Monday, 20 January 2014

Microsoft will furnish malware assassin to XP users until mid-2015

Malicious Software Removal Tool (MSRT) to scrub infected XP PCs for more than a year after Microsoft ends patches

Microsoft confirmed on Friday that it will continue to offer its malware scrubbing program to Windows XP users for more than a year after it stops patching the operating system.

"Microsoft's Malicious Software Removal Tool is aligned with the company's anti-malware engines and signatures, and as such the removal tool will continue to be provided for Windows XP through July 14, 2015," a company spokesperson wrote in an email reply to questions.

The Malicious Software Removal Tool (MSRT) is updated monthly as Microsoft targets specific major malware families it believes are the biggest threats at the time. It's distributed through Microsoft's Windows Update service and the business-grade Windows Server Update Service (WSUS) on "Patch Tuesday," the date each month when the company ships security patches and other fixes to customers. The MSRT automatically installs and then runs in a seek-and-destroy mission.

Users can also manually download the MSRT from Microsoft's website.

MSRT is not an antivirus program, but rather a cleanup utility designed to eradicate malware that has already wormed onto a Windows PC. The tool was first released in 2005.

The extension of MSRT's availability for Windows XP was part of Microsoft's decision last Wednesday to offer new anti-malware signatures to XP customers who run the company's free Security Essentials antivirus (AV) software.

Originally, Microsoft had said it would stop shipping Security Essentials' signature updates to XP PCs after April 8. But in a tacit nod to XP's widespread use, Microsoft postponed the cut-off until July 14, 2015.

Microsoft will ship its final public security patches for Windows XP in less than three months, ending nearly 13 years of support for the ultra-successful OS.

Microsoft did not reply Saturday to follow-up questions asking what channels it will use to distribute the malware eraser between April 8, 2014, and July 14, 2015.

If Microsoft continued to deliver the MSRT via Windows Update, the tool would be a valuable weapon in containing infections on Windows XP PCs.

Say a new malware family popped up, or an older one began infecting large numbers of Windows PCs, including those still running XP. Microsoft would be able to revise MSRT so it targets the new or suddenly aggressive malware for detection and deletion, and automatically put it on XP systems. Not only would that keep the remaining XP owners safer, but it would also reduce the number of compromised computers that could in turn be used by hackers to infect machines running the still-supported Vista, Windows 7 and Windows 8 operating systems.

The impact of the MSRT extension would be more muted if Microsoft required users to download the tool themselves. Even so, MSRT is a very popular download -- currently No. 2 on the company's Download Center -- indicating that large numbers of customers seek it out.

Although Microsoft has been urging customers to drop XP before the April 8 deadline for a new OS or PC, millions of machines worldwide will continue to run the aged OS for months and maybe even years to come.

According to metrics company Net Applications, Windows XP's user share -- the percentage of all personal computer owners who went online with that OS -- stood at 29% at the end of December 2014. Computerworld has forecast that at least 25% of all personal computers will be running the operating system at the end of April, and about 20% at the end of this year.

Those numbers were at the root of Microsoft's recent moves to help out XP users: While the company has remained adamant that bug patches will be discontinued after April 8, some cracks in its "Death to XP" policy have appeared, including the continued availability of Security Essentials' signatures and the lifespan extension for the MSRT.

The explanation: Microsoft has decided it best for all concerned -- including itself and its reputation -- that it throw some security bones, if only small ones, to those who can't or won't upgrade from XP.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Friday, 27 December 2013

3 Ways Enterprise IT Will Change in 2014

The holiday season is a great time to look back at the year, with an eye toward what we in the ever-changing world of information technology can expect in 2014. These three trends warrant your close attention in the new year.

In Light of NSA Revelations, companies Will Be Wary of the Cloud
For most businesses, 2013 was the year of the cloud. Companies that still hosted their email in house would in large part move that expense and aggravation to someone else. Microsoft SharePoint and other knowledge management solutions could be run in someone else's datacenter, using someone else's resources and time to administer, thus freeing your own people to improve other services or, gasp, work directly on enhancing the business.

But then Edward Snowden came around in June and started to release a series of damning leaks about the United States National Security Agency's capability to eavesdrop on communications. At first, most folks weren't terribly alarmed. But as the year wore on, the depth of the NSA's alleged capabilities to tap into communications - both with and without service provider knowledge - started to shake the faith of many CIOs in the risk/benefit tradeoff for moving to cloud services.

For companies in heavily regulated industries, it's hard to ignore the continued discovery of the depths to which the NSA has the capability to read data both in transit and at rest. Patient privacy records, sensitive financial transactions and any other data that must by law be kept private - is it now considered private? Can you warrant that to your customers? Can you warrant that to your regulators? Can you afford the risk that NSA access to your data represents? Is it even something that you can control, or do you just ignore it and hope for the best? (That is said with no judgment; given the realities of your business, that could very well be a valid strategy.)

