Microsoft out-of-band security update for Internet Explorer. Microsoft released an urgent security update for Internet Explorer on all currently supported versions of Windows.
Compare Bargains on Hardware Diagnostics
![]() |
Identity ProIdentity theft is on the rise. Your own computer may be one of the easiest ways for thieves to access your information! Search and secure your private information, including social security numbers, credit cards, drivers license, and even passwords. Find and secure your personal information (PI) before others get the chance! Identity Pro goes beyond current protection offered by anti-virus, anti-spyware, anti-spam, or anti-phishing, etc, to protect you where these programs don't. Automatically seek out and protect your important data. You'll be surprised at how much of your information is kept on your PC, from web forms to emails. Once you know what's there, you can delete or encrypt with ease. |
CIS Center for Internet Security. A non-profit enterprise whose mission is to help organizations reduce the risk of business and e-commerce disruptions resulting from inadequate technical security controls.
Nessus is a popular vulnerability scanner used in over 75,000 organizations world-wide. Use Nessus to audit business-critical enterprise devices and applications. Check your networks, servers and applications for potential security vulnerabilities.
ITsafe provides a free Warning Service to help protect home and small business users of computers and other devices from attack. IT Security Awareness For Everyone. UK Government's ITsafe Service.
How To Break Web Software - A look at security vulnerabilities in web software. Video- (Large, but worth, (a must), watching video).
Sysinternals File and Disk Utilities Harddrive links
Microsoft Security Assessment Tool (MSAT) is a risk-assessment application designed to provide information and recommendations about best practices for security within an information technology (IT) infrastructure.
Microsoft Baseline Security Analyzer More Microsoft links
Google Launches Encrypted Search Option. Are your Web searches safe from snoops? It's an issue that may not have been on many people's radar. Traditionally, the higher-profile issue for search engines like Google and Yahoo is that they maintain a record of users' search sessions for several months as part of a massive data collection the companies say is needed to help improve search results. Now Google is tackling a different slice of the privacy issue by launching a beta of its standard Google search that's encrypted with the same Secure Sockets Layer (SSL) technology used by many Web services including e-commerce sites and Google's own Gmail service. Web addresses that begin with the letters "https" are SSL-protected. More Search engines. Online Dictionary, Thesaurus. Acronym or abbreviation finder, etc.. More Google Knowledge. Google Information More Yahoo Knowledge. Yahoo Information
| How To Keep Your Laptop From Being Stolen |
Tinkernut Forum Video Tutorials These video will show you how to keep your laptop from being stolen and how to track it if it has been stolen. |
How to Track a Stolen Laptop | ||
Adeona is the first Open Source system for tracking the location of your lost or stolen laptop that does not rely on a proprietary, central service. This means that you can install Adeona on your laptop and go ? there's no need to rely on a single third party. What's more, Adeona addresses a critical privacy goal different from existing commercial offerings. It is privacy-preserving. This means that no one besides the owner (or an agent of the owner's choosing) can use Adeona to track a laptop. Unlike other systems, users of Adeona can rest assured that no one can abuse the system in order to track where they use their laptop. Adeona is designed to use the Open Source OpenDHT distributed storage service to store location updates sent by a small software client installed on an owner's laptop. The client continually monitors the current location of the laptop, gathering information (such as IP addresses and local network topology) that can be used to identify its current location. The client then uses strong cryptographic mechanisms to not only encrypt the location data, but also ensure that the ciphertexts stored within OpenDHT are anonymous and unlinkable. At the same time, it is easy for an owner to retrieve location information. Using Adeona only requires downloading and installing a small software client. Adeona is free to use.
Security Pro News An article portal for Internet and Technology professionals. SecurityProNews is the most popular newsletter for IT managers in the World :-
Breaking news and updates in Internet security
![]() |
| Internet Explorer 8 Vulnerability Exposed |
![]() |
| Dell Collaborates with Trend Micro |
![]() |
| Apple And Adobe Both Roll Out Large Security Updates |
![]() |
| HP to Acquire Fortify |
![]() |
| Microsoft Issues Record Breaking Security Update |
![]() |
| Microsoft Fixes Most Recent Vulnerability |
![]() |
| Google Pushing To Redefine 'Responsible Disclosure' |
![]() |
| Mozilla Rolls Out Security Update For Firefox |
![]() |
| Windows XP Security Patch |
![]() |
| iTunes Store To Receive Security Makeover |
Seecrets Delivery Services (SDS) will be free for personal users. An e-security suite of crypto e-mail, secure password manager, zip manager & For-Your-Eyes-Only content viewer. The unique e-mail security caters for the privacy of all web mail and POP3 users. SDS uses RSA 8192-bits public key cryptography and AES 256-bits. All symmetric encryption uses our Secrets Signature-Free technology. Keeping Your Secrets Secret, Encryption, For-Your-Eyes-Only Protection, Watermarking, Secure Delivery.
Common Weakness Enumeration (CWE) Now Available. CWE is a community-developed formal list of common software weaknesses. The intention of CWE is to serve as a common language for describing design, or code; as a standard measuring stick for software security tools targeting these weaknesses; and to provide a common baseline standard for weakness identification, mitigation, and prevention efforts. Broad community adoption of CWE will help shape and mature the code security assessment industry and also dramatically accelerate the use and utility of software assurance capabilities for organizations in reviewing the software systems they acquire or develop.
Encryption with DeGPG Protect your files. DeGPG runs in the background on your server to provide access to GPG encrypted data to your web scripts. It will also work with GPG to encrypt and store data submitted via web forms. To give your web scripts access to encrypted data, you log in and enter the passphrase to decrypt the data. The data is decrypted and stored in memory till a web script needs to access it. In cases where your web script only needs, for example, and MD5 hash of the data, rather than the decrypted data itself, DeGPG can be instructed only to reveal the MD5 hash, and not the raw data. Additional data may be prepended or appended to the decrypted data before computing the hash.
Androsa FileProtector is a professional and freeware file encryption software that protects any type of file encrypting completely the content with the most advanced systems of cryptography.
SecuritySpace is proudly brought to you by E-Soft Inc., a privately owned Canadian consulting firm, with proven expertise in internet security and on-line services. We specialize in the following areas:
The Windows Memory Diagnostic Tests the Random Access Memory (RAM) on your computer for errors. The diagnostic includes a comprehensive set of memory tests. If you are experiencing problems while running Windows, you can use the diagnostic to determine whether the problems are caused by failing hardware, such as RAM or the memory system of your motherboard. Windows Memory Diagnostic is designed to be easy and fast. On most configurations, you can download thediagnostic, read the documentation, run the test and complete the first test pass in less than 30 minutes.
The Platform for Privacy Preferences Project (P3P) enables Websites to express their privacy practices in a standard format that can be retrieved automatically and interpreted easily by user agents. P3P user agents will allow users to be informed of site practices (in both machine- and human-readable formats) and to automate decision-making based on these practices when appropriate. Thus users need not read the privacy policies at every site they visit. Have a look at the list of P3P software. PSP is a W3C standard for creating machine-readable privacy policies. The standard allows a website to create an XML version of its privacy policy so that it can be evaluated automatically against an individual's privacy preferences.
P3P Toolbox is a one-stop resource developed by the Internet Education Foundation in cooperation with the World Wide Web Consortium and a coalition of Internet industry leaders and public interest organizations to provide privacy officers and Webmasters with the information they need to make their Web sites P3P compliant. The site is no longer active and is being hosted here by Internet Education Foundation for archival purposes.
Infographic by WordStream Internet Marketing Software
Iconix eMail ID software download Iconix is committed to making it easy to identify legitimate emails. We are working closely with companies like Google and Iconix to give our users the best protection against fraudulent, phishing and suspect emails. If you are a Gmail user, it's easy to identify legitimate emails. You can simply enable an icon which will only show up when an email is from PayPal (or from our sister company, eBay). So when you receive an email from us, or our partners at eBay , you will see a key icon next to the message in your Inbox. Only legitimate PayPal emails have this icon so if you get an email claiming to come from PayPal and you don't see the icon, it's not from us. So please don't open it. To enable this feature in Gmail, go to 'Settings', 'Labs', then tick the Enable box next to the 'Authentication icon for verified senders' option and click on 'Save Changes'. This software download from Iconix can help reduce phishing by confirming whether you received a legitimate PayPal email. After Iconix eMail ID has been installed, you'll see an Iconix eMail ID icon (a gold lock with a tick) whenever you receive authentic emails from PayPal. It's free and it works with most of the major email services like Gmail, (Google Mail), MSN Hotmail, Yahoo Mail, Outlook Express, and many more. If your preferred email program, web mail provider or operating system. is not listed, click here and we will notify you when support is available. For more information, go to the Iconix website, How does the Iconix solution work? The Iconix solution couples our advanced technologies with authentication techniques such as Yahoo!'s Domain Keys and Microsoft's Sender ID to confirm the source of an email, and will support Domain Keys Identified Mail (DKIM), which is a joint effort between Cisco and Yahoo!, as it is adopted in the industry. This combined solution makes it very difficult for bad guys to spoof the identity of emails with an Iconix Truemark icon. Also see PayPal Support Club. Review and helpful links, coding examples, warnings, other shopping cart links, etc. PayPal is a on-link banking system that allows website owners to integrate shopping cart technology into their site. Find out more, includes links to helpful site about PayPal shopping cart technology.
PrivacyFinder is a privacy-enhanced search engine. Once you state your privacy preferences (low, medium, high, or custom), the search results are ordered based on how their computer-readable privacy policies comply with your preferences. A red bird indicates that the site has conflicts with your preferences while a green bird indicates compliance. The absence of any bird means that a valid computer-readable privacy policy, known as a The Platform for Privacy Preferences Project (P3P) policy, could not be located.
No Right Click Disable the right click on your pages to prevent users from "borrowing" images from your site and viewing your page source! . (BACK UP ALL FILES FIRST) Do a temporary copy upload and check the site works first, (as this does some more complex code changing onload), if the site functions OK then replace the normal site with the temp upload and retest... May only work with LINUX host) This can be a bit time consuming as if I remember correctly each image has to be Hot-Link prevented individually, and then if you add a new image this also has to be Hot-link protected. (I believe Hot-Link protection on the Host uses .htaccess) and this may be worth checking out as well.
CopyWipe is a utility for copying or securely overwriting (wiping/erasing) entire hard drives. CopyWipe can ease and expedite the transition to a new hard drive by copying the entire contents of one drive to another. CopyWipe can also help prevent confidential or private data from being recovered, by securely wiping the contents of a drive. A number of options are provided for wiping, most of which exceed governmental standards (such as DoD 5220.22-M, NAVSO P-5239-26, etc.); this allows the user to choose an optimal balance between security and duration of the wiping operation.
Stop Badwear. The "Badware" problem. We've all seen it happen: you or someone you know has downloaded something from the internet that seemed harmless enough at the time. Next thing you know, the computer has slowed to a crawl. Pop-up advertising starts to appear out of nowhere. Private information gets sent to some company you've never heard of. And the worst part? Trying to uninstall the software sometimes makes the problem worse. Find out more...
Sender Policy Framework. Sender Address Forgery. Today, nearly all abusive e-mail messages carry fake sender addresses. The victims whose addresses are being abused often suffer from the consequences, because their reputation gets diminished and they have to disclaim liability for the abuse, or waste their time sorting out misdirected bounce messages. You probably have experienced one kind of abuse or another of your e-mail address yourself in the past, e.g. when you received an error message saying that a message allegedly sent by you could not be delivered to the recipient, although you never sent a message to that address. Sender address forgery is a threat to users and companies alike, and it even undermines the e-mail medium as a whole because it erodes people's confidence in its reliability. That is why your bank NEVER sends you information about your account by e-mail and keeps making a point of that fact.
Auslogics System Information provides you with detailed information about your computer operating system and hardware, including installed devices, running processes and services, memory and CPU usage, drive properties as well as other technical details. The information can be viewed from the categorized interface or exported to HTML, XML or text format.
Falcon21 Home PC Security website!
Security Team Blog ( Security Team ) more Blog links
The Secunia PSI is the FREE security tool that is designed with the sole purpose of helping you secure your computer from software vulnerabilities.Free Internet Eraser is an Internet privacy software that protects your Internet privacy by permanently erase internet history and past computer activities. Even though, many of the tasks can be performed manually,
Advanced Windows Care - Freeware Advanced Windows Care v2 Personal is a comprehensive PC care utility that takes an one-click approach to help protect, repair and optimize your computer. It provides an all-in-one and super convenient solution for PC maintenance and protection. This fantastic program is available free of charge for private use. More Microsoft Windows Windows Vista. Windows XP, etc.
Google Responsible Disclosure: Focus on protecting end users. Vulnerability disclosure policies have become a hot topic in recent years. Security researchers generally practice ?responsible disclosure?, which involves privately notifying affected software vendors of vulnerabilities. The vendors then typically address the vulnerability at some later date, and the researcher reveals full details publicly at or after this time. A competing philosophy, "full disclosure", involves the researcher making full details of a vulnerability available to everybody simultaneously, giving no preferential treatment to any single party. The argument for responsible disclosure goes briefly thus: by giving the vendor the chance to patch the vulnerability before details are public, end users of the affected software are not put at undue risk, and are safer. Conversely, the argument for full disclosure proceeds: because a given bug may be under active exploitation, full disclosure enables immediate preventative action, and pressures vendors for fast fixes. Speedy fixes, in turn, make users safer by reducing the number of vulnerabilities available to attackers at any given time. More Google information links
Skipfish (from Google) is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments. SkipFish Documentation.A fully automated, active web application security reconnaissance tool. Key features:
The tool is believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments. Support the open source community by providing a scalable, reliable, and fast collaborative development environment for open source software, docs, and standards that promotes best practices in open source software engineering." |
SkipFish Security Report example :- | |
![]() |
SpoofStick is a simple browser, (Internet Explorer or Firefox), extension that helps users detect spoofed (fake) websites. A spoofed website is typically made to look like a well known, branded site (like ebay.com or citibank.com) with a slightly different or confusing URL. The attacker then tries to trick people into going to the spoofed site by sending out fake email messages or posting links in public places, hoping that some percentage of users won't notice the incorrect URL and give away important information. This practice is sometimes known as phishing".
Identity theft. (Home Office Identity Theft website), Your identity and personal information are valuable. Criminals can find out your personal details and use them to open bank accounts and get credit cards, loans, state benefits and documents such as passports and driving licenses in your name.
The Identity and Passport Service was established as an Executive Agency of the Home Office on 1 April 2006. The Agency builds on the strong foundations of the UK Passport Service (UKPS) to provide passport services and in the future, as part of the National Identity Scheme, ID cards for British and Irish nationals resident in the UK. Foreign nationals resident in the UK will also be included by linking the scheme to biometric immigration documents.
National Identity Fraud occurs when a person's personal information is used by someone else without their knowledge to obtain credit, goods or other services fraudulently. It can even extend to securing a passport in their name.
Federal Trade Commission (Identity Theft)
Visit the UK Passport website issue UK passports to British nationals living in the UK. Our website is here to help you with your passport application.
Preventing Virtual Blight: my presentation from Web 2.0 Summit
Belarc Advisor builds a detailed profile of your installed software and hardware, missing a href="http://www.acomputerportal.com/microsoft_windows.html">Microsoft hotfixes, anti-virus status, CIS (Center for Internet Security) benchmarks, and displays the results in your Web browser. All of your PC profile information is kept private on your PC and is not sent to any web server.
OpenID is an open, decentralized, free framework for user-centric digital identity. OpenID starts with the concept that anyone can identify themselves on the Internet the same way websites do-with a URI (also called a URL or web address). Since URIs are at the very core of Web architecture, they provide a solid foundation for user-centric identity.
Free Internet Window Washer is a free internet tracks eraser and privacy cleaner software. As you work on your computer and browse the Internet, you leave behind traces of your activity. The Windows built-in functions will not protect you, most of the tracks can not be erased with them. Therefore, anyone else can see what you have been doing on your computer. Furthermore, much of your activity information takes up valuable disk space, and recovering this space can be very beneficial.
Process Library resource is for anyone who immediately wants to know the exact nature and purpose of any and every single process that is - or should not be - running on your PC.
Security Config, your security portal. Here you can find all of the tools you need to secure your website, business, data, and everything else digital. Downloads ranging from: Anti Virus Software, Cookie Tools, Desktop Security, Email Security, Encryption , Enterprise Monitoring , Firewalls, Network Security, Password Software, SSH Tools and more.
Google Hacks 2.0 - video powered by Metacafe Also see Google Knowledge. Google Information
Microsoft Baseline Security Analyzer
ModSecurity is a web application firewall that can work either embedded or as a reverse proxy. It provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis. Provides Geo IP resolution, credit card number detection, support for content injection, automated rule updates, scripting, as well as many more security methods. See more Trackers, Website statistics, Hit Counters. Page Load Speed Tests
The ISO 17799 Information Security Portal. ISO17799, ISO 27000 and Computer Security News.
Consumer Direct, a telephone and online consumer advice service supported by the Department of Trade and Industry.
APACS - Association for Payment Clearing Services
National Lottery, (United Kingdom), scam (fraudulent) emails are increasing at an alarming rate.
Business Software Alliance. Help businesses avoid software licensing problems. We've designed the Anti-Piracy Information section to help users prevent software theft. BSA® one of the World's leading anti-software piracy groups is committed to providing support every step of the way. In 2003, across the EMEA region, the BSA handled 57,625 calls, followed up 7,929 end user leads and took legal action against 9142 companies. Learn about the types of software piracy, its penalties and find all the tools you need to make a difference: Asset Management Resources, Guide to Software Management, Reasons to Fight Software Piracy, Online Shopping Tips and much more. If you've already thought through the issues and now wish to report a company that uses illegal software, you can do so anonymously through our Online Reporting Tool. (Don't forget, when an organization is prosecuted, it is the company directors who face legal action.) Report Piracy Now
Red Flag Rule, (Federal Trade Commission), require financial institutions and "creditors" with "covered accounts" to establish identity theft prevention programs to identify, detect and respond to patterns, practices or specific activities that could indicate a customer-account holder has been victimized by -- or is engaged in -- identity theft.
The Windows Security Center, (Microsoft Windows®), which is already installed on your computer, monitors and enables you to manage important security settings on your computer, including a firewall, automatic updates, and the status of your antivirus software.
Microsoft Windows® Service Pack 2 A free software update pack for Windows XP, which is the operating system of many home PCs. Microsoft Windows® Service Pack 2 is commonly known as SP2 is designed to fix several bugs and vulnerabilities in Windows XP simultaneously, and give your PC better protection from viruses and hackers. How to get SP2 Also view Microsoft Windows®
BitLocker Drive Encryption is the final feature release name for the project previously referred to as "Secure Startup Full Volume Encryption." Some preliminary releases of Windows Vista®, still use the old project name in text strings and Windows® titles. This step-by-step guide uses the old project name where appropriate, such as referring to the user interface where it appears. Otherwise, the feature release name is used.
WinErrs Did you ever get an Illegal Operation 'or' Page Fault' error message when using Microsoft Windows® and wonder what it meant? WinErrs is a database of 1.554 (Microsoft Windows®), error codes and their definitions. These codes are extracted directly from (Microsoft Windows®), and are their descriptions.
Apple Product Security Mac OS X Security Apple Security Updates page More Apple Links
Hoax-Slayer is dedicated to debunking email hoaxes, thwarting Internet scammers, combating spam, and educating web users about email and Internet security issues. Hoax-Slayer allows Internet users to check the veracity of common email hoaxes and aims to counteract criminal activity by publishing information about common types of Internet scams. Hoax-Slayer also includes anti-spam tips, computer and email security information, articles about true email forwards, and much more. New articles are added to the Hoax-Slayer website every week.
Secunia PSI (Personal Software Inspector) scans your computer for seriously outdated software products that have been discontinued or require critical security updates from the vendor.
CAPTCHA™ is a program that can generate and grade tests that most humans can pass, but current computer programs can't pass. For example, humans can read distorted text, but current computer programs usually can't read such distorted text. This may be useful to confirm emails are genuine and other basic Diagnostics and Security checking.
WebScarab is a Web Application Review tool. It sprang from the designs of the people inhabiting the WebAppSec list run from SourceForge, for a powerful, free, open tool for reviewing web applications for security vulnerabilities. Not much of the original design has actually been implemented as envisioned. WebScarab started as a spider that could download all the pages on a site. It stayed that way for almost a year, before I decided to take lessons learned during the development of Exodus and implement them as part of WebScarab.
OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. The Open Web Application Security Project (OWASP) is dedicated to finding and fighting the causes of insecure software. Everything here is free and open source. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work. Participation in OWASP is free and open to all.
Security config Software to Protect your system.
Identity Finder - Freeware. Let us prove to you the power of our search capabilities for free. Simply download, install, and run the search. It will detect unprotected credit cards and passwords on your computer that are vulnerable to identity theft or fraud. Once found, you can permanently shred or encrypt the information with a password so identity thieves cannot steal them. Take the first step towards protecting your family, your employees, and your business; try Identity Finder today. Installation and removal are easy.
| PC Pitstop! |
GetNetWise. Accessing the Internet through a broadband or high speed Internet connection at home really enhances the online experience. However, broadband users should take extra precautions to secure their computer and their computer files. The speed at which information can be transferred to and from your computer and the fact that it stays connected to the Internet for long periods of time makes your it a more likely target for hackers than dial-up Internet users. By taking some basic precautions and using a few simple tools, you can do your part to protect cyberspace from hackers. At the same time, you'll also protect your computer and your information from theft, misuse and destruction. GetNetWise Main page
Information Virtual Private Network (or VPN). (Wikipedia), is a secure network connection that is layered on top of the Internet. This type of connection is used to move secure data to and from corporate networks safely, minimising the chance of these systems being "hacked or abused".
Secondary DNS , (SECDNS), provides redundant name service for a domain that you own, DNS is managed on your own nameserver(s). The servers providing Secondary DNS are located on separated networks to prevent any downtime. With Secondary DNS even if yours goes down, it will continue to resolve your queries. In the event of an attack the restoring of the secured DNS network will take place to keep websites on-line and useable.
Domain Name System Security Extensions (DNSSEC). (Wikipedia), is a suite of Internet Engineering Task Force (IETF) specifications for securing certain kinds of information provided by the Domain Name System (DNS) as used on Internet Protocol (IP) networks. It is a set of extensions to DNS which provide to DNS clients (resolvers) origin authentication of DNS data, authenticated denial of existence, and data integrity, but not availability or confidentiality..
Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography. A free implementation of this protocol is available from the Massachusetts Institute of Technology. Kerberos is available in many commercial products as well.
DNS How To DNS is the Domain Name System. DNS converts machine names to the IP addresses that all machines on the net have. It translates (or "maps" as the jargon would have it) from name to address and from address to name, and some other things. This HOWTO documents how to define such mappings using Unix system, with a few things specific to Linux.
SpoofStick is a simple browser add-on for Internet Explorer, that may help novice users to spot phishing scams that are linked from emails or web sites.
PhishFighting. Fight back and take down the Phishers. Enter phishers URL to Report it.
PhishGuard is a simple, FREE software service for computers running Microsoft operating systems (Windows 98 through XP) and any version of Microsoft Internet Explorer 4.0 or greater. PhishGuard harnesses the collective observations of Internet users to detect and rapidly disable Internet Phishing or Spoofing attacks designed to steal critical financial data.
Reporting Spam SpamCop parses reported email, sending warning information to the internet service provider responsible for hosting the services used by the spammer (web sites and email sending sites). SpamCop also uses the information to generate SpamCop's free blocking list. Unfortunately, this is an ongoing battle. Spammers adapt quickly and persistently. Report spam and help SpamCop turn the tide. SpamCop makes this otherwise slow and technical task quick and easy. The SpamCop reporting service is free. More...
What is "mole" reporting? SpamCop Mole reporting was an experiment that presented many problems in the operations and integrity of SpamCop, so is mostly being disabled. Reports from users who choose to be mole reporters will count only in the statistics and aggregate counts. Reports are not sent and can only be viewed by SpamCop administrators. Mole reports do not count in the stats used to determine listing and delisting of IP addresses in the SpamCop Blocking List. As spam defenses and spammers become more sophisticated, many smart spammers have developed very sophisticated defenses against being detected. One of the spammer's strategies is to quickly and effectively remove anyone from their mailing lists who files a spam complaint (until they want to get revenge, and then the use these "remove lists" differently). This is generally (although not always) good for the person filing the complaint, but it is bad for spam defense in general, since these activists are the only ones identifying the problem. By removing the "trouble makers", spammers too often slip "under the radar" and appear to be legitimate senders, even though the majority (or entirety) of the victims don't want the mail (they are just the ones who don't bother to make waves). More...
Flash, aaaaagh! Is your school website flashy but safe? Most educational websites in the U.S. are using Flash applications that fail to adequately secure these pages. This is a growing problem for the Internet as vulnerable sites can be hijacked for malicious and criminal activity, according to a paper published in the International Journal of Electronic Security and Digital Forensics this month. More links about Flash
Cloud Computing is a somewhat nebulous word to describe that modern users will "rent" or borrow online software instead of actually purchasing and installing it on their home computers. It is the exact same idea as people using Gmail or Hotmail services, except that cloud computing goes much further than simple email. Cloud computing is where entire businesses and thousands of employees will run their computer tools as online rented products. All of the processing work and file saving will be done "in the cloud" of the Internet, and the users will plug into that cloud every day to do their computer work. It is said that Could Computer suppliers buy computer systems by the container load. This help reduce cost because of Economies of scale. Software as a Service (aka "Saas" or "SaS"). Platform as a Service (aka "PaaS" or "PaS") . Software and Platform.
Cloud Security Frame. Cloud Security Frame at Shaping Software. This frame is especially important because we?re using it to help us map out the Cloud security space for our patterns & practices Cloud Security Guidance project. It?s helps us scope our project. The frame is basically a set of Hot Spots. We use the Hot Spots to find, organize, and share principles, patterns, and practices. We also use the Hot Spots to find pain points and opportunity or to organize key engineering decisions.
The Security Development Lifecycle:- Dave again! We’ve been asked if commercial enterprises can use the SDL documentation that we recently released under a Creative Commons license. It seems that there is some confusion within the IT community regarding our use of a CC license that stipulates non-commercial terms. The purpose of this post is to clarify our intent in releasing the SDL materials under a Creative Commons license and to define acceptable uses of these materials. All organizations, including for-profit enterprises, may copy, distribute and transmit any SDL content we release under the Attribution, Non-Commercial, Share Alike (cc by-nc-sa) terms. This means that businesses are free to incorporate the SDL content we release under this Creative Commons license into their internal process documentation and development methodologies and to use the SDL content to advance the development of secure software, provided the terms of the license are followed. Microsoft released the SDL content under this Creative Commons license to enable individuals, organizations and businesses to incorporate security and privacy into software development practices. Microsoft, however, does not extend this license grant to organizations or individuals whose primary purpose is to generate revenue by reselling the SDL content. Our intent here is to make it easier for all organizations to incorporate security and privacy into their development practices. By incorporating security and privacy into the development lifecycle of many businesses, we get more secure software, which reduces risk for the entire computing ecosystem. If you have questions about commercial uses of the SDL content, please feel free to post your question on the Microsoft SDL forums – we’d be happy to help Hello all, Dave here… We have received a quite a number of requests from various organizations and individuals that wish to use our Security Development Lifecycle (SDL) content to build out their own secure development processes. We have put a lot of thought into these requests and how best to service them. Up to this point, Microsoft has released SDL information using a license that did not allow for reproduction, inclusion or transfer of any part of our documentation or process without express written consent from Microsoft. I am happy to announce that from this point forward, Microsoft will be making our publicly available SDL documentation and other SDL process content available to the development community under a Creative Commons license. Specifically, we will be using the license that specifies Attribution, Non-Commercial, Share Alike (cc by-nc-sa) terms. By changing the license terms, we are now allowing people and organizations to copy, distribute and transmit the documentation to others; this means that you can now incorporate content from the SDL documents we release under Creative Commons into your internal process documentation – subject to the terms specified by the Creative Commons license mentioned above. You can learn more about the specifics of that license here: http://creativecommons.org/licenses/by-nc-sa/3.0/ Note that we do not intend to change the licensing for any of the SDL tools released by Microsoft – those will continue to use existing Microsoft licenses. Our first two documents for release under a Creative Commons license will be the English versions of the “Simplified Implementation of the Microsoft SDL” whitepaper and the Microsoft Security Development Lifecycle (SDL) - Version 5.0 paper that illustrates how Microsoft applies the SDL to our own products and services. Those releases will be completed over the next few weeks. There is a lot of information on our portal about the SDL; case studies, whitepapers, training materials etc. It is our intention to analyze this content and apply Creative Commons licenses to these works as well – assuming it makes sense and isn’t already covered by new works under a CC license. It will take time for us to analyze and repost the documents with the new license – so we ask for your patience. It’s our hope that by making the SDL documentation more accessible and portable, that more people will start doing secure development and realizing the benefits of incorporating security and privacy throughout the development lifecycle. Hi everyone, Bryan here. If you’re at Black Hat this week, I’ll be giving a talk Thursday afternoon on the topic of cryptographic agility – the ability for applications to change which cryptographic algorithms or implementations they use without having to make changes to the source code. Cryptographically agile applications can more easily comply with various countries’ myriad cryptography requirements such as FIPS 140, and in many cases they can also outperform applications with hardcoded algorithms. Best of all, when some hotshot cryptographer breaks an algorithm, the agile application will be able to swap out to a more secure alternative in minutes rather than weeks or months. Check out the Black Hat website for more information on my talk, “Cryptographic Agility: Defending Against the Sneakers Scenario,” on Thursday, July 29, 4:45 PM in the Roman Ballroom at Caesar’s Palace. Hope to see you there! Hi, Adam Shostack here. I just wanted to let you know that I’ll be speaking at Black Hat about “Elevation of Privilege: The Easy Way to Threat Model.” Threat modeling is critical to secure development, and people find it intimidating and tough to get started. I will present Elevation of Privilege, a simple card game that makes it easy and fun to get started threat modeling. This turbo talk will take place in the Florentine room at 11:15 on Thursday, July 29. I look forward to seeing you there! Hi everyone, this is Grant Bugher. I’ll be giving a talk Thursday afternoon at BlackHat 2010 about securely using cloud storage systems like Windows Azure Storage – how applications that use cloud storage as their database back-end can protect themselves from attacks. Just as with traditional methods of data storage and retrieval like SQL-based relational databases, application authors must take care to use cloud storage systems correctly to avoid unauthorized data access or tampering. My presentation will cover a variety of attacks on applications using cloud storage, such as enumeration and REST/SOAP injection, to show how some of the same effects as a SQL injection attack can also be used on an application using a cloud storage system. There’s more information on my talk on the BlackHat website, under “Secure Use of Cloud Storage.” The talk will be on Thursday, July 29 at 11:15 AM in the Augustus Ballroom (3+4) at Caesar’s Palace. Hope to see you there! Steve Lipner here. Next Tuesday evening (July 27), SAFECode will be sponsoring a brainstorming panel at Black Hat that’s