quinta-feira, 10 de setembro de 2009

Novo roubo de segredos na DuPont?

DuPont Alleges Second Insider Breach In Two Years
Chemical giant claims former employee was headed to China with company secrets

Set 09, 2009 | 05:47 PM

By Tim Wilson
DarkReading

Just two years after discovering an insider breach that might have cost it $400 million, DuPont is alleging theft of trade secrets by another one of its employees

According to an article in DuPont's home state of Delaware, DuPont has filed a lawsuit against -- and fired -- a Chinese-born employee who was allegedly about to leave Delaware and return to China with company trade secrets.

The suit, filed in late August in the Delaware Court of Chancery, accuses Hong Meng of breach of contract and misappropriation of trade secrets -- specifically, research into a paper-thin computer display technology called an "organic light-emitting diode," or OLED.

The suit alleges Meng was planning to take the proprietary information to his alma mater, Peking University in Beijing, which is involved in research on OLED technology, the report says.

DuPont issued a brief statement Friday, indicating Meng, a Chinese national with permanent residency status in the United States, was fired after an internal investigation, and the lawsuit was filed "to ensure that he not use or disclose DuPont trade secrets," according to the report.

"As a science company, DuPont acts to protect our unique and confidential technologies," the statement said. "These events underscore our unwavering commitment to protect the integrity of our proprietary science and technology for the benefit of DuPont shareholders, employees and customers."

DuPont says it spotted Meng's actions when it reviewed his hard drive prior to transferring him to China. Meng had downloaded a number of proprietary files about the OLED, the company alleges.

The chemical giant faced a similar problem two years ago, when former employee Gary Min was found to be in possession of thousands of files relating to the company's trade secrets. The estimated value of the information was assessed at around $400 million.

In that case, Min -- who also has ties to China -- downloaded thousands of documents without authorization from company systems. He also made paper copies of thousands more documents and stored them in an apartment he had rented for that purpose.

Min received a sentence of 18 months in jail and a $30,000 fine.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


sábado, 16 de maio de 2009

GFI fornece scanner free!

A GFI (www.gfi.com), empresa de soluções de segurança, dentro da iniciativa "We Care" (http://www.gfi.com/wecare/), disponibilizou dois de seus produtos em versões gratuitas.
 
O primeiro é o aclamado GFI Languard (www.gfi.com/lannetscan), para verificação de vulnerabilidades em servidores. A versão gratuita é para 5 IPs.
 
O outro é o GFI Backup Home Edition (www.gfi.com/backup-hm/), para backup e recuperação.
 
Vale à pena conferir, e usar!
 

sábado, 25 de abril de 2009

CISA - Best Certification Program - SC Magazine Awards 2009

A certificação CISA (Certified Information Systems Auditor) foi a vencedora do prêmio Best Professional Certification Program da SC Magazine Awards 2009.

Saiba mais detalhes aqui e aqui.

terça-feira, 21 de abril de 2009

NIST Released Draft SP 800-118

DRAFT SP 800-118 Guide to Enterprise Password Management

 

NIST announces that Draft Special Publication (SP) 800-118, Guide to Enterprise Password Management, has been released for public comment. SP 800-118 is intended to help organizations understand and mitigate common threats against their character-based passwords. The guide focuses on topics such as defining password policy requirements and selecting centralized and local password management solutions.

 

NIST requests comments on draft SP 800-118 by May 29, 2009. Please submit comments to 800-118comments@nist.gov with "Comments SP 800-118" in the subject line.

 

Drafts page URL for 800-118:

http://csrc.nist.gov/publications/PubsDrafts.html#800-118

 

 

-


quinta-feira, 16 de abril de 2009

O helicóptero de Obama tinha um cliente P2P com ligação direta com o Irã


marine-one

Uma empresa norte-americana, de nome Tiversa, especializada em segurança de informática, encontrou os detalhes dos sistemas de comunicação e de engenharia do "Marine One", ou seja, o helicóptero presidencial usado por Barack Obama, num computador em Teerã ligado a uma rede P2P.
A informação que estaria replicada para este cliente P2P iraniano continha, além dos já citados, detalhes dos sistemas de engenharia e de comunicações do helicóptero, informações sobre as atualizações de engenharia programadas, dados sobre a rede do helicóptero e vários planos do aparelho.

Ora se toda esta informação estava numa rede P2P, então é porque um cliente P2P estaria também instalado no helicóptero, parece que instalado por um outsourcing trabalhando para o Departamento de Defesa e que teria usado ou o LimeShare ou o BearShare num portátil que ligou na rede local do helicóptero.

Segundo a Tiversa, ainda que a instalação do cliente P2P no helicóptero possa ter sido não intencional, o fato destes dados terem aparecido em Teerã pode não o ser, já que se sabe que os iranianos estão particularmente atentos a informação que apareça nestas redes e que lhe possa ser útil.

O incidente, além de aumentar o risco de segurança para o Presidente dos EUA, expõe também o erro que é o de entregar a manutenção de meios tão sensíveis como este a empresas de outsourcing, que não têm regulamentos e implementações de segurança tão exigentes como os dos meios militares ou das forças de segurança. Isto não quer dizer que este tipo de programas não apareça instalado em computadores militares, já que a própria Tiversa admite que isso aconteceu diversas vezes na última guerra do Iraque e que o que existe, além de outsourcings relaxados, inconscientes e com uso exagerado, é também uma fraca cultura de segurança, ausente no sempre mais inseguro e exposto (porque mais usado) sistema Windows e utilizando (ou não) Group Policies relaxadas ou incorretamente implementadas.

FONTE
: http://topnews.us / COLABOROU: Edilson Moura

quinta-feira, 9 de abril de 2009

Microsoft Security Intelligence Report v6

A Microsft liberou a última versão de seu Security Intelligence Report (SIRv6), com análises de vulnerabilidades em softwares próprios e de terceiros. 


O documento pode ser baixado em www.microsoft.com/sir

sábado, 21 de março de 2009

New CS Anti-Virus based on ClamAV/ClamWin engine

Interessante, novo projeto baseado no ClamAV, agora para Windows.
 
Aguns detalhes (em inglês):

Include a Window service (CSAntivirus.exe) that perform all scans through the libclamav.dll, the control executable for
desktop interaction (CSAVTray.exe) and a small tool for generate new virus signatures (CSigTool.exe).
 
The project is developed in Visual Basic 6.0 and Visual C++ 6.0 (The C++ ATL CSAVCoreEngine.dll is a proxy for libclamav.dll). The project is "not yet stable".
 
This build is only 0.1.2 and is Beta. Anyhow the system is already usable on all NT based Windows Server and Client O.S. (from Windows 2000 to Windows 7) Tested on 2000/XP/Vista.

Follow a list of features:

Freeware, usable on server and client O.S., desktop interaction on system login (application on try bar), use of ClamAV engine and ClamAV virus database (main.cvd and daily.cvd), resident shield (File Guard) at the  moment only for one HD (or one root path), memory/process scan (on idle), File/Path scan, daily and weekly schedule scans, daily update, manual update, events log, event notify, virus log, quarantine (not yet complete), user-define signature creation tool, GUI for engine control, service control, program settings, notify, etc...

There are still many bugs (obviously), but the entire system is already usable.

On the follow link there are others information and the setup file:

http://www.creasoftware.net/prodotto.asp?id=16

sexta-feira, 20 de março de 2009

NIST Announces the Release of Draft Special Publication 800-16 Revision 1

> NIST announces the release of the Initial Public Draft (IPD) of
> Special Publication 800-16, Revision 1, Information Security
> Training Requirements: A Role- and Performance-Based Model. This
> publication is now available for public comment.
>
> The comprehensive training methodology provided in this publication
> is intended to be used by federal information security professionals
> and instructional design specialists to design (1) role-based
> training courses or modules for personnel who have been identified
> as having significant responsibilities for information security, and
> (2) a basics and literacy course for all users of information systems.
>
> We encourage readers to pay special attention to the Notes to
> Reviewers section, as we are looking for feedback on the many
> changes we have made to this document.
>
> Comments will be accepted until June 26, 2009. Comments should be
> forwarded via email to 800-16comments@nist.gov.
>
> URL to Draft SP 800-16 Rev. 1:
> http://csrc.nist.gov/publications/PubsDrafts.html#800-16-rev1
>
>
> Quick update - in the email sent to list on March 3, the NIST IR
> 7536 2008 Computer Security Division Annual Report was released. We
> have updated the PDF file for this document. We now have a final
> layout version available which includes charts, graphics, etc. The
> text inside this report did not change. For those interested in
> viewing the final printed version can find the updated PDF file here:
>
> It is a PDF file and depending on your Internet speed, it may take a
> couple extra seconds to load - PDF file is about 3.9 MB.
> http://csrc.nist.gov/publications/nistir/ir7536/NISTIR-7536_2008-CSD-Annual-Report.pdf
>

quarta-feira, 18 de março de 2009

Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5K

Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5K

Charlie Miller defends his title; IE8 also falls on Day 1 of hacking contest
Gregg Keizer
 

March 18, 2009 (Computerworld) Charlie Miller, the security researcher who hacked a Mac in two minutes last year at CanSecWest's PWN2OWN contest, improved his time today by breaking into another Mac in under 10 seconds.

Miller, a principal analyst at Independent Security Evaluators LLC, walked off with a $5,000 cash prize and the MacBook he hacked.

"I can't talk about the details of the vulnerability, but it was a Mac, fully patched, with Safari, fully patched," said Miller Wednesday not long after he had won the prize. "It probably took 5 or 10 seconds." He confirmed that he had researched and written the exploit before he arrived at the challenge.

The PWN2OWN rules stated that the researcher could provide a URL that hosted his or her exploit, replicating the common hacker tactic of enticing users to malicious sites where they are infected with malware. "I gave them the link, they clicked on it, and that was it," said Miller. "I did a few things to show that I had full control of the Mac."

Two weeks ago, Miller predicted that Safari running on the Mac would be the first to fall.

PWN2OWN's sponsor, 3Com Inc.'s TippingPoint unit, paid Miller the $5,000 for the rights to the vulnerability he exploited and the exploit code he used. As it has at past challenges, it reported the vulnerability to on-site Apple representatives. "Apple has it, and they're working on it," added Miller.

According to Terri Forslof, the manager of security response at TippingPoint, another researcher later broke into a Sony laptop that was running Windows 7 by exploiting a vulnerability in Internet Explorer 8. "Safari and IE both went down," she said in an e-mail.

TippingPoint's Twitter feed added a bit more detail to Forslof's quick message: "nils just won the sony viao with a brilliant IE8 bug!"

Forslof was not immediately available to answer questions about the IE8 exploit.

TippingPoint will continue the PWN2OWN contest through Friday, and will pay $5,000 for each additional bug successfully exploited in Apple Inc.'s Safari, Microsoft Corp.'s Internet Explorer 8, Mozilla Corp.'s Firefox or Google Inc.'s Chrome. During the contest, IE8, Firefox and Chrome will be available on the Sony, while Safari and Firefox will be running on the MacBook. The researcher who exploited IE8 will, like Miller, be awarded not only the cash, but also the laptop.

"It was great," said Miller when asked how it felt to successfully defend his title. "But I was really nervous for some reason this time. Maybe it was because there were more people around. Lucky [the exploit] was idiot-proof, because if I had had to think about it, I don't know if I'd had anything."

This year's PWN2OWN also features a mobile operating system contest that will award a $10,000 cash prize for every vulnerability successfully exploited in five smartphone operating systems: Windows Mobile, Google's Android, Symbian, and the operating systems used by the iPhone and BlackBerry.

Miller said he won't enter the mobile contest. "I can't break them," said Miller, who was one of the first researchers to demonstrate an attack on the iPhone in 2007, and last year was the first to reveal a flaw in Android. "I don't have anything for the iPhone, and I don't know enough about Google."

CanSecWest, which opened Monday, runs through Friday in Vancouver, British Columbia.

sexta-feira, 27 de fevereiro de 2009

Para configurar o Safari 4

Segue o link com os comandos para reconfigurar o Safari 4: http://swedishcampground.com/safari-4-hidden-preferences