June 26, 2012

The two most feared attacks and how to avoid them

Large organizations with ample resources quake in their boots over two common security threats. Here's your best defense

These days when I'm consulting with big businesses, governments, and other organizations, two main topics come up over and over: pass-the-hash attacks and hacktivism. One government client put it thusly: "Our department considers pass-the-hash attacks our No. 1 threat, above all other computer threats." A lot of things are broken in the security world, so to pick out one and call it the greatest threat is saying something, especially since the customer has what most readers would consider nearly unlimited funds, a multitude of competing vendor partners, senior management support, and a horde of experts with whom to discuss the problem.

Defending against pass-the-hash atttacks
The reason pass-the-hash attacks are so feared is that once the password hashes have been obtained, the attackers can move around the compromised environment with ease. Hashes can be used to access any protected resource within the same forest. Worse, if a domain admin has logged on to a computer, a local attacker with Administrator credentials can harvest the domain admin authentication hashes right out of memory.

[ Prevent corporate data leaks with Roger Grimes' "Data Loss Prevention Deep Dive" PDF expert guide, only from InfoWorld. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

I think it is the latter attack, the ability for an attacker to elevate themselves to domain administrator -- just because a domain admin had logged on to a box -- that scares defenders the most. Essentially, the trustworthiness of your domain admin credentials are now an exponential factor of every computer they have ever been used on.

How to fix it? The best way is to not have any domain admins. Even if attackers compromise elevated accounts, their access is less than elevated domain admin. And if they add themselves to the domain admins group, an alert will be generated quickly because your monitoring software will know that should be an empty group. Here are other actions you can take:

Never log on to a normal end-user workstation as a domain administrator. Limit your domain administrator logons to domain controllers or special file servers. By never logging onto regular workstations, you significantly reduce risk.
If you have to log on using domain admin (or other elevated credentials), always do so from a trusted computer. These are known as "jump" boxes. These jump boxes can be unique per user, virtual machined, and flashed cleaned after every use. The idea is to always log on to boxes that you know are clean.
Do as many administration tasks and fixes as possible using remote console tools, which are less likely to leave password credentials in memory on the remote computers. Most pass-the-hash attacks take interactive log-ons (unfortunately Remote Desktop and Terminal Services are interactive log-ons), so the less of them you do, the better.
If you have to interactively log on to a computer, after you are through, reboot the computer (if possible). Rebooting removes the credential temporarily stored in memory.
Frequently update elevated account passwords. I have many clients who change passwords after every use, often with the help of third-party software. That way, if an attacker grabs the credentials out of memory, so what? They aren't any good anymore.

The No. 1 way to prevent pass-the-hash attacks is to keep the bad guy from getting domain admin or local admin in the first place. After doing your best to achieve that, see how far you can get using the other recommendations above.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com


The looming hacktivist threat
Another growing fear involves hacktivism-style attacks. Most companies point to the malicious success of the Anonymous group. Each CIO I've spoken with is increasingly worried that determined adversaries will get access to data if they want it.

You might ask why they don't fear APT (advanced persistent threats) as much. They do, but most have already been through that pain and are living with the outcome and response. And unlike APT, which usually steals data silently, hackivists steal data or cause DoS attacks, and they publicize the fact to embarrass the entity and cause it to lose customers, trust, and money. In many circles, the publicity factor is worse than some city-state threat looking to steal intellectual property.

How do you defend against hackivist threats? Most attacks of this ilk begin with a compromised Internet-facing host or social engineering of credentials from a trusted employee. If you're worried about hackivists, start here.

First, conduct a penetration test on your outward-facing assets. Why let random attackers be the first to test your new Internet-facing application, server, database, or defense? Use your own testers and/or hire "red teams" to fill the role of the rogue hackivist.

Make sure all custom application code has undergone security development lifecycle creation and review. Make sure all your software is created from the ground up with security built in from the start and not as an afterthought.

Engage in strong antisocial engineering education for all end-users who are in a position to release credentials or protected information. Recently, I was asked to assess how well a large company's antisocial engineering education and policies were working to prevent hackers, calling in over the phone, from obtaining credential information or other employee-related data from administrative assistants.

At this company, the assistants are part of the first-tier support for such information, and they're all trained to ask for specific information and/or to check for confirmation with superiors before releasing such data. I was amazed with the results. Although the company has thousands of administrative assistants, often changing, each with varying levels of computer skills and malware awareness, the education program has been highly successful.

After hundreds of over-the-phone hacking attempts each year, as far as I know, only one hacker was successful in the course of the last decade in obtaining a password reset and none were in obtaining personally identifiable information. No one knows if every attempt (successful or not) was noted, but when going back and auditing accesses and password resets, we were able to verify that nearly 100 percent of them were legitimate and valid requests when reported as such, and vice versa.

I got to listen (or read transcripts) to many of the recorded phone calls of hackers trying to obtain protected information from administrative assistants. The calls went something like this: The hacker would always start by being as friendly as possible, while asking for access to confidential information or a password reset. When challenged to produce the verifying information, the hackers always became more hostile. The more the assistants resisted, the more the hackers challenged. Many times, by the end of the call, the hacker would explode in anger and threaten the assistant's job security. I wondered how well I would have handled such a call early in my career. It showed me that a well-run education program could work.

Of course, you can't rely on end-user education alone. I prefer systematic DLP (data loss prevention) solutions. DLP software monitors your content and traffic flows to prevent unauthorized access. False positives are still a problem, but recent improvements have helped.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com

June 24, 2012

Microsoft, Google, IBM and Salesforce.com heat up PaaS

IBM, Microsoft, Google and Salesforce share their strategies regarding one of the hottest emerging areas of the cloud: Platform as a Service.

What do you get when you get four of the biggest cloud vendors in a room to talk about one of the hottest emerging trends in the industry? Not a whole lot of agreement for one thing.

At last week's Cloud Leadership Forum, which was sponsored by IDC Research and IDG Enterprise, officials from IBM, Google, Microsoft and Salesforce.com came together to discuss their platform as a service (PaaS) offerings. PaaS is a way to develop and deliver applications in the cloud, but it's the least mature of the three major cloud delivery models compared to infrastructure as a service (IaaS) and software as a service (SaaS). And pretty much one of the only things all four companies agree on is that PaaS is still in its early days.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com



While PaaS is still a developing market, some experts predict that PaaS could become the most important cloud model. PaaS lets companies build customized applications and designed from the start to run in the cloud. In the near term companies that embrace PaaS have a market differentiator compared to competitors, says Steven Hendrick, an IDC analyst tracking the PaaS market. As the IaaS and SaaS offerings continue to gain widespread adoption, the real differentiators for companies will be applications they have tuned to the specifications of their business needs, he says.

PaaS has some technology advantages as well, he adds. A PaaS environment sits between the software and infrastructure layers, which gives applications designed in a PaaS space insight into the supply and demand of the cloud environment. "That uniquely positions them to understand the workload demands of the applications and the system resources of the infrastructure," Hendrick says.

There's a growing marketplace of vendors attempting to stake a foothold in the PaaS arena. In addition to some of the big-name players like Microsoft, Google and Salesforce, emerging players such as Engine Yard, CloudBees and AppFog are also in the market. VMware has an open-source PaaS offering named Cloud Foundry, while Red Hat has its own PaaS offering named OpenShift, which is expected to be brought out of developer preview later this year. Amazon Web Services, the dominant public cloud IaaS provider, Hendrick says, could even be classified as a PaaS offering because it offers tools for developers to build and deploy applications in the AWS cloud.

But the four big-name tech stalwarts are making sure they're not left out of the cloud conversation moving forward.

Microsoft

Microsoft may have one of the most recognizable PaaS products in the market with its Azure platform, but Tim O'Brien, general manager and platform evangelist at Microsoft, says cloud is still mostly seen today through the lens of IaaS. "The PaaS question we get today is, 'How is that different from IaaS?'" In a simplified form, IaaS is nothing more than virtualized machines or storage, he says, whereas PaaS is a development fabric. The idea is that developers deploy the software and the application automatically provisions virtual machines to its specifications. To allow for easier connections between the PaaS and IaaS layer, Microsoft recently extended an IaaS offering to Azure, which O'Brien says makes it the most comprehensive cloud offering on the market. "No other provider has that kind of breadth," he says. The other major differentiator is the company's 25-year experience working with enterprise IT, which he says newer tech companies just don't have the experience of. "There are no shortcuts to truly understanding what keeps CIOs up at night," he says.

June 23, 2012

ComponentOne Studio for WinForms controls

Even with all the advancements in technology, two important factors for enterprise desktop development still hold true today. There remains a need for better performance and an appealing user interface (UI). Today, you've got the opportunity to win a free license of ComponentOne Studio for WinForms controls (valued at $1,195.00) that will help you do just that. (Note: contest is complete and winner awarded)

I was excited when presented with the opportunity to test ComponentOne's collection of .NET Windows Form controls included in the Studio for WinForms suite. What’s great about ComponentOne is that they have been providing some of the most well-known grids for Windows Client apps, FlexGrid and TrueDBGrid, since 1991. With that longevity, you know that their controls will stand the test of time and evolve along with market trends.

The Studio offers over 65 .NET Windows Forms controls, in some instances extending what is “in the box” and in others providing controls you can’t get anywhere else. ComponentOne Studio for WinForms controls include code-free designers, built-in features, like the ability to replicate popular interfaces as seen in Microsoft Office, and awesome flexibility. The Studio comes with controls like Chart, Ribbon, FlexGrid, Scheduler, Reports, and True DBGrid.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


As you read on you’ll see this product earned high remarks and we decided to hold a drawing so that one of our readers would have a chance to win a Free License of ComponentOne Studio for WinForms. Be sure you are logged in as an eggheadcafe.com member and click the entry banner to be automatically entered in the drawing

As a developer, you invest in a third party control suite (or get your employer to do so) for several reasons:
• First, because it provides controls with functionality that you need in order to develop better applications in less time.
• Second, because it can be significantly less expensive to purchase the control suite than to devote the many hours of development time that would be necessary to provide the needed functionality.
• And third, because the professional look and feel of a control suite enhances the usability and performance of your applications. Having reviewed ComponentOne's Studio for WinForms controls, it's my opinion that the suite meets all three criteria

One really strong suit for ComponentOne's Studio for WinForms controls is it's all-in-one reporting solution, which has a rich object model for generating reports, several UI controls for previewing, and a report designer for creating and designing reports. Reports for WinForms is pretty much an all-in-one reporting solution. You can generate professional looking, well-behaved reports for your applications. You can even integrate your existing reporting solutions (SQL Server, Access, Crystal) into your applications.

I used the report designer to create a custom report based on some tables in the trusty Northwind database with no trouble at all. You can drag fields onto your report designer surface and easily design custom reports exactly to your liking. I generated a Grouped-by-Country Sales report from Northwind in a matter of seconds, from a stored procedure. These can then be either printed, or exported to other programs such as Excel, PDF, Html, RTF, Text, and XML Paper Specification:

Here's another custom report I did with a C1 Chart control added. You can see my Bromberg IPA and Ultra Bock are doing well:

The C1Chart control offers a wide range of features and makes it relatively easy to create really stunning color charts of just about any type. Here's one I did using the OpenHighLowClose bar chart style for a stock:

C1Report provides a rich object model for creating, customizing, loading, and saving report definitions. Whether you need to generate reports with barcodes, charts, etc., or render reports directly to a printer or preview control it is possible using C1Report. You can also modify existing SQL Server SSRS reports or even create new reports completely in code using the C1RdlReport component

People often ask about importing, and with ComponentOne’s control you can import Access report files (MDB) and Crystal report files (RPT) using the C1ReportDesigner application. The C1ReportDesigner uses a banded report model for a highly organized and familiar layout. You can create complex hierarchical documents with automatic word index, TOC generation, data binding, and more with C1PrintDocument.

Controls that come with the C1Report features include:

C1Report Component : The C1Report component generates Access-style database reports. C1Report exposes an object model for creating, customizing, loading, and saving report definitions. I experimented mostly with this component. I found it easy to use and easy to customize with a variety of added controls.

C1RdlReport Component : The C1RdlReport component provides support for SQL Server Reporting Services. C1RdlReport exposes the full RDL object model so you can modify existing reports or create new reports without external dependencies such as Microsoft Reporting Services. Import your existing SSRS report definitions (RDL) into C1RdlReport to programmatically generate your reports and integrate them with the full ComponentOne Reporting suite.

C1PrintDocument Component : The C1PrintDocument component provides an object model that allows you to create arbitrarily complex documents in code. The object model specifically targets paginated documents, providing a rich set of features to facilitate automatic and intelligent pagination of complex structured documents. Documents can be completely created in code, or bound to a database via a flexible data binding model.

C1MultiDocument Component : C1MultiDocument is designed to allow creating, persisting and exporting large documents that cannot be handled by a single document object due to memory limitations. Use C1MultiDocument to combine multiple C1PrintDocuments, C1Reports and C1RdlReports which will be rendered as a whole continuous document with shared page numbering, a common TOC, word index, page count and inter-document hyperlinks.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Bookmark and Share