Forgot your password?

typodupeerror

Submission Summary: 0 pending, 4 declined, 1 accepted (5 total, 20.00% accepted)

Security

What security policy and processes do you use?-> 1

Submitted by EvilMonkeySlayer
EvilMonkeySlayer writes "Recently we had a big multi-billion dollar four letter Japanese company install some very expensive software and hardware on our premises. Unfortunately the engineers who did the installing also brought a virus in and managed to install that onto their very expensive server.

Through processes i'd put in and a bit of luck the server that they installed was the only thing infected. I'd like to say this was the first time this has occurred but this has happened in the past where a third party who installed a piece of hardware has brought in a virus. I've got a decent security in depth set-up so much so that none of our machines has never been infected either through employees or cracking attempts on our public/private servers and workstations. However, it seems once every so often when we have a third party bring in their own server/machine that we've purchased they will inevitably infect said machine.

I have pressed managers in the past at our company to inform any engineers that they must pass any laptops, flash drives etc by me before connecting them up to our network or to another pc. However, they have typically neglected to inform them. Case in point an engineer decided to connect an infected flash drive to one of the workstations which is how I found out about the virus in the first place since the workstation AV blocked the virus and informed me immediately at which point I rushed over and forbid him from using it.

I have been talking to the company MD and he's talking of getting any engineers who come on site to sign a document stating that their computers are virus free etc.

I am wanting to literally make it very much clear to everyone and any third party that if they bring in a computer/flash drive it MUST pass by me first.

Unfortunately I can't always hold the hands of these engineers as I'm the only IT guy in the entire company, so often I may not be available or in a different part of one of our two buildings.

Also, the engineers installed a web server so customers can login remotely for the system. However, the web server is an older version of Apache (2.2.9) running on windows. I have forbidden this machine from having external access until in the words of the account manager for the four letter company "we're waiting to hear back from Japan because the software needs to be updated from them" which doesn't fill me with confidence especially for something that needs to be updated relatively frequently. (contractually wise me updating Apache on this windows server is in a grey area...)

What policy or methods do you guys use to enforce the rules?

I've talked of sending a very clear letter to all the managers from the MD that if they do not inform any third party that they must pass any computers/flash drives through me first that there will be serious consequences. (for example docking of wages, sacking etc)"

Link to Original Source
Security

Getting help reporting a security issue

Submitted by
EvilMonkeySlayer
EvilMonkeySlayer writes "I recently got provided a pre-configured router after signing up to an ISP. However, the router in question I have discovered to my chagrin has a number of security issues such as a weak password (since changed) and ports 21, 23 and 80 are open to external access. So anyone can attempt to login to the router remotely.

The ports in question cannot be closed from either the routers web interface nor via telnet (at the moment). I can go into the routers service selections and totally disable the routers ftp, http and telnet abilities thereby shutting off anyone from logging in however this would also disable my ability to login too.

I have been trying to get in contact with someone senior at the ISP in question but have been brick walled by their Indian tech support.

How can I report this serious issue and hopefully get a fix?

The ISP is Demon. The connection type is "Demon Business Broadband 8000" (ADSL2) and the router is the "Thomson Speedtouch 585v7".
I do have a fallback option, I do own a different router however with that router I can only connect to the line at half the speed of the Speedtouch."

Extreme fear can neither fight nor fly. -- William Shakespeare, "The Rape of Lucrece"

Working...