Ajit Gaddam

Writing about security, identity, cryptography, data systems, product engineering, and the changing edges of the web.

132 entries · 2006—2020

Notes from the work.

Original publication dates are preserved. Older technical guidance reflects the tools and assumptions of its time.

132 STORIESNEWEST FIRST

Featured

Winner of 2017 Information Security Executive Award

Honored and privileged to have been chosen as the Information Security Executive of the year 2017. The awards ceremony and the winners for the executive of the year and security project of the year were announced at an A…

TechNews

Judge for SC Magazine Awards 2017

The annual SC Magazine 2017 awards celebrating the best and brightest in Information Security is around the corner. As part of this mission, it was a huge honor and privilege to be part of a small panel of judges compris…

TechNews

Speaking at Global Big Data Conference 2016

Speaking on Securing Apache Kafka [caption id="attachment_421" align="aligncenter" width="1322"] Securing Apache Kafka by Ajit Gaddam[/caption] http://globalbigdataconference.com/santa-clara/big-data-bootcamp/schedule-77…

Cloud

Cloud Security Guidance

This post is a summary of the guidance provided in version 3 of the Cloud Security Alliance document Security Guidance for Critical Areas of Focus in Cloud Computing v3.0. The CSA guidance remains one of the best around…

Tools

Good List of Open Source Security Projects

This is a compilation of some excellent open source security projects. I will continue to update this page. Insert in comments below if you have any good reference projects or open source security tools. I am excluding t…

TechNews

Speaking at Black Hat USA 2015

Very excited to announce my selection and participation in Black Hat USA 2015 being held in Las Vegas this year. My talk is titled 'Securing Your Big Data Environment'. Come join me in the South Seas CDF room in Mandalay…

Application Security

The need for Secure Coding in an Enterprise

We live in a global village of interconnected systems that share data and other services. Such an environment calls for heightened awareness around application security. Enterprises should establish a strong application…

Security

How to create Secure and Easy to Remember Passwords

It is very important to choose a secure password to help protect your identity and information on the Internet. I previously wrote about strong password suggestions and how easy it is for bad guys and hackers to guess yo…

Security

Weekly Security Updates on 2011-10-23

'Ever notice how it's a penny for your thoughts, yet you put in your two-cents? Someone is making a penny on the deal.' - Steven Wright # Review of the excellent @NewYorker article around Ray Dalio including quotes &…

Security

Weekly Security Updates on 2011-10-16

Developers, developers, developers replaced by Platforms,platforms, platforms in this insightful article around #Google http://t.co/kNjpw7N4 #…

Security

Weekly Security Updates on 2011-10-02

var life = new[] {"eat", "sleep", "security"} # #BSIMM3 has been released. Go grab it http://t.co/3xnMgSLp and account for application #security maturity #AppSec #BSIMM # Checking out #Tableau Desktop http://t.co/Tuw5oaP…

Security

Weekly Security Updates on 2011-09-11

Revoke trust of the #DigiNotar root certificates - root CA, Root CA G2, PKIoverheid CA, PKIoverheid CA Organisatie. http://t.co/biXY2bj # Enterprise or Security Architects don't define the strategy but define the capabil…

Security

Weekly Security Updates on 2011-08-28

Security Quote of the day: #cloud is one of those solutions waiting for a problem. No one knows its purpose yet #SABSA #InfoSec #quote # Just experienced my first earthquake a 5 something #Washington #Virginia #earthquak…

Security

Weekly Security Updates on 2011-08-14

Excellent article about #data #exfiltration http://t.co/cLn509m #infosec #security # Test #Android for #security with this excellent #pentesting guide http://t.co/R8z4yNN #…

Security

Weekly Security Updates on 2011-08-07

Reading #Application #Security: 2011 & Beyond – A #Forrester Research Report http://t.co/m3DV7R5 (pdf). Good insights and recommendations #…

Security

Weekly Security Updates on 2011-07-24

#ISC2 Global Information #Security Workforce study http://t.co/iJDDSoG (pdf). Topics: #salary experience, training & #certifications # Excellent #Ruby on Rails Security guide. http://t.co/VZ8LwQC #AppSec # Own your o…

