Archive for August, 2006

Avoiding Data Disasters: Managing Risk from Undiscovered Sensitive Data

Wednesday, August 30th, 2006

Where does sensitive data exist in your organization? Where is it hiding, how does it flow through your systems, and who really has access? If you think you know the answers, think again.

In most companies, recognized data represents just the tip of the iceberg, while undiscovered sensitive data lurks below—posing a serious but preventable compliance risk.

Join this one-hour Webinar to explore what you can do to prevent costly and embarrassing data breaches.

Topics that will be covered:

  • How unintended data exposure happens, including case examples
  • Risk concepts every technie should be able to discuss with business users
  • Specific compliance requirements including PCI, Gramm-Leach-Bliley, and HIPAA
  • Checks and balances even small organizations must have in place to protect sensitive data
  • Capital costs and risks stemming from sensitive data exposure
  • Best practices for data relationship discovery and de-identification

(more…)

Cisco Warns of Flaw in Firewall Products

Wednesday, August 30th, 2006

An alert from Cisco Systems Inc. describes an unintentional password modification vulnerability in multiple firewall products that could be exploited to change passwords without user interaction and allow “unauthorized users to gain access to a device that has been reloaded after passwords in its startup configuration have been changed. Authorized users can be locked out and lose the ability to manage the affected device.”  

The flaw affects Cisco PIX 500 Series Security Appliances, Cisco ASA 5500 Series Adaptive Security Appliances and Firewall Service Module (FWSM) for Cisco Catalyst 6500 switches and Cisco 7600 Series Routers running affected versions of the software.

Cisco has issued software to address this vulnerability.  A second alert from Cisco describes a pair of flaws in Cisco VPN 3000 series concentrators with FTP file management enabled that could be exploited to execute some FTP commands and delete files.  Cisco has issued free software to address these two flaws and also made workarounds available.
http://www.cisco.com/en/US/products/products_security_advisory09186a00807183b0.shtml
http://www.cisco.com/en/US/products/products_security_advisory09186a0080718330.shtml

The 5th Annual Philippine IT Security Conference - MANILACON 2006: Progress@Risk

Tuesday, August 29th, 2006

5th Annual Philippine IT Security Conference
September 11- 12, 2006
Hotel Intercontinental
Makati City, Philippines 

This year’s 5th Information Systems Security conference and exhibit is dubbed: “ManilaCon 2k6:progress@risk” and is organized by the Information Systems Security Society of the Philippines (ISSSP), in cooperation with the Commission on Information and Communications Technology (CICT) and the National Security Council (NSC) towards the development and implementation of a National Cyber Security Strategy.

We need one to ensure the integration of public and private efforts to counter threats and institutionalize the protection of national and local cyber infrastructures and businesses.

We expect all security concerned CEOs, CIOs, Security Officers and Systems Administrators/Programmers to be more vigilant in securing cyberspace, not just for the protection of their respective enterprises but for the protection and security of all those existing and doing business in cyberspace.

This conference and exhibit is designed to kick-start this national effort and concern.

To join, please see below, details of the program schedule and delegate fees.

For registration or more information, please call Ellen at the ISSSP Secretariat telefax no. 750-3742 or mobile 0920-2413954. Or send email to isssphil[at]yahoo.com. You may also visit http://www.isssp.org.ph/ for other details of this conference and exhibit and/or to register online.

Signed: 

AMADO A. MALACAMAN, JR., President – ISSSP             

Angelo Timoteo M. Diaz De Rivera,  Commissioner – CICT

(more…)

Unified Multi-purpose ID System to be Implemented Soon

Monday, August 28th, 2006

The National Statistics Office and National Economic Development Authority are pilot agencies in the implementation of Executive Order No. 420 otherwise known as the Unified Multi-purpose Identification (UMID) system issued by President Gloria Macapagal Arroyo, directing government agencies under the executive branch to harmonize identification systems and adopt a uniform ID data collection and format.

According to Catalino G. de Gracia, Statistician II, of the local NSO UMID will give people easy access to government transactions. “It will start with the NSO and NEDA this year, then to all government agencies by January 2007 and eventually to the local government units”, he said. “It will not violate the individual’s right to privacy since it only ask the basic information about the person, similar to our Office or Government Security Insurance System(GSIS) ID cards”, he stressed.

