The Coalfire Blog

Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique cybersecurity issues that impact the industries we serve, including Cloud Service Providers, RetailFinancial Services, Healthcare, Higher Education, Payments, Government, Restaurants, and Utilities.

The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts. We look forward to your comments, so please join the conversation.


  • AWS Certified Cloud Practitioner: A Valuable Certification for Professionals in Non-Technical Roles

    May 16, 2018, Jennifer Tonisson, Partner Marketing Manager, Technology & Cloud, Coalfire

    Within the past year, AWS unveiled what is arguably one of the best programs they have ever offered to non-technical professionals in the AWS Partner Network (APN): the AWS Certified Cloud Practitioner certification. The program, which is especially valuable for those in sales or marketing roles, doesn’t offer any high-tech products or services for selling or marketing AWS. Instead, it offers a learning path and a certification that is intended to provide individuals with the knowledge and skills necessary to effectively demonstrate an overall understanding of the AWS Cloud.

    Read more
  • Microsoft Word Document Upload to Stored XSS: A Case Study

    May 09, 2018, Esteban Rodriguez, Consultant, Coalfire Labs, Coalfire

    Anytime I see a file upload form during an application test, my attention is piqued. In a best-case scenario, I can upload a reverse shell in a scripting language available on the webserver. If the application is running in PHP or ASP for example, it becomes quite easy. If I can’t get a backdoor uploaded, I will attempt to try to upload an HTML page to get my own client-side javascript uploaded for XSS attacks.

    Read more
  • Cloud Security Governance - Optimizing the Business Benefits of Security in the Cloud

    May 02, 2018, Michael Addo-Yobo, Managing Principal, Cyber Risk Advisory, Coalfire

    Enterprises are increasingly pursuing the business advantages of migrating technology platforms and services into the cloud environment leveraging one or more of the three main cloud service areas – Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). These advantages include but are not limited to rapid information system deployment, significantly reduced operating costs, massive economies of scale, processing speed, and agility. However, subscription to these services often imply security and compliance challenges for enterprises who are often unprepared to resolve them.

    Read more
  • Cooking Up Shells with Chef

    April 30, 2018, Ryan Wendel, Consultant, Coalfire Labs

    I was able to compromise a Chef server on one of my recent engagements. Owning a Chef server means having the keys to the castle. I wasn’t quite sure how to go about using this tool. I’m familiar with Puppet as I’ve spent the majority of my career on the systems side. Having never run into Chef, I needed to put a little time into figuring out the fastest way to use a Chef infrastructure to shell a bunch of sensitive hosts. Here is how I went about it.

    Read more
  • RSA 2018 recap: GDPR, Increasing Visibility and Transparency of Cloud Security

    April 27, 2018, Marshall England, Sr. Marketing Director, Technology & Cloud

    RSA 2018 is in the books! The event welcomed 42,000 attendees to San Francisco, including cybersecurity professionals, vendors, media, and analysts. The themes of visibility and transparency repeatedly came up in discussions and presentations as organizations grapple with ever-increasing data flows across multiple technology platforms and cloud ecosystems. Another big topic of interest was the European Union’s upcoming General Data Protection Regulation (GDPR) and how it will affect organizations and their data.

    Read more
  • Displaying results 11-15 (of 295)
     |<  <  1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10  >  >| 

Recent Posts

Post Topics

Archives

RSS Feed

The Coalfire BlogSubscribe to Feed
Chrome users will need to install RSS Subscription Extension (by Google)

Tags