aimed at gathering security community input on vision and approaches for improving software assurance over the next 10 years. SAFECode members all have established software assurance programs, but we all believe it’s important to seek new ideas and approaches and then follow up on them. Since Black Hat is one of the largest gatherings of security experts, we’re taking advantage of the opportunity to meet with the community and listen to their thoughts. There will be several of us from SAFECode in attendance, but we hope that most of the “air time” will be taken up by community input. We look forward to a robust discussion If you’re coming to Black Hat, please join us from 5 to 6:30pm on Tuesday at Caesar’s Palace in Room Neopolitan 4. We’re asking attendees to register in advance at http://www.safecode.org/register.php so we can get a count of attendees and be sure we won’t overflow the space allocated. If you’re not coming to Black Hat, you can also submit your idea on the web at the link above. Jeremy Dallman here. This morning Brad Arkin via the Adobe ASSET team blog announced their upcoming release of Adobe Reader Protected Mode. I wanted to take a moment to congratulate Adobe Security and the Adobe Reader team on reaching this significant milestone. As Brad mentioned in his blog post, Microsoft worked with Adobe on the design model for this security feature. This work was part of the ongoing collaboration between the Microsoft SDL team and the Adobe ASSET team. We were glad to introduce the Adobe Reader team to the Microsoft Office team and have them work closely with David LeBlanc, Dan Jump and other members of the Microsoft Office security team to leverage Microsoft’s sandboxing knowledge and experience. Adobe Reader Protected Mode is based on Microsoft's Practical Windows Sandboxing technique. We look forward to the release of the Adobe Reader Protected Mode feature and the protections it will provide our mutual customers. Arjuna Shunn here to talk with you about the importance and value of software security training when implementing the Microsoft SDL. Product and application development too often only focuses on finding security issues late in the development lifecycle, long after developers have completed features and code. Delaying focus on security results in both significant cost and a less effective software security posture. While security testing and analysis post-development are components of the SDL, the best returns on investment – and the focus of the SDL – are much earlier in the development lifecycle. One of the earliest, and often most effective components of a secure development program is effective training for product and application development staff, so they better understand the risks they can introduce into software before any code is written and indeed before any architecture is designed. To that end, we are releasing guidance to assist you with the adoption of critical training for creating more secure software. In recent months, there have been several instances within private and public sectors where software security training for engineers has been recommended as a key method to help solve current software security problems. To assist you with developing training capabilities which will ease your deployment and accelerate your implementation of the SDL, we are releasing a whitepaper entitled Essential Software Security Training for the Microsoft SDL. The expected audiences for this paper are technical decision-makers, compliance managers, software developers, and systems integrators who are working within or on behalf of organizations that are looking to implement the Microsoft SDL as part of their development lifecycle. The paper is broken into easy-to-digest sections that we hope are both readable and practical: 1. Overviews of Software Security Training: purpose, goals, and characteristics 2. A description of the Microsoft SDL core training courses, 3. Descriptions of advanced training content and topics While training regimens differ based on organization specific needs, we hope this paper will provide a viable framework for understanding your needs as a development organization and help you to create and maintain an effective software security training capability. As always, we welcome your questions and feedback in comments, mail, and our forums. Adam Shostack here. One of the really exciting things about being in the Microsoft Security Engineering Center is all of the amazing collaborators we have around the company. People are always working to make security engineering easier and more effective. When we talk about security testing, we often focus on what it can’t do. “You can’t test security in,” and “test will never find everything.” But much like there’s code that’s easy to get wrong, there’s code that’s hard to test. Writing code to be testable has a long history, and one we don’t often talk about in security. Today’s post is from Hassan Sultan, who’s responsible for one of our internal fuzzing tools. We hope it inspires you to think about the question “How can I make the security of my code more easily tested?” And here’s Hassan: Security testing is an integral part of the software development lifecycle. At Microsoft, the biggest part of the security testing done is usually implemented through a technique called fuzz testing: sending unexpected input to the product and checking whether it behaves in an acceptable way (i.e. it doesn’t crash, hang, leak memory…). We also use other techniques such as static source code analysis but today we’re going to focus on fuzz testing and how you can best make use of it. Almost every software company and every software project has to perform within constraints, they can be financial, the project has to be completed within a set budget, or time-driven, the project has to ship within a specific timeframe. The corollary is that the product must be of the highest quality possible within those constraints. How then can you perform efficient, quick and cheap security testing? One approach we have started using at Microsoft is to change our engineering and test engineering practices to make fuzz testing easier, it’s a little bit of additional upfront work but with great savings in terms of time and resources quickly appearing over the life of the project. There are two popular approaches to fuzz testing, considering data exchanges between a producer (the software sending data) and the consumer (the target software processing the data): A couple of things are obvious when comparing these two approaches: The approach I’m going to talk about is based on MITM fuzzing; the goal is to develop functionality tests in a way that makes them easily reusable as producers for MITM fuzz testing, as well as to provide a bit of functionality in the actual product to make fuzz testing more efficient. This approach makes security testing much cheaper to implement, is quite efficient and allows improving the fuzzing over time without having to rewrite numerous security tests. MITM fuzzing using functionality tests has the following drawbacks: The approach here is thus to fix all these problems at the source, we have listed the steps required along with each step’s priority, obviously the more you do, the better, but if in a crunch, start from the top of the list and go down as far as you can. (A test hook is a configuration option that modifies the product’s behavior when set, it can be removed before the product ships if needed) These modifications to the way tests and products are engineered are minor and cheap to implement when planned early on and will produce tremendous benefits by: Ultimately, using both Generation fuzzing and MITM fuzzing would be ideal, as generation fuzzing provides a few benefits that won’t be attained by MITM fuzzing(the ability to create very specific scenarios for example), but when dealing with time and resource constraints, the MITM fuzzing approach allows for efficient fuzzing that can be improved over time at a minimal cost. Jeremy Dallman here to talk about aligning SDL practices with Health Insurance Portability and Accountability Act (HIPAA) regulatory activities when developing or integrating healthcare applications. Today, I would like to announce the release of a new whitepaper: SDL and HIPAA: Aligning Microsoft SDL Security Practices with the HIPAA Security Rule. We are all acutely aware that our lives are becoming more and more digitized. New technology and services are storing, aggregating, and sharing our personal information in new ways every day. With these innovations come inherent risks; and with these risks come new regulations designed to ensure technology is protecting our personal information. Along with the development of new technology and implementation of regulations is a rapidly-growing awareness that securing applications is a critical component of securing data. It is no longer enough to only rely on perimeter or infrastructure-based protections. The critical process of creating more secure applications is what the Microsoft SDL is designed to address. Recent studies have shown that organizations are spending on compliance tasks in lieu of security – however compliance and security don’t have to be at odds. For organizations already tasked with ensuring their software meets the demands of regulatory compliance, adopting the Microsoft SDL process alongside these activities may seem both time consuming and costly. Yet, their customers are (or soon will be) demanding evidence of security best practices for how applications are written or integrated. In recent months, the U.S. Department of Health and Human Services (HHS) has set a 2015 deadline to increase use of electronic health records (EHRs) by 60%, largely spurred by $19 billion in incentives for health care organizations to adopt EHRs. This push for EHR adoption and the billions of dollars in incentives are all part of the Health Information Technology for Economic and Clinical Health (HITECH) Act approved by Congress in 2009. As we became aware of this convergence of new technology, regulatory compliance, demands for more secure software, and the inherent costs of these activities; it became apparent that we needed to evaluate the application of the Microsoft SDL alongside some of these regulatory activities. This paper shows how the Microsoft SDL can help meet some of the requirements of HIPAA. It addresses two primary scenarios—the development of new healthcare software and the integration of healthcare software into an EHR solution. Both of these scenarios represent common intersections between software security and HIPAA requirements. Our goal is to show where software security can both assist in attaining regulatory compliance with HIPAA and ensure that the software created for the healthcare industry is written and deployed with security as a priority, using the Microsoft SDL as a guide. Additionally, this paper highlights some HIPAA security requirements (called safeguards) and demonstrates how SDL practices can be used to support those safeguards. The expected audiences for this paper are business decision-makers, compliance managers, software developers, IT consultants, and systems integrators who are working within or on behalf of organizations that must meet HIPAA compliance requirements. This paper is not intended to advise organizations of their legal requirements and responsibilities. It is assumed that the reader understands the laws and regulations mentioned in this paper and how those laws and regulations apply to their organization. The paper is broken into easy-to-digest sections that we hope are both readable and practical in application: 1. Overviews of the Microsoft SDL and the HIPAA Security Rule 2. A scenario-based review of SDL applicability to the HIPAA Security Rule 3. A “rip-out” mapping of SDL Practices to the HIPAA Security Rule Safeguards in the Appendix We realize that aligning security practices with compliance activities will vary across organizations, but we hope this paper will help you think through how your organization may be able to adopt the Microsoft SDL to write more secure software and realize redundancies or improve efficiencies between those security practices and your HIPAA regulatory activities. As always, we welcome your questions and feedback. Jeremy Dallman here to introduce a new paper we released earlier this week that introduces you to the Windows Live team’s implementation of the SDL in their web application scenario. The paper will join our other internal SDL case studies and white papers in the Publications section of our SDL web portal and can also be downloaded directly: Applying the SDL at Windows Live. The Windows Live™ team adopted many of the newer Web-focused requirements of the SDL. This paper summarizes these new requirements, describes the process that the Windows Live team followed in integrating the SDL starting with Wave 2, and captures some of the lessons that they learned along the way. This paper also describes how the use of SDL by the Windows Live team has evolved, starting with Windows Live Wave 2, through Windows Live Wave 3, and on to the upcoming release, Windows Live Wave 4. This paper focuses on two classes of Windows Live products: · Web applications, such as Windows Live Hotmail®, running on Web servers hosted for Microsoft. · Client applications, such as Windows Live Messenger, running on users' desktops. The security threats and mitigations for these two classes of products are very different. The most common vulnerabilities observed in the Web applications are cross-site scripting (XSS), cross-site request forgery (XSRF), open redirects (XSRs), and JavaScript object notation (JSON) hijacking. In the client applications, past vulnerabilities are often due to buffer overflows and integer overflows. Some other common security vulnerabilities, such as Structured Query Language (SQL) injection attacks, are not as prevalent in Windows Live products because of their limited use of SQL. This paper walks you through a phase-by-phase description of how the Windows Live team mitigated these threats by implementing the SDL while giving you a good view of how the SDL is applied by web application development organizations inside Microsoft. Hi, Michael here. It gives me great pleasure to introduce Tim Burrell from our team based in Cheltenham, England. Amongst other things, Tim works on static analysis and compiler security improvements, but more on that work in a later post! As I have mentioned many times, I’m a huge fan of anything that reduces friction for software developers; anything that makes it easier to design, build and test code that’s more secure is a huge win in my book. Now, over to Tim to see how a tool he created can help reduce coding friction and help you be more SDL-compliant! In a previous post we mentioned that our team had worked with the Visual C/C++ compiler team to make significant enhancements to /GS buffer overrun detection in Visual Studio 2010. While working on /GS – and navigating the unfamiliar corridors of the Visual Studio buildings – I got talking to Boris Jabes, Program Manager Lead in the Visual Studio IDE team. He told me how they were making the IDE easier to extend in Visual Studio 2010. This piqued my interest because one of the challenges we face when enforcing compiler warnings is that teams write their code, and then get notified of the errors and warnings later on. There are some downsides to this process: 1. By the time the developer gets notified of the error or warning that needs fixing, the context is lost: i.e. the developer has to remind himself of what the line of code in question was doing. 2. Typically there may be multiple errors or warnings to resolve: the approach is naturally to go and fix all of them as quickly as possible to avoid any further delays to development. This can lead to errors. 3. The code that immediately follows the fixed code may also need updating as a result of the fix, and this can be time-consuming. By flagging an issue in the editor itself, as the code is being written, the developer can immediately correct the issue knowing the code’s context. With all the benefits of flagging coding issues early in mind, I decided to create an SDL Banned API extension for Visual Studio. The extension is very simple: at the moment a developer types the name of a banned function, such as strcpy Visual Studio highlights the offending code using a squiggly line, much like a spelling error in Microsoft Word: Visual Studio extensions can also differentiate between C and C++ language elements. For instance, we can ensure that we don’t underline occurrences of banned API function names that occur in comments or string literals: We can also add tooltip information pointing to the SDL required coding practice. Let us know what you think or how you extend this extension to your own purposes. Thanks to Boris Jabes and Noah Richards in the Visual Studio IDE team for coding this up! The code for the SDL Banned API IDE Visual Studio extension is available in SDLBanned.zip. There are two folders in the ZIP file: src and bin. The source code folder includes the necessary C# code and VS2010 project to tweak the code. The binary code folder includes a single file: BannedAPIextension.vsix. Double-clicking this file will install it into Visual Studio 2010. You can enable, disable and uninstall extensions from the Visual Studio Tools | Extension Manager menu. Finally, if you want to tweak the code you need to install the Visual Studio 2010 SDK, the link is below. Security Development Lifecycle (SDL) Banned Function Calls, MSDN, May 2007. MSF Agile + SDL process template for Visual Studio Team System Microsoft SDL process template for Visual Studio Team System Extending the editor, MSDN. VSX home on code gallery, samples, documentation and more, MSDN. Noah Richards’ blog, lots of examples and discussion from Noah Richards on the IDE team. Hi Michael here. Over the last few months, a small cross-group team within Microsoft, including the SDL team, has written a paper that explains how to use the security defenses in Windows Azure as well as how to apply practices from the SDL to build more secure Windows Azure solutions. We wrote this paper because no matter how many defenses we add to Windows Azure, it is important that people building software or hosting services in “The Cloud” understand that they must also build software with security in mind from the start. The paper also discusses some common threat scenarios, and provides mitigation guidance. Below is a short video introducing the paper and a link to the paper. The paper is here. Read the paper if you’re building solutions for Windows Azure so you know the threats your application might face and you know the practices you should use to defend against those threats. Let us know what you think. On a similar note, Warwick Ashford, a UK reporter, interviewed Steve Lipner for a podcast about the paper and Microsoft’s cloud security practices. In the podcast, Steve touches on the roles of assurance and the SDL, operational security, and certifications in providing a secure environment for hosting applications in the cloud. Hi everyone, Bryan here. Judging from the quantity of email I’ve been getting since Visual Studio 2010 shipped last month asking when we’ll have an SDL process template available for it, there are a lot of you out there who have already upgraded to VS 2010 and are looking to integrate SDL processes into your development environment. So, I am extremely happy to announce that the MSF-Agile+SDL Process Template for TFS 2010 is now available for download. If you’re already using either the MSF-Agile+SDL template for TFS 2008 or the MSF for Agile Software Development template that ships in the box with TFS, you’ll find it extremely easy to pick up the new MSF-Agile+SDL template for TFS 2010. The new 2010 template retains all of the features of the 2008 template, including: In addition, the 2010 template also includes some new features: The MSF-Agile+SDL process template is freely downloadable, so if you’re running TFS 2010, give it a try and be sure to let us know what you think about it. I have written about some of the security improvements in VC++ 2010 (here and here) and want to mention another important one: improved SAL support. The Standard Annotation Language (SAL) is a way of annotating function prototypes to help static analysis tools find bugs, including many classes of security vulnerabilities, with a low false-positive rate. If you are not familiar with SAL, declspec versus attribute syntax, and the use of macros to implement SAL, you should read this first. The two biggest SAL changes in VC++ 2010 are: What this means to you as a C or C++ developer using VC++ 2010, is that the compiler and static analysis toolset (/analyze) will find more bugs in your code. And all you did was upgrade to the newer compiler! On a slightly different, but related topic, the advent of macros for attribute SAL (as used in VC++ 2010) is a major milestone for SAL, because it means we are in a position to make SAL a requirement for the next version of the SDL. Presently, SAL is a recommendation, although larger Microsoft teams use SAL anyway. It's important to realize that we can't make anything a requirement in the SDL unless: The SAL requirement is going through the feedback period right now. Clearly SAL can help with the second point, because SAL can help pinpoint buffer overruns in C and C++ code. The addition of attribute SAL macros in sal.h means the third point is addressed too. Telling developers to annotate code using low-level SAL constructs in this manner: void Func( Is simply not going to fly! But asking developers to annotate their code using high-level SAL macros like this: void Foo( Is acceptable. Steve Lipner here. As many of you already know, Microsoft was one of the original nine companies that participated in the first iteration of the Building Security In Maturity Model (BSIMM). For those of you unfamiliar with BSIMM, it describes common software security practices across the participating companies - or as the authors describe it; "...a collection of good ideas and activities that are in use today." BSIMM allows you to determine which software security practices are most widely used across the sample set of development organizations. The first BSIMM report was released in early 2009, and provided some great insights on security policies and practices currently in use. With today's announcement, BSIMM has been expanded to include more companies, in more industries, across a wider geographical area. I’m happy to have been asked to participate on the newly established BSIMM Advisory Board - to help guide the theory and practice of BSIMM, and to ensure that the data gathered has practical application for the security community at large. I'd encourage you to take a look at the BSIMM - and compare your practices to the ones outlined in the BSIMM report. You might be surprised at the results! Hello all, Dave here... There have been a number of insightful comments of late about the news that Microsoft and Cisco Systems have been collaborating on secure development concepts. The most interesting set of comments I saw were from Adrian Lane at Securosis who in his post entitled "FireStarter: Secure Development Lifecycle-You're Doing It Wrong" stated the following: "...If you take the SDL Microsoft has described and try to implement it, you will fail. I am talking to the 99% of people out there who would think about implementing SDL and think "Hey, Microsoft published this new thingie for free; let's use it and save ourselves the time and money!" Wrong." What may surprise many of you is that we are largely in agreement - for many of the same reasons that Adrian stated in his post. If you take Adrian's comment as ‘let's use it exactly and expect to save time and money!' you'll run into problems. On the other hand, using what we've done as a base for your own security development process will save you time and money. That said, it's clear to me that "what we've got here is...failure to communicate." My profound apologies to "Cool Hand Luke" fans. : - ) We have received many requests over time for information on how Microsoft applies the SDL to our products and online services. The SDL process as outlined in the book written by Michael Howard and Steve Lipner as well as the guidance posted on the MSDN Developer Center is provided for one primary reason - to provide process transparency for our customers. There are a surprising number of customers who are starting to demand that vendors provide evidence of effective security processes, and we're happy to oblige. While development teams external to Microsoft may find that our documented processes provide useful context, they are just that, our documented processes. It has never been the intent of Microsoft or the SDL team to present our process guidance on MSDN as implementation guidance. Adrian's point #5 pretty much sums up our philosophy: "Do what Microsoft did, not what they do." We couldn't agree more - and that's the reason why we released a whitepaper I wrote entitled "Simplified Implementation of the Microsoft SDL" in February 2010 at Blackhat D.C. In contrast to the 150+ pages of us "showing our work" to our customer base, the "Simplified" paper is seventeen pages of proven, non-proprietary, platform agnostic information for development teams to consider when implementing the core security elements that make up the Microsoft SDL. A skeptic might conclude that since Microsoft is a software company, there must be a reliance on Microsoft tools in order to "do" SDL. There is no reliance on Microsoft tools - while we do provide tools for various activities in the SDL, there are perfectly acceptable substitutes (or methods) available to those who wish to use something other than a Microsoft solution. For example, we've heard of instances where dev teams have written narrative threat models in Word - heavy on the verbiage and light on the Visio diagrams. There was another instance where a team engaged in threat modeling as a whiteboard exercise; which seems like a really cool and interactive way for a team to get a solid understanding of the threats and mitigations for a particular application - until it's time to archive the result. So, they took a picture of the whiteboard and called it good. While we think the SDL Threat Modeling tool is pretty handy in these situations and we are convinced of its effectiveness in surfacing design threats, the method used for the threat model is unimportant in the grand scheme of things. The importance lies in the act of threat modeling and using the output from the threat modeling process to drive the changes necessary to secure an application. Similarly, if a dev team wants to start fuzzing, it makes no difference from an SDL perspective whether you use excellent free tools like the MiniFuzz fuzzer Michael Howard wrote, or Michael Eddington's Peach, or if you use any of the quality fuzzers available from SDL Pro Network tool vendors. Just find a tool that is appropriate to your needs and go fuzz your apps. Adrian is "spot on" when he muses about the resources necessary to implement the SDL at Microsoft - it's a non-trivial bit of effort. Then again, there's only one Microsoft - we ship hundreds of applications, used in over 150 countries worldwide and deployed on a variety of software and hardware platforms. We feel we have a unique responsibility to make our products as secure as possible - that drives our security philosophy and our ongoing investment. The Simplified SDL (or any proven security methodology for that matter) requires adequate resources, smart people, and subject matter expertise. We realize that not all organizations have the resource base of a Microsoft