Subscribe:

Thursday, 11 August 2011

The SSL Implementation Equation


Many SSL servers aren't as secure as you'd think, according to new data from Qualys' SSL Labs

By Kelly Jackson Higgins
Dark Reading 

Only about one-fifth of SSL websites actually redirect to SSL for authentication, according to new data released at Black Hat USA last week.

That's one deployment failure among several in today's SSL-secured websites. "In the security community, we talk about advanced attacks [in research], but today, it's not advanced attacks that are making sites vulnerable," says Ivan Ristic, director of engineering for Qualys. Organizations are improperly implementing SSL on their servers, he says.

Ristic has been working on a project for Qualys' community project SSL Labs, which has been studying major SSL sites over the past year. Among the latest findings: of the nearly 250,000 SSL sites, only 51,00 redirect to SSL, and the other 80 percent may or may not redirect to SSL for authentication, according to the SSL Labs data.

"So 80 percent of all vulnerable to a Firesheep attack or similar tool," Ristic says.

And when you visit an SSL site, you assume it protects your credentials. Well, not so much: Ristic says 70 percent of the servers handled the login in plain text, and 55 percent submitted passwords in plain text. "We looked for every authentication page in our crawler and tracked the implementation," he says. "They may a well-configured SSL server, but they made a conscious choice not to use SSL in authentication.

"In most cases, developers are not aware of these issues … Maybe they make mistakes. And there is a level of anxiety about performance," he says.

Ristic also looked at HTTP Strict Transport Security among the SSL sites he surveyed, and only 80 sites use HSTS, which provides a level of security against cookie-forcing attacks.

As for Extended Validation SSL (EV SSL), only nine sites had these certificates.

Ristic says overall, he has not seen much improvement worldwide in SSL server deployments over the past two years. "The only thing that will cause the sites to improve is to attack them or show them how easily it is to be attacked," he says, noting that such a scenario was what helped Google shore up its defenses.

"I don't want to name any of the SSL websites" that aren't securely implemented, he says. "Everyone is guilty of this. There are so few sites that do it well."


GlobalSign Provides Full Online Security Suite to the Spanish Market

SSL Certificates, malware monitoring, and digital signature solutions are now readily accessible to Spanish customers
 Leuven, Belgium (PRWEB) August 11, 2011

GlobalSign (http://www.globalsign.eu), one of the longest established Certification Authorities (CA) and specialists in Digital Certificate security, today announced the expansion of the GlobalSign brand further into the Spanish speaking market through the launch of http://www.globalsign.es. The fully localised web presence, backed-up by dedicated sales and support services in the native language will guarantee Spanish-speaking customers easy access to GlobalSign’s leading Digital Certificate solutions; making for a quick, effective and hassle-free experience.

With more than 1.7 million websites in Spain, only about 1% of those sites (12004) are SSL secured, meaning the risk of online fraud and identity theft are an everyday threat. GlobalSign, the first European Certification Authority, aims to educate customers about online threats, best security practices and appropriate solutions to help organisations mitigate the risks of using the Internet.

GlobalSign’s range of SSL Certificates help website owners ensure that any data transmitted over the Internet remains secure from prying eyes. The move into the Spanish market comes at a time when the Spanish SSL market is booming. As organisations recognise the need to protect themselves and their customers, secure sites have increased by almost 10% since the beginning of 2011. GlobalSign will help respond to increasing demand in SSL with a feature-packed offering and a simplified user experience through sales and customer service in the local language.

GlobalSign will be offering its full range of SSL Certificates directly to help meet a wide range of customer security requirements at cost-effective levels. The GlobalSign SSL products include fast issuance DomainSSL, Organisation Validated SSL and the most advanced and visible Extended Validated (EV) SSL Certificates. All GlobalSign Certificates use the strongest security levels available, with all browsers of all ages benefiting from the same strong encryption. GlobalSign SSL also works with every imaginable device that could connect to the customer’s website. All SSL Certificates also provide a free malware monitoring service, which scans the website for compromise and alerts website owners of the presence of malicious code, allowing then to tackle two major security concerns with a single product.

