<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Web Security</title>
	<atom:link href="http://blog.kraasecurity.com/category/websecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Citibank Data Security Breach</title>
		<link>http://blog.kraasecurity.com/2011/06/24/citibank-data-security-breach/</link>
		<comments>http://blog.kraasecurity.com/2011/06/24/citibank-data-security-breach/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 13:20:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[citibank hack]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=337</guid>
		<description><![CDATA[Citibank Data Security Breach, credit cards stolen]]></description>
			<content:encoded><![CDATA[<p>Recently <strong><a href="http://www.citibank.com">Citibank</a></strong> announced that they were hacked, a typical <strong>data breach</strong>. See the International Business Times article here, <strong><a href="http://http://www.ibtimes.com/articles/160376/20110609/hacking-citibank-citibank-hacked-citi-hacked-citibank-hack-2011-citibank-online.htm">http://www.ibtimes.com/articles/160376/20110609/hacking-citibank-citibank-hacked-citi-hacked-citibank-hack-2011-citibank-online.htm</a></strong>. Were they not conducting vulnerability tests on their own system to see if they were vulnerabile? The comes on the heels of Sega, Sony, Lockheed Martin amongst others. So far they only report that 360,000 cards were compromised. We can assume that those customers, if they actually know which accounts were compromised will get 2 years of credit monitoring. But what happens when you actually get false charges? You now have to go spend time to resolve the problems and most likely you might take a hit to your credit score.</p>
<p>Its amazing that this continues to happen and there isn&#8217;t a stronger tie between the credit reporting agencies and the hacked banks to help consumer manage their credit and not be responsible to follow up on a data loss. The consumer is the one who has to bear all the burden. And the banks will probably just add another fee to cover their costs to managing the <strong>security breach</strong>.</p>
<p>These banks should really be more proactive in conducting <strong><a title="vulnerability testing" href="http://www.kraasecurity.com/risk-assessment/vulnerability-assessment">vulnerability scans</a></strong> daily, conducting <strong><a title="website security testing" href="http://www.kraasecurity.com/risk-assessment/website-security-assessment">website security testing</a></strong> and implement<strong><a title="intrusion detection system" href="http://www.kraasecurity.com/risk-assessment/security-architecture-analysis"> intrusion detection and prevention systems</a></strong>. We do not know if Citibank had a IDS system in ploace but you would think that with a good prevention system in place, this hack should have been immediately identified and stoped before the data breach could occur?</p>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com">www.kraasecurity.com</a></p>
<p><a title="social media policy" href="http://www.kraasecurity.com/social-media-security">Social Media Security</a></p>
<p><a title="website security testing" href="http://www.kraasecurity.com/risk-assessment/website-security-assessment">Website Security Testing</a></p>
<p><a title="security policy development" href="http://www.kraasecurity.com/compliance-solutions">Security Policy Development</a></p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://cybersecurityhacking.wordpress.com/2011/06/12/city-bank-gets-hacked/">City Bank Gets Hacked&#8230;..</a> (cybersecurityhacking.wordpress.com)</li>
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2011/06/09/citibank-hack/">Citibank Hack Affects 210,000 Customers</a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://telecomcanadaen.wordpress.com/2011/06/22/360-000-accounts-hacked-with-citibank/">360 000 Accounts Hacked with Citibank</a> (telecomcanadaen.wordpress.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.ghacks.net/2011/06/09/massive-data-theft-in-citibank-hack/">Massive Data Theft in Citibank Hack</a> (ghacks.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=816346a6-6f93-4f93-8d57-61dcfff2523b" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/06/24/citibank-data-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Me on the Web, is it any good?</title>
		<link>http://blog.kraasecurity.com/2011/06/17/google-me-on-the-web-is-it-any-good/</link>
		<comments>http://blog.kraasecurity.com/2011/06/17/google-me-on-the-web-is-it-any-good/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 20:56:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=331</guid>
		<description><![CDATA[Google Me on the Web, identity theft and reputation management]]></description>
			<content:encoded><![CDATA[<p>Google has a new feature in their dashboard, &#8220;<span style="text-decoration: underline;"><strong>Me on the Web</strong></span>&#8220;. The pitch is that it will help your protect your identity.  The Huffington Post did a write up of it here, <a href="http://www.huffingtonpost.com/2011/06/16/google-me-on-the-web_n_877996.html">http://www.huffingtonpost.com/2011/06/16/google-me-on-the-web_n_877996.html</a> Google &#8216;Me On The Web&#8217; Tool Promises To Help You Manage Your Online Identity. &#8220;Your online identity is determined not only by what you post, but also by what others post about you &#8212; whether a mention in a blog post, a photo tag or a reply to a public status update,&#8221; Google explained in a <a href="http://googlepublicpolicy.blogspot.com/2011/06/me-myself-and-i-helping-to-manage-your.html" target="_hplink">blog post</a>. But what is it really all about?</p>
<p>At first glance it seems to be just an interface to Google Alerts (www.google.com/alerts).  I use google alerts for all kinds of key word searches, (my name included). In this screen shot you can see what the interface looks like for <span style="text-decoration: underline;"><strong>Me on the Web</strong></span></p>
<p><img title="Google me on the web" src="http://blog.kraasecurity.com/wp-content/uploads/2011/06/google.jpg" alt="Google me on the web" width="530" height="327" /></p>
<p>Nothing terrible exciting here. The advice they give you about managing your online reputation is particularly bland. &#8220;If you find content online&#8211;say, your telephone number or an embarrassing photo of you&#8211;that you don&#8217;t want to appear online, first determine whether you or someone else controls the content. For example, if the photo you want to hide is part of your Picasa account, you can simply <a href="http://picasa.google.com/support/bin/answer.py?hl=en&amp;answer=113516" target="_blank">change your photo visibility settings</a>. <img src="http://services.google.com/images/adwords/doit.gif" alt="" /> If, however, the unwanted content resides on a site or page you don&#8217;t control, you can follow our tips on <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=164133" target="_blank">removing personal information from the web</a> <img src="http://services.google.com/images/adwords/doit.gif" alt="" /> and <a href="http://www.google.com/support/webmasters/bin/answer.py?hl=en&amp;answer=164734" target="_blank">removing a page from Google&#8217;s search results</a>. <img src="http://services.google.com/images/adwords/doit.gif" alt="" />&#8221;</p>
