Search

Search results below

Thursday, April 23, 2009

Hacking the Industrial Network

The expense of protection is a fraction of 1% of the IT budget.

By Frank Dickman, Engineering Consultant

The Issue
It was a Trojan program inserted into SCADA system software that caused a massive natural gas explosion along the Trans-Siberian pipeline. The Washington Post reported the resulting fireball yielded "the most monumental non-nuclear explosion and fire ever seen from space."

Malicious hackers have discovered SCADA (Supervisory Control and Data Acquisition) and DCS (Distributed Control Systems) since reports of successful attacks began to emerge after 2001. A former hacker interviewed by PBS Frontline advised that "Penetrating a SCADA system that is running a Microsoft operating system takes less than two minutes."

DCS, SCADA, PLCs (Programmable Logic Controllers) and other legacy control systems have been used for decades in power plants and grids, oil and gas refineries, air traffic and railroad management, pipeline pumping stations, pharmaceutical plants, chemical plants, automated food and beverage lines, industrial processes, automotive assembly lines, and water treatment plants.

The History

There are a wide range of security technologies that can be used to protect the corporate network, but these are less successful within a production network. Software-based solutions (personal firewalls, anti-virus software) cannot run on some proprietary operating systems, due to lack of compatibility, and often can't be integrated into systems which use older processor technology -- because these lack the necessary performance.

The following table illustrates chronological history of publicly reported hacking incidents that provide a chilling insight into the problems and their potential for disruption and disaster. Some of these damaging exploits were kept secret for years.


"Some of these damaging exploits were kept secret for years."

A Short Chronological List of Widely Reported Incidents of Hacking and Disruption

Feb 2009 Highly evasive Conficker/Downadup worm infects 12 million computers, stealing information. - BBC
Jun 2008 "Security Hole Exposes Utilities to Internet Attack" - Associated Press
May 2008 SCADA vulnerability...control software used by one-third of industrial plants. - SC Magazine
Mar 2008 Emergency 2-day shutdown of Hatch nuclear plant from software update on one business computer.
Feb 2008 Retail Chinese digital picture frame virus steals passwords and financial info. - SF Chronicle
Jan 2008 Hackers turn out the lights in multiple cities and demand extortion payments." - Associated Press
Sep 2007 DOE Idaho National Lab video shows the remote destruction of a large SCADA controlled generator.
Sep 2007 Hackers compromise Homeland Security computers, moving information to Chinese websites. - CNN
Jul 2007 3Com's security division demonstrates how SCADA system flaws can be exploited.
Nov 2007 "Insider Charged with Hacking California Canal System" - ComputerWorld
Nov 2007 "Solar Sunrise" - Three teenagers penetrate USAF logistic systems at Middle East support bases.
Aug 2007 "Hackers Take Down the Most Wired Country in Europe" for two weeks. - Wired Magazine
Jun 2006 "Information on SCADA systems can be found by a determined attacker." - US-CERT
Jan 2006 Homeland Security Conference - SCADA systems are vulnerable to intrusion. - UrgentComm
Jan 2006 "SCADA Security & Terrorism: We're Not Crying Wolf" conference presentation. - Xforce Security
Aug 2005 175 companies including Caterpillar, General Electric, UPS and DaimlerChrysler attacked by Zotob worm.
2003-2005 Undetected for 2 years, Chinese Army downloads 10-20 terabytes data from Pentagon, DOE, others.
Aug 2003 CSX loses signaling & dispatch control over 23 state railroad due to a worm virus. - InformationWeek
2003 "Cyber War" - PBS Frontline documents penetration of US utilities using commonly known methods.
Jan 2003 Davis-Besse nuclear plant safety monitoring system knocked offline 5-hours by the Slammer worm.
Jan 2003 "Slammer" worm infects 300,000 computers in the first 15 minutes, interrupting 911 and airlines.
Sep 2001 "Nimda" worm infects millions of computers causing billions of dollars in damage. Originator unknown.
Jul 2001 "Code Red" worm infects 300,000 computers in a month and then launches attack on White House web.
Apr 2000 Hackers succeeded in gaining control of the world's largest natural gas pipeline network (GAZPROM).
Apr 2000 Hacker uses a SCADA system to dump millions of gallons of sewage onto hotel grounds for 3 months.
1998-2000 "Moonlight Maze" - For two years, hackers penetrated the Pentagon, NASA, DOE, university labs.
1998 A 12-year-old hacks into Roosevelt Dam, with complete SCADA system control of massive floodgates.
1997 "Eligible Receiver" - DOD & Joint Chief Command hacked in 48 hours with publicly available methods.
1997 A teenager hacks into NYNEX and cuts off air/ground communication to Worchester Airport for 6 hours.

