who have Internet access at work say they will shop for holiday gifts from the office, according to a November poll conducted for Shop.org, a division of the National Retail Federation. While online shopping may be more efficient than braving the crowds at lunch hour, employee shopping can compromise both security and productivity, says David Kelleher of GFI Software, which sells remote monitoring and management software primarily to small and medium firms. He spoke recently about this topic with Smart Answers columnist Karen E. Klein. Edited excerpts of their conversation follow.

Read more about this @

http://www.enterprise-security-today.com/story.xhtml?story_id=012000108410

Monday, November 9, 2009

Wednesday, November 4, 2009

HP-UX System Getting restarted on scan

Details for HP-UX system I did the scan.

HP-UX OS Version -11.31 Integrity superdome and Itanium CPU.

Cluster version: Service Guard version 11.19

I have further checked and found that this problem is caused by a missing patch PHSS_40145 on HP-UX 11.31 server which I scanned. During the port scanning phase, Nessus/(any port scan can cause) initiated the reboot of the server.

PHSS_40145: 11.31 Serviceguard A.11.19.00
ABORT PANIC If cmcld receives unexpected data cmcld may hang
resulting in a node TOC. The following messages will be logged in flight
recorder
log SEC:01: Event - Unknown message version

Fix is available via below patches
PHSS_40144 Serviceguard A.11.19 on HP-UX 11.23
PHSS_40145 Serviceguard A.11.19 on HP-UX 11.31

So it is recommended to apply these patches before doing any scans and Please ensure the scans are conducted during the non-bussiness hours.

https://discussions.nessus.org/message/3808#3808


Tuesday, October 13, 2009

METASPLOIT UNLEASHED - MASTERING THE FRAMEWORK

A free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals.

Source: http://www.offensive-security.com/metasploit-unleashed/

Need of Social Engineering Tests

Social engineering is an art by which trick the working class or an organization and getting comply with your wishes. The basic goals of social engineering are to get unauthorised access to systems or information in order to commit fraud, industrial espionage, identity theft, or simply to interrupt the system or network.
Social engineering is in essence the practice of obtaining confidential information or coercing people into performing a particular action from users of your network. Social engineering techniques are also used to gain access to premises and other company assets.
'Social Engineering' is a threat, often overlooked but regularly exploited; to take advantage of what has long been considered the 'weakest link' in the security chain of an organization – the 'human factor'.
Everyone should want to be security conscious because not only does the company benefit from being aware, but that mentality will carry over into their personal lives as well, which will help prevent them becoming a victim of identity theft and a number of other crimes.

A company can spend billions of dollars on all kinds of security equipment, but it only takes one person for a company’s security to be compromised.

It is important to be familiar with Social Engineering techniques to reduce the likelihood of success. By having this knowledge, one can ensure appropriate (preventative, detective and corrective) measures are implemented to protect the staff and assets of an organization.

Information Gathering, observing human behavior, Shoulder surfing, Checking the rubbish (Dumpster diving), By acting like an helpless user or by acting like an user from technical support or by acting like an important user, By sending fake mails to get important information like credit card details, phishing, Telephone etc.

A company will obviously have to have a social engineering training plan made to fit the Company’s needs. A great social engineering strategy plan may be short lived if it is not reinforced with occasional mock social engineering attempts or short little tips emailed or posted regularly in a bulletin that everyone receives. Procedures and guidelines should be in place specific to your companies function to minimize the threat of social engineering.
Everyone should want to be security conscious because not only does the company benefit from being aware, but that mentality will carry over into their personal lives as well, which will help prevent them becoming a victim of identity theft and a number of other crimes.
                                                                   - Ratheesh Kannan

Tuesday, October 6, 2009

No Emergency Patch For Latest Windows Exploit

Another reason for Windows users to hate the Microsoft Patch Tuesday policy,

The exploit isn’t 100% reliable but it’s still fairly significant, as it is a critical vulnerability and can be used for code execution.

To read more, click on the link below:

Microsoft Confirms Hotmail Data Posted on Web Site

Thousands of usernames and passwords from hotmail.com, msn.com and live.com accounts were posted on a third-party site (http://pastebin.com), Microsoft has confirmed. The Windows Live Hotmail data leak was not due to a phishing scheme and not a data breach, Microsoft said. The Hotmail users affected appeared to be mostly based in Europe.