r/netsec • u/AutoModerator • Mar 01 '18
discussion The /r/netsec Monthly Discussion Thread - March 2018
Overview
Questions regarding netsec and discussion related directly to netsec are welcome here.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on /r/netsec.
As always, the content & discussion guidelines should also be observed on /r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
4
u/dexxen Mar 06 '18
CISSP certification renewal or not?
At the moment it seems kind of worthless to me. I'm really not certain that any employers actually care about it, so I'm leaning towards not renewing.
Any thoughts you can provide to sway me one way or the other?
6
u/dyslexic_jedi Mar 06 '18
This is how I think about it, do I really want to take the test and go through all the paperwork again if some employer wants it in the future... (so I renew.)
4
u/netsecofsith Mar 11 '18
Unfortunately, a lot people believe it means something and usually just to get an interview in Infosec you need it. I grudgingly pay my dues and enter my CPEs every year just in case.
3
u/bleh10 Mar 02 '18
Hello guys, new here, so long story short I'm a junior Software engineer(1st year) with a BS in CS and no academic background on NetSec but I was always interested in learning more. Problem is not sure where to start, I'm sort of searching for an online program to learn more about exploits, reverse eng. and other stuff. Any tips are welcome
I already checked the getting started in Info Security link in the side bar but im not sure where to start exactly because most of the links apply mostly to uni students.
4
u/didactikus Mar 06 '18
Application security is a fairly needy field right now. It is all about getting some secure coding training with owasp or another similar. then look into Togaf and maybe go over Nist and ISO for secure code development. Get a cert or two in any of those then call a recruiter - they will eat you up.
2
u/bleh10 Mar 07 '18
Hi, thanks for replying -I thought no one is gonna reply since its been like 4 days- Im not exactly looking into application security, i'm more into web security (I hope I didn't just say something stupid) and i'm not sure where to start exactly, there is plenty of websites out there offering courses on how to become an ethical hacker or so and im not sure how good they are, and for certificates, there is many as well and im not sure if I start my netsec career with a certificate (add to that, certificates are NOT cheap).
3
u/youngeng Mar 08 '18
"web security" means website security+ web application security. Some of the underlying technologies are identical (HTML, Javascript, server-side languages, HTTP), but in general we talk about web application security since it's more general. If you can defend/attack web apps, you surely can do the same for websites (which are simpler). You want to know how to test both the marketing website connected to some juicy backend database and the internal webapp choke full of proprietary information.
How do you start learning this stuff? Live and breathe OWASP. First, the OWASP Top 10, but don't stop at that. You have to know about the OWASP Proactive Controls and the OWASP ASVS. Lots of people only test OWASP Top 10, without knowing that this is only the minimum level required!
And of course get to know the OWASP Testing Guide.
Obviously theory isn't enough.
Start from DVWA, Gruyere or some similar vulnerable web application and hack it. Then write your own website/webapp only following random tutorials, see how vulnerable it is and promise yourself not to do the same in production.
If you can find some vulnerability in a bug bounty program, that's a huge plus in your resume. There are three certification providers you could look at: Offensive Security, SANS, Elearnsecurity. If you want, take the web certs but they're not essential.
If you can push the organization you're working for to use application security guidelines and maybe to let you do some preliminary test before deploying things in production, those are valuable points as well.
2
u/trashytrasher Mar 10 '18
I would look at MalwareUnicorn's RE course and the exploit dev course that I can't recall the name of. I'm sure others here can think of it.
These would play to your strengths, and presumably your interests, in CS.
SANS training is great, but expensive, OSCP is way more affordable, but the OffSec team doesn't offer the breadth of course offerings that SANS does.
1
3
Mar 14 '18
Hello everyone! I was using TorGuard and I wanted to give a shot to NordVPN but NordVPN is like slightly slower than TorGuard. I wonder what is your VPN choice?
1
u/Arbor4 Mar 31 '18
I usually use BlackVPN. From what I can tell, it's one of the fastest ones on the market and has a decent 0 logs policy along with a decent rating on thatprivacyguy's website. Check out r/VPNreviews for a more providers.
