Friday, December 17, 2010

When's a password good or bad?

A reasonable article on when good passwords don't matter.

Story here

Another story on the ability to crack 'good' passwords
here

NSA and compromised networks


Apparently the NSA think that their own networks can't be considered clean and security and take the appropriate actions based on that position including increased audit, new network sensors and standardisation.

Story here


Wednesday, December 15, 2010

Mounting a dd image




Interesting article on how to mount a dd image from a backup or when a hard drive is failing or copied

http://rackerhacker.com/2010/12/14/mounting-a-raw-partition-file-made-with-dd-or-dd_rescue-in-linux/

Hashing tool


New Hashing tool http://secure1st.com/

Friday, November 5, 2010

Vmware vsphere achieves eal 4+ certification




http://virtualization.info/en/news/2010/11/vmware-vsphere-4-0-receives-common-criteria-eal4-certification.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Virtualization_info+%28virtualization.info%29

Interesting comment at end of article on what is not included

Because the vendor itself specifies the Security Target document, it’s really interesting to know what isn’t included, especially when you want to compare the product with comparable products which are also EAL4+ certified.

For ESX/ESXi functionalities not included in the Security Target are:

Simple Network Management Protocol (SNMP), File Transfer Protocol (FTP), Telnet
The use of any authentication method on ESX(i) other than the local password database
VMware Software Development Kit (SDK) tools
The procfs interface (used to manage CPU resources) on the ESX host Service Console
VMware Scripting Application Programming Interface (API) on the ESX host.
VMware Consolidated Backup
Guest OS patch updates via Update Manager
By earning this certification VMware stays way ahead of Citrix for which XenServer 5.6. and XenDesktop 4.0 achieved EAL2 certification in September this year.

four pillars of endpoint security




Interesting article from Microsoft technet

http://technet.microsoft.com/en-gb/magazine/gg213837.aspx

Tuesday, October 19, 2010

Java outstrips Adobe


Apparently Java is the new Adobe when it comes to malware attacks on PC's. According to a report by Microsoft, the attacks on vulnerable are magnitudes of order greater than adobe, previous number one target of malware.













 
Copyright 2009 Security Monkey. Powered by Blogger Blogger Templates create by Deluxe Templates. Sponsored by: Website Templates | Premium Themes. Distributed by: blog template