Security

Weekly Security Updates on 2011-07-17

How to make folks ready a #privacy policy? Turn it into an interactive game http://t.co/WYqYpag. Check out #zynga #039;s #PrivacyVille # Johns Hopkins University course on #Security and #Privacy in #Cloud Computing. Exce…

Security

Weekly Security Updates on 2011-07-10

Now that you can buy any TLD,buy ".1" and create a host called "127.0.0" under it. Lets see what breaks. Lend me $185000 via @mikkohypponen # Updated #SDL banned function calls http://t.co/kRi6YEQ. Include various C runt…

Security

Weekly Security Updates on 2011-07-03

I like the security concept behind Google+ - it's a social network almost nobody can join via @dourscot # Primary threats targeting mobile devices and data. Good infographic & report (PDF) via @symantec http://t.co/L…

Security

Weekly Security Updates on 2011-06-12

Looking at #sectestsuite for automated #security #testing http://goo.gl/IocPB including automation of the #owasp testing guide via @owasp303 # Have an #Android phone? Use RedPhone and TextSecure apps http://goo.gl/4p2Dg…

Application Security

Resolve Facebook security warnings when a user enables https

When a user who has https enabled and lands on your page or Facebook app, your page maybe generating security warnings about webpage content that was delivered. Do you want to view only the webpage content that was delivered securely? If an FB app does not have the Secure Canvas URL set, the error message will be shown

Application Security

Resolve Facebook Security Warnings when https is Enabled

This article if focused on Facebook App Security and Facebook https warning. You may have come across the security warning as shown below if your app requires communication over https. This is due to cross domain content…

Security

Weekly Security Updates on 2011-06-05

Facebook Account got #hacked Five tips to recover your #Facebook http://goo.gl/iHT0j #security #privacy # Train employees and risk them leaving or not train employees, and have them stay! #evenworse #training #infosec vi…

Security

Facebook Account got Hacked? How to Recover your Facebook

Is your profile sent spammy links to your friends walls with events or videos you did not create? Is your wall flooded with spam messages? It is possible that malicious software (e.g. computer virus or worms) has been do…

Security

Weekly Security Updates on 2011-04-03

#Google +1 sounds cool and geeky. Would regular folks know what it would mean? #likebutton #request # If #Google didn't want to use like, maybe a "promote" tag or something else # Don't think I will be promoting search r…

Security

Weekly Security Updates on 2011-03-20

"How I need a drink, alcoholic of course,after the tough lectures involving quantum mechanics" Count letters for 3.14159265358979 #pi #piday # Time to update your Google Profiles. #Google intends on deleting all private…

Security

Weekly Security Updates on 2011-03-13

@securityincite Mike, did you folks explore security as a service, not cloud services but internal to an organization(architecture domains)? # @securityincite Mike, sent you a high level description of my thought around…

Security

Weekly Security Updates on 2011-03-06

#CareerBuilder is calling the "Cyber Security Specialist" as the top potential #job http://goo.gl/HEH59 via@securityincite #career #InfoSec # Am now #Gingerbread Not a big fan of all green though. #NexxusOne #Android #Go…

Security

Weekly Security Updates on 2011-02-27

Great analysis of the effectiveness of #DEP and #ASLR and their value -- both alone and together.http://goo.gl/YpblS #InfoSec #AppSec # Read: Model-driven Cloud Security: http://ibm.co/evKuue via @IBMFedCyber by @objects…

Security

Weekly Security Updates on 2011-02-20

Seeing all these booth numbers at #RSA I wonder who booth number 1337 is .. #security #infosec #leet # #NIST Information Security Glossary of Key Information #Security Terms released http://goo.gl/DYRpI #InfoSec # #BSide…

Security

Weekly Security Updates on 2011-02-13

#WordPress 3.0.5 is now available and is a #security hardening update for all previous WordPress versions http://wordpress.org/download/ # Open #Security Analyst position on Threat and Vulnerability team with focus on we…

