Recent Comments
- Doug on Credit card security fail
- T.Rob on Encrypting passwords in config files – secure or not?
- Gustav on Encrypting passwords in config files – secure or not?
- Kalpana on WMQ Security in v7.1
- T.Rob on Hang on – switching hosting providers
-
Recent Posts
Archives
Categories
Blogroll
Stack Exchange MQ Q&A- Can create Websphere Queue Manager but not connect – stackoverflow.com
- WebSphere MQ Performance – stackoverflow.com
- Test sending of mqseries messages without installing WebSphere MQ – stackoverflow.com
- Getting MQ queue statistics in Java – stackoverflow.com
- MQMessage read or delete – stackoverflow.com
- WebSphere MQ 7, can I use one machine to send message to remote queue – stackoverflow.com
- WebSphere MQ: Consuming Messages in Batches – stackoverflow.com
- WebSphere Message Broker MQMD Report – stackoverflow.com
- com.ibm.mq.MQException: MQJE001: Completion Code '2', Reason '2035' – stackoverflow.com
- IBM MQ - Moving messages between queues using Java MQ APIs – stackoverflow.com
Meta
Tag Archives: security
WMQ Security bulletin site
Been wondering how to know if your WMQ is up to date for security patches? Wonder no more! Just go visit the Security Bulletin for WebSphere MQ page. The Recommended Fixes page lists all of the Fix Packs and from … Continue reading
Posted in News, WMQ, WMQ Security
Tagged compliance, CVE, fix packs, fixes, HIPAA, patches, PCI, security, SOX, vulnerability, WMQ, WMQ Security
Leave a comment
WebSphere MQ – Coming soon to an audit near you!
The June 29 episode of The Deep Queue is finally up! Sorry about the delay, I was on an engagement last week that had me staying over the weekend in Boston to perform a production implementation on Saturday. Although I’ve … Continue reading
Posted in DeepQueue, Podcast, WMQ Security
Tagged Admin, Best Practices, commentary, DeepQueue, News, Podcast, security, WebSphere MQ, WMQ, WMQ Security
Leave a comment
New WMQ Channel vulnerability and interim fix announced
The IBM Internet Security Systems XForce team recently announced a buffer overflow vulnerability in WebSphere MQ client channels. According to the release, the vulnerability includes the possibility of remotely executing arbitrary code or “causing the application to crash.” It is … Continue reading
Posted in News, WMQ, WMQ Security
Tagged News, security, WebSphere MQ, WMQ, WMQ Security
Leave a comment
Deep Queue #11: Security breaches are not news?
The subject of the UC Berkeley data breach was discussed on the May 15th Security Squad podcast. The thing that struck me was that the breach itself was not the topic of conversation but rather the debate was about whether … Continue reading
Posted in DeepQueue, Podcast, WMQ, WMQ Security
Tagged DeepQueue, Podcast, security, WebSphere MQ, WebSphere MQ Security, WMQ, WMQ Security
Leave a comment
WANTED DEAD OR ALIVE: WMQ Security exits
As you know, there are some security functions in WebSphere MQ that require an exit. By now everyone should be familiar with BlockIP2, the well known channel security exit. But there are a couple of other requirements that a channel … Continue reading
Posted in WMQ, WMQ Security
Tagged Best Practices, design, security, WebSphere MQ, WMQ, WMQ Security
2 Comments
Wrapping up IMPACT 2009
Well, this is the last day of IMPACT. It’s always lightly attended as many folks take Friday as a travel day. I have one more session this morning though. It’s the WMQ ESE introduction. Overall the WMQ security sessions were … Continue reading
Posted in Events, General, News, WMQ
Tagged Conferences, Events, General, News, security, WebSphere MQ, WebSphere MQ Security, WMQ, WMQ Security
Leave a comment
Update to MQ Security Heats Up comment thread
There’s a comment thread going on over at the “WebSphere MQ Security Heats Up” post regarding the script settings as originally published versus the updates I have posted on this site. RKPowers writes “I am still confused about the +set … Continue reading
Posted in Errata, WMQ, WMQ Security
Tagged Errata, security, WebSphere MQ, WebSphere MQ Security, WMQ, WMQ Security
Leave a comment
The Deep Queue – Episode #7: Reducing your attack surface
This installment of The Deep Queue is about improving security by reducing the number of attack vectors that are exposed. Given two systems with equivalent functionality the one with more exposed attack vectors is said to have a “larger attack … Continue reading
Posted in DeepQueue, Podcast, WMQ, WMQ Security
Tagged DeepQueue, News, Podcast, security, WebSphere MQ, WebSphere MQ Security, WMQ, WMQ Security
Leave a comment
Choosing a PCI DSS Auditor? Does WMQ awareness count?
James DeLuccia’s post about choosing a PCI DSS QSA auditor has some good advice. I would add to his list a criteria one of my own: the auditor should at least know how to spell WMQ. Or JMS. Or “message … Continue reading
Posted in General, News, WMQ Security
Tagged audit, Best Practices, commentary, PCI-DSS, security, WMQ Security
Leave a comment
Guest blogger @ WebSphere User Group
Ben Wen and I were invited to be guest bloggers at WebSphere User Group this month so the post I was planning for this space was hijacked! You can read it at WebSphere User Group posted as The Invisible Threat.