Security Expert Security Expert

Amazon AWS Security Mistakes to Avoid

Amazon’s AWS (Amazon Web Services) is a popular cloud computing application which is used by people worldwide. It can help business owners reduce their IT costs. You no longer have to purchase expensive machinery and hire extra IT staff. You can use this cloud application to pay as you go to cut monthly costs for IT services.

Amazon’s AWS (Amazon Web Services) is a popular cloud computing application which is used by people worldwide. It can help business owners reduce their IT costs. You no longer have to purchase expensive machinery and hire extra IT staff. You can use this cloud application to pay as you go to cut monthly costs for IT services.

Being a relatively new service, users do find it a bit difficult to operate. Because of lack of awareness and neglecting the security protocols users make mistakes which can lead to many security risks. These risks can turn into real damaging situations which can harm your business.

PUBLICLY PUBLISHING KEYS

In their guidelines, Amazon specifically asks their clients to not publish their EC2 and S3 private keys publicly. But a research performed in Germany, by Centre for Advanced Security Research Darmstadt (CASED), suggests that AWS users are constantly publishing their private keys on the AMIs (Amazon Machine Images). With the access to these keys, any criminal element can access the data of a particular business and use it to damage the business. They can also use the data of companies to take advantage of their clients at the expense of the company.

Because users utilize their credit cards to gain access to the AWS, their credit card information is also vulnerable when a way to access their clouds is publicly published. When using the AWS, read the provided tips and guidelines carefully to avoid this risk.

CRITICAL IPS ON PUBLIC INTERNET

Some people leave their critical IP address open for public view. This can leave a door open to the cloud application and your important data is at risk of exposure. The critical IPs should be kept secure and access to them should be limited to essential users only.

PUBLIC ACCESS TO AMIS

Amazon Machine Images are created to store your sensitive data. Sometimes users leave it out in the open where anyone can access it. Set the access to private when creating AMI and use security software to keep it secure.

Amazon continually offers webinars and instructive videos to their AWS users so mistakes like these can be avoided. Read the user instruction carefully and take a look at some of those videos so you don’t leave any open doors to your data.

Read More
Security Expert Security Expert

Hidden Backdoors into Your WordPress Page

Like every other popular service or software on the internet, WordPress is prone to hacker attacks. There are some vulnerabilities in WordPress itself. Other security risks are created because of user neglect and carelessness. Users create websites and blog pages using WordPress and all their information is at risk when proper care is not taken to keep the pages secure.

Following are some common security risks that users face when using WordPress, by avoiding these you can keep your websites safe:

Like every other popular service or software on the internet, WordPress is prone to hacker attacks. There are some vulnerabilities in WordPress itself. Other security risks are created because of user neglect and carelessness. Users create websites and blog pages using WordPress and all their information is at risk when proper care is not taken to keep the pages secure.

Following are some common security risks that users face when using WordPress, by avoiding these you can keep your websites safe:

WORDPRESS VERSION

WordPress personnel are regularly coming out with updated versions of their web software to remedy the issues that their users face. Most people don’t update or forget to update their WordPress to the newer version which leaves their pages vulnerable.

Another mistake made regarding the WordPress version; users display the version they are using on their page. This allows hackers to learn the version and their job is made much easier. By removing the version display from your page and updating to the newest version of WordPress you can avoid these issues.

PLUGINS USAGE AND VERSIONS

Users of WordPress have the option of customizing their pages by using various plugins and themes. These can make a website stylish and user friendly, but overuse can leave a backdoor open for hackers to access your page. Be very stingy with your plugin and theme use. Only use the ones that are essential and keep them updated to latest versions to negate risks.

USERNAME AND PASSWORD

Don’t use admin as your username and password. That would be equivalent to giving your house key to a thief. Choose a unique username and a complicated/strong password. If there are multiple users then make certain that they all adhere to this rule. Remove any user accounts that are unused.

SECURE HOSTING SERVICE

Not all hosting services are secure enough to host your WordPress sites. Choose a hosting service after ensuring that it provides adequate security to your website. WordPress security and your personal efforts will be futile if your hosting service isn’t secure.

BACKUP

Even after taking all the precautions there are still risks that are unavoidable. Because of that reason, you should keep a backup of your webpage. If there is an attack on your site which compromises it, you can use the backup to restore your site easily.

Keep the aforementioned precautions and advice in mind for the safety of your WordPress sites. The best option is to get security software which has features that will help you monitor your WordPress pages and keep them secure effortlessly.

Read More
Security Expert Security Expert

Cloud Security Tools Which Are Worth It

Many organizations are migrating their data and software on to the cloud due to its increased popularity. However, where cloud computing is proving to be beneficial, it is also facing security concerns. Here are some cloud security tools, which are worth it to be secure on the cloud

How can you be protected on the cloud? Cloud computing brings reduced costs, scalability, and increased mobility to businesses along with security concerns. Many organizations are migrating their data and software on to the cloud due to its increased popularity. However, where cloud computing is proving to be beneficial, it is also facing security concerns. Here are some cloud security tools, which are worth it to be secure on the cloud:

BITGLASS

Currently in beta, Bitglass provides protection to business data. It is usable on mobile devices as well as computers. It improves the visibility of data and reduces the risk of data loss. Bitglass gives a combination of security types in one package. For cloud security services specifically, it gives the ability to detect usage of cloud applications, track business data on the internet, and encrypt data, which is uploaded on the cloud. By tracking data on the internet, it allows visibility for file sharing even when employees upload data onto personal file sharing services. Bitglass allows to wipe data on mobile device without using additional software. It provides specific builds for commonly used cloud apps such as Gmail or Salesforce, but variants are also available to configure with any cloud-based applications your business might use.

CIPHERCLOUD

Ciphercloud encrypts data directly at the business gateway. It aims to ensure data security, which is contained within the cloud system. It encrypts data during uploading and decrypts it during downloading. Since the encryption keys remain within the business network, unauthorized users are unable to view data; they will only see indecipherable text.

SKYHIGH NETWORKS

Skyhigh networks allow you to discover and secure the usage of your cloud applications. It provides you with a cloud application risk assessment of all cloud apps being used by your employees, by tracking logs from existing proxies and firewalls. The analysis tools it provides are able to detect inconsistencies in security policies and potential data leaks.

OKTA

Okta aims to provide secure single sign on for all on-premise and mobile cloud applications used in the business. It provides among other features, automated user management, multifactor authentication, support for mobile devices and flexible security policies. It enables you to trace user access to cloud through audit logs and allows setting access policies from a centralized position.

All these security applications provide ample security solutions to tackle threats on cloud computing, but app suitability for your business will depend on your business security needs and problems.

Read More
Security Expert Security Expert

WordPress security risks assessment

It is not a surprise that hackers target WordPress web sites. There are about 60 million WordPress web sites in the internet, and if a new vulnerability is discovered in the platform, all these sites will become vulnerable and can be compromised.

WordPress is now one of the most popular blogging platforms in the internet. It is an open source platform and a large number of plugins and additional themes and features are available from different developers and companies. The software can be easily customised and new features, such as contact forms, ecommerce, surveys, membership areas can be added to the web site.

It is not a surprise that hackers target WordPress web sites. There are about 60 million WordPress web sites in the internet, and if a new vulnerability is discovered in the platform, all these sites will become vulnerable and can be compromised.

There are two most common ways how the hackers compromise the WordPress web site:

  • Exploiting the well-known or new vulnerability in a plugin or a theme. As mentioned earlier, there is a huge number of plugins available for the WordPress and some of them are written by unskilled developers. According to http://www.cvedetails.com/ WordPress contains about 163 well-known security issues, some of them allow remote code execution.
  • Discovering the admin password to the management interface. By default, /wp-admin/ directory is not protected by SSL encryption. This means that if an administration is logging in to the web site from insecure network, for example, WiFi Hotspot, his credentials can be easily intercepted. Also, if the password is not strong, the external hackers can easily brute force the password.

So how to secure your WordPress web site? The internet contains a number of articles on this topic. The official security guide can found on wordpress.com web site: http://codex.wordpress.org/Hardening_WordPress

To summarise some key points:

  • Keep your wordpress blog and all the plugins up-to-date. Regularly check the WordPress platform for the updates and apply them as soon as possible. Install updates for the plugins as soon as they are available (obviously you need to test the new versions first and make sure they won’t break your web site). Subscribe to the latest news from the security web sites and monitor the vulnerabilities applicable to your plugins and the version of WordPress you are running.
  • Configure the strong password policy for your admin account. The passwords should be at least 8 characters long and should be changes regularly. Also configure your web site to temporary block the admin account after 5 unsuccessful login attempts. Make sure that SSL is implemented to secure the admin credentials: SSL provides the encryption of the username and password so it will be very challenging for the hackers to intercept them.
  • Limit the number of users with admin privileges to your web site. Review the user accounts on the regular basis and delete the accounts that were not used for a long time. Keeping the large number of users with admin privileges will increase your risk of being compromised. Even if you use SSL encryption for your web site, your users may use weak passwords or reuse the same passwords for different services.

The risks described above are just some of the risks the business owners inherit when they use the WordPress platform for their web sites. Although most of the risks can be remediated by implementing the appropriate control, the business owners need to be aware of them.

