High-Security Locks Are Key In Protecting Game Machine Revenue
By Jim Samuel
Locks are a paradox for the gaming industry. Seeming simple mechanical devices that are easy to operate and have remained virtually unchanged for decades, locks can also be one of the most difficult security devices to properly manage.
The cause of the paradox? Like most security issues in casinos, the cause is people. No matter how well a lock performs or how well it is made, it can’t be secure if its keys are improperly managed. The fact is that even the strongest locks cannot protect against lost or duplicate keys.
This is a great article that is written for the casino industry, but has great parallels in any security consideration. Take for instance, the fact that I am contracted to recover or change Windows administrator passwords at least several times per year. All I need is physical access to any system and I can own it within 10 minutes (up to 4 hours in the worst case so far). So all I need is access to the server room to own the server....right? Not quite. All I need is access to any system that is currently or has been on the network that has a valid and cached Domain Admin password. By cracking that system, I can own the Windows Domain/AD servers. It is time to get proper access control and auditing processes into place in today's small business, especially since the tools are already in place, just unused. Access control in a casino may be easier than in the average modern business - which has the better payout?....you decide, it's your money. -Bryan
Wednesday, March 02, 2005
Wednesday, February 16, 2005
HNS - The Threat Within - Why Businesses Need To Manage And Monitor Employee Email Usage
HNS - The Threat Within - Why Businesses Need To Manage And Monitor Employee Email Usage: "The Threat Within - Why Businesses Need To Manage And Monitor Employee Email Usage
by Jamie Cowper - Senior Technical Consultant, Mirapoint - Monday, 14 February 2005.
In a few short years, email has become a major part of the national psyche and a business-critical tool of communication. However, while companies have been more than willing to embrace the business benefits of email, they continue to remain oblivious to many of the responsibilities this new form of communication brings, particularly as it affects their employees.
"
Security starts with policies, but those policies must have sharp teeth in the form of technology and defined IT processes. And while technology can help with the monitoring and enforcement of your policies, you still need periodic user education and proof that those policies are enforced without prejudice (in law enforcement, wars, and streetfighting this is called "a show of force"). Just make sure that your show of force can survive a wrongful termination suit by having properly executed policies in the first place. -Bryan
by Jamie Cowper - Senior Technical Consultant, Mirapoint - Monday, 14 February 2005.
In a few short years, email has become a major part of the national psyche and a business-critical tool of communication. However, while companies have been more than willing to embrace the business benefits of email, they continue to remain oblivious to many of the responsibilities this new form of communication brings, particularly as it affects their employees.
"
Security starts with policies, but those policies must have sharp teeth in the form of technology and defined IT processes. And while technology can help with the monitoring and enforcement of your policies, you still need periodic user education and proof that those policies are enforced without prejudice (in law enforcement, wars, and streetfighting this is called "a show of force"). Just make sure that your show of force can survive a wrongful termination suit by having properly executed policies in the first place. -Bryan
HNS - A Simple Guide to Securing USB Memory Sticks
HNS - A Simple Guide to Securing USB Memory Sticks: "A Simple Guide to Securing USB Memory Sticks
by William Lynch - Senior Consultant for CTG's Information Security Services Practice - Wednesday, 2 February 2005."
This is a great article for every end-user who uses ANY portable media: CD's, USB, MicroDrives, etc. As well, any data on the local drives would be well protected using this same, free method.
by William Lynch - Senior Consultant for CTG's Information Security Services Practice - Wednesday, 2 February 2005."
This is a great article for every end-user who uses ANY portable media: CD's, USB, MicroDrives, etc. As well, any data on the local drives would be well protected using this same, free method.
