PortalGuard Climbs the SharePoint Summit

April 26, 2010 by Kimberly Johnson · Comment
Filed under: PortalGuard, SharePoint Authentication 

Climb the Sharepoint Summit

Come join PortalGuard by PistolStar, Inc. at the SharePointPro Virtual Conference, Climbing the Sharepoint Summit. No need to leave your office, just join us online to ask us any questions you like May 20th 9:00am-4:00pm EST. The best part is that registration is open to anyone and free!

Come see if PortalGuard is right for your company! See how you can meet or exceed your security objectives, including:

  • Stronger Authentication
  • Reducing Risk - both financial and security
  • Enhance compliance with both security and industry standards
  • Deliver effective password policies
  • Implement Best Practices

And Many More…

Conference Website & Information

PortalGuard Homepage

PortalGuard has Great Success at the 2010 SharePointPro Summit & Expo

Thanks for Stopping By!

We first would like to extend a thank you out to those of you who stopped by our booth at the SharePointPro Summit this year. It was fascinating to hear about how SharePoint authentication and security is being handled, what specific requirements you are looking for, and how PortalGuard or Tailored Authentication could help you with your SharePoint security needs.

If you did not have a chance to see us at the show, then we encourage you to visit PortalGuard.com, to see how PortalGuard is the solution for meeting and exceeding your security objectives. PortalGuard is supported on multiple platforms including Microsoft SharePoint/IIS, IBM Websphere/Websphere Portal, and Lotus Domino.

PortalGuard:

PortalGuard is an authentication and security solution that allows end-users to securely authenticate and manage their portal login credentials directly from a Web browser, while providing administrators with functionality to meet or exceed their security objectives. With PortalGuard, administrators can implement best practices for ensuring stronger and consistently secure authentication. Learn More…

Extensible Authentication Framework:

Many of our customers implement our standard Password Power Plug-ins - the authentication software framework offers robust functionality and feature-rich security, access control, and password management.

But for those customers who have a unique user base, organizational complexities, specific security and compliance requirements or multiple and diverse applications, our expert professional services and development team will develop a solution adapted to their environment and delivered within the framework of our standard Password Power software product, including ongoing technical support. Learn More…

PistolStar Brings PortalGuard to the SharePointPro Summit & Expo

 

PistolStar Brings PortalGuard to the SharePointPro Summit & Expo on March 17th & 18th, in Las Vegas!

Come stop by booth #508 for more information on:

PortalGuard:

PortalGuard is an authentication and security solution that allows end-users to securely authenticate and manage a portal password directly from a Web browser, while providing administrators with functionality to meet or exceed their security objectives. With PortalGuard, administrators can implement best practices for ensuring stronger and consistently secure authentication.

Security & Auditing:

  • One-Time Password - stop being vulnerable to replay attacks
  • Limit multiple concurrent logon sessions - prevent multiple users from logging in with the same set of credentials
  • Define strike-out limits by person, group or hierarchy – Alerts are emailed when strike-out limits are exceeded
  • Lockout inactive users after “n” days – Identify and stop access to dormant user accounts

 Help Desk and End-User Productivity:

  • Self-service Active Directory password reset via challenge question/response — Highly configurable and secure!
  • Prove your identity to the help desk - by providing highly configurable challenge question and answer functionality

 Services:

  • Tailored Authentication - we deliver a product that will fit precisely with your environment
  • Excellent Customer Service - receive support directly from the developers
  • Easy deployment — let us take you by the hand

 

† Fully supports & enhances multiple platforms and portals — IBM Lotus Domino (AIX, Solaris, Windows, System i, Linux), IBM WebSphere/WebSphere Portal, and Microsoft SharePoint

For more information please visit: PortalGuard.com

PistolStar is Attending Lotusphere 2010!

January 12, 2010 by Kimberly Johnson · Comment
Filed under: Lotusphere 2010 

Come stop by booth #324 to learn more about:

PortalGuard:

A password authentication and security solution that allows end-users to securely authenticate and manage a portal password directly from a Web browser.

Tailored Authentication:

For a unique environment and/or situation, which requires specific functionality, our team would make the necessary adaptations to meet or exceed your security objectives, and provide a fully supported product.

Rule-based Alerts:

Security - Activity Monitoring - making early predictions leads to being proactive instead of reactive.

Bound2Authenticate Presented by Victor Toal at Lotusphere 2010

January 12, 2010 by Kimberly Johnson · Comment
Filed under: Authentication Trends, Lotusphere 2010 

Victor Toal  Bound2Authenticate Presented By Victor Toal

When:
Tuesday, January 19, 2010
2:00pm-3:00pm

Where:
Lotusphere, Swan Hotel, Ibis Room

An exclusive raffle is offered to all attendees.