or a Cisco - but frankly speaking, you don't need to be an organization with several thousand developers, testers and architects to implement the SDL. Experience tells us that organizations (regardless of size) usually take an incremental approach to process improvement - security processes are no exception. If secure software is the end goal, then we can state with confidence that implementation of any of the processes listed in the Simplified SDL paper (in whole or in part) will contribute to more secure software. The bottom line from our perspective is that development teams need to take an outcomes-based approach - they should strive to understand the operational environment in which their application will run and should take the steps necessary to ensure that the application (when code complete) is as safe as it can be, given available knowledge and resources. So, a big hat tip to Securosis and Adrian for his insights - which gave us a great opportunity to talk about how the SDL is more than just a Microsoft process. - Dave Steve Lipner here. Almost from the time we created the SDL in 2004, we’ve been sharing information about our process, tools and training. We’ve taken this step because we recognize that our customers use lots of software that comes from organizations other than Microsoft, and that in order for them to have a more secure experience on the Internet, the organizations that develop that software also have to apply secure development practices. Beyond making information and tools available through our web site, we also engage in direct collaboration with some development organizations. Those collaborations have been driven by the importance of the other organization to the Internet ecosystem and by the opportunity for us to have a technical exchange with a sophisticated development team that may have some ideas, approaches, or challenges that we haven’t thought of. At any one time in recent years, we’ve had several such collaborations going, usually driven by Jeremy Dallman from our SDL team. The collaborations are usually conducted under a nondisclosure agreement because we need to exchange proprietary information about companies’ processes and tools. We may never talk publicly about these agreements at all. However, we are pleased to say that about three weeks ago, Cisco announced the creation of the Cisco Secure Development Lifecycle (CSDL) and elected to acknowledge that the CSDL had benefited from one of these collaborations. I’d like to thank our colleagues at Cisco for their acknowledgement, and to say that we’ve enjoyed and benefited from the opportunity to work with them. Jeremy Dallman here to announce that we are releasing the latest version of the Microsoft Security Development Lifecycle process guidance – Version 5 (SDLv5). It is now available for download as well as updated in the MSDN library. We have released incremental updates to the SDL process guidance document since 2008 in an effort to provide transparency into how we implement the SDL at Microsoft. If you are just getting started on investigating or implementing the SDL, we would encourage you to start with the SDL Optimization Model and the Simplified Implementation of the SDL paper and then use the SDLv5 guidance as an additional reference tool as needed for your own implementation. What is new in the SDLv5 documentation? We made a handful of significant changes in SDLv5 documentation. I summarize them below, but also encourage you to read the document for the detailed notes related to each (search in document for “New for SDL 5.0” and “Updated for SDL 5.0”). 1. SDL for Agile included: The largest change in SDLv5 is the inclusion of SDL for Agile Development as an Addendum at the end. We took the SDL-Agile guidance that was published in November 2009 and included it in the parent SDL document to make it a one-stop resource. 2. New and updated security requirements and recommendations Requirements Phase (1 new) New Requirements · Include third-party code licensing security requirements in all new contracts. Design Phase (3 new) New Requirements · Hardware: Perform hardware security design review. · Server/SaaS: Perform integration-points security design review. · Web application: Implement strong log-out and session management Implementation Phase (10 new, 1 update) New/Updated Requirements · Use Secure methods to access databases · Avoid LINQ ExecuteQuery · Avoid EXEC in stored procedures · Update: new minimum required versions for code analysis tools (also see Appendix E) New Recommendations · Web applications: Use HTTPOnly cookies. · Implement reflection and authentication relay defense. · NULL out free’d memory pointers in new code · All sample code should be SDL compliant · Internet Explorer 8 MIME handling: HTTP response sniffing opt-out · Lock ActiveX controls to a defined set of domains · Verify use of ClickJacking defenses in code Verification Phase (2 new, 2 updates) New/Updated Requirements · Network fuzzing: Any new network parsers must be able to accept 100,000 malformed packets without failure · Update: Web applications: Use ViewStateUserKey or ValidateAntiForgeryTokenAttribute against CSRF attacks · Update: Do not use banned APIs in old or new code New Recommendations · Web applications: Use a passive security auditor Feel free to email ask questions via the email feature in the blog or the comments section below. Jeremy Dallman here. Earlier today, Errata Security released the results of their survey: Integrating Security into the Software Development LifeCycle. This survey was conducted over a two-week period and gathered information from 46 different companies both online and at events around the RSA 2010 Conference. It was specifically designed to ask people in the software development community about how they integrate security solutions into their development lifecycle. We were very glad to see that most companies surveyed have integrated security activities into their development organizations. We were also very encouraged by the awareness and implementation of the Microsoft SDL and Microsoft SDL-Agile methodologies. This provides some great validation that the SDL we apply to Microsoft products is transferrable to other software development organizations. The result of more secure software is a more secure software ecosystem and more secure customers. If you are using (or considering using) the Microsoft SDL or SDL-Agile methodologies in your organization, we welcome your feedback and recommendations for what you would like to see in the SDL moving forward. Jeremy Dallman here. I wanted to let you know about a great paper from Fortify, one of our newest SDL Pro Network Tools members. The paper highlights the Microsoft SDL approach to secure software development and shows how Fortify’s security solutions can help you implement the SDL and create/deploy more secure software. At RSA 2010 last week, Fortify published a paper titled Optimizing the Microsoft SDL for Secure Development: Fortify Solutions to strengthen and streamline a Microsoft SDL Implementation. This paper does an excellent job of explaining the challenges of developing secure software, detailing the Microsoft SDL approach to secure software development, and mapping Fortify’s solution offerings to each SDL Practice based on the Simplified Implementation of the SDL. If you are looking for tools to support your implementation of the SDL, I would encourage you to read through Fortify’s paper to see if their solutions can help you. Jeremy Dallman here to let you know we published a couple of new interesting Microsoft SDL stories last week in an effort to continue demonstrating in a tangible and easy-to-read way how Microsoft teams implement the SDL. We hear about more companies investigating how they can integrate the Microsoft SDL into their software development process in order to ship more secure software. At Microsoft, we have been doing this for several years, but have only recently shared the stories behind how our product teams do the SDL (see SDL Publications – whitepapers). As Windows Internet Explorer 8 and the 2007 Microsoft Office System were publicly released, the security experts that guided those products through the full Security Development Lifecycle saw an opportunity to share some details about how each of these products executed on the SDL. They have written the stories of the SDL for each of these products. Internet Explorer 8 and the Security Development Lifecycle These papers can serve as a reference tool as you begin to think about the implementation of the SDL in your own software development lifecycle. The Microsoft SDL has been in place at Microsoft for almost six years and has demonstrated its effectiveness in improving software security. We hope that these papers along with the SDL Optimization Model, the Simplified Implementation of the Microsoft SDL whitepaper, and our other resources on the SDL portal will help you as you begin integrating the Microsoft SDL into your own software development process. If you are starting to think about adopting the SDL or already have created your own version of the SDL, we would love to hear from you! Feel free to either tell us in the Comments section of this post or email us directly. Adam Shostack here. I’m pleased to announce that at RSA this week, Microsoft is releasing Elevation of Privilege, the Threat Modeling Game. Elevation of Privilege is the easiest way to get started threat modeling. EoP is a card game for 3-6 players. Card decks are available at Microsoft’s RSA booth, or for download here. The deck contains 74 playing cards in 6 suits: one suit for each of the STRIDE threats (Spoofing, Tampering, Repudiation, Information disclosure, Denial of Service and Elevation of Privilege). Each card has a more specific threat on it. For example, here’s the 5 of Tampering. The threat is “an attacker can replay data without detection because your code doesn’t provide timestamps or sequence numbers.” Because we want everyone developing software to threat model, and there’s no better way to get people to do what you want than to ensure they have fun while doing it. Everyone in software draws diagrams. From pictures on napkins or whiteboards to DFDs, UML or other formalisms, everyone diagrams. When you’re done (all the cards have been played), count up the points, give the winner a pat on the back, and have someone file bugs. That may seem a little complex, but it’s pretty simple when you have cards in hand. There’s a video of me explaining the game here and of people playing on the launch page. There’s also a strategy card in the deck with a flowchart to help you decide what card to play. Right now! If you’re at RSA, come by the Microsoft booth, or download the cards here If you’re developing software, this is for you. We’d love to hear your feedback here, we’d love for you to blog about it, but most of all we’d love for you to play Elevation of Privilege. Once you have, we’d also like you to play with the idea of serious games for threat modeling and security. To help you get started, we’re making Elevation of Privilege available under a Creative Commons Attribution license which gives you freedom to share, adapt and remix the game. I want to thank Austin Hill of Akoha for introducing me to the wide field of serious games (see http://www.seriousgames.org/ or http://en.wikipedia.org/wiki/Serious_game for some more on the broad concept), and Laurie Williams of North Carolina State University for designing “Protection Poker,” which inspired me to design Elevation of Privilege. On Friday, the team at Microsoft that’s driving our End to End Trust initiative launched a new web site that provides an update on the End to End Trust vision for a more trustworthy and accountable Internet. The site’s launch was timed to precede Scott Charney’s keynote next Tuesday at the RSA Security Conference in San Francisco. The site will be updated later that day with a video of Scott’s keynote. One of the key components of the End to End Trust vision is what we refer to as “Security and Privacy Fundamentals” – the recognition that better authentication and accountability are only effective if the underlying computer systems are built to resist attack and the intrusion of unwanted software. At Microsoft, the way we build systems to resist attack is by implementing the SDL for any products or online services that expose our users to risk. The End to End Trust site includes several videos about the SDL and its role in End to End Trust, as well as links to details posted on the SDL web site. I’d encourage you to review the End to End Trust site, Scott’s video when it’s posted, and of course the SDL information on both the End to End Trust and SDL web sites. Steve Lipner Hi everyone, if you’re headed to RSA next week be sure to check out these sessions featuring SDL team members: Wednesday, March 3, 9:10 AM Katie Moussouris and Bryan Sullivan (A preview of this session is available as a podcast at https://365.rsaconference.com/blogs/podcast-series-rsa-conference-2010/2010/02/19/and-202-microsoft-sdl-tools-automating-the-security-development-lifecycle-pk-session.) Wednesday, March 3, 9:10 AM David Ladd, Eric Baize (EMC), Gary McGraw (Cigital), Richard Pethia (Carnegie Mellon University) Wednesday, March 3, 10:40 AM Katie Moussouris, Martin McKeay (Network Security Blog), Brad Arkin (Adobe Systems), Tim Stanley (Continental Airlines), Steve Dispensa (PhoneFactor), Michael Barrett (PayPal), HD Moore (The Metasploit Project) (A preview of Katie Moussouris speaking on the topic of Responsible Disclosure can be found at https://admin.secure.streamos.com/streamos/player/flv/?url=http://rsa.edgeboss.net/flash/rsa/rsaconference/2010/us/podcasts/rsac_02-03-10-hot-203-moussouris.mp3.) Thursday, March 4, 1:00 PM Adam Shostack and Danny Dhillon (EMC)
The Security Development Lifecycle
I’m looking forward to seeing some of you next Tuesday in Las Vegas!