Tuesday, February 15, 2005
Ping Identity Announces Risk-Free Trial, Pilot & Production use of PingFederate --Advanced Federation Software for Simplified Identity Federation - Pi
Ping Identity Announces Risk-Free Trial, Pilot & Production use of PingFederate --Advanced Federation Software for Simplified Identity Federation - Ping Identity Corporation: "Ping Identity Announces Risk-Free Trial, Pilot & Production use of PingFederate --Advanced Federation Software for Simplified Identity Federation"
Federated identity management across domains, sites and organizations....and the server is free until 100,000 transactions. Plenty of time to get it running and realize its value. -Bryan
Federated identity management across domains, sites and organizations....and the server is free until 100,000 transactions. Plenty of time to get it running and realize its value. -Bryan
Monday, February 14, 2005
Welcome to SmartWater Technology
Welcome to SmartWater Technology
SmartWater will provide your commercial property with a unique 'forensic fingerprint', which whilst being virtually invisible to the naked eye, glows under UV light and is practically impossible to remove entirely. SmartWater will protect individual items, especially mobile items such as laptops and phones, but it also protects the whole of your business or organisation from burglary and theft. It’s a chilling thought that the majority of theft for most organisations comes in the form of pilferage. So whilst you will be letting burglars know you’re protected by forensic coding, your staff can also be taking the message on board.
Now this is cool...permanent microdot watermarking for anything that you can imagine! Stealthily applied or overtly advertised....many possible uses. See this link for a real-life example of this in action:
http://www.met.police.uk/pns/DisplayPN.cgi?pn_id=2005_0007
-Bryan
SmartWater will provide your commercial property with a unique 'forensic fingerprint', which whilst being virtually invisible to the naked eye, glows under UV light and is practically impossible to remove entirely. SmartWater will protect individual items, especially mobile items such as laptops and phones, but it also protects the whole of your business or organisation from burglary and theft. It’s a chilling thought that the majority of theft for most organisations comes in the form of pilferage. So whilst you will be letting burglars know you’re protected by forensic coding, your staff can also be taking the message on board.
Now this is cool...permanent microdot watermarking for anything that you can imagine! Stealthily applied or overtly advertised....many possible uses. See this link for a real-life example of this in action:
http://www.met.police.uk/pns/DisplayPN.cgi?pn_id=2005_0007
-Bryan
Artists Against 419 - Is this a legit bank or company?
Artists Against 419 - Is this a legit bank or company?: "Is this a legit bank or company?
Online search tools
Have you received an offer from a bank or a security or off-shore company, or perhaps a winning notification from a foreign lottery? Want to know if they're real? If you can't find your bank on our list of 419 fake banks and lottery websites, that doesn't mean it's legit! New fakes come online every day. The following tips and tools can help you identify and avoid fraudulent banks and other fake web sites. If you're suspicious about a site, contact the artists!"
I get so many questions about suspected fraudulent emails in this category. A danger in these sites is not only from the fraudsters themselves, but from the danger of their sites being cracked and that data getting into even more criminals hands. I investigated a site recently and found several security flaws that could have been used to crack the site and potentially gain fraudulently gathered bank account data. The banks, FED's and the ISP's simply do not have enough personnel to properly attack this growing problem. See my full-disclosure post regarding this incident and the resulting discussion thread:
http://www.networksecurityarchive.org/html/FullDisclosure/2005-01/msg00893.html
Online search tools
Have you received an offer from a bank or a security or off-shore company, or perhaps a winning notification from a foreign lottery? Want to know if they're real? If you can't find your bank on our list of 419 fake banks and lottery websites, that doesn't mean it's legit! New fakes come online every day. The following tips and tools can help you identify and avoid fraudulent banks and other fake web sites. If you're suspicious about a site, contact the artists!"
I get so many questions about suspected fraudulent emails in this category. A danger in these sites is not only from the fraudsters themselves, but from the danger of their sites being cracked and that data getting into even more criminals hands. I investigated a site recently and found several security flaws that could have been used to crack the site and potentially gain fraudulently gathered bank account data. The banks, FED's and the ISP's simply do not have enough personnel to properly attack this growing problem. See my full-disclosure post regarding this incident and the resulting discussion thread:
http://www.networksecurityarchive.org/html/FullDisclosure/2005-01/msg00893.html
Institute for Information Infrastructure Protection
Institute for Information Infrastructure Protection: "The I3P Knowledge Base has been developed to support the I3P's mission to protect the information infrastructure of the United States. This web-based resource provides access to events, funding opportunities, experts in the field, and I3P initiatives. As the I3P Knowledge Base matures, we will be integrating tools for online collaboration, and other services to support the work of the I3P Consortium."
A good place to find upcoming security conference events (see the event calendar) and to see what some of the security community is thinking up for the future.
-Bryan
A good place to find upcoming security conference events (see the event calendar) and to see what some of the security community is thinking up for the future.
-Bryan
SecurityFocus HOME Infocus: Penetration Testing IPsec VPNs
SecurityFocus HOME Infocus: Penetration Testing IPsec VPNs: "Penetration Testing IPsec VPNs
by Rohyt Belani and K.K. Mookhey
last updated February 9, 2005
1. Introduction
As companies expand their presence globally, there arises a need for secure electronic communications between geographically dispersed locations. Virtual private networks (VPNs) provide an economically viable option to address this need."
All IT managers need to understand the points made in this article. The VPN can be the single most exposed point on the corporate network. Given a list of usernames, cracking the VPN is a great way to get ownership of the whole corporate LAN since most are configured for unfettered access to all devices in the LAN. And if there is a site to site VPN in aggressive mode with PreSharedKeys (PSK), then it is trivial to force the VPN server to send the PSK HASH, from which you can easily bruteforce the PSK at leisure on your own system. This can all be done without triggering any major alerts or doing noisy/detectable scans. -Bryan
by Rohyt Belani and K.K. Mookhey
last updated February 9, 2005
1. Introduction
As companies expand their presence globally, there arises a need for secure electronic communications between geographically dispersed locations. Virtual private networks (VPNs) provide an economically viable option to address this need."
All IT managers need to understand the points made in this article. The VPN can be the single most exposed point on the corporate network. Given a list of usernames, cracking the VPN is a great way to get ownership of the whole corporate LAN since most are configured for unfettered access to all devices in the LAN. And if there is a site to site VPN in aggressive mode with PreSharedKeys (PSK), then it is trivial to force the VPN server to send the PSK HASH, from which you can easily bruteforce the PSK at leisure on your own system. This can all be done without triggering any major alerts or doing noisy/detectable scans. -Bryan
Tuesday, February 08, 2005
Loren Bandiera's weblog � sussen
Loren Bandiera's weblog � sussen: "Loren Bandiera's weblog"
Loren Bandiera's weblog...some interesting NASL and other network probe and vuln experiments going on here. -Bryan
Loren Bandiera's weblog...some interesting NASL and other network probe and vuln experiments going on here. -Bryan
Wednesday, February 02, 2005
WASC Articles: The 80/20 Rule for Web Application Security
WASC Articles: The 80/20 Rule for Web Application Security: "...we'll look at a few techniques anyone can use to decrease the risk of their website being hacked. And to make it really easy you won't have to alter a single line of code!"
Some good points made in this article to quickly improve security while other improvements are being made as well. Just applying these rules does not create a healthy security implementaion.
-Bryan
Some good points made in this article to quickly improve security while other improvements are being made as well. Just applying these rules does not create a healthy security implementaion.
-Bryan
Monday, January 31, 2005
SecurityFocus HOME News: 'Thiefproof' car key cracked
SecurityFocus HOME News: 'Thiefproof' car key cracked: "
'Thiefproof' car key cracked
By John Leyden, The Register Jan 31 2005 8:33AM
Researchers have discovered cryptographic vulnerabilities in the RFID technology used in high-security car keys and petrol pump payment systems. The attack against Texas Instruments DST tags used in vehicle immobilisers and ExxonMobil's SpeedPass system was identified by experts at Johns Hopkins University and RSA Laboratories. "
Security through obscurity really is neither.... -Bryan
'Thiefproof' car key cracked
By John Leyden, The Register Jan 31 2005 8:33AM
Researchers have discovered cryptographic vulnerabilities in the RFID technology used in high-security car keys and petrol pump payment systems. The attack against Texas Instruments DST tags used in vehicle immobilisers and ExxonMobil's SpeedPass system was identified by experts at Johns Hopkins University and RSA Laboratories. "
Security through obscurity really is neither.... -Bryan
Monday, January 24, 2005
Matt Blaze's Technical Papers - Safecracking and Physical Locks - AT&T Labs -- Research
Technical Papers: "Physical Security
Cryptologic techniques can be applied outside of computers and networks, Perhaps surprisingly, the abstractions used in analyzing secure computing and communications systems turn out also to be useful for understanding mechnical locks and their keyspaces. Indeed, modeling master keyed locks as online authentication oracles leads directly to efficient solutions for what might naively seem like exponential problems for the attacker. In fact, it seems like almost a textbook example, as if master keying practices for locks were designed specifically to illustrate this class of weakness. We sometimes assume that hardware-based security is inherently superior to that based in software, but even the humble mechanical lock can be just as insecure as complex computing systems, and can fail in similar ways."