Many more incidents go unreported for reasons of national security or corporate embarrassment. Even more go undetected. Properly executed, successful hacks are undetectable and untraceable.

The threat comes in many forms. It does not need to be an intelligently directed attack. The non-intelligent Slammer worm covered the globe in 30 minutes, infected business and Pentagon computers in the first 8 minutes, and caused $3 billion damage to Wall Street.
Common Objections

"Our production systems are completely isolated from outside access"
In his book "The Art of Intrusion," hacker Kevin Mittnick clearly explains how even a neophyte can easily gain root (administrator) access to the entire network through the corporation's protected public website, from anywhere in the world. The majority of PLCs are currently ordered with Web services enabled, but 87% of users leave the Web servers active, unused (and not configured), with factory default passwords.

"Our system is secure because it would be impossible for an outsider to understand it."
This is nicknamed "security by obscurity" and has repeatedly been shown to be a false assumption. There are only 5-6 leading DCS and SCADA systems used throughout the world, and there are millions of U.S. and foreign engineers who have been trained in their use.

"We're not a likely target. We're not important or interesting enough to attract hackers."
Malware (Trojans, viruses and worms) can be inadvertently downloaded from the Internet, and these can replicate themselves on portable memory devices of all types. In 2008, digital picture frames sold by major retailers were found infected with a program that disabled antivirus software and sent passwords to servers in China.

"We've never had a problem. There has been no intrusion or disruption in our production network."
When new Intrusion Detection Systems (IDS) were installed on US Department of Defense networks, they showed that thousands of attempted illegal penetrations were going on daily. One general was incensed. "Before we had these IDS, we were never attacked. Now that we got them on the network, people are attacking our nets every day thousands of times trying to get in! And some of them are getting in!"

"We can't justify the expense and manpower."
The expense of protection is a fraction of 1% of the IT budget. With the latest generation of equipment, a network of protection can be installed, plug and play, by a handful of technicians rather than IT managers. Production need not be interrupted. Beyond ROI, the simplest justification is "What will we suffer if a disaster shuts us down?"

The consequences of production interruption in the Industrial sector are much more serious than failures within the office network. In 2005, the Zotob worm simultaneously attacked 175 major corporations including Caterpillar, General Electric, DaimlerChrysler and United Parcel Service. Thirteen U.S. DaimlerChrysler plants had to be shut down, idling their assembly lines and 50,000 workers. What do you think that cost per hour?
"Thirteen U.S. DaimlerChrysler plants had to be shut down, idling their assembly lines and 50,000 workers. What do you think that cost per hour?"
Harmful programs, capable of paralyzing automation systems, are often introduced internally. External service technicians, contractors, employees and visiting consultants with laptops can inadvertently (or deliberately) introduce malicious software behind the external firewall. Surveys reveal that roughly 40% of security incidents involved insiders.

Establishing production network security bears a close relationship to the logic of adhering to fire codes.

Industry Recommendations

The ideal solution would require several unique features. It should provide distributed "Defense in Depth" as a second or third layer of protection. These offer greater security, flexibility and lower cost. It should be capable of providing various levels of security. It should be easy to implement, by technicians rather than network administrators, without modification to the network's configuration.

Various Applications and Formats Available: Rackmount, DIN Mount and PCI cards

Templates for devices should be configurable for single units or very large groups from a central location. It should be available in various formats, provide hardware and software based security, and be applicable to various network configurations.

It should monitor incoming and outgoing data packets offering secure communication via Virtual Private Network (VPN) tunnels. Ideally, the solution and firewall should be invisible to intruders attempting to map the network. Network Address Translation (NAT) should be used to provide protection by IP address masquerading.

For remote maintenance and diagnostics, the ideal solution would be one that denies access, even by the original manufacturer of the production equipment, except when the equipment operations people request it, and when the connection is strictly authenticated via digital certificates of authority.
Specific industrial-based solutions are already available. They may be lesser known in the IT world because they exist in the industrial space, and they may be lesser known in the security world, where there is a tendency to concentrate on physical security and physical access.

