RANSOMEWARE HIT COMPUTER SYSTEMS
Farell Folly
farellfolly at GMAIL.COM
Mon May 15 12:08:18 EEST 2017
Dear All,
Using a FOSS is not the ultimate solution for security. Actually, The more
an OS is used by (or open to) many people, the more chance there is that a
vulnerability assessment/Penetration testing will reveal issues as the
system is also open for worldwide hackers to know how it works and how it
shouldn't !
For your information, Android and Linux were the most vulnerable OS in
2016 according to Business Insider (image attached)
Also :
100% security is not achievable
80% + of attacks come from insiders
90% of attacks target application layer
Therefore, Even when using a FOSS, consider the following rules :
Use most stable versions,
Conduct regular Vulnerability Assessment and Penetration Testing. Apply
latest patches and updates as soon as possible.
Development Information Security policy in your entity and implement it.
Conduct awareness campaigns (this is one of the most important rule : the
more a user is ignorant the more he/she is prone to use his /her IT asset
in a more vulnerable way)
Best Regards
@__f_f__
about.me/farell
________________________________.
Mail sent from my mobile phone. Excuse for brievety.
Le 15 mai 2017 15:35, "Enrique Chaparro" <echaparro at vialibre.org.ar> a
écrit :
> [[SLIGHTLY OFF-TOPIC FOR THE LIST]]
>
> Some quick notes:
> 1
> If you are interested in the worm mechanism spreading
> the infection, there's a good article here:
> https://blog.malwarebytes.com/threat-analysis/2017/05/the-
> worm-that-spreads-wanacrypt0r/
>
> 2
> You may adopt FOSS for many good reasons, but security
> is not one of them. Unpatched vulnerabilities in critical
> FOSS pieces have lived for years. E.g., 'Dirty Cow'
> (CVE–2016–5195) was sitting unnoticed(?) for nine
> years; the bug causing CVE-2015-7547 glibc vulnerability
> was around for 8 years, etc.
>
> 3
> As ecosystems show, diversity is A Very Good Thing™.
> However, diversity in the critical Internet infrastructure
> is actually very poor. A critical exploit affecting Cisco core
> routers may bring the Internet to its knees... and there is
> nothing we can do in a highly concentrated, quasi-monopilistic
> market.
>
> Regards,
>
> Enrique
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170515/2e11d515/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 2017-05-15 16.57.43.png
Type: image/png
Size: 242562 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170515/2e11d515/attachment.png>
More information about the Ncsg-discuss
mailing list