<p>There really isnt anything proactive or defensive about this &#8220;new tool&#8221;. But setting up appropriate alerts is definitely a must in the online world.</p>
<p>For some really intersting tracking of online activity, check out <span style="text-decoration: underline;"><strong>SocialMention.com</strong></span></p>
<p>Gary Bahadur</p>
<p>CEO KRAA Security</p>
<p><a href="http://www.kraasecurity.com">www.kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com/social-media-security">Social Media Security</a></p>
<p><a href="http://www.kraasecurity.com/risk-assessment">Network Risk Assessment</a></p>
<p>New book coming soon &#8220;Securing the Clicks: Network Security in the age of Social Media&#8221; <a href="http://www.amazon.com/Securing-Clicks-Network-Security-Social/dp/0071769056/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1308343778&amp;sr=8-1">http://www.amazon.com/Securing-Clicks-Network-Security-Social/dp/0071769056/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1308343778&amp;sr=8-1</a></p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://techie-buzz.com/tech-news/googler-me-on-the-web-tracks-online-mentions-of-your-name.html">Google&#8217;s &#8220;Me on The Web&#8221; Tracks Online Mentions Of Your Name, Just Like Google Alerts</a> (techie-buzz.com)</li>
<li class="zemanta-article-ul-li"><a href="http://lifehacker.com/5812650/google-updates-dashboard-to-help-you-manage-your-identity-on-the-web">Google Updates Dashboard to Help You Manage Your Identity on the Web [In Brief]</a> (lifehacker.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=4dd48b13-5595-432e-b019-0f1b17523913" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/06/17/google-me-on-the-web-is-it-any-good/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Geo-tagging photos can lead to cyberstalkers finding you</title>
		<link>http://blog.kraasecurity.com/2011/02/04/geo-tagging-photos-can-lead-to-cyberstalkers-finding-you/</link>
		<comments>http://blog.kraasecurity.com/2011/02/04/geo-tagging-photos-can-lead-to-cyberstalkers-finding-you/#comments</comments>
		<pubDate>Fri, 04 Feb 2011 20:42:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Global Positioning System]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Mobile phone]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Social network service]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=305</guid>
		<description><![CDATA[A new threat could be giving up your location when you post a picture from inside your house. A team of scientists dicovered that with some smartphones, a user's latitude and longitude can be attached tothe picture you post in the metadata.]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 276px"><a href="http://commons.wikipedia.org/wiki/File:Facebook.svg"><img title="Facebook logo" src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/06/Facebook.svg/266px-Facebook.svg.png" alt="Facebook logo" width="266" height="100" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>When you take a photo of yourself in your house and then post it via Facebook or twitpic, you assume that no one will really know where you are taking that picture. Well, you may be wrong. <a title="Social Media Security assessment" href="http://www.kraasecurity.com/social-media-security/social-media-security-assessment">Social media security </a>is in a very nascent development stage. There are a number of theats already to social media such as malicious applications in Facebook or trojans in shortened URLs that the average user does not know about or where to turn to for advice.</p>
<p>A new threat could be giving up your location when you post a picture from inside your house. A team of scientists dicovered that with some smartphones, a user&#8217;s latitude and longitude can be attached tothe picture you post in the metadata. That&#8217;s pretty scary. See the news story &#8221; Tips to Turn Off Geo-Tagging on Your Cell Phone&#8221;  (<a href="http://abcnews.go.com/Technology/celebrity-stalking-online-photos-videos-give-location/story?id=11443038">http://abcnews.go.com/Technology/celebrity-stalking-online-photos-videos-give-location/story?id=11443038</a>) &#8220;Many people are not aware of the fact that there are geotags in photos and videos,&#8221; said Gerald Friedland, one of the scientists.</p>
<p>A website that has been setup to show the dangers of this capability is <a href="http://www.icanstalku.com/">www.icanstalku.com</a>. So what can you do about this? Do you want to be stalked?  ON the IPhone, go to Settings, General, then Location Services and disable the applications you do not want to use Geo-tagging, such as Camera.</p>
<p>Regards</p>
<p>Gary Bahadur</p>
<p><a href="http://www.kraa.security.com/">www.kraasecurity.com</a></p>
<p>blog.kraasecrity.com</p>
<p>888-572-2911</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.cnn.com/2010/TECH/social.media/07/21/netiquette.cyber.stalker/index.html&amp;a=21312974&amp;rid=c51eb71d-d627-462b-8b72-1bc57b579e1f&amp;e=f5fa5244ecc1f20062465806e1283193">How to handle a cyberstalker</a> (cnn.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.lv.com/media_centre/news/detail?detailid=3827">Cyberstalking threat hits UK</a> (lv.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.dreamindemon.com/2011/01/19/teen-charged-with-cyberstalking-after-creating-fake-facebook-account/">Teen Charged With Cyberstalking After Creating Fake Facebook Account</a> (dreamindemon.com)</li>
<li class="zemanta-article-ul-li"><a href="http://newyork.cbslocal.com/2010/11/03/geo-tagging-the-dangers-of-posting-pictures-online/">Geo-Tagging: The Dangers Of Posting Pictures Online</a> (newyork.cbslocal.com)</li>
<li class="zemanta-article-ul-li"><a href="http://harlemworldblog.wordpress.com/2010/11/04/the-dangers-of-geo-tagging-in-harlem/">The Dangers Of Geo-Tagging In Harlem</a> (harlemworldblog.wordpress.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.jakeludington.com/downloads/20110130_geotag_photos_with_geosetter.html">GeoTag Photos with GeoSetter</a> (jakeludington.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c51eb71d-d627-462b-8b72-1bc57b579e1f" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/02/04/geo-tagging-photos-can-lead-to-cyberstalkers-finding-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook’s new security features and the Zuckerberg hacking incident</title>
		<link>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/</link>
		<comments>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 22:06:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Mark Zuckerberg]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Muhammad Yunus]]></category>
		<category><![CDATA[Nobel Prize]]></category>
		<category><![CDATA[Social business]]></category>
		<category><![CDATA[Social network service]]></category>
		<category><![CDATA[TechCrunch]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=297</guid>
		<description><![CDATA[Facebook’s new security features and the Zuckerberg hacking incident]]></description>
			<content:encoded><![CDATA[<p>This past week was eventful for <a class="zem_slink freebase/en/facebook" title="Facebook" rel="homepage" href="http://facebook.com/">Facebook</a> and for <a class="zem_slink freebase/en/mark_zuckerberg" title="Mark Zuckerberg" rel="myspaceeverything" href="http://www.myspace.com/everything/mark-zuckerberg">Mark Zuckerberg</a>. The Facebook page was hacked as first reported by <a class="zem_slink freebase/en/techcrunch" title="TechCrunch" rel="homepage" href="http://www.techcrunch.com/">Techcrunch</a> ““Let The Hacking Begin” Declares Person Who Hacked Zuckerberg’s Facebook Fan Page”  (<a href="http://techcrunch.com/2011/01/25/zuckerberg-fan-page-hack/">http://techcrunch.com/2011/01/25/zuckerberg-fan-page-hack/</a>) . The message left on the page was:</p>
<p><em>“Let the hacking begin. If facebook needs money, instead of going to the banks, why doesn&#8217;t Facebook let its users invest in Facebook in a social way? Why not transform Facebook into a &#8216;social business&#8217; the way Nobel Price winner Muhammad Yunus described it? http://bit.ly/fs6rT3 What do you think? #hackercup2011”</em><em> </em></p>
<p>Facebook then said it was a “bug” as reported by the BBC “Facebook blames bug for Zuckerberg &#8216;hacking&#8217;” (<a href="http://www.bbc.co.uk/news/technology-12286377">http://www.bbc.co.uk/news/technology-12286377</a>). Well I guess they can speak to Microsoft about “bugs” and letting their software be hackable. Not much more was explained.</p>
<p>One other interesting event that was also news with Facebook was the launch of their encrypted login process as reported by the Huffingtonpost “What Facebook&#8217;s New Security Features Mean For You”. This has actually been around for a while but not published. What does this mean? Well when you go to Facebook.com now, just go to <a href="https://www.facebook.com/">https://www.facebook.com</a>.  The “https” will allow you to have your login encrypted so the guy sitting next to you in Starbuck and capture your traffic on the wireless network and steal your login ID and password by running Firesheep or other sniffing program. You can also do this with many social networking sites even though they do not publicize it.</p>
<p>To turn on this feature automatically go to “Accounts” -&gt; “Account Setting” -&gt; “Account Security” -&gt; “Change” and select “Browse Facebook on a secure connection (https) whenever possible”. If you have never played with the Privacy Setting you should probably check those out as well. Stop sharing everything about yourself with “Everyone”!</p>
<div id="attachment_302" class="wp-caption alignnone" style="width: 310px"><a rel="attachment wp-att-302" href="http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/facebook-privacy/"><img class="size-medium wp-image-302" title="Facebook privacy settings" src="http://blog.kraasecurity.com/wp-content/uploads/2011/01/facebook-privacy-300x223.png" alt="Facebook privacy settings" width="300" height="223" /></a><p class="wp-caption-text">Facebook privacy settings</p></div>
<p><a class="zem_slink" title="gary bahadur" rel="homepage" href="http://www.kraasecurity.com/">Gary Bahadur</a></p>
<p>CEO KRAA Security, <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Police Development</p>
<p>*PGP Security</p>
<p>*Free Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.devicemag.com/2011/01/28/mark-zuckerbergs-facebook-hacked/">Mark Zuckerberg&#8217;s Facebook Hacked</a> (devicemag.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=1b100e50-ce67-4217-8def-0bf7804faac3" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Dangers of Employee Social Media Usage</title>
		<link>http://blog.kraasecurity.com/2010/12/29/the-dangers-of-employee-social-media-usage/</link>
		<comments>http://blog.kraasecurity.com/2010/12/29/the-dangers-of-employee-social-media-usage/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 02:17:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=292</guid>
		<description><![CDATA[Employers are constantly hearing of social media this and social media that. When your employees go on break or eat lunch, they are usually on their cell phones talking. But, now there are also applications on phones like Facebook, Twitter, FourSquare and others where an employee can actually send photo uploads while being mobile and [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } --><span style="font-family: Times New Roman,serif;">Employers are constantly </span><span style="font-family: Times New Roman,serif;">hearing </span><span style="font-family: Times New Roman,serif;">of social media this and social media that. When your employees go on break or eat lunch, they are usually on their cell phones talking. But, now there are also applications on phones like Facebook, Twitter, FourSquare and others where an employee can actually send photo uploads while being mobile and even post to Facebook automatically. Are employees using social media securely?</span></p>
<p><span style="font-family: Times New Roman,serif;">Does your company have anything in place for protecting confidentiality through social media usage? Do you have a <a href="http://www.kraasecurity.com/social-media-security/social-media-policy-development">Social Media Security Policy</a>?  Employees sign agreements when joining the company but did the business cover disclosing things like pictures or private conversations and even meeting information via Google Buzz or Facebook? What about brand new products being developed that are trade secrets?</span></p>
<p><span style="font-family: Times New Roman,serif;">If your employees are online working to do their job and Facebook, MySpace, or gaming sites like Pogo are not blocked, how do you know they are doing their work 100% of the time? Just because their production numbers look great, doesn’t mean they are not slacking. Have you done a <a href="http://www.kraasecurity.com/social-media-security/social-media-security-assessment">Social Media Security Assessment</a>? </span></p>
<p><span style="font-family: Times New Roman,serif;">It is becoming an epidemic in the work force with employees breaking rules and ultimately being fired every day.  If <a href="http://www.kraasecurity.com/social-media-security/social-media-employee-monitoring">security monitoring technologies</a> are in place you could possibly sue the former employee but your trade secrets are gone and so might be your reputation.  If an employee is bad-mouthing your company and tells everyone to not buy or shop with you, there goes your business immediately. </span></p>
<p><span style="font-family: Times New Roman,serif;">You can make a legal policy for employees to sign when they start their job that they will not talk, disclose, or say anything bad about the company on social media sites. If businesses do not step up soon and do something it can be a total free for all!</span></p>
<p><span style="font-family: Times New Roman,serif;">Here are a few interesting facts to consider. One out of every ten employees admitted overriding their job’s security system so they could access restricted sites.  In 2009, 24% of eight hundred employers surveyed said they had to discipline an employee for using social media sites. Another study showed 8% of employees were terminated for accessing Facebook out of two hundred businesses polled. Twenty eight thousand people were polled in the United Kingdom at the beginning of 2010 and a whopping 87% said they can do what they want; it is their right to do so.</span></p>
<p><span style="font-size: x-small;">It is now believed that social networking will replace email by 2014 as the main way to communicate for 20% of all business owners or users. Is your company prepared for Secure Social Media?</span></p>
<p>Gary Bahadur</p>
<p>CEO KRAA Security, <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><span style="color: #0000ff;"><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></span></p>
<p><span style="color: #0000ff;"><a href="../">http://blog.kraasecurity.com</a></span></p>
<p><span style="color: #0000ff;"><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></span></p>
<p><span style="color: #ff0000;">*Managed Security Services</span></p>
<p><span style="color: #ff0000;">*Vulnerability Management</span></p>
<p><span style="color: #ff0000;">*Compliance &amp; Police  Development</span></p>
<p><span style="color: #ff0000;">*PGP Security</span></p>
<p><span style="color: #ff0000;">*Free Website Security Test</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/12/29/the-dangers-of-employee-social-media-usage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Media Warfare: Are you attacking or defending?</title>
		<link>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/</link>
		<comments>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 01:33:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Entrepreneur]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[social media policy]]></category>
		<category><![CDATA[social media security]]></category>
		<category><![CDATA[social media war]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=276</guid>
		<description><![CDATA[Image via CrunchBase Is there such a thing as Social Media Warfare? We have had cyber warfare going on for years now. So it should be an obvious &#8220;YES&#8221; that Social Media warfare exists. But is that true?  To get to a full blown war opposing sides go through an escalation process. Where are we [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 255px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-450x450.png" alt="Image representing Facebook as depicted in Cru..." width="135" height="55" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p>Is there such a thing as Social Media Warfare? We have had cyber warfare going on for years now. So it should be an obvious &#8220;YES&#8221; that Social Media warfare exists. But is that true?  To get to a full blown war opposing sides go through an escalation process. Where are we in this process? From a pure cyber warfare perspective, we are in world war three, many opposing sides, lots of new and improved weapons, completely escalating attacks and no end in sight. Companies are used to conducting <a title="vulnerability assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">vulnerability management</a> and<a title="risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/roadmap-strategy-development"> risk assessment</a>. This new war will require new tactics and defense strategies.</p>
<p>I think we have seen the first skirmishes of the war. It started with all the spammers morphing their tools into <a class="zem_slink freebase/en/facebook" title="Facebook" rel="homepage" href="http://facebook.com">Facebook</a> and <a class="zem_slink freebase/en/twitter" title="Twitter" rel="homepage" href="http://twitter.com">Twitter</a> hacking. Then moving into phishing. Then into negative attacks on your reputation by disgruntled customers and competitors. So what is the progression of this coming war? Is there a similarity to how &#8220;normal&#8221; cyber  warfare started? But why is this war inevitable?</p>
<p>The attack vectors in the Social Media War are probably categorized into personal use and corporate use. If these are the assets that needs to be protected, we can then figure out how the assets will be attacked, how will the enemies do reconnaissance, what alliances will be formed and what should be the defense strategies and weapons for defense.</p>
<p>The progression of of this war will follow different patterns and there is probably no end in sight.</p>
<table style="border-color: #f9051d; border-width: 1px; width: 677px; height: 585px;" border="1" align="left">
<tbody>
<tr>
<td><strong>Action</strong></td>
<td><strong>Personal</strong></td>
<td><strong>Corporate</strong></td>
</tr>
<tr>
<td>Skirmish</td>
<td>Home users receiving spam and phishing attacks and scams</td>
<td>Corporate users seeing more phishing attacks, attackers going through Linkedin profiles</td>
</tr>
<tr>
<td>Protest Actions</td>
<td>Users might complain to attorney generals, or write nasty messages about Microsoft <a class="zem_slink freebase/en/adobe_systems" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> or <a class="zem_slink freebase/en/apple_inc" title="Apple" rel="homepage" href="http://www.apple.com">Apple</a> security weaknesses</td>
<td>The IT department is inundated with help desk calls. Companies have the ability to complain to ISPs or event countries about originating attacks.</td>
</tr>
<tr>
<td>Negotiations</td>
<td>There really isn&#8217;t anyone to negotiate with. Writing on your Facebook wall will not do a darn thing.</td>
<td>Companies definitely do not want to negotiate. But will see blackmail more and more.</td>
</tr>
<tr>
<td>Failed Negotiations</td>
<td>The home user is bascially screwed anyway.</td>
<td>Succumbing to blackmail will only lead down a bad path.</td>
</tr>
<tr>
<td>Declaration of War</td>
<td>This is a defacto state with the home user. They are at war whether they know it or not.</td>
<td>Companies have to take a proactive approach to security versus reactive. Anticipate the next types of attacks and have a budget to address it.</td>
</tr>
<tr>
<td>Launch Attacks and Defend</td>
<td>More defend, get your anti-spyware, <a title="Antivirus and AntiSpyware" href="http://www.kraasecurity.com/managed-services/system-defense/antivirus-and-spyware">antivirus</a>, personal firewalls and encryption up to speed. But after that, understand how attackers use Social Media.</td>
<td>Spend massive amounts of money on understanding how so fight in the Social media landscape, security hardware and software are not enough.</td>
</tr>
<tr>
<td>Allies Join the War</td>
<td>The home user can only rely on the Social media companies for basic security.</td>
<td>Their will be more collaboration between companies and governments. Perhaps together they have a fighting chance. Regulations are also going to force changes.</td>
</tr>
<tr>
<td>Years of Conflict &#8211; Never Ending</td>
<td>Whats the next thing after Facebook and Twitter? Whatever it is will have its own security challenges. But by that time the home user will probably have given out every bit of personal information on all the Social Media venues anyway.</td>
<td>A company can only rely on the right process to secure their social media usage. As technologies change and new sites go live, a good process and social media security policy is all you can rely on.</td>
</tr>
<tr>
<td>Winner</td>
<td>The ISP, they get to sell bandwidth.</td>
<td>The VCs who fund companies like Facebook and Twitter.</td>
</tr>
</tbody>
</table>
<p>I will get into more tactics in the coming war in future posts.</p>
<p>Gary Bahadur</p>
<p>CEO KRAA Security,  <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="../">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*<a title="Security management" href="http://www.kraasecurity.com/managed-services/intrusion-defense">Managed Security Services</a></p>
<p>*<a title="Vulnerability scanning" href="http://www.kraasecurity.com/managed-services/vulnerability-defense">Vulnerability Management</a></p>
<p>*<a title="Compliance" href="http://www.kraasecurity.com/compliance/pci-assessment">Compliance &amp; Policy Development</a></p>
<p>*<a title="Email Encryption" href="http://www.kraasecurity.com/products/pgp-enterprise-products">PGP Security</a></p>
<p>*<a title="Website security" href="http://www.kraasecurity.com/free-website-test">FREE Website Security Test</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2267544/public-approval-cyberwarfare">Public gives approval for cyber warfare</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.trendhunter.com/trends/google-vs-facebook-employment-war">Social Media Wars &#8211; The Google vs. Facebook Employment War Gets Messy (GALLERY)</a> (trendhunter.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=18799bf6-d5b7-4e8c-becf-073468d79dc0" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When will Vendors provide Risk Assessments of their products?</title>
		<link>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/</link>
		<comments>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 04:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[CIO.com]]></category>
		<category><![CDATA[Cross-site scripting]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=185</guid>
		<description><![CDATA[Image via Wikipedia Vendor risk assessment are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 92px; height: 52px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg"><img title="Adobe Systems Incorporated" src="http://upload.wikimedia.org/wikipedia/en/thumb/d/dd/AdobeSystems.svg/300px-AdobeSystems.svg.png" alt="Adobe Systems Incorporated" width="97" height="65" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a title="vendor risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment"><strong>Vendor risk assessment</strong></a> are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer either. So why do we accepts buggy <a class="zem_slink freebase/en/computer_software" title="Computer software" rel="wikipedia" href="http://en.wikipedia.org/wiki/Computer_software">software</a> that is vulnerable to things like cross site scripting attacks, buffer overflows, malware and such? But we do that everyday.</p>
<p>Everything from vulnerable <a class="zem_slink freebase/en/operating_system" title="Operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating systems</a> such as Windows to vulnerable applications such as <a class="zem_slink freebase/en/adobe_creative_team" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> and weak website such as Facebook. As stated by <a class="zem_slink" title="CIO.com" rel="homepage" href="http://www.cio.com">CIO.com</a>, &#8220;SANS and Mitre, a Bedford, Mass.-based <a class="zem_slink freebase/en/non-profit_organization" title="Non-profit organization" rel="wikipedia" href="http://en.wikipedia.org/wiki/Non-profit_organization">non-profit</a>, federally funded technology <a class="zem_slink freebase/en/research_and_development" title="Research and development" rel="wikipedia" href="http://en.wikipedia.org/wiki/Research_and_development">research and development</a> organization, today is also releasing its second annual CWE/SANS Top 25 list of the most common programming errors currently being made by software <a class="zem_slink freebase/en/software_developer" title="Software developer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Software_developer">developers</a>. The authors say the errors on the list are responsible nearly every major type of cyber attack, including the recent intrusions at Google (<a class="zem_slink freebase/en/google" title="NASDAQ: GOOG" rel="stockexchange" href="http://finance.yahoo.com/q?s=GOOG">GOOG</a>), and numerous utilities and government agencies.&#8221;  The biggest companies are culprits.</p>
<p>So what are we do to about buggy software? How do you force a <strong>vendor risk assessment</strong> on all yoru vendors? Maybe scream &#8220;I&#8217;m mad as hell and I am not going to take it anymore!&#8221;  Might feel good for a second or two, but not going to solve the almost daily patch process we have to go through for our software. <strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Patch management</a></strong> is a thriving sector!</p>
<p>As I see it, some theoretical things the end user can do to change the deadly cycle of poor software:</p>
<ol>
<li>Sue! I don&#8217;t know if that&#8217;s possible, but if you bought a car with bad acceleration problems (ahem Toyota) you might just sue the manufacturer if you got into an accident. What can we do that if some hacker breaks in through buggy software?</li>
<li>Stop buying from that vendor! <a class="zem_slink" title="Apple Inc." rel="geolocation" href="http://maps.google.com/maps?ll=37.33187,-122.029669&amp;spn=1.0,1.0&amp;q=37.33187,-122.029669%20%28Apple%20Inc.%29&amp;t=h">Apple</a> seems to be taking this tactic by not allowing Flash on the IPad. But can we all move away from <a class="zem_slink freebase/en/microsoft" title="Microsoft" rel="homepage" href="http://www.microsoft.com">Microsoft</a> tomorrow? Probably not.</li>
<li>Make the vendors conduct <strong><a title="application security assessment" href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">Risk Assessments</a></strong> of their products prior to release. A third party risk assessment is probably a good idea. Something with more teeth than a SAS70 type review.</li>
</ol>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p> *Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p> *FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/188591-apple-vs-microsoft-making-platform-enemies-and-friends?source=feed">Apple vs. Microsoft: Making Platform Enemies and Friends</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/">Adobe Reader And Acrobat Get Yet Another Security Update</a> (ghacks.net)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13860_3-10447081-56.html?part=rss&amp;subj=BeyondBinary">Microsoft investigates new Internet Explorer flaw</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/developer-world/adobe-air-20-full-featured-flash-player-coming-smartphones-253&amp;a=13137035&amp;rid=5940a61e-7193-4971-a98b-6547400ef860&amp;e=5d602d8d9add939e9717afe63232605d">Google readies Flash for Android devices</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9162258/IBM_Vulnerabilities_fell_in_09_but_other_risks_abound?source=rss_security">IBM: Vulnerabilities fell in &#8217;09, but other risks abound</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9157558/Update_Adobe_issues_emergency_PDF_patches?source=rss_security">Update: Adobe issues emergency PDF patches</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/">Serious web vuln found in 8 million Flash files</a> (theregister.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/347250/Hold_Vendors_Liable_for_Buggy_Software?source=rss_dev">Hold vendors liable for buggy software, group says</a> (computerworld.com)</li>
</ul>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/5940a61e-7193-4971-a98b-6547400ef860/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=5940a61e-7193-4971-a98b-6547400ef860" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Loss, this time with Network Solutions</title>
		<link>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</link>
		<comments>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 16:55:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[stolen data]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</guid>
		<description><![CDATA[Data Loss, this time with Network Solution Network Solutions, one of the largest domain registrars recently announced a data breach. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a [...]]]></description>
			<content:encoded><![CDATA[<h1>Data Loss, this time with Network Solution</h1>
<p>Network Solutions, one of the largest domain registrars recently announced a <strong>data breach</strong>. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a routine check. Since the breach occurred between March 12 and June 8th, how routine was the actual checks? I wonder when their last vulnerability assessment or <a href="http://www.kraasecurity.com/">Information security risk assessment</a> was conducted? Data loss prevention is sorely lacking in just about every industry.</p>
<p>Here is what the company said &#8220;At this point, we have no reports or other reasons to believe that any credit card account information has been misused and, under established practice, credit card issuing companies generally will not hold our merchants’ customers liable for any fraudulent purchases made using their credit card account numbers that are reported in a timely way to the issuer,&#8221; a statement from the company reads. All these statements around <strong>hacker breaches </strong>and <strong>stolen credit cards </strong>read the same.</p>
<p>The process now begins where all the merchants have to be identified, then each merchant has to notify their customers. Their customer then have to work with their banks to stop credit cards, have to get credit monitoring and thus goes the Circle of Life (of data breaches) Here is the list of <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2009">data breaches</a> in 2009 alone. If you recall the breaches of Heartland Payment Systems and RBS WorldPay, the breachescaused them to be removed from the <a href="http://www.kraasecurity.com/compliance/pci">PCI security audit</a> () list . Well that should be obvious, or should they have been rated compliant int he first place. Known non-compliance might be a better than weak compliance.</p>
<p>The basic question is what was Network Solution not doing to have malicious software installed on key servers? Was it a breach through a web application, was it through malicious email, a browser based attack, some insider who didn&#8217;t know enough about security and clicked on the wrong thing? What routine check found it and why wasn&#8217;t this check run on a more routine basis, such as weekly or even daily?</p>
<p>At the end of the day, security is a moving target. We can utilize encryption, vulnerability management, <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a>, <strong>email filtering, backup and recovery</strong>, but all will be useless is we follow poor practices or do not have good procedures in place to take into account the human element. Most breaches are insider problems or mis-configurations or plain old stupidity.</p>
<p>Gary Bahadur<br />
<a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p>http://blog.kraasecurity.com</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*FREE Website Security Test</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/755d6115-051b-8f3d-a5f6-0fd37b657b56/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=755d6115-051b-8f3d-a5f6-0fd37b657b56" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless (in)Security in Your Pocket</title>
		<link>http://blog.kraasecurity.com/2009/06/22/wireless-insecurity-in-your-pocket/</link>
		<comments>http://blog.kraasecurity.com/2009/06/22/wireless-insecurity-in-your-pocket/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 00:05:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[wireless security]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[verizon mifi]]></category>
		<category><![CDATA[wireless hacking]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=61</guid>
		<description><![CDATA[Verizon has launched the pocketable MiFi router. The MiFi 2200 has CDMA with EV-DO Rev. A. So you can roam around without a datacard as the only means for your laptop on the middle of nowhere. This credit card size access point can connect multiple devices such as your iPhone or a laptop. I havent bought a gadget in awhile, [...]]]></description>
			<content:encoded><![CDATA[<p>Verizon has launched the pocketable MiFi router. The MiFi 2200 has CDMA with EV-DO Rev. A. So you can roam around without a datacard as the only means for your laptop on the middle of nowhere. This credit card size access point can connect multiple devices such as your iPhone or a laptop. I havent bought a gadget in awhile, but this might be the one.</p>
<p> <img class="aligncenter size-medium wp-image-63" title="mifi_full" src="http://blog.kraasecurity.com/wp-content/uploads/2009/06/mifi_full-300x192.jpg" alt="mifi_full" width="148" height="83" /></p>
<p>Sitting on the plane for three hours in a delay might be more tolerable if you can get online. Not having to pay for TMobile hotspot access and not being tethered to your laptop, all great features. But what about the dangers?  <strong>Wireless security</strong> is a challenge here and it should be addressed sooner rather than later.</p>
<p>The wireless risks actually havent changed. But the reality is that if someone uses the MiFi to connect their IPhone rather than using the ATT network to browse, do you think they will think as much about security as if they used a laptop? Probably not.  Using portables to get online doesnt seem as dangerous as a laptop does it? People equate more &#8220;data&#8221; risk with a laptop, but most portable devices have tons of stored data, contacts, files etc. They are at risk and the education isnt there yet about these risks. Should you be running antivirus on your portable device? Should you have an iPhone Firewall application?</p>
<p>So what do you need to do? Well the steps are pretty much the same as for other wireless hotspot access points:</p>
<p>1) Require <strong>encrypted authentication</strong></p>
<p>2) Change <strong>default username and passwords</strong></p>
<p>3) Disable broadcast of the SSID</p>
<p>4) Enable logging and alerting</p>
<p>5) Have<strong> hostbased security</strong> tools such as <strong>antivirus, firewal</strong>ls and <strong>intrusion detection</strong> on your portable devices if possible.</p>
<p>If you are so old fashioned that you dont have one of these in your pocket and you need a hotspot, try the HotSpot finder Jiwire, <a href="http://www.jiwire.com/">http://www.jiwire.com/</a>  Here are some interesting Wifi hotspot stats from Jiwire</p>
<div class="col3">
<h4>Top 10 Location Types</h4>
<table border="0" cellspacing="0">
<thead>
<tr>
<th>Rank</th>
<th>Type</th>
<th>Locations</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-hotel-resort-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Hotel / Resort</span></a></td>
<td>59,224</td>
</tr>
<tr>
<td>2</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-cafe-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Cafe</span></a></td>
<td>39,310</td>
</tr>
<tr>
<td>3</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-other-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Other</span></a></td>
<td>38,430</td>
</tr>
<tr>
<td>4</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-restaurant-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Restaurant</span></a></td>
<td>37,159</td>
</tr>
<tr>
<td>5</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-public-space-public-building-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Public Space / Public Building</span></a></td>
<td>19,386</td>
</tr>
<tr>
<td>6</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-store-shopping-mall-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Store / Shopping Mall</span></a></td>
<td>16,063</td>
</tr>
<tr>
<td>7</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-office-building-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Office Building</span></a></td>
<td>10,145</td>
</tr>
<tr>
<td>8</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-pub-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Pub</span></a></td>
<td>5,478</td>
</tr>
<tr>
<td>9</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-hotzone-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Hotzone</span></a></td>
<td>5,413</td>
</tr>
<tr>
<td>10</td>
<td><a href="http://blog.kraasecurity.com/wp-admin/hotspots-hot-spot-airport-directory-browse-by-country.htm?provider_id=0"><span style="color: #000099;">Airport</span></a></td>
<td>2,938</td>
</tr>
</tbody>
</table>
</div>
<p> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">Gary Bahadur</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #c0504d;"><a href="mailto:baha@kraasecurity.com"><span style="color: blue;">baha@kraasecurity.com</span></a></span></span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://www.kraasecurity.com/"><span style="color: blue;"><span style="font-family: Calibri; font-size: small;">http://www.kraasecurity.com</span></span></a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;"><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></span></span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;"><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></span></span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Managed Security Services</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Vulnerability Management</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Compliance &amp; Policy Development</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*PGP Security</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*FREE Website Security Test</span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/06/22/wireless-insecurity-in-your-pocket/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Security- Identity Theft and Hacker ransom</title>
		<link>http://blog.kraasecurity.com/2009/05/07/healthcare/</link>
		<comments>http://blog.kraasecurity.com/2009/05/07/healthcare/#comments</comments>
		<pubDate>Thu, 07 May 2009 22:57:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=34</guid>
		<description><![CDATA[I hope no one is actually shocked by this story. Records are stolen everyday. Typically, the hackers will sell the information in the underground somewhere is Eastern Europe or Asia. The fact that someone is asking for ransom, and so publicly it actually a good thing in my opinion. Why is it good you ask? (I [...]]]></description>
			<content:encoded><![CDATA[<p>I hope no one is actually shocked by this story. Records are stolen everyday. Typically, the hackers will sell the information in the underground somewhere is Eastern Europe or Asia. The fact that someone is asking for ransom, and so publicly it actually a good thing in my opinion. Why is it good you ask? (I assume you are asking that, vulcan mind meld and all that..) Maybe the industry (meaning all industries) need a sensational story to get real change in their IT Security environments.</p>
<p>When the <strong>Heartland data breach</strong> happened, it was interesting but the general public didnt find it sexy enough. A ransom note, publicly done makes for good drama. Equate it to the Somali pirates. They really broke in the news because of the weapons they captured. This might be the &#8220;weapons&#8221; story that gets the general public asking about security of the places they use on the Internet.</p>
<p>Identity theft is on the rise. Most companies never do a web application security assessment. They almost never do a database security review. If the hacker can break in through your web portal but your database of customer data is encrypted, well your last line of defense can save your hide.</p>
<p>So what are some things you can do to protect your website?</p>
<p>1) Conduct a <strong>web application security assessment</strong>. You should probably do this twice a year or anytime you make any significant changes to the application.</p>
<p>2) Conduct an <strong>architecture review</strong>. If your network architecture has holes in it, a hacker can find away around the application and perhaps get to the data through a different port.</p>
<p>3) Conduct a <strong>host security diagnostic review</strong>. If the hacker can get on the system and take advantage of an operating system weakness, you will still be compromised</p>
<p>4) Conduct a <strong>database security review</strong>. Your last line of defense, make sure the data in encrypted, access is completely authenticated and IDS on the database to flag and stop inappropriate access</p>
<p>5) Hire someone smart to do your <strong>security assessment</strong>.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">Gary Bahadur</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://www.kraasecurity.com/"><span style="color: blue;"><span style="font-size: small; font-family: Calibri;">http://www.kraasecurity.com</span></span></a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Managed Security Services</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Vulnerability Management</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Compliance &amp; Policy Development</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*PGP Security</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*FREE Website Security Test</span></span></span></p>
<p>+++++++++++++++++++++++++++++++++++++++++++++++</p>
<div id="blogstitle">The Channel Wire</div>
<div id="blogsdate">May 06, 2009</div>
<div id="blogsheadline2"><a href="http://blog.kraasecurity.com/security/217300538"><strong><span style="color: #0b2795;">Hacker Holding Health Records Hostage Demands Ransom</span></strong></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/05/07/healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ways to Maintain Website Security</title>
		<link>http://blog.kraasecurity.com/2009/04/10/website-security/</link>
		<comments>http://blog.kraasecurity.com/2009/04/10/website-security/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 14:33:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Code review]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[firewall management]]></category>
		<category><![CDATA[Intrusion detection system]]></category>
		<category><![CDATA[Intrusion prevention system]]></category>
		<category><![CDATA[Managed Vulnerability Scanning]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=3</guid>
		<description><![CDATA[With the advancement in technology comes the heavy responsibility of monitoring an organization&#8217;s sensitive and valuable information. The use of the Internet has become a necessity in organizations to exchange their data and various other business details with their business partners, vendors and clients. In many cases, during transmission of datahackers compromise a network or [...]]]></description>
			<content:encoded><![CDATA[<p>With the advancement in technology comes the heavy responsibility of monitoring an organization&#8217;s sensitive and valuable information. The use of the <a class="zem_slink freebase/guid/9202a8c04000641f800000000001de59" title="Internet" rel="wikipedia" href="http://en.wikipedia.org/wiki/Internet">Internet</a> has become a necessity in organizations to exchange their data and various other business details with their business partners, vendors and clients. In many cases, during transmission of datahackers compromise a network or transmission medium and illegally gain the data. It maligns not only the market value of the company but also the number of clients that place trust in the company and the company’s infrastructure or website.</p>
<p>There are preventive measures that every company can adopt to maintain the value of the company as well as the client base. It is very important for any company to maintain the data securityase and safeguard the internal information of the company. The clients and business partners share their data only after confirming that the partner company will keep it safe and intact under the safety norms of the company.</p>
<p>By taking a few cautionary measures, one can easily secure the sensitive information of the company. Installing a <a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall">firewall </a>in the network system keeps the security intact and safe. Earlier, this was a bit expensive for companies but with the advent of technology, this has become an easily accessible tool for the organization. Affordable monthly subscriptiuons are available for <a class="zem_slink freebase/en/firewall" title="Firewall" rel="wikipedia" href="http://en.wikipedia.org/wiki/Firewall">firewalls</a>, <a class="zem_slink freebase/en/intrusion-detection_system" title="Intrusion detection system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">Intrusion detection systems</a> and host <a href="http://www.kraasecurity.com/managed-services/intrusion-defense/intrusion-detection">intrusion prevention systems</a>.  They need not spend a lot of money in availing these services now.</p>
<p>A firewall is the main defense. A firewall carries out routine security checks and blocking techniques at particular time intervals and this helps stop attacks. It will sound an alert in case of any threat posed to the data and will automatically start blocking and reporting.  on it. It never compromises on your company&#8217;s security and safety and always keeps the information safe. Firewall protection can be easily availed from various online sources at quite reasonable rates but one must always cross-check the credentials of the source company as well and only then purchase it from experts in the field.</p>
<p>Other than installing these tools to maintain web security, companies are also hiring third parties to review the policies and procedures of the organization and also to keep track of the online process of distribution of data of the company. These third parties install web applications that thoroughly review the codes installed in the process and provide valuable feedback to update and upgrade the quality of network systems. hough it is somewhat expensive to employ third-parties but they really keep a detailed track of the security system of their clients&#8217; information.</p>
<p>Many network systems of very renowned companies are getting hacked and misused these days by the hackers. It is high time that the companies take proper action against such activities and thefts as the number of incidents are growing day-by-day. Otherwise, people will start losing their trust in sharing their personal information through web sites.</p>
<p>A web security expert of <a href="http://kraasecurity.com/">application security risk assessment</a> has written this article.</p>
<p>Gary Bahadur<br />
baha@kraasecurity.com<br />
<a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Managed Security Services<br />
Managed Firewall<br />
Managed Vulnerability Scanning</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.schneier.com/blog/archives/2010/03/electronic_heal.html">Electronic Health Record Security Analysis</a> (schneier.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.channelweb.co.uk/crn/news/2260643/saas-demand-fuel-growth">SaaS demand to fuel growth in security services</a> (channelweb.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/03/19/gartner_virt_server_security/">Fake servers even less secure than real ones</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=aa33117b-3a26-49b8-afd8-63a851e3d98f" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/04/10/website-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

