


2022.1月企業電子報第124期- 【GREYCORTEX MENDEL】網路偵測與回應(NDR)解決方案,協助企業防範「資安事件」於未然


有優秀的黑客嗎?

Hello and welcome back to our “Mystery Jet Ski.” Much better than those programs about supernatural stuff and alien suppositions. Today we will continue with our exhaustive investigation on the hacker world, and we will delve a little more into the concept of “ethical hacker.” Is it true that there are good hackers? Who are the so-called “White hats”? Who will win this year’s Super Bowl?
Do you already know who the so-called “White Hats” are?
In this blog we never stop saying it: “No one is free from EVIL, because EVIL never rests”, and if in previous articles we saw that a bad hacker, broadly speaking, is a person who knows a lot about computers and uses their knowledge to detect security flaws in company or organization systems and take control of them, today we will see who is the archenemy of the bad hacker or cracker, the superhero of security, networks and programming… “The White Hat Hacker.”
White Hats are “evangelized” hackers who believe in good practice and good ethics, and who use their hacking superpowers to find security vulnerabilities and help correct or shield them, whether in networks, software, or hardware. “Black Hats” would be the rogue hackers we all know for their evilness, and the “White Hats” would be their honest and do-gooder counterpart. Both hack systems, but White Hat hackers do it with the goal of favoring/helping the organization they are working for.
White Hats, ethical hackers
If you thought that piracy and honesty were antonyms, you should know that, within IT, they are not necessarily so. As we pointed out, White Hats do their thing but in an ethical and supervised way, all with the aim of improving cybersecurity, not damaging it. And, dear friend, there is lots of demand for this. White Hats are not short of work, they are in high demand as security researchers and freelancers. They are the candy of organizations to strengthen their cybersecurity. Companies, in fact, take white hat hackers and make them try to hack their systems over and over again. They find and expose vulnerabilities so that the company is prepared for future attacks. They show the ease with which a Black Hat could infiltrate, and even get to the kitchen, in a system, or look for “back doors” within the encryption determined to safeguard the network. We could almost consider the White Hats as another IT security engineer or an insightful network security analyst within the company.
Some known white hat hackers:
- Greg Hoglund, “The Machine.” Mostly known for his achievements in detecting malware, rootkits, and hacking online games. He has worked for the United States government and its intelligence service.
- Jeff Moss, “Obama’s Right Hand (on the Mouse)”. He came to work on the US National Security Advisory Council during the Obama term. Today he serves as a commissioner in the World Commission on the Stability of Cyberspace.
- Dan Kaminsky, “The Competent.” Known for his great feat of finding a major bug in the DNS protocol. This could have led to a complex cache spoofing attack.
- Charlie Miller, “The Messi of hackers.” He became famous for highlighting vulnerabilities in the products of famous companies like Apple. He won the Pwn2Own edition in 2008, the most important hacking contest in the world.
- Richard M. Stallman, “The Hacktivist.” Founder of the GNU project, an essential free software initiative to understand computing without restrictions. Champion of the free software movement since 1980.
Are there more “Hats”?
We have already talked about the exploits of these White Hats, but what about the previously mentioned “Black Hats”? Are there more “Hats”? Let’s have a look:
- Black hats: Well, these are the bad guys, the computer criminals, the ones we know and take for granted. The villains of this story. They start out, perhaps, as inexperienced Script Kiddies and end up as crackers. Pure jargon to designate how bad they are. Some do it alone, selling malicious tools, others work for criminal organizations as sophisticated as the ones in movies.
- Gray hats: Right in the middle of computer morality, we find these hats, combining the qualities of black and white. They are usually devoted, for example, to looking for vulnerabilities without the consent of the owners of the system, but when they find them they let them know.
- Blue hats: These are characterized by focusing all their malicious efforts on a specific subject or group. Motivated perhaps by revenge, they dominate it just enough to execute it. They may also be hired to test specific software for bugs before it is released. They say that their name comes from the blue emblem of the Microsoft employees.
- Red Hats: The Red Hats do not like the Black Hats at all and act ruthlessly against them. Their life goal? Destroy all evil plans that bad hackers have in their hands. A good Red Hat will always be aware of the initiatives of the Black Hat, their mission is to intercept it and hack the pirate.
- Green hats: These are the “newbies” of the hacking world. They want to go further, for their hat to mature into an authentic and genuine Black Hat. They will put effort, curiosity and boldness in said company. They are often seen grazing in packs within hidden hacker communities asking their elders for everything.
Conclusions
Sorry for the Manichaeism, but we have the White Hat that is good, the Black Hat that is bad, and a few other colorful types of hats that fall between these two poles. I know that now you will imagine hackers classified by colors like Pokemon or Power Rangers. If only achieved that with this article, everything was worth it.
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.


您知道有幾種 USB 類型嗎? 你都認識他們嗎?

USB types: the final list to know them all
“Pen drive”, “memory stick”, for those less attentive: “VHS”… We have given many names to what we actually meant by USB. But you have to know that the term goes a little beyond that gadget of four or eight gigabytes that we use for so many things. In fact, there are several USB types, and today we will delve into getting to know them.
USB Types: What is a USB?
First we should make clear that, as many suspected but few dared to inquire, the acronym USB is derived from the corresponding words: Universal Serial Bus. USB is a connection protocol that allows us to connect several peripheral devices to an electronic device to achieve an exchange of data. It can also be useful to carry out some operations or charge the battery of our devices. It is, then, like a port that works as a connection socket between different devices.
The range of devices that we can interconnect to a computer thanks to USB is quite wide. We just have to think a bit so that they all come to our heads immediately. Mouses, keyboards, video and photo cameras, smartphones, USB memories, music players, webcams, speakers, printers, recorders, external hard drives, PDA… There are countless examples.
We owe this protocol to the fruitful 1990s, a wonderful decade for Britpop and for technology. It was seven large technology corporations (Intel, IBM, Northern Telecom, Compaq, Microsoft, NEC and Digital Equipment Corporation) who joined hands to reach an agreement on the peripheral connection standard for a computer. The idea was good for everyone, and although they started with a first model, USB 1.0, different from the current ones, everything was just a matter of evolution.
USB Types: Standards
USB devices are classified into four types based on their data transfer speed: Low Speed (1.0), Full Speed (1.1), High Speed (2.0) and Super High Speed (3.0).
- USB 1.0. It was the one that appeared in the mid-nineties. The maximum speed at which information could be transferred was 1.5 Mbps. Well, it could be used for connecting devices like the mouse and keyboard for example.
- USB 1.1. The transfer rate increased to 12 Mbps.
- USB 2.0. It is undoubtedly the most widespread standard and sends data at a speed of 480 Mbps, although its actual rate is 280 Mbps. In the cable you may find four lines: two for data transfer and two for power.
- USB 3.0. We can consider it about ten times faster than 2.0. It reaches speeds of 4.8 Gbps. The best thing is that it is still compatible with the previous ones and on top of that, it includes five additional contacts. At present, it coexists with 2.0. in perfect harmony.
- USB 3.1 It is the last of the standards. In fact it emerged just a few years ago. It reaches a data transfer speed of 10 Gbps. As an incentive, it comes with a new type of connector, connector C.
USB Types: Types of connectors
Now we go to the shapes of USB, which is why we are more familiar with them.
Type A. It is the one that most users will recognize. That flattened rectangle in which we can see internal connections. The male connector is at the end of the cables, while the female is the port itself.
Type B. The ports and connectors belonging to this type are just as recognizable by users, but somewhat smaller and wider than those of type A. As a general rule, we can find them in devices such as printers.
Type C. The Type-C connector has appeared the same as USB 3.1 and the distinguishing feature is that it is reversible. That’s right, no matter which side you insert, it works both ways.
MiniUSB. You may find two different versions of this one, made by 5 or 8 pins. We can see them in cameras, external hard drives, music players and a few other trinkets.
MicroUSB. The microUSB is the smallest and thinnest of all. It is quite flat and was conceived to connect to our smartphones. With them we can transfer information and charge batteries, so we also know it very well.
USB Types: Mistaking them with USB Memory
As we have seen, the concept of USB refers to the connection port. However, the term “USB” has also been extended to refer to pen drives. Pen drives are enabled with a memory that works as a place for storing and transporting data. It’s the rightful replacement for floppy disks and CDs (who doesn’t have one, for God’s sake?!), with different capacities ranging from 1GB to 1TB. Simply because the pen drive connects through USB, they have ended up calling it that. To shorten it. We are that practical and love saving that much.
Once you just got into the technological ins and outs, are you hungry for more? Would you like to go even further in the world of technology? What about spending a couple of minutes to find out what computing system monitoring is and why it is also very important?
Monitoring systems are responsible for supervising technology (hardware, networks and communications, operating systems or applications, for example) in order to analyze its performance, and to detect and alert about possible errors. And this leads us to Pandora FMS, that wonderful tool thanks to which this blog is possible.
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.