Security

Weekly Security Updates on 2011-02-06

If you have #GoDaddy as your ISP, you can now enable #mod_pagespeed now http://goo.gl/kyVV9 by editing your .htaccess file # #OWASP #Appsec Tutorial Series that highlights a different security concept, tool or methodolog…

Security

Weekly Security Updates on 2010-12-12

Apply for the #Google #Chrome netbook pilot program here http://www.google.com/chromeos/ #chromeos #android # Performance Analysis of WS-Security Mechanisms in SOAP-Based Web Services http://goo.gl/yoKNV #CMU #IdM #secur…

Security

Weekly Security Updates on 2010-12-05

Wordpress 3.0.2 is out - security update http://wordpress.org/download/ #wordpress #security # How to improve the security of Internet Explorer protected mode in the enterprise http://goo.gl/uBrfp #sandbox #internetexplo…

Security

Weekly Security Updates on 2010-11-28

No more flat networks. ANSI ISA-99 security zones guide. http://goo.gl/PI3JE (pdf) #stuxnet #security #network #ANSI # "Berlin" is revealed as #Kryptos clue. Time to dig deep. http://goo.gl/eu44v #CIA #Kryptos #encryptio…

Security

Weekly Security Updates on 2010-11-21

Free online Certified Ethical Hacking (CEH) course from Logical Security http://goo.gl/hKTm4 #CEH #hacking #course #security #free # Just got added to The Open Group (TOG) public certification register for my TOGAF 8 cer…

Security

Weekly Security Updates on 2010-11-14

Hotmail is now using SSL https://www.hotmail.com. Can choose to always use SSL. Won't work with Outlook or any live mail apps. #Hotmail #SSL # HTML5 security cheatsheet http://goo.gl/KGo8R via @0x6D6172696F #HTML5 #secur…

Security

Weekly Security Updates on 2010-10-17

@mattcutts he seems to have figured out the answer to the life, universe and everything.. a successful marriage in reply to mattcutts # installing Ubuntu 10.10 on 10/10/10 # Orgs with a data breach were 50% less likely c…

Security

Weekly Security Updates on 2010-10-10

The often-misused SAS-70 auditing standard is set to be replaced next year by SSAE-16 http://goo.gl/SEtI #cloud #SAS70 #standard #security # @indi303 you have leet followers ... # Improper output & input handling res…

TechNews

Happy 10/10/10 Binary Day

The day is made up entirely of ones and zeros, the binary language for computing. Some other trivia about 10/10/10 0. Converting 101010 from binary to decimal gives 42, the answer to the meaning of life, the universe and…

Security

Weekly Security Updates on 2010-10-03

I have access to the new Twitter #woot #twitter # I heard Stuxnet was running for president with drop database as his running mate via @st0rmz #stuxnet #hype #worm # Great list of default passwords with over 361 vendors…

Security

Mentoring the SANS 401 Security Essentials class

Definitely happy and excited that my mentor class is now live and I can begin the mentor program beginning September 21st in Cleveland. Personally, it is a wonderful opportunity for me to interact with other security pro…

Data Protection

Analyzing the 2010 Verizon Data Breach Report

In a way, the annual Verizon Data Breach reports have become a must read when it comes to analyzing the latest trends associated with data breaches. This years report had more meat and gained additional weight when the U…

Application Security

SQL Injection Attacks explained for the Developer

SQL injection attacks have become the most widely exploited security attacks on the Internet as they can usually bypass layers of security such as firewalls and any other network detection sensors. They are used most oft…

Security

Facebook Privacy Settings Guide

Facebook, the most popular social networking site just implemented a bunch of new privacy settings for its users. The new privacy settings are being promoted by Facebook as making it easier for its users to control their…

Application Security

Encrypt HTML form data without using SSL

In certain cases, it might be hard to install SSL certificates or SSL is not supported by some webhosts. In those cases, there is a need to encrypt the data (POST/GET) that is sent when you submit a form because if you d…

Security

How to Encrypt Files using TrueCrypt

TrueCrypt is a free open source disk encryption software that works on both Windows and Linux platforms. Data stored on an encrypted volume cannot be read (decrypted) without using the correct password/keyfile(s) or corr…

Security

Mozilla Firefox disables Microsoft .NET and WPF addons

This morning, I was prompted by Firefox that it had disabled the .NET Framework Assistant and the Windows Presentation Foundation addons. The popup concluded with the message that these addons have been known to cause st…

Security

How to Protect your Identity from Identity Theft

This guide will help you take action to protect yourself against identity theft. If you have already been victimized, this guide will provide information about restoring your credit profile and minimize the potential for any future occurrences of identity theft.

Application Security

How to Get a Google Wave Account

Click here on how you can get access to get a beta or sandbox account for Google Wave. Google Wave is a new tool for communication and collaboration on the web, coming later this year.

Security

Privacy Settings for Facebook

Facebook is currently the most popular social networking website with over 250 million active users worldwide. Anyone who is 13 and over can sign up for a Facebook account and can add friends and share their most intimate information with their friends including pictures and personal information. While it can be fun and convenient to keep up with old friends and make new ones online, sharing too much personal information on these sites can be risky.

TechNews

Why is Windows so expensive?

If you type in the query of Why is Windows so expensive? or Why is Microsoft Windows so expensive? on Microsoft's search engine bing.com returns the top result as "Why are Macs so expensive". This is rather disappointing…

TechNews

Dan Kaminsky gets hacked

Noted security professional Dan Kaminsky's personal website was hacked into and personal information was stolen from his webserver and posted online on the eve of the Black Hat security conference. The stolen files inclu…

WordPress

Solution to Error 500 after upgrading to WordPress 2.7

After I recently upgraded my blog to the latest version of Wordpress v2.7, I noticed an Error 500 - Internal server error. This seems to be a problem for WordPress blogs which are hosted by 1&1 The solution to the Er…

Security

Solving FBI's 2008 Code Cracking Challenge

The Federal Bureau of Investigation (FBI) has issued a code cracking challenge today. This was in response to a similar challenge the FBI issued last year, which proved to be hugely popular with many thousands responding…

Security

Strong Password Suggestions using a Password Chart

I think I came across one of the best strong password generators on the Internet at Password Chart. Picking a strong password is very important. A strong and secure password should go beyond just a simple number such as…

Security

Generate Secure Passwords using the Enigma Code Machine

The Enigma was a rotor machine used by the German Military during WW II to encrypt messages they sent to each other. It was invented by German Engineer Arthur Scherbius in 1923. The Enigma Code Machine consisted of a plu…

Security

How to Break Web Software

Mike Andrews was one of the coolest and most knowledgeable professors I had the opportunity of learning from, while at school @ Florida Tech. Currently, Mike is currently working as the Principle consultant at Foundstone…

Field note

The Great Zero Challenge

The Great Zero Challenge: A challenge to confirm whether or not a professional data recovery firm or any individual(s) or organization(s) can recover data from a hard drive that has been overwritten with zeros once. All…

Pen Testing

How to crash Google Chrome

Google claims that its browser Google Chrome is able to isolate events that may crash a browser, isolated within those individual tabs. However, an issue exists with how Google Chrome handles undefined handlers in chrome…

TechNews

Internet Browsers and their users

Comparison of the different Internet Browsers and their users. Click here for a bigger picture : http://www.flickr.com/photos/21904710@N00/2754981251/sizes/o/ In case you are wondering what Internet browser I use ... bel…

Security

What is Defense in Depth

Defense-in-depth is fundamental to the design of a secure system. It stems from the idea that software can have flaws; people can make configuration mistakes; and hardware devices can fail. To compensate for events like…

Security

Computer Security Tips and Best Practices

Protecting yourself is very challenging in the hostile environment of the internet. Imagine a global environment where an unscrupulous person from the other side of the planet can probe your computer for weaknesses, and…