(more…)

Global Security Week 2006 — Identity Theft

Sunday, August 27th, 2006

Global Security Week 2006, the week leading up to September 11th each year, is an opportunity to join forces with other security professionals worldwide and promote security to the masses. The theme for Global Security Week 2006 is identity theft. Find out about the truth behind the headlines. Is “phishing” a genuine threat? What are the banks doing about it? What can ordinary members of the public do about it? Participate in Global Security Week to help spread the word about identity theft and encourage ordinary law-abiding citizens to be on their guard.

http://www.globalsecurityweek.com/index.html

Security Solutions Virtual Tradeshow

Friday, August 25th, 2006

Security Solutions Virtual Tradeshow
Balancing the Need for Heightened Security and Increased Access

Wednesday, September 13 & Thursday September 14, 2006 Today’s CIOs and IT managers face a daunting task: protect their network from viruses, spyware and the latest threat du jour—phishing and keyloggers to ransomware and cyberextortion. They must also ensure that their IT spending helps their company comply with legislation, maintain internal and perimeter security, and protect information assets and personal data. But, it doesn’t end there–IT executives must contend with an increased reliance on wireless networks, smart phones, instant messenger, P2P and VoIP.  That is the mandate and there is no way getting around it.

New tools and technologies provide widespread access to enterprise users, but they also demand improved security strategies and policies. As IT managers develop more sophisticated security strategies, more complex and damaging threats will be unleashed that drain time and resources. It’s an uphill battle and it’s all in a day’s work for an already overtaxed IT department.

(more…)

Antivirus Researcher Gullotto of Symantec is Now With Microsoft

Thursday, August 24th, 2006

Microsoft has hired one of the industry’s top antivirus researchers to run its nascent antivirus research and response team.Vinny Gullotto, who had been at Symantec Corp. since earlier this year, started work at Microsoft last week. His charge at Microsoft will be to help the software giant get its virus response team up to speed with those run by the major antivirus vendors.

Gullotto will be the general manager of Security Research and Response, a separate unit from the Microsoft Security Response Center (MSRC); both teams fall under Microsoft’s Security Technology Unit.

(more…)

Kevin Mitnick’s Website Hacked Anew

Thursday, August 24th, 2006

Digital vandals defaced the Web site of hacker-turned-security-consultant Kevin Mitnick over the weekend, replacing information on his books and consulting services with foul language.

According to CNET News.com, the vandals, who are reportedly based in Pakistan, hacked into the machine hosting Mitnick’s site, removed his front page and put their own page in its place. The defacement affected four of Mitnick’s Web addresses, including KevinMitnick.com and MitnickSecurity.com.

“The Web hosting provider that hosts my sites was hacked,” Mitnick told CNET News.com. “Fortunately, I don’t keep any confidential data on my Web site, so it wasn’t that serious. Of course it is embarrassing to be defaced — nobody likes it.”

Mitnick gained notoriety as a hacker who was caught by the FBI in 1995 after a much-publicized pursuit. He served a five-year prison sentence for wire and computer fraud and later became a security consultant and author, traveling the lecture circuit.

IBM to Acquire ISS - Internet Security Systems

Thursday, August 24th, 2006

Wednesday morning IBM announced it would acquire the Atlanta-based security vendor for approximately $1.3 billion in cash. The move is expected to augment the managed security services offerings in Big Blue’s global services unit.

ISS customers will benefit from IBM’s vast resources while Big Blue gets a comprehensive perimeter security service, analysts say. However, long-term stumbling blocks remain. Most notably, IBM needs a plan to ensure it can retain ISS’s talented staff.

More details about the acquisition @

IBM to Acquire Internet Security Systems

IBM/ISS Deal Positive for Customers

Phishing Scams Target PNB - Philippine National Bank

Wednesday, August 23rd, 2006

I recently came across emails that at first glance came from a local bank — PNB Philippine National Bank.

I know for a fact that it is a phishing scam since I don’t have a bank account with PNB ;-)

Click on the links below for a screenshot of the PNB Phishing emails.

PNB Phishing Email # 1

PNB Phishing Email # 2