Products include Phoenix Contact mGuard™, Byers Tofino, Siemens Scalance, Weidmuller IE, Hirschmann Eagle mGuard™, and Innominate mGuard™. It was Innominate Security Technologies AG, the developer of mGuard, that won the Frost & Sullivan "2008 Global Ethernet Security Product Value Leadership of the Year Award," for their mGuard product family. Some of the products listed above are derived from the Innominate product set or licensed and rebranded OEM products based on earlier Innominate software release.

This article was read at http://www.industryweek.com/articles/hacking_the_industrial_network_18937.aspx

Critical infrastructure must be protected and kept out from cyber evils. Stealth technologies must be used so that these can be undetected from the internet. Internal exploits still remain a threat.

Wednesday, April 15, 2009

PIN Crackers Nab Holy Grail of Bank Card Security

By Kim Zetter
Hackers have crossed into new frontiers by devising sophisticated ways to steal large amounts of personal identification numbers, or PINs, protecting credit and debit cards, says an investigator. The attacks involve both unencrypted PINs and encrypted PINs that attackers have found a way to crack, according to the investigator behind a new report looking at the data breaches.

The attacks, says Bryan Sartin, director of investigative response for Verizon Business, are behind some of the millions of dollars in fraudulent ATM withdrawals that have occurred around the United States.

"We're seeing entirely new attacks that a year ago were thought to be only academically possible," says Sartin. Verizon Business released a report Wednesday that examines trends in security breaches. "What we see now is people going right to the source ... and stealing the encrypted PIN blocks and using complex ways to un-encrypt the PIN blocks."

The revelation is an indictment of one of the backbone security measures of U.S. consumer banking: PIN codes. In years past, attackers were forced to obtain PINs piecemeal through phishing attacks, or the use of skimmers and cameras installed on ATM and gas station card readers. Barring these techniques, it was believed that once a PIN was typed on a keypad and encrypted, it would traverse bank processing networks with complete safety, until it was decrypted and authenticated by a financial institution on the other side.

But the new PIN-hacking techniques belie this theory, and threaten to destabilize the banking-system transaction process.

Information about the theft of encrypted PINs first surfaced in an indictment last year against 11 alleged hackers accused of stealing some 40 million debit and credit card details from TJ Maxx and other U.S. retail networks. The affidavit, which accused Albert "Cumbajohnny" Gonzalez of leading the carding ring, indicated that the thieves had stolen "PIN blocks associated with millions of debit cards" and obtained "technical assistance from criminal associates in decrypting encrypted PIN numbers."

But until now, no one had confirmed that thieves were actively cracking PIN encryption.

Sartin, whose division at Verizon conducts forensic investigations for companies that experience data breaches, wouldn't identify the institutions that were hit or indicate exactly how much stolen money was being attributed to the attacks, but according to the 2009 Data Breach Investigations report, the hacks have resulted in "more targeted, cutting-edge, complex, and clever cybercrime attacks than seen in previous years."

"While statistically not a large percentage of our overall caseload in 2008, attacks against PIN information represent individual data-theft cases having the largest aggregate exposure in terms of unique records," says the report. "In other words, PIN-based attacks and many of the very large compromises from the past year go hand in hand."

Although there are ways to mitigate the attacks, experts say the problem can only really be resolved if the financial industry overhauls the entire payment processing system.

"You really have to start right from the beginning," says Graham Steel, a research fellow at the French National Institute for Research in Computer Science and Control who wrote about one solution to mitigate some of the attacks. "But then you make changes that aren't backwards-compatible."

PIN hacks hit consumers particularly hard, because they allow thieves to withdraw cash directly from the consumer's checking, savings or brokerage account, Sartin says. Unlike fraudulent credit card charges, which generally carry zero liability for the consumer, fraudulent cash withdrawals that involve a customer's PIN can be more difficult to resolve since, in the absence of evidence of a breach, the burden is placed on the customer to prove that he or she didn't make the withdrawal.

Some of the attacks involve grabbing unencrypted PINs, while they sit in memory on bank systems during the authorization process. But the most sophisticated attacks involve encrypted PINs.

Sartin says the latter attacks involve a device called a hardware security module (HSM), a security appliance that sits on bank networks and on switches through which PIN numbers pass on their way from an ATM or retail cash register to the card issuer. The module is a tamper-resistant device that provides a secure environment for certain functions, such as encryption and decryption, to occur.

According to the payment-card industry, or PCI, standards for credit card transaction security, PIN numbers are supposed to be encrypted in transit, which should theoretically protect them if someone intercepts the data. The problem, however, is that a PIN must pass through multiple HSMs across multiple bank networks en route to the customer's bank. These HSMs are configured and managed differently, some by contractors not directly related to the bank. At every switching point, the PIN must be decrypted, then re-encrypted with the proper key for the next leg in its journey, which is itself encrypted under a master key that is generally stored in the module or in the module's application programming interface, or API.

"Essentially, the thief tricks the HSM into providing the encryption key," says Sartin. "This is possible due to poor configuration of the HSM or vulnerabilities created from having bloated functions on the device."

Sartin says HSMs need to be able to serve many types of customers in many countries where processing standards may be different from the U.S. As a result, the devices come with enabled functions that aren't needed and can be exploited by an intruder into working to defeat the device's security measures. Once a thief captures and decrypts one PIN block, it becomes trivial to decrypt others on a network.

Other kinds of attacks occur against PINs after they arrive at the card-issuing bank Once encrypted PINs arrive at the HSM at the issuing bank, the HSM communicates with the bank's mainframe system to decrypt the PIN and the customer's 16-digit account number for a brief period to authorize the transaction.

During that period, the data is briefly held in the system's memory in unencrypted form.

Sartin says some attackers have created malware that scrapes the memory to capture the data.

"Memory scrapers are in as much as a third of all cases we're seeing, or utilities that scrape data from unallocated space," Sartin says. "This is a huge vulnerability."

He says the stolen data is often stored in a file right on the hacked system.

"These victims don't see it," Sartin says. "They rely almost purely on anti-virus to detect things that show up on systems that aren't supposed to be there. But they're not looking for a 30-gig file growing on a system."

Information about how to conduct attacks on encrypted PINs isn't new and has been surfacing in academic research for several years. In the first paper, in 2003, a researcher at Cambridge University published information about attacks that, with the help of an insider, would yield PINs from an issuer bank's system.

The paper, however, was little noticed outside academic circles and the HSM industry. But in 2006, two Israeli computer security researchers outlined an additional attack scenario that got widespread publicity. The attack was much more sophisticated and also required the assistance of an insider who possessed credentials to access the HSM and the API and who also had knowledge of the HSM configuration and how it interacted with the network. As a result, industry experts dismissed it as a minimal threat. But Steel and others say they began to see interest for the attack research from the Russian carding community.

"I got strange Russian e-mails saying, Can you tell me how to crack PINs?" Steel recalls.

But until now no one had seen the attacks actually being used in the wild.

Steel wrote a paper in 2006 that addressed attacks against HSMs as well as a solution to mitigate some of the risks. The paper was submitted to nCipher, a British company that manufactures HSMs and is now owned by Thales-eSecurity. He says the solution involved guidelines for configuring an HSM in a more secure manner and says nCipher passed the guidelines to customers.

Steel says his solution wouldn't address all of the types of attacks. To fix the problem, would take a redesign.

But he notes that "a complete rethink of the system would just cost more than the banks were willing to make at this time."

Thales-eSecurity is the largest maker of HSMs for the payment-card and other industries, with "multiple tens of thousands" of HSMs deployed in payment-processing networks around the world, according to the company. A spokesman said the company is not aware of any of the attacks on HSMs that Sartin described, and noted that Thales and most other HSM vendors have implemented controls in their devices to prevent such attacks. The problem, however, is how the systems are configured and managed.

"It's a very difficult challenge to protect against the lazy administrator," says Brian Phelps, director of program services for Thales-eSecurity. "Out of the box, the HSMs come configured in a very secure fashion if customers just deploy them as is. But for many operational reasons, customers choose to alter those default security configurations — supporting legacy applications may be one example — which creates vulnerabilities."

Redesigning the global payment system to eliminate legacy vulnerabilities "would require a mammoth overhaul of virtually every point-of-sale system in the world," he says.

Responding to questions about the vulnerabilities in HSMs, the PCI Security Standards Council said that beginning next week the council would begin testing HSMs as well as unattended payment terminals. Bob Russo, general manager of the global standards body, said in a statement that although there are general market standards that cover HSMs, the council's testing of the devices would "focus specifically on security properties that are critical to the payment system." The testing program conducted in council-approved laboratories would cover "both physical and logical security properties."

This article appear on Wired.com

http://blog.wired.com/27bstroke6/2009/04/pins.html

Wednesday, April 8, 2009

Bogus bomb, somewhere near you

Rob Stringer

Security labs have discovered a variant of malicious spam that is engineered to report an exploded bomb within the recipient’s vicinity.

The ‘waledac’ variant, containing an apparent link to a Reuters website, shows the geolocation of the explosive as corresponding to the users IP address.

The story, perhaps designed off the back of recent terrorism-related events, claims that 12 people have been killed in the blast, and over 40 wounded, and contains such leading subject titles as "Why did it happen in your city?", "Take Care!" and "Are you and your friends in good health?"

Links to Wikipedia and Google are also included to convince the recipient of the veracity of the report.

"This is a clever piece of social engineering,” says Graham Cluley, senior technology consultant at Sophos. "If you visit the webpage from Southampton, Bristol or London it is likely to claim that the bomb blast has occurred there. There are the usual clues that the observant computer user will recognise as spam - poor spelling and grammar being the key one - but the danger is that other less wary users won't notice this and will become engrossed in the story without realising that their PC is being infected as they read."

This news article was submitted at infosecurity-magazine.com

Tuesday, April 7, 2009

Kids responsible for Estonia attack

Kids responsible for Estonia attack

Ian Grant, ComputerWeekly


The distributed denial of service attack that took down Estonia was run by a bunch of kids, it has emerged.

Two years ago, the former Soviet satellite found its banking and government websites paralysed for several weeks by a distributed denial-of-service (DDoS) attack.

The incident prompted a massive reorganisation and upgrade of network security and early warning systems among Nato members, and Nato even set up a cyber-security research house in Estonia.

At the time Russia was suspected of orchestrating the attack, but Moscow always denied it, and indeed Estonian officials never accused the Kremlin directly.

Yesterday, Konstantin Goloskokov (22) claimed he and some friends set up the attack to protest the removal of a Red Army monument from a downtown site in Estonia's capital Tallinn. The move had earlier led to rioting by pro-Soviet protesters.

Goloskokov told Reuters the attack was an act of civil disobedience, and, therefore, completely legal. "I was not involved in any cyber-attack," he said.

Goloskokov, a pro-Soviet activist, said he and his friends had set up the botnet that overloaded Estonian websites, causing them to crash.

"The fact that they could not withstand this is, strictly speaking, the fault of those people who, from a technical point of view, did not equip them properly," he told Reuters.

This article first appeared on the web-site of Computer Weekly, at
http://www.computerweekly.com/Articles/2009/03/13/235262/kids-responsible-for-estonia-attack.htm

Monday, June 30, 2008

Detecting SSH tunnels

Italian researchers have published a paper on the Detection of Encrypted Tunnels across Network Boundaries.

Click here to read:
http://coderrr.wordpress.com/2008/06/28/detecting-ssh-tunnels/

Saturday, June 28, 2008

Beijing.Exe Storm Outbreak

A new spam outbreak attributed to the Storm Botnet has been hitting the Internet since Jun 18, 2008. The message warns of earthquakes hitting well known sites around the world causing significant destruction and loss of life and is being distributed from IP addresses hosted around the world. This site claims a quake measured in at 9.0 on the Richter scale has caused casualties and threatens the preparations for the upcoming Olympics hosted in China. The page contains links to a supposed video that actually downloads the Storm worm

Click below to read:
http://www.trustedsource.org/blog/125/BeijingExe-Storm-Outbreak

Former White House Advisor: Hackers Didn't Cause 2003 Blackout

Cyber security consultant Paul Kurtz threw some cold water this week on a report that Chinese hackers caused the massive 2003 northeastern U.S. blackout. He worked for the White House at the time of the outage.

Click below to read:

http://blog.wired.com/27bstroke6/2008/06/former-white-ho.html

Wards didn't tell consumers about credit card hack

An old name in retail was hit by a modern scourge - a hack of its customers' credit card numbers - but didn't inform the consumers, revealing how data breaches might be heavily undercounted even with new notification laws.

At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward. The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy. It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com.

Click below to read more:

http://apnews.myway.com//article/20080627/D91II9U82.html

Researchers Reveal Security Holes in Internet Explorer

Two security issues, one in Internet Explorer 7 and the other in Internet Explorer 6, could leave users open to attack.

