Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

How to remotely Lock or Reset your stolen Android device.

How to remotely Lock or Reset your stolen Android device.
                Google announced a new locator feature for Android devices called Android Device Manager. This app helps owners to find thei...

Make Every Application an Independent Tenant

Make Every Application an Independent Tenant
Traditional data centers are usually built in a very non-scalable fashion: everything goes through a central pair of firewalls (and/or load ...

Can You Find SQL Injection Vulnerabilities with Spirent Avalanche NEXT?

Can You Find SQL Injection Vulnerabilities with Spirent Avalanche NEXT?
An odd idea stroke me when watching the Avalanche NEXT presentation during Networking Tech Field Day – they have a fuzzing module that you...

Dual-Stack Security Exposures

Dual-Stack Security Exposures
Dual-stack exposures were the last topic Eric Vyncke and myself addressed in the IPv6 security webinar. They range from missing ip6tables o...

First-Hop IPv6 Security Features in Cisco IOS

First-Hop IPv6 Security Features in Cisco IOS
I wanted to figure out how to use IPv6 DAD proxy in PVLAN environments during my seaside vacations, and as I had no regular Internet access ...

IPv6 Address Assignment and Tracking

IPv6 Address Assignment and Tracking
One of the significant challenges of IPv6 is definitely the host address assignment and tracking (for logging/auditing reasons), more so if ...

Real-Life SDN/OpenFlow Applications

Real-Life SDN/OpenFlow Applications
NEC and a slew of its partners demonstrated an interesting next step in the SDN saga @ Interop Las Vegas 2013: multi-vendor SDN application...

IPv6 uRPF and Neighbor Discovery Throttling

IPv6 uRPF and Neighbor Discovery Throttling
IPv6 source address spoofing should be old news – it’s no different from its IPv4 counterpart. Neighbor discovery exhaustion attack is an I...

The Dangers of Ignoring IPv6

The Dangers of Ignoring IPv6
I was sitting next to a really nice security engineer during the fantastic dinner-in-a-wine-cellar @ Troopers 13 and as we started talking ...

Troopers 13 – a must-visit security conference

Troopers 13 – a must-visit security conference
If you live in Europe and happen to be interested in security, make sure you put Troopers on the list of must-attend events. Like many thin...

Are stateless ACLs good enough?

Are stateless ACLs good enough?
In one of his Open Networking Summit blog posts Jason Edelman summarized the presentation in which Goldman Sachs described its plans to rep...

Dedicated Hardware in Network Services Appliances? Meh!

Dedicated Hardware in Network Services Appliances? Meh!
Francesco made an interesting comment to my Virtual Appliance Performance blog post: Virtual Appliance Performance is comparable to the eq...

They want networking to be utility? Let’s do it!

They want networking to be utility? Let’s do it!
I was talking about virtual firewalls for almost an hour at the Troopers13 conference , and the first question I got after the presentation...

Virtual Appliance Performance is becoming a non-issue

Virtual Appliance Performance is becoming a non-issue
Almost exactly two years ago I wrote an article describing the benefits and drawbacks of virtual appliances , where I listed virtualization ...

VM BPDU spoofing attack works quite nicely in HA clusters

VM BPDU spoofing attack works quite nicely in HA clusters
When I wrote the Virtual switches need BPDU guard blog post, I speculated that you could shut down a whole HA cluster with a single BPDU-ge...

This is what makes networking so complex

This is what makes networking so complex
The responses to my What did you do to get rid of manual VLAN provisioning post were easy to predict: a few people sharing their best pract...

Compromised Security Zone = Game Over (Or Not?)

Compromised Security Zone = Game Over (Or Not?)
Kevin left a pretty valid comment to my Are you ready to change your security paradigm blog post: I disagree that a compromised security z...

Are you ready to change your security paradigm?

Are you ready to change your security paradigm?
Most application stacks built today rely on decades-old security paradigm: individual components of the stack (web servers, app servers, dat...

IPv6 Source Address Validation Improvement

IPv6 Source Address Validation Improvement
We learned how to deal with ARP and IP spoofing in IPv4 networks. Every decent switch has DHCP snooping, ARP protection and IP source guard ...

The Spectrum of Firewall Statefulness

The Spectrum of Firewall Statefulness
One of the first slides I created for the Virtual Firewalls webinar explained various categories of traffic filters, from stateless (and fa...