什麼是真正的黑客?

What is a hacker? More like Mr. Robot rather than Operation Swordfish
If we lived in a fair and more appealing world, children would not want to be Cristiano Ronaldo or PewDiePie (popular Swedish youtuber that if you have a certain age, or dignity, you won’t know about). Children would like to be someone with values, like Immanuel Kant, She-Ra or, of course, a high-level hacker who, from the sewers of a suburban pavilion, controls the world with his killer laptop and his hoodie.
We get the idea of Immanuel or She-Ra, but why do we keep that idea in our head that hackers are so cool? What is a hacker seen through the eyes of someone who knows what this world is all about? It is not that we have brought to the fore a real hacker to solve it -authorities stay calm-, but we have brought Kevin Rojas, a project consultant at Pandora FMS and a renowned technologist and nerd of these things.
What is actually a hacker?
A hacker is a person who knows a lot about computing (security, networks, programming) and uses his knowledge to detect security flaws in the computer systems of companies or organizations.
What exactly do they do?
There are different types of hackers depending on what they do and how they do it, although it could be simplified into “good hackers” and “bad hackers”. The “good guys” (ethical hackers or “white hats”) are usually hired by companies to help them improve the system security by plugging holes and fixing bugs, and the “bad guys” (“black hats”) take advantage of those holes and mistakes for personal profit. Then there are all sorts of intermediate points, such as “gray hats”, who look for faults in business systems… to attempt to be hired to help them solve them.
Why do you think they are so romanticized by movies?
I guess because of the growing importance of computing and how “appealing” it sounds to be able to break into any kind of security. In the end, a hacker is someone who gets away with anything by being “more resourceful.” Who doesn’t like big hit movies?
In addition, a hacker does not obey to any physical pattern: it does not matter whether a person is tall or short, fat or skinny, it does not matter if that person is extroverted or what his economic level is. Anyone with enough wit (and knowledge) could be a hacker… and it’s no small feat.
What things do they usually do?
A real hacker could spend a lot of time studying (really, a lot). They have to know how things work, how elements interact, what known errors different technologies have, what the most effective security policies are and what the most common errors that users make are (which, by the way, are usually the chain’s weakest link: Have you seen those people who write down the password of their user in a post-it stuck to the screen?).
What they also usually do is a lot of programming. They create malware that takes advantage of system vulnerabilities, or that captures the keystrokes and mouse keys of careless users who install programs from suspicious web pages.
They do a lot of things, but there’s one I guarantee they don’t usually do: program “detailed 3D graphical interfaces with countdowns that light up the screen red while a submarine alarm beeps when the system recognizes a security breach and activates the countermeasures”. They don’t do that, even though you may have seen it in movies like Skyfall.
What do you think are the biggest differences between a real hacker and a cliché movie hacker?
Movie hackers often hacking into systems “just like that”. “Give me any computer with Internet access and in 10 minutes I’ll be connected to the Ministry of Defense network.” Well no, it is way more complex than that and it takes much more work behind. It’s more like Mr. Robot rather than Operation Swordfish. Not that much glamour and a lot of black screen with Linux terminals.
Could you name a real hacker who has gone down in computer history for his misdeeds? What did he do?
We do not have to go that far: Swedish Julian Assange, for example, went down in history in 2010 (and on the lists of most wanted people in the United States) for leaking documents from the American intelligence service regarding several incidents that took place in the war against Afghanistan.
Also the group Anonymous is currently quite a hot topic, which is not a single person but a large group of hackers, who have been leaking information since 2003 and from which the aforementioned series, Mr. Robot was inspired.
But not all famous hackers are bad guys: there are also famous ethical hackers like Chema Alonso, Telefónica’s current CDCO, one of the heads involved in managing of the 2017 Wannacry crisis, which, in case you don’t remember, was caused by a program that encrypted the code and data of infected computers, and asked for money to recover them. We need hackers to deal with hackers…
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.


Zendesk 插件:Pandora FMS 的新集成

It is always a luxury to show off a new plugin in Pandora FMS, and for that reason we decided to devote an article in style to this Zendesk plugin on our blog. We will discuss what it is and how it can help us. Step by step, and concisely, so that no one gets lost along the way.
New Zendesk plugin added to Pandora FMS
But first: What is Zendesk?
Zendesk is a platform that channels the different communication modes between customer and company through a ticketing system.
A consolidated CRM company, devoted specifically to customer service, which designs software to improve relationships with users. Known for growing and innovating while building bonds and putting down roots in the communities where it lives. Its software, such as Pandora FMS, is very advanced and flexible, being able to adapt to the needs of any growing business.
Zendesk plugin
The plugin we are talking about today allows you to create, update and delete Zendesk tickets from the terminal, or from Pandora FMS console. For that, it makes use of the API of the service, which allows this system to be integrated into other platforms. Using a series of parameters, which would be the configurable options of the ticket, you may customize them as if you were working from Zendesk itself.
Zendesk Ticket System
Zendesk has an integrated ticketing system, with which you may track support tickets, prioritize them and resolve them.
To the point: System configuration to use the plugin.
To make use of the plugin, enable access to the API, either using password or token.
Do it from the API section in the administrator menu.
Plugin parameters
The plugin makes use of a number of parameters when creating, updating or deleting tickets. With them you may configure the ticket according to your own criteria and needs. Just as you would do it from Zendesk’s own system.
Method
-m
With this option you will choose whether to create, update or delete the ticket. Use post to create it, put to update it, and delete to delete it.
IP or hostname
-i
With this alternative you may add the ip or name of your site. Sites usually have this format:
“https://<nombre>.zendesk.com
For example, mine is https://pandoraplugin.zendesk.com/. So, in this case, it should be pandoraplugin.
* If the full url is placed, it will not work.
User
-us
Your username. Usually the email with which you signed up in Zendesk. Use this option, combined with password or token, depending on how you have it enabled.
Password
-p
The password to authenticate with the API.
Token
-t
The token to authenticate to the API. If you use this option, you do not have to use the password option.
Ticket name
-tn
The name to be given to the ticket.
Ticket content
-tb
Ticket text. It should be enclosed in quotation marks.
Ticket ID
-id
Ticket ID. This option is for when you want to update or delete a ticket.
Ticket status
-ts
The status of the ticket, which can be new, open, hold, pending, solved or closed.
Priority
-tp
The priority of the ticket, which can be urgent, high, normal or low.
Type
-tt
The ticket type, which can be problem, incident, question or task.
Ticket creation
By running the plugin with the appropriate parameters you may create tickets:
python3 pandora_zendesk.py -m post -i <ip or site name> -us <user> -t <token> -tn <ticket name> -tb <ticket content> -tp <priority> -tt <type> -ts <ticket status>
Example
With the following command:
python3 pandora_zendesk.py -m post -i pandoraplugin -us alejandro.sanchez@pandorafms.com -t <token> -tn "Problem with X" -tb "Something is giving some problem" -tp urgent -tt task -ts new
Interact with the API and the ticket will be created in your system.

Ticket update
You may update the tickets. The parameters are the same as in creation, but you have to add also the id, which will be the id of the ticket to be updated.
python3 pandora_zendesk.py -m put -i <ip or site name> -us <user> -t <token> -id <id ticket> -tn <ticket name> -tb <ticket content> -tp <priority> -tt <type> -ts <ticket status>
Example:
Let’s update the ticket we created in the example above, which has id #24
With the following command:
We see that the ticket has been updated and moved to pending tickets.

Ticket deletion
You may also delete a ticket by searching it by its ID with the following command:
python3 pandora_zendesk.py -m delete -i <ip o host> -us <user> -t <token> -id <id ticket>
Use of the plugin from Pandora FMS console
You will be able to execute the plugin from the console, by means of an alert, which will make the use of the plugin easier.
To that end, go to the menu Commands in alerts:
Inside, create a new command that you will use to create alerts. To achieve this, run the plugin by entering its path and use a macro for each of the parameters used to create a ticket.
Add the description to each of these macros:
Once the command is saved, create an action to which assign this created command:
In each field below (the one of each macro where you have added a description when creating the command), add the value that you would have added to the parameter.
Once you have filled in all the fields of the necessary parameters, click Create.
Once done, go to List of alerts (don’t worry, once configured, you won’t have to repeat the process for each ticket you want to create), and create one.
Designate an agent and a module (it does not matter which one), and assign the action you just created. In the template, set the manual alert.
Once completed, click Add alert.
Now, to run the plugin, go to the view of the agent that you assigned to the alert and you will see it there. You may execute it by clicking the icon Force.