Security

Preventing Security Threats from USB Storage Devices

Working in Computer Security, one of the biggest threats we face today is the threat of an Insider, an Employee who might casually walk in with his 4 GB USB Flash drive, plug it in to their computer within the corporate…

Security

Most Influential People in Security

Ryan Naraine over at eweek.com has come up with an interesting list of the top 15 most influential people in Computer Security. 1. Tavis Ormandy, Google Security Team’ 2. Ivan Krstic, One Laptop Per Child’ 3. Chris Paget…

TechNews

Microsoft Windows 7 Feature Request List

Microsoft seems like it is on track to release the next generation or the next version of Windows, Windows 7 to be tentatively released in 2009. An indicator of what users wish to see in this next version of Windows has…

Field note

Bastille Linux

Besides manual security hardening of a Linux OS, let’s check out a free open-source tool to automate and simplify the process. Bastille will disable unnecessary services and install operating system updates as well as co…

Security

The History of Hacking

Discovery Channel played a very interesting documentary titled "The History of Hacking". This goes into the whole history of hacking starting with phone phreaking and Blue boxes and to the present state of hacking. Howev…

Pen Testing

Yahoo! CAPTCHA Cracked

A CAPTCHA is a type of challenge-response test used in computing to determine whether the user is human. The process involves one computer (a server) asking a user to complete a simple test which the computer is able to…

Security

How to Remove Duplicates from a List

Sometimes when running through a CSV or any kind of a log file, you may encounter lists with a lot of duplicates. I will show an example of the simplest order here. Say, you have a duplicates.txt that goes one two three…

Security

Unix Shell for Windows

A lot of us who use Linux at work/school or have always grown up using Unix commands and using the Unix shell for years and more often than not, there are instances where a ls command comes more naturally than the dir co…

Pen Testing

Network Security Risk Assessment

In this article, I will introduce you to some well known tools which security analysts use for Network Security Risk assessment, to know more about the layout of the network they are trying to test and also gather intell…

Security

Important Computer Security Terms and Terminology

This article lists some Computer Security Terms and Computer Security Terminology. For anyone reading any of the computer security terms below for the first time, I highly recommend that you Google these keywords and lea…

WordPress

WordPress Security Tips to protect your WordPress Blog

While WordPress in general is pretty secure grounds up, it is still vulnerable to the many kinds of security exploits out there. WordPress Security Tip # 1: Upgrade your WordPress Blog Keeping your WordPress blog up to d…

Security

Security of Open Source Software

Is Open Source Software Really more Secure? The constant stream of Windows vulnerability attacks result not solely due to security holes in the Operating System, but also because of the ubiquity of Windows as both a clie…

Security

How to Create a Strong Password

The notion of passwords is not flawed, but rather it is the type of passwords that are commonly used that lead to password or security breaches. You need to have a complex and a strong password which needs to be changed…

Pen Testing

TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS

The TIBCO Rendezvous RVD daemon is vulnerable to a memory leak, which when remotely triggered, prevents any further RV communication until the daemon is manually restarted. Vulnerability Type / Importance: Remote DoS / H…

Security

IT Security Interviews Exposed

IT Security or Information Security has steadily grown from being an obscured field of work in some government or military or financial institutions to become a mainstream activity practiced by many professionals includi…

Security

How to remove Tracking Cookies

Tracking Cookies while generally of a low threat level to your PC, they are still classified as Spyware. This article describes what a tracking cookie is, how to identify tracking cookies and finally how to remove tracki…

Security

External Content Threats Security and Web Beacons

For IT Security folks, especially those in a large corporation, dealing with Threats Security or External Content Threats Security has a potential to take away a significant operations time. So what is External Content T…

Security

Remove Powered by Zedo & URL.cpvfeed.com Popups

Spyware such as Zedo, powered by Zedo and URL.cpvfeed.com redirects your browser or opens popups displaying advertising. Step by step security article on How to remove the Zedo, powered by zedo, URL.cpvfeed.com popups and also remove the core.sys rootkit.

