barrett778

Real Name:n/a
Location: USA
Joined:11-20-2007
Make barrett778 a Guide: follow clipper
About me
CISSP, Government Computer Security
Why I use Clipmarks
Information Security; Cyber Defense; Hackers; Information Assurance
Where to find me on the web
Email: 







   
 
 
 
   
 
top scroll end
0
POPS
Virtual PCs Add New Layer of Security
barrett778
by barrett778  1-4-2008   
 1. Can't wait to try it 2. Wonder if there is a threat to this that we need to block
0
POPS
Nato secrets USB stick lost in Swedish library
barrett778
by barrett778  1-4-2008   
 Encryption, encryption, encryption
0
POPS
Fast Flux DNS Wiki
barrett778
by barrett778  1-1-2008   
 Technique used to mask attacker's true identity and to avoid countermeasures such as IP ACLs
0
POPS
Storm, Nugache lead dangerous new botnet barrage
barrett778
by barrett778  12-19-2007   
 The future will continue to hold significant challenges.
0
POPS
Adobe ships ‘critical’ patch for Flash Player
barrett778
by barrett778  12-19-2007   
 More Zero Day stuff, just in time for the holidays :)
0
POPS
Hot: Real-time security monitoring
barrett778
by barrett778  12-17-2007   
 Risk Management Framework from NIST and Cyber Defence capabilities under the Einstein gateway monitoring program.
1
POPS
Swatting
barrett778
by barrett778  12-17-2007   
 This is a new one... Get someone to provide you some personal information, their address, and their phone number, phreak the phone number, and send the SWAT team to their house.
0
POPS
Windows Vista Service Pack 1 RC Public Availability Program
barrett778
by barrett778  12-17-2007   
 Installing SP1 RC1 now. You must run the script, then download the RC and the prereq's through Windows Update. Only install on non-critical machines. You will have to uninstall the RC before installing the final version. But hey, can installing the RC be any worse right now?
0
POPS
Did NSA Put a Secret Backdoor in New Encryption Standard?
barrett778
by barrett778  12-17-2007   
 Not sure how easy it is to force the use of another random number generator, but I guess I will be learning how to shortly.
0
POPS
GAO praises TSA for its handling of sensitive info
barrett778
by barrett778  12-5-2007   
 Good news stories are few and far between. Nice to highlight them when they happen.
1
POPS
How to Track Down Anyone Online
barrett778
by barrett778  12-5-2007   
 items to help you 'profile' yourself to ensure you aren't coughing up too much information.
0
POPS
ThreatCon Level is 1
barrett778
by barrett778  12-5-2007   
 Back to '1'
0
POPS
Schneier on the SANS Top 20 Vulnerabilities
barrett778
by barrett778  12-4-2007   
 Need to proxy connections to the Internet and STRICTLY limit where people can go. Unfortunately, there is very little desire to do this and many are willing to accept living in a compromised environment. At home, I have been modifying each machine's 'HOSTS' files ('There's no place like 127.0.0.1'), using K9 Web Content filtering, and recently been using OpenDNS to limit where my users (family) can go. Also, I have killed MSIE and have forced all users to use Firefox with the NoScript enabled. I have played with a virtual proxy that works well (especially when configured with 'Hosts', K9, OpenDNS, Antivirus, and FW blocking of all other hosts besides the proxy. When I figure out how to do the failover piece to keep the availability at 99%, I will implement it for good. Nothing is full-proof, but I sleep better at nights! (Thanks to RF-NCNF for the OpenDNS and NoScript tips!).
0
POPS
Microsoft Security Advisory (945713)
barrett778
by barrett778  12-4-2007   
 Should not affect home users who are not part of a domain and also should not affect corps with a second-level domain (affects third-level or more). Proxy servers, WPAD servers, and those who disable the IE 'Automatically Detect Settings' mitigate this vulnerability. Most flavors of Windows/Vista affected when using MSIE (unclear whether or not other browsers have the same vulnerability, but I would assume they do if they depend on Windows/Vista to automatically detect settings).
0
POPS
Bruce Schneier Q&A
barrett778
by barrett778  12-4-2007   
 This is a MUST read for all computer users. Bruce does us all a favour and links back to his pertinent articles.
0
POPS
MI5 warns of Chinese hack attacks
barrett778
by barrett778  12-3-2007   
 UK warning to businesses.
0
POPS
Governments prepare for 'cyber cold war'
barrett778
by barrett778  12-3-2007   
 More on the threat
0
POPS
Inside Microsoft's security war room
barrett778
by barrett778  12-3-2007   
 For fun...
0
POPS
Defending Against the Unusual Suspect: the Modern Cyber Criminal
barrett778
by barrett778  12-3-2007   
 The evolving threat environment.
0
POPS
Security in Ten Years
barrett778
by barrett778  12-3-2007   
 Marcus Rancun and Bruce Schnieier on security in ten years. They take the bleak view; I think we will have a security revolution before then which will make it better than they think...
0
POPS
THREATCON AT LEVEL 2
barrett778
by barrett778  12-2-2007   
 Elevated as RSTP exploits are introducted.
2
POPS
The biggest data disaster ever
barrett778
by barrett778  12-1-2007   
 Similar events to follow?
3
POPS
The new battleground in cybercrime
barrett778
by barrett778  12-1-2007   
 The cat and mouse game continues
0
POPS
Data theft touches 150,000 Massachusetts seniors
barrett778
by barrett778  12-1-2007   
 ID Theft report
2
POPS
Google removes thousands of malware sites
barrett778
by barrett778  11-30-2007   
 Follow-up to earlier post
2
POPS
10 Extremely Useful Websites to Stop Big Brother From Snooping on You
barrett778
by barrett778  11-30-2007   
 No Remarks
0
POPS
fwtest - Firewall Testing Toolkit
barrett778
by barrett778  11-30-2007   
 No Remarks
1
POPS
How to Harvest Passwords
barrett778
by barrett778  11-30-2007   
 This would be a great job if it weren't for the users...
0
POPS
Data breach costs soar
barrett778
by barrett778  11-30-2007   
 Save this one for your risk assessments and business cases when selling security.
0
POPS
With data breach costs soaring, companies should review data sharing policies
barrett778
by barrett778  11-30-2007   
 Information management is the key... Most people who argue that "Need to Share" competes with "Need to Know" don't get it. One is about information managment, the other is about information security and there must be a balance between the two.
0
POPS
Criminals burrow into browsers to hack banks
barrett778
by barrett778  11-28-2007   
 Important to note that these attacks are occurring BEFORE transmission. Therefore, the SSL tunnel between you and your bank (signified by the little lock on your browser) is meaningless as your information is compromised as it is entered on the form. The information is then sent by malware back to the harvesters who sell your information to the highest bidder. Preventing infection, detecting and removing the malware, and blocking egress communications with a firewall are the best prevention mechanisms. Also, keeping an eye on your credit is important.
0
POPS
More on the QuickTime RSTP vulnerability
barrett778
by barrett778  11-28-2007   
 More on the RSTP vulnerability from Quicktime. Countermeasures include disabling Quicktime and iTunes until the problem is patched (likely v7.4), blocking RSTP at the gateway (TCP 554 and a range of UDP ports in 6000's), IDS detection of RSTP. Note- files are vulnerable too, so just blocking egress ports is probably not enough as any installed malware will probably use port 80 to egress. Best to disable the applications via the Registry (or uninstalling) until the patches are available as these exploits are almost certainly out there now.
0
POPS
America's 8m victims of identity theft
barrett778
by barrett778  11-28-2007   
 About 2.5% of the population. Emphasis protection (computer security & document security for protecting personal information, use of credit cards and checks, using one account only for online transactions) and detection (credit checks, fraud alerts) with family, friends, co-workers.
0
POPS
Spam Traveling with .SCR File Attachments, Trojans in Tow
barrett778
by barrett778  11-28-2007   
 Another item to block at the gateway
0
POPS
Glossary of Terms Used in Security and Intrusion Detection
barrett778
by barrett778  11-28-2007   
 Good resource for security professionals
0
POPS
Part III: U.S. targets terrorists as online thieves run amok
barrett778
by barrett778  11-28-2007   
 US Government actions (or failure to act). Series part III.
0
POPS
Part II: How well are we protecting ourselves?
barrett778
by barrett778  11-28-2007   
 Internet fraud- impact and our defenses. Part II of the series.
0
POPS
Part I: How online crooks put us all at risk
barrett778
by barrett778  11-28-2007   
 Good series on the Internet fraud machine. Part I.
0
POPS
Cybercrime vs Cyberterrorism
barrett778
by barrett778  11-28-2007   
 Sometimes, it is all about using the right words. Prioritization seems to be the problem in the US Government. National Strategy to Secure Cyberspace is still falling short according to GAO audits. DHS has not figured out how to get in front of this issue, as the executive agent. PITAC recommendation to President should be strongly considered to ensure the funds committed are spent wisely.
1
POPS
Sunbelt Software: Google search results delivering massive malware attacks
barrett778
by barrett778  11-28-2007    1
 Crackers rigging web pages to gain high search rankings, enabling them to be posted near the top of the search thread. Best defense is to ensure you are surfing the web from a non-privileged account and to have a hardened browser (Firefox with the 'No Script' add-on, for instance). For IE, need to consider disabling iFrames.
— end of the list —

barrett778  follow

loading clips...
Filter
rss tools
Clipmarks
About   Clippers   Privacy   EULA   Copyright   Site Map

OK