• Gadi Evron
  • Security Architect
    Send Message | Company | Website | Blog
  • Member Since: Feb 22, 2006
  • Featured Posts: 19
  • Comments: 23

About: Gadi Evron is Security Architect for Afilias Global Registry Services and recognized globally for his work and leadership in Internet security operations. He is the founder of the Zeroday Emergency Response Team (ZERT), organizes and chairs worldwide conferences, working groups and task forces. He is considered an expert on corporate security and counterespionage, botnets, e-fraud and phishing. Previously, Gadi was CISO at the Israeli government ISP (eGovernment project) and founded the Israeli Government CERT. Gadi authored two books on information security and is a frequent lecturer.

Creative Commons Except where otherwise noted, all postings by Gadi Evron on CircleID are licensed under a Creative Commons License.
Displaying recent 5 of 19 posts | View All Featured Posts — by Gadi Evron 

DNS, Domain Names, Internet Governance, Privacy, Security, Spam, Whois / blogs / Nov 21, 2007 1:59 PM PST

An Internet Security Operations Viewpoint of IGF

The Internet Governance Forum (IGF) is an annual UN conference on Internet governance which was held this year in Rio de Janeiro, Brazil. The topics discussed range from human rights online to providing Internet access in developing countries. A somewhat secondary topic of conversation is Internet security and cyber-crime mostly limited to policy and legislative efforts. Techies and Internet security industry don't have much to do there, but I have a few updates for us from the conference. ›››

By Gadi Evron | Comments: 12 | Views: 5767

Access Providers, Broadband, Security / blogs / May 13, 2007 10:44 AM PST

More on Broadband Router Insecurity and Being Proactive

Fergie replied on NANOG to my recent post on the subject of broadband routers insecurity: "I'll even go a step further, and say that if ISPs keep punting on the whole botnet issue, and continue to think of themselves as 'common carriers' in some sense -- and continue to disengage on the issue -- then you may eventually forced to address those issues at some point in the not-so-distant future..." He is right, but I have a comment I felt it was important - to me - to make. Not just on this particular vulnerability, but on the "war"... ›››

By Gadi Evron | Comments: 0 | Views: 2317

Access Providers, Broadband, Regional Registries, Security / blogs / May 11, 2007 4:26 PM PST

Broadband Routers and Botnets: Being Proactive

In this post I'd like to discuss the threat widely circulated insecure broadband routers pose today. We have touched on it before. Today, yet another public report of a vulnerable DSL modem type was posted to bugtraq, this time about a potential WIRELESS flaw with broadband routers being insecure at Deutsche Telekom. I haven't verified this one myself but it refers to "Deutsche Telekom Speedport w700v broadband router"... ›››

By Gadi Evron | Comments: 0 | Views: 2242

DNS, Domain Names, Internet Governance, Regional Registries, Security, Spam, Top-Level Domains / blogs / Apr 02, 2007 7:59 PM PST

Put Security Alongside .XXX

Isn't security as important to discuss as .XSS? The DNS has become an abuse infrastructure, it is no longer just a functional infrastructure. It is not being used by malware, phishing and other Bad Things [TM], it facilitates them. Operational needs require the policy and governance folks to start taking notice. It's high time security got where it needs to be on the agenda, not just because it is important to consider security, but rather because lack of security controls made it a necessity. ›››

By Gadi Evron | Comments: 1 | Views: 3777

DNS, Domain Names, IP Addressing, Security, Top-Level Domains / blogs / Mar 30, 2007 11:10 PM PST

Ongoing Internet Emergency and Domain Names

There is a current ongoing Internet emergency: a critical 0day vulnerability currently exploited in the wild threatens numerous desktop systems which are being compromised and turned into bots, and the domain names hosting it are a significant part of the reason why this attack has not yet been mitigated. This incident is currently being handled by several operational groups. This past February, I sent an email to the Reg-Ops (Registrar Operations) mailing list. The email, which is quoted below, states how DNS abuse (not the DNS infrastructure) is the biggest unmitigated current vulnerability in day-to-day Internet security operations, not to mention abuse. ›››

By Gadi Evron | Comments: 1 | Views: 2825
More...