Archive

Archive for the ‘Security’ Category

114,000 iPad owners’ emails and account IDs exposed

junho 12th, 2010

News that vulnerabilities on the AT&T network allowed a group calling itself Goatse Security to harvest emails and AT&T authentication IDs of 114,000 early-adopters of Apple’s iPad shocked potential victims.

Read More

Read More 2

Security

vSphere 4.0 Security Hardening Guide.

maio 30th, 2010

This guide represents a new approach to providing security guidance from VMware.

This document is the official release of the vSphere 4.0 Security Hardening Guide. This version is based on feedback collected during the public draft comment period.

Read Here

[ ]’s
Alvaro Anton

Security, Virtualization

Security - Chip and PIN is broken

fevereiro 12th, 2010

Read This

Our technical paper Chip and PIN is Broken explains how. It has been causing quite a stir as it has circulated the banking industry privately for over 2 months, and it has been accepted for the IEEE Symposium on Security and Privacy, the top conference in computer security. (See also our FAQ and the press release.)

http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/

[ ]’s

Security

How secure is your Optical Network? SafeNet Fiber Tapping Video

abril 21st, 2009
Comments Off

The video exposes the vulnerabilities of high-speed Metro Ethernet Networks and shows how you can simply and effectively secure your data in motion - by encrypting it end-to-end.

SafeNet

[ ]’s

Security

MD5 considered harmful today

janeiro 15th, 2009

Creating a rogue CA certificate

We have identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol.

Source: http://www.win.tue.nl/hashclash/rogue-ca/

[ ]’s

Security

Detection and Preventing Anonymous proxy usage

janeiro 15th, 2009
Comments Off

Na lista SNORT-BR o amigo Rodrigo Montoro(Sp0oKeR) enviou o link para o seguinte documento da SANS. Vale a pena conferir.

http://www.sans.org/reading_room/whitepapers/detection/rss/detecting_and_preventing_anonymous_proxy_usage_32943

[ ]’s

Security

DRI - International

dezembro 2nd, 2008

DRI International was founded in 1988 as the Disaster Recovery Institute in order to develop a base of knowledge in contingency planning and the management of risk, a rapidly growing profession.

Today DRI International administers the industry’s premier educational and certification programs for those engaged in the practice of business continuity planning and management.

Business Impact Analysis

Identify the impacts resulting from business interruptions that can affect the organization and techniques that can be used to quantify and qualify such impacts. Identify time-critical functions, their recovery priorities, and inter-dependencies so that recovery time objectives can be established and approved.

DRII
BIA

Security

How to Achieve Comprehensive Network Security - Q1Labs

novembro 27th, 2008

Security practitioners need to think about security management along three separate axes - operations, investigations, and compliance reporting. Each of these functions is distinct, and typically involves different organizational hierarchies, which dramatically complicates the challenge of security management. The good news is that all of these management functions ultimately can be driven by a common data set, and that is the opportunity for a security management platform to aggregate this data once and leverage it for a number of suitable purposes.


click here

[ ]’s

Security

ISSA Day Novembro 2008

novembro 26th, 2008

Anote em sua agenda: no dia 26/11/08, quarta-feira, a ISSA capítulo Brasil/SP irá realizar mais um ISSA Day, com o apoio da CLM.

Neste evento, a ISSA Brasil convidou o André D. Corrêa para apresentar uma palestra sobre o projeto “Malware Block List” (www.malware.com.br). Nos últimos 3 anos o projeto Malware Block List tem coletado, analisado e monitorado URLs utilizadas em Phishing Scams e que apontam para Malwares. As listas de URLs são distribuídas gratuitamente para  que administradores de sistemas e redes bloqueiem o acesso a elas,  impedindo assim que usuários sejam infectados por Malware. Nesta  apresentação serão discutidos os desafios de desenvolver e manter este  projeto, bem como os aspectos de colaboração com a comunidade de  segurança e as tendências futuras em Phishing scams.

Data: 26/11 das 19h às 22h
Local: Sonesta São Paulo Ibirapuera, Avenida Ibirapuera, 2534, Moema, São Paulo (SP)

[ ]’s

Security