Archive for February, 2007

Security Shifts to Data

Thursday, February 15th, 2007

Eric Lundquist, in a February 5 eWeek article, tells a story that is near to my heart–it’s about the data, stupid.  For years security has been focused on system or device protection.  This must  change.

Our goal as security professionals is to protect the confidentiality, availability, and integrity of the data.  This means protecting it at rest and in motion.  Protecting your HR servers doesn’t do much good if your employees’ PII (personally identifiable information) is compromised through storage or LAN/WAN access control weaknesses.  Carrying this a bit further, IM and email transfer of sensitive information completely bypasses any device or perimeter security that isn’t specifically designed to filter and block/alert on sensitive information moving into insecure areas, like the Internet or internal systems at lower trust levels.

New ‘Drive-By’ Attack Is Remote

Thursday, February 15th, 2007

In a February 15 Dark Reading article, Kelly Jackson Higgins reports on a proof of concept attack against broadband routers.  Called drive-by pharming, attackers can gain web access to home or business broadband equipment by using manufacturer default passwords.  This attack vector differs from war driving attacks because the attacker doesn’t have to be anywhere near the target device.  The best defense is to ensure all default passwords are changed when implementing broadband routing equipment.

 

 

Protect yourself from the byproducts of software piracy

Thursday, February 15th, 2007

It isn’t news that software piracy is a big problem for software vendors.  Illegal use of applications has been going on since the first PC rolled off the line.  What might be news, however, is the negative impact piracy might have on the Internet and on your company network.

See the rest of the article here.

 

______________________________________________________

Check out my book, Just Enough Security, at Amazon.com

Additional security management resources are available at http://adventuresinsecurity.com/.

My podcasts –> http://blastpodcast.com/viewpodcast.html?id=441

Free security training –> http://adventuresinsecurity.com/SCourses
_________________________________________________________

I’m Back

Wednesday, February 14th, 2007

After living several months at ITTOOLBOX.com, I’ve returned to my original home.  I hope you’ll check in for daily security updates.

You might also want to check out my articles and security updates at TechRepublic.com