What is ‘Wardriving’ and How Can It Affect Your Company’s Computer Network?

Sneaky MalwareBy Scott Aurnou

Computer networks can be threatened by a host of potentially unexpected sources. Some of these start with ‘wardriving.’ Naturally, this begs a few questions…

What is ‘wardriving’? Literally speaking, it refers to hackers driving around with laptops or mobile devices connected to high-powered antennas, scanning for unlocked (i.e., no password needed for access) or poorly protected networks. The name is a variant on ‘wardialing,’ which was inspired by a scene in the movie WarGames in which the lead character used an old-style telephone modem to search for open computer networks. Strictly speaking, wardrivers log and collect wireless network info, without actually jumping onto the networks. Using another’s network without permission is called ‘piggybacking.’

What can wardriving lead to? Wardriving is often used to locate networks vulnerable to attack. If hackers identify yours as unlocked or relatively unprotected, they can download malware onto the system and/or surreptitiously search the computers and devices connected to the network for personal, company and financial data, log in credentials, passwords, etc. One relatively common scam involves spotting a vulnerable network via wardriving, infiltrating it to steal online banking log in information and then using it to transfer or withdraw funds from the company’s accounts.
Read more ›

Tagged with: , , , , , , , , ,
Posted in Network Security

What is Computer Forensics?


Computer Security Tip of the Week

Scott Aurnou – Computer forensics can be used to preserve electronic evidence and determine the methods used and damage caused by a data breach.

A longer course on computer forensics is available here (and can be viewed for free):
Computer Forensics: Deleting Does Not Mean What You Think

If you enjoyed this video, you can see more on TheSecurityAdvocate YouTube channel (and subscribe if you like).

Tagged with: , , , , , ,
Posted in Network Security, Security Tip of the Week

Cloud Service Contracts: Breaking Down the All Important Service Level Agreement (SLA)

By Kaiser WahabCloud Storage

For many businesses, storing company and customer information in the cloud may seem like the cheapest and most convenient option. Too often however, businesses rarely realize that with one-click ease they are putting critical data (personal info, trade secrets, intellectual property, etc.) in the crosshairs of a security disaster, due to compliance issues over privacy, data security, and other laws and regulations. Hence, the ease of a cloud solution can lead to a legal headache if a strong contractual foundation is not put into place. The most critical of those contracts may be the SERVICE LEVEL AGREEMENT (“SLA”) between the client and the cloud service.

By making both parties aware of their responsibilities and when they may be held liable for failing to live up to those responsibilities, a strong SLA can help prevent many of the hassles and dangers that can come with switching over to the cloud. This article provides insight into the major parameters and provisions that drive the SLA.

The provisions of an SLA generally fall into three broad categories:

Data Processing and Storage;
Infrastructure and Security; and
The Provider-Client Relationship.
Read more ›

Tagged with: , , , , , , , , , , , , ,
Posted in Cloud Security, Guest Posts

What is Whitelisting and How Can It Protect Your Network?


Computer Security Tip of the Week

Scott Aurnou – Whitelisting is a method of protecting a computer network by blocking programs and incoming Web traffic unless they are specifically approved to connect to the network.

If you enjoyed this video, you can see more on TheSecurityAdvocate YouTube channel (and subscribe if you like).

Tagged with: , , ,
Posted in Network Security, Security Tip of the Week

‘Watershed’ United States v. Cotterman Decision Limits Border Searches

GavelBy Scott Aurnou

In February 2013, this website discussed the effective non-existence of 4th Amendment protections at U.S. border crossings. For years, under what is known as the ‘border search exception,’ U.S. border agents have had unfettered authority to examine and search any luggage – including any cameras, laptops, mobile phones, tablets and other electronic devices – of anyone entering the United States without any justification needed.

Less than a month later, a major decision from the United States Court of Appeals for the Ninth Circuit Court (a Federal appellate court encompassing the states and territories of Alaska, Arizona, California, Guam, Hawaii, Idaho, Montana, Nevada, the Northern Mariana Islands, Oregon and Washington State) in a case called United States v. Cotterman has added a new wrinkle. While the Court ruled that border agents can still perform a standard search of electronic devices at will, they must have a ‘reasonable suspicion’ of criminal activity before the devices can be subjected to a deeper forensic analysis used to uncover data not readily apparent upon the initial examination on the device. This reasonable suspicion can be based upon the ‘totality of the circumstances,’ as opposed to a single specific incriminating item or event.
Read more ›

Tagged with: , , , , , , , , , , , , , ,
Posted in Laptops & Desktops, Privacy Issues, Smartphones & Tablets
Twitter: saurnou
TheSecurityAdvocate Youtube Channel