<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-22206882</id><updated>2011-11-28T00:05:49.118Z</updated><title type='text'>Infosec Dan</title><subtitle type='html'>Infosec rants. Your 'Daily Source' for Infosec Tips and Tricks (tm). Warning: Bad humour and unintended puns may follow.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-22206882.post-113978735761555624</id><published>2008-10-06T23:26:00.000+01:00</published><updated>2009-01-12T11:28:44.344Z</updated><title type='text'>Risk Management</title><content type='html'>Security comes at a price. A very steep price, that most businesses are reluctant to pay. I mean 'isn't it enough that we keep our information in a firewalled DMZ, physically located in an alarmed, hermetically sealed, climate controlled room, protected by biometricly equipped entry/exit points with twenty four hour guards, eight foot fences... Killer Poodles?&lt;br /&gt;&lt;br /&gt;The answer, in case you are wondering, is no. Unfortunately the premium on Killer Poodles that can sniff network traffic as well as bite intruders is way too high. so other methods to be employed. One, poodleless way to reduce the cost of Security is through Risk Management. Wow, that is freaky, I swear I just heard the Internet yawn. No really, Risk Management is the answer! In fact it is the only answer. 'Information Security' = 'Risk Management'. You heard it here first folks.&lt;br /&gt;&lt;br /&gt;Here is an official definintion:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;Risk management is the identification, measurement, control and minimization of loss associated with uncertain events or risks. It includes the overall security reviews, risk analysis, evaluation and selection of safeguards, cost/benefit analysis, management decisions, safeguard implementation and effectiveness reviews.&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;- Hansche, S;Berti, J;Hare, C. Official (ISC)2 Guide to the CISSP Exam. New York: Auerbach Publications;2004.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Over my next few bleurghs or what simple folk refer to as a 'blog entry', I will talk about the Risk Analysis part of 'Information Security Management'. For now, go read a book.&lt;br /&gt;&lt;br /&gt;If you enjoyed this post &lt;a onclick="return dbt_bookmark('http://infosecdan.blogspot.com/2006/02/risk-management.html');" href="http://www.blogger.com/post-edit.g?blogID=22206882&amp;amp;postID=113978735761555624#"&gt;Bookmark it at del.icio.us&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22206882-113978735761555624?l=infosecdan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/113978735761555624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22206882&amp;postID=113978735761555624' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113978735761555624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113978735761555624'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/2006/02/risk-management.html' title='Risk Management'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22206882.post-3512835410317741505</id><published>2008-04-30T10:27:00.003+01:00</published><updated>2008-04-30T10:57:30.164+01:00</updated><title type='text'>Personal Data Encryption with TrueCrypt</title><content type='html'>If you need a tool to encrypt your personal data in an efficient, manageable and above all secure manner then I can't reccomend TrueCrypt - &lt;a href="http://www.truecrypt.org/"&gt;www.truecrypt.org&lt;/a&gt; highly enough.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22206882-3512835410317741505?l=infosecdan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/3512835410317741505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22206882&amp;postID=3512835410317741505' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/3512835410317741505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/3512835410317741505'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/2008/04/personal-data-encryption-with-truecrypt.html' title='Personal Data Encryption with TrueCrypt'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22206882.post-114175066423137209</id><published>2006-03-07T16:46:00.000Z</published><updated>2006-03-07T17:18:27.846Z</updated><title type='text'>Why replace telnet with SSH?</title><content type='html'>I still get asked this one from time to time, so here it is in writing for future reference.&lt;br /&gt;&lt;br /&gt;Essentially you might as well ask why you should replace any unencrypted protocol with an encrypted one.  A detailed risk or cost benefit analysis is probably unnecessary when you consider this question:&lt;br /&gt;&lt;br /&gt;Do you trust the people you allow onto your network?&lt;br /&gt;&lt;br /&gt;If the answer is no, and it really should be, then you should consider replacing any unencrypted authentication (HTTP Digest, FTP, Telnet) to your companies assets with more secure methods (HTTPS, SSH, SFTP).&lt;br /&gt;&lt;br /&gt;If you can’t be convinced to distrust your staff, then I hope you have implemented Port Based Network Access Control (802.1x)  or have really clever guard dogs at a minimum, because with the following freely available tool, anyone who manages to connect to your network will basically own it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.oxid.it/cain.html"&gt;http://www.oxid.it/cain.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;At it's heart Cain is an extremely comprehensive, yet easy to use, set of password cracking tools combined with a network sniffer. The latest feature to be introduced is truly frightening. Automated ARP cache poisoning. For those of you who don't understand the significance of this you should read the following article:&lt;br /&gt;&lt;a href="http://www.grc.com/nat/arp.htm"&gt;&lt;br /&gt;http://www.grc.com/nat/arp.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Quite simply it gets around one of the supposed security benefits of switched networks. The inability to sniff traffic destined for ports other than the one you are connected to.&lt;br /&gt;&lt;br /&gt;If you enjoyed this post &lt;a href="#" onclick="return dbt_bookmark('http://infosecdan.blogspot.com/2006/03/why-replace-telnet-with-ssh.html');"&gt;Bookmark it at del.icio.us&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22206882-114175066423137209?l=infosecdan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/114175066423137209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22206882&amp;postID=114175066423137209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/114175066423137209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/114175066423137209'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/2006/03/why-replace-telnet-with-ssh.html' title='Why replace telnet with SSH?'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22206882.post-113957117933324516</id><published>2006-02-10T11:23:00.000Z</published><updated>2006-02-23T11:35:46.150Z</updated><title type='text'>Tip #1 - Never use customer data in a test lab. Or 'How to get Fired in Three Easy Steps'.</title><content type='html'>This is one that never ceases to surprise me. People, how hard is it to generate fake customer data? Wait that gives me an idea. A 'Fake Customer Generator'. I'm going to get right on it.&lt;br /&gt;&lt;br /&gt;If you enjoyed this post &lt;a href="#" onclick="return dbt_bookmark('http://infosecdan.blogspot.com/2006/02/tip-1-never-use-customer-data-in-test.html');" &gt;Bookmark it at del.icio.us&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22206882-113957117933324516?l=infosecdan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/113957117933324516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22206882&amp;postID=113957117933324516' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113957117933324516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113957117933324516'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/2006/02/tip-1-never-use-customer-data-in-test.html' title='Tip #1 - Never use customer data in a test lab. Or &apos;How to get Fired in Three Easy Steps&apos;.'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22206882.post-113950809860498022</id><published>2006-02-09T18:00:00.000Z</published><updated>2006-02-23T12:07:44.630Z</updated><title type='text'>My Favourite Tools (smirk)</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;The obligatory posting of favourite security tools:&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.insecure.org/nmap/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Nmap&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;The tool that has rocked many a world.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;nmap &lt;/span&gt;-sI 4lyfe&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;a href="http://tcpreplay.sourceforge.net/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Tcprelay&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;Great for knocking over flaky services&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;a href="http://nemesis.sourceforge.net/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Nemesis&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;A bit like witchcraft for packets.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;a href="http://www.chiark.greenend.org.uk/%7Esgtatham/putty/"&gt;Putty &lt;/a&gt;(is there an alternative?!)&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;SSH Client.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Nessus&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;   &lt;ul&gt;     &lt;li&gt;&lt;span style="font-family:trebuchet ms;"&gt;The lazy way.&lt;br /&gt;  &lt;/span&gt;&lt;/li&gt;   &lt;/ul&gt;   &lt;li&gt;&lt;a href="http://www.microsoft.com"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Powerpoint&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;   &lt;ul&gt;     &lt;li&gt;No jokes. The most effective way I know of explaining security to the PHBs other than knocking them over the head with a brick.&lt;br /&gt;&lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;ul&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;If you enjoyed this post &lt;a href="#" onclick="return dbt_bookmark('http://infosecdan.blogspot.com/2006/02/my-favourite-tools-smirk.html');" &gt;Bookmark it at del.icio.us&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22206882-113950809860498022?l=infosecdan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecdan.blogspot.com/feeds/113950809860498022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22206882&amp;postID=113950809860498022' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113950809860498022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22206882/posts/default/113950809860498022'/><link rel='alternate' type='text/html' href='http://infosecdan.blogspot.com/2006/02/my-favourite-tools-smirk.html' title='My Favourite Tools (smirk)'/><author><name>DC</name><uri>http://www.blogger.com/profile/01054975835962882702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
