• 06 Jun 2011

    InfraGard Atlanta hack highlights some lessons for us all

    What started with an email from a colleague's compromised Gmail account Friday evening has ended up making international news - the InfraGard Atlanta website has been hacked. With user names, email addresses and passwords - including those associated with the FBI - available via a quick web search I knew that this was a pretty serious issue. Although I've been disconnected from InfraGard Atlanta for the past ~6 years, I ...

    Continue Reading...
  • 23 May 2011

    Sony PlayStation discussion download

    In case you missed our Sony PlayStation Security Fiasco roundtable discussion last week, here's a link to the MP3 recording.Enjoy!...

    Continue Reading...
  • 02 Mar 2011

    The real numbers behind lost laptops

    Here's a recent piece I wrote for my friends at SearchCompliance.com regarding the lost laptop problem and what it's costing businesses:The Billion Dollar Lost Laptop – What’s it costing your business?I've seen some naysayers out there stating that there's no way a lost laptop could match up to Ponemon's figures. I say why find out!? Whatever the cost, the solutions for laptop security are simple once the choice is made ...

    Continue Reading...
  • 10 Dec 2010

    Canon’s digital camera image originality not so original

    How's this pic for an attention grabber?!Well, the folks at Elcomsoft have done it again. This time they've discovered a vulnerability in Canon's Original Data Security system demonstrating that digital image verification data can be forged. Apparently Canon has yet to respond.Why is this a big deal? Well, it's impactful for the media, for forensics investigators, and for those of us in infosec as digital images are used in many ...

    Continue Reading...
  • 27 Sep 2010

    Got VoIP? Better make sure it’s secure.

    Given that VoIP has been around for more than 10 years, it's hard to find a business where's it's not running in some capacity. I do find it interesting how many network managers aren't too concerned about the security of VoIP. People say things like "It's on the inside of the network", "It's running on a separate VLAN", and "We're PCI and HIPAA compliant but there's nothing of significance being ...

    Continue Reading...
  • 15 Sep 2010

    Hacking Methodology chapter available for download

    Chapter 4 of the latest edition of my book Hacking For Dummies is now available for download on TechTarget's SearchWindowsServer.com.If you like what you see, here's a direct link to the book on Amazon where you can save 34% off the cover price: Happy ethical hacking!...

    Continue Reading...
  • 22 Jan 2010

    What are your thoughts on Web hosting / colo providers?

    Better think things through when giving up the reigns and letting a third-party Web hosting or colo provider run the show:When using a Web hosting provider can be bad - really bad - for your businessYou'd think Network Solutions would have better security controls in place.When will people pull their heads out of the sand? Maybe never??Speaking of this specific vulnerability, here's a recent bit I wrote on Acunetix's blog ...

    Continue Reading...
  • 11 Jan 2010

    Introducing my new book – Hacking For Dummies, 3rd edition

    Well, after months of edits, additions, and subtractions my new piece of work has finally arrived: Hacking For Dummies, 3rd edition I just received my copies last week and it should be in bookstores any time - if it's not already. Hacking For Dummies, 3rd edition is also available on Amazon.com (at a 34% discount to boot!).So, how is this 3rd edition different or better from the previous editions? In ...

    Continue Reading...
  • 19 Aug 2009

    No soup for you….20 years!

    Here's a bit on the recent indictment of a Florida man known as the soupnazi (man, I miss Seinfeld) and two Russians for the data breaches of Heartland, Hannaford, and many others. Facing 20 years and a $250,000+ fine and he still has other cases pending!The funny thing is that he's a former informant to the U.S. Secret Service!Lesson to be learned: test your systems for security vulnerabilities before the ...

    Continue Reading...
  • 17 Jul 2009

    A way to keep the RF in your RFID

    In case you're as concerned as I am about this, we now have a way to keep our RFID-tagged passports and driver's license secure. Just another public service announcement.......

    Continue Reading...