Saturday, March 10, 2018

Infosec quotes - Incident Response prep

A key part of Incident Response success. 

“... Educate incident responders with what is ‘normal’ within the environment—installed software, permitted ports and protocols, acceptable use policies, etc...”


https://twitter.com/teoseller/status/972502345983627269?s=21

Infosec quotes - av is not dead

“... I know AV is supposedly dead and all that, but any decent AV would have prevented this developer's apps from being infected with the Ramnit worm…”


https://twitter.com/hasherezade/status/972551006751002624?s=21 

Infosec quotes - risk acceptance

Risk acceptance should be temporary and require renewal so that owners can reflect on past decisions and determine if new mitigations or better options now exist.

“... Just because you accepted the risk before and it worked out so far, it doesn't mean it won't go wrong eventually...”


https://twitter.com/techhelplistcom/status/972560140087037958?s=21 

Infosec quotes - printer to domain admin

Take seriously the security hardening of everything you plug into your network. Even printers.

“... It's just a printer... What's the worst that could happen? [SPOILER] Look at me.. I'm the Domain Admin now...”


https://twitter.com/grimhacker/status/971833029537677313?s=21 

Friday, March 9, 2018

Infosec quotes - http CNET

User shouldn’t be downloading their own software especially not from download sites like CNET. IT needs to vet these first. Oh and don’t download from insecure HTTP sites ever or this could happen.

“... Targeted users in Turkey and Syria who downloaded Windows applications from official vendor websites including Avast Antivirus, CCleaner, Opera, and 7-Zip were silently redirected to malicious versions by way of injected HTTP redirects...”


https://twitter.com/citizenlab/status/971976301299998720?s=21 

Infosec quotes - 700 emotet urls

Here’s what your security team is up against. Emotet phishing campaigns are blasted out daily from attackers to your users . Each days campaign has new urls, new payloads , and new c2 traffic. Yesterday’s batch had 700 urls in one day.


https://twitter.com/_ddoxer/status/972048093289091072?s=21 

Infosec quotes - fast flux

Good example why your security team needs real-time dns logs.

“... Here’s a simple illustration: If criminals assign www.uniquedomain.org a set of IP addresses that change every 150 seconds, users who access www.uniquedomain.org are actually connecting to different infected machines every single time...”


https://twitter.com/malwarebytes/status/940884072649445377?s=21