Tuesday, May 26, 2015

Netiquette IQ Blog Of 5/25/15 - The Seven Deadly SIns Of Security

 ============================================
One of Tabula Rosa's Strong Security offerings is Sophos. They have a wide and comprehensive ranges of security solutions. For each of the "deadly sins" noted below, Sophos has a product to address the need. Please contact Tabula Rosa (see below) for any additional information.
=============================================
From Sophos Security Software - The Seven Deadly SIns Of Security


Mobile Negligence

That flashy little device in your pocket is a big security risk. Hackers are increasingly targeting mobile devices to steal data (emails, contacts, corporate data, financial information) and send premium rate SMS, using up your bandwidth in the process. Android devices are most vulnerable to threat - last year SophosLabs saw an 1800% increase in Android malware. While there is less iOS malware these devices are still vulnerable to attack, particularly jailbroken devices
Mac Malice
Macs are gaining ground on Windows in corporate usage. However, many Macs aren’t properly protected against malware and data loss. Macs can be infected with malware just like PCs, and the threat is growing. Macs can also play host to Windows malware and spread it across your network to all your Windows computers. Your employees love their Macs. But you can’t afford to give Macs a pass on protection.
Unsecure WiFi
Put an access point in your office and you’ll have a Wi-Fi hotspot in no time. Then along come all these devices that want to connect – smartphones and tablets belonging to your employees, laptops brought in by visitors. Do you know where those devices have been? And if your hotspot provides full access to your corporate network, that could mean access to more data than you intended. If you don’t protect your wireless network, it can open the door to threats.

Un-encrypted Email

Your email typically traverses the Internet in plain text format. It’s like sending a postcard in the mail. Anyone with the means and motive – government agencies, ISPs, webmail providers, hackers, advertisers and even your competitors – can take advantage of this to steal sensitive data, facilitate identity theft, access credit card information, or provide more targeted advertising. We’re in the middle of an email snooping epidemic and unsecure email is a major liability.

Faulty Firewall

It may look like an unassuming box in the server room, but your firewall is your network’s first line of defense: blocking port scans, thwarting data-stealing malware, controlling Facebook access, prioritizing bandwidth for corporate applications … the list goes on. If your firewall can’t keep up with threats and bandwidth demands, or is too complex to use effectively, you’re not getting the full potential from your network.

Un-encrypted Files

Major corporations like Target, The Home Depot and JPMorgan Chase have suffered data breaches that are devastating to their brands. Smaller companies suffer the same fate with less fanfare. No matter what the size of the breach, your reputation and customer loyalty can be damaged beyond repair. If you’re not securing sensitive company data and your customers’ identities, your customers will flee even if your business escapes the wrath of regulators.

Delinquent Web Filtering

Web filtering used to be easy – block out the pornography, gambling and extremist content and you’re safe. But today that’s no longer enough to keep employees secure against dangerous websites - 80% of all web malware is now hosted on legitimate websites that have been compromised. Hackers compromise thousands of new sites every day, using sophisticated techniques to keep their malware from being detected. You can get infected with malware by browsing to a hacked website that might have been safe the day before, without even knowing it.
============================================
Good Netiquette And A Green Internet To All!

============================================ 

Great Reasons for Purchasing Netiquette IQ
·         Get more email opens.  Improve 100% or more.
·         Receive more responses, interviews, appointments, prospects and sales.
·         Be better understood.
·         Eliminate indecision.
·         Avoid being spammed 100% or more.
·         Have recipient finish reading your email content. 
·         Save time by reducing questions.
·         Increase your level of clarity.
·         Improve you time management with your email.
·        Have quick access to a wealth of relevant email information.
Enjoy most of what you need for email in a single book.

=====================================================

**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Monday, May 25, 2015

Tabula Rosa Systems Security Bulletin - US-Cert Summary For The Week Of 5/18/2015

================================================
National Cyber Awareness System:
05/25/2015 07:19 AM EDT

Original release date: May 25, 2015
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.
The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
·         High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0
·         Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9
·         Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9
Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.
===============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Sunday, May 24, 2015

Tabula Rosa Systems Blog Of 5/24/2015 - Long List Of Devices Believed To Be Affected by NetUSB Vulnerability

 ============================================
 
May 19, 2015 SC Magazine

Long list of devices believed to be affected by NetUSB vulnerability
The vulnerability was identified by researchers with SEC Consult, who initially discovered the issue in on a TP-LINK device.
Potentially millions of devices around the globe – notably routers – are vulnerable due to a remotely exploitable kernel stack buffer overflow (CVE-2015-3036) identified in NetUSB, a Linux kernel module developed by Taiwan-based KCodes that is used to provide USB device sharing on a home network.
The issue presents itself when a client sends the computer name as part of the “connection initiation,” a Tuesday blog post stated, explaining that the stack buffer overflows when specifying a name longer than 64 characters.
“Because of insufficient input validation, an overly long computer name can be used to overflow the “computer name” kernel stack buffer,” according to a Tuesday advisory. “This results in memory corruption which can be turned into arbitrary remote code execution [or denial-of-service].”
The vulnerability was identified by researchers with SEC Consult, who initially discovered the issue in on a TP-LINK device and later verified that the bug exists in the most recent firmware versions of TP-LINK TL-WDR4300 V1, TP-LINK TL-WR1043ND V2, and NETGEAR WNDR4500.
SEC Consult went on to identify NetUSB in the most recent firmware versions of several other products, including D-Link DIR-615 C, as well as several other NETGEAR, TP-Link, TRENDnet, and ZyXEL devices.
Altogether, based on data embedded in KCodes drivers, researchers believe the following are among vendors that are affected: ALLNET, Ambir Technology, AMIT, Asante, Atlantis, Corega, Digitus, D-Link, EDIMAX, Encore Electronics, EnGenius, HawkingTechnology, IOGEAR, LevelOne, LONGSHINE, NETGEAR, PCI, PROLiNK, Sitecom, TP-LINK, TRENDnet, Western Digital, and ZyXEL.
According to the advisory, SEC Consult contacted KCodes numerous times throughout February and into March, but a fix was not made available. SEC Consult later contacted TP-LINK and NETGEAR, as well as CERT Coordination Center (CERT/CC) and other CERTs, before making a public disclosure.
“To this day, only TP-LINK released fixes for the vulnerability and provided a release schedule for about 40 products,” the blog post said. “Sometimes NetUSB can be disabled via the web interface, but at least on NETGEAR devices this does not mitigate the vulnerability. NETGEAR told us, that there is no workaround available, the TCP port can't be firewalled nor is there a way to disable the service on their devices.”
According to a CERT/CC advisory, blocking port 20005 on the local network could help mitigate the issue by preventing access to the service.
============================================
Good Netiquette And A Green Internet To All!

============================================ 

Great Reasons for Purchasing Netiquette IQ
·         Get more email opens.  Improve 100% or more.
·         Receive more responses, interviews, appointments, prospects and sales.
·         Be better understood.
·         Eliminate indecision.
·         Avoid being spammed 100% or more.
·         Have recipient finish reading your email content. 
·         Save time by reducing questions.
·         Increase your level of clarity.
·         Improve you time management with your email.
·        Have quick access to a wealth of relevant email information.
Enjoy most of what you need for email in a single book.

=====================================================

**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Systems Technical Term For 5/24/15 - Attack Surface Analysis

  ======================================================
From whatis.com
Attack surface analysis is an assessment of the total number of exploitable vulnerabilities in a system or network or other potential computer attack target.
IT security workers  and hackers both use attack surface analysis to detect security weaknesses in a system. An individual trying to break into a system generally starts by scanning the target’s attack surface for vulnerabilities before choosing an attack vector. This is generally true for active attacks, passive attacks, ethical hacking and hacking competitions.
An organization’s attack surface can be subdivided into a few categories:
  • The network attack surface: the totality of all vulnerabilities in connected hardware and software that are accessible to an unauthenticated  user.
  • The software attack surface: the complete profile of all functions in any code running in a given system that are available to an unauthenticated user.
  • The physical attack surface: all security vulnerabilities in a given hardware system that are accessible to an attacker in the same location as the target.
These different types of attack surfaces pose very different types of threats. Usually, the analysis of a target’s vulnerabilities focuses on exposed functions of incoming and outgoing code (the software attack surface). With the majority of attacks coming from the web, network attack surface is a very important consideration because it is the most common path to the software attack surface.
The physical attack surface branches out with more and different possibilities in close access to the target. The physical element includes insider threats, social networking and even break and entry and vandalization as considerations.

OWASP offers an attack surface analysis cheat sheet for organizations; software tools include Microsoft Attack Surface Analyzer. However, as attackers can be very creative, it is often necessary for security analysts to think like a hacker to perceive potential threats.


 +++++++++++++++++++++++++++++++++++++++++++++++++
Good Netiquette to all!
===================================================
Have you ever wondered how it would be if your email suddenly came to life? You are about to find out.
https://www.youtube.com/watch?v=HTgYHHKs0Zw
====================================================
Have you ever wondered what a conference call looks like in real life? See the link below
https://www.youtube.com/watch?v=DYu_bGbZiiQ
=====================================================
**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================