Notify me!
-
Recent Posts
Archives
Categories
Stack Exchange MQ Q&A- IBM MQ web api - retrieve messages without message format – stackoverflow.com
- MQCONNX ended with reason code 2393 when connecting mTLS enabled queue – stackoverflow.com
- how to rectify javax.jms.JMSException: Failed to create connection? – stackoverflow.com
- IBM MQ 2059 (MQRC_Q_MGR_NOT_AVAILABLE) error in .NET 9.0 console app using IBMMQClient with certificate-based SSL setup – stackoverflow.com
- TIBCO BWCE Send Message Did Not Send ApplIdentityData MQMD to MQ – stackoverflow.com
Meta
Follow me on Twitter
My Tweets
Tag Archives: WMQ Security
Signed C&C messages? What a novel idea!
I’ve been saying for a while now that Command and Control messages to be signed. It’s a question of authentication. When you pass a message to perform an administrative action, what assurance do you have that the message got to … Continue reading
Posted in IBMMQ, News, WMQ Security
Tagged crypto, DNS, DNSSEC, News, security, SSL, WMQ, WMQ Security
Leave a comment
The Deep Queue – Episode #6: The Myth of the Trusted Internal Network
In this episode of The Deep Queue I explain why I believe the “trusted internal network” is a myth. Many of the problems that I see on consulting assignments would have been prevented by the same security measures I recommend … Continue reading
Posted in DeepQueue, IBMMQ, Podcast, WMQ Security
Tagged commentary, DeepQueue, Podcast, security, WebSphere MQ, WebSphere MQ Security, WMQ, WMQ Security
1 Comment
WMQ File Transfer Edition launched
I’ve been haunting the Vienna MQ list server for long enough to have seen the topic of moving files over MQSeries, and later WebSphere MQ, raise it’s ugly head on many occasions. I say “ugly” because creating a general-purpose program … Continue reading
Updated script templates
The script templates for locking down admin access have been updated for WMQ v7 to include topics. I’ve also added additional comment lines, a change log and fixed a couple of typos. The new versions are an update to the … Continue reading
Puzzled by WMQ vulnerability advisory
Well, I knew this one was out there but never looked at the CVE for it – there is a memory corruption vulnerability in the WebSphere MQ ( CVE-2007-6044) that is network exploitable. What I can’t figure out is why … Continue reading
Posted in General, IBMMQ, WMQ Security
Tagged advisory, CVE, MITRE, vuln, vulnerability, WMQ, WMQ Security
Leave a comment
The Deep Queue – Episode #3: Ethical Administration
In this episode of The Deep Queue I propose something I’m calling “ethical administration”. Most people have heard of ethical hacking – doing what the bad guys do on behalf of and in cooperation with the good guys. Ethical administration … Continue reading
The Deep Queue – Episode #2: Security Best Practices and FIPS
I just uploaded the second episode of The Deep Queue. This episode expands on my recent Mission:Messaging column and also discusses some nuances of working with FIPS compliance in WebSphere MQ. The next episode is scheduled for October 6th. Between … Continue reading
The Deep Queue – Episode #1: PCI-DSS and WMQ
The first episode of the new Deep Queue podcast is online! In this episode I introduce the podcast for a few minutes and then talk about a discussion that I had with some guys from the IBM Retail group. The … Continue reading
See you in Barcelona!
I just found out my travel has been approved for IBM’s Transaction & Messaging Technical Conference coming up this November in Barcelona! I seem to have inherited ownership of the High Availability presentation which I certainly do not mind. I … Continue reading
Posted in Events, IBMMQ
Tagged Conferences, Events, presentation, security, WebSphere MQ, WebSphere MQ Security, WMQ Security
3 Comments
Choosing a PCI DSS Auditor? Does WMQ awareness count?
James DeLuccia’s post about choosing a PCI DSS QSA auditor has some good advice. I would add to his list a criteria one of my own: the auditor should at least know how to spell WMQ. Or JMS. Or “message … Continue reading →
Share this: