2016-03-22

NAXSI – Open-Source WAF For Nginx

Niginx用のwebアプリケーションファイアウォール。使ってみたいところです。

----
NAXSI – Open-Source WAF For Nginx
// Darknet – The Darkside

NAXSI is an open-source WAF for Nginx (Web Application Firewall) which by default can block 99% of known patterns involved in website vulnerabilities. NAXSI means Nginx Anti XSS & SQL Injection Technically, it is a third party Nginx module, available as a package for many UNIX-like platforms. This module, by default, reads a small subset...

Read the full post at darknet.org.uk

----


2016-03-20

Defence In Depth For Web Applications

これ面白い記事ですね。多層防御、defence in depthをwebアプリに適用するときの考え方。こういうテンプレートが増えていくと、セキュリティの向上ににつかがりますね。

----
Defence In Depth For Web Applications
// Darknet – The Darkside

Defence in depth for web applications is something that not many companies apply even though the model itself is nothing new. Defence in depth refers to applying security controls across multiple layers, typically Data, Application, Host, Internal Network, Perimeter, Physical + Policies/Procedures/Awareness. Defence in depth is a principle of...

Read the full post at darknet.org.uk

----

2016-03-17

More than a Billion Snapdragon-based Android Phones Vulnerable to Hacking

クアルコムのSoCまわりに、ルート昇格のバグがあったらしい。影響範囲が10億というのがなんとも、スケールが大きい。

----
More than a Billion Snapdragon-based Android Phones Vulnerable to Hacking
// The Hacker News

More than a Billion of Android devices are at risk of a severe vulnerability in Qualcomm Snapdragon chip that could be exploited by any malicious application to gain root access on the device. Security experts at Trend Micro are warning Android users of some severe programming blunders in Qualcomm's kernel-level Snapdragon code that if exploited, can be used by attackers for gaining root

----

2016-03-08

=?cp932?Q?Turing_Award_=81\_Inventors_of_Modern_Cryptography_Win?= =?cp932?Q?_$1_Million_Cash_Prize_?=

ディッフィーとヘルマンがチューリング賞を取ったらしい。暗号からのチューリング賞は感慨深い。

----
Turing Award — Inventors of Modern Cryptography Win $1 Million Cash Prize
// The Hacker News

And the Winners of this year's Turing Award are: Whitfield Diffie and Martin E. Hellman. The former chief security officer at Sun Microsystems Whitfield Diffie and the professor at Stanford University Martin E. Hellman won the 2015 ACM Turing Award, which is frequently described as the "Nobel Prize of Computing". Turing Award named after Alan M. Turing, the British mathematician and computer

----

2016-02-28

Nissan LEAF cloud security fail leaves drivers exposed

ニッサンのリーフもクラウド周りがあやしそうなもよう。

----
Nissan LEAF cloud security fail leaves drivers exposed
// Naked Security - Sophos

Guess how strong the "password" is that protects the data that your Nissan LEAF electric car uploads to the cloud...
----

2016-02-27

IKE/IKEv2 Ripe for DDoS Abuse

RDDoSがなかなか治らないようす。今度はikeを悪用するみたい。

----
IKE/IKEv2 Ripe for DDoS Abuse
// The Akamai Blog

By Bill Brenner, Akamai SIRT senior tech writer

Akamai's Security Intelligence Research Team (SIRT) is conducting research into the security posture of the Internet Key Exchange (IKE & IKEv2) protocol. The paper outlines the findings thus far, including configurations in the protocol itself that attackers could potentially leverage to launch reflected DDoS campaigns.

Our motivation to examine it is based on the nearly ubiquitous nature of IKE/IKEv2,  which is used to facilitate secure key exchanges between peer devices in the IPsec protocol suite. It is widely deployed in multiple secure tunneling applications such as VPN products from major vendors and open source projects.

Given its heavy use, it made sense to take a look under the hood.

Several UDP protocols have appeared on our radar during more than four years of active monitoring and advisory releases concerning reflection-based DDoS attacks. Results yielded from this research have gone into Akamai's State of the Internet Security reports supporting active trends in the DDoS threat landscape.This history has sparked efforts internally to help discover potential UDP based reflection and amplification opportunities, with the goal of disclosing, cleaning up, and fixing issues before they can be weaponized for DDoS.

This is our first piece of research in this regards and is dedicated exclusively to discoveries in IKE/IKEv2. What follows is what we learned after setting our sites more intently on the protocol.

The full paper, available here, delves into the history of IKE, offers visuals to illustrate where the weaknesses are and offers steps organizations can take to reduce risk exposure.


----

(お知らせ)「ドコモnet」のセキュリティ機能を強化 -「マカフィー(R) インターネット セキュリティ」の12か月間無料提供サービスを開始-

NTTは回線にセキュリティの付加価値をつけるサービスを始めるらしい。どれくらいの精度があるのか気になるところ。

----
(お知らせ)「ドコモnet」のセキュリティ機能を強化 -「マカフィー(R) インターネット セキュリティ」の12か月間無料提供サービスを開始-
// NTTドコモ 報道発表資料


----