Speaker Information:

Victor Toal is a messaging and collaboration architect and engineer with more than 15 years experience with Domino (since R 4.1), Sametime, Quickr, Lotus Connections, and WebSphere. Victor’s clients include the Pentagon, US Army, banks, as well as manufacturing, tourism, and medical companies. He has worked in the US and overseas (Japan, Austria, Great Britain, Germany, France, Italy, Hungary, Poland, and Czech Republic) and speaks fluent German and Japanese. He is certified in Domino R4-R8.5 and Sametime 7.5 and 8.0.

Unable to attend? Request a recording of the presentation by visiting the Contact Us page.

The Trojan Horse: Sneaking Past Your City Walls

For centuries the Trojan horse was a weapon of war; a historical piece of trickery and deceit, which was used to bring down the City of Troy. Now in this century, when searching the term Trojan horse, the first result to appear is about the technology verison of the  Trojan horse. As many of us know malware stands for malicious software. The vehicle in which it obtains its unwanted access is the Trojan horse programs. These carriers are great at disguise, trickery, and breaking down the walls of your personal identity and even financial status.

 

Recently a new Trojan horse program has appeared, and has many concerned. Trojan Horses, as many of us know, are invasive, but this new one goes beyond that, targeting specifically financial institutions and Internet Explorer users. The new name to fear: W32.Silon. With the target of financial institutions, Silon can intercept Internet Explorer sessions, and steal credentials. Many say this attack has two heads, the generic Trojan horse approach into all applications, and then the financial focus.

 

When it comes to logging onto your bank account online, that is when to watch out. The Silon Trojan will intercept between the token protected financial sites and the user, putting up a façade that looks like their normal login screen. This allows them to transmit your credentials to hackers, to be able to obtain your financial data, and reap the rewards. The main thing that is clear about this attacker is that it is following and changing wih the authentication trends. With more advanced authentication techniques, attacks are becoming more and more sophisticated. The Silon is a prime example, as it attacks the two prong stronger authentication methods with ease. Bank accounts beware!

 

For more information check out these links:

http://en.wikipedia.org/wiki/Malware

http://en.wikipedia.org/wiki/Trojan_horse_(computing)

http://in.sys-con.com/node/1162320

Issues in Compliance for Instant Messaging

October 12, 2009 by Kimberly Johnson · Comment
Filed under: IT Security, compliance 

Compliance is always a large concern, especially with attacks and data breaches increasing. It is important to understand the industry and regulatory requirements that need to be enforced within your corporation and security environment. One area that experts are beginning to see as an issue is instant messaging. This is a communication method that is hard to regulate and record, which could pose problems with industries with strict compliance standards.

In a recent article by Dmitry Shapiro, CTO at Akonix Systems, Inc., “Instant Messaging and Compliance Issues: What You need To Know” the issues that are becoming ever present with IM are discussed. The main issue is the sheer volume of users on these IM systems, totaling in the 100s of millions. This is not to mention what IT managers are most afraid of, which are the public IM systems, such as AOL Instant Messenger and Yahoo Messenger.

Although IM is a functional tool for communication there are key areas with which there is a lot of concern for compliance issues:

-        Record Retention

-        Information Security

-        Theft

-        Copyright Infringement

These issues are ever rising with the number of users and amounts of information on these systems. With the public IM services, the control a manager could have with an internal system is taken away. Tasks such as auditing, logging, and deleting records are all issues when the manager cannot oversee the whole system, and the web of IMs being created.

Without compliance and monitoring, the one thing that is apparent is that risk will increase. Shapiro says that the main issues to watch for are:

-        Organization of records

-        Retention of records

-        Tamper Proof Records

-        Record Retrieval

-        Off-Site Copies

And many more…

With such acts as the Sarbanes-Oxley Act, HIPAA, and GLBA the ability to control, monitor, protect, and delete records is essential. These regulations are going to require IT managers to remain compliant and come up with ways to monitor their users IM behaviors. If this is not done, IMs will be a strong source of theft and cybercrime.

Common Password Attacks: Do You Know How They’ll Steal Your Password?

Just like we have multiple ways to secure our passwords, hackers have multiple ways to steal them right out from underneath us. Passwords are so valuable to us, some can hardly imagine letting one slip into the wrong hands. So the main question is how do you protect yourself?

