Wednesday, March 1, 2017

Redefining my state of mind

After a two week pause from the mundane realities of the working world I've discovered that a redefinition of my perceptions is required. I must refocus my mind on the most important things; love, clarity of thought, objectivity, and empathy.

By those things I believe I can find contentment.

Tuesday, October 14, 2014

It's the wild wild west out there suckas! Simple tips to secure a network.

Reading the latest Brien Krebs report, and so many others I've seen emerge lately, it brings to mind that these kinds of attacks don't just happen against the listed industries.  They also go after any organizations that could have any potential information on those industries.  This means lawyers, accountants, or any other outsourced professional services.  What savvy criminal wouldn't want to know the dirty or otherwise secrets of some public company?

What a crazy wonderfully incomprehensible universe we live in.  The thing is, not too many of us have reached that higher plane of existence, and see the Matrix in all its glory for us to unfold and manipulate.
THERE IS A GODDAMN SPOON! Right there. In front of me. It's got marmalade on it.  Mmm tasty marmalade...

I digress.  So in simple terms, there's some easy crap you can do to secure your network to prevent 99% of the targeted attacks seen lately.  Really easy simple rules to follow that prevent your company from being one of those 'low-hanging fruit' so easily targeted by the untalented masses buying the latest exploit kit off the black market.  Of course I'm talking about a Windows network, but I suppose this applies to any network really.
So, here's a few things to bare in mind:

USE A VULNERABILITY AND PATCH MANAGEMENT SOFTWARE.  With vulnerability and patch management software running, it addresses the kinds of vulnerabilities sought after by opportunists chomping at the bit to dismantle the lasted adobe update to see what they can attack on users too lazy to update their software. As seen time and time again, the main source of exposure comes from outdated software on workstations. This update software should be maintained and checked periodically to ensure its operation.

DON'T ALLOW USERS TO OPERATE UNDER LOCAL ADMIN RIGHTS.  Give them the local admin account and password so they can go to town installing whatever application(*from the approved list*) that they want to install.  Keep it separate from their user account, so they get used to switching accounts when they want to do something important.  This saves the casual click to install and view exploit.  Might make them stop, think, then ask their IT if its ok. With vulnerability management software, you'll see if someone installs something they shouldn't, so you can then go slap them with the mighty glove of "I'm watching your every move on this workstation, so behave!"  It's a bit big brother'ish, and likely not necessarily true, but if you put the fear in them, they'll think before clicking or installing.

KEEP YOUR INTERNET FACING SERVERS IN THE GODDAMN DMZ ZONE.  This includes any virtual host you have.  Visualization is great until the fabled VM Escape attack hits, then what else is running on that host hmmmm? The last thing you want to do is poke a hole in your router or firewall to allow even a single port to access your network. Should any server be compromised, it could be pivoted inward by an attacker to gain access to other more important information assets.

SANDBOX YOUR WEB BROWSERS AND OFFICE APPS.  Isolating the web from the workstations is the only way any organization can maintain a high degree of trust from their clients and save themselves from an embarrassing situation where the data ends up in the hands of some third party.  The easiest place to hit any organization from is its endpoints.  Sure outdated software can be a hole, but so can your fully updated Internet Explorer browser that Sally just learned how to break with her new virus code you stumbled onto..  Sally also works for the NSA and might not want to tell anyone about this problem just yet...   O.O  So... yeah, just get yourself an application that will sandbox your internet access.  Also, NEVER turn off User Access Control in Windows, as it essentially disables Internet Explorers built in sandbox.

Also, install EMET if your using Windows.  No comment on that, just read up on it and install it.  All over the freakin' place.

LOGS ARE YOUR FRIEND.  Love the logging, enable it everywhere, ensure it is pertinent information you are getting, and ensure you automatically email yourself those logs.  Make a folder in your email and direct all of your logs there.  CHECK THE LOGS.  Too many companies rely on automation and not the diligence of a human brain to make sense of it and mitigate potential threats.

KEEP INFORMED ON THE SOFTWARE YOU RUN.  That's right.  Read those security bulletins from Microsoft.  Subscribe to info security blogs.  Follow industry leaders on twitter.  RTFM DAMNIT!!! Most importantly apply suggested mitigation strategies.  Network management tools such as group policy allow you some great granular and uniform control of your workstations.  Use them.  Use security templates already written by people smarter than you.  Having a baseline configuration in your environment allows you to easier see when changes happen.

MAKE YOUR USERS FEAR YOU.  What does the IT guy know?  Pretty much everything, and often is seen as the omnipotent master of his domain who sees all, knows all, and grants you access at his whim.  Garner this reputation, foster this.  Fearful users are careful users.  Hammer into them the importance of their online actions. The human element is ALWAYS the easiest way to get information out of a company.  Kevin Mitnick proved this time and time again, and even wrote a book on it.  Informed and cautious users are really your first and last line of defense against the Shisters out to steal.

MEDITATE.  Because people are people, IT can be stressful, and one day you might see past the spoon.

Wednesday, March 7, 2012

VPN fo life!

Today I want to talk to you all about privacy and how you can keep it. With all this new legislation being proposed in government and the like, you might ask yourself, how do can I take matters into my own hands to protect my privacy.

Well, today I'm going to illustrate for you two methods of doing so.

Before I do, I just want to say that I don't advocate the use of the following tools or techniques within an enterprise environment, because that would cause your IT guy a whole lot of headaches. So if you work in an office, do not use these techniques on your computers at work. If you're like me, I can see when this kind of stuff is happening on the network and probably come over and smack you for it.'

So just don't do it on your work computer. This is specifically for your home computer.

Also, I'd like to point out that no technique to conceal yourself is entirely foolproof. Unless you have access to a stolen credit card, there is no way to totally hide yourself if you want to live more or less legitimately under the laws that govern your country. Even then, that's not foolproof either. So, unless you want to become a criminal to conceal your identity, keep that in mind.

Also, I don't advocate the stealing of intellectual property. All people have a right to be paid for what they do. Their labors should have reward. While legitimate means of reasonable access to affordable content is available, there should be no reason not to pay for other peoples stuff.

With all that in mind, these are some ways you can protect yourself a little from nosy people.

First thing I recommend is getting yourself a little program called "Peerblock." This is a handy little free application that basically just blocks known bad computers on the internet from connecting to you. When I say bad, I mean, governments, certain media corporations, and other people who just want to watch what your doing for whatever nefarious purpose. It's whats more commonly known in the IT community as an IP Filter which inspects internet traffic when it reaches your computer.

Once you install it and run it, you'll see what I mean when you go to surf the net. Particularly when you're watching netflix. They have a nice graphical interface which shows who is trying to connect to your computer. I take a little bit of unhealthy enjoyment from seeing those connections being dropped when I periodically check it.

Now the second way of protecting your privacy is to get yourself an account with a VPN service. These are basically people who run servers which allow you to connect and funnel your internet traffic through them. You basically create a tunnel from your computer to their computer which is totally encrypted and unreadable by anyone trying to monitor your internet usage, including your ISP. When you surf through one of these VPN's, well it looks like the websites or whatever traffic your generating is done from the site your connected to. So for example I connect to a vpn server in Seattle, and go to a specific website thats only viewable in the US, all of a sudden it works for me in Canada. This helps you get around pesky censorship laws that your crazy government might be imposing upon you.

There are dangers though when connecting to a VPN service. The first and foremost is that when you connect your computer to another with a vpn connection, you have opened yourself up to whatever is on that network. This also means, that those who are administering the network can view whatever you do on the connection. So, that means, when you are connected to a VPN service for privacy purposes, do not check facebook, do not check your email, and certainly don't do any online banking. Any time you have to type in a username and password while connected to one, you are exposed.

The VPN service you want to look for are ones which are described as being based or having servers in non-compliant areas. Non-compliant areas being, China, Russia, or any other country which is known not to co-operate with international censorship laws. Most of the time this means that those kinds of VPN's won't just give up their usage logs to governments when they are asked to. Also something to consider when connecting to non-compliant regions, you then expose your computer to those countries which are notorious for cyber crime.

There are VPN services based here in Canada which would give you a nice degree of anonymity without sacrificing the security you would lose connecting to a different country. The advantage of local VPN's is that there is a degree of recourse should anything happen.

The other disadvantage of a VPN service is connection speed. Because you are now relying on both your internet speed and the internet speed of the VPN provider, you will generally see slower connections. So you take the hit in download speed for a bit of privacy.

So on that note, I just want to end off with a nice quote I heard recently.

"Those who know know, and let me keep what little privacy I have."

Well, thats all I had to say about that..