Access Control: Opinions
Opinions
- +
Strange account management at Amazon 09/10/2008 09:51:00
A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past. - +
Five lessons learned about computer security 16/07/2008 11:15:22
How a hacker turned an illegal hobby into a useful career.Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career. - +
Hack a million systems - earn a job 16/07/2008 16:12:54
The idea of employing an admitted botnet creator and carding software author might not be palatable for many, but not so for an 18-year old New Zealander.It has been a number of years since the fantasy that hackers will be offered a job by those who they hacked was even a potential reality, but there are reports that this might still be the case in New Zealand. - +
When university research is responsible for that network probe 10/07/2008 10:08:45
ISC handlers recently noted odd network traffic on an unexpected port across many systems. It turned out that the traffic was the result of a Texas A&M research project.The Internet Storm Center, operated by SANS, is one of the leading sources when it comes to identifying emerging attacks against networks, through their DShield collaborative network analysis effort. Traffic spikes on network ports that are well above the normal rates of traffic flow can signify a rapidly spreading exploit or it could be a misconfigured network spewing rubbish across the rest of the Internet. One of the ISC's handlers noted a significant spike of traffic on port 7 recently and was surprised by what he found. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
Online poker cheating demonstrates insider risk 18/06/2008 15:55:02
Poker cheats are using insider knowledge to gain competitive advantage.When determining the risk to a system and the data stored on it, insider threats are generally regarded as lower risk. Despite the complete access (high risk) that insiders generally have, most of the time insiders are trusted agents (very low risk) on the network. When it breaks down, it can break down in a catastrophic manner, especially if there is money at stake. - +
A resurgent Denial of Service threat emerges 11/06/2008 19:12:24
Something new might be emerging from the underground.A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack. - +
Security in a bubble 19/03/2008 11:03:54
Security must be distributed, ubiquitous and pervasivePeople don't notice change when it's gradual. Sometimes, however, small, incremental changes add up in a way that isn't noticed until a change in degree becomes a change in kind. - +
How to limit what contractors can do on the network 17/07/2007 10:15:02
Some ways to implement controls for contractorsQuestion: We have contractors perform a number of critical services, such as managing our IBM blade servers. These staff have to be on the LAN, and they're long-time contractors, so trust levels run pretty high, but I know they shouldn't be able to go everywhere on the LAN. How can I limit their access while still letting them do their jobs, and most important, not making them feel like I don't trust them?
Additional Resources
Polls
CSO Online Member Login
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
“Just Graphics” isn’t enough any more 2008-11-28 15:02:00+11
Why Sealy’s management sleep soundly at nights... 2008-11-28 11:18:00+11
Capture and Digitize Your Treasure Moments ~ Compro VideoMate C200 USB A/V Capture Stick 2008-11-26 12:37:00+11
Net 24 slashes backup window by two-thirds 2008-11-26 10:28:00+11
Sponsored Links
PC World
Buying Guides
Good Gear Guide
Buying Guides
Computerworld
ARN


