Microsft Security Policy Compliance...

Redmond enlists security vendors to automate policy compliance
An interesting idea talked about over at Network world, is Microsoft working with A-V vendors on the idea of security policy compliance software. If I'm reading it correctly, the idea is that when an machine tries to log onto a Microsoft network it's agent software will transmit information about things like it's A-V pattern files and patch level and if these don't meet defined standards it will not be able to connect, until it was updated.
It's a good idea for things like laptop users, who perhaps aren't in the office often enough to get updates. That said I like the idea of this being tied into the network switch/router infrastructure more.
The reason being is that even if a PC can't log onto a windows domain it can still connect to other client-server applications, whereas if the switch the PC is connected to, won't let it communicate with anything other than the update server untill it is patched, it will be a more effective control.

Career path to Network Security

Martin McKeay's Network Security Blog: How to get into Network Security
A link to an interesting article at securityfocus talking about the prerequisites for getting into network security. My path was train as an accountant, get lucky and move over to IT before having to do any accounts, spend 5 years in Networking and general IT, then move into IT security. I've found my background in IT to be very useful when having security related conversations with IT staff, it definately helps to understand where they're coming from and also if they might be being "economical" with the truth...
There's another reference to this story over at Joat's blog , which mentions coding as a required skill. I've picked up bits of a couple of languages over the years, and I'd like to learn more, but I've never been sure which language would be best to focus on, with the inevitable result that I've not really learned any of them....

Good example of Social Engineering

There's a article which runs though a good example of social engineering here . The methods used give examples of how easy it is to gain access to information or goods without authorisation. It does require a talent for thinking on your feet though....

US falls for Phishing...

An interesting article over at vnunet.com quoting gartner on the levels of loss in the US from phishing scams. I'm definately suprised that it is as high as $1.2 billion, but if those figures are accurate, I'd hope to see the financial institutions involved moving to authentication schemes which are more resistant to this kind of attack, maybe like the ones I mentioned here

Client Security, It's important!

This one is one of my recurrant rants, so I thought I'd post it while I think about it....
Why do large corporations, spend loads of money securing their perimiter, a fair quantity on their core line of business servers and very little securing corporate desktops...
If someone can compromise a desktop PC, they can get all the rest of the access they need very easily, they can also easily compromise your core servers...
Here's one scenario of many.
1st step - Get local administrator rights on a corporate PC running windows. Easily done by booting off a CD grabbing the SAM file and cracking the password. In most networks I've seen the local admin password is the same on all the PC's
2nd step - find out the IP address or machine name of an admin level persons desktop. shouldn't be too hard if you are in the same building, if you're not something like an HTML e-mail with a web-bug in it would do the trick.....
3rd step - connect to their PC using the local administrator account and install a keylogger.
4th step - grab all the passwords as they type them! if you're feeling fancy, install a remote control program on their workstation then log on to their machine as them and connect to the servers they administer. At that point it would be very hard for mechanisms like IDS to know that you're not the administrator of the system.....
How do you mitigate this?
One way would be to deploy 2-factor authentication for all your admins. If you use RSA tokens or some other form of one-time password, it would cut back on the window of opportunity.
Another option would be to put desktop firewalls on all admin (or potentiallly all) PC's and configure a reasonable ruleset on them which only allows inbound connections from specific subnets, as required to maintain the system.
Another option (only applicable to this particular attack) would be to specify different local administrator passwors for each PC (might be a bit hard to administer though)

Sasser worm Author caught

Over at the BBC they're carrying the story that " Teen 'confesses' to Sasser worm". What worries me most about this, is if this guy turns out to be the author of the Sasser worms and the Netsky virii (which some other newswires are suggesting), he has managed to cause millions of pounds of damage on his own... one teenager.....
Given that, what level of damage could be done by an organised, well funded group of people, looking to maximise the damage done to the Internet...? Not a comforting thought really.

Detecting Rogue machines on client subnets

A little while back, I was giving some thought as to how to mitigate the risk of rogue DHCP servers on internal networks.
The risk, briefly, is that if someone can get their rogue DHCP server to hand out an address faster than the real one, then they can control things like the default gateway and DNS server of client PC's. Once they've set that up they can sniff any and all traffic that goes by and also modify traffic if required.
One of the standard technological controls for stopping people putting rogue devices on a network, static MAC address assignments on the switch ports, isn't likely to be effective here as it would be very onerous to maintain that on client subnets... Likewise other ones like an IDS system aren't likely to be deployed in what is perceived generally as "low risk" segments of the network...
So, an idea which might work (and it may already exist, I'd be interested to hear if it does) would be to have something like NMAP scanning round the subnets on a regular basis looking for new services coming online... all that would be needed is an interface for admins to define what to look for (eg, there should be only ports 137-139 and 445 on this subnet) and an alerting system... Would also help for detecting unauthorised web servers and the like in large corps...

Security threats to open/closed source software

Over at David Cartwright's Home Page there's some comments on a debate about the relative security of open and close source software. It pretty much sums up how I feel about it.
There are potentially going to be security flaws, either malicious or accidental, in any software much more compicated than "Hello World", be it open or close source. My personal opinion is that at least with open source software if it's sufficiently important to you to mitigate that risk you *can* get the source code reviewed. This cannot be the case with closed source software as even if you are given a copy of the code to review (for example with Microsoft through their shared source initiative) you have no guarantee that the code you reviewed is the code that was compiled to create the software you get on the CD.....
Leads me on to another thought actually which is, I wonder if any of the shared source licensees have been able to comile something like Win2003 server from the source they've been given to create a running OS.....?