Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 22 January 2010

Lighting Down the Line

Posted on 11:50 by Unknown

By Davin Fligel, Security Analyst

Nobody wants to be an innocent bystander; we avoid high risk areas where problems are likely to break out. The risk averse amongst us avoids areas that pose even a modicum of risk. You are unlikely to find me trawling a battle ground even for the most precious of loot. So it was with horror that I learnt as a teenager that lightning could come down a telephone line and kill you. More precisely kill me!

I could become an innocent bystander in my own home. I was not safe inside all that brick and mortar. The first thing that came to mind was: “What are the chances of that?” closely follow by, “I live in a lightning prone area” and “I need the phone to communicate.” This was the choice of communication methods before the ubiquitous mobile phone and the pervasive Internet. So I ran to my mother and demanded that we get lightning surge protectors as fast as humanly possible. How could I survive without a telephone, I was a teenager.

On the Internet computers are to homes as browsers are to telephones. To be able to communicate between houses you need to use your browser. Some would say the Internet is somewhat “lightning prone.” You browse around as normal until unsuspectingly hitting an intentionally malicious or even legitimate site that had been compromised and your computer is compromised. How does not using the internet for security reasons sound you? Could you do it or would you sprint out and get the first “surge protector” you could find?

“But I have a firewall” cries the recently recruited member to the latest fashionable botnet. Unless your firewall can stop you connecting outbound to a compromised site then it is useless against this threat. Last I checked I was not blocking my browser from connecting to the Internet. That would defeat the purpose.

“But I only visit safe sites” cries the latest attack vector into a corporate network after being compromised by the penetration testing team. Man in the middle attacks from fake or compromised wireless access points or internet cafes, even man in the middle attacks on the LAN if the opportunity arises. No WiFi? I think not, Sir!

“But I have antivirus” cries the IT Manager as he explains to the CIO how he just lost a stack of confidential records. Kernel rootkit injection and core library replacement through an un-patched vulnerability had left him open long enough to get the data and leave without writing the files that AV definitions would easily identify.

The truth of the matter is browser security is the new file and network security. Even legitimate web sites fall prey to zero day vulnerabilities, cross site scripting and SQL injection attacks. If not the sites themselves, then the advertising engines posting advertisements for their parent sites. This is assuming you are surfing from a safe network let alone the added risks of unprotect wireless networks and the hacker friendly man in the middle opportunities they present.

This is lightning down the wire all over again, only on a grander scale with exponentially more lightning.

The moral of this story is simple to elucidate but difficult to implement: Make yourself a smaller target, install your lightning protectors, patch your browsers and if you cannot patch them use ones that are not vulnerable, use Intrusion Prevention Systems (IPS), Host Intrusion Prevention Systems (HIPS), Layer-7 aware Web Application Firewalls (WAFs), use a secure VPN from public WiFi hotspots, block unnecessary outbound communications, or at a minimum monitor them.

Surf safe, don’t browse without protection.

Caretower Limited is exhibiting at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th – 29th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ▼  January (27)
      • Novatel Wireless Announces Successful HSPA+ Dual-C...
      • Origin says Swiss Army encryption challenge worth ...
      • RockYou hack reveals world's most popular passwords
      • FalconStor® FDS Version 2.0 Delivers Enterprise-Cl...
      • Data hung out to dry as 4,500 USBs are left in Dry...
      • 8,378 reasons for better banking security
      • MiFi security weakness highlights need for code au...
      • CTO Doubts Internet Explorer Vulnerability Was Beh...
      • New Security Score Offers Snapshot of Firewall Ris...
      • 360°IT Event gives thumbs up on IBM/Panasonic clou...
      • Lighting Down the Line
      • German Government advice on web security not optimal
      • Oaklee Housing Association protect sensitive data ...
      • False Advertising by Vodaphone
      • Time for multi-factor security on portable data as...
      • Cyber-Ark Labs launched to combat emerging threats...
      • Where Does the Ownership Lie?
      • Creating uniform security across the police force
      • Modified portable devices create significant secur...
      • Serious SQL flaw could have compromised millions
      • Logitech Speaker Lapdesk N700 Brings the Cinema Home
      • Did Santa bring you a Netbook?
      • Police force computer misuse investigation "no sur...
      • Companies advised to code audit open source applic...
      • Securing Web 2.0 in the workplace
      • Kingston Datatraveler security flaws highlight nee...
      • Credant says MoD laptop theft highlights dangers o...
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile