<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-32727974</id><updated>2011-08-01T10:27:13.425-04:00</updated><title type='text'>stephen r. moore</title><subtitle type='html'>my professional, academic, and volunteer work in information assurance</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>54</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-32727974.post-6951320101547060053</id><published>2009-01-09T13:14:00.010-05:00</published><updated>2009-01-09T15:30:52.674-05:00</updated><title type='text'>Email RFC 2142</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LRSPJLcRRPw/SWez1vvHVJI/AAAAAAAAAN0/hShDMEf0igY/s1600-h/email.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 104px; height: 67px;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/SWez1vvHVJI/AAAAAAAAAN0/hShDMEf0igY/s200/email.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5289394023298454674" /&gt;&lt;/a&gt;I am always amazed at the wealth of talent on the SANS alumni email list. Yesterday, someone asked "what email address do you use for security? If someone discovers a vulnerability, issue, or breach how do you expect them to easily get a hold of you?"&lt;br /&gt;&lt;br /&gt;Great question. Having some experience in this, I generally dredge their website or use Google. What I didn't know is &lt;a href="http://www.faqs.org/rfcs/rfc2142.html"&gt;RFC 2142&lt;/a&gt; answers this very question.&lt;br /&gt;&lt;br /&gt;Credit to Igor Mozolevsky for this information.&lt;br /&gt;&lt;br /&gt;Part 4 of RFC2142[1] states:&lt;br /&gt;&lt;br /&gt;4. NETWORK OPERATIONS MAILBOX NAMES&lt;br /&gt;&lt;br /&gt;Operations addresses are intended to provide recourse for customers,&lt;br /&gt;providers and others who are experiencing difficulties with the&lt;br /&gt;organization's Internet service.&lt;br /&gt;&lt;br /&gt;MAILBOX AREA USAGE&lt;br /&gt;----------- ---------------- ---------------------------&lt;br /&gt;ABUSE Customer Relations Inappropriate public behavior&lt;br /&gt;NOC Network Operations Network infrastructure&lt;br /&gt;SECURITY Network Security Security bulletins or queries&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-6951320101547060053?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/6951320101547060053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=6951320101547060053&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/6951320101547060053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/6951320101547060053'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2009/01/email-rfc-2142.html' title='Email RFC 2142'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/SWez1vvHVJI/AAAAAAAAAN0/hShDMEf0igY/s72-c/email.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-2887411046035734132</id><published>2008-12-01T09:34:00.005-05:00</published><updated>2008-12-01T09:42:33.915-05:00</updated><title type='text'>December (IN)SECURE Magazine</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.net-security.org/dl/insecure/INSECURE-Mag-19.pdf"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 220px; height: 280px;" src="http://www.net-security.org/images/insecure/issue-main-19.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;Check out the December edition of (IN)SECURE magazine&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size: 12pt; line-height: 115%; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt; &lt;a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-19.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-2887411046035734132?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/2887411046035734132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=2887411046035734132&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/2887411046035734132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/2887411046035734132'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2008/12/december-insecure-magazine.html' title='December (IN)SECURE Magazine'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-112153419861511767</id><published>2008-11-15T16:00:00.002-05:00</published><updated>2008-11-15T16:06:58.283-05:00</updated><title type='text'>shmoocon 2009</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_LRSPJLcRRPw/Ry3s2lS1UjI/AAAAAAAAAJk/H92kdWxkBVY/s200/con1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 174px; height: 88px;" src="http://bp2.blogger.com/_LRSPJLcRRPw/Ry3s2lS1UjI/AAAAAAAAAJk/H92kdWxkBVY/s200/con1.jpg" alt="" border="0" /&gt;&lt;/a&gt;Yup. Going again! &lt;br /&gt;Glad I am staying at the Wardman Park Marriott .... so the walk will be short.&lt;br /&gt;&lt;br /&gt;Any other Indy people going?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-112153419861511767?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/112153419861511767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=112153419861511767&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/112153419861511767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/112153419861511767'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2008/11/shmoocon-2009.html' title='shmoocon 2009'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_LRSPJLcRRPw/Ry3s2lS1UjI/AAAAAAAAAJk/H92kdWxkBVY/s72-c/con1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4164583960979797484</id><published>2008-11-15T15:46:00.004-05:00</published><updated>2008-11-15T16:10:04.774-05:00</updated><title type='text'>ISP McColo Shut Down After Connection Found To Spammers</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.crn.com/security/212002220"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 170px; height: 170px;" src="http://elkridgefootball.org/deadbug.