Showing posts with label Investigations. Show all posts
Showing posts with label Investigations. Show all posts

Monday, April 15, 2013

Australian Feds charge 17 year-old 'Anon' with four crimes

17-year-old suspected member of ‘Anonymous’ charged with unauthorised access to computer data

A 17-year-old youth appeared in Parramatta Children's Court on Friday (5 April 2013) to face charges relating to unauthorised access to computer data. The juvenile is suspected to be a member of the online issue motivated group "Anonymous" and allegedly committed serious offences on their behalf.

Commander Glen McEwen, Manager Cybercrime Operations, said the AFP takes any computer intrusion offences very seriously and remains committed to investigating offences that occur in cyberspace. "Protesting through computer intrusions and website defacements is not an appropriate method to raise public awareness about any issue," Commander McEwen said. "The AFP investigates various types of cybercrime and will continue to take a strong stance against these perpetrators."

Refer here to read more details.

Saturday, August 11, 2012

6 Steps to Handle IT Security Incidents

New Guide from the National Institute of Standards and Technology

The National Institute of Standards and Technology has issued a revision of its guidance to help organizations establish programs to manage computer security incidents.

NIST, in Special Publication 800-61 Revision 2: Computer Security Incident Handling Guide, spells out what incident-response capabilities are necessary to rapidly detect incidents, minimize loss and destruction, mitigate weaknesses that were exploited and restore IT services.

Revision 2 updates the original guidance to reflect changes in attacks and incidents. "Understanding threats and identifying modern attacks in their early stages is key to preventing subsequent compromises, and proactively sharing information among organizations regarding the signs of these attacks is an increasingly effective way to identify them," NIST says in the introduction to the guide.

"This revised version encourages incident teams to think of the attack in three ways," says guide co-author Tim Grance. "One is by method - what's happening and what needs to be fixed. Another is to consider an attack's impact by measuring how long the system was down, what type of information was stolen and what resources are required to recover from the incident. Finally, share information and coordination methods to help your team and others handle major incidents."

The Recommendations

The guide advises organizations to:

  1. Reduce the frequency of incidents by effectively securing networks, systems and applications.
  2. Document their guidelines for interactions with other organizations regarding incidents. Because these communications often need to occur quickly, organizations should predetermine communication guidelines so that only the appropriate information is shared with the right parties.
  3. Be generally prepared to handle any incident but should focus on being prepared to handle incidents that use the most common attack vectors. Incidents can occur in countless ways, so it's not feasible to develop step-by-step instructions for handling every incident.
  4. Emphasize the importance of incident detection and analysis throughout the organization. Millions of possible signs of incidents may occur each day so automation is needed to perform an initial analysis of the data and select events of interest for review.
  5. Create written guidelines for prioritizing incidents. Incidents should be prioritized based on relevant factors, such as the functional impact of the incident (e.g., current and likely future negative impact to business functions), the information impact of the incident (e.g., effect on the confidentiality, integrity and availability of the organization's information) and the recoverability from the incident (e.g., the time and types of resources that must be spent on recovering from the incident).
  6. Use the lessons learned process to gain value from incidents. After a major incident has been handled, the organization should hold a lessons-learned meeting to review the effectiveness of the incident handling process and identify necessary improvements to existing security controls and practices. 

NIST says the guidelines can be followed independently of particular hardware platforms, operating systems, protocols or applications organizations use.

Thursday, June 14, 2012

Metasploit: The Penetration Tester’s Guide

Want a great book on Backtrack 5 and the Metasploit Framework?


Look no further than “Metasploit: The Penetration Tester’s Guide” written by the all star cast of David Kennedy (creator of the Social Engineering Toolkit), Jim O’Gorman (instructor at Offensive-Security), Devon Kearns (a BackTrack Linux developer), and Mati Aharoni (created BackTrack and founder of Offensive-Security). 


This is the most complete and comprehensive instruction book for Metasploit that I have seen so far. The authors walk you step by step, command by command through using the Metasploit Framework as a penetration tester. You move quickly from the basics of Penetration testing through using the platform to perform the different phases of intelligence gathering and exploitation. 


Excellent book for anyone interested in a hands on approach to computer security, the Metaslpoit pro who wants a great reference book and those new to Metasploit that want a step by step instruction manual.


Metasploit: The Penetration Tester’s Guide – Check it out!

Sunday, July 31, 2011

Security Training Video: Investigating DoS Attacks

Introduction to DoS Attacks and techniques

CareerAcademy.com is offering a free EC-Council training video to try out their training delivery platform.

The course offered is on Computer Hacking Forensics Investigator (CHFI): Investigating DoS Attacks, and is intended for IT security professionals. The course outline is below, along with a link to try it out.

Please feel free to forward to others in your organization who may be interested this type of training.

Link to sign up for the free training course:
http://www.careeracademy.com/download/freeCHFIm31.html

Course Description:

This free introductory online training course (Value at $195) will immerse the student in an interactive environment where they will be shown how to investigate DoS attacks. Students will be introduced to the types of DoS attacks, buffer overflow, DoS attack techniques, intrusion detection systems, live demonstrations of SYN Flooding, Smart Sniff, 3D Trace Routes, and many more critical concepts.

Use the link above to sign up, and or more information, visit www.careeracademy.com or contact CareerAcademy.com at 1-800-807-8839 x201 (US), 1-781-453-3900 x201 (International), email: info@careeracademy.com

This course is Module 31 of a 51 module EC-Council Computer Hacking Forensic Investigator CHFI Training CBT Boot Camp.