To establish different tickets, go to the action you created and change the values of the fields.
Just as we generated an alert for ticket creation, you may make another to update them and another to delete them to allow the use of the optimized plugin.
More integrations in ticketing services
Apart from Zendesk, there are more ticketing services that can be used from Pandora FMS by using a plugin. These are Redmine and Zammad, which have new plugins with which to create, update and delete tickets in these systems. And Jira and OTRS, which also have a plugin in the library that allows you to use these services easily from Pandora FMS.
Resources cursos:
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.


雲原生和“人造”雲安全產品之間的 10 個差異
For IT and security teams with limited staff and tight budgets, cloud-native software-as-a-service (SaaS) security products offer tremendous value. Some CIOs have even mandated that new security tools be delivered in the cloud where possible. Some vendors with older on-premises products have tried to sneak in their products by claiming they are now “in the cloud,” but the truth is that that is a façade.
Let’s call these products “faux” cloud security to contrast against products that are truly “cloud native.” Vendors of faux cloud products hope that with a little marketing smoke and mirrors, they can use some “cloudy” language and potential buyers will not know the difference. When we say faux cloud, technically speaking, we mean that the vendor is just allowing the customer to host their on-premises product in the customer’s public cloud account. This means the customer still must install, configure, deploy, maintain, update, and eventually decommission that product.
In other words, you as the customer must do all the work. The only “cloud” aspect of this arrangement is that you can do all the work on a server you are renting (that is, paying for) from AWS, Azure, Oracle, Dell, etc.
Faux Cloud Security in the Real–World
A real-world example of this software sleight-of-hand is Cisco’s Internet Security Engine (ISE). Cisco delivers ISE as a virtual appliance to handle network access control (NAC) – a critical component of any effective cyber security stack. As of ISE’s latest version, a customer can deploy the software in their own AWS or Azure accounts.
That is the long and short of it, however. The well-known challenges of setting up ISE – or any other network security appliance – remain. It is difficult to get your ISE server configured properly, ensuring it communicates with all your network equipment, even after having committed over 1,200 pages of ISE documentation to memory.
Cloud Native Reduces the Hassles
In contrast, a truly cloud-native solution allows the customer to sign up through a web page, configure as needed, and move on – the application just works out-of-the-box. Period. Now, that’s the easy part. As your organization consumes a cloud service, it does not have to concern itself with nagging issues and questions along the way common with on-premises software (e.g., How do we roll out patches and upgrades? Is there a security vulnerability in the operating system? Who is handling system backup?). You, as the end-user, have historically been responsible for these items with legacy on-premises software.
Portnox CLEAR NAC-as-a-service is cloud-native – “born in the cloud” as it were. To deploy CLEAR, a customer just needs to visit the sign-up page, enter their wireless controller information, configure the RADIUS settings on the network device, and CLEAR will begin enforcing policies. Portnox customers have done this in as fast as 30 minutes from start to finish. As is true of cloud-native solutions in other domains, customers can see value in minutes, not days, weeks, or even months. No complexity. No hassle.
Knowing the Difference Before You Commit
As a potential customer, how can you distinguish cloud-native from faux cloud security software?
There are a few telltale signs. The table below summarizes some of the most salient differences. When you evaluate a new vendor, be sure to ask questions such as who is paying for the infrastructure? Who is responsible for updates and upgrades?
| Cloud Native | Faux Cloud | |
| Infrastructure | Provided, paid, and managed by the vendor; mostly invisible to anyone utilizing the service | Provided, paid, and managed by you through your own AWS or Azure account |
| Implementation | Quick time to value; much of the work is invisible to you | Depends on the complexity of the app, but it is your responsibility to do the work or pay someone else to do it |
| Pricing | Subscription with lower up-front cost | Perpetual license with expensive up-front cost that are amortized over time.
