- We got a chance to do some Endpoint Security testing for ZDNet here: How effective is endpoint security? Thanks for the feedback on this one. We only had a very small window to get this done and given more time, the results in terms of scope of testing would have been much larger. It is what it is and we hope you liked it. Hopefully a part II, with some really cool stuff.

- Fionnbharr Davies from Securus Global (Thoth) will be presenting at Kiwicon 2009. Fionn’s talk synoposis: “Linux kernel rootkits are everywhere, but no modern (public) detection system exists. Linux rootkit checkers are currently woefully inadequate, often focusing upon mundane and outdated techniques that are only used by the lowest of the kiddies. I will briefly highlight common modern rootkit techniques as seen in real in-the-netz linux rootkits, and walk through my Antilulz tool, which is an LKM designed to be loaded at times of peak paranoia to give your kernel the once over. I’ll continue the conversation discussing what a rootkit would need to do to defeat these checks, and expand upon antilulz to continue the cold war. If I’ve time, I’ll talk a bit about the state of rootkit detection, and will discuss real-time kernel IDS techniques, and why they are extremely hard to do”.

- Thanks to Craig B and fudsec.com for having me on; Testing the Vendor Guarantees. Guaranteed Security….Just Show Us the Money.

- Some articles at Tek-Tips. Here’s a couple of the latest ones:

Clouding the Solution Landscape: Mediocrity vs Strategy – Going the Easy Path

Data Classification Policies – Forgotten Purpose

As always, keen on your thoughts.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in: cyber crime, news


  1. Wade M says:

    Nice work on the ZDNet write up. It’s a hot topic over here, and I ended up sending the link around internally for the team to read :) .

    Great to see you guys keep doing your thing, and releasing it where-ever possible as always :)

    Peace,
    –Wade

  2. Drazen Drazic says:

    Thanks Wade. Means a lot to get that feedback from you.

    Am enjoying the responses here:
    http://www.zdnet.com.au/reviews/software/security/soa/How-effective-is-endpoint-security-/0,139023452,339299310,00.htm?omnRef=1337#talkback

    We’ll respond soon to the comments. They’ve all been appreciated that people good or bad took the time out. All taken on board one way or another.

    DD

  3. D2 says:

    Ack on the work for ZDnet… nice work…

    I would like to see the same tests run on IBM ISS Proventia Desktop, Cisco Security Agent and F-Secure whereupon sandboxing and other heuristics and anomaly detection is used internally by these agents…

    D.

  4. Thanks D2. If we are asked to do it, we’ll go for it. No word yet on what the next testing could be for ZDNet. (If they want more from us).