Just Another Security Blog http://www.infosecwest.com/wp My other server is a botnet Thu, 08 Jan 2009 03:36:47 +0000 http://wordpress.org/?v=2.9.2 en hourly 1 Endless Possibilities http://www.infosecwest.com/wp/?p=14 http://www.infosecwest.com/wp/?p=14#comments Thu, 08 Jan 2009 03:34:04 +0000 admin http://www.infosecwest.com/wp/?p=14

The global credit-crunch has affected many, including my former employer. It is now strongly likely that I will be packing up the family and heading off to continue seeking fame and fortune. With the current financial market volatility it is important to keep focus on the benefits that the recent crisis will have for the security industry and individuals.

As organisations and individuals (including organised crime) are put under financial pressure, crime and employee misdeed will surely increase. History has shown that during these tough times, law enforcement and others charged with the protection of property (physical and intellectual) have their work cut out for them. It stands to reason that the demand for information security and risk has been on the increase.

Now may be a time of turmoil and change, however change more often than not, brings with it new opportunities.

opportunity

Even with housing prices, fuel costs and interest rates on the decrease not everyone will be as fortunate. As you consider your circumstances, you may like to spare a thought for those most impacted by the crisis.

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=14 0
Living in interesting times… http://www.infosecwest.com/wp/?p=9 http://www.infosecwest.com/wp/?p=9#comments Fri, 10 Oct 2008 01:01:03 +0000 admin http://www.infosecwest.com/wp/?p=9 The last 12 months has been a whirlwind of devastation for all who have experienced it.

Global Warming, Financial Meltdown and the end of Big Brother from Australian TV :-)

These times of hardship raise many questions, one of which is, “apart from the cockroaches, who will survive?”

According to Yahoos Hotjobs and Wikipedia there is a range of professions which will weather the storm better than others. But what can you do to help ease the financial burdens on your employer and improve your value to them?

The key is to start today, before crunch time comes. Here are some suggestions to improve your value:

  • Strengthen relationships with your customers.
  • Strengthen relationships with your team.
  • Focus on the wildly important (franklin covey). What things MUST be done?
  • Spend some time considering efficiency. Can a task be automated or techniques improved. Is there a bureacracy which should be changed, challenged or reconsidered?
  • Take initiative and be proactive. Addressing issues before they become a problem.
  • Provide timely and worthwhile MI which will be valued by your stakeholders.
  • Undertake self-improvement, training or professional development.
  • Conduct mentoring, training and knowledge transfer.
]]>
http://www.infosecwest.com/wp/?feed=rss2&p=9 0
Social Engineering http://www.infosecwest.com/wp/?p=8 http://www.infosecwest.com/wp/?p=8#comments Tue, 22 Apr 2008 01:24:06 +0000 admin http://www.infosecwest.com/wp/?p=8 So what exactly is social engineering?

Trickery, subterfuge and exploitation of the human element in the security lifecycle.

Why bother to brute-force passwords when people will gladly give them to you for a chocolate bar.

Social engineering is a heartbreaking challenge for the security professional as it undermines any technical measures which you implement. It crosses the boundary of the binary veil and often results in physical harm to those who are attacked.

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=8 0
Domain targetted by Spam Spoofers http://www.infosecwest.com/wp/?p=7 http://www.infosecwest.com/wp/?p=7#comments Wed, 05 Mar 2008 11:46:03 +0000 admin http://www.infosecwest.com/wp/?p=7 Don’t you just hate it when:

  1. ISP’s auto respond to email bounce messages
  2. Someone forges/spoofs email from your domain
  3. That same someone sends spam

The result is obvious. Lots of email bounces from MTA’s bouncing back email which appears to come from me.

In the words of one of my colleagues “that is pants!”. I am not completely sure what this means or its origin but

its meant to represent a state of badness.

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=7 0
Foiled by a dodgy DNS record http://www.infosecwest.com/wp/?p=6 http://www.infosecwest.com/wp/?p=6#comments Mon, 18 Feb 2008 10:43:30 +0000 admin http://www.infosecwest.com/wp/?p=6 Last week I had a call from one of IINETs customers who was trying to send me email.

Unfortunately for him, but probably fortunate for me, his aforementioned ISP still had DNS records for my domain which were:

Bogus and

5 years old!!!

 

This got me thinking about how many junk DNS entries exist for domains and what are the implications?

Assuming the poor schmo who received my old fixed IP address from IINET was watching his traffic, he would have seen

  • web requests from any user using their DNS
  • email connection requests for anyone trying to send email to me
  • and possibly much worse

It is a good thing that I am a trusting soul :-)

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=6 0
Security problems to fix http://www.infosecwest.com/wp/?p=5 http://www.infosecwest.com/wp/?p=5#comments Mon, 11 Feb 2008 21:25:09 +0000 admin http://www.infosecwest.com/wp/?p=5 Rather than construct a five hundred page document of the broken components in information technology today, I thought I would start simple.

What is one of the most important challenges facing computer security today?

The answer to this question is different to all people, so I considered what affects people most:

  • Social Engineering
  • Scams and Spam
  • Malicious Software (Malware)
  • Hackers and Cyberstalking

Over the coming months we will explore effective and accessible options for addressing each of the security concerns above.

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=5 0
Ground Zero http://www.infosecwest.com/wp/?p=3 http://www.infosecwest.com/wp/?p=3#comments Wed, 30 Jan 2008 12:06:04 +0000 admin http://infosecwest.com/wp/?p=3 So what does an information security guy do when he has a spare 30 mins?

  1. Have a beer, cider or wine with a few friends at the pub
  2. pwn some n00bs in a first person shooter
  3. Trawl through interesting firewall logs
  4. Setup a new website and start a blog

Those who answered 4 are on the money!

 

So, who the heck am I?

Hmm… A deep question indeed!   I am a security professional from Perth Western Australia. (way down under and across to the left)

When I am not Penetration Testing, Vulnerability Assessing, Reverse Engineering Malware, Managing a security incident, Forensically acquiring or analyzing a system, Undertaking Security Reviews of Companies, Analyzing Enterprise Risks or Building Strategies to handle over the horizon threats…..

I am a husband, a father, a brother, a son, a gamer, a really bad musician.

]]>
http://www.infosecwest.com/wp/?feed=rss2&p=3 0