Matt's Master-Keyed Lock Vulnerability article is here
And Matt's safecracking PDF is here
Since information security and risk reduction invariably relies on physical security, it is time that infosec pushes the envelope on mandating physical security that is not based an illusion of security, but on provable security. That tape library with millions worth of intellectual property and trade secrets is sitting in a "Safe" somewhere right? Is that really safe? Probably in name only. As a great mind or two have concluded over the centuries: "security through obscurity is neither..."
-Bryan
Cryptologic techniques can be applied outside of computers and networks, Perhaps surprisingly, the abstractions used in analyzing secure computing and communications systems turn out also to be useful for understanding mechnical locks and their keyspaces. Indeed, modeling master keyed locks as online authentication oracles leads directly to efficient solutions for what might naively seem like exponential problems for the attacker. In fact, it seems like almost a textbook example, as if master keying practices for locks were designed specifically to illustrate this class of weakness. We sometimes assume that hardware-based security is inherently superior to that based in software, but even the humble mechanical lock can be just as insecure as complex computing systems, and can fail in similar ways."
Matt's Master-Keyed Lock Vulnerability article is here
And Matt's safecracking PDF is here
Since information security and risk reduction invariably relies on physical security, it is time that infosec pushes the envelope on mandating physical security that is not based an illusion of security, but on provable security. That tape library with millions worth of intellectual property and trade secrets is sitting in a "Safe" somewhere right? Is that really safe? Probably in name only. As a great mind or two have concluded over the centuries: "security through obscurity is neither..."
-Bryan
Onion Routing
Onion Routing: "Onion Routing
The Onion Routing project researches, designs, builds, and analyzes anonymous communications systems. The focus is on systems for Internet-based connections that resist traffic analysis, eavesdropping, and other attacks both by outsiders (e.g. Internet routers) and insiders (Onion Routers themselves). Onion Routing prevents the transport medium from knowing who is communicating with whom -- the network knows only that communication is taking place. In addition, the content of the communication is hidden from eavesdroppers up to the point where the traffic leaves the OR network."
Been playing around with this since a friend pointed me back to it the other day (thanks Joel). A must use for browsing around sites that you may not want to know your identity. Will setup a hardened and malware resistant tor server here soon.
And since I don't want my tor server to be used to anonymously hack other systems, ingress/egress layer-7 screening will be used even if it upsets the cyber-anarchists out there.
-Bryan
The Onion Routing project researches, designs, builds, and analyzes anonymous communications systems. The focus is on systems for Internet-based connections that resist traffic analysis, eavesdropping, and other attacks both by outsiders (e.g. Internet routers) and insiders (Onion Routers themselves). Onion Routing prevents the transport medium from knowing who is communicating with whom -- the network knows only that communication is taking place. In addition, the content of the communication is hidden from eavesdroppers up to the point where the traffic leaves the OR network."
Been playing around with this since a friend pointed me back to it the other day (thanks Joel). A must use for browsing around sites that you may not want to know your identity. Will setup a hardened and malware resistant tor server here soon.
And since I don't want my tor server to be used to anonymously hack other systems, ingress/egress layer-7 screening will be used even if it upsets the cyber-anarchists out there.
-Bryan
Sunday, January 23, 2005
On the discussion of security vulnerabilities
On the discussion of security vulnerabilities: "Is it harmful to discuss security vulnerabilities?
