Blog Feed: Information security insight, tips, tricks, and tools for enterprise security administrators, architects, developers, a..
| Home | My Account | Directories |
Webcertiv Website Security Suite – Web Security for the Masses
Published on 0000-00-00 00:00:00
Does your company have money to spend on web security? Chances are you have a (very) limited security budget, and you wouldn’t be alone. In the face of financial hardship, companies looking to cut costs often drop expensive security products and services from their budgets before anything else. Realizing this trend, Webcertiv has launched the Webcertiv [...] > read more
Secure Mind Labs Blog Goes Live
Published on 0000-00-00 00:00:00
Welcome to the official blog of Secure Mind Labs! Stayed tuned for security insight, tips, tricks, and tools to improve your security knowledge and awareness. > read more
Metadata Extraction – Is Your Website Leaking Information?
Published on 0000-00-00 00:00:00
If you’re reading this post, chances are you’re concerned about website security. As a responsible website owner or systems administrator, you have considered the obvious security precautions. You’ve placed your web server behind a firewall, you keep your web server software updated and patched, you use strong passwords, and you encrypt sensitive traffic sent between web browsers and your server. [...] > read more
Do You Need a Web Application Security Assessments?
Published on 0000-00-00 00:00:00
“My web server was tested in our last network vulnerability assessment. Do I need a separate web application security assessment?” We get asked this question often. The (not so) simple answer is… it depends. Network vulnerability assessments typically identify vulnerabilities in the host operating system and web server software. Web application security assessments, on the other [...] > read more
The “SML Enterprise Security Tips” Series is Here
Published on 0000-00-00 00:00:00
As information security professionals, we invest considerable time, effort, and money into staying just one step behind crackers and cyber criminals (yes, you read that correctly, one step behind). No sooner do we implement a cool new security technology to combat an existing threat than the hacker community devises a new type of attack. Keeping up [...] > read more
Enterprise Security Tip #1: Keep a Watchful Eye on Web Traffic
Published on 0000-00-00 00:00:00
Welcome to the first post in the SML Enterprise Security Tips series. In this post, we’re going to discuss a danger present in many enterprise networks: HTTP port and protocol abuse. Let’s start with a scenario. Like all good security administrators, you have installed a firewall between your internal network and the Internet, and you’ve configured [...] > read more
8 Ways Your Website Could Be Leaking Login IDs
Published on 0000-00-00 00:00:00
Hackers frequently gain access to computers and applications using compromised usernames and passwords. While phishing attacks account for a large percentage of compromised accounts, there are other techniques employed by attackers to identify valid login IDs for use in password guessing attacks. Here are eight ways that your website could be leaking login IDs… File metadata [...] > read more
Enterprise Security Tip #2: Strengthen the Weakest Security Link First
Published on 0000-00-00 00:00:00
When performing penetration testing, we consistently gain access to hosts and applications using educated password guessing attacks. This is especially true of web applications which often 1) maintain their own database of user accounts and 2) lack adequate password policy enforcement. One of the most successful techniques involves sweeping a list of usernames for weak passwords. [...] > read more
Stealing ATM PINs Using Thermal Imaging
Published on 0000-00-00 00:00:00
At the USENIX Security Symposium in San Francisco, researchers from the University of California at San Diego presented a paper on using thermal imaging to steal ATM PINs. In their paper, entitled Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks, Keaton Mowery, Sarah Meiklejohn, and Stefan Savage describe how thermal cameras can [...] > read more
Got a security question? Ask an expert!
Published on 0000-00-00 00:00:00
Do you ever wish you could get your information security questions answered without the hassle of searching the Internet, posting to an online forum, or visiting the book store? Well, look no further. Get your questions answered now using our Ask a Security Expert service. It’s a free service for IT professionals and small business owners. Systems [...] > read more