Test engineering changes for functionality tests
Engineering changes in the product
A Banned API extension to the Visual Studio 2010 IDE
Links to related articles
[SA_Pre (Null=SA_No,ValidBytes="cb")]
[SA_Pre(Deref=1,Valid=SA_Yes)]
[SA_Pre(Deref=1,Access=SA_Read)] BYTE* pBuf, size_t cb );
_In_bytecount_(cb) BYTE* pBuf,
size_t cb );What
Why
How
When
Who
Acknowledgements
AND-202: Microsoft SDL Tools: Automating the Security Development Lifecycle
EXP-202: Picking a Yardstick to Measure Your Software Security Practices
HOT-203: Responsible Disclosure: It’s Their Fault!
AND-304: Threat Modeling: Lessons Learned & Practical Ways to Improve Your Software
PayPal Support Club. Review and helpful links, coding examples, warnings, other shopping cart links, etc. PayPal is a on-link banking system that allows website owners to integrate shopping cart technology into their site. Find out more, includes links to helpful site about PayPal shopping cart technology. Report eBay spoof emails to spoof@ebay.com Report spoof PayPal emails to spoof@paypal.com
| Yoggie Internet Security Systems at CES 2009 | ||
| Yoggie main website |
Hacktivism is the writing of code, or otherwise manipulating bits, to promote political ideology. Taking Lessig's message to heart, hacktivism believes that proper use of code will have leveraged effects similar to regular activism (or civil disobedience). Fewer people can write code, but code affects more people. myWiseOwl
Security Protector Free security utility enables you to protect your PC by disabling some features like: use of the MS-DOS command prompt in Windows and real mode DOS applications from within the Windows shell.
PC WIZARD is a powerful utility designed especially for detection of hardware, but also some more analysis. It's able to identify a large scale of system components and supports the latest technologies and standards. This tool is periodically updated (usually once per month) in order to provide most accurate results.
CPU-Z is a freeware that gathers information on some of the main devices of your system. Name and number. Core stepping and process. Package. Core voltage. Internal and external clocks, clock multiplier. Supported instructions sets. All cache levels (location, size, speed, technology).
System Monitor. This software lets you keep your eye on system resource usages of your PC. It currently supports 27 kinds of information including CPU, Memory, Network, and detailed HDD usages.
My Lockbox is a security software enabling you to password protect folders on your computer. The protected folder is hidden and locked from any user and application of your system and also from the net. To access the protected folder you have to provide a valid password.
Diag Plus Diagnose registry problems from DOS. From WindizUpdate (62NDS Solutions Ltd.) More Hardware links
AIM Encryption Certificate Generator You can use this tool to generate a security certificate file that you can import into AIM. You can then have encrypted conversations with any other member who also has imported a security certificate. The certificates produced by this tool are generated on demand, and no two certificates will share the same private key. This means that the certificates produced here are much more secure than the one certificate being mass distributed at AIM Encrypt - Free Security Certificate for AIM
AIM Encrypt - Free Security Certificate for AIM! Encryption certificate. Why do I want AIM Security? AIM is known to not have the best security, or any for that matter. If someone on your network is using a "packet sniffer" or other type of traffic analyzing tool they can see your AIM conversations and read them word for word. AIM Security using SSL Certificates makes your conversation appear much like trash to anyone analyzing what you type much like "Sw43jg73js7HSkg8Skeq3k65" instead of "Hello Friend". This certificate encodes the message so only the sender and the receiver can read the message. But still please use common sense and don't send credit card numbers, etc. over IM, this should only make you about "this" much safer on the internet, and make you feel cool having a padlock next to your name
SSL, Secure Socket Layer. This is a system used to protect secure information, for example credit card, bank account details, etc. Most sites that use this system will have URL's that start with https:// ,( note the "s" ), instead of the normal unprotected http://
The sites that use SSL, Secure Socket Layer may also display a small padlock image in the Task Bar. You should not send private or sensitive information of any type without using the SSL, Secure Socket Layer method.
The Secure Sockets Layer protects data transferred by using encryption enabled by a server's SSL Certificate. Uses a public key and a private key. A public key is used to encrypt, (note that some systems may have different levels of encryption but this should not be any less than 128 bit encryption), information and a private key is used to decipher it. When a browser points to a secured domain https://, a SSL handshake authenticates the server and the client and establishes an encryption method and a unique session key.
The GNU Privacy Guard. GnuPG is a complete and free replacement for PGP. Because it does not use the patented IDEA algorithm, it can be used without any restrictions. GnuPG is a RFC2440 (OpenPGP) compliant application. OpenPGP is the most widely used email encryption standard in the world. It is defined by the OpenPGP Working Group of the Internet Engineering Task Force (IETF) Proposed Standard RFC 2440. The OpenPGP standard was originally derived from PGP (Pretty Good Privacy), first created by Phil Zimmermann in 1991. PGPdump Interface OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured, and Open Source toolkit implementing the Secure Sockets Layer and Transport Layer Security protocols as well as a full-strength general purpose cryptography library. The project is managed by a worldwide community of volunteers that use the Internet to communicate, plan, and develop the OpenSSL toolkit and its related documentation. Apache-SSL SSL 3.0 specification, Netscape. RSA security
Get Safe Online will help you protect yourself against internet threats. The site is sponsored by government and leading businesses working together to provide a free, public service.
Bank Safe Online sets out simple steps you can take to help keep safe online. We also provide you with updates on the latest scams, and enable you to report any suspicious emails or websites to us direct.
Advanced WindowsCare Repair and fix windows with 1-click. Slow down, freeze and blue-screen crash are over. Advanced WindowsCare thoroughly examines the Windows system, accurately detects the bottlenecks for slowing down and crashing, fixes these problems and repairs Windows. All work will be done with 30 seconds and 1 click. The intuitive interface makes Advanced WindowsCare the perfect tool for Non-IT professionals
Free Internet Window Washer is a free privacy cleaner to remove internet tracks and computer activities. It can erase Window®:s temp folders, run history, search history, recent documents, browser's cache, cookies, history, typed URLs, autocomplete memory, index.dat files, and more. You can also easily erase the tracks of up to 100 popular applications. It also provides you option to clean the data more securely so that they could not be recovered.
Home Office Identity Fraud Steering Committee What is Identity theft? Your identity and personal information are valuable. Criminals can find out your personal details and use them to open bank accounts and get credit cards, loans, state benefits and documents such as passports and driving licenses in your name.
CIFAS, (Credit Industry Fraud Avoidance Scheme), the UK's Fraud Prevention Service. CIFAS is a not for profit membership association solely dedicated to the prevention of financial crime. CIFAS provides a range of fraud prevention services to its members, including a fraud avoidance system used by the majority of the UK's financial services companies.
Card Watch raises awareness about all types of plastic card fraud in the UK, and provides information to prevent fraudulent use of credit cards, debit cards, cheque guarantee cards and charge cards.
The Council of Better Business Bureaus and BBB OnLine Complaint System. The BBB does not take sides in a dispute. The BBB works to facilitate communication between the company and the consumer, to help both sides come to a satisfactory resolution to the complaint. In many cases, dispute resolution, including mediation and arbitration, may be available to help resolve the dispute.
The European Telecommunications Resilience and Recovery Association (ETRA) is a European forum for discussion, debate and information. Based in the UK it aims to extend understanding of the relationship between telecommunications, information assurance, security, disaster management and corporate governance.
WARPs (Warning Advice and Reporting Points). WARPs are part of the Centre for the Protection of National Infrastructure Security information sharing strategy to help combat the increasing risk of electronic attack on our information systems.
Center for the Protection of National Infrastructure. Information sharing strategy to help combat the increasing risk of electronic attack on our information systems.
Securityvulns Computer Security Vulnerabilities. Reports on Vulnerabilities in software and hardware:-securityvulns.com vulnerabilities newsline
Iirongeek. Adrian Crenshaw's Information Security site (along with a bit about weightlifting and other things that strike my fancy). Articles and tutorials.
CERT® Coordination Center (CERT/CC) is a center of Internet security expertise, located at the Software Engineering Institute, a federally funded research and development center operated by Carnegie Mellon University.
The National High Tech Crime Unit:- National unit formed in April 2001 comprising personnel from the National Crime Squad, the NCIS, and from HM Customs & Excise. It works in conjunction with computer crime units in UK police forces.
National crimes quad police UK The National Crime Squad works at the heart of tackling serious and organised crime.
Internet Crime Complaint Centre:- An American organisation which is a partnership between the FBI and the US National White Collar Crime Center. Its mission is to address fraud committed over the Internet and it includes a reporting mechanism through which people can alert authorities to a suspected criminal or civil violation.Computer Crime and Internet-Related Crime The Metropolitan Police Service.
National Crime Prevention Council's (NCPC) mission is to prevent crime and build safer, more caring communities.
Terrorist Activity Report Them Here (FBI) Federal Bureau of Investigation. Stop and report terrorists United States of America
CRIMESTOPPERS United Kingdom. Call anonymously with information about crime.
MI5 the official website of the UK Security Service (MI5) are responsible for protecting against threats to United Kingdom National Security, such as terrorism and international terrorism. If you know something about a threat to National Security. STOP and report terrorists.
Blocking Unwanted Parasites with a Hosts File and other security tips.
Fraud:- Attention Footie fans! Following discussions with the European Commission FIFA has agreed to accept more ticket payment methods in the next stages of ticket allocation for the 2006 World Cup in Germany. Watch out for the latest scam - an e-mail that pretends to come from FIFA, telling you that you've got a ticket to the World Cup. It carries a mass-mailing worm. The advice, as always, is not to open attachments in such e-mails, (use anti-spam software), and to ensure that your Anti-Virus Software Tools & Utilities protection is up to date.
SPIM & SPIT (SPIM, SPam using Instant Messaging), is another new spamming technique, the difference in this case being that the spam is delivered through Instant Messaging rather than email. It's not as common as email spam. According to a report from Ferris Research, 500 million IM spam were sent in 2003, twice the level of 2002. As it becomes more common, spim could affect businesses in the same way that email spam does now, creating security problems and costing time and money. SPIM stands for Spam over Internet Telephony. It's essentially like spam email, only rather than getting unwanted messages in your inbox, they're left on your voicemail. It can happen if you're using a phone connected to the Internet, something more and more people are choosing to do. VoIP, ( Voice over Internet Protocol ), addresses or may hack into a computer used to route VoIP calls. And, because calls routed over IP are much more difficult to trace, there's a far greater potential for fraud.
Yahoo Security information and advice
Yahoo Hacking. Social Engineering, Phishing information (Faux is a French work used to describe something made to resemble something else. The original French word means false, fake, imitation or artificial.)
Yahoo Reporting Password Scams
Free PC Scan Windows Registry Repair
PC Security Software PCSecurityShield. Protection Range. Anti-virus, Firewall, Privacy Defender, Spam Shield, Popup Blocker, Delete files PERMANENTLY, etc...
