Followers

Wednesday, 20 February 2019

Controlling your weakest link

You’ve probably heard “An organization’s security is only as good as its weakest link”.  
Companies spend a tremendous amount of money, time, and energy on security products, services and software, thinking that these will be enough? But the bitter truth is that all it takes is one person to burst the bubble. A majority of all “major” attacks that exist today are due to a single mistake by a single person using Social engineering, a bad password, opening an email virus or something similar. That is why the weakest link in the data security chain is, and always will be, “human error”. 
User Behavior Analytics was defined by Gartner in 2014 as a category of cybersecurity tools that analyze user behavior on networks and other computer systems and apply advanced analytics to detect anomalies. These can be used to discover security threats like malicious insiders and privileged account compromise, which traditional security tools cannot see. 
So, the question arises how does a company analyze the behavior of its employees. 
The User Threat Quotient (UTQ) report provided by Sophos XG firewall does exactly that. This provides security intelligence to an administrator and gives them information on the risky users who are posing security threats on the organization’s network. 
Sophos XG Firewall (SF) calculates the UTQ score of each user based on the following two criteria: 
  1. Web surfing behavior (Only Allowed, but potentially risky and Denied Web traffic for each user) 
  1. Advanced Threat Protection (ATP) logs (Infected clients/hosts or clients that are part of a botnet) 
UTQ help administrators to: 
  • Spot risky users at a glance. 
  • Identify which clients/hosts within the network are infected or part of a botnet. 
  • Find malicious insiders. 
  • Avoid the chances of human oversight when correlating data from various logs and reports. 
  • Take appropriate actions like fine-tuning security policies, security awareness training, etc. 
The UTQ Dashboard is displayed in the form of a bubble graph and a table. The bubble graph is plotted between Relative Risk Ranking and Relative Threat Score; the bubble represents a user and the bubble size represents the Relative Threat posed by the user. Moving the mouse over the bubble displays details like the Username, the Relative Threat Score and the Relative Risk Ranking of a user. 
  
The bubble graph area is divided into three sections where: 
  • The top 10% are marked as High-Risk Users 
  • The next 40% are marked as Medium Risk Users 
  • The remaining 50% are marked as Low Risk Users 
The table at the bottom contains the following information: 
User: The username of the User as defined in SF. If the User is not defined, then it will display ‘N/A’ which means the traffic is generated by an undefined user. 
Relative Threat Score: The threat posed by the user (as a number), relative to the web behavior of all the other users, in the selected date range. 
The UTQ reports for a particular can also be viewed. To view these reports for a particular user, navigate to Reports > Dashboards. In the Show field, click on the drop-down menu and then select User Threat Quotient (UTQ). Click on the bubble of a particular user or click on a user under the User column at the bottom of the page in order to view the report. 
 
You can view the reports for the selected user, Advanced Threats, Detailed View ATP, Security Heartbeat ATP, High Risk Web Categories/ Domains, and Blocked High-Risk Web Categories/Domains by accessing the relevant widgets from the screen shown above. 
By using such features, the network administrators will be able to identify the risky users, educate them or take actions respectively. By having such insights of the network users, the probability of attacks will be dramatically decreased. 

Tuesday, 19 February 2019

Barracuda Rate Control


The Barracuda Spam Firewall Rate Control feature protects the system from spammers or spam-programs (also known as "spam-bots") that send large amounts of email to the server in a small amount of time. Rate Control is configured on the BLOCK/ACCEPT > Rate Control page. 
As part of the Connection Management Layer, the Rate Control mechanism counts the number of connections to the Barracuda Spam Firewall in a half hour period and compares that number to the Rate Control threshold, which is the maximum number of connections allowed from any one IP address in this half-hour time frame. If the number of connections from a single IP address exceeds the Rate Control threshold within the half hour period, the Barracuda Spam Firewall will defer any further connection attempts from that particular IP address until the next half hour time frame and log each attempt as deferred in the Message Log with a Reason of 'Rate Control'. 
In this case, for each message deferred, the sender will receive a 4xx level error message instructing the mail server to retry after a predefined time interval. Well-behaving mail servers act upon the defer message and will try sending the message again later, while email from large volume spammers will not retry sending the email again. 

You can exempt trusted IP addresses from Rate Control by adding a trusted IP address to the BLOCK/ACCEPT > Rate Control > Rate Control Exemption/IP range list. Also, any IP address that you enter as a trusted forwarder on the BASIC > IP Configuration page will be exempted from Rate Control. 


Friday, 15 February 2019

SQL Injection- A proper way to attack websites!

SQL injection is a popular way to attack websites. Developers can easily make coding mistakes that leaves a site open, and the payoff from getting access to the database can be big. Coding a site with no injection vulnerabilities takes not just careful programming, but an overall discipline that prevents mistakes. 

There are several types of SQL injection, but they all involve an attacker inserting arbitrary SQL into a web application database query. The simplest form of SQL injection is through user input. Web applications typically accept user input through a form, and the front end passes the user input to the back-end database for processing. If the web application fails to sanitize user input, an attacker can inject SQL of their choosing into the back-end database and delete, copy, or modify the contents of the database. An attacker can also modify cookies to poison a web application's database query. Cookies store client state information locally, and web applications commonly load cookies and process that information. A malicious user, or malware, can modify cookies to inject SQL into the back-end database. Server variables such as HTTP headers can also be used as a SQL injection attack vector. Forged headers containing arbitrary SQL can inject that code into the database if the web application fails to sanitize those inputs as well. Second-order SQL injection attacks are the sneakiest of the bunch, because they aren't designed to run immediately, but much later. A developer who correctly sanitizes all their input against an immediate attack may still be vulnerable to a second-order SQL when the poisoned data is used in a different context. 

Any input to your web application database should be considered untrustworthy and treated accordingly. Also limit account privileges. Assume a breach. What if a developer fails to sanitize a single user input field? Sanitize input but assume something is going to slip past you. Limit the account privileges of the database user. Is your web application read only. The principle of least privilege applies here. Give the web application the minimum privileges it needs to run. 

Stored procedures can also make SQL a lot harder — although not impossible. If your web application only needs to run a handful of SQL queries, create stored procedures to execute those queries. Typically, only the database administrator has privileges to create or modify stored procedures. Be aware, though, that many databases ship with default stored procedures out of the box, and attackers know this. Consider removing those default stored procedures unless you really need them. 

Tuesday, 12 February 2019

Sophos RED device is the solution to your multiple site-branches protection


If you have multiple site-branches to protect and a low budget Sophos RED device is the solution to your problem.

Sophos Remote Ethernet Device (RED) is a small network appliance, to provide a secure tunnel from its deployment location to a Sophos UTM firewall.

It is designed to be fully configured and managed from an Sophos UTM. RED devices can be shipped to a remote site, connected to any DHCP connection to the internet, and be fully configured by a remote administrator with no prior knowledge of the site, and no need to walk local personnel through technical setup steps.

It can be deployed in three modes:
  • Standard/Split Mode
  • Standard/Unified Mode
  • Transparent/Split

Saturday, 2 February 2019

ILOVEYOU - A Guinness World Record Virus


ILOVEYOU was so effective it actually held the Guinness World Record as the most ‘virulent’ virus of all time. A viral virus, by all accounts. Two young Filipino programmers, Reonel Ramones and Onel de Guzman, were named as the perps but because there were no laws against writing malware, their case was dropped and they went free. 


It’s been almost 20 years since this virus was seen. By today’s standards it’s a tame virus, but in 2000 it was the most damaging malware event of all time. Likely, ILOVEYOU inspired many hackers to wield their keyboard as a weapon. Well, in 2000 malware was a bit of a myth. In fact, it was such a myth that malware could get away with being completely unsubtle. If you got an email today like the one that was sent around in 2000, you’d never open it. (We hope!) The virus came in an email with a subject line that said “I love you”. 

Being curious types, people clicked into the email with aplomb—regardless of the fact the email was not from anyone they knew. 

The malware was a worm that was downloaded by clicking on an attachment called ‘LOVE-LETTER-FOR-YOU.TXT.vbs’. 

ILOVEYOU overwrote system files and personal files and spread itself over and over and over again. ILOVEYOU hit headlines around the world and still people clicked on the text—maybe to test if it really was as bad as it was supposed to be. Poking the bear with a stick, to use a metaphor. 

Softech Middle East FZC Announces Partnership with SolarWinds

Softech Middle East FZC to offer SolarWinds comprehensive IT management and monitoring solutions to partners and customers in Pakistan Sof...