The Tech Herald

NCSAM: Security in 140 characters or less…

by Steve Ragan - Oct 5 2011, 12:00

Tom Liston, the Senior Security Consultant for InGuardians, Inc, has written a great blog on the SANS ISC diary, focusing on the basics of information security. His tips were sourced from Twitter; hence this story’s title, but they are a perfect fit for National Cyber Security Awareness Month.

Liston’s blog starts out by recounting a recent job. “I had just spent a week immersed in a corporate culture that seemed to have focused itself on so many higher-level security issues that the basics – the ‘Security 101’ stuff – was just plain overlooked,” he wrote.

“The more I thought about it, the more it bothered me.  It wasn't some fancy-schmancy 'leet h@x0r 0-day that let us take down this organization from the inside: it was stupid-simple low-hanging fruit… Think about it: Over the past year, how many high-profile hacks have been the result of awesome cutting edge skillz?  How many have happened because someone just flat-out did something dumb? We truly are neglecting the basics.”

Liston went to Twitter and asked other security professionals to share their wisdom. Some of the highlights are below, the rest can be seen on the SANS post, or on Twitter here.

If you can guess where PHPmyAdmin is installed, then so can attackers.

You are already pwn3d. The question is, "What will you do about it?"

Don't leave default passwords on the administrative interfaces of your 3rd party web applications.

Know your network - and all devices in it - well enough to spot unusual activity.

Security 101: If you don't need it, turn it off.

Computers remember a lot. Even more if you contact security personnel before you reboot.

If your product allows remote connections somebody WILL write a python/perl/ruby script to connect to it and send whatever THEY want.

A backup is not a backup until you do a restore.

Attack vectors and regulatory requirements change. "That's how we've always done it" is a poor and lazy excuse.

In your encryption system, your key is the weakest link. If it isn't, you're doing it wrong.

If you don't log "accepts" in your FW logs for admin protocols you will have no way of knowing when those accounts are abused.

Analyse your logs in detail, it is those with their heads buried in your logs that hold the key to prevent, detect and recover.

Give only the permissions required to do the normal daily duties, nothing more. Special logons for special occasions.

Unencrypted Wi-Fi is never secure. WEP = Unencrypted Wi-Fi. Trust me. Stop using it. Now. Really.

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

Car Games Update August 30th

We have added a few new games to the car games section of Autosaur. First up is the Car Eats...

2015 Toyota Tundra TRD Pro Prices

Toyota have announced prices for their 2015 Tundra TRD Pro, based on the Tundra it includes ...

2015 Toyota Tundra TRD Pro Pictures

Toyota recently announced prices for the 2015 Toyota Tundra TRD Pro. We have added some...

2015 Dodge Challenger Mopar Challenger Drag Pak Pictures

Mopar have been showing off their 2015 Mopar Challenger Drag Pak test vehicle at the Nationa...

Ford Customers Test 2015 F-150

Ford have selected four customers from the 15,000 who applied to be first to test the latest...