Wednesday, June 10, 2009

Tenable Nessus Error on Windows Vista: Invalid Challenge Response

I'm trying to install Nessus Vulnerability Scanner (version 4.0.1) at home on Windows Vista Basic and the installation went fine but registering the product stalled my effort for quite some time with the error message below:

the error message comes after I enter the activation key and clicked Register. I can't start the Nesses server and therefore can't also condifure the daemon. If I try to re-register the same registration code, i get a message that the code has already been used so I need to get another code the Tenable website.

Frustrated, I also tried Nessus Off-line registration (without an internet connection), got the nessus-fetch.rc installed and I was able to start the nessus daemon at Services but still can't get past the initial screen of Nessus Server Manager.

Is this another one of Windows Vista problems or just Nessus? Will try to post this on the Nessus Discussion forum for answers, solutions or workarounds.

Monday, June 08, 2009

Information Security and Conflicts of Interest

I used to handle both Information Security and Auditor, I know but it happened because our Internal Auditor left.

I know I can perform both but the situation is really conflict of interest. Now that we have an Internal Auditor, other conflicting roles came out to the surface

Conflict of interests mostly uncovered were roles that doesn't adhere to segregation of duties. I know many banks who have a listed Information Security Officer just to comply with BSP mandate but the personnel is actually doing another function.

Information Security needs to be independent from IT or Operations and needs to report to management directly. Any InfoSec officer or IT security officer is not a good one if he's reporting to the IT head.

Independence is the key!

Monday, May 25, 2009

The Best IDP/IDS/IPS Intrusion Prevention System: Do you Really Need One?

In my normal line of work, I always get questions regarding certain technologies I use to secure my network beyond the usual firewalls

One of them is the IDS (Intrusion Detection System), IDP (Intrusion Detection and Prevention) and IPS (Intrusion Prevention System)...

It's just a play on words thou IDS is merely detection which is inutile since the damage may have been done already.

As for me I prefer the IDP/IPS particularly the inline type i.e. placed before the server/network to be protected rather than one that's just passively listening on a mirrored port.

But I was asked why it' took me so long to ever think of buying and justifying one. It's just that it's hard to justify expensive security systems if you're going to face traditional thinking superiors looking for security ROI.

I'm more into securing the hosts: the OS and apllication more than expensive security equipment...

adding an IPS is just another layer of security for me.

If you're looking for the best there is, I can;t make recommendations but it's always Tipping Point, Forescout, IBM's ISS et al or probably the free Snort :P