It may be cliché but security is an ever-changing world. I am often asked how I keep up to date on the latest security trends and news in this rapidly changing world. The two primary tools I use to do this are security podcasts and Twitter. Being a consultant I spend a lot of time on the road and have long periods of free time while driving or flying to clients’ sites. While on the road, or during my daily commute, I fill those open hours by listening to podcasts. I am going to discuss the security podcasts I listen to, with a short description of each one. In a future post I’ll discuss how I use Twitter to keep in touch with the security community and stay on top of emerging trends.
ASIS Security Management Podcast is a monthly podcast containing highlights from the ASIS Security Management magazine. The magazine and podcast tend to be heavily focused on physical security, but there is some information security mixed in also. This is a great podcast if you want to learn more about physical security.
Crypto-Gram Security Podcast is simply Bruce Schneier’s monthly Crypto-Gram newsletter read aloud by Dan Henage. If you don’t have time to read the printed version of Crypto-Gram, this is a great way to keep up to date on a fascinating newsletter. If you haven’t read the Crypto-Gram newsletter you owe it to yourself to check out this podcast. I leave every podcast thinking about a security problem or issue in a new way.
CyberSpeak is a podcast focused on forensics. It is hosted by two formal federal agents who have spent their careers doing data forensics work. This show covers everything from basic to cutting edge forensic techniques. Whether you are a novice in forensics or an experienced forensics examiner, you will learn something from each episode.
Eurotrash Security Podcast comes to us from a band of security professionals and hackers based in Europe. This is one of the few podcasts that covers information security from a European point of view, so it is curious to see how security concerns over there line up and differ from the concerns in the States.
Exotic Liability Podcast is often offensive, usually informative, but always a fun time. This podcast is definitely not safe for work. So be careful where you listen to it. I recommend skipping this podcast if you are offended at obscene language and concepts. Topics usually focus on penetration testing and social engineering. The hosts also have some entertaining war stories about penetration testing.
OWASP Security Podcast focuses on all aspects of web application security. Many of the episodes are short interviews with experts in this field. This podcast is a wonderful way to learn about or keep on top of web application security topics.
Network Security Podcast is a weekly security news podcast covering new stories from the previous week. This show covers all aspects of security. The hosts comment on the news stories, often adding insight which makes the program well worth the listen.
PaulDotCom Security Weekly focuses on the technical side of security. Shows usually include a technical segment, new stories from the previous week, and interviews with special guests. If you want to learn more about the technical side of security this is a podcast you must check out. They also provide very detailed show notes which can be helpful when trying to implement an attack discussed on the show. An episode of PaulDotCom Security Weekly often is broken into two parts and the entire weekly show usually runs two to three hours. If I am running short on podcast time in a week, I also will use the show notes to determine what topics are of interest so I can fast forward to that portion of the podcast.
Risky Business is a news show which focuses on security from down under. The host of the show, Patrick Gray, does a very good job of explaining security concepts and concerns. Patrick also has a good handle on the importance of balancing security with business requirements, something many security folks forget. Because of these two factors, this is a great show for someone just getting into security.
SANS Audio Cast is a short weekly newscast produced by SANS. Episodes tend to be ten to fifteen minutes long so it is a great way to quickly catch up on the hot security news from the previous week. Even if I am running behind on podcasts, I try to listen to this one the week it is released while the information is still fresh.
SecuraBit Podcast is a security news podcast that focuses on technical security topics. I mainly listen to SecuraBit for the special guests they have, who tend to be big names in the security community.
Security Justice is hands down the best security podcast ever made. This monthly podcast covers a variety of security topics but tends to lean more toward physical security and the convergence of physical and logical security. This also is the only security podcast recorded live in a bar. Because this podcast is recorded in a bar, expect bar like language that may not be safe for work. Also in the interest of full disclosure, I should state the author of this post is also a co-host on this show so his views of the show are most likely biased.
Social Media Security Podcast focuses on the security concerns related to social media sites such as Facebook, Twitter, MySpace, and LinkedIn. The team that runs socialmediasecurity.com hosts the show. This podcast is a great way to learn about the threats in the emerging area of social media. The show also provides great case studies and stories that can be used for end user education and awareness training.
Social-Engineering.org Podcast is a monthly podcast focusing on social engineering. Produced by the team that run social-engineering.org, the podcast covers a number of topics related to social engineering. This podcast brings in some amazing guests. At first the guest’s or show topic’s relationship to social engineering might not be clear, but hang in there and the team always ties in how they relate. At its roots this podcast is about how to influence people, which is an important skill for any security professional to have. So even if you are not interested in social engineering, I still recommend you check out a few episodes of this podcast.
The Southern Fried Security Podcast looks at security from the CSO and management level, which is a welcome change from the often technical-heavy security podcasts. The podcast focuses on integrating security into a business and the importance of balancing the business needs with security. Most security professionals have a hard time achieving this balance, so do your self a favor and listen to at least a few episodes of this podcast.
If any of these podcasts sound interesting to you, I recommend you download a few episodes and give them a listen.
What security podcasts do you listen to? Any podcast you think I should start listening to? If so, tell me why in the comments.
Read more!
Showing posts with label SecureState. Show all posts
Showing posts with label SecureState. Show all posts
Friday, May 7, 2010
Friday, March 6, 2009
Firewall Ruleset Review
I’ve done a lot of firewall ruleset reviews for companies large and small. There is a pattern forming in almost every firewall I’ve seen.
Bad management.
It’s not about blaming people though. The economy is in the sewer and layoffs plague every company across the planet. Most every security team is dealing with tons of ongoing work to stay secure and low budgets and resources to get the job done.
The firewall rule sets I’ve seen range from 50 lines to 10,000+ lines. Some are so complex that we schedule a week of work to audit and determine what can be taken out, what needs to stay and what shouldn’t have been there in the first place.
Let’s face it; many firewalls have dead rules, non-existent networks and “permit any” rules. Those are the low lying fruit that we look for first and when fixed, automatically increase security surrounding the attached networks.
Any access list that ends in “permit ip any any” is wasted CPU power and increased RAM usage. Why make your firewall go thru all of those rules if you permit everything at the end anyways? Not to mention, if you’re going to do that, you could have saved yourself hundreds or thousands of dollars and just gotten a router and used static routes to forward traffic. But in the security world that isn’t an option.
Too often we see timeout settings that are too large, insecure protocols being used and lack of ingress or egress rules. The worst cases are the firewalls that are built backwards (a whole slew of deny statements followed by a permit any statement).
Overall, the largest issue is lack of egress filtering. Time and time again, we run into this. And in many of our assessments we capitalize on this. In both Social Engineering attacks and Penetration tests we are able to accomplish many tasks by using these lax rules. Even if you aren’t worried about the next major virus or worm, you should care in not helping spread the infection. Close your doors and be a good neighbor!
All of these issues add up to the sum of bad network security which is caused by bad management. There needs to be process and documentation of all rules and configuration settings within a configuration. Asking “Hey Chuck, there’s a strange rule in here, did you do that?” doesn’t count as documentation either.
At the end of the day, if you skip on a little security here and a little security there, what’s the point of implementing high dollar equipment? If you’re going to implement your firewall properly you should have dedicated process behind the ruleset. Justify every rule, every business segment, set it, and forget it. There should be no need to constantly be modifying your firewall. I can see the need if you’re installing a new server or software package, but adding and dropping lines daily or even weekly is not efficient use of anyone’s time.
The moral of the story is, if you are making constant changes, have bad rules, or an insecure configuration, then you should start over and build your configuration properly. A regular audit of the firewall ruleset is always a good idea and should be budgeted for. Put in the proper change control, documentation and justification, and you will be amazed how much more secure your network will become.
Read more!
Bad management.
It’s not about blaming people though. The economy is in the sewer and layoffs plague every company across the planet. Most every security team is dealing with tons of ongoing work to stay secure and low budgets and resources to get the job done.
The firewall rule sets I’ve seen range from 50 lines to 10,000+ lines. Some are so complex that we schedule a week of work to audit and determine what can be taken out, what needs to stay and what shouldn’t have been there in the first place.
Let’s face it; many firewalls have dead rules, non-existent networks and “permit any” rules. Those are the low lying fruit that we look for first and when fixed, automatically increase security surrounding the attached networks.
Any access list that ends in “permit ip any any” is wasted CPU power and increased RAM usage. Why make your firewall go thru all of those rules if you permit everything at the end anyways? Not to mention, if you’re going to do that, you could have saved yourself hundreds or thousands of dollars and just gotten a router and used static routes to forward traffic. But in the security world that isn’t an option.
Too often we see timeout settings that are too large, insecure protocols being used and lack of ingress or egress rules. The worst cases are the firewalls that are built backwards (a whole slew of deny statements followed by a permit any statement).
Overall, the largest issue is lack of egress filtering. Time and time again, we run into this. And in many of our assessments we capitalize on this. In both Social Engineering attacks and Penetration tests we are able to accomplish many tasks by using these lax rules. Even if you aren’t worried about the next major virus or worm, you should care in not helping spread the infection. Close your doors and be a good neighbor!
All of these issues add up to the sum of bad network security which is caused by bad management. There needs to be process and documentation of all rules and configuration settings within a configuration. Asking “Hey Chuck, there’s a strange rule in here, did you do that?” doesn’t count as documentation either.
At the end of the day, if you skip on a little security here and a little security there, what’s the point of implementing high dollar equipment? If you’re going to implement your firewall properly you should have dedicated process behind the ruleset. Justify every rule, every business segment, set it, and forget it. There should be no need to constantly be modifying your firewall. I can see the need if you’re installing a new server or software package, but adding and dropping lines daily or even weekly is not efficient use of anyone’s time.
The moral of the story is, if you are making constant changes, have bad rules, or an insecure configuration, then you should start over and build your configuration properly. A regular audit of the firewall ruleset is always a good idea and should be budgeted for. Put in the proper change control, documentation and justification, and you will be amazed how much more secure your network will become.
Read more!
Labels:
firewall,
Information Security,
network security,
networking,
ruleset,
SecureState,
Security
Monday, February 2, 2009
SecureState Speaks at ShmooCon 2009
SchmooCon for SecureState! SecureState's Dave Kennedy and Matt Neely will be speaking at ShmooCon in Washington, D.C., the annual East coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software & hardware solutions, and open discussions of critical infosec issues. The first day is a single track of speed talks, One Track Mind. The next two days, there are three tracks: Break It!, Build It!, and Bring It On!.
Principal at SecureState, Dave Kennedy focuses on the technical side of security, performing penetration tests, source code review, web application security, data forensics, electronic discovery and wireless assessments. Prior to SecureState, Dave worked for the National Security Agency (N.S.A.) and has worked with some of the nations most elite security groups. Dave is also the author of Fast-Track, an open-source penetration testing suite available in Linux, has previously presented at Defcon, and is a contributor to the BackTrack distributions.
Dave's presentation (The Fast-Track Suite: Advanced Penetration Techniques Made Easy) will be the last talk in the Bring It On! track where he will discuss attacks in detail and also release the newest version of Fast-Track.
Matt Neely, Profiling Manager at SecureState, will be presenting "Radio Reconnaissance in Penetration Testing - All Your RF Are Belong to Us," in the first talk of Bring It On! track this Saturday.
Read more!
Principal at SecureState, Dave Kennedy focuses on the technical side of security, performing penetration tests, source code review, web application security, data forensics, electronic discovery and wireless assessments. Prior to SecureState, Dave worked for the National Security Agency (N.S.A.) and has worked with some of the nations most elite security groups. Dave is also the author of Fast-Track, an open-source penetration testing suite available in Linux, has previously presented at Defcon, and is a contributor to the BackTrack distributions.
Dave's presentation (The Fast-Track Suite: Advanced Penetration Techniques Made Easy) will be the last talk in the Bring It On! track where he will discuss attacks in detail and also release the newest version of Fast-Track.
Matt Neely, Profiling Manager at SecureState, will be presenting "Radio Reconnaissance in Penetration Testing - All Your RF Are Belong to Us," in the first talk of Bring It On! track this Saturday.
Read more!
Friday, January 16, 2009
SecureState Attends PCI Compliance Seminar with ISACA
Today, ISACA’s membership—more than 86,000 strong worldwide—is characterized by its diversity. Members live and work in more than 160 countries and cover a variety of professional IT-related positions inlcuding but not limited to IS auditor, consultant, educator, IS security professional, regulator, chief information officer and internal auditor.
SecureState's Brian Telesz and Nicole McClain (pictured above with Craig Monastra of Sterling Jewelers) attended the most recent ISACA seminar at Harry's Steakhouse for good food and a great presentation on PCI Compliance. Keynote speaker was Lisa Peterson of Progressive Insurance.
The Information Systems Audit and Control Association is primarily focused on promoting quality IS audit and governance education to its members. The IS audit profession is based and dependent upon technological expertise. With Audit and Compliance being one of SecureState’s four divisions of expertise its helps our consultants and directors keep abreast on the latest hot topics, concerns and trends in the IT audit world. SecureState is a leader in the Audit and Compliance world. We engage in many different environments such as finance, insurance, manufacturing, retail and energy which gives us a very diverse expertise in the many compliances and security regulations that companies need to adhere to.
In addition to the importance of Audit and Compliance, SecureState belongs to the local chapter and attends the monthly meetings to keep SecureState in front our current and prospective clients who are members. We will also speak and present at these monthly meetings which helps educate ISACA chapter members on what SecureState sees out in the field during engagements and clarify and educate on IT audit issues.
Would you like SecureState to speak at your next event? Contact SecureState at 800.903.6264 for more information.
SecureState's Brian Telesz and Nicole McClain (pictured above with Craig Monastra of Sterling Jewelers) attended the most recent ISACA seminar at Harry's Steakhouse for good food and a great presentation on PCI Compliance. Keynote speaker was Lisa Peterson of Progressive Insurance.
The Information Systems Audit and Control Association is primarily focused on promoting quality IS audit and governance education to its members. The IS audit profession is based and dependent upon technological expertise. With Audit and Compliance being one of SecureState’s four divisions of expertise its helps our consultants and directors keep abreast on the latest hot topics, concerns and trends in the IT audit world. SecureState is a leader in the Audit and Compliance world. We engage in many different environments such as finance, insurance, manufacturing, retail and energy which gives us a very diverse expertise in the many compliances and security regulations that companies need to adhere to.
In addition to the importance of Audit and Compliance, SecureState belongs to the local chapter and attends the monthly meetings to keep SecureState in front our current and prospective clients who are members. We will also speak and present at these monthly meetings which helps educate ISACA chapter members on what SecureState sees out in the field during engagements and clarify and educate on IT audit issues.
Would you like SecureState to speak at your next event? Contact SecureState at 800.903.6264 for more information.
Read more!
Subscribe to:
Posts (Atom)


