Security's Everyman

Security's Everyman
Showing posts with label Info Security. Show all posts
Showing posts with label Info Security. Show all posts

Friday, November 16, 2007

It's good to know that education and hard work have finally paid off

All of us have received many different phishing, scam, and junk emails. I get them ranging from the real SPAM ones to the Nigerian bankers widow and all sorts of them asking for an "updated" version of my resume along with my bank account number so they can deposit my pay check. Today I think I got the one that may well top the list as my all time favorite. I'm including the body of the email so you can read it.

My favorite part is the highlighted sentence. It's good to know that all my IT and security training has paid off and that they think so highly of my resume.


Dear applicant,
Having carefully investigated your resume we would like to employ you to work with our company as an administrative assistant. Monthly salary of $2000 is guaranteed for 10-15 hours of work per week. Our company was established in 2003 in Birmingham, Great Britain, and we have a number of branches in Eastern Europe and the United States. Our main trading specializations involve products sale and resale, as well as auction drop off.
Our task is to guarantee effective cooperation between sellers and managers, which ensures beneficial sales. Our operation involves maintenance of auction services, which allow anyone to sell unnecessary goods, using the services of professional sellers.
Why selling on an auction?
Using auctions is very convenient, because it allows people to sell their goods at the optimal price. We provide comprehensive support, examination of the item, and stressing attention on its positive features, as well as making professional pictures of the goods. After that, we fill in the listing form and post the information about the item in the necessary auction category. We also try to determine the best time for the start of the auction. We notify the clients about the start and end of the auction. In the course of the auction we advice buyers, receive payments and return change when necessary. Our other duty is to pack the item and deliver it to the buyer, along with some other things that are necessary for a perfect sale.
Who sells the items?
Our clients can reside anywhere. In anyplace of our world. These people are professionals with a great experience of 98% of successful deals. The majority of them are qualified to work on Ebay, Qxl, and Amazon online auctions.
Where are the items dropped off?
The items are sold on the different online auctions as Ebay US, Amazon Auctions, Big Deals, Ebay, QXL(UK Auctions), etc.
What items are usually sold?
The most popular selling categories are watches, silver and golden wares, collectibles, electronic appliances.
What are my duties as an administrative assistant?
Administrative assistants are mediators between sellers and buyers. This job is vital, in case if a person, living in {Moscow, Saint-Petersburg, Kiev}, want to sell his/her goods to Australia. Our assistant can make this operation possible. Administrative assistants are responsible for collecting and keeping all sales records in his/her region, and should also receive payments from clients. The assistant's duty is to draw up daily, weekly and monthly statements and keep record of incoming and outgoing mail to representatives of the management and sales department.
Will I be directly involved in sales? How will I find out that a deal has been made?
You do not need to sell or buy anything. Your task is to accept payments in your sales area and send all the relevant mail to the administration. If a buyer is not satisfied with the item, there is no refund. The only way is to exchange the item. In this case the seller and the buyer will settle this matter on their own. After the transaction is complete, you will be sent an e-mail with the purchase data, including the price of the item sold and its buyer's name.
What bonuses will I have as an employee of your company?
All the workers have a right for two-week paid vacations twice a year. After first three months an employee may take up his/her first vacation. We also offer {great,huge} discounts for our employees. They are listed in a catalog, which will be sent to you. Moreover, after receiving an invoice (at the end of each month) - we will pay all your taxes, reported in your tax returns.
How much should I invest to start working with you? How will I receive my pay?
No expenses initial payments are needed. All money, that may be invested by you will be returned by the company. Your monthly salary can reach up to $1,800-2,300. You will receive a 5-percent commission from each deal managed by you. A minimum salary is $2,200. If your salary does not amount in this sum - you will receive the amount of the shortfall by check or bank transfer.
For details, e-mail us at: xxxx@xxxx.com

Best Regards,
Leslie Nolan.

So I guess once I accept this I'll stop blogging. Hey! Wipe that grin off your face. I'm not gonna stop. :)

Tuesday, October 16, 2007

Keeping your system updated

I was looking at the latest issue of the SANS @Risk newsletter and it mentioned something that we need to keep in mind. I know that it's not something that I do regularly but I really need to do.