(Note: many vendors are moving away from perpetual licensing for on-prem or faux cloud products, but as they do, their customers are getting the worst of both worlds – paying more annually while still being responsible for on-going maintenance of the product) |
| Total Cost of Ownership | The price of the product reflects the genuine cost of ownership | The price of the product is only one (and sometimes only a small) part of the total cost that is reflected in the staff time and public cloud expenses; in many instances, you may not even know what it is going to cost you until it is too late |
| Vendor Lock-In | Easy to switch to another vendor should your business needs change | Expensive license, deployment and maintenance costs make switching prohibitive, often for years |
| Access | Access anywhere via browser with internet connection | On-premises model often requires access via VPN
(Note: what happens when there is a problem with your solution and your VPN is configured to use your on-premises system? Sounds like someone is driving into the office!) |
| Scalability | Automatically scales with usage | Customer must increase capacity to keep up with usage |
| Updates | Vendor regularly updates the underlying components such as servers, databases, etc. This process will often be invisible to you. | You are responsible for ensuring that the entire tech stack – components, databases, servers, network – is updated with the latest patches |
| Upgrades | You seamlessly and transparently reap the benefit of new features, enhancements, and other improvements with zero effort | Any upgrade requires you to install, test, and then deploy the upgrade in production, often during nights and weekends in case something goes wrong |
| Accountability | The vendor takes ownership of the uptime and security, performance, and availability of the service | Apart from the infrastructure as a service, you are on the hook for the performance, health, security, and availability of the solution, lock stock and barrel |
Cloud Native
Infrastructure
Provided, paid, and managed by the vendor; mostly invisible to anyone utilizing the service
Implementation
Quick time to value; much of the work is invisible to you
Pricing
Subscription with lower up-front cost
Total Cost of Ownership
The price of the product reflects the genuine cost of ownership
Vendor Lock-In
Easy to switch to another vendor should your business needs change
Access
Access anywhere via browser with internet connection
Scalability
Automatically scales with usage
Updates
Vendor regularly updates the underlying components such as servers, databases, etc. This process will often be invisible to you.
Upgrades
You seamlessly and transparently reap the benefit of new features, enhancements, and other improvements with zero effort
Accountability
The vendor takes ownership of the uptime and security, performance, and availability of the service
Faux Cloud
Infrastructure
Provided, paid, and managed by you through your own AWS or Azure account
Implementation
Depends on the complexity of the app, but it is your responsibility to do the work or pay someone else to do it
Pricing
Perpetual license with expensive up-front cost that are amortized over time.
(Note: many vendors are moving away from perpetual licensing for on-prem or faux cloud products, but as they do, their customers are getting the worst of both worlds – paying more annually while still being responsible for on-going maintenance of the product)
Total Cost of Ownership
The price of the product is only one (and sometimes only a small) part of the total cost that is reflected in the staff time and public cloud expenses; in many instances, you may not even know what it is going to cost you until it is too late
Vendor Lock-In
Expensive license, deployment and maintenance costs make switching prohibitive, often for years
Access
On-premises model often requires access via VPN
(Note: what happens when there is a problem with your solution and your VPN is configured to use your on-premises system? Sounds like someone is driving into the office!)
Scalability
Customer must increase capacity to keep up with usage
Updates
You are responsible for ensuring that the entire tech stack – components, databases, servers, network – is updated with the latest patches
Upgrades
Any upgrade requires you to install, test, and then deploy the upgrade in production, often during nights and weekends in case something goes wrong
Accountability
Apart from the infrastructure as a service, you are on the hook for the performance, health, security, and availability of the solution, lock stock and barrel
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。