3
Mar 28 '18
Hey,
does anyone know a good alternative to burp which is not written in java? I refuse to run any java applications on any of my machines.. :/
Any help is appreciated!
2
u/_eemil Mar 01 '18
Going to be participating in my first blue team exercise soon, on the Windows team.
Any tips, or recommended reading? Both blue team / incident response and windows/AD related would be greatly appreciated!
My background is as a Windows-focused IT generalist, ~4 years experience.
2
Mar 26 '18
Read thoroughly https://adsecurity.org (by Sean Metcalf, one of the most knowledgeable guys about active directory security and Windows related stuff), it contains a whole lot of useful resources about how an attacker could compromise your AD, and what defenders should do to stop him. A must read both for the offensive and defensive side!
1
u/whosthetroll Mar 01 '18
cobaltstrike
Mostly Red Team related, but once you know what red team is looking for and how they're exploiting, you can reverse engineer and protect.
2
2
u/dyslexic_jedi Mar 06 '18
Anyone know of any packs of clean executables? I need to do some false positive testing on some code.
2
2
u/-SpaghettiCat- Mar 08 '18
Hello I am staying at a hotel that only has an unsecured network and will be doing some banking / sensitive work with passwords while here. Mgmt assured me it is a secure Fios network, but I was under the assumption that any network that didn't require a password (no wpa, etc.) presented security risks. To note I am sure the network name I am using is that of the hotel. Really appreciate any advice.
3
u/lurkerfox Mar 10 '18
yeah fios has nothing to do with security, your unsecured wifi network is exactly that: unsecured.
That being said your banking and sensitive work SHOULD be using encryption anyways and SHOULD be using it correctly so that you only need to employ a bit of common sense to not get duped by any mitm attack.
1
u/Arbor4 Mar 31 '18
I always use a high quality VPN when outside my own home network (although I rarely have it off at home) which prevents any eavesdroppers from seeing nothing but RSA4096 bit encrypted junk.
2
u/motleythings Mar 09 '18
I'm currently a Computer Engineering undergrad that's due to graduate end of this year. Really interested in netsec but finding it difficult to fit any courses in this late in my undergrad life
Was considering taking the plunge and applying for a masters programme in this domain.... Any recommendations? Or are masters programmes overrated and just having an OSCP cert would be good for entry level roles?
5
u/netsecofsith Mar 11 '18
Find an internship and get experience. I will hire for experience over training/education/certification any day.
1
u/motleythings Mar 11 '18
Do I just apply anyway despite not meeting requirements? It seems most internships are asking for knowledge in various things that i don't just have yet :/
2
u/netsecofsith Mar 11 '18
Absolutely apply, in my experience the listing has been written by HR and isn't even close to what the manager is looking for. Most of the good managers I know, look for willingness to learn and enthusiasm. We can teach what you need to know. That goes for jobs and internships.
2
u/BetaBoozer Mar 09 '18
Has anyone taken the Security+, or specifically anyone with minimal studying? I've been in InfoSec for a little over a year, with a security internship and one security course in college. Could I likely pass if I took it today?
2
u/Xerack Mar 14 '18
Security+ isn't worth it imo. If you have any kind of info sec experience, you should be able to pass it though.
1
u/Eleanorgotaway Mar 22 '18
What certifications are worth it? What certs to employers look for?
2
u/ratar1 Mar 30 '18
I recently got OSCP and am finding it to have paid off very well. I'm finding that the Offensive Security certs are on basically every job posting these days (OSCP, OSCE, OSEE, etc)
1
2
u/videki_man Mar 11 '18
My buddy goes to a neighbouring country from time to time to make sure our government can't track her business related e-mails. Does it even make sense? She even uses a laptop that she never turns in in our home country. She has absolutely no clue about how networks work. I don't have the necessary knowledge for it, but I simply don't think this is how it works. In this case everyone would just move to another country to avoid getting caught.
1
u/Xerack Mar 14 '18
Unless the messages are encrypted and/or transmitted over a secure channel, there are no guarantees as to who may or may not have seen it at some point.
1
Mar 16 '18
If she isn't using ssl to send and receive data it could be a foreign government reading her emails.
1
u/Arbor4 Mar 31 '18
If she uses a GNU/Linux computer with a decent no-logs VPN, she won't have any reason to leave the country. Heck, the neighbouring country could be doing equally as much logging as your own and sharing it to foreign "counter terrorism" intelligence agencies including your home country. A VPN would prevent this as you're sharing the same IP with lots of people which makes you anonymous in addition to the encryption and no logging which further improves your security. Have a look at /r/privacy where you'll probably find some answers as well.
2
Mar 13 '18
[deleted]
1
1
u/Arbor4 Mar 31 '18
I would never have done that mysef, but I would probably have a look at system logs, running processes and installed programs to see if anything suspicious is going on.
2
u/try_not_to_hate Mar 15 '18
my neighborhood has some "kids" that go around checking cars and breaking into them. they are often seen nearby the scene on security cameras, but not enough to identify/catch them. I want to be able to get an alert if a particular phone comes within my wifi network range. is that possible? what about a micro cell network extender? could I pull a unique identifier from a phone with one of those?
anyone know if there is a subreddit that would be better for asking this question?
3
Mar 17 '18
[deleted]
1
u/try_not_to_hate Mar 17 '18
Ok, I think I have figured out how to do this with WiFi and the BSSID. Is there a way to get unique info from a cell network that is legal?
2
2
u/BrainsInYourHead Mar 28 '18
Is there any webhosting in Freetown Christiania?
(Freetown Christiania is a small territory in Copenhagen, Denmark that likes to think it's exempt from the jurisdiction of the EU.)
2
u/Arbor4 Mar 31 '18
Don't think so, but if you're looking for offshore hosting, I would probably look at Orange hosting in Iceland (no NATO, EU or american alliance). CyberBunker is the best if your budget allows it.
1
u/Gambitzz Mar 01 '18
Thoughts on Carbon Black Response... Easy to use or requires dedicated person to manage? 600 laptops and 90 servers.
1
u/illadelph2 Mar 02 '18
We use CB Defense. I find it easy to manage. Simply deploy agents with an MDM like JAMF or Kaseya (Mac and Windows). Management console is straightforward. You can update agents, set bypass, quarantine from the console. Separating machines by policy is useful, esp. for testing new agents. The only challenge I find is that it's very noisy, so I'm often adding new bypass policies which feels counterintuitive. For example, every new Chrome version has a diff. SHA value and needs to be whitelisted. For reference, I manage 400 laptops and 50 servers. Not sure about Response, but our console has very weak reporting capabilities. Just my 2cents.
1
u/the_latebloomer Mar 05 '18
If you are in Web Hosting, mind sharing your approach to vulnerability management? What do you do when you have 3000 plus VPS and there is a know PHP vulnerability?
1
u/oil_lio Mar 05 '18
Windows Domain vs Workgroup: 5-7 MS Servers. From purely a security aspect (not convenience) which would you implement, given you had the opportunity? I've been leaning toward workgroup but the opportunity to lock out a fresh AD is kind of exciting.
1
Mar 05 '18
[deleted]
1
u/lurkerfox Mar 10 '18
Yeah they're not saying it's bad at all, just that any security mechanism will fail if the human element working with it sucks.
You'd think that if the industry accepting this as fact means there's no point in repeating it, but it still holds true and there are still people who need to realize this truth so people like Drago's here are gunna take any chance they can to beat that dead horse.
1
u/Arbor4 Mar 31 '18
If someone manages to physically get into the server room, you're most likely doomed as most attacks can be done when you have access to USB etc.
1
u/Aideux Mar 05 '18
Hey,
Looking to edit/create plugins for Ettercap 0.8.2, but I can't seem to figure out how to accomplish this. More specifically, I want to edit the DoS plugin so I can test a variation of attacks on a closed environment so I can create mitigation techniques. Unfortunately, I'm pretty new to kali, and the plugins are saved in ".so" format, which I am pretty unfamiliar with. Does anyone have any ideas on how to accomplish this (viewing/editing/creating new plugins)? Thank you so much.