“GlobalSign is already familiar with the Spanish SSL market through our channel customers, and the new direct presence is an exciting development to further strengthen the GlobalSign brand in Spain and throughout Europe,” said Paul Tourret, managing director, GMO GlobalSign Ltd. “GlobalSign products provide the ideal answer for customers looking to secure their websites, online identities, and electronic documents. We look forward to helping enterprises meet data security and privacy compliance effectively.”

GlobalSign’s other Digital Certificate solutions will also be available from the new website, including SSL Managed Service for enterprises with multiple SSL Certificate requirements, Code Signing Certificates, Client Certificates for secure email and Microsoft Office document security, as well as Adobe PDF signing. GlobalSign’s expansion will provide the Spanish market with an exclusive “one-stop shop” for all PKI requirements.

To learn more about GlobalSign and the GlobalSign Digital Certificate Solutions, please visithttp://www.globalsign.es.

About GlobalSign 
Established in 1996 and as a WebTrust accredited public certificate authority, GlobalSign offers publicly trusted SSL Certificates, EV SSL Certificate, Managed SSL Services, S/MIME email security and Code Signing for use on all platforms including mobile devices. Its Trusted Root solution uses the widely embedded GlobalSign Root CA certificates to provide immediate PKI trust for Microsoft Certificate Services and internal PKI, eliminating the costs of using untrusted Root Certificates. Its partnership with Adobe to provide Certified Document Services (CDS) enables secure digitally signed PDF documents, certified transcripts and e-invoices. These core Digital Certificate solutions allow its thousands of authenticated customers to conduct secure online transactions, data transfer, distribution of tamper-proof code, and protection of online identities for secure email and access control. The company has a history of innovation within the online security industry and has offices in the US, UK, Belgium, Japan and China

About GMO Internet Group 
GMO Internet Group is one of the most comprehensive providers of industry-leading Internet services worldwide. As well as domain registration, web hosting, ecommerce, and payment processing businesses that each hold the top share in their respective markets in Japan, services operated by the group include Internet advertising, search engine marketing and research. Global online security brand GlobalSign and major Japanese online securities brokerage, GMO CLICK Securities are also group members. In 2011 a new Social Media & Smartphone Platform segment was established bringing together group initiatives in social apps development, flash marketing and Android apps distribution. GMO Internet, Inc. is headquartered in Tokyo, Japan. Please visit http://www.gmo.jp/enfor more information.

For further details please contact: 
Steve Waite 
GlobalSign 
+32 16 891900 / +44 1622 766766 
press(at)globalsign(dot)com
###

Tuesday, 9 August 2011

Take Advantage of Our Advanced .NET Obfuscation Features

CliSecure .NET obfuscator goes beyond traditional obfuscation methods. In addition to renaming your metadata entities, it also supports advanced obfuscation methods that will harden your overall protection scheme and foil reverse engineering altogether.
Advanced obfuscation features include control flow obfuscation, method call obfuscation, string encryption, assembly merging and cross assembly obfuscation.



Features
Entity Renaming 
CliSecure .NET obfuscator renames all metadata constructs, this includes namespaces, class names, method signatures and fields as well as methods implementation and string values of your assembly. Renaming scheme includes 'unreadable chars' scheme, this method will transform classes, methods and field names to unprintable unicode chars. When decompiled, the result is an extremely difficult to understand source code. Since unprintable chars are used it won't be possible to compile the sources produced after decompilation. 
Control Flow Obfuscation
CliSecure .NET obfuscator provide control of flow obfuscation, control flow obfuscation hides the control flow information of the program by transforming exiting code flow patterns to semantically equivalent constructs, however different than the code originally written. The control flow obfuscation algorithm converts the original implementation into spaghetti code thus making it extremely harder to infer program logic. CliSecure .NET obfuscator ensures that application code flow of the obfuscated assembly remains intact.
Cross Assembly Obfuscation
Cross Assembly Obfuscation allows renaming of external references thus dramatically increasing the number of obfuscated constructs. Given a set of assemblies that interface each other, CliSecure will rename classes, methods and fields referenced from other assemblies uniformly. For example, if class A declared in assembly A is referenced from assembly B and CliSecure renames class A to A1, it will also rename B's external reference from A to A1.
Code Shrinking
If your application does not use all of the contained MSIL code, CliSecure .NET obfuscator will drastically reduce the size of the input assembly files. The shrinking engine analyzes the MSIL code of all input files in order to determine which code entities cannot be reached from a set of given code entry points. These obsolete code fragments (either entire classes or single methods and fields) will then be removed from the obfuscated assembly.
Software Watermarking
Software watermarking is a technique used to protect software from piracy. It is used to discourage a user from illegally redistributing copies of the software. The general idea of software watermarking is very similar to media watermarking in which a unique identifier is embedded in images, audio, or videos through the introduction of errors which are undetectable by human. CliSecure .NET obfuscator watermarks each assembly with a unique identifier that can later be used to identify owners of the software or to track the origin of a pirated copy.
Incremental obfuscation
Incremental obfuscation allows the developer to make changes to the original sources after releasing an obfuscated assembly and then provide a patch to the user that reflects the changes to the original application while preserving the name-mapping used in the original release. In order to accomplish this, a map file must be saved and later used to ensure that the renaming is preserved when making changes and re-releasing the obfuscated assembly.
Application Code Flow Remains Intact
It is essential that an obfuscator keep the functionality of the software totally intact while making the original source code unrecognizable if the obfuscated assembly is decompiled. CliSecure .NET obfuscator ensures that the obfuscated assembly will run the same way as the original assembly.
Configuring your obfuscation process
Obfuscation can introduce issues when reflection API is used in obfuscated assembly. Methods calls that were performed through the usage of reflection API are likely to fail once the application has been obfuscated, this happens since the method has been renamed by the obfuscator, however the call site still refers to the method by its original name. To mitigate these problems, CliSecure .NET obfuscator fully supports Microsoft's declarative obfuscation attributes. These attributes, declared directly in source code, allows the user to define class and method names that shouldn't be renamed.
String encryption
A common attacker will often search deployed assemblies for strings containing keywords such as 'GetLicense' or 'Invalid License'. By locating such strings, hackers attempt to circumvent the license protection embedded in the product that they are hacking. CliSecure .NET obfuscator provides the option of string encryption.
x64 platform support
Supports 32-bit and 64-bit applications
Framework 1.1, 2.0, 3.0, 3.5, 4.0 support
Support all versions of the .NET framework including version 4.0, the framework that ships with windows 7. Our obfuscation tool can be used to protect applications deployed under the .NET Compact Framework. 
Mixed-mode Assemblies Support
CliSecure can obfuscate mixed-mode assemblies.
Debugging
One of the side effects of obfuscation is the difficulty of debugging obfuscated code. Exceptions generated and reported by a user will typically include obfuscated method and class names making it almost impossible to trace back the stack trace in the source code. CliSecure .NET obfuscator generates a clearly labeled map file containing a detailed description of the obfuscated entities and their original names, this information is essential to the user in interpreting debugger output from the obfuscated assembly.
MSBuild and NAnt build Integration
CliSecure integrates with MSBuild and NAnt thus promoting its usage as a part of an entire range of complex build scenarios.


Cisco CCNA Certification: The Worth Of The CCNA And CCNP


One query I see typically on the ‘Net is “Is it price my time to earn a CCNA / CCNP / CCIE certification?” My personal answer to that could be a resounding yes. The facility of Cisco certifications has allowed me to create an amazing career, they usually can do the identical for you.

There has by no means been a greater time to speed up your IT profession, and incomes a technical certification is a great way to just do that. I don’t care when you’re looking at earning an MCSE, a Cisco certification, Pink Hat, or every other vendor – you are always better off having a technical certification than not having one. Technical certifications are a superb solution to market yourself and stand out from the crowd. Earning certifications reveals a potential employer (and your present one) that you are willing to go the additional mile.

Sadly, while you ask this query on most Web message boards, you’re going to get some very unfavourable individuals providing you with their “unbiased” opinion. Ask yourself this query: Do you need to entrust the route of your profession to someone you do not know, has no accountability for what they say, and has some sort of ax to grind? Would you like someone like that to resolve whether or not you must earn a CCNA or CCNP?

I can communicate from expertise on this point. When I informed just a few people that I used to be going to earn my CCIE, virtually 100% of the responses I obtained have been negative. “It’s too arduous”, “nobody can cross that”, “the CCIE is not worth the work”, etc. Each single one of these statements is fake, and again I speak from firsthand experience. The identical is true for the CCNA, CCNP, and MCSE. All of these certifications can add worth to your career and put more money in your pocket. However it’s important to make the decision to earn them and to “hold your goals away from the trolls”.

Don’t ask nameless strangers whether or not it’s “well worth the time” to get a CCNA, MCSE, or other pc certification. The one particular person you need to ask that question of is yourself. Whether you want to start an IT career or jumpstart your present one, make the choice to move ahead in your profession – after which follow via on that decision.

Whenever you’re studying in your CCNA examination on the way in which to incomes this coveted Cisco certification, the details can seem overwhelming! On this article, I’ll point out 5 Frame Relay details that you should be mindful while you’re on your solution to the CCNA examination!

Inverse ARP starts working as quickly as you open the serial interface. This protocol performs dynamic Frame Relay mapping, however you don’t have to allow it – it’s already enabled as soon as you enter the command “encapsulation frame-relay”.

If you’re configuring Frame Relay map statements manually, do not forget that you’re mapping the native DLCI to the distant IP address.

Once you run “present frame map”, the word “dynamic” signifies mappings created by Inverse ARP, and “static” signifies it was manually created.

To identify potential LMI type mismatches, run “present body lmi”. Numerous Standing Timeouts signifies that there may be an LMI downside between your router and the frame relay switch.

This last one is for the various of you building CCNA house labs. A frame relay switch is a superb addition to your lab! Whilst you’re busy putting the configuration together, do not forget the global command “frame-relay switching” – it’s this command that enables a Cisco router to act as a body relay swap!

To move the CCNA exam, you will have to be able to write and troubleshoot access lists. As you climb the ladder towards the CCNP and CCIE, you may see increasingly more uses for ACLs. Therefore, you had better know the fundamentals!

The usage of “host” and “any” confuses some newcomers to ACLs, so let’s take a look at that first.

It’s acceptable to configure a wildcard mask of all ones or all zeroes. A wildcard masks of 0.0.0.0 means the tackle specified within the ACL line have to be matched exactly a wildcard mask of 255.255.255.255 signifies that all addresses will match the line.

Wildcard masks have the choice of using the phrase host to signify a wildcard mask of 0.0.0.0. Take into account a configuration where only packets from IP supply 10.1.1.1 needs to be allowed and all different packets denied. The following ACLs each do that.

R3conf t
R3(config)access-checklist 6 permit 10.1.1.1 0.0.0.zero
R3(config)conf t
R3(config)entry-list 7 permit host 10.1.1.1

The keyword any can be utilized to characterize a wildcard masks of 255.255.255.255.

R3(config)entry-record 15 permit any Another typically overlooked element is the order of the lines in an ACL. Even in a two- or three-line ACL, the order of the strains in an ACL is vital.

Contemplate a state of affairs where packets sourced from 172.18.18.zero /24 shall be denied, however all others can be permitted. The next ACL would do that.

R3conf t
R3(config)entry-checklist 15 deny 172.18.18.zero 0.0.0.255
R3(config)entry-list 15 allow any
The earlier example also illustrates the significance of configuring the ACL with the lines in the appropriate order to get the desired results. What could be the end result if the strains had been reversed?

R3conf t
R3(config)entry-record 15 allow any
R3(config)entry-checklist 15 deny 172.18.18.0 0.0.0.255

If the traces were reversed, traffic from 172.18.18.0 /24 can be matched towards the primary line of the ACL. The first line is “permit any”, which means all visitors is permitted. The visitors from 172.18.18.0/24 matches that line, the visitors is permitted, and the ACL stops running. The assertion denying the traffic from 172.18.18.zero isn’t run.

The key to writing and troubleshoot entry lists is to take simply an additional second to read it over and ensure it may do what you propose it to do. It’s higher to comprehend your mistake on paper as a substitute of as soon as the ACL’s been applied

About the Author

You may read extra in my website , i am completely happy that you just read my article, thnak you , you may go to here


Taking Advantage of Wildcard Certificates

If you've done some SSL Certificate research, you would notice that SSL providers only allow one domain to use one SSL certificate. This means that buying an SSL certificate for example dot com will not give you SSL security for www.example dot com or secure.example dot com. Most people can get away with only one SSL certificate, but what about those who use several domain names? Here's an example of a website that uses several domain names: shop.bigbusiness dot com, secure.bigbusiness dot com, buy.bigbusiness dot com, and mail.bigbusiness dot com.

You may buy SSL certificates for every additional subdomain on your website, but costs will significantly increase if you need certificates for four or more subdomains. Fortunately, you have the option to go for wildcard certificates that allow you to use one SSL certificate on an unlimited number of subdomains.

Wildcard? What's that?

You might be curious what "wildcard" means in "wildcard certificate". In computer terminology, a wildcard is basically a sybol, usually an asterisk (*), what stands to be replaced by another character or string. Very simply, an asterisk may mean any word. For example, *.example dot com refers to all subdomains of example dot com like mail.example dot com, secure.example dot com, news.example dot com, etc.

The "Common Name" field in an SSL certificate indicates the domain in which the certificate will be used. Wildcard certificates are basically certificates with wildcards in the Common Name, like *. bigbusiness dot com. If, in the future, you choose to get a wildcard certificate, you will be asked to supply the Common Name.

Good Things About Wildcard Certificates

Purchasing just one Wildcard Certificate for all your subdomains will obviously save you a lot of money. A typical SSL certificate costs about $150 which is fine if you only use a few subdomains, but with five subdomains, you’ll need to shell out $750. Think about how much money you can save if, let's say, you own a website with 10 subdomains needing SSL security. That's already $1,500. Comparing that to wildcard certificates that only cost $600 each, you save $900. The websites of big companies will sometimes need SSL on over 30 subdomains.

Manageability is another benefit to using wildcard certificates. It's not easy to purchase, set up, and then renew annually a number of SSL certificates. It's an extremely error-prone task for a single person to manage so many SSL certificates all at once. Fixing those errors will cost you money. On the otherhand, think about worrying about just a single wildcard certificate. Managing just one certificate is a much simpler task. Errors, in this case, become rare.

The Bad Things about Wildcard Certificates

Using wildcard certificates does have some drawbacks. The first thing that experts will point out is problems with security. Big websites are usually run by multiple servers, and by sharing one wildcard certificate, they share a single private decryption key. This means that if someone manages to compromise one of your servers and retrieve the decryption key, every subdomain on every server that uses the same certificate is also compromised.

All subdomains will cease to work if the wildcard certificate is revoked for any reason. Until you fix the wildcard certificate or get individual SSL certificates for each subdomain, you may have to put your website on down time.

The last thing you should know is that Extended Verification (EV) does not work with wildcard certificates. What is EV in the first place? It's a set of stringent rules that certificate providers use when approving applications for SSL certificates. EV was meant to increase public confidence in SSL. Wildcards in the Common Name are not allowed by EV guidelines. The green address bar feature only works in EV SSL Certificate, so you don't get that feature with wildcard certificates.

Monday, 8 August 2011

Should the Web be Encrypted?