The debate over the open discussion of security vulnerabilities long predates the Internet and computers. The recent reaction of some locksmiths to my master keying research paper heightened my interest in this subject. Here's what one of the 19th century's foremost inventors of mechanical locks had to say 150 years ago:"
The debate over the open discussion of security vulnerabilities long predates the Internet and computers. The recent reaction of some locksmiths to my master keying research paper heightened my interest in this subject. Here's what one of the 19th century's foremost inventors of mechanical locks had to say 150 years ago:"
Tuesday, January 18, 2005
Monday, November 29, 2004
Quiet Encoding: How Your Laser Printer Manufacturer Has Embedded An ID Code On Every Page You Print - Robin Good's Latest News
Quiet Encoding: How Your Laser Printer Manufacturer Has Embedded An ID Code On Every Page You Print - Robin Good's Latest News
------------
Blue LED Flashlight + loupe = Gotcha!
------------
Blue LED Flashlight + loupe = Gotcha!
Wednesday, November 10, 2004
the Bleeding Edge of Snort - Breaking Snort Signatures
the Bleeding Edge of Snort - Breaking Snort Signatures: "The Aggregation Point for Snort Signatures and Research"
If you use Snort, then you should be familiar with this site...I was going through my bookmarks and re-discovered this one today. Good stuff!
If you use Snort, then you should be familiar with this site...I was going through my bookmarks and re-discovered this one today. Good stuff!
Tuesday, November 09, 2004
Sender Policy Framework
Sender Policy Framework
SPF: Sender Policy Framework
The Anti-Forgery solution
That's making the world a
Safer place for email.
---------------------
SPF: Sender Policy Framework
The Anti-Forgery solution
That's making the world a
Safer place for email.
---------------------
Friday, October 22, 2004
remote-exploit.org
remote-exploit.org: "News: Auditor 081004-01 released
remote-exploit.org
Again it is time to make a major release of the Auditor Security Collection. It has hughe changes on it. Check out the project web site and the changes file. The Auditor Security Collection is the most advanced and up-to-date penetration testing linux live distro available. Its perfect for security analyses, wireless security analysis and ...... check it out."
...Old news, but a great set of tools for auditing networks. Check it out even if only to find out what kinds of snooping can take place.
Cheers,
-Bryan
remote-exploit.org
Again it is time to make a major release of the Auditor Security Collection. It has hughe changes on it. Check out the project web site and the changes file. The Auditor Security Collection is the most advanced and up-to-date penetration testing linux live distro available. Its perfect for security analyses, wireless security analysis and ...... check it out."
...Old news, but a great set of tools for auditing networks. Check it out even if only to find out what kinds of snooping can take place.
Cheers,
-Bryan
Friday, October 15, 2004
Schneier on Security
Schneier on Security
Bruce Schneier on Security
A weblog covering security and security technology.
Schneier: Security outsourcing widespread by 2010
Bruce Schneier is founder and chief technology officer of Mountain View, Calif.-based MSSP Counterpane Internet Security Inc. and author of Applied Cryptography, Secrets and Lies, and Beyond Fear. He also publishes Crypto-Gram, a free monthly newsletter, and writes op-ed pieces for various publications. Schneier spoke to SearchSecurity.com about the latest threats, Microsoft's ongoing security struggles and other topics in a two-part interview that took place by e-mail and phone last week. In this installment, he talks about the safety of open source vs. closed source, the future of security management and spread of blogs.
.........If you have not read any of Bruce's books or articles...then your geekdom is in question. Here is your chance to gain some knowledge from an expert whom I consider to be a very practical and realistic security expert. -Bryan
Bruce Schneier on Security
A weblog covering security and security technology.
Schneier: Security outsourcing widespread by 2010
Bruce Schneier is founder and chief technology officer of Mountain View, Calif.-based MSSP Counterpane Internet Security Inc. and author of Applied Cryptography, Secrets and Lies, and Beyond Fear. He also publishes Crypto-Gram, a free monthly newsletter, and writes op-ed pieces for various publications. Schneier spoke to SearchSecurity.com about the latest threats, Microsoft's ongoing security struggles and other topics in a two-part interview that took place by e-mail and phone last week. In this installment, he talks about the safety of open source vs. closed source, the future of security management and spread of blogs.
.........If you have not read any of Bruce's books or articles...then your geekdom is in question. Here is your chance to gain some knowledge from an expert whom I consider to be a very practical and realistic security expert. -Bryan
Subscribe to:
Posts (Atom)