Pages

Wednesday, June 20, 2012

Wednesday, June 6, 2012

Verify Your Linkedin Hash Wasn't Stolen

Check out this link to verify that your Linkedin Hash wasn't one of the 6.5 million stolen today.

http://erratasec.blogspot.com/2012/06/confirmed-linkedin-6mil-password-dump.html

You'll need to find the hash list, but that shouldn't be too hard :)

Monday, June 4, 2012

Looking for "Guest" authors!!

Hello everyone,


I'm looking for guest authors to contribute to my blog www.frontlinesentinel.com. If you're interested in writing about information security topics please contact me at frontlinesentinel[at]gmail.com


Thanks!!

Tuesday, May 29, 2012

Compliant or Complacent? A Security Pro's Viewpoint

Increased government regulations and industry requirements are forcing organizations to comply with standards that in the long run are actually very useful. Many of the required controls can seriously help improve your security posture – especially if your company is new to compliance. 
The compliance trap that many companies fall into is that they focus on passing an audit instead of ensuring a sound network security posture.  Being compliant is one thing, but being secure is a completely different level.

As we’ve seen in the news recently there have been multiple companies that were compliant (and possibly complacent), yet not secure. Achieving compliance should not be the end-all-be-all of your security program; it should be viewed as a minimum baseline.

Read the rest of my article for Algosec.com here:

http://blog.algosec.com/2012/05/compliant-or-complacent-a-security-pros-viewpoint.html

Saturday, May 12, 2012

New Features in Nessus 5.0

In the new verion of Nessus you can filter by exploitable vulnerabilies, framework, pluggins, timeframe, MS-Bulletins, CVSS Score and free text. It also has an updated version of the scanning results and reporting capabilites. Looking pretty good.

Friday, May 11, 2012

An interview with a cybercriminal

There's a thread on reddit.com where a cybercriminal operating a botnet of more than 10,000 nodes utilizing the Zeus banking trojan, DDoS capabilities and the ability to mine bitcoin takes questions from the reddit community.

 http://www.reddit.com/r/IAmA/comments/sq7cy/iama_a_malware_coder_and_botnet_operator_ama/

A few take away's from this thread are as follows:

  • He's an engineering student potentially in the United States. His English is good and he makes references to American movies. 
  • He's aware of the law, cyberlaw in particular, in the way he doesn't use the credit card data, but only sells it. This doesn't mean that he's not stealing, but he does mention the loose laws in other countries, Spain in particular, in which cybercrime is easier to operate.
  • The criminal mentions the utter uselessness of anti-virus and ways that he gets around them. He did however plug Kapersky in being paranoid and giving him a hard time.
  • During questions he does understand that its wrong and he admits he's stealing, but he continues to grasp at straws to try and convince himself that its okay. This is greed.
  • He also admits to hacking other companies under the guise of "Anonymous". Which goes out of the realm of cybercrime and more along the line of mischief. This shows that he's not scared of authority and is fine with flexing his "cyber muscle".
  • He relies on encryption and polymorphic code to keep hidden.
  • His advice on how not to become a victim is very good, especially the use of a LIVE cd. 
All in all this is very interesting look into the mind of a cybercriminal, how they operate and their mindset on how they justify what they do. I'd highly recommend reading it.