Click on link to read more:

http://www.eweek.com/c/a/Security/Researchers-Reveal-Security-Holes-in-Internet-Explorer/

Friday, June 27, 2008

Antispam group outlines defenses to block botnet spam

A major antispam organization is pushing a set of new best practices for ISPs (Internet service providers) to stop increasing volumes of spam from botnets.

Click the link to readhttp://www.networkworld.com/news/2008/062608-antispam-group-outlines-defenses-to.html?Inform=nl&nlhtsec=rn_062708&nladname=062708securityal:

Cisco, IBM, Intel, Juniper and Microsoft fight cyber terror together

Five major network hardware, software and services vendors are banding together to improve IT security by promoting faster responses to threats.

click on link below to read full story:
http://www.networkworld.com/news/2008/062707-icasi-cyber-terror.html?nlhtsec=ts_062708&nladname=062708securityal

Thursday, June 26, 2008

Virgin loses data on 3000 customers

Virgin Media has disclosed that an unencrypted CD containing personal details of around 3000 customers went missing on 29 May.

Click below to read more:
http://www.heise-online.co.uk/security/Virgin-loses-data-on-3000-customers--/news/110991

Woman accused of spying for China at Motorola

A Chinese spy was caught "red-handed," according to federal authorities, as she was about to board a plane at O'Hare bound for Beijing.

Click below to watch & read:
http://abclocal.go.com/wls/story?section=news/local&id=6228552

Stakeouts, Lucky Breaks Snare Six More in Citibank ATM Heist

Citibank officials monitoring their network for fraud on Thursday, May 8, noticed suspicious ATM transactions at 8:30 p.m., coming through the five cash machines in the vestibule of a Citibank branch at 65th Street and Madison Avenue in New York City's Upper East Side.

http://blog.wired.com/27bstroke6/2008/06/fbi-arrests-six.html

Researcher slams Adobe for 'epidemic' of JavaScript bugs

Adobe fixes critical flaw in Reader, Acrobat; exploits circulating

Click below to read more:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9102878&source=rss_topic85

HSBC scripting flaws play into the hands of phishers

Several HSBC websites are subject to scripting flaws that create a possible mechanism for crooks to create more convincing phishing scams.

Click on the link below to read more:
http://www.theregister.co.uk/2008/06/25/hsbc_scripting_flaws/

Monday, June 23, 2008

Sun launches Identity Manager 8.0

Sun has released its Identity Management software version 8.0 today. It automates processes that have been done manually in the past, including administrative activities and everyday tasks such as password management that were delegated to administrators and users. As a result, a reduction of operational costs and personnel workload can reach 80%, improving the rate of return on your investment in identity management.

Addressing security and compliance is still the largest expenditure for organizations," said Mark Herring, vice president of marketing Software Infrastructure. "Customers like GE, eBay, and Equifax are partnering with us because they know they can count on Sun for their needs.” Sun’s Identity Management Identity currently manages the identities of more than 12,000 eBay employees and contractors.

Click here to read more and know more

Symatec End point Management platform

Symantec Corp today announced the release of the new Symantec Endpoint Management Suite to define the next generation of integrated, best-of-breed systems management, endpoint security, backup and recovery.

Symantec Endpoint Management Suite secures the endpoint by providing the leading technology in all three areas of system configuration: management, security and recovery. The suite includes Symantec Endpoint Protection 11.0, Altiris Client Management Suite 6 and Backup Exec System Recovery 8 Desktop Edition.

Laptop Security

Hi,

Found this article on SANS site for Laptop security. As described in the document a Handy-dandy device with lots of information (official / personal) more valuable than the laptop itself.

People have started moving away from traditional Desktops to laptops not only in official environment but in homes also. Recommend reading this article & take the measures for securing your laptops.

Click here to read

The Best Security Books to have in your library

While i was going through the SANS articles found this write up on the best security books where the GIAC students who got above 90 were invited to the advisory board. Some books that received multiple polls were:

1. Counter Hack Reloaded: A Step-by Step Guide to Computer Attacks and Effective Defenses (2nd Edition) - Edward Skoudis and Tom Liston
2. Security Metrics: Replacing Fear, Uncertainty, and Doubt - Andrew Jacquith
3. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks - Michal Zalewski
4. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks - Michal Zalewski

Happy reading