If you ever find yourself in front of a public computer connected to the Internet and are concerned about the security of the path between you and a website you wish to visit, a SOCKS proxy can come in handy. SOCKS proxies generally allow you to “bounce” a TCP connection off another server transparently– basically instructing another computer to make a connection on your behalf. When used in combination with Secure Shell (SSH), it can form an encrypted tunnel that insulates you from anyone attempting to grab traffic off the wire. The following is a simple step-by-step tutorial about how to do this. You will need: -Putty SSH client: http://www.putty.org -An account on an Internet-accessible server that accepts SSH connections[…]

A while back I posted about my and others’ concerns about Firefox’s newly handled way of dealing with self-signed or unapproved certificates. It seems the folks over at Carnegie Mellon University have released an extension for Firefox to help deal with this exact issue. My main issue with my last posting wasn’t directly tied to the error in the security model Firefox was introducing, but simply the intrusion factor of what was taking place, and the lack of information that FF was providing when denying access to the site. The extension provides two primary benefits: If you connect to a website with an untrusted certificate (e.g., a self-signed certificate), Firefox will give you a very nasty security error and force[…]

One of our clients unintentionally DoSed themselves this weekend by switching registrars. In what turns out to be an honest mistake on someone’s part, the new registrar set the company’s DNS servers to the registrar’s (pretty standard action), but they didn’t copy the old DNS information from the previous registrar. Effectively denying service to the organization’s mail server (no DNS entry and no MX record), and some websites that generate revenue. I would suspect that this is a common situation for smaller companies. They decide that they’re not happy with their current registrar for whatever reason, and switch. Unfortunately, not understanding how computers find each other and buying into the “complete hosting solution” packages offered by many registrars. In an[…]

IBM’s X-Force R&D has sent out a report( “pdf”:http://www-935.ibm.com/services/us/iss/xforce/midyearreport/xforce-midyear-report-2008.pdf ) detailing computer security statistics collected over the first six months of 2008. Among the results of this report, we find the following (compared to last year’s figures): Decreased time between disclosure and public exploit Further shift from OS and multimedia exploits to web browser exploits Further shift from browser core to browser plugins What this tells us is that attackers are keeping a steady eye on the disclosure process itself, quickly adapting the details into POC code. It also shows that attackers are recognizing and taking advantage of the browser as an attack vector– a trend that has been steadily increasing over the past few years. Another interesting trend that[…]

This week, Websense published its State of Internet Security report for the first half of the year.  Here are some things to take away from it: Legit Sites with Malicious Code – Most of the sites that contain malicious code are legitimate and have been compromised.  This number went up 50 percent over the past six months.  The growing popularity of sites with user-contributed content is opening holes in areas of the Web that people consider trustworthy.  Sixty percent of the top 100 sites have been involved in some kind of malicious activity this year. “Blended Threats” Increase – Continually increasing amounts of e-mails contain a link to a spam site or a site with malicious code.  “Storm” attacks are[…]

Today we are proud to present an update to the Security Musings site.  We’ve moved to WordPress, and made the look and feel very similar to the main Gemini Security Solutions site.  We have also started using FeedBurner to manage our feeds, allowing you to subscribe to Security Musings by email.  Please let us know if you notice any problems with the new site by leaving a comment below.  Enjoy!