How-to: 5 Tips to Keep Your Data Secure on the CloudMore: Who Can Pry Into Your Cloud-based Data?
In 2014, we'll see a continued analysis of just what services make sense in the cloud, but some old cherished low-hanging fruit, like email and collaboration, will no longer be considered "easy wins" because of these continuing allegations. Perhaps the cloud will not be the default choice going forward but, rather, a choice made after careful study of the environment, using these PRISM leaks as one important bit of context.

Microsoft's CEO Search Will Define the Future of Their Products in Your Organization
The biggest story of the first part of 2014 will undoubtedly be Microsofts selection for only its third CEO in its history. This job is one of the most important positions in the technology industry; who is selected, and what he or she does in her first 100 days, will set the tone for the next five to 10 years.

Reports as of the Monday morning after Thanksgiving 2013 suggest that the Microsoft board of directors has narrowed its potential selections to two: Satya Nadella, the current chief of servers and tooling at the company, and outsider Alan Mulally, who currently is in charge of the Ford Motor Company and is widely credited for executing a fantastic turnaround of operations, profits, and shareholder return after joining the company from Boeing, a corporate neighbor of Microsoft. ( Mulally denies he's interested in the Microsoft job, only heightening speculation.)

There are two main questions surrounding both the choice of chief executive and the immediate moves he makes in the first part of his tenure.

Will the new CEO continue the remake of Microsoft into a devices and services organization?
Steve Ballmer, the company's current CEO, has tried to convert the software company into an organization that makes a variety of devices, such as tablets and phones, which connect to services that Microsoft runs. This has been done both to make those devices more rich and useful for the end user but also to monetize that usage through enhanced upgrade services, advertising revenue and subscription profits.

Of course, this represents a big switch from Microsoft's traditional "pay us for the right to use this software in perpetuity" practice that propelled the business to its current height. Many investors and customers wonder if this transformation is beneficial to them. Will the new CEO elect to continue this transformation and carry on the vision of Steve Ballmer even after his departure? Or will the new CEO put pause on the progress and take a few months to assess whether that transformation is good for both Microsoft and its customers? The answers will have a big impact on the role Microsoft software and technology plays within your own business.

Will the cloud still be a huge focus of the company?
Will the continued preference of developing for Microsoft' cloud-based services versus its traditional on-premises software erode the trust of corporate customers who still have significant investments in their existing on premises licenses?

Related: Why Microsoft SharePoint Faces a Challenging Future
Nowhere is this tension more evident than in the Exchange community, where Exchange Server 2013 customers feel as if they are a distant second cousin to the Office 365 subscription data center environment. Complaints abound, from poor patch quality to irregular updates to features arriving in Office 365 but not Exchange Server 2013 for some time. These on-premises customers, paying many thousands of dollars for their combined server and client access license fees, feel shafted on their investment. Will this tension bleed over into other areas? Is the Exchange model the new model, warts and all, for the company's cloud focus? This is a trend to watch in 2014.

The Role of the Cloud Broker Will Emerge in 2014
Whatever Microsoft does and whatever the revelations about the NSA's PRISM program mean for your business, the continued push around consumerization will mean more cloud services for your organization, not fewer. PRISM might eliminate email and other line of business data from being considered in a move to the cloud - but other, less sensitive data can still be stored in the cloud. The corporate IT department can take advantage of a number of cloud businesses that are designed to save money and lower the cost of access to data while revealing new insights and workflows that may not have been feasible for your organization before.

Blog: Dirty Secrets of Dropbox, Google Drive and Other Cloud Storage ServicesAlso: How to Find the Cloud Storage Service That's Right for You
In 2014 that the cloud broker or cloud solution provider position will really come into its own and begin bearing fruit. Vendor neutral, pay-for-service cloud brokers will be able to consult on your situation and recommend both a provider and a strategy for making use of that provider's products and services for any given task or workload.

IT departments will be in the drivers' seats, able to really sit down with a knowledgeable set of professionals and figure out exactly what solution and what model works best. The cloud broker role will be best placed to help the furthering of the IT organization's transformation from a cost center to a place where new revenues and profits are generated - an additional trend to watch in 2014.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 17 December 2013

Microsoft joins group seeking to replace passwords

The FIDO Alliance envisions a system where users can interact with an online service without surrendering personal details

Microsoft has joined the FIDO Alliance, an industry group attempting to craft industry standards that reduce reliance on passwords, long regarded as a weak point in Web security.