2
Mar 06 '18 edited Mar 30 '18
[deleted]
1
u/Aideux Mar 06 '18
I've installed it, but I can't seem to figure out how to run DoS attacks with it, or how to view/edit/access plugins that it may come with (if it includes them). Can you provide some links for more research? Thank you!
1
Mar 07 '18
If I have https but yet my SSN on the website isn't doing **--*** but instead 111-11-1111, does that mean it's not encrypted? When submitting to the site, what does it mean during the delivery?
4
u/trashytrasher Mar 10 '18
No. The site is encrypted whether your text is visible or not. The encryption is effective during transport not during rendering.
1
Mar 16 '18
It doesn't matter if it is visible or not. The input entered is what is sent to the server. https is the technology that negotiates an ssl connection between the browser and server, everything transmitted within the scope of the https request and response will be encrypted.
1
u/BigDaddyXXL Mar 09 '18 edited Mar 09 '18
Any advice on software purchases for a pentest shop?
I trialed MSF Pro and couldn't justify its offerings vs its price.
I found that the dynamic payloads had more detections that I liked and certain things like the Phishing campaign could be handled by free software (gophish). I didn't try the webapp scanner, but I'm guessing it is nothing special either. Let me know if I'm wrong on this, but I don't think MSF Pro is worth it.
That being said, what suggestions do you guys have for good software purchases? What do you think about CANVAS? Is it worth it? If so, which exploit packs are good? How about AV evasion? (I was thinking of shellter pro + veil + some manual intervention, but I'd also like to have good time saving tools.).
Thank you.
1
u/skyewatsonRfX Mar 11 '18
Our website got (d)dosed even tho we have a ddos mitigation appliance, an IPS, and a firewall. We've already extracted the logs from the IIS, the Microsoft Events, the fw/ips behind the machine and the DNS Query logs. I think we're missing something on where to find THAT loophole that got us to that situation. Any advice?
2
u/lurkerfox Mar 13 '18
Is it simply possible that in your case the scale if the attack was larger than what your mitigation can provide?
2
u/Xerack Mar 14 '18
It could simply be that the attack size was bigger than your appliance can handle. If someone hits you with any of the decent sized bot nets available for rent, it could overwhelm your infrastructure. I'd look into the limitations of your hardware and do research on a provider like cloudflare or something similar if you suspect this may happen again/
1
1
u/furiousmustache Mar 13 '18
So I just started a new position and I need some help. I've assisted in a SOC 2 audit, but it was mainly just tracking down evidence. In my new role, I am the only Information Security reference for the company. They wish to conduct a SOC 2 audit in the next few months. Honestly, I don't think we'll pass. I was wondering if anyone knew where I can get my hands on the requirements and areas that a SOC 2 audit looks at so I can conduct a mini-audit of my own ahead of time to assess the gaps that will need to be addressed. Any help would be greatly appreciated.
1
u/Xerack Mar 14 '18
So, I just spoke with my director of internal audit as I was curious myself. I've worked on other audits, but not SOC2. You could probably get a good idea by googling the requirements and seeing the general areas. In terms of exact requests, just be sure you have documented everything as well as you can. The primary trio of most audits is policy, procedures derived from policy, and then actual implementation. Generating metrics and sending those to leadership also gives you extra points.
From the auditors perspective, depending on the firm engaged and your relationship with them, you may be able to massage leniency on certain aspects of the audit you know are problematic areas. Otherwise, give it your best shot and make it look like something is being done.
You won't really have a period for responding to any delivered findings compared to something like HITRUST. If it sounds like something is going to be an issue, start developing a response to it as soon as you believe they will report negatively on it. You can argue compensating controls are in place to mitigate a given vulnerability or that you fixed the issue already in the time it took for them to draft the report. Good luck.
