A friend of mine pointed me to a good article on securing PDF documents. http://secforall.info/2009/06/29/securing-pdfs/ It’s a good tutorial on how to password protect, digitally sign and certify PDF documents. Now if only we could have some intelligence in email clients (or maybe a setting in Acrobat Reader?) that would prohibit or at least strongly [...]
Continue reading...4. June 2009
Dancho Danchev posted on the release of a McAfee report that analyzes what keywords are the most dangerous in terms of the search results linking to malware. “Upon searching for 2,658 unique popular keywords and phrases across 413,368 unique URLs, McAfee’s research concludes that lyrics and anything that includes ‘free” has the highest risk percentage of [...]
Continue reading...10. February 2009
MIT Lincoln Laboratory has developed a Network Security Analysis application known as NetSPA. In short, I am very impressed with this tool. NetSPA (Network Security Planning Architecture) correlates firewall rules / ACL’s with vulnerability data such as Nessus output. This tool then visually plots attack paths through an interactive interface that lets you model different [...]
Continue reading...29. October 2008
This morning at work I moderated a panel discussion on Network Access Control. The audience was made up of IT Security staff from several research and development organizations. There were representatives from 3 vendors in attendance as well. The audience represented a good cross section of NAC adopters. Some have had it for 2 years, [...]
Continue reading...1. July 2008
A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to [...]
Continue reading...1. July 2008
World of Warcraft creator Blizzard Entertainment is selling hardware security devices. These small devices can fit on a key ring and provide a second form factor for authentication using something similar to a one time pad. The cost…..6 EUR. Robert over at Errata Security has a pretty good write up on it. Now if only [...]
Continue reading...23. June 2008
I saw this today on Slashdot. There is an ICANN registrar in China who is apparently not living up to its obligations to verify proper contact information for people registering domain names. The registrar is Xinnet Bei Gong Da Software. How bad is it you ask? Of 11,000 suspected spam domains registered through them, NONE were [...]
Continue reading...25. March 2008
I saw this press release today from my Savant Protection. According to the release Savant’s Protection has been ported over to the Google Android platform. Savant Protection is very interesting technology in the fight to prevent the spread of malware. It’s not AntiVirus in the traditional sense and it is not really white listing either. [...]
Continue reading...Bad Behavior has blocked 1220 access attempts in the last 7 days.
27. December 2009
0 Comments