Launched in July 2012, FIDO, which stands for Fast IDentity Online, is hoping its specifications for security devices and browser plugins will be widely adopted across the technology industry.

+ Also on Network World: Bitcoin -- 8 Funny Money videos +

Such efforts depend on voluntary adoption by many companies and organizations. So far, those participating in FIDO include heavyweights Google, MasterCard, Lenovo, Infineon, LG Electronics and a variety of smaller companies.

Authentication hardware and software widely varies, with many proprietary clients and protocols. FIDO hopes that standardizing authentication technologies will lead to better interoperability and innovations in biometrics, PINs (personal identification numbers) and secondary authentication technologies, according to its website.

Usernames and passwords underpin most online services but are easy to intercept. Computer security experts have long warned of password weaknesses, such as easy-to-guess ones and people who reuse them across multiple services.

Password replacement technology has a high bar: it needs to be both effective and simple for users.

FIDO envisions a software client that's installed on computers that employ public key cryptography to authenticate users. All major Web browsers will be supported. The initial focus will be on securing access through Web browsers to Web applications. The group also plans authentication options for Android phones soon and eventually for Windows tablets and Apple products.

When FIDO authentication is used, a user will not need to submit their biometric or personal information to an online service.

The FIDO Alliance will eventually submit its protocol to groups dedicated to Web standards, such as the Internet Engineering Task Force or the World Wide Web Consortium.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, 12 December 2013

Juniper EVP Muglia abruptly quits

Leaves networking company shortly after new CEO is named

Bob Muglia, executive vice president of Juniper Networks' software solutions division, has abruptly resigned from the company following the appointment of a new CEO.

Juniper confirmed Muglia’s departure via this e-mailed statement: “We can confirm that Bob Muglia is leaving Juniper Networks effective Tuesday, December 10. We thank Bob for his contributions to Juniper and wish him well in his future endeavors.

“(CEO) Kevin Johnson will step in as Acting GM of the software division through the end of the month. He will then transition the organization over to Shaygan Kheradpir when he starts as our new CEO in January. We will be relentlessly focused on our customers through this transition.”

The move was first reported on Tuesday by the San Francisco Business Times, which did not give a reason for Muglia’s departure, but did outline the compensation package he will receive.

+ MORE ON NETWORK WORLD Juniper finally talks SDNs +

Juniper named Kheradpir, a former Barclays and Verizon information technology executive, as its new CEO a month ago. Kheradpir replaces Johnson, who last summer announced plans to retire once a new CEO was found.

Muglia, who also worked with Johnson while the two were at Microsoft, was mentioned as a possible replacement for Johnson. But after Johnson’s unremarkable five-year tenure at Juniper, many thought it unlikely Juniper would turn to another former Microsoft software executive to assume leadership of the company.

"Muglia, in my opinion, was always a long shot to get the role," said financial analyst, consultant and blogger Nikos Theodosopoulos, a long time Juniper watcher.

Other observers suggested Muglia was comfortable working with Johnson and perhaps did not relish establishing a new relationship with Kheradpir.

Juniper did not say who would assume Muglia’s role heading up the company’s software business. Muglia developed Juniper’s software-defined networking strategy, which relies on a new software licensing model for more of the company’s revenue.

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com



Thursday, 7 November 2013

Social Engineering: The Basics

What is social engineering? What are the most common and current tactics? A guide on how to stop social engineering.

You've got all the bells and whistles when it comes to network firewalls and your building's security has a state-of-the-art access system. You've invested in the technology. But a social engineering attack could bypass all those defenses.

Say two fire inspectors show up at your office, show their badges and ask for a walkthrough—you're legally required to give them access to do their job. They ask a lot of questions, they take electrical readings at various wall outlets, they examine wiring under desks. Thorough, aren't they? Problem is, in this case they're really security consultants doing a social engineering 'penetration test' and grabbing access cards, installing keystroke loggers, and generally getting away with as much of your business's private information as they can get their hands on. (See How to rob a bank for details from this real-world example.)

Social engineers, or criminals who take advantage of human behavior to pull of a scam, aren't worried about a badge system. They will just walk right in and confidently ask someone to help them get inside. And that firewall? It won't mean much if your users are tricked into clicking on a malicious link they think came from a Facebook friend.

In this article, we outline the common tactics social engineers often use, and give you tips on how to ensure your staff is on guard.

What is social engineering?
Social engineering is essentially the art of gaining access to buildings, systems or data by exploiting human psychology, rather than by breaking in or using technical hacking techniques. For example, instead of trying to find a software vulnerability, a social engineer might call an employee and pose as an IT support person, trying to trick the employee into divulging his password.

Famous hacker Kevin Mitnick helped popularize the term 'social engineering' in the '90s, although the idea and many of the techniques have been around as long as there have been scam artists of any sort. (Watch the video to see social-engineering expert Chris Nickerson size up one building's perimeter security)
Through a Social Engineer's Eyes
Social Engineering expert Chris Nickerson reveals what criminals are looking for when it comes vulnerabilities in building security.

How is my company at risk?
Social engineering has proven to be a very successful way for a criminal to "get inside" your organization. In the example given above, once a social engineer has a trusted employee's password, he can simply log in and snoop around for sensitive data. Another try might be to scam someone out of an access card or code in order to physically get inside a facility, whether to access data, steal assets, or even to harm people.

Chris Nickerson, founder of Lares, a Colorado-based security consultancy, conducts 'red team testing' for clients using social engineering techniques to see where a company is vulnerable. Nickerson detailed for CSO how easy it is to get inside a building without question.

In one penetration test, Nickerson used current events, public information available on social network sites, and a $4 Cisco shirt he purchased at a thrift store to prepare for his illegal entry. The shirt helped him convince building reception and other employees that he was a Cisco employee on a technical support visit. Once inside, he was able to give his other team members illegal entry as well. He also managed to drop several malware-laden USBs and hack into the company's network, all within sight of other employees. Read Anatomy of a Hack to follow Nickerson through this exercise.

In What it's like to steal someone's identity professional pen tester Chris Roberts, founder of One World Labs, says he too often meets people who assume they have nothing worth stealing.

"So many people look at themselves or the companies they work for and think, 'Why would somebody want something from me? I don't have any money or anything anyone would want,'?" he said. "While you may not, if I can assume your identity, you can pay my bills. Or I can commit crimes in your name. I always try to get people to understand that no matter who the heck you are, or who you represent, you have a value to a criminal."


Sneaky stuff. Give me some specific examples of what social engineers say or do.
Criminals will often take weeks and months getting to know a place before even coming in the door or making a phone call. Their preparation might include finding a company phone list or org chart and researching employees on social networking sites like LinkedIn or Facebook.

In the case of Roberts, he was asked to conduct a pen test for a client who was a high-net-worth individual to see how easy it would be to steal from him. He used a basic internet search to find an email address for the individual. From there, it snowballed.

Useful Books on Social Engineering!

Social Engineering: The Art of Human Hacking
By Hadnagy and Wilson (Wiley, Dec 2010)
"This book covers, in detail, the world's first framework for social engineering."

No Tech Hacking: A Guide to Social Engineering, Dumpster Diving, and Shoulder Surfing
By Johnny Long et al (Syngress 2008)
"Whether breaking into buildings or slipping past industrial-grade firewalls, my goal has always been the same: extract the informational secrets using any means necessary."

"We searched for the e-mail address online were able to find a telephone number because he had posted in a public forum using both," said Roberts. "On this forum, he was looking for concert tickets and had posted his telephone number on there to be contacted about buying tickets from a potential seller."

The phone number turned out to be an office number and Roberts called pretending to be a publicist. From there he was able to obtain a personal cell phone number, a home address, and, eventually, mortage information. The point being from one small bit of information, a social engineering can compile an enitre profile on a target and seem convincing. By the time Roberts was done with his pen test, he knew where the person's kids went to school and even was able to pull a Bluetooth signal from his residence.

Once a social engineer is ready to strike, knowing the right thing to say, knowing whom to ask for, and having confidence are often all it takes for an unauthorized person to gain access to a facility or sensitive data, according to Nickerson.

The goal is always to gain the trust of one or more of your employees. In Mind Games: How Social Engineers Win Your Confidence Brian Bushwood, host of the Internet video series Scam School, describes some of the tricks scam artists use to gain that trust, which can vary depending on the communication medium:

-- On the phone:
A social engineer might call and pretend to be a fellow employee or a trusted outside authority (such as law enforcement or an auditor).

According to Sal Lifrieri, a 20-year veteran of the New York City Police Department who now educates companies on social engineering tactics through an organization called Protective Operations, the criminal tries to make the person feel comfortable with familiarity. They might learn the corporate lingo so the person on the other end thinks they are an insider. Another successful technique involves recording the "hold" music a company uses when callers are left waiting on the phone. See more such tricks in Social Engineering: Eight Common Tactics.

-- In the office:
"Can you hold the door for me? I don't have my key/access card on me." How often have you heard that in your building? While the person asking may not seem suspicious, this is a very common tactic used by social engineers.

In the same exercise where Nickerson used his thrift-shop shirt to get into a building, he had a team member wait outside near the smoking area where employees often went for breaks. Assuming this person was simply a fellow-office-smoking mate, real employees let him in the back door with out question. "A cigarette is a social engineer's best friend," said Nickerson. He also points out other places where social engineers can get in easily in 5 Security Holes at the Office.

This kind of thing goes on all the time, according to Nickerson. The tactic is als o known as tailgating. Many people just don't ask others to prove they have permission to be there. But even in places where badges or other proof is required to roam the halls, fakery is easy, he said.

"I usually use some high-end photography to print up badges to really look like I am supposed to be in that environment. But they often don't even get checked. I've even worn a badge that said right on it 'Kick me out' and I still was not questioned."

-- Online:
Social networking sites have opened a whole new door for social engineering scams, according to Graham Cluley, senior technology consultant with U.K.-based security firm Sophos. One of the latest involves the criminal posing as a Facebook "friend." But one can never be certain the person they are talking to on Facebook is actually the real person, he noted. Criminals are stealing passwords, hacking accounts and posing as friends for financial gain.

One popular tactic used recently involved scammers hacking into Facebook accounts and sending a message on Facebook claiming to be stuck in a foreign city and they say they need money.

"The claim is often that they were robbed while traveling and the person asks the Facebook friend to wire money so everything can be fixed," said Cluley.

"If a person has chosen a bad password, or had it stolen through malware, it is easy for a con to wear that cloak of trustability," he said. "Once you have access to a person's account, you can see who their spouse is, where they went on holiday the last time. It is easy to pretend to be someone you are not."

See 9 Dirty Tricks: Social Engineers Favorite Pick-up Lines for more examples.
Social engineers also take advantage of current events and holidays to lure victims. In Cyber Monday: 3 online shopping scams and 7 Scroogeworthy scams for the holidays security experts warn that social engineers often take advantage of holiday shopping trends by posioning search results and planting bad links in sites. They might also go as far as to set up a fake charity in the hope of gaining some cash from a Christmas donation.

Why do people fall for social engineering techniques?
People are fooled every day by these cons because they haven't been adequately warned about social engineers. As CSO blogger Tom Olzak points out, human behavior is always the weakest link in any security program. And who can blame them? Without the proper education, most people won't recognize a social engineer's tricks because they are often very sophisticated.

Social engineers use a number of psychological tactics on unsuspecting victims. As Bushwood outlines in Mind Games, successful social engineers are confident and in control of the conversation. They simply act like they belong in a facility, even if they should not be, and their confidence and body posture puts others at ease.
This is your brain on social engineering

Brian Brushwood is really good at tricking people. So good he founded a website called "Scam School".
Brushwood understands how social engineers mislead people. Four basic principles:
They project confidence. Instead of sneaking around, they proactively approach people and draw attention to themselves.
They give you something. Even a small favor creates trust and a perception of indebtedness.
They use humor. It's endearing and disarming.
They make a request and offer a reason. Psych 101 research shows people are likely to respond to any reasoned request.


Read the details in Mind games: How social engineers win your confidence
"People running concert security often aren't even looking for badges," said Brushwood. "They are looking for posture. They can always tell who is a fan trying to sneak back and catch a glimpse of the star and who is working the event because they seem like they belong there."

Social engineers will also use humor and compliments in a conversation. They may even give a small gift to a gate-keeping employee, like a receptionist, to curry favor for the future. These are often successful ways to gain a person's trust, said Bushwood, because 'liking' and 'feeling the need to reciprocate' are both fixed-action patterns that humans naturally employ under the right circumstances.

Online, many social engineering scams are taking advantage of both human fear and curiosity. Links that ask "Have you seen this video of you?' are impossible to resist if you aren't aware it is simply a social engineer looking to trap you into clicking on a bad link.

Successful phishing attacks often warn that "Your bank account has been breached! Click here to log in and verify your account." Or "You have not paid for the item you recently won on eBay. Please click here to pay." This ploy plays to a person's concerns about negative impact on their eBay score.

"Since people spend years building eBay feedback score or 'reputation,' people react quickly to this type of email. But, of course, it leads to a phishing site," said Shira Rubinoff, founder of Green Armor Solutions, a security software firm in Hackensack, New Jersey. "Many people use eBay, and users often bid days before a purchase is complete. So, it's not unreasonable for a person to think that he or she has forgotten about a bid they made a week prior."

Recent phishing lures even take advantage of the economic downturn, said Rubinoff. It has not been uncommon for fake emails to turn up that claim to be from human resources which say: 'You have been let go due to a layoff. If you wish to register for severance please register here,' and includes a malicious link.

No one wants to be the person that causes problems in this economy, so any email that appears to be from an employer will likely elicit a response, noted Rubinoff. Lares' Nickerson has also seen cons that use fake employer emails.

"It might say, 'In an effort to cut costs, we are sending W-2 forms electronically this year,'" said Nickerson.

How can I educate my employees to prevent social engineering?
Awareness is the number one defensive measure. Employees should be aware that social engineering exists and also aware of the tactics most commonly used.

For elements of an effective security awareness program, see Seven Practical Ideas for Security Awareness and Now Hear This!.

Fortunately, social engineering awareness lends itself to storytelling. And stories are much easier to understand and much more interesting than explanations of technical flaws. Chris Nickerson's success posing as a technician is an example of a story that gets the message across in an interesting way. Quizzes and attention-grabbing or humorous posters are also effective reminders about not assuming everyone is always who they say they are.

"In my educational sessions, I tell people you always need to be slightly paranoid and anal because you never really know what a person wants out of you," said Lifrieri. The targeting of employees "starts with the receptionist, the guard at the gate who is watching a parking lot. That's why training has to get to the staff."

Social engineering tricks are always evolving, and awareness training has to be kept fresh and up to date. For example, as social networking sites grow and evolve, so do the scams social engineers try to use there; see 5 Facebook, Twitter Scams to Avoid and 5 More Facebook, Twitter Scams to Avoid.

The National Cyber Security Alliance recently launched a 'Stop.Think. Connect.' campaign to get users to give more thought to their online behavior so they recognize social engineering cons before they get in trouble.

But it isn't just the average employee who needs to be aware of social engineering. A study conducted in 2010 found executives are actually the easiest targets. In Social engineering: 4 reasons why executives are the easiest targets Jayson Street, a security consultant and CIO of Stratagem 1 Solutions, says executives are soft targets for many reasons, including a lax security attitude and their tendency to use the latest technology—even before it is properly vetted.

Although it's a tactic to use with great caution, fear of embarrassment is a strong motivator. Nobody likes to look foolish, and a successful social engineering test does make the victim feel foolish. This is partly why storytelling works—the reader or listener feels empathy for the person who "got suckered."

Consider this factor if you choose to design an in-house social engineering penetration test. A little embarrassment will put everyone on their toes; crossing the line to humiliation will only make employees angry.


Are there any tools to help make this process more effective?
A number of vendors offer tools or services to help conduct social engineering exercises, and/or to build employee awareness via means such as posters and newsletters.

Also worth checking out is social-engineer.org's Social Engineering Toolkit, which is a free download.

The toolkit helps automate penetration testing via social engineering, including "spear-phishing attacks", creation of legitimate-looking websites, USB drive-based attacks, and more.


MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com

Monday, 28 October 2013

6 dirty secrets of the IT industry II

The classic illustration of this principle occurred in January 2012, when U.S. and New Zealand authorities shut down Kim Dotcom's MegaUpload file locker in January 2012. Along with a trove of allegedly pirated movies, the authorities confiscated the data of thousands of law-abiding customers and refused to return it. Whether those customers will ever get their data back remains unresolved.

"The risk of seizure is real," confirms Jonathan Ezor, director of the Touro Law Center Institute for Business, Law and Technology. "If there is any legal basis for law enforcement or other government officials to seize storage devices or systems -- which may require a warrant in certain circumstances -- and those systems contain data of both suspects and nonsuspects, all might be taken. Ultimately, any time an organization's data are stored outside of its control, it cannot prevent someone from at least gaining access to the hardware."

Users who want to protect themselves against this worst-case scenario need to know where their data is actually being kept and which laws may pertain to it, says David Campbell, CEO of cloud security firm JumpCloud.

"Our recommendation is to find cloud providers that guarantee physical location of servers and data, such as Amazon, so that you can limit your risk proactively," he says.

Encrypting the data will decrease the chance that anyone who seizes it will be able to read it, adds Ezor. Another good idea: Keep a recent data backup nearby. You never know when it might end up being your only copy.

Dirty IT secret No. 4: Your budget's slashed, but the boss has a blank checkRFPs are for peons

In virtually every midsize or larger organization, there are two ways to get purchases approved, says Mike Meikle, CEO of the Hawkthorne Group, a boutique management and information technology consulting firm. There's the official purchasing procedure -- a time-consuming process that forces you to jump through more flaming hoops than a circus act. And there's the special procurement diamond lane, available only to a special few.

"People at the senior leadership level have their own procurement pipeline," he says. "What takes an IT person eight months to obtain through official channels these execs can get in a few weeks, if not sooner. It's what I call the Diamond Preferred plan. I've never worked with an organization in government or private industry that didn't have a secret procurement path."

The purpose of the official procurement process is to make it harder for employees to spend the company's money, says Meikle -- unless, of course, they know the secret handshake. Unfortunately, he adds, the CIO is usually not a member of this club, which means large tech purchases can be made without serious cost benefit analysis or consideration of IT's strategic vision. 

