Wednesday, October 11, 2017

"Hey America (and World) GDPR Applies to You To"

In 2003 California rocked the privacy world when it passedCalifornia S.B. 1386. This law stated that any organization that was breached and had the personal data of California residents had to notify those individuals that their data was breached. While the lawwas only passed inCalifornia, the law impacted any organization in the United Statesthat handled … Continue reading Hey America (and World) GDPR Applies to You To

from lspitzner

Tuesday, October 10, 2017

SharePoint and OneDrive: security you can trust, control you can count on

This post is authored by Bill Baer, Senior Product Marketing Manager, SharePoint and OneDrive Team.

In todays complex and regulated environment, businesses need to focus on building more secure solutions that deliver value to their customers, partners, and shareholdersboth in the cloud and on-premises.

Microsoft has been building enterprise software for decades and running some of the largest online services in the world. We draw from this experience to keep making SharePoint and OneDrive more secure for users, by implementing and continuously improving security-aware software development, operational management, and threat-mitigation practices that are essential to the strong protection of your services and data.

SharePoint and OneDrive are uniquely positioned to help you address these evolving security challenges. To begin with, Microsoft has continued to evolve with new standards and regulations. This has been a guiding principle as we think about security for SharePoint and OneDrive. Right alongside that principle is this one: There is no security without usability. If security gets in the way of productivity, users will find a different, less secure way to do their work.

SharePoint and OneDrive allow your organization to go beyond its regular business rhythms and be nimbler in responding to market changes and opportunities. These solutions enable users to access the files and documents they need wherever they’re doing work while sharing and collaborating in real-time. And you control and own your data while Microsoft takes care of it. Explore the many options SharePoint and OneDrive provide to secure you and your information and then read our eBook Securing your content in the new world of work with SharePoint and OneDrive.

For businesses, the time is now to reevaluate security practices. In the modern communications and collaboration, landscape connectivity is ubiquitous and the ability to work remotely has become an ingrained part of the work practice. People have come to expect to be able to access email and documents from anywhere on any device – and for that experience to be seamless.

While this has been an enormous boost to productivity, it also presents huge challenges for security. Previously, businesses needed to concern themselves with a firewall that ended at the corporate boundary. Now that boundary has shifted to the end user. Businesses need to ensure sure that corporate data is safe while enabling users to stay productive in today’s mobile-first world, where the threat landscape is increasingly complex and sophisticated.

We know that data loss is non-negotiable, and overexposure to information can have legal and compliance implications. SharePoint and OneDrive provide a broad array of features and capabilities designed to make certain that your sensitive information remains that way with investments across our security and compliance principles to include compliance tools that span on-premises servers and Office 365 while providing a balance between enabling user self-service.

The rapidly-changing security landscape means that your organization’s content – its knowledge – is being shared more broadly, and accessed from more devices and more locations, than ever before. We’re committed to the security, privacy, and compliance of your data, and we continuously innovate intelligent ways to protect your content and to empower you to govern and manage information. Last month we announced label-based classification for information management policies, which enable a more dynamic governance of content across SharePoint, Exchange, and Skype, and Microsoft Teams. We’re continuously working to ensure content usage adheres to corporate policy defending your organization from todays growing and evolving advanced threats.

To learn more about security and compliance with SharePoint and OneDrive:



from Microsoft Secure Blog Staff

Monday, October 9, 2017

BruCON Network 0x09 Wrap-Up

BruCON 0x09 is over! It’s time to have a look at the data captured during the last Thursday and Friday. As the previous years, the setup was almost the same: An Internet pipe with a bunch of access-points, everything interconnected through a pfSense firewall. The guest network (dedicated to attendees) traffic is captured and processed by a SecurityOnion server + basic full packet capture. We also used our classic wall-of-sheep to track the web browsing activity of our beloved visitors.

Let’s start with a few raw numbers. With the end of the 3G/4G roaming costs in Europe since June, most European visitors avoid the usage of wireless networks and prefer to remain connected via their mobile phone. In a few numbers:

  • 206 Gigabytes of PCAP files
  • 50.450 pictures collected by the wall-of-sheep
  • 19 credentials captured
  • 500+ unique devices connected to the WiFi network
  • 150 PE files downloaded (Windows executables)
  • 3 blocked users
  • 1 rogue DHCP server

We saw almost the same amount of traffic than the previous years (even if we had more people attending the conference!). What about our visitors?
Unique Wi-Fi Clients by OS over Time

Strange that we had some many “unknown” device. Probably due to an outdated MAC address prefixes databases.

Top 10 Applications by Usage - Summary

Good to see that SSL is the top protocol detected! UDP reached the third-position due to the massive use of VPN connections. Which is also good!

