Lightning Down the Line

RSS

Lightning Down the Line

Story by Davin Fligel, 25-01-2010, 0 comment

Don't tempt lightning, protect your browsers.

Nobody wants to be an innocent bystander; we avoid high risk areas where problems are likely to break out. The risk averse amongst us avoid areas that pose even a modicum of risk. You are unlikely to find me trawling a battle ground even for the most precious of loot.

So it was with horror that I learnt as a teenager that lightning could come down a telephone line and kill you. More precisely kill me! I could become an innocent bystander in my own home. I was not safe inside all that brick and mortar. The first thing that came to mind was: “What are the chances of that?” closely followed by, “I live in a lightning prone area” and “I need the phone to communicate.” This was the choice of communication methods before the ubiquitous mobile phone and the pervasive Internet.

So I ran to my mother and demanded that we get lightning surge protectors as fast as humanly possible. How could I survive without a telephone, I was a teenager.

On the Internet, computers are to homes as browsers are to telephones. To be able to communicate between houses you need to use your browser. Some would say the Internet is somewhat “lightning prone.” You browse around as normal until unsuspectingly hitting an intentionally malicious or even legitimate site that had been compromised and your computer is compromised.

How does not using the internet for security reasons sound you? Could you do it or would you sprint out and get the first “surge protector” you could find?

“But I have a firewall” cries the recently recruited member to the latest fashionable botnet. Unless your firewall can stop you connecting outbound to a compromised site then it is useless against this threat. Last time I checked I was not blocking my browser from connecting to the Internet. That would defeat the purpose.

“But I only visit safe sites” cries the latest attack vector into a corporate network after being compromised by the penetration testing team. Man-in-the-middle attacks from fake or compromised wireless access points or internet cafes, even man-in-the-middle attacks on the LAN if the opportunity arises. No WiFi? I think not, Sir!

“But I have antivirus” cries the IT Manager as he explains to the CIO how he just lost a stack of confidential records. Kernel rootkit injection and core library replacement through an un-patched vulnerability had left him open long enough to get the data and leave without writing the files that AV definitions would easily identify.

The truth of the matter is browser security is the new file and network security. Even legitimate web sites fall prey to zero day vulnerabilities, cross site scripting and SQL injection attacks. If not the sites themselves, then the advertising engines posting advertisements for their parent sites.

This is assuming you are surfing from a safe network;  the added risks of unprotected wireless networks and the hacker friendly man in the middle opportunities they present increase your risks to horrendous levels.

This is lightning down the wire all over again, only on a grander scale with exponentially more lightning. The moral of this story is simple to elucidate but difficult to implement:

Make yourself a smaller target, install your lightning protectors, patch your browsers and if you cannot patch them use ones that are not vulnerable.
Use Intrusion Prevention Systems (IPS), Host Intrusion Prevention Systems (HIPS), Layer-7 aware Web Application Firewalls (WAFs).
Use a secure VPN from public WiFi hotspots
Block unnecessary outbound communications, or at a minimum monitor them.

Surf safe, don’t browse without protection.

Caretower Limited is exhibiting at Infosecurity Europe 2010, held on 27th – 29th April in Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit Infosec


SHARE THIS.

Post new comment





500 characters left

Verification Image

SIGN UP.

Sign up to receive the latest news and updates from Server-Management via email.

News & Features Feed
Viewpoints Feed
FOLLOW US.
OUR SPONSOR.
Top 10 Most Popular Articles
Top 5 Jobs
Part time IT Trainer
Posted:
2010-03-11
Location:
City of London, London
Salary range:
1 - 35000
Salary period:
year
Description:

Part time IT Trainer – 3 days – Up to £35,000 pro rota Training Needs Analysis, User Guides, Documentation, Developing & coaching delegates, City of London My client is based in the City of London and looking for a proactive IT Trainer with excellent interperso... read more

Head of Data - SQL/Datamodelling/Warehousing - W.Mids
Posted:
2010-03-11
Location:
West Midlands, West Midlands
Salary range:
55000 - 60000
Salary period:
year
Description:

Head of Data - SQL/Data-warehouse/Data-modelling/Strategy - Industry Leader - West Midlands Data Manager/Head of Data/Data Strategy Manager/Head of BI As part of my well known client's ongoing IT strategy, they are in urgent need of an experienced Head of Data to make a real impact in the ... read more

Technical Presales Consultant
Posted:
2010-03-11
Location:
Reading, Berkshire
Salary range:
20000 - 25000
Salary period:
year
Description:

This is a fantastic job opportunity for a keen IT person, who has a massive interest in computers and building a career within this sphere. My client a well known IT Reseller based in Reading is seeking to recruit a Technical Presales Consultant. You do not have to be qualified as my client is l... read more

IT Technician
Posted:
2010-03-11
Location:
Sheffield, South Yorkshire
Salary range:
20000 - 25000
Salary period:
year
Description:

IT Technician (Legal) Sheffield £20-25k The Job Role: We are looking for a network administrator who will be able to maintain and support the systems our client has in place providing services to their team. The Systems Administration Team will be responsible for building, supporting ... read more

Senior Infrastructure Engineer
Posted:
2010-03-11
Location:
Cambridgeshire, Cambridgeshire
Salary range:
35000 - 40000
Salary period:
year
Description:

My client, a specialist consultancy, are looking for a senior Infrastructure Consultant. You will be the sole owner of the companies infrastructure so must have solid Windows Server experienced including Active Directory coupled with excellent IIS Administration experience.Ideally you will have ... read more


Want to advertise here? Follow me!