Wow, so 2014 is over apparently. And that means a new blog post. Every year I like to sit back and think about significant events and take stock of where I am and where I would like to be in the not too distant future.
I found late in 2014 that I had read a few books that really got my attention with me. I am not normally a big reader - at least of entire books. With my attention span matching Twitter more than the New York Times, unless it grabs me in the 1st chapter or so, I am not going to get very far. However the two books below were addictive reads for me and likely for other people in IT/InfoSec. So I thought I would share my two cents on them in the hopes that if anyone reads this post they might be led to read either of these two future classics - IMHO.
Countdown to Zero Day by Kim Zetter
I am very glad this book did not come out before I had written my master's thesis on Stuxnet. If the book had come out I would have been hard pressed to not simply use this book as a primary source and all of her references as secondary. Kim Zetter hit it out of the park with this book. Her writing and ability to tell a complex true story and cover both the facts as well as unpack some of the bigger issues that Stuxnet raised as far as that thing people call Cyberwar made this a page turner for me. The amount of solid research she did for this book is clearly massive, including interviews with those who were doing the analysis and putting pieces together - the Symantec duo and Ralph Langner and his team as well as VirusBlokAda who appear to have found the first sample and began to realize the complexity of the Stuxnet attack.
Spam Nation by Brian Krebs
Krebs is a celebrity/hero amongst InfoSec bloggers. A former IRL Washington Post journalist, he has been blogging on the underbelly of the Interwebz for a long time. He has been able to infiltrate forums and actually get acquainted with people who are involved in criminal activities using/abusing technology. The credit card black market for one, and the former kingpins of the spam world for two. His research and connections gave him enough material for an entire book devoted to the email scourge we call spam. In some ways it's a sad statement on modern life, how everyone has more or less accepted needing an email filter in 2014 the same way we need other defensive technologies such as firewalls/antivirus/etc. Sad to me in that from Krebs' point of view a significant amount of spam could have been stopped long ago if the right people/organizations got together sooner than they did. Suffice it to say the tales Krebs lays out in his book are fascinating, and the spam business is unlikely to go away. The fake pharmacy topic alone is enough to get you thinking and wondering about how the prescription drug problem is not going away soon, and why it is that the big drug companies seem unwilling to participate in significant efforts to stop people from buying versions of their drugs online - both legit versions that have the right active ingredient and others that do nothing and/or contain some scary ingredients no human being should ingest.
Well, that is all I have to say about the books above. I recently began Shane Harris' book @War and it looks to be a good read as well but until I get further into it I can't say much. If you want to know how/why the NSA got to where it did post-Snowden this one looks to have a lot of meaty goodness.
I wish all who end up reading this a wonderful year, no matter what year you read this ;)
Monday, January 12, 2015
Saturday, January 11, 2014
How did it get to be 2014 already?!?
My poor forgotten blog, ever since my ADHD met Twitter things just haven't been the same between me and this blog.
I hope and pray anyone who stumbles on this forsaken corner of blogger.com has a great 2014 (or whatever year it is when you read this.)
In reflecting on 2013 it was a pretty decent year. I finally finished my master's degree - Master's of Science in Information Assurance (MSIA) at Davenport University in the Spring. Overall I was pretty pleased with the program. I took the online route, and while I would have preferred to go to class and meet other people in person the convenience of online is hard to beat if you have a job and/or family or are busy like most people are. My thesis was about Stuxnet and the ways that a utility organization can prevent a similar attack from occurring in their control system/SCADA environment. Stuxnet is a fascination of mine as I work for a municipal utility, and our control systems are the crown jewels of our IT infrastructure.
My new year's resolution is to restart banjo lessons and to continue to grow in my knowledge/application of InfoSec. I know the latter is too vague, but I don't feel like writing about specifics right now. I'd rather kick back and listen to the B side of Bruce Springsteen's Born to Run, as the A side just ended. Plus my kids are chilling and they actually asked for more tunes from my little vinyl vault. Like the Kids in the Hall used to say, "Life is a pretty sweet fruit."
Peace out,
Doug
I hope and pray anyone who stumbles on this forsaken corner of blogger.com has a great 2014 (or whatever year it is when you read this.)
In reflecting on 2013 it was a pretty decent year. I finally finished my master's degree - Master's of Science in Information Assurance (MSIA) at Davenport University in the Spring. Overall I was pretty pleased with the program. I took the online route, and while I would have preferred to go to class and meet other people in person the convenience of online is hard to beat if you have a job and/or family or are busy like most people are. My thesis was about Stuxnet and the ways that a utility organization can prevent a similar attack from occurring in their control system/SCADA environment. Stuxnet is a fascination of mine as I work for a municipal utility, and our control systems are the crown jewels of our IT infrastructure.
My new year's resolution is to restart banjo lessons and to continue to grow in my knowledge/application of InfoSec. I know the latter is too vague, but I don't feel like writing about specifics right now. I'd rather kick back and listen to the B side of Bruce Springsteen's Born to Run, as the A side just ended. Plus my kids are chilling and they actually asked for more tunes from my little vinyl vault. Like the Kids in the Hall used to say, "Life is a pretty sweet fruit."
Peace out,
Doug
Tuesday, January 22, 2013
(Belated) InfoSec Predictions for 2013
Now that we are more than halfway through January I feel obligated to make my predictions for what will happen in 2013. Are you ready to have your mind blown?
MORE OF THE SAME!
I know, it is not a pearl of wisdom but with 2013 already bringing us a vulnerability in IE 6, 7 & 8 plus... [wait for it] yet another scary bad Java vuln, the year is off to a helluva start.
And let us not leave out our favorite whipping boy(s)/girl(s) at Adobe - Reader and Flash remain among the best ways to pop a box with our pals at Oracle and their Java write once debug everywhere platform.
So there you have it from the security equivalent of the armchair quarterback.
As they used to say on Hill Street Blues, let's be careful out there.
Peace,
Doug
Sunday, January 20, 2013
Welcome to 2013!
Wow, my blog is so very neglected. With Twitter fitting my attention span better, it isn't likely to see many new posts this year either. And I think I am OK with that.
Happy belated new year to all who stumble on this lonely blog. I pray 2013 will be a better year for you and yours. My new year's resolution is to be grateful and appreciate at least one person and/or thing every day. There's a lot of good to be happy about in this life if we open our eyes and make an effort to be aware of it.
Sincerely,
Doug
DefCon 20 (My 1st pilgrimmage)
The summer of 2012 was an eventful one for me - several camping trips with my better half the kids and of course the dog. Two new babies in the family tree - congrats to my brother and sister! Add to all of that my 1st visit to the mother of all InfoSec cons - DefCon XX.
I was very excited when the planets aligned and I received work and home management approval to attend. I've been wanting to go for as long as I can remember, so this was a bucket list-worthy item in my book.
DefCon did not disappoint. Met many new people from across the US and around the world: Brazil, Germany, Romania, and more. I even made a new friend from Canada of all places (hi Carlo!) from working on the scavenger hunt with some friends from Grand Rapids.
I went to a handful of talks each day and wandered around taking in all the other happenings - the contests, gaming areas, the DefCon private cellular network van... The standout talks for me were General Keith Alexander, Mark Weatherford from DHS, Wesley McGrew, and Cutaway - the ones related to critical infrastructure protection, vulnerability research on SCADA HMIs & how breakable many current 'smart' meters are.
I hope to return next year if possible and perhaps take in both Black Hat + DefCon.
I was very excited when the planets aligned and I received work and home management approval to attend. I've been wanting to go for as long as I can remember, so this was a bucket list-worthy item in my book.
DefCon did not disappoint. Met many new people from across the US and around the world: Brazil, Germany, Romania, and more. I even made a new friend from Canada of all places (hi Carlo!) from working on the scavenger hunt with some friends from Grand Rapids.
I went to a handful of talks each day and wandered around taking in all the other happenings - the contests, gaming areas, the DefCon private cellular network van... The standout talks for me were General Keith Alexander, Mark Weatherford from DHS, Wesley McGrew, and Cutaway - the ones related to critical infrastructure protection, vulnerability research on SCADA HMIs & how breakable many current 'smart' meters are.
I hope to return next year if possible and perhaps take in both Black Hat + DefCon.
Wednesday, April 18, 2012
Notacon 9 - Cleveland FTW!
Back to Notacon - where to begin? Froggy and friends put on a conference like no other -
literally. It is a very cool mix of InfoSec, IT, hackers, geeks and people who are fun to meet/talk to and hang out with. Met a guy who has the same Yamaha QY10 sequencer/synth that I have. That almost NEVER happens. Seriously, who had one of these but me - let alone remembers (not so) fondly doing MIDI step programming to put together a basic drum rhythm and bass line?http://en.wikipedia.org/wiki/Yamaha_QY10
And then there are the talks at Notacon. I am biased b/c I got to present with my friend EggDropX but still - there were fascinating talks on everything from open source music making via algorithms to how to help your kids be good Internet consumers. You aren't going to get that at most other conferences that I've been to. And if you are like me either work won't pay for BlackHat/DefCon or you cannot afford it out of pocket.
And so, let me close this brief shout out with some advice - you owe it to yourself to checkout Notacon 10 in 2013, and also you need to go to GrrCON. It's what put GR on the InfoSec map. This is year 2 and it will blow your mind and if it doesn't there is free beer. Enough said.
www.notacon.org + www.grrcon.org = doubleplusgood
Friday, July 8, 2011
A Fresh Perspective

After returning from a nearly two week vacation I realized how important it is to take a break, get away, relax and recharge. While the first day back at work was a rather painful adjustment to the reality of work and not being able to do whatever I wanted for the day, on day two I realized that I had clarity on some things that had been rather fuzzy before vacation. It was like when the coffee kicks in on a morning after a good night of sleep and suddenly things make sense - only more so.
So my summer 2011 advice is get out of the house, get out of town if you can and spend time with people you love and who love you be it friends or family. Or, if you are so inclined get away for a few days alone. Do something fun, try something new, consider pursuing a hobby completely unrelated to your job. Leave the cell phone at home (or at the very least turn off the pulling of work emails.) I found camping where there is no cell signal whatsoever helps if self control does not allow a completely off the grid getaway.
Tuesday, February 8, 2011
Know Thyself -> Subtitle: Is DIY always a good idea?

A recent presentation I did at work for management about justifying hosted SIEM (Security Information & Event Management) and some follow-up questions from leadership got me thinking about the do it yourself ethos. I think IT in general and InfoSec specifically are big on DIY and this is for the most part a good thing in my opinion.
Products/solutions like Snort/Wireshark/Metasploit/etc. would not be what they are today without the roll up your sleeves, pour yourself another cup of caffeine, get down to the bits and bytes or hex command line foo.
(You knew the but was coming.) But when does trying to be all ninjas to all people become your achilles heel? If you are in a small IT shop is it realistic to think I (or perhaps you the reader) can be a master of all [CISSP] domains? Could trying to do it all lead to missing important stuff while trying to figure out whether or not to worry about a particular IDS event that may or may not be important.
Maybe this is about trying to reassure myself that the insecurity devil that occasionally sits on my left shoulder saying "YOU ARE A NOOB AND A POSER AND YOU WILL NEVER BE A NINJA" is just a figment of my imagination. Or perhaps I am taking a look in the mirror and trying to have an honest self assessment and admit that I am better off finding a good consulting shop to help me tune my IDS/IPS or perhaps hiring out some security functions such as log/event analysis ala SIEM.
Everyone has different gifts/talents/abilities. Knowing yours and admitting which hats do not fit is sometimes painful but can also be a liberating experience and lead to focusing on what gets you fired up.
Sources:
- This post was inspired in part by a radio program I heard featuring Christian author/speaker Chip Ingram about doing a sober self assessment - identify your 3 greatest strengths and 3 biggest weaknesses, there was more to the talk but this to me was the crux.
- The thinking chimp photo is just something I thought about after watching a Nature episode on monkeys - did you know some monkeys have learned to lie and they also have squabbles between groups which lead to injury and death?
Friday, December 31, 2010
My 2011 prediction = more of the same

Since I am not able to predict the future and I don't have enough big picture expertise in InfoSec to make intelligent and plausible predictions, I am going to take the easy way out. I know it isn't exactly exciting and you might even call it lame, but I predict 2011 will bring more of the same. (I am not a poet, and I know it.)
- Increasingly frequent financial data breaches ala TJX and Heartland
- Malware, malware, and STILL MORE malware - and likely even more crafty varieties
- Finally, the one that freaks me out most of all - more SCADA/Control System activity ala Stuxnet. Even without (alleged ;) government involvement, no doubt the bad guys took careful notes of the possibilities. The terrorists and government sponsored groups are likely pulling down additional copies of Siemens, Schneider, Rockwell, Modicon et al softwarez and likely also buying a representative bunch of PLCs to increase their mad skillz in pawning pumps, valves and variable frequency drives.
Thursday, December 16, 2010
More Amusing Malware

So this one really cracked me up. My friend and co-worker Matt are chatting about this and that with an infected client sitting behind us running a virus scan when BOOM the computer came to life with another of your garden variety fake AV. It was funny and sad at the same time.
It gets better, after pulling the Ethernet plug out and watching to see what Matt calls the bad mojo was going to do next (several minutes passed, not much happening) then all of a sudden the following warning about an attack/threat from a specific IP.
If the bad guys can block threats even when the computer is offline, that is simply cool and yet unfortunately impossible. I love my job.
Monday, December 13, 2010
InfoSec FUD Marketing

I received this email recently and I think it hit on my last good nerve. C'mon people, do we really need this kind of crap going around in 2010?
If this email works to drum up business for a telecom/security/whatever consulting group, I would really like to find out who the people are biting on this particular fish hook. I would call them myself under the guise of Doug's Ninja Service LLC as I think I could also sell them some DLP snake oil or perhaps a bit of magic pixie dust that stops all future malware variants - in the cloud.
Thursday, December 2, 2010
Censorship be damned

December in Michigan began with a snowstorm and a chill in the air that seems to be stuck inside my bones. While it does not seem to have affected my lukewarm heart, the jury is still out.
I thought that I would begin the last month of the year by posting a PDF of my absolute fave blog post of 2010. I can say that now because there is no possible way to upstage this gem.
Matt Olney of Sourcefire VRT fame posted a somewhat inflammatory but 100% spot on rant that was shortly thereafter removed. I made a PDF from the ever useful Google cache version and am posting it here until the ever witty and sharp tongued Mr. Olney asks me to remove it himself.
The Rise of the Citizen Cyberwarrior by Matt Olney
Monday, November 29, 2010
Cloudy with a chance of better security

