Look Beyond the Exploit

January 25th, 2010 admin

The post One Exploit Should Not Ruin Your Day by Dino Dai Zovi made me think: Finally, the larger problem is that it only took one exploit to compromise these organizations. One exploit should never ruin you day. [sic] No, that is wrong. The larger problem is not that it “only took one exploit to compromise these organizations.” I see this mindset in many shops who aren’t defending enterprises on a daily basis. This point of view incorrectly focuses on exploitation as a point-in-time, “skirmish” event, disconnected from the larger battle or the ultimate campaign. The real “larger problem” is that the exploit is only part of a campaign, where the intruder never gives up. In other words, comprehensive threat removal is the problem. There is no “cleaning,”…


Originally posted on TAOSecurity

 
  Related Posts
Gonzalez Accomplice Gets Probation for Selling Browser Exploit
Gonzalez Accomplice Gets Probation for Selling Browser Exploit
A computer security professional who sold Internet Explorer exploit code to credit card hacker Albert Gonzalez was sentenced Tuesday in Boston to three years probation and a $10,000 fine. Jeremy Jethro, 29, was paid $60,000 by Gonzalez for a zero-day exploit against Microsoft’s browser, “the purpose and function of which was to …... 
All Aboard the NSM Train?
All Aboard the NSM Train?
It was with some small amusement that I read the following two press releases recently: First, from May, NetWitness® and ArcSight Partner to Provide Increased Network Visibility : NetWitness, the world leader in advanced threat detection and real-time network forensics, announced certification by ArcSight (NASD: ARST) of compliance with its Common... 
Two Dimensional Thinking and APT
Two Dimensional Thinking and APT
I expect many readers will recognize the image at left as representing part of the final space battle in Star Trek II: The Wrath of Khan. During this battle, Kirk and Spock realize Khan’s tactics are limited. Khan is treating the battle like it is occuring on the open seas, not in space. Spock says: He is intelligent, but not experienced.... 
Hackers exploit Adobe Reader flaw via comic strip syndicate
Hackers exploit Adobe Reader flaw via comic strip syndicate
Hackers broke into an online comic strip syndication service Thursday, embedding malicious code that sought to exploit a newly discovered security flaw in Adobe Reader and Acrobat, Security Fix has learned. On Monday, Adobe Systems Inc. said it was investigating reports that criminals were attacking Internet users via a previously unknown security... 
Attribution Using 20 Characteristics
Attribution Using 20 Characteristics
My post Attribution Is Not Just Malware Analysis raised some questions that I will try to address here. I’d like to cite Mike Cloppert as inspiration for some of this post. Attribution means identifying the threat, meaning the party perpetrating the attack. Attribution is not just malware analysis. There are multiple factors that can be... 
  Related Tweets from Twitter
MelissaBasolo (Melissa Basolo)  : Just unpacked my entire room in our new apt in Chelsea, and am now packing again for Provincetown with the gays for a week!..
Updated : 2010-07-31T00:03:21Z   |  Reply  |  View Tweet
iamDalia (Dalia)  : Some lady at work just started crying to me bc her cell phone doesn't work in her new apt. Aw I wanted to hug (cont) http://tl.gd/2r8bff..
Updated : 2010-07-31T00:03:15Z   |  Reply  |  View Tweet
CheckWoodz (Check Woodz)  : @Misha_Renee yeah I got some raw fish at my apt we can cut it up and wrap some rice around it....lol...I got soy sauce too..
Updated : 2010-07-31T00:03:04Z   |  Reply  |  View Tweet
adambatty (adam batty)  : So, today is my stag. I'm going to watch an apt film in the morning. At the moment I'm thinking the loneliness of the long distance runner...
Updated : 2010-07-31T00:02:49Z   |  Reply  |  View Tweet
erica1597 (Erica Stewart)  : http://bit.ly/cMFtMH Press Release - CSR expands audio expertise with acquisition of APT..
Updated : 2010-07-31T00:02:44Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.

Spam Protection by WP-SpamFree

TOP