maravis.com Exploring Information Security

Monday, February 6, 2012

  • Email This Page  Print This Page

    Posts Archive

    This page contains links to all the posts on this site. If you are looking for tutorials and articles, they are in the articles and tutorials section.

DigiNotar and SSL certificate security

Published: September 5, 2011

DigiNotar breach and its impact on SSL security


Have you fallen for the Microsoft support phone scam?

Published: August 22, 2011

Did you get fooled by scam artists purporting to be Microsoft support personnel? If you did, this is what you need to do right away.


Why Chain-of-Trust is important when applying software updates

Published: August 15, 2011

The reason Chain-of-Trust is important for software vendors when providing updates and patches.


Is your Anti-Virus program working properly?

Published: July 14, 2011

Test your anti-virus software with the EICAR test file and see if it is doing its job properly.


Check if your account has been compromised

Published: June 18, 2011

Check if your account has been compromised in the latest hack by Lulzsec.


Most common iPhone passcodes

Published: June 15, 2011

Most common iPhone and iPad passcodes. The case of the usual suspects.


Most hacked environment – Interesting survey results

Published: June 13, 2011

Interesting results form the Anti-Phishing Working Group survey shows that LAMP is the most hacked environment.


Rash of hacks across the world

Published: June 12, 2011

What's up with the rash of attacks against some of the biggest names on the internet?


The recent Sony hacks and their causes

Published: June 3, 2011

The causes of the Sony hacks and what to do to prevent these attacks.


Determine your PCI validation level

Published: April 12, 2011

Answer the questions on this web page to find out your PCI validation level.


More on the RSA SecurID breach

Published: April 7, 2011

More information on how the RSA breach started and spread within one of the biggest security companies in the world.


Minimizing the impact of the RSA SecurID breach

Published: March 18, 2011

Steps you can take to minimize the impact of RSA's security breach involving SecurID


The case for storing passwords in unreadable form

Published: March 11, 2011

Why passwords should never be stored in clear text.


When idiots attempt to attack websites

Published: February 21, 2011

Handling attacks on your website and managing risk.


iOS device encryption may not protect as much as you expect

Published: February 11, 2011

Your iOS device (iPhone/iPad) encryption may not be as effective at protecting sensitive data as you think.


Clarification on using MD5 and its impact on PCI DSS compliance

Published: January 31, 2011

MD5 hashing is allowed by PCI DSS under certain circumstances.


Misconceptions on PCI DSS applicability

Published: January 18, 2011

People still have misconceptions about whether or not PCI DSS applies to them.


Deleting Flash cookies made easier

Published: January 14, 2011

Deleting Flash cookies will soon be an option when deleting browser history in FireFox and Chrome.


Safer web browsing with HTTPS

Published: November 7, 2010

Browsing the web safely by forcing the use of HTTPS for all (or most) traffic.


Clarification on cardholder data and protections

Published: November 3, 2010

PCI DSS v2.0 clarifies what constitutes cardholder data and how they need to be protected.


Chain of trust for installation & update files

Published: October 24, 2010

Understanding and meeting the 'chain of trust' PA DSS requirement for installation files and updates.


Siemens’ password advice for Stuxnet victims

Published: September 30, 2010

Siemens' advice on changing passwords for victims of the Stuxnet worm.


Data encryption best practices for PCI

Published: September 22, 2010

Guidance from Visa on encryption algorithms and key strengths for protecting sensitive cardholder data.


Version 2 of PCI and PA DSS coming Oct 28, 2010

Published: September 20, 2010

New versions of PCI and PA DSS being released Oct 28, 2010. Download a summary of changes.


Insider attacks – No one is safe

Published: September 16, 2010

The risk of insider attacks and the importance of properly auditing all users.


CitiBank’s iPhone app stores account info

Published: August 27, 2010

CitiBank's iPhone app stores account info


Storing PAN with other cardholder data

Published: July 27, 2010

Clarification on whether cardholder name, expiration date, etc. need to be rendered unreadable if stored in conjunction with the PAN (Primary Account Number)


iTunes user accounts hacked

Published: July 5, 2010

Apple iTunes user accounts were hacked over the July 4th holidays and unauthorized purchases made.


