Sprinkling on the Magic FISMA Fairy Dust

Posted July 30th, 2007 by

I promised myself I would stop with the vendor bashing at least long enough to catch my breath. Well, sometimes in your life something comes along that you just can’t help but comment on.

Press release on how a network emulator can help with FISMA reporting.

This class of products is great–simulated network lag so you can test your network devices, software, etc. Every lab should have this stuff.  I’m pretty sure that some of it is inside my building in the various replicas of customer networks that the engineers use.

But what does this have to do with information security management? Once again, it’s sprinkling the magic FISMA fairy dust and wishing that it makes your product a security device.  Makes me had the”make it secure” wand (complete with star on end and ribbons) that one CISO I know of carries about just for the purpose of being able to wave it around and say “*Poof* It’s secure now.”  I figure happy thoughts are in there somewhere, but I’m just not seeing the exact mechanism.

My friends have a theory that I should start selling SOX socks and FISMA underwear. I’m not so sure about that, but I figure if it works for all these other products, it might be a massive moneymaker for me.  =)



Similar Posts:

Posted in FISMA, Technical, The Guerilla CISO, What Doesn't Work | 1 Comment »

Managing Security in Large Organizations

Posted July 27th, 2007 by

Interesting news article about some of Boeing’s problems.

This is an industry problem, one that we don’t talk about too much, and the heart of it is that it’s hard to manage security in huge organizations. Sure, there is the infosec frameworks like 7799/27001, FISMA, etc. If you look at the fairly undeveloped pieces of security, you’ll notice some trends:

  • At the tactical level, we know vulnerability scanning, exploit writing, and hardening standards.
  • At the operational level (Army sense of operational–we’re talking brigades and divisions here), we have risk management, certification, and my favorite whipping-boy, compliance.
  • At the strategic level, we have enterprise architecture, inventory management, and capital planning.

My opinion, and it’s purely opinion, is that as you progress up the ladder to strategy, there is less and less of a knowledge base and a higher rate of opportunity for charlatans. But then again, it echoes IT management in general–everybody knows how to build a fairly secure server, not a whole lot of people know how to manage IT infrastructure for 75K users.

Purely as a sidenote, ISM-Community is working to be a player in the operational and strategic area of security, I’m just trying to figure out how to get more people involved.



Similar Posts:

Posted in ISM-Community, The Guerilla CISO, What Doesn't Work, What Works | No Comments »

It’s Still not Too Late

Posted July 26th, 2007 by

Nominations for the Pwnie Awards are open until the 28th.  It’s still not too late to get in that last-minute nomination for your favorites.

Award categories:

Note that they don’t have a “Most Loveable but Still Harmless Curmudgeon who Obsesses about Flyfishing, Zombies, and a Whole Lot More” category because I could win it hands-down. =)

Deep inside the site is this link:  PNG (Portable Network Graphics) Deflate Heap Corruption Vulnerability complete with this song:

<Preamble>
Twas the night before Christmas, and deep in IE
A creature was stirring, a vulnerability
MS02-066 was posted on the website with care
In hopes that Team eEye would not see it there

But the engineers weren’t nestled all snug in their beds,
No, PNG images danced in their heads
And Riley at his computer, with Drew’s and my backing
Had just settled down for a little PNG cracking

When rendering an image, we saw IE shatter
And with just a glance we knew what was the matter
Away into SoftICE we flew in a flash
Tore open the core dumps, and threw RFC 1951 in the trash

The bug in the thick of the poorly-written code
Caused an AV exception when the image tried to load
Then what in our wondering eyes should we see
But our data overwriting all of heap memory

With heap management structures all hijacked so quick
We knew in a moment we could exploit this $#!%
More rapid than eagles our malicious pic came —
The hardest part of this exploit was choosing its name

Derek Soeder
Software Engineer
eEye Digital Security
</Preamble>



Similar Posts:

Posted in Hack the Planet, Technical | No Comments »

Volunteer to be Tracked

Posted July 26th, 2007 by

Robert Scoble has an interesting interview with founder and demo of Plazes.

It’s such a strange concept to me because I have spent most of my adult life making sure that people either didn’t track $us or to allow $us to track other people and what they are doing.  I just don’t buy off on the fact that people would volunteer their geolocation and current activity–I’m too much inclined to answer “Nun yo” if you ask where I’m at than I am to tell you the truth.

At this point about all I can do is shrug and say “Wow, the Web 2.0 kids are weird.” =)

Now all we need is for Al Qaeda to register and we’ll be golden.  “I’m sitting at a teastand in Quetta, here is my GPS grid and I’ll be here for a couple of hours.”



Similar Posts:

Posted in Army, Odds-n-Sods | 2 Comments »

Lions, Tigers, and VLANs Oh MY!

Posted July 25th, 2007 by

I’ve been courting with VLANs again this week.

For those of you who don’t habla routing and switching, VLANs are a way to carve out a virtual switch. You can share the VLANs over different physical switches using a technique called trunking, which comes in way handy.

Technically, it makes sense to take most (all?) of your switches and trunk them into one huge-gantic, gi-normous switch then do all the work withVLANs.  This is the “cram everything (router, firewall, and port modules) into one Catalyst 6500 chassis and have a nice day” approach which Cisco will gladly sell you.

Until you start looking at the typical setup. For DMZ servers (just about everything I deal with is in a DMZ of some sort), it’s fairly standard to have a switch (or any number thereof) sliced up by VLANs for different functions and then each VLAN segregated by a firewall.

The problem with this is when you put untrusted/external and  trusted/internal network segments on the same switch and use VLANs to separate them.  Basically what you’ve done is taken a “moderately robust security architecture” and configured it so that the switch is a single point of security failure.  That is, if you misconfigure or compromise the switch, you can bypass the firewalls.

In either case, being able to conduct a successful attack depends on misconfigurations which can happen anyway with firewalls, servers, and any other equipment that you own.  The real problem is that single-point-of-failure that the switch becomes.

My personal rules for using VLANs:

  • Don’t put untrusted/external and trusted/internal VLANs on the same switch.
  • Putting untrusted/external and semi-trusted/DMZ VLANs on the same switch is on a case-by-case basis.
  • Putting trusted/internal and semi-trusted/DMZ VLANs on the same switch is on a case-by-case basis.
  • Don’t trunk VLANs across trust boundaries.  IE, don’t mix up customer switches with our own switches.

I think the key for today’s CISO is that when people bring you drawrings of what the network looks like, you should get both a logical network drawring and a physical network drawing.  The differences between the 2 might shock you.  Usually when you’re asked to approve a design, you get the former and not the latter, so the usual caveats apply.

Further reading:



Similar Posts:

Posted in Risk Management, Technical, The Guerilla CISO | 2 Comments »

Wednesday Zombie Post–The Last Stand

Posted July 25th, 2007 by

The Last Stand

This is a good zombie defense game, just keep hitting the left mouse button, the grey shambling horde comes on strong and fast.



Similar Posts:

Posted in Zombies | No Comments »

« Previous Entries


Visitor Geolocationing Widget: