Hullo

That’s right, this site is back from the dead. I feel rather bad for not having written anything here for awhile. That and WordPress 3.0 has just been released, and I figured that was just the impetus I needed to start blogging again. Check out some of the cool new features:

I can’t promise how active it will be in the immediate future as I’m going to be busy with a cross country move shortly, but rest assured I’ll do my best to keep the cobwebs here at bay. Thanks for dropping by.

The New Insider Threat

It’s not a new threat really. People inside an organization can always be a threat. It’s just that many people, some of them prominent security professionals, have been downplaying the insider threat lately in order to hype other emerging threats. I’m of the opinion that we’ll see insider threats rise through the year and probably into next. As the economy worsens, people who are becoming financially stressed may turn to corporate crime, or may retaliate for being laid off.

Prime example, news this week of a former Fannie Mae contractor leaving a malicious script designed to wipe out thousands of computers after he was fired for…a scripting error he made earlier in the month. Luckily they stumbled upon the script before it was set to execute. They might not have been so lucky though. Bruce Schneier has some good tips about reducing the threat trusted individuals can pose.

In the end, you can take several measures to reduce your insider risk but you can never eliminate it entirely. At the end of the day the weakest link always comes down to people. People are sometimes dishonest, it’s simply a fact of life. Luckily for the rest of us, they seem to be a pretty small minority.

Nmap Network Scanning Review

Nmap Network Scanning by Fyodor
Title: The long winded title for this book is Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning, but I’ll just be calling it NNS.
Author: Gordon “Fyodor” Lyon
Rating: *****
Bottom Line: The definitive nmap book, for all your network scanning needs.

From the moment you start to read NNS, it is engaging and informative. The wealth of information contained in this book will have even hardcore nmap experts learning a thing or two about the preeminent network scanner. Of course, I expected nothing less from NNS because the author is nmap’s chief architect and programmer, Fyodor. Inside you’ll find his 11 years of network scanning experience distilled down into the ultimate nmap guide.

The material is presented in an engaging way, and wherever possible examples are given where the techniques described are applied in real world scenarios. The book is also littered with command line and output examples as well as diagrams. These items in addition to the text allow one to enjoy and learn from the book without having to sit in front of a command line and try every single command yourself. That said, it took me a bit of time to get through the book because I kept stopping to play with new options I’d learned. 🙂

From introductory network scanning (What’s a stealth SYN scan?), to scan optimization (Why is it taking so long?!), to advanced techniques (Learn how to write your own nmap plug ins!), NNS covers the gamut. Anyone who does even occasional network scanning with nmap (And you are scanning your network on a regular basis aren’t you?) owes it to themselves to pick this one up.

Bookmark Backup?

Are you backing up your bookmarks? Oh, you don’t store local bookmarks? You use a social bookmarking website you say? Well I hope you weren’t using Ma.gnolia. They announced on Friday morning that they’ve experienced a catastrophic data loss. Wired is reporting Ma.gnoalia has lost both their production database and backups of user data. Bye bye bookmarks!

So my question to you is, do you have backups? Ma.gnolia didn’t. If they did have backups, my guess is they failed step 5 on the path to the tao of backup. While I have both local and off site backups (that yes, I test on a frequent basis…it’s all about restores!), I had overlooked my bookmarks. Luckily, they are safe and sound on del.icio.us. I might not be so lucky next time though. If you’re a del.icio.us user as well, I suggest you export a copy for safe keeping. Then take a moment to think about what else you have stored, and stored solely, in the cloud. Make sure you add those things to your backup procedures.

Risk Analysis

I’ve been thinking about risk analysis recently. The Times Online has an interesting story on teaching risk analysis in schools. People need proper tools to assess the deluge of information given to them. They tend to blow emotional stories up (like one person in the US getting mad cow disease) even if their personal risk is very low. It doesn’t help that it’s so easy to lie with statistics either.

Speaking of a risk analysis deficit, there must be a major one on the interstate. Every time I’m driving along, I notice when going from a 65 mph zone into a 55 mph zone most people seem to maintain their previous speed. People who wouldn’t go over the speed limit, or were only going 5 mph over had no problem with suddenly going 10 or 15 mph over. Hello?! What’s wrong with people? Maybe it’s just because I’m sort of in that risk mindset, but it seems rather silly.

Of course, if you’re being really risk adverse you’d probably take the bus instead! 🙂

Interesting SANS posts

Some interesting posts on the SANS Internet Storm Center blog. I’m sure these have already been posted everywhere (I saw one on delicious earlier), but it’s always good to have these kinda things to refer back to later.

The first post is about targeted social engineering. One of the more interesting aspects:

In one incident, an attacker used phrases directly taken from a public blog, as well as a cordial greeting that the blogger had used when writing about a personal topic. This made the message significantly more authentic to the target, who duly clicked on the attachment.

Pretty clever. Anything you can do to make people even subconsciously believe a message is legitimate will increase your success rate. It only takes one person to fall for it in most cases, to get a foothold that you can leverage for a deep internal attack.

The other post is simply a list of what NOT to do when it comes to IT security. Some of the highlights:

  • Assume the users will read the security policy because you’ve asked them to.
  • Assume that policies don’t apply to executives.
  • Don’t review system, application, and security logs.
  • Expect end-users to forgo convenience in place of security.

I’d add a couple of my own to the list:

  • Assume that because you’ve never been compromised you’re secure
  • Assume that you can prevent all compromises
  • Protect only the perimeter
  • Have no incident response plan

Style

You may notice the blog at times might not look quite right. I’m still perodically working on the CSS style to get it to look correct. While I work on it you might notice it looking whacky. I’m temporarily leaving on the default look until I finish the design.

Juxtaposed

Transatlantic Cables Terminated in Avon NJ

Transatlantic Cables Terminated in Avon NJ

I couldn’t resist this juxtaposition. These cables are VSNL submarine telecommunications cables that cross the Atlantic and come above ground in the VSNL building in Avon, NJ. They are capable of carrying over an estimated 3.5 Tbps (that is terabits per second). Probably less from over head and my guess from the article’s figure (60,000,000 simultaneous voice calls = 60,000,000 DS0s = 60,000,000 * 64kb/s). In any case, those cables are extremely important for international communication but they look like utterly unimportant buried utility cable. Just a great photograph. Via Wired.