Does PA-DSS apply to you?

Published: June 15, 2010

A few tips on when PA-DSS applies and when it does not apply to a payment application.


Why I prefer Microsoft Security Essentials

Published: June 8, 2010

One more reason I prefer Microsoft Security Essentials over others for anti-virus/anti-malware solution.


Secure web search with Google

Published: May 26, 2010

Overview of Google's new secure web search; what it does and what it does not do.


Lessons from the BP oil leak

Published: May 25, 2010

The BP oil leak and what organizations can learn from this disaster.


GMail geolocation to alert about account hacks

Published: March 24, 2010

GMail introduces geolocation to alert against account hacks.


Another Twitter hack

Published: March 24, 2010

An unemployed Frenchman has hacked into Obama's Twitter account.


Wyndham hotels hacked again

Published: March 3, 2010

Wyndham hotels hacked and card data stolen..again..


Malware in Firefox add-ons

Published: February 9, 2010

Malware found in Firefox add-ons in the official repository.


More problems for Twitter

Published: February 3, 2010

Twitter authentication credentials compromised, leading Twitter to push password resets for some users.


France wants to do away with passwords

Published: February 3, 2010

France proposes to do away with passwords to keep the internet secure.


Poor online password practices

Published: January 22, 2010

Lessons on password strength and password security from the RockYou breach.


Heartland settles for $60 Million

Published: January 13, 2010

Heartland Payment Systems to pay Visa $60 million in damages related to the breach in 2008.


Twitter DNS attack

Published: January 5, 2010

More information on how the Twitter DNS redirection happened.


Search engine results and security

Published: December 9, 2009

A look at search engine results and how they can be manipulated to compromise your security.


Massive debit-card fraud in BC

Published: November 20, 2009

Massive fraud hits debit-card users in British Columbia, Canada


Insider threat: T-Mobile staff sold customer data

Published: November 17, 2009

T-Mobile employees reportedly sold customer data to brokers who in turn sold the data to competing phone firms.


MD5, PCI-DSS and Security

Published: November 15, 2009

Clarification on the use of MD5 hashing algorithm, and how it impacts PCI compliance and security.


Misuse of session tokens by programmers

Published: November 12, 2009

How programmers promote session hijacking vulnerabilities by misusing session-ids


Files and documents as confetti

Published: November 9, 2009

Workers toss files, documents during Yankee victory parade.


NASA IT security vulnerability report

Published: October 18, 2009

Some details from a GAO report that says NASA IT security is inadequate


Using a LiveCD/USB for safe online banking

Published: October 14, 2009

Pros and cons of using a Linux LiveCD/USB to ensure security for online banking.


Update on stolen webmail accounts

Published: October 6, 2009

Update on the Hotmail account compromise that revealed an interesting fact about passwords


Phishing attack compromises Hotmail accounts

Published: October 5, 2009

Microsoft Hotmail accounts have been compromised by a phishing attack.


Logo for PCI Compliance?

Published: September 25, 2009

Opinion on the calls for a PCI compliance logo.


PCI Compliance does not equal security

Published: September 24, 2009

Why being PCI compliant does not mean you are secure.


Using device fingerprints for security

Published: September 20, 2009

A look at device fingerprinting, its strengths and weaknesses and uses in security


Tapping Skype VoIP calls

Published: September 7, 2009

A program that intercepts Skype VoIP calls is finally here. A trojan program intercepts Skype calls, records them as mp3 files and uploads them to pre-defined locations.


A look at Spyglass Software Surveyor Enterprise

Published: August 28, 2009

An overview of Spyglass Software's Surveyor Enterprise, a tool that can help you identify sensitive data within a network.


Data security in development and testing

Published: August 25, 2009

A quick look at a report on data security in development and testing from the Ponemon Institute


Stealing Credit Card Numbers

Published: August 17, 2009

Man arrested for stealing 130 Million credit card numbers using SQL Injection attack.


DEFCON17

Published: August 3, 2009

Attended DEFCON17 in Las Vegas


OWASP Security Summit Update

Published: July 27, 2009

Photos from the OWASP Security Summit at Stanford University.


Speaking at OWASP Security Summit

Published: July 17, 2009

Siva Ram is speaking at the OWASP Application Security Summit on security of web application sessions.


Twitter breach

Published: July 17, 2009

Twitter breach and its lessons


Risk from shortened URLs

Published: July 7, 2009

A look at why shortened URLs can cause problems and what you can do about it.


Wireless keylogger – Keykeriki

Published: June 17, 2009

A keylogger for wireless keyboards has been developed. This will have an impact on privacy and possibly compliance.


Problems with identifying breaches

Published: June 3, 2009

Some of the reasons that data breaches are not identified as soon as they happen.


Social networks and (in)security

Published: May 21, 2009

Social networking sites such as Facebook and LinkedIn can be more effectively used to launch attacks against organizations.


Domino’s gives away pizzas

Published: April 2, 2009

Domino's gave away 11000 free pizzas because a customer who ordered online put in the word "bailout" as a coupon code.


Cyber spying network unearthed

Published: March 28, 2009

A major cyber-spying operation has been unearthed involving about 1295 computers belonging to government agencies, embassies and others in 103 countries.


BBC botnet controversy

Published: March 15, 2009

A lot of people are outraged at the BBC using a botnet to show how easy it is to takeover computers and launch attacks. Are they justified?


Caught within the PCI-DSS box

Published: March 7, 2009

PCI-DSS compliance can dominate an organization's security posture. Learn to look outside the PCI-DSS box.


Misconceptions about PCI-DSS

Published: March 1, 2009

An attempt to clarify some of the misconceptions about PCI-DSS


QSA Training and ISACA Winter Conference

Published: February 28, 2009

A general news update: Attended QSA training and the ISACA Winter Conference


Data breaches in 2008

Published: February 20, 2009

A quick look at data breaches that happened in 2008 and the most obvious causes.


Is the Web Application Firewall (WAF) a silver bullet?

Published: February 2, 2009

An overview of web application firewalls (WAF) and why they cannot replace secure coding practices.


Obama’s new phone

Published: January 22, 2009

Obama's new hi-tech phone: One of the perks of being President of the USA.


Heartland data breach

Published: January 21, 2009

Heartland Payment Systems, a process of credit card transactions has disclosed that its systems have been broken into, resulting in millions of cards being compromised.


Top programming errors

Published: January 15, 2009

The top 25 programming error that lead to security breaches in web applications/sites.


A peek at AppScan Developer Edition

Published: January 8, 2009

A quick overview of IBM Rational's new application vulnerability scanning tool for developers.


The need to follow good practices

Published: January 5, 2009

Blogging service JournalSpace is no more because they did not follow good practices. What happened here?


Is it “goodbye MD5″?

Published: January 3, 2009

Real life exploits showing two different messages resulting in the same MD5 hash value seem to suggest an end to the use of MD5 for all practical purposes.


Web app security – Where do I start?

Published: January 1, 2009

You have been tasked with making your applications secure. Where and how do you start?


Giving away sensitive information

Published: December 15, 2008

The pitfalls of not removing data from your phone before throwing them away..


Malware on Mac?

Published: December 6, 2008

Did Apple remove an advisory about Mac users using anti-virus software for selfish reasons?


Obama’s cellphone records breached

Published: November 22, 2008

Every organization is worried about hackers breaking into the network from outside. What about insider threats?


Alan Greenspan shocked

Published: October 24, 2008

Why was Alan Greenspan shocked that all the financial companies that failed did not regulate themselves?


Does compliance mean anything?

Published: July 4, 2008

Does compliance mean anything? Or is it just something companies do because they have to?


SecureData from Voltage Security

Published: March 18, 2008

Database encryption made simple?