Department of Trade and Industry Notes
SiteAdvisor. We test the Web to help keep you safe from spyware, spam, viruses and online scams.
APNIC Spammers & hackers : Using the APNIC Whois Database to find their network | Spam | Hacking
!exploitable, (pronounced "bang exploitable") Crash Analyzer, (!exploitable Crash Analyzer - MSEC Debugger Extensions). A plugin for the Windows Debugger that parses your crash logs and gives you two important pieces of information. First, it will collate all of your crashes and determine exactly how many there actually are. So for example, out of 60 crash reports, there may only be 2 or 3 actual problems. The second thing it does is look at the type of crash and try to determine if the error is something that could be exploited by a malicious hacker. This means that more junior employees can work these bug issues without taking the time of more senior examiners. More Microsoft Windows Links.
Web Master Tools and Utilities
Scurity wonks.org Forum
Alliance of Security Analysis Professionals (ASAP).
Keylogger Hunter - Detects Keyboard Monitoring Programs
Help maximize your security with the Internet Explorer High Encryption Pack.
| 5 Steps for Preventing Employee Fraud | ||
| What you can do to avoid it. By Abby Johnson Did you realize that a typical organization loses up to 5 percent of its annual income to fraud? This information is one result of an annual survey of Certified Fraud Examiners conducted by the Association of Certified Fraud Examiners. As reported in the video these losses could be very harmful to small businesses. |
UBCD4Win Bootable CD Repair/Restore/Diagnose etc for Windows®.
DomainKeys: Proving and Protecting Email Sender Identity (Information by Yahoo) Email spoofing, (and Phishing) - the forging of another person's or company's email address to get users to trust and open a message - is one of the biggest challenges facing both the Internet community and anti-spam technologists today. Without sender authentication, verification, and traceability, email providers can never know for certain if a message is legitimate or forged and will therefore have to continually make educated guesses on behalf of their users on what to deliver, what to block, and what to quarantine, in the pursuit of the best possible user experience.
DNSSEC, (DNS Security ExtensionSecuring the Domain Name System).
Brit holds the 'key to the Internet. (Reboot the web if it Goes down) From Yahoo News. The CommunityDNS is made up of a team of specialists that created a security system, known as DNSSEC, (DNS Security ExtensionSecuring the Domain Name System).
Net Tools is a comprehensive set of host monitoring, network scanning, security, administration tools and much more, all with a highly intuitive user interface. It's an ideal tool for those who work in the network security, administration, training, internet forensics or law enforcement internet crimes fields.
Phishing. A lot of Major banks, Credit Card operators, e-Commerce Sites, Visa, PayPal, (PayPal Support Club), and eBay, (also many other websites), have suffer from Phishing. This is where people were directed to a fraudulent website that is identical to the companies' sites in the hope that they will supply details so they can be used illegally.
Anti-Phishing Working Group - Committed to wiping out Internet scams and fraud.
Phishing Report The Phish Report Network (PRN) was established to address the growing problem of phishing. As the industry's first anti-phishing aggregation service, PRN enables companies to better protect consumers against online fraud.
Know your Enemy: Phishing Behind the Scenes of Phishing Attacks. The Honeynet Project & Research Alliance.
FireFox Browser A Mozilla project, empowers you to browse faster, more safely and more efficiently than with any other browser.
Internet Watch Foundation Site Index (Legal issues. Reports illegal and offensive Internet Issues.)
SafeSurf Creating a Safe Internet Without Censorship Help Us Accomplish This Goal.
EFF is a nonprofit group of passionate people & lawyers, volunteers, and visionaries working to protect your digital rights.
Copyscape Search for copies of your page on the Web. Defend your site a against plagiarism.
Rules for Uniform Domain Name Dispute Resolution Policy (the "Rules") (As Approved by ICANN on October 24, 1999)
http://www.icann.org/udrp/udrp-rules-24oct99.htm or http://www.icann.org/udrp/udrp-rules-24oct99.htm
Domain Name Transfer's ICANN Inter-Registrar Transfer Policy.
UKReg Domain Name Dispute Policy
Nominet Disputes account all registrations in the .uk Top Level Domains.
Domain Name law (Sedo)
eSecurity4Britain Inform, educate and provide protective measures to ensure small businesses can use the internet to operate their businesses - with security.
7Safe is an Information Security services firm offering a diverse portfolio of services including security training & certification, penetration testing, computer forensics and risk management (including BS 7799).
Police United Kingdom UK Police Service portal.
Ofcom is the independent regulator and competition authority for the UK communications industries, with responsibilities across television, radio, telecommunications and wireless communications services.
Association of Certified Fraud Examiners The ACFE is an anti-fraud organization and provider of anti-fraud training and education. Tthe ACFE is reducing business fraud world-wide and inspiring public confidence in the integrity and objectivity within the profession.
Check premium rate numbers ICSTIS, Independent Committee for the Supervision of Standards of the Telephone Information Services- the premium rate services regulator.
Also view our Scams and hoaxes. Fraud warnings. Virus Attacks.
SquareTrade eBay User Support. Trouble with a transaction? SquareTrade can help you resolve issues independently or through professional mediation.
eBay Safe Harbor - SafeHarbor is eBay's safety resource and protective arm, and should be used for eBay fraud issues only. Fraud reports and insurance claims may be filed through Safe Harbor.Federal Trade Commission - As part of an international group of consumer protection agencies, the FTC monitors an online complaint site called econsumers.gov. Although they do not resolve individual consumer problems, complaints are used to help investigate fraud, and can lead to law enforcement action.
National Fraud Information Center - The NFIC helps consumers distinguish between legitimate and fraudulent promotions in cyberspace and route reports of suspected fraud to the appropriate law enforcement agencies.
Mobile Industry Crime Action Forum. An organisation set up by the United Kingdom mobile telecommunications industry, including mobile handset manufacturers, to address the issues of mobile phone theft.
Security Focus Magazine (Phishing Forensics)
Federal Trade Commission (Anti-Phishing)
Better Business Bureau (Anti-Phishing)
Patents: Commission proposes rules for inventions using software
Wireless Security Issues from our page WAP, WML, Wireless Markup Language, Wireless links, Wi-Fi, BlueTooth, PixeCode, PDF414, Semacode, Datamatrix, radio links.
Safe Options Safe Options is the UK's leading online security store. Buy Safes, Lockers, Convex Mirrors and Key Cabinets online from our UK security store. We supply fire safes and security safes to both Business and Home Safe Users Buy Safes on 30 Day terms - available for recognised UK institutions FREE DELIVERY OF SAFES and LOCKERS ON THE UK MAINLAND* (*Ground Floor with easy access except N.Ireland and Islands)
Homeland Security Threat Monitor (United States of America). A small Windows application that runs in your system tray, showing the current terrorism threat level. It periodically checks to make sure the information is up to date by contacting the Department of Homeland Security web server. Establish an emergency preparedness kit and emergency plan for themselves and their family, and stay informed about what to do during an emergency.
The Open Web Application Security Project released a helpful document that lists what they think are the top ten security vulnerabilities in web applications.
Host Files. You can begin blocking ads and help keep yourself from being tracked by using the Hosts file with Windows and other operating systems.
Microsoft Diagnostics and Recovery Toolset. 30 day evaluation of the Microsoft Diagnostics and Recovery Toolset. This product provides powerful, intuitive tools that help administrators recover PCs that have become unusable, and easily identify root causes of system issues. This toolset is part of the Microsoft Desktop Optimization Pack.
eBay Help about how to spot a Spoof emails
Reporting eBay Account Theft, If you feel your account has been compromised, please report it.
Cut down eBay monopoly and the sale of counterfeit goods. Sign this petition There is a massive silent minority, out there, that have suffered injustice or have lost money through eBay and their sister company PayPal. It is silent because there is no one and nowhere where one could place a complaint.New PayPal phishing scam uncovered The email, which purports to come PayPal, claims that the recipient's account has been the subject of fraudulent activity. However, unlike normal Phishing emails, there is no internet link or response address. Instead, the email directs the recipient to call a phone number and verify their details. When dialled, users are greeted by an automated voice saying: "Welcome to account verification. Please type your 16 digit card number." Once the credit card details are entered, the scammer is free to steal the credit information for their own use. Spyware analysts SophosLabs are warning users not to respond to the email. Graham Cluley, senior technology consultant at Sophos said "Though it's an American telephone number, the fact that PayPal is used globally means that anyone could potentially be tricked into making the call." More SpyWare Removal Links.
PayPal Support Club. Review and helpful links, coding examples, warnings, other shopping cart links, etc. PayPal is a on-link banking system that allows website owners to integrate shopping cart technology into their site. Find out more, includes links to helpful site about PayPal shopping cart technology.
Freenet is free software which lets you anonymously share files, browse and publish "freesites" (web sites accessible only through Freenet) and chat on forums, without fear of censorship. Freenet is decentralised to make it less vulnerable to attack, and if used in "darknet" mode, where users only connect to their friends, is very difficult to detect.
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which enable malicious attackers to inject, client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Their impact may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site, and the nature of any security mitigations implemented by site owner.
Also read Methods of Internet adverting
Click Fraud Protection and Click Fraud Security
Scams and hoaxes. Fraud warnings. Virus Attacks
Backup/File Compression Data Recovery
Protect your Usernames and passwords. Protect your system
Disaster Recovery Planning. (Also Undelete Files) So how good is your Disaster Recovery Planning?
Anti-Virus Software Tools & Utilities
Web Master Tools and Utilities
Forums. Computing Forums. Webmaster Forums, Programming Forums
Terrorist Activity Report Them Here (FBI) Federal Bureau of Investigation. Stop and report terrorists United States of America
CRIMESTOPPERS United Kingdom. Call anonymously with information about crime.
MI5 the official website of the UK Security Service (MI5) are responsible for protecting against threats to United Kingdom National Security, such as terrorism and international terrorism. If you know something about a threat to National Security, STOP and report terrorists.
Police United Kingdom UK Police Service portal.
Web Masters. Click Here Now to start making money. A Great opportunity to make some money. Receive 50% by offering your users Ton's of Keywords on A Great Portal websites. Our Affiliate Program Pays you 50% on Level 1 of Every Sale of our Text Link both searchable and static Text Link!
A Computer Portal. Freeware, Shareware. Download software. Computer languages and Programming code. Including PERL Scripts and Java Scripts. Webmaster Tools. Internet Marketing, Website promotion. Hardware Help from BIOS to Windows and UNIX.
® © ™ are owned by respective authors and websites. There may be a charge for some software. Google™ is a trademark of Google Inc, These pages are not endorsed by Google or any other Company