RSS

Archive | Security RSS feed for this section

New mass-mailing worm spreading like crazy – VBMania

Normally I let the vendors communicate this stuff out but this is spreading like crazy. A mass-mailing worm that McAfee is calling VBMania is on the loose. We’ve stopped an ton of these this afternoon. More information here: http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-virus/ –Chris

Continue reading...

Intel to acquire McAfee for $7.7 Billion

Most of you have probably heard that Intel announced that it will acquire McAfee for almost $8 billion dollars. What I find interesting is that Intel paid $48 per share or about 60% more than the $30 per share where McAfee had been trading at. There are a lot of discussions about why Intel did [...]

Continue reading...

How-to on securing PDF documents

A friend of mine pointed me to a good article on securing PDF documents. http://secforall.info/2009/06/29/securing-pdfs/ It’s a good tutorial on how to password protect, digitally sign and certify PDF documents. Now if only we could have some intelligence in email clients (or maybe a setting in Acrobat Reader?) that would prohibit or at least strongly [...]

Continue reading...

Most dangerous keywords to search for

Dancho Danchev posted on the release of a McAfee report that analyzes what keywords are the most dangerous in terms of the search results linking to malware. “Upon searching for 2,658 unique popular keywords and phrases across 413,368 unique URLs, McAfee’s research concludes that lyrics and anything that includes ‘free” has the highest risk percentage [...]

Continue reading...

MIT Lincoln Lab Network Security Software

MIT Lincoln Laboratory has developed a Network Security Analysis application known as NetSPA. In short, I am very impressed with this tool. NetSPA (Network Security Planning Architecture) correlates firewall rules / ACL’s with vulnerability data such as Nessus output. This tool then visually plots attack paths through an interactive interface that lets you model different [...]

Continue reading...

NAC Panel Discussion: What is the state of NAC?

This morning at work I moderated a panel discussion on Network Access Control. The audience was made up of IT Security staff from several research and development organizations. There were representatives from 3 vendors in attendance as well. The audience represented a good cross section of NAC adopters. Some have had it for 2 years, [...]

Continue reading...

Record IM video on the network?

A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to [...]

Continue reading...

WoW adds 2 factor authentication

World of Warcraft creator Blizzard Entertainment is selling hardware security devices. These small devices can fit on a key ring and provide a second form factor for authentication using something similar to a one time pad. The cost…..6 EUR. Robert over at Errata Security has a pretty good write up on it. Now if only [...]

Continue reading...

Bad Behavior has blocked 1012 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.