INSECURE-Mag-8.pdf

(6247 KB) Pobierz
275439380 UNPDF
275439380.007.png
275439380.008.png
Hello everyone, welcome to issue 8 of (IN)SECURE. We’re happy to report that our subscriber list is
growing strong. This, combined with the e-mails and quality article submissions, is a clear indication that
the security community has embraced this concept and found it to be a valuable resource.
This issue is packed full with material for every knowledge level and will especially be of interest to those
that want to know more about the inner workings of the Payment Card Industry since we got two articles
related to the topic.
Mirko Zorz
Chief Editor
Visit the magazine website at www.insecuremag.com
(IN)SECURE Magazine contacts
Feedback and contributions: Mirko Zorz, Chief Editor - editor@insecuremag.com
Marketing: Berislav Kucan, Director of Marketing - marketing@insecuremag.com
Distribution
(IN)SECURE Magazine can be freely distributed in the form of the original, non modified PDF document.
Distribution of modified versions of (IN)SECURE Magazine content is prohibited without the explicit
permission from the editor. For reprinting information please send an email to reprint@insecuremag.com
or send a fax to 1-866-420-2598.
Copyright HNS Consulting Ltd. 2006.
www.insecuremag.com
275439380.009.png
Defend Windows web servers with ThreatSentry 3.0
ThreatSentry 3.0 is a Host Intrusion Prevention System (HIPS) specifically
designed to address internal and external unauthorized system access and
cyber-criminal threats on Web servers utilizing Microsoft Internet Information
Services (IIS). Since its introduction, IIS has grown in popularity and ranks as
one of the most widely used platforms for enabling simple to sophisticated
Web sites and Web-based applications. While it is well-regarded for its ease
of use and range of features, it is frequently targeted by hackers due to a va-
riety of IIS-related vulnerabilities and the inherently open nature of many
Web applications – many of which manage sensitive information such as
credit card numbers, passwords, or other private information. ThreatSentry pricing starts at $399
per server. For more information visit hwww.privacyware.com
AirDefense Mobile 4.0 released
AirDefense announced the release of AirDefense Mobile 4.0, the
newest version of the company’s security and wireless network
assessment tool. Mobile 4.0 includes a new analysis engine,
which is built on the award-winning, patented technology used in
the company’s flagship product, AirDefense Enterprise. The analysis engine provides network
administrators with more than 100 security and performance-based alarms, along with other new
features such as alarm notification via email or Syslog messaging. AirDefense Mobile runs on any
Windows 2000 or XP platform, and installs on any laptop with an Atheros-based 802.11 a/b/g
wireless card, such as Netgear (WAG511) or Cisco (CB21AG). For more information visit
www.airdefense.net
www.insecuremag.com
4
275439380.010.png 275439380.001.png 275439380.002.png
SECUDE releases Secure notebook 7.2
SECUDE secure notebook reliably protects notebooks, desktops and
external mass storage devices from unauthorised access. Unlike
other solutions it encrypts the entire hard disk rather than just indi-
vidual files or folders, which means it protects temporary files, swap
files and even the operating system itself.
A new feature with version 7.2 is the encryption of hibernation files
(the files that a notebook creates just before entering hibernation mode); eliminating the possibil-
ity of attack by this route and guaranteeing full protection in all circumstances.
This version also offers a Plug-In for BartPE; the Windows recovery system that boots and runs
from CD. It supports the creation of an emergency recovery disk (ERD), which can be used to
secure data for emergency cases, preventing loss; as well as getting the notebook running after a
system crash. More information is available at www.secude.com
Anti-keylogger plugin for Microsoft Internet Explorer released
A browser plugin named KeyScrambler was recently released by
Florida startup QFX Software. The Personal edition is free for
download at the company’s website and it protects all logins
against keyloggers.
The new anti-keylogging tool is an invaluable addition to the IE
users’ security as it protects all login pages and it does so by
encrypting the user’s keystrokes at the kernel driver level, before
keyloggers can record them. Download the trial from
www.qfxsoftware.com
AirPcap USB 2.0 WLAN packet capture device available
CACE Technologies announced the release of AirPcap
USB 2.0 WLAN packet capture device for Windows. The
device enables troubleshooting tools like Wireshark and
WinDump to provide information about the wireless proto-
cols and radio signals.
The AirPcap adapter, together with the Wireshark Network
Analyzer, gives you a detailed view on the 802.11 traffic,
including control frames (ACK, RTS, CTS), management
frames (Beacon, Probe requests and responses,
Association/Disassociation, Authentication/Deauthentication) and data frames. The captured
frames include the 802.11 Frame Check Sequence, and it’s possible to capture frames with an
invalid FCS to spot remote access points with a weak signal. For more information visit
www.cacetech.com
www.insecuremag.com
5
275439380.003.png 275439380.004.png 275439380.005.png 275439380.006.png
Zgłoś jeśli naruszono regulamin