Store and Forward

A blog about securing and using WebSphere MQ

Store and Forward header image 5

Entries Tagged as 'DeepQueue'

WebSphere MQ – Coming soon to an audit near you!

July 4th, 2009 No Comments

The June 29 episode of The Deep Queue is finally up!  Sorry about the delay, I was on an engagement last week that had me staying over the weekend in Boston to perform a production implementation on Saturday.  Although I’ve got a great recording setup at home, I’m afraid I don’t have decent equipment to [...]

Tags:   · · · · · · · · ·

Deep Queue #11: Security breaches are not news?

May 25th, 2009 No Comments

The subject of the UC Berkeley data breach was discussed on the May 15th Security Squad podcast.  The thing that struck me was that the breach itself was not the topic of conversation but rather the debate was about whether the breach was in fact newsworthy.  If you are not familiar with it, 160,000 Social [...]

Tags:   · · · · · ·

The Deep Queue – Episode #10: Cash in on mortgaged risk!

May 2nd, 2009 No Comments

No, that’s not mortgage risk.  Someone’s already done that and look where it got us.  No,I’m talking about mortgaged risk – the act of saving time or money by accepting risk that is hard to measure but easy to hide or ignore.  The risk is essentially a mortgage on your future.  A hidden cost that [...]

Tags:   · · · · · ·

The Deep Queue – Episode #9: Going postal about WMQ security

April 2nd, 2009 No Comments

This episode of The Deep Queue takes its inspiration from the thousandth time I was asked how to “turn on MQ security”.  Yes, that’s right, the thousandth time.  At least since I’ve been counting.  There were perhaps half a thousand instances before I started keeping track.  Unlike being the millionth customer at the local hair [...]

Tags:   · · · · ·

The Deep Queue – Episode #8: The good news and the bad news

February 27th, 2009 1 Comment

This episode of The Deep Queue contains news about the new MSoT stand-alone WMQ Explorer SupportPac, yet another payment processor data breach, updates to some items we’ve covered in the past and breaking news about a WebSphere MQ interim fix that many people will want to take a close look at.

Tags:   · · · · · · · ·

The Deep Queue – Episode #7: Reducing your attack surface

February 2nd, 2009 No Comments

This installment of The Deep Queue is about improving security by reducing the number of attack vectors that are exposed.  Given two systems with equivalent functionality the one with more exposed attack vectors is said to have a “larger attack surface”.  As I explain in the podcast, having a smaller attack surface doesn’t automatically result [...]

Tags:   · · · · · · ·

The Deep Queue – Episode #6: The Myth of the Trusted Internal Network

January 1st, 2009 1 Comment

In this episode of The Deep Queue I explain why I believe the “trusted internal network” is a myth.  Many of the problems that I see on consulting assignments would have been prevented by the same security measures I recommend to protect against malicious attacks.  Except the incidents in question are not usually malicious, they [...]

Tags:   · · · · · · ·

The Deep Queue – Episode #4: Listener email and why you should care about message types

November 3rd, 2008 3 Comments

In this installment we answer an email from a listener asking about channel authentication.  The requirement is for a channel exit pair that exchanges credentials securely then falls back to a plaintext channel.  In the second segment we talk about message types and how ignoring them opens up a vulnerability in your application. Andy Piper [...]

Tags:   · · ·

The Deep Queue – Episode #3: Ethical Administration

September 29th, 2008 2 Comments

In this episode of The Deep Queue I propose something I’m calling “ethical administration”.  Most people have heard of ethical hacking – doing what the bad guys do on behalf of and in cooperation with the good guys.  Ethical administration as I have imagined it is acting like the good guys on behalf of the [...]

Tags:   · · ·

The Deep Queue – Episode #2: Security Best Practices and FIPS

September 14th, 2008 3 Comments

I just uploaded the second episode of The Deep Queue.  This episode expands on my recent Mission:Messaging column and also discusses some nuances of working with FIPS compliance in WebSphere MQ.  The next episode is scheduled for October 6th.  Between now and then I have a large Extended Security Edition gig, a security assessment and [...]

Tags:   · ·