SE·CU·RI·TY: procedures followed or measures taken to ensure the safety of a state or organization.

Internet Storm Center Infocon Status
Showing posts with label cross site scripting. Show all posts
Showing posts with label cross site scripting. Show all posts

Sunday, April 13, 2014

If you don't know what the heartbleed bug is, you need to start now!



The Internet’s Most Widespread Vulnerability

heartbleed

Remember when you were a little kid and you and your friends had your own secret code words and no one was able to tell what you were saying???  Now, imagine that someone had a secret decoder ring and was able to understand everything you were saying.  But this is the best part, you didn’t even know that a decoder ring existed for your imaginary language!  Oh, and this decoder ring has been available in every box of cereal on store shelves!

Now lets change some of the details of the story….


    Ovaltine Decoder Ring
  • Store Shelves = Internet
  • Cereal Boxes = Websites/Webservices
  • Secret Code = encryption
  • Friend = Server
  • Decoder = Heartbleed bug

How many boxes of cereal were on store shelves that came with a prize?  Imagine if 66% of them did.  That is a lot of decoder rings.

xkcd comics
From the Heartbleed homepage:
[The Heartbleed bug] compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content... As long as the vulnerable version of OpenSSL is in use it can be abused.  
So, when you are accessing a website and sending your information out and getting information back, all this 'computer talking' should be encrypted, and no one should have the key except for you and the server you are talking with.  And in some cases, this is probably true and hasn't changed.

But if the website you are using protects information using any version of OpenSSL released in the past 2 years (May 2012), than you probably should change your password...NOW!  


OpenSSL is used by the web servers Apache and nginx, it is used to protect "email servers (SMTP, POP and IMAP protocols), chat servers (XMPP protocol), virtual private networks (SSL VPNs), network appliances and wide variety of client side software."  This pretty much includes more than half the internet.  


Well, at least it was discovered by a researcher for Google and the security engineers at Codenomicon instead of a hacker, right???  At least everyone assumes, but there really is no way to tell for sure because Heartbleed is undetectable, untraceable. 


The only way to be safe now is to change your passwords.  If you have entered a password on any account that has been using the OpenSSL Versions issued in the past 2+ years, change it!  But not until you know that the site has installed a patch and issued new certificates.  If they haven’t, don’t try to access that account!  Any information passed between you and the server is still susceptible.   


For more information on the Heartbleed Bug, or to see if a site you use could be affected, check out these sources:




Resources:
www.heartbleed.com
http://mashable.com/2014/04/09/heartbleed-nightmare/
https://lastpass.com/heartbleed/
http://www.cnet.com/news/heartbleed-bug-what-you-need-to-know-faq/




Wednesday, March 19, 2014

Where do you go for information security?

If you are interested in more information on Web Application Security, be sure to check out our Resources page for direct links to some of the top informational sources.

There you will find links to the SANS Institute, as well as pertinent information and affiliated sources by them, the National Cybersecurity & Communications Integration Center, and the US Computer Emergency Readiness Team.

These sources provide valuable information on what threats exist, emerging threats, and how to protect your Web Application.

Friday, February 7, 2014

NBC: All Visitors to Sochi Olympics Immediately Hacked

What can we do to secure our wireless devices and our data from hackers?

In an increasingly digitally wireless, always connected world, it is almost certain that you will have a mobile device connected to a network that you have no control over.
From Starbucks to universities, grocery stores, shopping malls, book stores, hotels, conference centers...networks are everywhere and ready for you to connect.
What data is on that device? Personal information, family member's addresses, your children's pictures and birth dates, their school information, banking information, calendars and schedules...
All this information could be used to impersonate you, track you, know when you will be at work or soccer practice, and how often you download music from iTunes and pay your mortgage, or when your paycheck is deposited.

Wikipedia

Search results