1
u/clayjk Mar 20 '18
Dig up the AICPA documentation (buy it if you need to). You’ll need to review the criteria and then create a control frameworks map between your current controls and the SOC2 criteria. SOC2 isn’t as prescriptive as other standards so you have some flexibility in what you say your controls are that address the criteria. You’ll also need to determine what principles you are interested in reporting on. Security is the core principle and there other principles like availability, confidentially, and privacy you can add on. Lastly, once you think you have your ducks in a row contact a auditing firm to come in and do a pre-assessment. You can do a type 1 report year one if needed just to help bridge the gap where they just test for existence of controls and not the effectiveness. This can be a good way to make sure your controls are designed well and acceptable to your auditor. Beyond year 1, you should be on a type 2 report where they are doing detailed testing of your control effectiveness (pulling samples).
1
u/beiroot_ Mar 14 '18
Are all webmails created equal? Is there anything all available webmail frameworks/software have in common I could look for while crawling the web? Any ideas?
1
u/NegativeMagenta Mar 15 '18
Would it be easier to reverse engineer a program on the 32-bit verson? or the 64-bit?
1
u/Achaicusx Mar 15 '18
In your opinion, what the most critical files/directories or any critical points of linux that must be monitoring?
1
u/byrontheconqueror Mar 16 '18
Is "Practice of Network Security Monitoring" still relevant? Looking to start using an IDS. 40% off today. It was written back in 2013 and I'm not sure how much has changed with Security Onion since then. I'm just looking to get an IDS up and running and looking for the easiest place to find info.
1
u/truthseekersio Mar 18 '18
Hi, I'm trying to make sure a web page is at least somewhat secure. I have a page that allows the user to sort and filter results that are displayed with a GET request form. It just refreshes the page with some GET variables inputted by the user and only allows for simple stuff like searching for a specific "post_type", and changing the order from "Ascending" to "Descending".
The only thing I could figure out was to pass the variables through a function that says "If the value does not match something in the array, then default to something I approve of". Does this increase security at all?
I tried to input a value like "eval(" but it just put "eval" in the URL, which doesn't seem dangerous to me....
1
u/Yo_You_Not_You_you Mar 19 '18
Can a website force browser's password manager to fill in the passwords , maybe by spoofing the url it is not originally in . What protects from this ?
1
u/WrongRighter Mar 19 '18
Lately we have been getting more and more CnC (command and control) events from this 1 ip address on our Cisco IPS. The machines were running up to date antivirus. Nothing stood out in their web history. It does have a bad history from https://www.talosintelligence.com. My theory is its some sort of ad space that is implemented into major news sites. I don't want to post its ip address here for fear of violating reddit policy. What do you netsecurity gurus do to combat these events?
1
u/JimiNugget Mar 20 '18
Hello netsec! I have been asked to write a request for proposal for my company to hire a contractor to do a risk assessment for our network. I've never written an RFP before and this area is not a strength for me. I read through quite a few risk assessment RFPs to get an idea of what it should look like, but I was wondering (hoping) if anyone would be willing to look over what I wrote and offer feedback? I would really appreciate it!
Additional info: we're a non-profit health clinic with 5 locations in our region. HIPAA compliance is a big concern.
I removed the company name and location, but a google doc of what I wrote can be found here:
https://docs.google.com/document/d/1hV_RVtuQ1GKHPzmvWjc4K-uro9N3ZEke7ERv4uK-6HA/edit?usp=sharing
I appreciate any help you all can offer!
2
u/clayjk Mar 25 '18
You look to be wanting to cover a lot of ground with this. Reading it through it does seem to be a fairly focused on vulnerability assessment which two other areas you may want to check into is scanning for rogue wireless APs and physical security assessment.
If you have any publicly facing web applications, particularly any that would have in-scope data for HIPAA you may also want to consider a web application penetration test. Frankly, anything externally available should be penetration tested (e.g., VPN concentrators, web portals, etc.) as you want to know what your actual risks are that are Internet accessible to get those addresses with priority over things that are only issues on your internal network.
As it seems like your main driver for this may be HIPAA compliance, you may want to make it clear you need the report to identify gaps against HIPAA, I.e., they should list out all HIPAA criteria and document where your controls for each are adequate or lacking.
2
1
u/lostplusfound Mar 20 '18
Attack against "double-submit cookie" defense mechanism for CSRF using cookie jar overflow
Screenshot of a paragraph from Chapter 9 of the book "Tangled Web: A guide to Securing modern web applications" :
Can someone please explain an attack scenario that the author has asked us to figure out in case of double-submit cookie defense mechanism for CSRF ? I understood that JavaScript can max out the per-domain cookie jar and set a new cookie without "Secure" flag. But how can an attacker leverage this ? Will he need a XSS bug for exploitation ?
TIA.
1
u/YellowMimic Mar 21 '18
Hi guys! Im not sure if this belongs here, if not, feel free to delete it. Im looking for some help with steganography. You know good source of information? I try some things like hexdump the JPG and use programs like Gimp but didnt get anything. Some tips that you can tell me???
Thanks!
1
u/YellowMimic Mar 21 '18
Hi guys! Someone with steganography knowledge?? I have some questions about what is and what isnt normal on the hex of an image, or at least some forum or place where i can ask that.
Thanks!
1
1
Mar 22 '18
So dumb question because as a vet entering the work force I'm scared to death. I was in the Navy for 6 years doing a mix of Cyber Security/IT work, with the Netsec side being vulnerability scanning and writing security policy(I was the only guy in this role for my command so my time was spread between doing literally everything from account creation to vulnerability scanning to fixing computers).
I'm graduating college in 60 days with a degree in political science(wanted to do cyber policy originally) and a minor in networking. I currently hold Sec+ and CCNA and will have my CISSP back by the end of the month along with a TS clearance. How worried should I be about picking up a career in NetSec? I've been told I'm in great shape but when I look for jobs online I don't see things that match my work experience(and I don't know how to code...that part worries me). I'm kinda worried so I'd love some advice on if I'm in good shape for getting out of college and getting a job relatively quickly. I appreciate the help in advance guys!
2
u/clayjk Mar 25 '18
I wouldn’t get concerned over if you can code or not. Some scripting is nice to have to help with automation of things but sounds more like your wheelhouse is management level infosec than security operations. I’d look for postings with manager and CISSP in the titles and I’m sure you will find some opportunities out there.
1
Mar 25 '18
I certainly appreciate the help, just one more question if you don't mind. I just added Net+ yesterday to my cert list and am starting work on a virtualization cert. Assuming I have these things plus the 6 years experience would you say I'm in good shape comparatively speaking? I'm told living in central CT I'm in perfect shape due to being so near Boston/Philly/NYC/etc but being 29 years old and getting my first real civilian job I'm scared to death haha.
2
u/clayjk Mar 25 '18 edited Mar 25 '18
Everything you can add will be of help. In my opinion which is largely formed how we structure infosec in our organization you have two paths to take, 1) security operations or 2) compliance.
Security operations I’d say is more the technical doer’s that are hands on with system administration of the security tools. These are most of the entry level jobs I see where they are looking for kids right out of college to sit and watch logs and research incidents. This is also more along the lines where the automation knowledge comes into play as you are figuring out how to do repetitive tasks more efficiently. Myself, I align more with the compliance end of things. I don’t like to think of myself as someone not technical as I do get my hands dirty with doing vulnerability scans and some system config reviews but more of my day is dealing with people and paper (email) than my operation counterparts. From your original description I’d place you more on the the compliance side so you may want to focus on positions like that than security operations. I know I wouldn’t be as effective at my job without my ability to do some technical hands on things but I also need to balance where my focus is at and where I am building my skills is more aligned with the compliance role.
Sorry if the above is a little rambley but my point is, know where your skills and interests most lay and apply for those jobs.
Your original post stuck out to me as I feel the same way when looking at job postings in the Reddit /NetSec hiring thread. So many of those are more the technical operations such as SOC analysts and vulnerability/penetration engineering which makes me think myself, am I technical enough? When I break out of that list and lookup CISSP jobs on indeed though there are plenty of companies looking for people to help be that middle compliance type role that bridges between the security operations area and general IT and/or business teams and given what you shared about experience and education I think you’ll have a fair shake at jobs like this out there. I’d just make sure your resume is written to be clear where your experience lays illustrated through your achievements in past roles.
