WatchGuard Security Week in Review: Episode 50 – UPnP Pwnage

UPnP Pwnage and Hacked Journalists

This week is rife with security news. If you want the quick highlights, you’ve come to the right place. Today’s video covers a few Yahoo XSS vulnerabilities, some serious UPnP security flaws, and the alleged China-based hack of the New York Times. Watch the video below for details.

Also, if you are interested in some other stories I didn’t have time to cover in the video, make sure to check out the Reference section for links to these extras.

Thanks for watching, and see you next week.

(Episode Runtime: 10:00)

Direct YouTube Link: https://www.youtube.com/watch?v=azjZ0dFxnR4

Episode References:

— Corey Nachreiner, CISSP (@SecAdept)

About Corey Nachreiner

Corey Nachreiner has been with WatchGuard since 1999 and has since written more than a thousand concise security alerts and easily-understood educational articles for WatchGuard users. His security training videos have generated hundreds of letters of praise from thankful customers and accumulated more than 100,000 views on YouTube and Google Video. A Certified Information Systems Security Professional (CISSP), Corey speaks internationally and is often quoted by other online sources, including C|NET, eWeek, and Slashdot. Corey enjoys "modding" any technical gizmo he can get his hands on, and considers himself a hacker in the old sense of the word.

2 Responses to “WatchGuard Security Week in Review: Episode 50 – UPnP Pwnage”

  1. Cross-site scripting and SQL injection attacks (similar with discussed in video and in extras article) are considered, let’s say “complicated malicious activities”, and if you will deeper analyze their technical nature – you will came to conclusion, similar with this:
    - Your employees, responsible for development of SQL Web applications (or dedicated testers), should make multiple check on stability of developed applications by revealing and applying potentially dangerous SQL queries to the applications. That should be done during testing period. It’s the way to proper data sanitization and secure the application code.
    - Multilayer protection should be provided for the perimeter networks of a company, hosting externally accessed services. And the firewalls with advanced security services can play their indispensable role to provide “defense-in-depth” for IT-resources.

    • I agree… I always recommend web developers at least look at OWASP.org to learn about some secure web development practices. Network security appliances, like the ones WatchGuard provides, and even more focus Web Application Firewalls (WAF), can help protect you during the “vulnerability window” when new flaws are found (because no coder is perfect)… but still the real solution is secure coding!

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 7,118 other followers

%d bloggers like this: