403 Blogs

Month

June 2012

5 posts

Reminder About "New" PCI DSS Requirements

We wanted to remind those organizations impacted by the Payment Card Industry Data Security Standard (PCI DSS) that two “best practices” will be maturing and going into effect as requirements after June 30th.

Both of the soon-to-be requirements fall under the section of the Standard devoted to developing and maintaining secure systems and applications (Requirement 6).

Read More →

Jun 27, 2012
#pcidss #submission #pcidss6.2.a #pcidss6.5.6 #compliance #infosec #security #pci #pcissc #development #application
Things to Consider When Using Wi-Fi

As a frequent business traveler and coffee shop web surfer, I am becoming more and more cognizant of what I am connecting to when it comes to Wi-Fi networks. Not only am I aware of what types of networks I am connecting to, but also where I am connecting (e.g. coffee shops, hotels, airports, etc.). Granted, my awareness is heightened due in part to the fact that I work in the Information Security field with some exceptionally brilliant minds who know the ins and outs of public and private Wi-Fi networks.

Recently, an article was published by Information Week that delved into some strategies for blocking hotel Wi-Fi malware. The post was inspired by a recent FBI advisory that made a point to mention that malware authors are targeting travelers abroad via pop-up in-browser windows.

At first glance you may say to yourself that you rarely travel abroad, therefore, you have nothing to worry about. Even if that is the case, you should always keep your guard up. Although the recent advisory was pointed at travelers abroad, the security essentials that the article points to can, and should, be applied to anyone.

Read More →

Jun 8, 20121 note
#wifi #infosec #security #wireless #network #malware #travel #submission
Practical Malware Analysis – Another Hit From No Starch Press

Malware analysis is an obsession for me. So when I heard that No Starch Press was coming out with a new book called Practical Malware Analysis (also available at Amazon), I had to pick it up. Having read several No Starch Press books, I was confident that the content of the book was going to be good. Once again, No Starch Press did not let me down.

The writers, Michael Sikorski and Andrew Honig, did an excellent job of starting off with the basics. They include a “Chapter 0,” called Malware Analysis Primer, before diving into the more in-depth concepts. From there, the book consists of six major parts, with each comprised of three to four chapters. The huge bonuses of this book in my eyes are the hands-on labs at the end of each chapter. These labs help solidify the concepts that appear within the chapter.

For those who may be considering checking out the book, I thought I would include a brief description of each section here:

Read More →

Jun 4, 2012
#malware #analysys #nostarchpress #c++ #book #infosec #security #submission
Secure Application Development and the OWASP Top 10 (Pt. 2 of 10)

This is part 2 of a 10-part series. You can check out part 1 here.

Some of you may already be familiar with the Open Web Application Security Project (OWASP) and its Top 10 2010 list due in part to Requirement 6.5 of the Payment Card Industry Data Security Standard (PCI DSS):

6.5 Develop applications based on secure coding guidelines. Prevent common coding vulnerabilities in software development processes.

For those of you who are not familiar with OWASP and their Top 10, the OWASP Top 10 2010 was aimed at highlighting simple problems that can plague applications and ultimately undermine security.

If you missed it, be sure to check out the previous post on A1: Injection. Here’s the second OWASP application security risk - Cross-Site Scripting.

Read More →

Jun 1, 20121 note
#XSS #pcidss #pentest #submission #owasp #application #development #infosec #security #coding #6.5
403 Labs Becomes P2PE Qualified Security Assessor and P2PE Payment Application Qualified Security Assessor

Brookfield, WI – June 1, 2012 – 403 Labs, LLC, a leading information security consulting and services company, has been certified as a Qualified Security Assessor for Point-to-Point Encryption (QSA (P2PE)) and Payment Application Qualified Security Assessor for Point-to-Point Encryption (PA-QSA (P2PE)) by the Payment Card Industry Security Standards Council (PCI SSC).

Read More →

Jun 1, 2012
#padss #pcidss #submission #about403 #infosec #security #pressrelease #p2pe #encryption #qsa #paqsa
Next page →
2012 2013
  • January 1
  • February
  • March 1
  • April 1
  • May
  • June 1
  • July
  • August
  • September
  • October
  • November
  • December
2011 2012 2013
  • January 2
  • February 6
  • March 3
  • April 4
  • May 4
  • June 5
  • July 1
  • August 4
  • September 6
  • October 1
  • November 2
  • December 4
2010 2011 2012
  • January 8
  • February 12
  • March 6
  • April 6
  • May 6
  • June 5
  • July 1
  • August 21
  • September 12
  • October 8
  • November 13
  • December 10
2009 2010 2011
  • January
  • February
  • March
  • April
  • May 1
  • June
  • July
  • August
  • September
  • October
  • November 7
  • December 16
2008 2009 2010
  • January
  • February
  • March
  • April 1
  • May 2
  • June 4
  • July
  • August
  • September
  • October
  • November
  • December
2007 2008 2009
  • January
  • February
  • March 1
  • April 5
  • May
  • June
  • July
  • August
  • September
  • October
  • November
  • December
2006 2007 2008
  • January
  • February 1
  • March
  • April 1
  • May 1
  • June
  • July
  • August
  • September
  • October
  • November
  • December
2006 2007
  • January
  • February
  • March
  • April
  • May
  • June
  • July
  • August
  • September
  • October 8
  • November 1
  • December