Skip to content

Steve Holden's Blog

    • ABOUT
  • Where Is Your Power Strategy?

    April 17, 2016

    +

    +

    +

    +

    +

    +

    Power-decisions

    Per FreeBeacon.com and TheHill.com there is news that the FBI has warned power companies about additional cyber threats to the United States critical infrastructure (i.e. the grid).  

    This warning drives home the continued need to not only protect your air gapped network from digital threats, but also to make sure you completely understand and protect your power needs required by your air gapped network:

    • Your Grid
    • Your Generator
    • Your Backup Battery

    You more than likely aren't able to completely power gap your air gapped system from the grid, but you do need to consider how to isolate as much as possible your generator(s) and your backup battery(s).  These capabilities will more than likely have industrial control systems (i.e. Internet of Things) that need to be protected from external threats.

    If you have any best practices then please let us know by leaving a comment.

    +

    +

    +

    +

    +

    +

    + Uncategorized

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • If You Can Do One Thing In San Diego …

    April 6, 2016

    +

    +

    +

    +

    +

    +

    1st Draft Posted: April 6, 2016 – 2113 PT

    Lajollashoressunset

    Motivation: One of my favorite bands Chvrches is coming to San Diego next week (April 14, 2015 – SOLD OUT) and this is a gift to them. If they have time and have a good experience doing any of these, then I've paid them back just a little bit for the joy I've gotten from their music and how they treat their fans.  If you have other suggestions, questions, thoughts, etc. … then leave a comment or let me know on Twitter @ sholden.

    Thrill Ride

    • Giant Dipper @ Belmont Park

    Burger & Fries*

    • Hodads

    Walk On The Beach

    • La Jolla Shores

    Pizza & Beer

    • Pizza Port Ocean Beach

    Hike

    • Torrey Pines

    Brewery

    • Stone Brewery World Bristo and Gardens

    Neighborhood

    • Northpark

    Something New

    • Liberty Public Market

    Really Good Mexican Food + View To Die For + Great Place To Camp

    •  Bull Taco at San Elijo State Beach

    The Best Mexican Food

    • Las Cuatro Milpas

    Books

    • Mysterious Galaxy

    Seafood

    • Point Loma Seafood

    Ice Cream

    • Hammond’s Gourmet Ice Cream in Pacific Beach

    *I really like burgers & fries at In-N-Out and Five Guys.  These are worth experiencing if you haven't.  Picking one is hard.

    +

    +

    +

    +

    +

    +

    + Beta, Current Affairs, DIY, Ideas, Music, Personal, San Diego, Tip

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • USB Memory Card Malware Threat

    March 27, 2016

    +

    +

    +

    +

    +

    +

    Flash-drive-146163_960_720
    There is reportedly a new particularly advanced USB-savvy malware being called "USB Thief" (Google Search) being discussed by many in the technology press.  

    If you allow users (including system admins) to use USB storage devices on air gapped systems then this threat can be a potential attack vector a persistent attacker could deploy against your organization.

    Basically an infected USB device could be inserted into an air gapped computer where it could collect considerable amount of "protected data" and then exfiltrate the "protected data" back to the infected USB device. Once the device is removed there is reportedly no trace of the malware on the compromised system and no record of the data collected.

    Best defense would be not to allow USB storage media on air gapped systems.  Otherwise, restricting data migration from the air gapped network (i.e. the high-side) to the internet network (i.e. the low-side) would be another defensive measure.  Good physical security would also limit the effectiveness of this threat vector.

    Some links with more coverage (some of it F.U.D.): techtimes.com, sci24h.com, arstechnica.com, pcworld.com, thestack.com, securitybrief.co.nz, slashdot.org, idgconnect.com, and itsecuritynews.info, 

     

     

    +

    +

    +

    +

    +

    +

    + Exfiltration, Physical, Threat, USB

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Emerging New Exfiltration Of Data Via RF Threat

    March 20, 2016

    +

    +

    +

    +

    +

    +

    Laptop-radio-exfil-project

    There is a new open source effort to build out a working data exfiltration toolkit using radio frequencies.   The source code has been posted to GitHub.  More info on the news at Softpedia. 

    The key defensive measure would be to make sure no malicious rogue capabilities make it to your air gapped networked systems, and that you consider RF shielding countermeasures.

     

    +

    +

    +

    +

    +

    +

    + Data, Exfiltration, Threat, Wireless

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Electromagnetic Attack Demo On Air Gapped System

    March 19, 2016

    +

    +

    +

    +

    +

    +

    EM-Computer-Attack-VisualizationResearchers preparing for a future conference presentation have released details (PDF paper here) of their successful electromagnetic (EM) attack against an air gapped system that included no additional software to be previously installed on the system being hacked.  The hardware costs to build the attacking system was around $3000.  The air gapped system had no TEMPEST protections (PDF reference for more information).

    You can read more via:

    • DailyMail
    • TechWorm
    • TimesOfIsrael
    • Motherboard@Vice
    • Softpedia
    • OO7Software
    • ComputerMagazine

     

     

    +

    +

    +

    +

    +

    +

    + Electromagnetic, TEMPEST, Threat, Wireless

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Recipe: No-bake Breakfast Cookies

    February 15, 2016

    +

    +

    +

    +

    +

    +

    IMG_20160215_093833-01

    I recently made the following no-bake breakfast cookies, but I had to substitute honey with Log Cabin Syrup and flaked cereal with Cheerios. They turned out awesome (my serving size ended up being eight).

    Ingredients:

    1/2 cup honey (or light corn syrup)
    1/2 cup non-fat dry milk (instant)
    1/2 cup raisins (or chopped dates)
    1/2 cup creamy peanut butter
    2 1/2 cups flaked cereal (coarsely crushed)

    Directions:

    1. Heat honey and peanut butter in a medium saucepan over low heat. Stir until blended.
    2. Remove from heat. Stir in dry milk.
    3. Fold in cereal and raisins. Drop by heaping tablespoons onto waxed paper to form mounds.
    4. Cool to room temperature.
    5. Store in refrigerator.

    Nutritional values per serving (makes about 12 servings): 160 calories, 5 g total fat (1 g saturated fat), 26 g carbohydrate, 4 g protein, 1 g dietary fiber, 110 mg sodium.

    Originally posted by Montana State University Extension, Nutrition Education Programs via What's Cooking, USDA Mixing Bowl. 

    +

    +

    +

    +

    +

    +

    + DIY, Food and Drink, Ideas, Personal, Tip

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Excellent Guide On Secure Shell (SSH)

    February 12, 2016

    +

    +

    +

    +

    +

    +

    Nist_thumb2

    This PDF guide entitled What You Need To Know About NIST Guidelines for Secure Shell (SSH) from shh.com is excellent.

    If you are already investing in an air gapped network and using SSH, then you should pay close attention to the recommendations in this guide.

    The basis for this guide is the NISTIR 7966 (PDF).

     

    +

    +

    +

    +

    +

    +

    + Encryption, System Administration, System Management, Tip

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Proof-Of-Concept: KVMs To Jump The Gap

    January 9, 2016

    +

    +

    +

    +

    +

    +

    The Register published news of a recent presentation by (@ynvb & @oppenheim1) that IP-enabled KVMs can be attacked in such a way to enable access on a closed network (no Internet connectivity).

    +

    +

    +

    +

    +

    +

    + KVM, Physical, Supply Chain, Threat

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • DOD Definition Of Insider Threat

    January 7, 2016

    +

    +

    +

    +

    +

    +

    The United States Department of Defense's definition of an insider threat:

    An insider threat is defined as someone who uses his or her authorized access to damage the national security of the United States, whether through espionage, terrorism, unauthorized disclosures of classified information, or other harmful actions.

    +

    +

    +

    +

    +

    +

    + Insider, Threat

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

  • Proof-Of-Concept: Smartwatch Leaks Keypad Numbers

    January 6, 2016

    +

    +

    +

    +

    +

    +

    Per Gizmodo, there is a proof-of-concept of how a smartwatch could be used to leak keypad numbers on an access control door or other PIN protected resource.

    +

    +

    +

    +

    +

    +

    + Uncategorized

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

    +

Previous
1 … 36 37 38 39 40 … 214
Next

BlueSky

Blog at WordPress.com.

  • Subscribe Subscribed
    • Steve Holden's Blog
    • Already have a WordPress.com account? Log in now.
    • Steve Holden's Blog
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar