• 26 May 2009

    Perfect example of an unknown app becoming a known target

    A while back I wrote about a great email server called Icewarp. It wasn't bloatware - it had just what SMBs needed in an email server...Oh, and it wasn't a target for security exploits - an obvious added benefit. But as with anything else, you grow bigger, your app becomes more complex, and you'll no doubt become a bigger target for attacks. As of late Icewarp has grown a lot ...

    Continue Reading...
  • 25 May 2009

    My latest security content

    Here's my latest information security content you may be interested in:How to forge an IT consulting careerHow to maintain IT shop efficiency when you're the last man standingDesktop security preparation for a new wave of Windows appsAs always, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 23 May 2009

    MagicJack – Great concept, awful execution

    You may have heard that AT&T is dropping its CallVantage VoIP service. I'm not too upset since their service has been mediocre and my enhancement requests have been ignored. As of late I've been searching for an alternative solution. I'd heard some good stuff about the MagicJack and thought I'd give it a try. It was a "free" trial so what did I have to lose?Apparently several hours of my ...

    Continue Reading...
  • 21 May 2009

    My CNN TV appearance – yet another mobile drive debacle

    CNN's Mike Ahlers and Elaine Quijano put together an intriguiging segment about a lost hard drive from the National Archives for The Situation Room with Wolf Blitzer television show I appeared on last night. The hyperlink goes to the actual article...the video hasn't been posted yet and they're telling me it may not be. I hope you had the chance to see it live last night. If it gets posted ...

    Continue Reading...
  • 20 May 2009

    I’m going to be on CNN at 5pm ET today

    I received a call from the producer of the CNN show The Situation Room With Wolf Blitzer today and ended up doing a TV interview. It's about the National Archive story that just came out regarding and external hard drive that recently went missing.Wonder if it was encrypted like I've ranted about here and elsewhere in the past? Probably not.It's going to be on in the 5pm ET hour on ...

    Continue Reading...
  • 19 May 2009

    I’ve been saying this for a while

    Apparently security researchers and Robert Abela with Acunetix agree with what I've been saying for a while: Web application firewalls aren't enough!Check out this post and the darkreading.com post it links to....

    Continue Reading...
  • 18 May 2009

    Tips on keeping your job these days

    I recently wrote about How to maintain IT shop efficiency when you're the last man standing (which reminds me I forgot to post this on my new content updates!).Well, here are some more tips that Linda Tucci with SearchCIO.com just wrote about.So there you go...two reading assignments. :-)...

    Continue Reading...
  • 13 May 2009

    Windows 7 – worth the wait?

    I've never been big on major OS upgrades however Windows 7 is looking promising. I installed Windows 7 RC on an older test system this past weekend and it actually seems to work well so far! I am having some video driver crashes but other than that it looks like MS may have actually fixed the quirkiness with Vista. I always liked the Vista interface (Windows 7 has it) but ...

    Continue Reading...
  • 12 May 2009

    Secure code by force?

    The Senate Homeland Security Committee, in their infinite wisdom, prodded by SANS' Alan Paller apparently believe they can legislate secure software from IT vendors.That'd be like legislating more secure health records, and personal financial information, and so on. Oh wait, that has been done. And it's not working all that well as far as I can tell.That'd also be like legislating higher-quality cars. Ha! The Feds can work that out ...

    Continue Reading...
  • 12 May 2009

    New version of Acunetix WVS is coming

    I just downloaded and am eager to try out the latest from the guys at Acunetix: Acunetix Web Vulnerability Scanner version 6.5 beta. It seems like they just came out with version 6.0! My last post on it was only a couple of months ago.Acunetix WVS 6.5 beta has a new feature called "file upload forms vulnerability checks" which they claim is an industry first. This is interesting because I ...

    Continue Reading...