Lean Security can help to secure the WordPress web site. Lean Security is focusing on securing all your “Cloud” application and can monitor multiple Worpress web sites from single console. Our security consultants will perform the full security assessment of your environment and import critical parameters into the tool for constant security monitoring and compliance. Contact Lean Security for more information.

Read More
Security Expert Security Expert

Amazon AWS Security Risks

Amazon AWS provides a great opportunity for the companies to reduce the costs in their IT infrastructure and increase the speed they can release their products to the market.

Amazon AWS provides a great opportunity for the companies to reduce the costs in their IT infrastructure and increase the speed they can release their products to the market. Amazon AWS contains a large number of resources, such as Infrastructure-as-a-Service (called EC2), file storage (S3 buckets), Database-as-a-service (RDS) and many others. The number is growing every day and the value increases significantly. Almost all startups and companies now consider Amazon AWS to host their IT infrastructure.

To make an appropriate decision to use Amazon AWS cloud or not the companies need to fully understand the risks introduced by using this technology. The risks landscape is very different from traditional IT infrastructure, when all the critical system and applications are located behind the corporate firewall in internal network. Now the infrastructure located in the Cloud and requires different protection.

Below are the common risks introduced by the adopting Amazon AWS Cloud:

  1. Unauthorised access to the Cloud Management Console.

    Description: The administrator or Amazon AWS Account owner has full control over the cloud resources. He or she can delete all the servers just by clicking the button. If the administrator is not fully understand the technical background, he or she can open the firewall rules to allow all the traffic going in and out of Amazon AWS account. The hackers can potentially brute force / guess/ steal the password and connect to the console. If a hacker gets control over the account, the availability and integrity of the systems can be affected.

    Risk: High
    Likelihood: High (by default the account is protected by only password)
    Impact: High (all the servers can be affected)

    Mitigation controls: Amazon AWS can provide additional protection for an Amazon AWS account: two factor authentication. The administrator can use their mobile phone with Google Authenticator installed to increase the security of the account. Two factor authentication is not enabled by default and requires additional configuration.

  2. Poor access management process.

    Description: The Amazon AWS Management console is available from anywhere in the world. Obviously it provide a great flexibility for the users, but also presents a huge risk. If a company doesn’t have strong access management process, the terminated employee will probably still have access to the console. He or she will be able to connect from home, internet café or even competitor. Many companies have Identity and Access Management (IAM) system implemented for their internal systems, but Amazon AWS console not always integrated with it.

    Risk: High
    Likelihood: Almost certain (if a company has a large number of users)
    Impact: High (terminated users may cause significant damage)

    Mitigation controls: The companies need to review the users on the regular basis. It may be difficult the one company has multiple Amazon AWS accounts as Amazon doesn’t provide centralised console at this stage. Another option is to integrate Amazon AWS with IAM system or Active Directory, but it requires significant investment.

  3. Weak firewall rules.

    Description: By default, when you create an Amazon EC2 instance the Amazon will propose the default firewall rules (Amazon calls them the “security groups”) to access the instance. For Linus based instances it will be port 22 (secure shell) and probably ports 80 and 443 for the web server. For Windows instances they will be port 3389 (Remote Desktop) and ports 80 and 443 for the web application. By default, all internet will have access to this ports (source is 0.0.0.0/0). The hackers will probably try to brute force the password for SSH or RDP or use known exploit to get in.

    Risk: Medium
    Likelihood: Almost certain (not many people change the default rule set)
    Impact: Medium (the SSH access by default is configured to use private/public key and Windows password is relatively strong)

    Mitigation controls: The administrators or security professionals need to constantly audit the firewall rules to make sure the remote access is configured for particular source IP addresses. The IP restriction will reduce the risk of compromise significantly.

The above risks are just an example of what the companies should look at when adopting Amazon AWS cloud. The internal security department or systems administrators should perform the comprehensive security assessment of the environment before putting critical application into the cloud. If a company doesn’t have necessary skills to do it “in-house”, Cloud Guardian will help. Cloud Guardian staff will perform the risks assessment of your environment, propose the best mitigation controls and integrate them with our monitoring system to make sure your environment is safe. Moreover, we’ll help you to secure all your Amazon AWS accounts from single interface. Contact us for more details.

Enjoy AWS Security like Never Before

If you want to secure your Amazon AWS accounts, Cloud Guarding is where your search ends. As a unique tool performing Amazon AWS risks assessment, Cloud guardian not only monitors changes across multiple Amazon AWS accounts but also manages multiple Amazon AWS accounts.
This way Cloud Guardian allows users to have absolute control over who is granted or denied access to their Amazon AWS accounts. Cloud Guardian also facilitates the security groups by ensuring that they are configured properly and ensures that all instances of a cloud are well protected.

Read More