The four most critical vulnerabilities this week touch just about every
Windows user: Internet Explorer, Outlook Express, Word, even Kodak Image
Viewer.

The Kodak threat highlights a useful, but unpleasant fact. Microsoft
patched this product because it was distributed with Windows, but most
of the other products you add to your computer are not patched
automatically. Many vendors expect you to check with their web site to
learn about flaws that need patching. The criminals know that - hence
the new wave of attacks against applications.
All of us have software on our systems that requires us to manually check for updates. This brings up several questions that we must answer.
  1. What software is on our systems? Do you know?
    Make a list of all the applications that are on your system.
  2. How often do you check for updates manually?
    Bookmark the support page for each and check it regularly. Set a calendar reminder to ping you monthly.
  3. Do you use all the applications on your system?
    Uninstall all apps that you don't need or use.
  4. Where did you get your software from?
    Shareware/Freeware are great, but make sure you know and can really trust the source. The bad guys are putting our free software that looks really cool but packs a punch when it comes to owning your system.
  5. Did it come preinstalled on your system?
    Lots of the software that comes preinstalled on your system are trial versions that only work at partial functionality or expire after a period of time. If you are not going to pay the license fee to make it a full version then uninstall it. Even dormant software can be exploited.
OK, I know that for most of you this is common sense and you are already doing much of this, but I just wanted to put it out there that all software is a potential vulnerability and we need to pay attention to the little things.

Friday, September 28, 2007

A Waste of Time

I just finished a training class on Cisco MARS (Monitoring, Analysis and Response System). It was a Cisco authorized course put on by a major training company. It was two days and cost $2300 (luckily I used Cisco Training Credits so it wasn't "real" money). But between travel and the actual class time it cost me 4 days of work. I can't believe how useless the class was. When I say useless I don't mean that I didn't learn anything but I didn't learn anything that I couldn't have learned on my own for a whole lot less money.

It just wrong when a company like Cisco charges an outrageous amount of money for a class that doesn't do anything. I've been to other classes that were either free or less than $200 for 2 days that I gained much more from. After the class was finished we filled out a class evaluation and I made sure to let it be know that I was unhappy. I was nice and constructive with my criticism. One of the questions was "Based on your experience in this class would you take another Cisco Authorized Training Class?" My answer was a resounding "NO!". This is my first CAT class and I'm sure that many of them are very well done, but his isn't one of them.

Wednesday, July 11, 2007

The Slow, Blue Poop Security Model

The other day I was on the TCC Silc channel and mad a comment about security being considered a four letter word at some companies. Well true to form James Costello and Larry Pesce both chimed in with several four letter words: slow, easy, blue, poop, none. The the conversation went south from there. Some how Larry coined the term "Slow, Blue Poop Security". I knew there was a blog hidden in there somewhere. Well here it is.

What does a SBP security model look like? It looks a lot like what you may have seen at your company or a company that you once worked for. It the security model that does just enough to get by. The security that keeps you from having you network owned by every hacker in the world but not enough to really offer protection. It provides just enough to make you feel like everything is OK but you really don't know what is going on. What is happening with your clients and servers? Just because AV doesn't report anything doesn't mean there isn't anything to report. Richard Bejtlich has a post today about something very similar. The SBP Security model doesn't let you know what is really going on on your network.

Sometimes the SBP model even looks good to the casual information security professional. The network has many tools and devices that look good and provide lots of pretty blinking lights. But there is no real plan behind them. These are devices that allow them to check boxes on their compliance audit. They have a device for each check box, yet there is still gaping holes in the network.

The point of all this is to say that there is no room for the SBP Security model in today's world. SBP security only causes things to be less secure in the long run. It keeps compromised systems on the network and allows them to still spew their SBP to the rest of the world. It gives the bad guys a cloak of privacy to do their bidding without being discovered because SBP makes you feel good.

That's where our job comes in to rid the world of SBP networks. To build our case for building networks that are really secure and that actually provide our companies, users and customers with the protection, privacy, and security that they really deserve.

And to quote Sun Tzu.................. Just kidding Amrit. :)

Larry, bet you didn't think I could do it.