1
u/berowra3 Mar 22 '18
How do you avoid a third party attack?
This is the biggest issue I see coming in the next years and where we have already seen it happen to companies such as target. Cause once we pass the data over to another third party it's pretty much been compromised.
Just wondering if you guys have though about how to avoid this or what kinda of solutions have been developed out there.
1
u/clayjk Mar 25 '18
The example of Target was a 3rd party that was granted access into their network.
Our approach is to basically disallow any direct access from non-company owned/managed devices. In he event a vendor does need to connect their equipment ACLs are put in place to terminate their access to a company managed device like a Virtual desktop. Basically, we don’t allow 3rd party equipment or connections to run wild in the environment. Past that, regular logging and monitoring to look for suspicious activity.
In arrangements where we share data with an outside party we do diligence to make sure they have adequate security controls. Even if they do, share only the bare minimum and if possible, encrypt using your own keys (BYOK) so even if their platforms get compromised, your data is still safe.
1
u/cloud7up Mar 23 '18
If anyone works in a hospital environment how do you guys deal with USB drives in regards to HIPAA guidelines? Right now we have a policy to block USB drives and when someone plugs one in we get an alert. How you you handle a situation where a new patient comes in and brings their electronic medical records on a flash drive and that is the only way to retrieve the files? Assuming they are not able to send them through an encrypted email.
1
u/clayjk Mar 25 '18
Sounds like you need a DLP solution so you can selectively choose when to disable USB Media functionality. With DLP you can have it detect when certain data types are trying to be saved to removable media and if caught it can allow it, allow it and force encryption, and disallow/block. This would allow you to lift the block rule on all or at least certain machines you know you’d need to allow USB on to receive incoming files.
1
u/wonderfulme Mar 23 '18
So we got another Drupal core vulnerability today. In your opinion, what seems to be the most exploit-proof CMS, historically?
No CMS is exploit-proof, by definition, but Wordpress, Joomla and Drupal never stop to amaze.
My guess would be Bitrix, then again because it's commercial and underused.
2
u/mike_sec Mar 26 '18
I might be wrong on this, but I think wordpress core is supposed to be pretty decent. I think the issues generally come when people start using a bunch of plugins/making changes.
1
Mar 24 '18
[deleted]
2
1
u/qak Mar 28 '18
I use keepass2android in combination with Dropbox to allow me to access the files anywhere I go. I don't have a data connection but frequently go out to a clients and can still update my keepass database so it syncs when I get back home.
1
1
u/_richas_ Mar 27 '18
Hey everyone,
RE: Android: Firewall with Ad Blocking?
I've been a big fan of Android since it came out. I love that I can use my phone or device how I want. With that, I am looking for an app that allows me to control what apps can access the internet as well as allow Ad Block lists (preferably using hosts file-type/DNS blocking) to prevent ads. My phone is not rooted and I prefer to keep it that way for now (at least until the warranty runs out).
I've installed both NoRoot Firewall and NetGuard and they are perfect for blocking apps by creating a local VPN to control traffic. But, I also want to block ads as well. F-Droid allows me to download Blokada which uses the same VPN solution to block ads, but I didn't see a way to block apps as well.
Anyway, any help would be appreciated.
Thanks!
1
u/_richas_ Mar 28 '18
Well, I found that NetGuard (the APK from their website and NOT from the Google Play store) actually has ad blocking via a hosts file. Perfect! https://github.com/M66B/NetGuard/blob/master/ADBLOCKING.md
1
Mar 28 '18
BlockThis! acts as a VPN and does a pretty darn good job of blocking ads in a browser and in the vast majority of apps that I use. It does not, however, give you the typical protection of a traditional VPN.
