- 1
- 2
- 3
- 4
- 5
- < previous
- +
Blog: Regulatory Compliance & the Real Risk of Undetected Malware 01/02/2008 12:35:37
With the emergence of regulatory laws borne out of experience from a variety of embarrassing security breaches, today's corporate leaders face a myriad of repercussions. These range from serious fines to jail time when found not in compliance with regulations such as Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley (GLB), and Payment Card Industry (PCI), etc. - +
How to Be a Supremely Productive Person: A Chat With John Halamka 11/01/2008 10:59:10
John Halamka has two CIO titles, a family, passionate rock-climbing and wine-making interests and a major-league blog habit. We discuss his celebrity turn in a BlackBerry ad, his tips for e-mail triage, how he sleeps three hours a night and why he now understands Britney Spears.John Halamka has two CIO titles, a family, passionate rock-climbing and wine-making interests and a major-league blog habit. We discuss his celebrity turn in a BlackBerry ad, his tips for e-mail triage, how he sleeps three hours a night and why he now understands Britney Spears. - +
Your World. . . Hacked 02/10/2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network - +
P&L Management 101 04/02/2008 13:09:05
Now that you find yourself in charge of a revenue line, it’s time to start thinking about how to manage your new businessCIOs often yearn for new worlds to conquer. For many, the first step on that journey is to earn the right to manage a P&L. In order to achieve that goal, executives listen to their external customers, engage with the business, focus on innovation and look for new revenue opportunities. These CIOs build new business models and sell them to their CEOs. In return, they receive the keys to P&L management - +
Blog: Interview Questions To Avoid 30/11/2007 13:00:49
After reading an article by business performance management consultant and executive coach Dan Coughlin on how to handle difficult corporate situations, it struck me how that same advice does not always apply to interviewing. Coughlin recommends confronting difficult situations head-on, such as when a peer is degrading your efforts around the office. But in job interviews, being direct isn't always the right approach. Some questions and situations surface during job interviews that you simply should not discuss. I've encountered a few recently during my job search. I share them with you here to show why the direct approach didn't work, along with some advice on how to handle these scenarios.
Tweener virtual worlds: Training grounds for tomorrow's cyberschnooks
Perp: "Helgi B"
Status: Scared straight (or so we hope)
Dossier: If you need proof that youth and innocence don't necessarily go together, you need look no further than the woeful tale of a 13-year-old sociopathic script kiddie who, for reasons of privacy, we'll refer to only by his "handle," Helgi B.
Helgi B has already learned the fine art of theft of online account information through social engineering. While even moderately sophisticated adults can easily see through his clumsily crafted scams, impressionable kids have already fallen victim. His target: Habbo Hotel game account information.
If you're not a Western European middle-schooler who plays online games, then you probably don't know that Habbo Hotel is an incredibly popular online environment, a kind of blocky, pixelated, isometric Second Life designed for Euro tweens. It's not so much a game as a hangout spot, one where you can have your own "room" and decorate it with furniture (or, in Habbo lingo, "furni") you buy using the in-game currency, "coins," which you obtain using real money through Habbo Hotel's online shopping page.
Helgi B's scam is to connive other Habbo players into giving him their account information, or paying him for dodgy "hacking" programs or for what he claims are discounted coins in bulk, at impossibly low prices. Of course, anyone with your account details can log in to your account and transfer your coins or furni to an accomplice, just as if someone with your bank account information logged in and transferred your entire balance to an untraceable account in Hackistan.
When security researcher Chris "Paperghost" Boyd began digging into Helgi B's online shenanigans, he had no idea where it would lead: YouTube videos demonstrating so-called game-hacking tools; downloadable phishing kits; archives full of stolen passwords and commercial software license keys; remote access Trojans he claims to have created; and worst of all, forum posts where he brags about his 1337 h4x0r skilz.
"When did we become so jaded that we didn't just tolerate anonymous punks hacking us but gave a green light to 13-year-olds screwing us over and doing it in full view?" Boyd writes on his blog at Vitalsecurity.org. "Sigh. These kids are openly and wantonly peddling their leet hacking tools across all manner of websites -- worse, they don't even bother to do it anonymously anymore."
So Boyd took it to the next level: He began, as he describes it, "14+ solid hours of non-stop beatdowns" on all of Helgi B's Web sites that peddle illegal goods. One after another, Boyd contacted the various Web hosting providers and ISPs where Helgi had set up shop, providing them with documentary evidence, including screenshots, detailing the broad scope of illegal activities the forum was engaging in.
The only glitch: One of the service providers hosting Helgi B's stolen-passwords/license-keys forum seems reluctant to take down the site. It goes down for an hour or two and then comes back online. Four days later, the Web host finally pulls the plug permanently -- but only after Boyd threatens to report the hosting company to law enforcement.
Lessons learned: Just because you may not have reached puberty doesn't mean you can't be arrested and prosecuted for cybercrimes. It just means your parents might go to jail also/instead, or have to pay a huge fine, and then who's going to drive you to band practice or soccer games? Remember: Going to jail is like being grounded ... in a jail cell. And for you Web hosts out there: Getting another $5 or $10 from some message board operator isn't worth having your head-end ISP pull the plug on you for violating their terms of service, so turn off those illegal sites when someone reports them. Fast.
Andrew Brandt loves doing play-by-play of a good cybercriminal beatdown when he's not terminating malware with extreme prejudice at his day job.
- 1
- 2
- 3
- 4
- 5
- < previous
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
An EMC Perspective on Data De-Duplication for Backup
Explore the factors that are driving the need for de-duplication and the benefits of data de-duplication as a feature of an organizations backup strategy.