Our visitors communicated with 118K+ IP addresses from all over the word:

Worldwide Connections

Here is the top-20 of DNS requests logged:

Rank

FQDN Hits

1

api.dataplicity.com

59310

2

www.google.com

20097

3

softwareupdate.vmware.com

9050

4

auth.gfx.ms

6766

5

swscan.apple.com

6706

6

v10.vortex-win.data.microsoft.com

5300

7

www.googleapis.com

5252

8

www.icanhazip.com

4402

9

www.google.be

3831

10

clients4.google.com

3721

11

play.google.com

3562

12

win10.ipv6.microsoft.com

3459

13

outlook.office365.com

3267

14

ssl.gstatic.com

3130

15

settings-win.data.microsoft.com

3111

16

pingsl.avast.com

2884

17

safebrowsing-cache.google.com

2841

18

avast.com.edgesuite.net

2533

19

graph.facebook.com

2164

20

0x13.nl

1990

As most of the traffic captured was web-based, I had a look at the different tools/applications used to access web resources. Here is the top-20:

Rank

FQDN

1

Firefox

2

Chrome

3

Microsoft-CryptoAPI

4

Microsoft

5

Safari

6

Dalvik

7

trustd

8

MSIE

9

cloudd

10

Debian

11

Windows-Update-Agent

12

iPhone

13

Unspecified

14

Microsoft-WNS

15

CaptiveNetworkSupport

16

serer-bag

17

MICROSOFT_DEVICE_METADATA_RETRIEVAL_CLIENT (1)

18

Spotify

19

Unknown

20

Microsoft-Delivery-Optimization

(1) https://docs.microsoft.com/en-us/windows-hardware/drivers/install/device-metadata-retrieval-client

I uploaded the 200+ gigabytes of PCAP data into my Moloch instance and searched for interesting traffic. What has been found:

  • One visitor polled his network devices (172.16.x.x) during the two days (5995 SNMP connections detected)
  • Two visitors performed RDP sessions to two external IP addresses
  • Two visitors generated SIP (VoIP) traffic with two remote servers
  • 29 remote IMAP servers were identified (strange, no POP3! 🙂
  • SSH connections were established with 36 remote servers (no telnet!)

Finally, our wall-of-sheep captured web traffic during the whole conference:

Wall of Sheep

Of course, we had some “p0rn denial of service attacks” but it’s part of the game right? See you for the 0x0A (10th edition) next year with, crossing fingers, more fun on the network!

 

[The post BruCON Network 0x09 Wrap-Up has been first published on /dev/random]



from Xavier

[SANS ISC] Base64 All The Things!

I published the following diary on isc.sans.org: “Base64 All The Things!“.

Here is an interesting maldoc sample captured with my spam trap. The attached file is “PO# 36-14673.DOC” and has a score of 6 on VT. The file contains Open XML data that refers to an invoice.. [Read more]

[The post [SANS ISC] Base64 All The Things! has been first published on /dev/random]



from Xavier

Thursday, October 5, 2017

"The Five Tenets of Cyber Security"

In thetwo day MGT433 Securing the Human course, we start the class bydefining what risk is. Security awareness is nothing more than acontrol to manage human risk. To manage risk, you have to first define it. What stuns me is how often security professionals that have been in this field 5, 10 or even 15 … Continue reading The Five Tenets of Cyber Security

from lspitzner

Announcing support for TLS 1.1 and TLS 1.2 in XP POSReady 2009

This post is authored by Arden White, Senior Program Manager, Windows Servicingand Delivery.

As a follow-up to our announcement regarding TLS 1.2 support at Microsoft, we are announcing that support for TLS1.1/TLS 1.2 on Windows Embedded POSReady 2009 and Windows Embedded Standard 2009 is now available for download as of October 17th, 2017. Were offering this support in recognition that our customers have a strong demand for support for these newer protocols in their environment.

This update for Windows Embedded POSReady 2009 and Windows Embedded Standard 2009 will include support for both TLS 1.1 and TLS 1.2. For application compatibility purposes, these protocols will be disabled by default in a manner similar to the TLS 1.1/TLS 1.2 support that was disabled by default in Windows 7 and Windows Server 2008 R2. After downloading and installing the update these protocols can be enabled by setting the registry keys described in KB4019276.

This update is being made available on the following timeline:

Release Date Channels Classification
October 17, 2017 Microsoft Catalog
January 16, 2018 Windows Update/WSUS/Catalog Optional
February 13, 2018 Windows Update/WSUS/Catalog Recommended


from Microsoft Secure Blog Staff

Wednesday, October 4, 2017

"October OUCH! Newsletter - Something Special for #CyberAware Month"

OUCH! is a free security awareness newsletter published every month in over 25 languages. Each edition focuses on a specific topic on howanyone can securely make the most of today'stechnology. In the past ten years OUCH! has become the world's most trusted security awareness newsletter, from personal use at home to the largest organizations in … Continue reading October OUCH! Newsletter - Something Special for #CyberAware Month

from lspitzner