Archive for 'Thoughts'

Zeus – NYS Department Homeland Security Guidance

Zeus – NYS Department Homeland Security Guidance

Hopefully, this will be the last time I write about Zeus the banking Trojan.  However, when the New York State Department of Homeland Security releases a five page cyber information security advisory — its a little hard to ignore it.

It’s a very comprehensive document that provides good guidance, although I was a bit disappointed they didn’t discuss using a non-windows platform and/or running off a live bootable cd or usb.

That being said, ...

Continue Reading →

“So Devin … is OSSIM Awesome?”

Ever have one of those really intriguing moments … where for the rest of the day your mind keeps circling back and considering the possibilities? I had one yesterday.

A client asked us to help them on a SIEM Proof of Concept leveraging OSSIM (Open Source Security Information Manager). We had tried OSSIM a few years ago with minimal success, but had been intrigued by Alien Vault’s stewardship of the project, so we were excited to participate. We ...

Continue Reading →

Pay Attention to Information Security: Zeus Bankrupting Companies

Sadly the ABA’s warnings regarding small businesses’ use of online banking has not been well heard. Most small businesses have not yet changed their information security practices to protect themselves from banking malware.

King & Little, a NY based marketing firm faces bankruptcy after it was victimized by the Zeus banking trojan.  Over a very short period the attacker emptied the bank account of $164,000. Continue Reading →

Online Banking: American Bankers Association Cries “Caveat Emptor”

Lost in the glow of Operation Aurora was the American Bankers Association (ABA) recommendation “that small to midsized businesses only conduct online banking on dedicated work-stations”.  On first blush,  sounds like sound information security advice; so why is it that I find this so significant?

 Because the banking industry  finally “gets it”. 

 When the ABA (dedicated to enhancing the competitiveness of the nation’s banking industry and strengthening America’s economy) suddenly throws a ...

Continue Reading →

Penetration Testing in a Foaming Dispenser ….

Last week I bemoaned Axe Shower Gel’s packagingand noted that we were working on some changes to our Penetration Testing service offerings to better meet our client’s assurance objectives.

Over the last 9 years we have found you can generally divide our Penetration Testing clients up into a few broad “stereotypes”, clients who:

  1. View a penetration test as a necessary evil (e.g., small banks and smaller SAAS providers who conduct them to satisfy a regulatory or customer requirement).
  2. Are ...
Continue Reading →
Page 8 of 10 «...678910