Interesting site on Wi-Fi news
Wi-Fi Networking News
Handy site, I like the little hotspot locator in the corner...
Wi-Fi Networking News
Handy site, I like the little hotspot locator in the corner...
Here's another article around the idea of policy enforcement, this time on Switches.
As I said previously I think that this is the right way to go about it. If it is possible to block a machine from getting on the network if it doesn't meet certain criteria, then it would be possible not only to reduce the incidence of virii/worms in corporate networks, it might also provide some defence from non-corporate machines being placed on the network.
SecurityFocus HOME Infocus: Wireless Attacks and Penetration Testing (part 2
Second part of an interesting article on Wireless Pen Testing.
Came across an interesting sourceforge site with lots of hints and tips on things like Linux, MySQL and bash, oddly it's called Souptonuts
SecurityFocus HOME Infocus: TCP/IP Skills for Security Analysts (Part 2)
The second part of the article on TCP/IP skills for security analysts is up on securityfocus.com
The story over at SecurityFocus HOME News: Unpatched IE vuln exploited by adware provides an example of a valuable point, which is that it is not just "white hat" security researchers that are looking for bugs in Microsoft, and other, products. Which is why it's important that vendors get their patches out as soon as they can and don't take up to 200 days to release it...
Over at www.xmethods.net there's a really cool list of functional web services.
With each there's a link so you can try them out. It's a pretty diverse bunch including practical things like curency conversion and less practical things like... random George W Bush quotes
A Link to a handy IP address location service...
It definately looks like Wireless insecurity issues will be here to stay for the time being. With 2 vulnerabilities in popular wifi products being announced here and here .
The main problem with these types of vulnerabilities is that I don't think that they will be patched anytime soon in the majority of affected devices. People are hardly waking up to the concept that software needs to be regularly patched, let alone the idea that hardware requires patches as well... Also a lot of wifi products tend to be deployed in smaller organisations and homes, where there is, typically, less security knowledge than in larger firms...
Also a problem is as noted here in a lot of cases you don't even need a vulnerability to hack into a wireless network as many vendors ship Access Points in a wide open config!
Microsoft, Sun Security Paths Diverge
Well here's a suprise (sorry being a tad cynical) Microsoft and Sun will be working to 2 different standards WRT identity management... VHS and Betamax anyone...