The Electronic Frontier Foundation is a non profit organization founded in 1990. It first released HTTPS Everywhere as a beta test version in June of 2010. Last week, it released the 1.0 version which includes support for hundreds of additional websites, using carefully crafted rules to switch from HTTP to HTTPS.
HTTPS is the keystone of Internet security and privacy. In particular it protects against "search hijacking".
Earlier this year, two research papers reported the observation of strange phenomena in the Domain Name System (DNS) at several US ISPs. On these ISPs' networks, some or all traffic to major search engines, including Bing, Yahoo! and (sometimes) Google, is being directed to mysterious third party proxies.
EFF Senior Staff Technologist Peter Eckersley explaind:
Without HTTPS, your online reading habits and activities are vulnerable to eavesdropping, and your accounts are vulnerable to hijacking. Today's Paxfire revelations are a grand example of how things can go wrong. EFF created HTTPS Everywhere to make it easier for people to keep their user names, passwords, and browsing histories secure and private."
HTTPS Everywhere 1.0 encrypts connections to Google Image Search, Flickr, Netflix, Apple, and news sites like NPR and the Economist, as well as dozens of banks. HTTPS Everywhere also includes support for Google Search, Facebook, Twitter, Hotmail, Wikipedia, the New York Times, and hundreds of other popular websites.
The EFF Firefox extension is able to protect people using Google, DuckDuckGo or StartingPage for their searches, but not Bing and Yahoo users, because those search engines do not support HTTPS.
Aaron Swartz, reported that he got the basics of HTTPS Everywhere running on Chrome.
Last year Dan Kaminsky wrote this essay on HTML 5 security and referencing the flaws in which browsers implement HTTP:
Robert “RSnake” Hansen and Josh Sokel’s “HTTPS Can Byte Me“. Their point is that the HTTP version of a site actually has quite a bit of control about the credentials presented to the HTTPS version of a site — and that this control, while not overwhelming, is a lot more powerful, and troubling than expected.
Dan explained:
  • If you have a site with a wildcard certificate, and that site has an XSS attack reachable irrespective of Host header
  • Since HTTP sites can write cookies that will be reflected to HTTPS endpoints, and since cookies can be tied to certain paths, and since servers will puke if given too long cookies, an HTTP attacker can “turn off” portions of the HTTPS namespace by throwing in enormous cookies.
Dan concluded:
Ultimately, these findings have increased my belief that we need the ability to mark sites as SSL-only, so they simply don’t have an HTTP endpoint to corrupt. The melange of technologies, from HTTPS Everywhere, to Strict-Transport-Security, to the as-yet unspecified DNSSEC Strict Transport markings, become ever more important.
The Web, having just turned 20, shows signs of fatigue and its core technologies seem to be increasingly unable to cope with sophisticated attacks. With the rapid growth of Web APIs, and the out-of-control proliferation of pseudo-standard ways to secure Web protocols, the bulk of our data is also at stake. Is the Web about to become encrypted? What's your take on it?

Source URl:-http://www.infoq.com/news/2011/08/https

Sunday, 7 August 2011

The Variances Among Wildcard SSL And EV SSL To Safe E-Commerce

Next you want to make sure that the provider you come to a decision to host your domains at features excellent purchaser help. These days you will need to only go with one that offers a toll-absolutely free amount furthermore 24/seven support.

If you are a Microsoft Front web page consumer, the Inexpensive Domain Identify and Internet Hosting service you choose will need to offer you Front Web page Extensions. If you presently know how to FTP that’s terrific. You’ll by now know how to get your webpage reside on the internet. However if you you should not, you will want to go with a service that gives a Free Internet site Builder and Web page Templates. Internet site Templates will help you save you from owning to go out and employ a website designer.

Make confident the Low-priced Domain Name and Web site Hosting support you pick presents Global Domain Names Help if you have a domain with a region particular extension like .au or .br or .ch for instance. Ultimately it’s often a good thing to be able to personalize your error pages so find a support that provides this characteristic as properly. And final but not minimum, get one for underneath $ten.00 per month. Yeah I’ve heard of a couple of for only a several dollars per month, but they are no superior and have no where by close to the characteristics you will need as your firm grows its upcoming online presence.

Diverse companies supply various cost for registering domain, down below we will speak about the components which will impact the selling price of domain sign up and where to uncover a best amount for it.

Critical Thing in Registering Domain

You have no want to shell out $35 per calendar year to get a domain identify, some really excellent and reputed providers will sale you a domain with pretty lower amount. You will need to spend an annual price to the domain sign up corporation, so never forget about to renew your domain every yr.

The price tag of domain is varied based mostly on the domain extensions you sign-up. For domain extension like .com, .web, it will charge you only about $seven every single year, but for “mobi” domain extension, you may well have to spend out $20 for each 12 months. Besides the domain extension, the domain sign-up corporation from different provider will consult for distinctive sign-up payment for the state level domainextension. This kind of as, you will get a minimal cost as ?one.99 from 1&amp1 United kingdom (which is a Uk firm) for domain extension “co.uk” (United kingdom place level domain extension), and a USA corporation may necessitate more for this domain extension.

When registering domain, you will usually be asked about the alternative for “Domain Privacy Protect”, this solution will allow for you to choose not to open your register facts so that people today won’t discover who unique the web web site through whois. In most circumstances, I would like to endorse this possibility for man or women, but for the provider, it isn’t going to make sensation to cover the sign up info due to the fact you want additional people to know who unique this web-site.

Source URL:-http://worldvillage.com/octaviowells38-bryon-floyd