IT Trenches:

vulnerability


November 17, 2008  7:44 PM

Surviving Cisco Telephony – SRST



Posted by: Troy Tate
administration, Cisco, DataCenter, design, diagnostics, IP telephony, PSTN, risk, unified communications, VoIP, vulnerability

As you may have seen in some of my previous posts the company I work for has implemented VOIP/IP telephony at some of our locations. VOIP - IPT - QOS - COS on and on - Oh...

Bookmark and Share     0 Comments     RSS Feed     Email a friend

November 11, 2008  3:51 PM

Did you see this? – MS08-067 and the Security Development Lifecycle



Posted by: Troy Tate
administration, analysis, awareness, blog, Data security, debugging, design, Development, malware, Microsoft, Microsoft Windows, patching, risk, Security, server, vulnerability

As you probably already know, Microsoft issued an urgent out of cycle security patch recently for a Vulnerability in Server service could allow remote code execution. Look here for additional


October 10, 2008  7:58 PM

Counterfeit Metrics – Type II Reverse Engineering



Posted by: Troy Tate
analysis, awareness, botnet, Data security, dhs, IT education, malware, Metrics, Monitoring, performance monitoring, reporting, research, risk, Security, vulnerability

If you are into metrics, you might find this article rather interesting. For Good Measure: Type II Reverse Engineering A couple of the security metrics I find interesting:

Counterfeit hosts...


October 9, 2008  3:00 PM

Alternatives to e-mail attachments – SharePoint is risky!



Posted by: Troy Tate
administration, Data security, DataManagement, design, email, Exchange, Firewalls, intellectual property, Networking, Policy, policy enforcement, risk, Security, SharePoint, Storage, vulnerability, website

I'm looking for some help on this topic and have posted a question to the ITKE community. Hopefully someone out there has had some experience with this service for your...


September 19, 2008  12:53 PM

Did you see this? – Encyclopedia of internal network security threats



Posted by: Troy Tate
antivirus, awareness, botnet, Browsers, Data security, design, Firefox, forensics, homeland security, honeypot, malware, man-in-the-middle, Microsoft, Microsoft Windows, Monitoring, Networking, Policy, reporting, research, risk, Security, tools, troubleshooting, vulnerability, web, website, WWW

Promisec has released an online encyclopedia of internal network security threats. This is available online for free. There is a lot of information to look through and decide how the risks affect your organization. Take...


September 8, 2008  4:49 PM

Did you see this? – 2007 Web Application Security Statistics Project



Posted by: Troy Tate
awareness, data loss, Data security, Database, DataManagement, Development, internet, malware, Metrics, Monitoring, Policy, research, risk, Security, tools, vulnerability, web, website, WWW


August 22, 2008  8:02 PM

Poor Spelling = Identity Lost



Posted by: Troy Tate
administration, awareness, blog, Browsers, CA, certificate authority, design, forensics, howto, intellectual property, malware, man-in-the-middle, MITM, network analysis, Networking, online identity, reporting, risk, Security, SSL, vulnerability, web, website, WWW

Well, I am not the best speller and I know that is true for most people. I have recently discovered how this human weakness can get you into trouble and cause identity loss as well as potential financial loss. This issue has recently come to light with some of the Black Hat presentations. The...


August 14, 2008  2:58 AM

Managing risk & vulnerability



Posted by: Troy Tate
administration, antivirus, awareness, CIO, Data security, DataCenter, DataManagement, design, forensics, honeypot, IT education, malware, Monitoring, Policy, policy enforcement, risk, Security, vulnerability

Jotting some quick thoughts here after answering a user post. Thought I would place the same information here for all to see. This list is by no means complete and your thoughts are always welcome. Some ways to measure risk include: How valuable is the asset? How much of a threat...