Friday, June 15, 2007

My Security RoadTrip

Martin asked several of us to tell our Security story again. I told it here (which was an updated story from earlier) and this time I'm going into a little more detail. Hope you enjoy it and I promise no Sun Tzu quotes Amrit.
____________________________________________________________________

I've mentioned before about how I got started in IT and sort of moved into Security but as I look back at what I wrote I didn't go into much detail about why and how I made the change.

I used to think that security meant a firewall and AV. The company I worked for never patched machines and I don't think that we even put AV on all machines (can't remember for sure). We ran MS Proxy Server 2.0 for a firewall and that was the extent of our security.

When we built a new data center we decided to "upgrade" our infrastructure we put in a Cisco PIX and MS ISA 2000 server. We put in McAfee EPO to manage AV. It was then that I started monitoring the firewall logs and ensuring that all our machines were updated with AV and we even started some patching. It was around this time that Code Red (or some high profile virus/worm) hit. It was then that I realized the implications of having a secure environment. I was also noticing attacks that were being attempted on our network from the outside. Several projects that I was involved in required me to do lots of research and talk with vendors about their offerings. I started realizing that there was lots of cool "toys" out there that allowed me to see deeper into the network and do things to mitigate the risks that I was starting to see.

My Boss was pushing me to upgrade my CCNA to CCNP. I had decide that I wanted to focus more on Security and asked him if he would object if I pursued what was at the time the equivalent of the CCSP (I think it was call CSS I and CSS II). He agreed and I started studying for it. Shortly after that I was laid off and my next job was a consulting position where I was hired to be the Security Specialist for the companies clients. I did network surveys to look for security weaknesses in their environments. Of course Security awareness was still in it's infancy (especially in small town USA) and most companies didn't want to pay for the service or the recommended changes to their environment. So I spent lots of time doing network monitoring and maintenance.

Until a month ago I had never held a pure security position. It was always just part of my job as a Network Engineer. I personally took the initiative to make it my priority and primary focus. As I was looking at what direction I wanted to take my career I decided that obtaining the CISSP over vendor certs would benefit me more. Since I was on my own for training, study, paying for tests, etc I had to choose carefully. Thus even though I'm qualified to work with several vendor devices I'm not certified on any of them.

There it is. My story. Long winded as it may be.

Tuesday, June 05, 2007

A new threat to security

I ran across this story today and it sends chills up my spine. A new wave of attack technology. DARPA is implanting chips in moths that will allow them to be controlled remotely and possible infiltrate enemy camps and beam back A/V signals.

What are the security implications of this for us? Are we now also going to have to be exterminators? I know this sounds ridiculous, but if this gets into the wrong hands it could prove to be a real problem. Imagine a moth watching you enter you password or sending video of your security configs to a hacker. What about listening in to conversations about security plans or board meetings?

This gives a whole new meaning to "shoulder surfing". I gotta go get a can of bug spray. :)

Thursday, May 24, 2007

User Awareness Awareness

I had to go to a training session yesterday for an app that is used for special purposes within my new company. It is used by several different groups some are regular computer users and some are not so savvy. The training went pretty well for all concerned up to the point where he was trying to explain the password policy for the app. It uses complex password requirements. You know Uppercase, Lowercase, number, special character. The problem was that it was explained poorly.

This is the problem with user awareness training that I'm always harping about. We take a subject that may be somewhat confusing for many people and make it even more confusing. Then we blame it on the user and call them stupid. These users aren't stupid. If they were they wouldn't be in the positions that they are in at work. They are very competent at their jobs. Also this goes back to poor security policies over many years. Users are accustomed to simple passwords. Having complex passwords that are poorly explained compounds the situation.

So what's the answer? First, when we plan our training (or explaining) talks we need to make sure that our examples make sense to not just us and others who are technical and regular users. We need to have someone who isn't so computer literate give us their input on how we explain the concept. Secondly, we need to work to change corporate culture on passwords and security. It may take a while and we may have to take "baby steps" but that is better than nothing or better than going from simple to complex and having the help desk flooded with calls because we took too big a step too quickly.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.