My First Post      My Facebook Profile      My MeOnShow Profile      W3LC Facebook Page      Learners Consortium Group      Job Portal      Shopping @Yeyhi.com

Pages










Monday, October 16, 2017

Some examples of Cyber Security Firms and what they do



This article is a part of my series 'Security is our duty and we shall deliver it'

Following are some examples of Cyber Security Firms and what they do:


IBM Security: Services include- security intelligence and analytics; identity and access management; application security; advanced fraud protection; data security and privacy; and infrastructure protection.


Symantec Software: World's largest security product vendor, largest antivirus (Norton) and a variety of backup and asset management systems manufacturer


Cisco - Products range from advanced malware protection; next generation firewalls; security management; cloud security; next generation prevention systems; VPN security clients; email security; policy and access; web security; network visibility and enforcement; and router security, to name a few.


BAE Systems - It operates through five segments: the electronic systems; the cyber and intelligence systems; intelligence and security systems; applied intelligence; and the platforms and services.


McAfee - One of the biggest antivirus and anti-malware provider in the world.


Palo Alto Networks - It works on Next-Generation Firewall, Advanced Endpoint Protection and Threat Intelligence Cloud. The company’s Next Generation Security Platform was built for breach prevention with threat information shared across a range of security functions that can operate over mobile networks.


Apart from these, there are hundreds of companies around the globe that manufacture security products or provide their services. We have relations with some of the companies fast emerging in these arena and some having good clientele and reputation in terms of Software security implementations. We are close to building one own Software Security product.



You can read and download the article from:
https://www.slideshare.net/toughjamy/security-is-our-duty-and-we-shall-deliver-it-white-paper

Read on LinkedIn:
https://www.linkedin.com/pulse/security-our-duty-we-shall-deliver-mohd-anwar-jamal-faiz/

Threat hunting, mitigation and Vulnerability Management




This article is a part of my series 'Security is our duty and we shall deliver it'

Threat hunting is a very deep and strong method to deal with security issues in markets and solutions that need stringent regulations, policies and have risks involved. It is the process of proactively and iteratively searching through networks to detect and isolate advanced threats that evade existing security solutions. According to SANS institute, the threat hunters are actively searching for threats to prevent or minimize damage. The formal process of threat hunting should not be confused with an attempt to prevent adversaries from breaching the environment or for defenders to eliminate vulnerabilities in the network. 


We employ SIEM tools typically only provide indicators at relatively low semantic levels. There is therefore a need to develop SIEM tools that can provide threat indicators at higher semantic levels. As the industry itself is developing around it, we also have our feets wet in the process. We have our Chief Security consultant actively involved in all the three methods viz. Analytics-Driven, situational-Awareness Driven and Intelligence-Driven. As an accompalished engineer he is a master of monkey and fuzzy tests as well.


For bug logging and defect tracking we use home grown technologies as well as Atlassian tools like Jira. For the cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities, i.e Vulnerability management we have adept leaders to lead and guide teams in teams in using vulnerability scanners. We have successfully employed Coverity and various checkstyles and PMD level rules. 


We have a set of our own scripts and systems to analyze and investigate for known vulnerabilities such as open ports, insecure software configurations, and susceptibility to malware infections. Like stated above, we have masters of fuzzer techniques who can work with us 24x7. Unknown vulnerabilities, such as a zero-day, and complex threats are all under our hand. We have consultants worked with a variety of antivirus software and heuristic analysis mechanisms. You remember we said, we have smartest of security consultants!


You can read and download the article from:
https://www.slideshare.net/toughjamy/security-is-our-duty-and-we-shall-deliver-it-white-paper

Read on LinkedIn:
https://www.linkedin.com/pulse/security-our-duty-we-shall-deliver-mohd-anwar-jamal-faiz/

Security is our duty and we shall deliver it! - A White Paper For Software Security Organizations

Recently, I wrote a White paper. It is titled as - 'Security is our duty and we shall deliver it!'


This paper could be best described in following words-

Quality Management, Information Security, Threat Hunting and Mitigation Plans for a Software Company or a Technology Start-up engaged in building, deploying or consulting in Software and Internet Applications.


The chief sections of the document would be:

  1. Introduction to Enterprise Risk & Cyber Security
  2. The technologies we employ in
  3. Types of Software testing
  4. Some examples of Cyber Security Firms and what they do
  5. How we achieve a secure product
  6. InfoSec and Managed Security Service Provider
  7. Training and development
  8. Safeguarding against Phishing and Multi-Factor Authentication
  9. Threat hunting, mitigation and Vulnerability Management
  10. The denouement


You can read and download the article from:
https://www.slideshare.net/toughjamy/security-is-our-duty-and-we-shall-deliver-it-white-paper

Read on LinkedIn:
https://www.linkedin.com/pulse/security-our-duty-we-shall-deliver-mohd-anwar-jamal-faiz/



Following blog posts are must read for any Software Quality and Security Professional or an organization working in this field:

http://www.w3lc.com/2010/05/veracode-as-new-whitebox-testing-tool.html

http://www.w3lc.com/2012/02/analysis-of-valgrind-still-reachable.html

http://www.w3lc.com/2011/07/stress-testing-what-how-when.html

http://www.w3lc.com/2011/02/types-of-software-testing.html

http://www.w3lc.com/2010/10/dos-and-ddos-clarification-on-hacking.html

http://www.w3lc.com/2010/05/baseline-and-traceability-matrix.html

Cheers my readers.
You are my reason to be motivated.

- M. Anwar Jamal Faiz










Wednesday, September 27, 2017

Best IDE for PHP: Edit, code, Autocorrect, run & debug

Let me begin this time with a theoretical answer- Nothing is good or bad. What suits you best is best for you!

Amused! Now, let Anwar come to the real analysis and advice.

I have seen people settling with Aptana now a days. It's reasonably fast, but chokes on large files when syntax highlighting is on. Setting up PHP debugging is hard. But three good things about Aptana: easy plugin installations, very fast and intuitive Subversion plugins, lighting fast file search.

I tried Eclipse PDT and Zend for Eclipse, but they have nightmare interface when it comes to PHP code. Installing plugins is a living horror of version mismatches and cryptic error messages.

I also use Komodo. Komodo has a very intuitive interface, but is ridiculously slow, chokes on medium sized files with syntax highlighting. File search is intuitive, but rather slow. Subversion integration is not that great - slow and buggy. But trust me on this, if you are using 16 GB RAM laptop or computer, Komodo will beat up on any rivals.


There is again another good player in this field. Enters PhpDesigner!!
The main pro of this one is that it's NOT Java based. This keeps the whole thing quick. I am listing its features that i collected from an internet post (Why to type again if its listed. Thanks to that man!)

Intelligent Syntax Highlighter - automatic switch between PHP, HTML, CSS, and JavaScript depending on your position! Lets see the languages supported!

PHP (both version 4 and 5 are supported)
SQL (MySQL, MSSQL 2000, MSSQL 7, Ingres, Interbase 6, Oracle, Sybase)
HTML/XHTML
CSS (both version 1 and 2.1 are supported)
JavaScript
VBScript
Java
C#
Perl
Python
Ruby
Smarty


Support for both PHP 4 and PHP 5

Code Explorer for PHP (includes, classes, extended classes, interfaces, properties, functions, constants and variables)
Code Completion (IntelliSense) for PHP - code assist as you type
Code Tip (code hint) for PHP - code assist as you type
Work with any PHP frameworks (access classes, functions, variables, etc. on the fly)
PHP object oriented programming (OOP) including nested objects
Support for PHP heredoc
Enclose strings with single- or double quotes, linefeed, carriage return or tabs
PHP server variables
PHP statement templates (if, else, then, while…)
Powerful PHP Code Beautifier with many configurations and profile support
phpDocumentor wizard
Add phpDocumentor documentation to functions and classes with one click!
phpDocumentor tags
Comment or uncomment with one click!
Jump to any declaration with filtering by classes, interfaces, functions, variables or constants
Debug (PHP):


Debug with Xdebug

Breakpoints
Step by step debugging
Step into
Step over
Run to cursor
Run until return
Call stack
Watches
Context variables
Evaluate
Profiling
Multiple sessions
Evaluation tip
Catch errors



Please note that the above features are decision making attributes. I analysed all other IDEs as well, over these parameters and able to reach some conclusion. Atleast for me i know who the bride would be. Ah! Bridegroom for all those female readers ;)

Coming  to my final verdict. I find its the Komodo that wins!
It has the best debugging facilities of any PHP IDE I have tried, is a very mature product and has more useful features than you can shake a stick at. Of note, it has a fantastic HTTP inspector, Javascript debugger and Regular Expression Toolkit. You can get it so that it steps through your PHP, then you see your Javascript running, and then see your HTTP traffic going out over the wire!

It also comes in free (Komodo Edit) and open (OpenKomodo versions). And, remember, Komodo is best suited for many other languages as well like Python.

Cheers!
* Please note: I am having messed up times because of two sweet angels at ma home. The frequency of posts have decreased, but i promise to come up with more researched book that i promised. And guess what, the poetry book that i was working upon is almost complete now. My wife is so enthusiastic for it :)

Friday, June 30, 2017

Link Aadhaar and PAN card : Income Tax India New Rule demystified at W3LC.com

Now that it is official that you need to link your Aadhar and PAN card details, the obvious question is how to do it. This post will explain that. But before that i will like to explain some points.


The Honourable Supreme Court in its landmark judgement has upheld Section 139AA of the Income Tax Act as constitutionally valid which required quoting of the Aadhaar number in applying for PAN as well as for filing of income tax returns. The Income Tax India official website shows this message clearly as on 14/06/2017. CBDT has extended the due date of furnishing Statement of Financial Transactions for AY 2017-18 from 31st May 2017 to 30th June 2017. https://incometaxindiaefiling.gov.in/




Method 1: Online Portal To link your Aadhaar with PAN:

* Go to the income tax e-filing website https://incometaxindiaefiling.gov.in/
* Click on the tab ‘Link Aadhaar’ on the left-hand side of the website. (See above screenshot)
* This will automatically lead you to https://incometaxindiaefiling.gov.in/e-Filing/Services/LinkAadhaarHome.html
* Fill your PAN and Aadhaar number
* Then enter your name exactly as mentioned in Aadhaar and then submit it.
* Enter captcha and click on 'Link Aadhaar'.
* After verification of details from the Unique Identification Authority of India (UIDAI), the linking will be confirmed.
* You will also get email at your registered email Id.
* In case, your linking was already done earlier, it will tell you that its already linked.


Method 2: SMS Method to Link you Aadhar and PAN card

For this you have to keep ready following information:
1. Your registered phone number with Adhar card
2. Your Aadhaar Number
3. Your PAN number

You need to send an SMS in a required format to given number by the government of India.

SMS format to link Aadhaar with PAN:
Send SMS to 567678 or 56161 from your registered mobile number in following format:
UIDPAN<12 aadhaar="" digit=""><10 digit="" pan="">

Example:
UIDPAN 123456789000 ABCDE1234M


Article on Hindustan Times
Guide on Business Standard Website
https://cleartax.in/s/how-to-link-aadhaar-to-pan
BankBazaar Notes