The key is being aware of what types of attacks are able to steal your password, and understanding what precautions to take. In a recent article by InfoWorld, “Prepare for the Next Password Attack”, the most popular attacks were listed, so that awareness is possible.

Authentication Bypassing – just like it sounds, it bypasses password security
Password Guessing – hackers attempt to guess credentials by testing tons of passwords until the correct one is guessed. This is usually automated.
Password Sniffing – picks up plain text passwords over a network
Keystroke Logging – records what users physically type in when logging on by recording keystrokes
Hash Cracking – uses bypassing to go into an authentication database, and steal stored credentials
Credential Replaying – replay a stolen password over a network
Social Engineering – this includes over the phone, in person, and other alternative ways besides    technology that someone can steal your password

This article does a great job of outlining the common attacks on passwords. With all of this attack talk it is almost frightening to have passwords at all. Putting up defenses is the best way to prevent these attacks, and as said before to be aware of them. By enforcing strong authentication mechanisms and password policies, it is possible to never experience an attack. Just remember knowledge is power.

Attacks Need Access to Happen: Yahoo Users Beware

Recently 1,000s of attacks have been occurring involving Yahoo mail and their users, and that is just one proxy that has been recorded. Brute force attacks are being used to steal users’ credentials and access their email accounts to conduct spamming attacks. With the future of Authentication Trends showing an increase in hackers, and phishing attacks, it is no wonder this is a recent hot topic. Attacks need access to happen and with the growing number of access points, to get to data, it is no wonder attacks are increasing as well.

The main login page for Yahoo mail is protected against these brute force attacks, which are when hackers just keep trying to guess credentials, until they are able to steal them. Usually they implement an automated script that cycles through passwords and names, until finding the correct match. They use mechanisms such as:

 

·     Enforce strike-out limits - the user will be prompted to enter in a CAPTCHA after they fail at    entering their credentials “n” number of times.

·     Incorrect credential is not specified – the error page following an incorrect login attempt, does not inform the user which part of their credentials, the username or password, was incorrect.

 

These mechanisms have been working to protect Yahoo mail users. Recent attacks and stealing of credentials happened through a service application, outside of Yahoo. With this API access point, hackers saw an open door.

This API is meant for ISP’s and third-party Web applications, but it does not enforce the same authentication mechanisms as Yahoo mail does, such as anti-automation defenses. There are no strike-out limits or CAPTCHAs, and the error page specifies which part of the credential you entered incorrectly. Hackers figured out quickly how to hammer this application with attacks, daily.

With further investigation it was found that hackers were trying something different in their attacks. Usually these brute force attacks are aimed at the Web interface that is highly visible, but this application was not for end-users, and just helped validating authentication credentials.

To fight these attacks the Web Application Security Consortium Distributed Open Proxy Honeypot project is being created. By getting attackers to push through the one proxy server for the project, the suspects can be monitored. It is a great idea, but with multiple phases of implementation, which started in 2007.

Yahoo has hundreds of servers, and attackers are learning to spread their attacks across a breadth of them. With current authentication mechanisms and projects, IT professionals are attempting to reduce attacks. Of course we all have to take a look at the overwhelming problem; users require multiple access points on a daily basis, and access opens the door for attacks. This will definitely be an ongoing dilemma.

 

Cloud Computing: The “Greener” Solution for Government

Upon visiting apps.gov, out of curiosity about what exactly cloud computing is, I came across the video showing the new plans the government has in store. Typically known as a huge overwhelming IT “creature”, the government is planning on changing their ways, in regards to IT systems.

Currently the government is riddled with 100s of systems, unique applications and environments, all across the globe. There are large IT infrastructures behind these individual systems supporting them as separate entities. What has now been looked at more closely is that some of these large systems are duplicating work that many other systems are completing as well, such as email functions.

The U.S. CIO Vivek Kundra is onboard with combining these massive infrastructures, to cut down on the serious carbon footprint they are leaving behind. With the idea of combining services and using the same infrastructure for multiple environments the government is attempting to cut down on costs.

Of course the question is will it work? The hope is that there will be less maintenance costs, less staff to maintain, and it is a greener solution. The government is showing the greatest amounts of concern with security, privacy, and procurement at the moment. Of course it is a giant system, with many legacy applications, that many are predicting will not go away.

If anything is to change it won’t be fast, and will be almost like a case study for the government to attack at all angles. The main idea that this brought up is if the government can do it, why can’t we? Although most of us are relying on external IT infrastructure, it would be interesting to see what would happen if everyone was onboard with cloud computing.

Learn More…

Apps.Gov

Next Page »