QUICK LINKS

  Zone-h Advisories

  CERT coordination

  InfraGard

  Homeland Security

  Microsoft Security

  F.B.I.

  Security Focus

blogd  Alan's Blog



Security and Technology

Many organisations today address the term security. The term is simple and small, but easily and widely misunderstood. Security is much more than login and password protecting corporate data or even securing the ports protecting your corporate perimeter. Many methodololgies are employed to create the perfect catch all be all to encompass: Information Security and Risk Management, Access Control, Cryptography, Physical Security, Security Architecture and Design, Business Continuity and Disaster Recovery Planning, Telecommunications and Network Security, Application Security, Operations Security, and Legal, Regulations, Compliance, and Investigations. Six Sigma mixed with modern processes have been perfected and deployed successfully at every organization Skomax has consulted with.

  Phase I Social Engineering -  

Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies. By this method, social engineers exploit the natural tendency of a person to trust his or her word, rather than exploiting computer security holes. It is generally agreed upon that “users are the weak link” in security and this principle is what makes social engineering possible.

Read More

  Probing and foot/finger printing

Serious hackers don't shoot in the dark when attempting to penetrate a system. Instead, they will systematically identify what systems and services your company is running to determine your weakest link. Are you connected to a partner network that has a firewall equivalent to Swiss cheese? Does your remote access system require only mediocre authentication?

Read More

  Signs of a compromised system

Worst case scenario: You have a funny feeling you've been hacked, but you're not quite sure what to do next. If you're like most IT people, you don't necessarily know where to look for evidence that shows the system has indeed been compromised. Let's look at a few of the more common pieces of evidence that you may find after a system breach.       Read More