Saturday, November 19, 2011

Nov 24th - My son's Second Birthday



I am happy to look forward my son's second birthday...I wish to start active blogging again...

Wednesday, February 3, 2010

Six Important Tips for Incident Response By Leighton Johnson, CISA, CISM, CISSP, CIFI

1) Be prepared for incident response. You must have tools, techniques, team members and training all completed before you respond to the computer incident. Also, corporate policies, procedures and guidelines for response need to be in place.
2) Properly identify the incident. Is the event simply an unusual activity, or can you identify it as suspicious? If so, what are the surrounding activities? Are there multiple reports of issues on the network, or is it confined to one machine or location? Some of the areas to check include suspicious entries in system or network accounting, unexplained new user accounts and unexplained new files.
3) Contain the incident and its effects. Change passwords for elevated privilege accounts and review computer trust relationships as fast as possible when an incident is identified. Protect and, where possible, keep the critical information resources available to the primary users.
4) Remove the issue as soon as is realistically possible. Possibly ensure and run your antivirus and antispamware programs. Review and potentially rebuild the operating system software. Remove the infected software utilizing approved removal software.
5) Return the infected system to operational use as soon as feasible. Remember there are two areas of focus for incident response: recovery and, potentially, prosecution.
6) Follow up with responders for improvements to the process. Check with the operational staff in areas where data or information was compromised.


PS: Leighton Johnson, CISA, CISM, CISSP, CIFI, is a senior security consultant for the Information Security & Forensics Management Team.

Monday, January 11, 2010

I am CISSP Now

What an eventful year 2009 was ? Oooooohhhhh! SWISS in my Company, CISA & CISSP. Really a fantastic year to look and cherish ..Looking forward in 2010 !

Thanks to Divine Mother for all her blessings,
Bala

Thursday, September 24, 2009

I am CISA Certified Now

I finshed my CISA and got the certification.

Wednesday, February 25, 2009

"Slum Dog Millionaire has won 8 Oscars!"

Poverty meets Wealth
Talent meets Recognition
Adversity meets generosity
Triumph meets destiny

Sounds Cynical, Skeptical ….

Hmmm….. Even paradoxical …!!!!

"Slum Dog Millionaire has won 8 Oscars!" --- Intriguing ….!!!

My dear fellow TMs, TM of the Day Pramodini and distinguished Guests ….. Good afternoon Wishes to you all …!

As promised, I am in front of you presenting the consolidated comments given by fellow Toastmasters and also my touch points regarding the Topic "Are the Oscars Honest?"

Views from Fellow Toastmasters:-

1) Gopi vehemently voiced that nothing is honest so as Oscars. All these awards are influenced by some people or country for specific motives.
2) Ravi elaborated further suspecting business or political motives. He also debated if the movie satisfies its director commercially and technically, nothing beats that feeling.
3) Chella Thangam choir the same view as Ravi's.
4) Dhana turns over the theme by asking the question about challenging existing systems without base. She also perceived that doing so reduces credibility.

Thanks a ton for these souls who spent their valuable time for giving comments.

These are the Ten Commandments to win the Oscars …!!!! Look, I am not here acting as MTV's Senior Cyrus Broacha. So Plz don't take it a laughing stuff.

1) Get a American Producer and Director. British also fine. Don't forget to wrap AR Rehman.
2) Take a subject which touches the heart of the people
3) Get it released in Holly Wood.
4) While choosing a subject, for an example, one night @ the call centre – Portray the worst side of life. But a word of caution – See if any previous similar movies were released and reached Oscars selection process
5) Plumb the depth. Make it technically perfect.
6) Make a movie by which every one should say, is this so bad..? We are much concerned … I would like to help them … How can I?
7) Make a visible marketing campaign for the movie and arrange for lot more previews.
8) Invite all famous celebrities and ensure to cover all major business dailies.
9) Give more interviews and advertisements.
10) Release the movie @ the right time like how slum dog had done.

If you have done all these ten points you are almost close to Oscars … But above all, matter of luck plays crucial role. Hope Kamal Hassan learns the lesson.

So my conclusion with director's touch are :-

1) I want to say positive about smiling Pinki which won an Oscar for short documentary but even that falls under my ten commandments.
2) Though famous icons like Amitabh Bachan and Shoba De felt in line with similar thoughts as mine, Lets take this event in a positive note and learn lessons from our past mistakes and take a pledge to continue our march in Academy Awards on our own.

Jai Hind

Wednesday, February 11, 2009

"Are the Oscars honest?"

"Jai Ho ... The New voice of India's talents being displayed in International Film Society … 3 Awards in Golden Globe …. 10 Nominations in Oscars under Main Stream Category.. 7 Awards in BAFTA ..!"

I am going to wear the shoes of both Academy Awards side as well as Indian Film Makers side to list out the positives and negatives. Also, I am going to post this speech in my blog and I request you all to voice your thoughts and same will be summarized in my next blog after Feb. '22 Academy Awards Results.

The world is dancing to the tunes of Jai Ho …. At the same time, lots of Indians felt this movie portrays India as the worst ….PILs filed against SDM crew members …. Why is this difference?

I have couple of major points about this movie …!

1) It's not a great movie at all when compared to the movies India have produced like Roja, Kannathial Muthamittal, Bombay, Company, Traffic Signal, Rang De Basanti, Manichitrathalu, Anjali, Black etc., I saw Dharavi very closely and I almost daily travelled across for close to 2 years when I worked for National Stock Exchange.

2) I doubt, "If this movie would have been directed by an Indian, would it gain this fame? I am not sure looking at the history. Quite a few incidents in this movie are exaggerated.

Let me tell you the positives of Oscars towards our Indian Movies.

From Mother India in the year 1957 starring Nargis and Sunil Dutt, Salaam Bombay in the year 1988 by Mira Nair, Lagaan in the year 2001 starring Aamir khan - all above three were received nominations under best foreign film category. Water (2006) by Deepa Mehta made in to Oscars thru Canadian Entry. In 1982, Gandhi won 8 Oscars under main stream category. Satyajit Ray won a honoury award in 1994. Is that enough for Indian Film Industry's whose had, having stalwarts like Amitabh Bachan, Kamal Hassan, Aamir Khan, Mani Ratnam, Shankar & many more ?

On the negative side, I wonder why the same Academy Awards has not even picked up for the nomination under best foreign film category for movies like Anjali, Thevar Magan, Bandit Queen, Indian, Taare Zameen Par ….? Is that means these movies are not even worth a nomination …?

Coming to the Indian Film Makers and Government of India side, Govt of India's selection to Academy Awards is the major negative.

1)I wonder seriously why I could not find movies like Roja, Company, Kannathil Muthamittal, Black, Traffic Signal, Bombay, Pitha Magan in India's nomination list.
2)Why there was no nomination from India to Academy Awards for almost 10 times ?
3)Is the committee really look at the quality of the movie … or some other factors play role …. Because I was stunned when I saw movies like Devdas, Eklavya being selected for Academy Awards contest from Indian Side.

Now from my perspective as conclusion, Oscars is not honest.

1)They consider various factors other than the quality and message of the film.
2)Production Group and Director origin played a key role while recognition as heavy international lobbying seems mandatory.

At the same time Govt of India need to take this activity of nomination to Oscars more seriously by putting proper screening panel for selecting the right movies.

Only thing which made me happy about this movie is not A.R Rehman got recognition but our Indian Government will not now require more effort to get more loans from World Bank.

Cheers,
Balachandar Natarajan

Sunday, January 18, 2009

Happy New Year 2009

Hai Friends,

Wishing you all a very Happy New Year 2009. I have started this new year with a great note by starting to Sabari Mala. It was a great Dharshan. Our troop was the great one and made my journey so lively & memorable. Most intriguing fact was the annadhan we carried out at Pamba right at the end of the tough journey from Karee Malai which is the most toughest one to traverse .... I would like to put a separate blog about my wonderful experiences there during my big route voyage, annadhan experience, group members and finally Ayyapan Dharshan. Now I am looking for this year to be a turning point in my life paving inroads towards achieving my aspirations .....Cheers and Enjoy life ...with a meaning ...!!! Bala

Saturday, November 15, 2008

Work life getting better !

Hai friends,

Just a month to go for CISA Exam ... Started in full speed for covering all chapters ... Mean while I completed my BEC Vantage Certification from BC. Diwali went well ... Nothing much in personal life too ... Work makes me happy now-a-days ..

Cheers !
Bala N

Tuesday, September 2, 2008

Whether Hardwork Pays ?

I feel hardwork doesn't pay if it is not clubbed with intelligence. Combination of Hardwork and Intelligence will raise us to the top.

I am in the process of restructuring my time schedules in order to accomodate my aspirations .....CISA & CISSP by the end of this year .....

I am feeling too sensitive now-a-days ... Don't know how to face failures ?

I am also getting a training from British Council and will be going to take the exam by Sep 21st and Sep 27th ....

Wishes needed .... Cheers !

Thursday, August 21, 2008

Failure - Stepping stones for success

Dear Friends,

I failed in CISSP Exam with a score 646 .... I have not performed well in areas like Application Security, Physical Security & Security Architecture & Design....
I have done well but unfortunately it is not enough to crack this exam....
Planning for giving it again in Oct since in Sep i have to give British Council Exam.
Registered today for CISA Exam in Dec ..... Miles to go before I sleep ....

Bravely waging a war against all obstacles .....

Cheers and wishes needed from you all .....

Yours,
Bala

Thursday, July 17, 2008

Registered for CISSP Exam

Friends,

I have registered for CISSP Exam on August 2nd in Bangalore. Putting my all efforts to read the (ISC)2 CBK. Hmm. Its really a good book ... Happy reading Bala ...

Till then ... Enjoy ....

Tuesday, July 15, 2008

Joke Time !

A Man was walking down a street when he heard a voice from behind, “If you take one more step, a brick will fall down on your head and kill you.” The man stopped and a big brick fell right in front of him. The man was astonished.

He went on, and after a while he was going to cross the road. Once again the voice shouted, “Stop! Stand still! If you take one more step a car will run over you, and you will die.” The man did as he was instructed, just as a car came careening around the corner, barely missing him.

The man asked. “Who are you?”

“I am your guardian angel,” the voice answered.

“Oh, yeah?” the man asked “And where the hell were you when I got married?”

I loved this joke like anything ....Good laughing stuff ...

Wednesday, July 9, 2008

Some Interesting blog I saw on Information Security !

Hai all,

I saw this blog today morning. It has more interesting stuffs, PPTs and articles.
Just a sample !

Thursday, June 26, 2008

You Are "A Security Idiot" If ...... you:


1) Misspell both HIPAA and SOX (how the f does one misspell SOX?)
2) Confuse "risks" and "threats"
3) Think that "Trojan is a vulnerability" AND "DoS is a vulnerability"
4) Quote "Insiders are 80%" without thinking for one darn second
5) Think that a loss of "$20 million is catastrophic to any company"
6) Talk about "NIST compliance"
7) Consider IDS a network security control
8) Shout that "perimeter is dead"


Explore more there ...

http://chuvakin.blogspot.com/

Cheers,
Bala

Wednesday, July 2, 2008

Good News !

I am back in form again. Will be definitely giving some useful hints in Information Security and Digital Forensics daily. Also will share some views on my preparation for CISSP too ... Cheers !

My Life !

Now-a-days I am too busy !Preparing for CISSP. Attended a crash course from Intellisecure in Chennai from Jun19-22 for 4 days. Ok It was. Nothing much I can say. Only advantage I had seen is a glance on all ten domains which will give u a trigger to complete the certification soon. Daily dedicating 2 Hrs in night. Thanks to my wife for her wonderful support and constant encouragement through this learning phase....Work is going fine.....

An article about recent microsoft patch for SQL Injection Attack

SQL Injection Attack targeting websites using MS ASP & ASP.NET Technologies

This document is to explain an overview about the Security Advisory-954462 note from Microsoft.

What is this alert?

Microsoft has released Security Advisory 954462 – Rise in SQL Injection Attacks Exploiting Unverified User Data Input - on 24 June 2008.

Summary by Microsoft:-

Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit specific software vulnerability, but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database. When a SQL injection attack succeeds, an attacker can compromise data stored in these databases and possibly execute remote code. Clients browsing to a compromised server could be forwarded unknowingly to malicious sites that may install malware on the client machine.

The purpose of Security Advisory 954462 is to assist Web site administrators in identifying possible issues with their Web application code being susceptible to possible SQL injection attacks and to provide a stopgap solution to mitigate SQL injection attacks against the server while the applications are being fixed.

Solution:-

We need to understand that if we are following the best practices for secure web application development having control over user data input; this is not at all a threat to us. This is applicable to only those web applications which are developed using Microsoft ASP & ASP.NET technologies. My attempt is to put the best explanations made by Microsoft for your easy reference and If you require more I can work on this topic in detail.

The first one is detecting the presence of the vulnerability. The second is to defend the same by installing a tool. Microsoft also developed a tool for ASP developers for detecting the susceptibility for SQL Injection attacks. This tool is for only those whose use ASP not ASP.NET

Microsoft's Suggested actions:-

I) Detection – HP Scrawlr
Hewlett Packard has developed a free scanner which can identify whether sites are susceptible to SQL injection. This tool and support for its use can be found at Finding SQL Injection with Scrawlr at the HP Security Center.
Detailed description:
The tool will be a black-box analysis tool (i.e. no source code required). The user will input a starting URL, and the tool will:

1) Recursively crawl that URL for hyperlinks in order to build up a site tree.
2) Test all discovered links for verbose SQL injection by sending HTTP requests containing SQL injection attack strings in query string parameters.
3) Examine the HTTP responses from the server for SQL error messages that would indicate SQL injection vulnerability.
4) Report any pages found to be vulnerable to the user, along with the associated input field(s). For example, the tool might report that the fields “username” and “password” on page “foo.asp” are vulnerable.

II) Defense – UrlScan version 3.0 Beta
UrlScan version 3.0 Beta is a Microsoft security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, UrlScan helps prevent potentially harmful requests from reaching the Web application on the server. UrlScan 3.0 will install on IIS 5.1 and later, including IIS 7.0. UrlScan 3.0 can be found at URLScan Tool 3.0 Beta.

Detailed Description:
UrlScan version 3.0 is a tool that will allow you to implement many different rules to better protect Web applications on servers from SQL injection attacks. These features include:
1) The ability to implement deny rules applied independently to a URL, query string, all headers, a particular header, or any combination of these.
2) A global DenyQueryString section that lets you add deny rules for query strings, with the option of checking un-escaped version of the query string as well.
3) The ability to use escape sequences in the deny rules to deny CRLF and other non-printable character sequences in configuration.
4) Multiple UrlScan instances can be installed as site filters, each with its own configuration and logging options (urlscan.ini).
5) Configuration (urlscan.ini) change notifications will be propagated to worker processes without having to recycle them. Log settings are an exception to this.
6) Enhanced logging to give descriptive configuration errors.

III) Identifying – Microsoft Source Code Analyzer for SQL Injection
A SQL Source Code Analysis Tool has been developed. This tool can be used to detect ASP code susceptible to SQL injection attacks. This tool can be found in Microsoft Knowledge Base Article 954476.
Detailed Description:
The Microsoft Source Code Analyzer for SQL Injection is a standalone tool customers can run on their own ASP source code. In addition to the tool itself, there is documentation included on ways to fix the problems it finds in the code it analyzes. Some key features of this tool are:

1) Scans ASP source code for code that can lead to SQL Injection vulnerabilities
2) Generates an output that displays the coding issue
3) This tool only identifies vulnerabilities in classic ASP code. It does not work on ASP.NET code

Some of the other urls I have referred and find useful details in related to this topic are:

1) http://msdn.microsoft.com/en-us/library/aa224806.aspx - This link tells you some basic thumb rules for preventing SQL Injection Attacks.
2) http://msdn.microsoft.com/en-us/library/cc676512.aspx - This link tells you the methods to find and fix SQL Injection vulnerability in ASP Technology.
3) http://msdn.microsoft.com/en-us/library/aa224806.aspx - This link tells you the methods to find and fix SQL Injection vulnerability in ASP.NET Technology.

Conclusion:-

The suggestions provided by Microsoft are more comprehensive based on reading the procedures. It seems to be practically possible though I have not tested anything. The HP Scrawlr tool is the simplest tool to carry out the testing in test environment. Further urlscan and Microsoft source code analyzer will give ways for prevention.

Best Regards,
Bala

Saturday, June 7, 2008

More Updates


Dear All,

Its really after a longtime. I am married and finished GCFA now. Just doing registration for CISSP.

Wednesday, February 6, 2008

Preparing for GCFA

Itz after a long time. I am busy with personal works like booking a flat, marriage arrangements, Case analysis in work along with GCFA Preparation. Would like to complete GCFA by march and finish CISSP by July. My work is going tough with more new challenges in the field of forensics daily.

See you soon,
Bala

Tuesday, December 11, 2007

Some Photos of London Trip



Dear All,

I ma back to Chennai. Great trip and nice KT from UK counter parts. We are now geared up fully for the work in Forensics....

See you soon ..

Friday, November 30, 2007

Visited Odeon --- Red Carpet

Itz great training out here. Yesterday been to Odeon in Leicester Square for meeting my brother-in-law. Saw Odeon theatre .. wow its awesome ...will post u with some photos soon .. going again now there to meet my friend of mine during my Eng college along with colleagues.