I have been mulling over cloud computing a little bit lately. My thoughts (as usual) are pretty simplistic so far. I work in the small/medium environment where good InfoSec is rare as hens teeth. IMHO, the issues are primarily time and expertise. Small IT shops tend to be reactive and spend a lot of time firefighting. Proactive security is just plain hard, and when you are doing InfoSec as a sideline or a hobby within your daily work it is a million baby steps to reach a decent security posture ala 2010. Can it be done? Yes. Do I feel like I am there yet? Not even close, but moving in the right direction.
So take virtualization and then take cloud computing aka using somebody else's virtual infrastructure by way of the Internets. I am all about that. If it is possible for say Google Apps or Microsoft's "Cloud Power" to serve up COTS applications and protect data in a way that prevents people from the usual bad habits i.e. emailing themselves that spreadsheet full of PII, what is the downside? Plus if cloud computing means that we can move to a thin client desktop approach where few applications need to be installed after the inevitable malware infection(s), then my good friend Matt the desktop guy has a reduced suck factor. That's a win-win in my book.
At the risk of over-statement, do I really believe I can do security better than say Google, Microsoft or Amazon AWS? I guess it depends on how arrogant and/or delusional I am. Enough said.
There is some good reading on Lenny Zeltser's blog around how the risk factors in the Cloud are not all unique in comparison to other disruptive technologies. As for me, I can't wait to stick my head and hands in the cloud(s) - and keep them there.
Wednesday, November 17, 2010
Fake AV - Phunny Fail

If you are in IT these days you likely see your fair share of fake/rogue antivirus malware, be it @ work or home (or your beloved Aunt Edna - you know the one who always forwards you the Nigerian 419 scam emails wanting to know when to expect the big payoff.)
Last week at work a co-worker received a drive-by 'gift' of goodness on his XP box. We use WSUS for the Microsoft patches and Symantec Endpoint Protection for client side I'net 'security'/AV and your mileage probably sucks as bad as ours. We're still trying to win the battle on Adobe / Apple patching, not there yet but moving along.
Anywho, this particular fake AV crapware does something really quite hilarious - it changes your desktop wallpaper to a FUD factor alarmist litany of bad things that can happen if you disregard the pleas of the badware to detach yourself from your hard earned $50 which will be guaranteed to do nothing but lead to someone spending more money (with your card number.)
If you believe the above warning - all those movies/MP3s you deleted are STILL THERE and "could break your life!" It is too bad the author's English was not up to par. Some days you just gotta laugh, 'cause the crying gets old after a while. And while I hate malware as much as the next guy, no one I know of has ever died from an infection.
Image courtesy of the Rogue Antispyware blog, a great resource for all the latest Fake AV news.
Saturday, November 13, 2010
I don't wanna be 'that guy'

I was thinking the other day, reflecting really. I do that once in a while but I'm no Jack Handey. I was thinking about a few times recently where I have been either confronted (by my better half) or felt convicted internally about my behavior as far as either exaggerated or extreme statements I have made on topics that raise my blood pressure. I do not wish to be a robot or shell of a man who has no emotion, but I was surprised on a couple of occasions at the strength of my own reaction - overreaction is more like it.
There are times in life when we all see our own ugliness. When the mirror is raised and we are at our worst, or at least close to it. I am grateful that God reveals these things to me, call it what you like if you are not a believer - intuition / insight / etc. The facts here don't change.
I do not want to be that guy (the jerk with the funny hat). The me who is impatient with people at work who are maybe a bit slow on the uptake, who don't agree with me on a matter that seems obvious (from my perspective), or the InfoSec No Team. You know, the folks who relish explaining ad nauseum why something cannot or should not be done instead of offering up constructive alternatives and/or suggestions as to how something could be done securely or at least more securely. Or sarcastically telling everyone who will listen (or not get away fast enough) about how piss poor and totally pawnable this or that system/software/OS is.
Dan Lohrmann addresses this in several of his blog posts, I am a big fan of Dan's openness and honesty especially in matters related to relationships - the squishy but critical soft skills those of us in IT sometimes fail to give adequate time and effort:
http://blogs.csoonline.com/the_customer_is_clueless_not
So at the risk of sounding like a dork cheerleader, join me in committing to doing better with patience and hearing people out to gain perspective. Think back to the times you have learned things from people you had perhaps written off as total n00bs.
Tuesday, October 26, 2010
Help me help you

Warning, this is a rant
To the user in this state of cluelessness: If you are unable or unwilling to assist your friendly neighborhood IT person/department with such fundamental principles as where you store your work related files, or what the frig you named a file (even one single word that you are certain was in the file name), then I am sorry to say that you are on your own.
And when it comes to InfoSec and DR/BC the same rules apply. If you don't have the ability to care about where your files are and whether they are being backed up, and you are OK with leaving your password post-it under your keyboard then I must advise you that I will find it hard to muster any sympathy or empathy when (not if) you get powned. In fact it will take every bit of my already limited supply of self control
So the subtext on the t-shirt above reads: because their ignorance is your job security. True that, I shut up now...
Sunday, October 17, 2010

Had an all around good time in Cleveland last week @ the (8th annual) Information Security Summit 2010. I had not previously attended this event, I was impressed. Good mix of speakers/topics and not too many vendors. I was grateful my employer allowed me to do the pre-conference training Mon/Tue/Wed.
Monday was a pretty good overview of 'next-gen' firewalls. Well, specifically Palo Alto Networks firewalls but they didn't push their product hard and the concepts behind application aware firewalls makes sense as a way to have better control of the things you want to allow vs. those you don't.
Tuesday/Wednesday was the highlight of the week for me, Intro to Malware Analysis taught by certifiable reverse engineer ninja Tyler Hudak. Tyler works for Richard Bejtlich at a little outfit known as General Electric. The course was very well thought out, great curriculum/flow and a good deal of hands-on with some of the current tools of the trade. Just enough to make me want to do more of this myself, while still realizing that it is an area of InfoSec where keeping skills sharp and moving to the next level is no small feat.
My favorite talk for the conference would have to be David Kennedy's Social Engineering Toolkit demo and evangelism soapbox. Mr. Kennedy created the SET and the demo struck fear in most of the people in the audience, me included. SET is no doubt an amazing tool, and David makes a strong case for SE becoming a standard part of pentesting.
Monday, September 20, 2010
800LB Gorillas Piss Me Off

So maybe I've been living under a rock for 6 months, but as my previous boss used to say on occasion, "what a d^ck move." I was working on a VPN issue today and I found that while I was sleeping Cisco reversed their statement there would NOT be a 64 bit IPSEC client for 64 bit Windows Vista/7. Ahem, so they released it in late April after many companies including the one I work for blew a wad of cash on buying SSL VPN licenses. Yeah, so 64 bit XP can't run it but how many people are running 64 bit XP? No offense if you are, but there just aren't that many of you.
Makes me about as happy as when M$ said Exchange public folders are going away for good years ago. At least until everyone started drinking the SharePoint kool-aid and then SURPRISE, just kidding. We'll let you keep your public folders. I am a SharePoint fan, but still.
Grrr..... Happy Monday to me.
Makes me about as happy as when M$ said Exchange public folders are going away for good years ago. At least until everyone started drinking the SharePoint kool-aid and then SURPRISE, just kidding. We'll let you keep your public folders. I am a SharePoint fan, but still.
Grrr..... Happy Monday to me.
Saturday, September 11, 2010
Sourcefire Razorback

I had meant to post this some months ago when fall seemed far away, but the announcement (timed for Black Hat) of Sourcefire's brand new thing aka Razorback caught my interest. The meaty articles are still somewhat lacking, but this brief markety bit on Dark Reading makes it sound worth a look. And true to form from the people who brought you Snort, the new 'mean pig' logo is just cool. Now if only one of the guys I used to work with would volunteer to help me get it up and running...
Thursday, July 15, 2010
Windows XP SP2, Thanks for the Memories

So this week brought the last security patches for Windows XP SP2. Interesting that XP SP3 will be supported until 2014. The 2020 date was somewhat misleading but is explained here:
http://www.zdnet.com/blog/bott/xp-in-2020-not-even-close-read-the-fine-print/2270
Hard to believe XP came out in 2001 and SP2 came out in 2004. Time to think about Windows 7, and the pain of getting rid of, replacing or re-writing those legacy apps. As I heard someone say the other day, the only constant is change.
Subscribe to:
Posts (Atom)