Category Archives: WMQ Security

WebSphere MQ Security-related posts.

New WMQ Channel vulnerability and interim fix announced

The IBM Internet Security Systems XForce team recently announced a buffer overflow vulnerability in WebSphere MQ client channels.  According to the release, the vulnerability includes the possibility of remotely executing arbitrary code or “causing the application to crash.”  It is … Continue reading

Posted in IBMMQ, News, WMQ Security | Tagged , , , , | Leave a comment

Deep Queue #11: Security breaches are not news?

The subject of the UC Berkeley data breach was discussed on the May 15th Security Squad podcast.  The thing that struck me was that the breach itself was not the topic of conversation but rather the debate was about whether … Continue reading

Posted in DeepQueue, IBMMQ, Podcast, WMQ Security | Tagged , , , , , , | Leave a comment

WANTED DEAD OR ALIVE: WMQ Security exits

As you know, there are some security functions in WebSphere MQ that require an exit.  By now everyone should be familiar with BlockIP2, the well known channel security exit.  But there are a couple of other requirements that a channel … Continue reading

Posted in IBMMQ, WMQ Security | Tagged , , , , , | 2 Comments

The Deep Queue – Episode #10: Cash in on mortgaged risk!

No, that’s not mortgage risk.  Someone’s already done that and look where it got us.  No,I’m talking about mortgaged risk – the act of saving time or money by accepting risk that is hard to measure but easy to hide … Continue reading

Posted in DeepQueue, Events, IBMMQ, Podcast, WMQ Security | Tagged , , , , , , | Leave a comment

Slides for PCI Knowledgebase webinar posted

Join me Wednesday April 15th @ Noon Eastern for a webinar hosted by the fine folks at PCI Knowledgebase.com on the topic of WebSphere MQ for QSA’s.  Register for the webinar at this link.  The slides have been posted here.

Posted in Events, IBMMQ, News, WMQ Security | Tagged , , , , , , | 3 Comments

Webinar: WMQ Security for QSA's April 15th

I will be presenting a webinar on April 15th, hosted by the fine folks at PCI Knowledgebase. The purpose of the webinar will be to introduce Qualified Security Assessors, or QSA’s as they are known, to the concept of WebSphere … Continue reading

Posted in IBMMQ, News, WMQ Security | Tagged , , , , , | 3 Comments

When automatic translators go wrong…very wrong!

I just found a blog post about WMQ security that has, I believe, been run through an automated translation service with unintentionally hilarious results.   Here’s an excerpt: WMQ Adventurer authenticating a connexion to a queue director For both waiter and … Continue reading

Posted in General, Humor, IBMMQ, WMQ Security | Tagged , , , | Leave a comment

The Deep Queue – Episode #9: Going postal about WMQ security

This episode of The Deep Queue takes its inspiration from the thousandth time I was asked how to “turn on MQ security”.  Yes, that’s right, the thousandth time.  At least since I’ve been counting.  There were perhaps half a thousand … Continue reading

Posted in DeepQueue, IBMMQ, Podcast, WMQ Security | Tagged , , , , , | Leave a comment

The Deep Queue – Episode #8: The good news and the bad news

This episode of The Deep Queue contains news about the new MSoT stand-alone WMQ Explorer SupportPac, yet another payment processor data breach, updates to some items we’ve covered in the past and breaking news about a WebSphere MQ interim fix … Continue reading

Posted in DeepQueue, Errata, IBMMQ, MQMFT, Podcast, Publications, WMQ Security | Tagged , , , , , , , , | 1 Comment

Update to MQ Security Heats Up comment thread

There’s a comment thread going on over at the “WebSphere MQ Security Heats Up” post regarding the script settings as originally published versus the updates I have posted on this site. RKPowers writes “I am still confused about the +set … Continue reading

Posted in Errata, IBMMQ, WMQ Security | Tagged , , , , , | Leave a comment