2022年擺脫十大網路安全壞習慣

1.沒有定期更新
電腦及設備上的操作系統、瀏覽器和其他軟體中的漏洞是網路犯罪可以進行攻擊的主要方式之一,在2020年發現了超過 18,100 個,而這相當於每天有50多個新的軟體漏洞,而您只要一個動作打開自動更新功能並在出現提示時點擊更新,就可以如常您的生活及工作。
2.不安全的密碼
對多個帳戶使用相同的密碼和易於猜測的憑證,為駭客提供了極大的便利,他們擁有破解弱加密的軟體,利用殭屍網路(botnet)以自動化方式不斷使用偷來的登入憑證試圖登入網路服務,稱為憑據填充(Credential Stuffing)。您可以使用密碼管理器來記住具強度的密碼並在提供它的任何帳戶上使用雙因素身份驗證 (2FA)。
3.使用公共 Wi-Fi
駭客可以利用相同的網路了解您的互聯網使用情況、登錄您的帳戶並竊取您的身份。為了安全起見,請盡量避開這些公共熱點,若您使用時,也避免在連接時登錄任何重要帳戶。
4.隨意點擊來路不明之連結
網路釣魚是目前最大的網路威脅之一,阻止這些攻擊的首要規則是在點擊之前三思而後行,與發送電子郵件的個人或公司仔細核對以確保其合法,不要被迫採取過於倉促的行為。
5.未在所有設備上使用資安產品
在網路威脅多變的時代,應該確認所有的電腦設備都有安裝專業且具知名度的資安產品,另外也請確認您的行動式裝置(如平板…)是否也有這麼做?
6.點擊不安全的網站
http:// 是網頁伺服器與您的電腦瀏覽器,以一般(非安全)模式在進行互動交談,所以內容有可能遭攔截竊聽;換句話說,在此類網頁上填寫傳送的資料有可能被有心人士看到。而https:// 多了一個字母S的差別代表”安全(secure)”,基本上意謂著,您的電腦與伺服器間的資料傳遞是以加密的方式進行進行互動交談。
7.工作的電子郵件被用於個人的日常
試想使用工作的電子郵件和密碼在消費性購物網站和其他網站上註冊,如果這些網站遭到破壞怎麼辦?駭客就有可能能夠劫持您的公司帳戶,另外使用未受保護的個人電腦設備進行工作其實也會增加額外的風險。
8.通過電話提供詳細訊息
語音網路釣魚(也稱為 vishing)是一種越來越流行的從受害者那裡獲取個人和財務資訊的方式,詐騙者經常偽裝他們的真實號碼以增加攻擊的合法性,所以請盡量避免透過電話發送任何敏感或重要訊息。
9.沒有定期備份
勒索軟體每年給企業造成數億美元的損失,試想如果突然無法開啟您的電腦,裡頭所有的資料,都可能永遠丟失,其中包括家庭照片和重要的工作文件等等;根據 3-2-1 最佳備份原則,定期備份可在最壞的情況發生時,讓您高枕無憂。
10.智能設備沒有被保護
近三分之一的歐洲家庭配備了智能設備,如語音助理、智能電視和監視器;但它們也同時連結網路,也因此成為犯罪分子的目標,進而被劫持並變成殭屍網路,對其他人發起攻擊,或者變成通往您其他設備和資料的管道。
*****ESET資安產品具備勒索病毒 / 惡意軟體 / 垃圾郵件 / 網路釣魚之防護功能,守護您的網路安全,立即購買:https://www.eset.tw/estore/zh/
原文出處:https://www.welivesecurity.com/2022/01/03/breaking-habit-top-10-bad-cybersecurity-habits-shed-2022/
關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。
台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。
關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟體提供商,其 獲獎產品——NOD32防病毒軟體系統,能夠針對各種已知或未知病毒、間諜軟體 (spyware)、rootkits和其他惡意軟體為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲 得了更多的Virus Bulletin 100%獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳 能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事 處,代理機構覆蓋全球超過100個國家。


