Showing posts with label Management. Show all posts
Showing posts with label Management. Show all posts

Sunday, March 27, 2016

Why I hate security "experts" (and "trainers")

Why I hate security "experts" (and "trainers")

Disclaimer: This is a pure rant, with no proper grammar, editing & politically (IN)correct logic... I am known to be politically incorrect, but 110% technically astute. I did NOT write this post to please you... You acknowledge that by reading this you will NOT judge the author of this post and Lucideus reputation as a security / service provider :D

Okay, this post was never meant to be written, but hey, every now and then you get a random love letter (e-mail spam) from _some_ company (read: lucideus)

I never wanted to see this page, being a semi-retired professional, hxxp://www.lucideus.com/security_technology_training.html


Then again when you claim to provide security training using funny jargon words like ATOM (Awareness, Technology, Operations, Management?) - you need to integrate that in to your website and company's security model. You should always practice what you preach, or stop preaching (read: selling snake oil), or be like Bill Clinton, [Telling people] "I am full of shit, I sell snake oil and bullshit" but be honest about it!


Your site is plagued with open ports, ranging from ssh to ftp, and what not! Your site has multiple network, web application (vulns like XSS, CSRF and SQL Injection) and server vulnerabilities, yet you claim to teach Web Application Security, IT Infrastructure Security and Cyber Security, apart from Incident Response which I very much doubt you'd be capable of performing; having a badly developed website which can be pwned by anyone with basic skills in under 40 minutes.


The worst part about this whole training page is "so-called" trainers using the words VA (Vulnerability Assessment) and PT (Pen Testing) in the same line / like a single word. This is the last time, I'll put up with this bullshit. If you can't differentiate between two different process maps in a security assessment, how the hell do you expect people to trust you? Take up your course? Are people so badly educated that they fall for a badly coded website running Apache?

The least you can do as a security trainer, you have to put your money where your mouth is?! Or atleast don't claim to be a security "expert" / "trainer" who trains people on a regular basis. I won't be surprised, if those 60,000 students from 200 plus organizations, come looking for a refund... haha! ;))

 

Secure your organization first, then start providing security services and training, be orderly in your business operations. So here's another organization, that can NOT secure themselves, but claim to provide security education, sound like a classic case of Catch-22? Fuel for your brain, haha! :D

Reminds of one meme where vijay kant asks manmohan singh for his "bonafide cetripicate signature" for his "practical ejam dumaaro", ofcourse, he said "bleaaase sir" hahaha! :))

And please spam wisely next time, okay?

Cheers!

Saturday, August 09, 2014

Firemon - Security Intelligence Platform (For Networks)

Disclaimer: Normally, I don't write about products or promote anything. This is NOT an endorsement or a promotion for Firemon and/or VMTurbo. The opinions and views scribbled herein must be taken with a grain of salt. My company is strictly vendor neutral !

Firemon - Company Overview

Consider this to be my notes from the session I attended at JW Marriott, Bangalore. 

Product: Appliance
Based on Cent OS 64-bit
DB Used: Postgres 64-bit
Licensing: Depends on Application Server and Number of Devices Required
Enables continual monitoring and understanding of Network Devices for Change, Risk and Compliance

Swag / Product information on Firemon
I had the opportunity to attend a session presented by James Frost, of Firemon EMEA team. Obviously he answered a few of my sensible questions. They gave away some cool swag. You (you as a reseller) are in business because you can do something better and more efficiently than your customer can do it. And you keep your customers because you can prove it. So, when it comes to managing firewalls, don’t just tell your customers that their firewalls are managed correctly. Show them with firemon!

Perks of being strong :D
The limitation of Firemon vs. a traditional SIM / SIEM is the scope of log aggregation and correlation that can be done (limited to Firewalls / Network Devices). Also, Firemon does NOT push policies or modify policies back to the firewall because, most vendors have no API support or Closed API. They plan to integrate Firemon with VMWare vShield which is opening up the debate of SDN (Software Defined Networks), which requires a separate post. With that said, its only fair to mention this product has a considerable edge over other firewall management products taking in to note the client's network context and covering change (in accordance with ITIL), risks and pre-emptive measures for managing change in an enterprise!

Check out their article on Enterprise Monitoring

One would relate this to VMTurbo (For VMWare - Virtualization) as vmturbo shows similar traits in pro-active monitoring and automating a lot of significant datacenter tasks. Not an apple to apple comparison per se, but NEW Products like Firemon and VMTurbo deserve a place in the enterprise where speed, automation and scalability need to be balanced by the IT Manager, productively using his costly IT resources to do other tasks at hand instead of closing tickets on a daily basis for Virtualization / Security.

Check out Firemon @ http://www.firemon.com
Check out VMTurbo @ http://www.vmturbo.com

Cheers,
Kish