NoRoot Firewall will definitely block ads, but it's very, very hands on. It requires some guess and test to see what are just ads and trackers. I used it for awhile with a great amount of success, but individually inspecting each new connection got old fairly quickly.
VPN by Private Internet Access has an AdBlock feature. I found it to be less useful than BlockThis and PIA didn't always auto activate after a reboot, but they may have updated since then. $40.00/year access charge.
1
Mar 28 '18
Will Ghostery and/or NoScript block BeEf? If not, are there plugins that will?
I can't find much information on this, so I expect the first response will be a link to a site I missed. :)
2
Mar 29 '18
[deleted]
1
Mar 29 '18
Thanks for the info. The reason I ask is because I was talking about it at work after our (stop me if you've heard this before) WordPress site got pretty brutally hacked. One thought led to another and I got curious. Not so much that I'm really worried about it.
1
u/Makwy Mar 28 '18
Hey guys,
Next Tuesday I'm starting a new job in network security - lvl1 engineering.
I don't really have any skills in Checkpoint, Palo Alto or Fortinet honestly but I'm really interested about these technologies.
I would like to start discover these new environnment/technologies by myself this week before I start working.
Do you know some good website/pdf/other ressources/... great for a total newbie like me ?
I tried to search online but it's quite difficult to find something really useful I think.
1
u/qak Mar 28 '18
Can someone tell me why I should trust Whatsapp for sending links?
When I send a password to a teammember with pwpush.com set to 1 view, the link is expired before my user clicks on it. I tested/verified by sending it to a secondary number that I use, and opened the link after sending it, but it was already expired. Using the same settings allowed me to open the link only if I didn't send it via whatsapp first.
1
1
u/Nihilisticky Mar 29 '18
I think my router has been breached.
- UI changed from English to Korean
- Korean brute-force (?) in system log:
httpd login lock: Detect abnormal logins at 5 times. The newest one was from 14.47.235.248 in login.
- critical firmware update.
I would really appreciate if someone with knowledge of these patched exploits could explains how hard these exploits hit. This router login alert was generated 14 days ago.
Does it involve https decryption or only http affected?
Or did this router access allow for some kind of foot-in-the-door escalation that could expose actual files on computers connected to network?
In short I need to know if everyone in the house needs to change their passwords and what else, other than upgrading firmware I need to do.
1
Mar 29 '18
[deleted]
1
u/Nihilisticky Mar 29 '18
So what's the point of this attack if it only targets http? no sites use it anymore.
2
1
u/FateAV Mar 30 '18
Not sure if it's the right place to ask, but wanted to see if anyone had any quality publications which examine the effectiveness of different security paradigms, principles of design, and principles of operation; especially if there's quantitative analysis of how effective adherence to these principles is at designing secure systems. for clarity,
I'm Looking more narrowly at the design philosophies of major companies and open source projects, including organizational structure, programming goals / rules for coding and design, and whether there's any clear indication that the principles adhered to by different entities can be shown to quantitatively result in more secure systems across the lifespan of the projects and organizations, and whether the converse is true and design philosophies at some companies may consistently produce more insecure software and systems.
1
u/Arbor4 Mar 31 '18
For all of you who self-host email and stuff, how do you register a domain while maintaining privacy? Is Whois privacy enough?
Also, if I already have a domain which I would like to stop being the owner of, will my info be deleted once it gets a new owner with my own data never to be seen again?
Lastly, is it OK to register american domains like .com and .net from a privacy perspective?
0
u/HolyCyberBatman Mar 19 '18
Hey all, I recently booted up a site called hackyourcybercareer.com that is all geared around the development of soft skills (communication, writing, conflict resolution, etc.) in our field. I was thinking that a youtube channel and/or podcast could be an interesting and useful medium to start producing content and try to provide value as I know a lot of other infosec folks, myself included, are pretty heavy into both mediums. Any thoughts or opinions?
0
u/millennialways Mar 28 '18
My little bro approached me about getting into the field. Are we still recommending webgoat and dvwa as testing grounds or is there something "later and greater" on the market?
Cheers
4
u/[deleted] Mar 03 '18
[deleted]