"They'll go out to lunch, a vendor will whisper sweet nothings in their ear, and the next thing you know they've spent half a million on a mobile application management solution, not realizing you already had one," he says. "Now you have two."

Not so, contends a private consultant to the military and Fortune 100 companies who asked to remain unnamed. While there are cases where organizations may bypass standard procurement procedures, it's almost always for something the IT department needs right away and doesn't want to waste weeks cutting through red tape to get it, he says.

"Nontechnology executives don't know enough about IT to make a large purchase decision," he adds. "If a senior executive circumvents the procurement process, that purchase order has to have a signature on it before the supplier will ship it. If anything goes wrong with that technology, the executive would be accountable and traceable. That's like kryptonite to those guys." 

Dirty IT secret No. 5: You're getting the short end of the customer support stickThat technician is just another script kiddie

Stop us if this sounds familiar: You're on the phone with a support technician halfway around the globe, but you get the distinct impression they know less than you do and are just reading from a script. Guess what? They probably are.

"IT support is a cheap commodity," says Tim Singleton, president of Strive Technology Consulting, a boutique support firm catering to small and midsized businesses. "Tools that do most of it for you are free, and computers require less knowledge now than they used to. Your neighbor's daughter or the tech-savvy guy in accounting can probably fix your computer as well as any IT company."

But some say that assessment is too broad. While that may be true for the simplest problems, it's not true for more complex ones, notes Aramis Alvarez, SVP of services and support at Bomgar, which makes remote IT support solutions for enterprises.

"The problem with calling IT support a 'cheap commodity' is that not every problem is created equal," says Alvarez. "Some basic issues can be diagnosed by any tech-savvy person, but difficult ones, such as viruses, cannot. Your neighbor's daughter may be armed with enough knowledge to be dangerous, but she could end up destroying the data on your computer."

Then you may end up paying much more later to clean up the mess, adds Joe Silverman, CEO of New York Computer Help -- which often happens when companies cut corners by shortchanging or overburdening internal IT support.

"We have gone to many NYC offices and apartments to see the leftover tracks of a shoddy computer repair or IT job from another company, family member, or friend who acted as the go-to IT guy," he says. "The guy in accounting who sometimes takes care of computer issues is most likely too busy and too inexperienced to fix a failed hard drive, motherboard, or power supply. If the network or server crashes, do you want to really depend on your accounting guy to get the job done, or a senior network engineer with 20 years of experience?"

Dirty IT secret No. 6: We know a lot more about you than you thinkGoing all in on data collection

Think the NSA has you under surveillance? They're punks compared to consumer marketing companies and data brokers.

One of the biggest offenders are casinos, says J.T. Mathis, a former casino database manager and author of a self-published expose about his experience titled, "I Deal to Plunder: A Ride Through the Boom Town." When you enter a casino, you're gambling with more than just money -- you're risking your most personal data. Mathis estimates that his former employer's marketing database contained the names of more than 100,000 active and inactive gamblers.

"From the moment you enter the casino, everything you do is tracked," says Mathis. "If you sit down at a slot machine, they know exactly where you're at, how many times you've pulled the handle, and how much money you're putting in. They know you like to eat at 4:30 and order the lobster platter. They know your favorite cigarettes and wine and whether you watched porn in your room. And when you arrive during the summer they know the lady you're with is not your wife, so employees make sure to call her Cindy and not Barbara."

Former casino executive and LSU professor Michael Simon confirms Mathis' story. But, he adds, it's not that much different than the kind of data collection performed by companies like CVS, PetSmart, or Amazon.

"I teach an MBA class on database analysis and mining, and all the companies we study collect customer information and target offers specific to customer habits," he says. Simon, author of "The Game of My Life: A Personal Perspective of a Retired Gaming Executive," adds, "It's routine business practice today, and it's no secret. For example, I bring my dog to PetSmart for specific services and products, and the offers they send me are specific to my spending habits, and I like that. PetSmart on the other hand gives me what I want instead of wasting time sending me stuff I won't use like discounts on cat food or tropical fish."

One thing that is different: When Mathis was laid off in May 2012, he still had copies of the database in hand. When he tried to return it, he was out of luck -- the casino refused to return his calls. Talk about gambling with your data.


MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com

6 dirty secrets of the IT industry

IT pros blow the whistle on the less-than-white lies and dark sides of the tech business

IT pros usually know where the bodies are buried. Sometimes that's because they're the ones holding the shovel.

We asked InfoWorld readers to reveal the dirtiest secrets of IT -- the less-than-white lies and dark sides of technology that others may not be aware of. We then ran those "secrets" through a BS detector, fact-checking them with experts in the relevant field. In some cases the experts concurred, in other cases they did not.

[ Also on InfoWorld: Take heed, young techies, of these 10 hard-earned lessons of a lifetime in IT and beware these 7 fatal IT mistakes that will get you fired. | Think you got it bad? Check out InfoWorld's dirty IT jobs hall of shame for a dose of perspective. | Get a $50 American Express gift cheque if we publish your tech tale from the trenches. Send it to offtherecord@infoworld.com. ]

Do sys admins wield power far beyond the CIO's worst nightmares? Are IT employees routinely walking off with company equipment? Can the data you store in the cloud really disappear in an instant? Are you paying far too much for tech support?

Read on to find out what our leakers and experts believe.

What's the biggest IT secret you know about? Spill the beans below. (6 Comments.)

Dirty IT secret No. 1: Sys admins have your company by the short hairsWhen the IT fox is guarding the data hen house

Anyone who's followed the Edward Snowden story knows what kind of damage a sys admin with an agenda can do. But even IT people may not realize the full range of unfettered admin access and the kinds of pain it can bring.

"There are no secrets for IT," says Pierluigi Stella, CTO for managed security service provider Network Box USA. "I can run a sniffer on my firewall and see every single packet that comes in and out of a specific computer. I can see what people write in their messages, where they go to on the Internet, what they post on Facebook. In fact, only ethics keep IT people from misusing and abusing this power. Think of it as having a mini-NSA in your office."

This situation is more common than even most CIOs are aware of, says Tsion Gonen, chief strategy officer for data protection firm SafeNet.

"I'd estimate this is true in 9 out of 10 organizations," he says. "Enterprise security is only as secure as the ethics of trusted IT administrators. How many of them have sys admins who abuse their access privileges is harder to say -- but enough to hit the news almost every week. The scariest thing is that the same people who present the greatest risk are often the very people who approve access."

David Gibson, VP of Varonis, a data governance solution provider, agrees that admins are often able to access data they shouldn't without being noticed, but he puts the number closer to 50 percent. He adds it's not just the admins; most users have access to far more data than they need to do their jobs.

He says the solution comes down to getting a better handle on two things: reducing access to get to a "least privilege" model, and continuous monitoring of who is accessing data.

"The organization needs to be able to see who has access to what data, who the data belongs to, and who has been accessing which files," he says. "From there, IT can involve the data owners directly to make informed decisions about permissions and acceptable use."

Dirty IT secret No. 2: Your employees may be helping themselvesWhen "retired" IT assets enjoy a surprise second career

Old tech equipment rarely dies, it just finds a new home -- and sometimes, that home is with your IT employees.

"Employee theft of retired equipment is commonplace," says Kyle Marks, CEO of Retire-IT, a firm specializing in fraud and privacy compliance issues relating to IT asset disposition. "I have never met someone from IT that doesn't have a collection of hardware at home. To many, taking retired equipment is a victimless crime. Most don't view it as a security threat. Once equipment is retired, they act like it is fair game."

The problem with taking equipment bound for the scrap heap or the recycling bin is that it often still contains sensitive data, which if lost could result in massive liability for the company that owns the equipment, says Marks. And, of course, it is still theft of company equipment.

"Theft and fraud are serious situations that create massive privacy liability," he adds. "A capricious IT insider can have costly consequences if left unchecked. Yet in most cases, the people responsible for making sure assets are disposed of properly -- with all data removed -- are in IT. Organizations need to have a 'reverse procurement' process that assures assets are retired correctly."

But does every IT employee really steal old hardware? A veteran of the IT asset disposition industry, who asked to remain anonymous, says the problem isn't nearly as commonplace as Marks makes it out.

"I'm not saying that theft is nonexistent," he says. "I am simply stating that I have never met anyone in the industry with that particular mind-set."

Most equipment that goes missing is simply lost for other, less nefarious reasons -- like it was shipped to the wrong place, he adds.

"It sounds like a bad generalization when in essence a lot companies pride themselves on providing secure services and act in a way that is completely honest and full of integrity."

Dirty IT secret No. 3: Storing data in the cloud is even riskier than you thinkAll the security in the world won't help when Johnny Law comes knocking

Storing your data in the cloud is convenient, but that convenience may come at a high price: the loss of your data in a totally unrelated legal snafu.

"Most people don't realize that when your data is stored in the cloud on someone else's systems alongside the data from other companies, and a legal issue arises with one of the other companies, your data may be subject to disclosure," says Mike Balter, principal of IT support firm CSI Corp.

In other words, your cloud data could be swept up in an investigation of an entirely unrelated matter -- simply because it was unlucky enough to be kept on the same servers as the persons being investigated.

MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com