使用 SCADAfence 回顧 2021 年的 OT 安全
As 2021 draws to a close, it is time for our customary round-up of the year’s industry-changing cyber attacks, product and company updates, and SCADAfence’s achievements.
A Landmark Year for SCADAfence
Before we get into the year’s industry and product news, 2021 has been an astonishing year for us at SCADAfence. To start off the year, we unveiled our strategic partnership with Rapid7 which was followed up with many partnerships with industry leaders such as Keysight Technologies, BDO, Fujitsu, NCC and others. Then came recognition from SC media naming SCADAfence the Best SCADA Security Solution for 2021 and Frost & Sullivan announcing SCADAfence as a leader in the Frost Radar for Critical Infrastructure Cyber Security Market report for 2021. On that note, we want to thank all our employees, customers, partners, distributors, investors, for helping us reach new milestones we couldn’t have dreamed of.
OT Security in the Spotlight
2021 started out with the entire security community recovering from the aftermath of the massive SolarWinds campaign. Just a few weeks later news broke that a water treatment plant in Oldsmar, Florida, was under attack but the security team quickly thwarted the attack. The attacker briefly pumped up sodium hydroxide, the main ingredient in liquid drain cleaners, from 100 parts per million to 11,100 parts per million into the water supply. That control was undone almost immediately and the public was never at risk in this case, but it’s a quick lesson at just how important OT security is in 2021 and beyond.
Over the next six months, the OT security industry was reminded that 2021 was the year of ransomware. Some of the ransomware attacks were so colossal, they grabbed national headlines for the impact they had on civilians’ daily lives. In early May, a ransomware attack on Colonial Pipeline, a major East Coast fuel supplier presented the different security risks of exploiting IT networks to reach OT infrastructures. Shortly after in June, meat producer JBS USA paid an $11 million ransom after attackers shut down operations at five of their beef-processing plants.
And now suddenly, it’s been a crazy year of attacks that have affected the OT security landscape but just two weeks ago we have moved onto another threat that could last for years. There’s really no way to predict where threat actors will head in 2022, but we expect to still see more attacks on critical infrastructure via ransomware to be on the rise.
Major SCADAfence Product Updates
With SCADAfence product, R&D teams, and security researchers working tirelessly, SCADAfence development saw several milestones. Perhaps most importantly, enhancing our Governance Portal with a complete UI facelift that offers faster and more advanced results and more coverage of compliance regulations. Today, our Governance Portal has become a significant contributor to the company’s revenue growth, which was driven by customer and market demand and the cybersecurity executive order by United States President Joe Biden.
SCADAfence’s Multi-Site portal also saw a major update, customers now can distribute their configurations to all their sites from the Multi-Site Portal to the distributed SCADAfence Platforms. The security configuration is managed via profiles and covers many security aspects including alerts policy, IP groups, central licensing, 3rd Party tools integrations, and more. By deploying the central configuration, administrators will now save more time while increasing productivity and efficiency while using the SCADAfence Platform in their multiple sites.
An additional product offering that we launched near the end of 2021 was SCADAfence’s Managed Services for OT security. Now industrial organizations can enable their OT security with minimal effort. Our OT security experts deliver the expertise and technology that is needed to effectively control OT networks with visibility, risk management, and vulnerability detection.
And, as usual, there were many equally important additions, such as feature updates, new integrations, performance improvements, and more.
2021, A Banner Year for SCADAfence
With 2022 right around the corner, we can’t forget the trend-setting year that was 2021. Here at SCADAfence, 2021 was a fruitful year of growth and opportunity which included quadrupling our yearly revenue and doubling our customer base over the last year. We accelerated our expanding global customer base across a diverse set of industries – including manufacturing, water treatment, critical infrastructure, oil and gas, pharmaceuticals, chemicals, and building management systems (BMS).
As a company, we moved to a beautiful new office in Ramat Gan and we recruited several industry-leading OT security experts from leading cybersecurity organizations to grow our sales, sales engineering and strategy team. We’ll share some more on that in future posts.
To a More Secure Year Ahead
We hope this recap of 2021 at SCADAfence helps you to see the larger trends of OT security and what our product has to offer. Stay tuned for more blog, news articles and innovative product updates in the upcoming year that will continue to examine new and emerging OT security trends we should all focus on.
As we conclude, we’d like to thank all our customers, employees, partners, investors and everyone who supported us this year. We couldn’t have done it without you, and look forward to continuing to collaborate with you!
Happy New Year!
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.


Pandora FMS 和 RedHat6,2022 年即將結束的故事

Today I will tell you a little story, that of good Redhat6 and Pandora FMS, a relationship that endured, on favorable terms, everything it had to endure, but finally fell apart. Calm down, they still will stay as friends.
Pandora FMS stops supporting RedHat6 this 2022
Redhat6 was once the generation of Red Hat’s complete set of operating systems, designed for mission-critical enterprise computing and certified by leading enterprise software and hardware providers. Many systems were based on Rhel6. Among them we highlight CentOS, which in its day, was a derivation, a kind of free clone of Redhat, with the same life cycle.
As many of us know, CentOS 6 reached the end of its official life cycle, on November 30th, 2020, so it is a system that has been obsolete for more than a year. However, we, Pandora FMS, have maintained a year of extended support (2021) for these systems to make transition and migration from CentOS 6-based systems to systems based on CentOS 7 or the latest RedHat 8 easier. But this is over by 2022.
The Future of RedHat
What will happen now? Well, let’s talk about RedHat Enterprise Linux 8. Because the most cutting-edge IT is hybrid IT. And in order to transform a system into a hybrid environment, from data centers to Cloud services, certain formalities are needed. Like an adaptable scalability. Seamless workload transfer. Application development… And, of course, RedHat already has an operating system that meets all these requirements, the path to its future is RedHat 8. Cutting-edge technology that adapts to businesses and has the essential features, “from container tools to compatibility with graphic processing units”, to launch tomorrow’s technology today.
Some alternatives to CentOS
Are there any alternatives for team administrators who already moved on? Well, we have some candidates and we know them well because we support them.
- RHEL for Open Source Infrastructure: RedHat itself launched this alternative to the community so that no one would sigh for the death of CentOS, even so we are facing a clone of RHEL.
- Rocky Linux: It was developed by Greg Kurtzer and named after Rocky McGough. During its first 12 hours of life online, it was downloaded 10,000 times.
- AlmaLinux: Although now managed by its own foundation, AlmaLinux was launched in its day by those responsible for CloudLinux. Since its inception it was claimed by many as the best positioned successor to CentOS, now its version 8.5 is the proposed exact copy of RHEL 8.5.
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.