Security

Why Biometric Security CANNOT secure a Corporate Environment

Biometric Security is being billed as the next savior of personal and corporate security, a superior solution to our Identity and Access management problems. However, the fact is that if someone steals your Biometric ID, it remains stolen for life.

Pen Testing

Introduction to Ethical Hacking and Penetration Testing

An Introduction to Ethical hacking through the eyes of a pen tester and hopefully helps anyone reading this blog on how to protect and secure a network by understanding how a Hacker operates and understanding their tools…

Field note

Google Gmail Keyboard Shortcuts

A Keyboard Shortcut according to Wikipedia states that a keyboard shortcut (or accelerator key, shortcut key, hot key, key binding, keybinding, key combo, etc.) is a key or set of keys that performs a predefined function…

TechNews

Google Accounts has retard as a CAPTCHA

A CAPTCHA (an initialism for "Completely Automated Public Turing test to tell Computers and Humans Apart", is a type of challenge-response test used in computing to determine whether or not the user is human. A common ty…

Application Security

How to edit any Webpage on the fly using JavaScript

OurPicks have an interesting piece of code snippet on their forums. A simple JavaScript code that lets you edit any webpage, static or dynamic on the fly Let us try this: Step # 1: Go to any website. Let us go to Slashdo…

TechNews

Slot Machine suffers from the Blue Screen of Death

The supposedly indestructuctible slot machines, turns out are prone to failure like any other machine. The inquirer reports this Blue Screen of Death on a slot machine at the International Casino Exhibition in Earl's cou…

Security

Analysis of Spam Thru botnet

Mark Sunner, Chief Security Analyst at MessageLabs was among the many security analysts watching one Trojan called "Spam Thru", a piece of malware designed to send spam from an infected computer, at the turn of last year…

Security

Nigerian Scammer moves to London, England

The most visible form of fee fraud today is the Nigerian Letter or 419 fraud. A typical letter claims to come from a person needing to transfer large sums of money out of the country or from a lottery company. As the Nig…

Security

Spammers now using TinyURL to flood comments

Spamming is the abuse of electronic messaging systems to send unsolicited bulk messages. While the most widely recognized form of spam is email spam, spam in blogs is becomming huge these days along with search engine sp…

Security

How to detect a Rootkit on your machine

A root kit is a collection of programs that intruders often install after they have compromised the root account of a system. These programs will help the intruders clean up their tracks, as well as provide access back i…

TechNews

Top 20 List of the Best Geek Quotes, Sayings and Phrases

For all the geeks out there, do you know someone who tried to teach themselves how to read Barcode? Here is a list of Geek quotes, sayings and phrases. Some of them are from Boardofwisdom who put together a nice compilat…

Pen Testing

Demonstration of Windows XP Privilege Escalation Exploit

This article is not a hacking tutorial. This is only to be used for educational purposes and should not be exploited. Using simple command line tools on a machine running Windows XP, we will obtain system level priviledg…

TechNews

Excellent JS based English to LEET translator

Leet is a phrase often used on the Internet, some being online games, message boards, and chat rooms. It comes from the word "elite", meaning "above everyone else". It's most commonly written as "1337" or "l33t". It can…

Security

Using DOMJAX for Domain Name Search

CNN writes that more than 70 million web domain names have been purchased, and most - if not all - dictionary-word domain names (i.e. house.com, furniture.com) have already been taken. That should not disappoint you sinc…

TechNews

Spotted: Geekiest License Plates

Seeing all these guys, I am more than motivated to get a customized plate myself. I am thinkin 31337 or r00t or something on those lines. Meanwhile check out these uber geeks and their licence plates. Sources for the pic…

TechNews

Developers are from Mars, Programmers are from Venus

Many of us use the terms programmer and developer interchangebly. Hacknot has an excellent article describing the concept the the terms programmer and developer are indeed as unique as how they are made out to be. The te…

Security

How to prevent your email from being spammed

All of us have experienced the tremendous pains of spam. Who can remember the glory days of Hotmail 2MB storage where 85% of the inbox was filled with spam. While this plague is going to exist for some more time, here ar…