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I can tell you the drop in our spam was around 35% - 40% after McColo was taken offline. Other reports are as high as 75%.&lt;br /&gt;&lt;br /&gt;Article &lt;a href="http://www.crn.com/security/212002220"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Hats off to &lt;span id="articleBody"&gt;Hurricane Electric for booting em.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4164583960979797484?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4164583960979797484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4164583960979797484&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4164583960979797484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4164583960979797484'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2008/11/isp-mccolo-shut-down-after-connection.html' title='ISP McColo Shut Down After Connection Found To Spammers'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4793466067951936079</id><published>2007-11-04T11:18:00.000-05:00</published><updated>2007-11-04T11:39:11.382-05:00</updated><title type='text'>Linked Armor</title><content type='html'>Allen and I are starting a business.  This is our logo.&lt;br /&gt;&lt;br /&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3xelS1UmI/AAAAAAAAAJ8/N2vU5QpCSoc/s320/linkedA.jpg" alt="" id="BLOGGER_PHOTO_ID_5129021058354336354" border="0" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4793466067951936079?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4793466067951936079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4793466067951936079&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4793466067951936079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4793466067951936079'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/11/linked-armor.html' title='Linked Armor'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3xelS1UmI/AAAAAAAAAJ8/N2vU5QpCSoc/s72-c/linkedA.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-1047796798472308743</id><published>2007-11-04T10:49:00.000-05:00</published><updated>2007-11-04T11:59:19.444-05:00</updated><title type='text'>shmoocon</title><content type='html'>&lt;a href="https://www.shmoocon.org/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3s2lS1UjI/AAAAAAAAAJk/H92kdWxkBVY/s200/con1.jpg" alt="" id="BLOGGER_PHOTO_ID_5129015973113057842" border="0" /&gt;&lt;/a&gt;Thanks to Brian (fellow IndySec-r), I will be going to &lt;a href="https://www.shmoocon.org/"&gt;shmoocon&lt;/a&gt;.  As you may know, tickets can be difficult to acquire. Let me know if you plan on attending.&lt;br /&gt;&lt;br /&gt;The date for the event is Feb 15 -17th.&lt;br /&gt;&lt;br /&gt;Thanks again Brian.&lt;br /&gt;&lt;br /&gt;-S&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-1047796798472308743?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/1047796798472308743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=1047796798472308743&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1047796798472308743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1047796798472308743'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/11/shmoocon.html' title='shmoocon'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3s2lS1UjI/AAAAAAAAAJk/H92kdWxkBVY/s72-c/con1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-83554037676713298</id><published>2007-11-04T00:20:00.000-04:00</published><updated>2007-11-04T11:07:41.281-05:00</updated><title type='text'>SANS SEC 540</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www2.sans.org/training/description.php?mid=917"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/Ry3t6FS1UkI/AAAAAAAAAJs/EJoYLtPwuv4/s200/voipclass.jpg" alt="" id="BLOGGER_PHOTO_ID_5129017132754227778" border="0" /&gt;&lt;/a&gt;Ok.  Things have been crazy; let me share.&lt;br /&gt;&lt;br /&gt;I just finished co-authoring SANS SEC 540 &lt;a href="https://www2.sans.org/training/description.php?mid=917"&gt;VoIP Security&lt;/a&gt; with Raul Siles and Dr. Eric Cole.   Eric will be teaching the inaugural course at the SANS Cyber Defense Initiative 2007 in December.&lt;br /&gt;&lt;br /&gt;The course is very lab intensive, so be ready (you won't be getting out of class early).  I hope you enjoy it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-83554037676713298?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/83554037676713298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=83554037676713298&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/83554037676713298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/83554037676713298'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/11/sans-sec-540.html' title='SANS SEC 540'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LRSPJLcRRPw/Ry3t6FS1UkI/AAAAAAAAAJs/EJoYLtPwuv4/s72-c/voipclass.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5285768128430066597</id><published>2007-11-01T12:27:00.000-04:00</published><updated>2007-11-04T11:09:56.656-05:00</updated><title type='text'>SANS Chicago 2007</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www2.sans.org/training/description.php?tid=510"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3utlS1UlI/AAAAAAAAAJ0/LqqUFtlWgyk/s200/503.jpg" alt="" id="BLOGGER_PHOTO_ID_5129018017517490770" border="0" /&gt;&lt;/a&gt;Headed to Chicago for SANS SEC 503 intrusion detection in-depth.  I love Chicago and 503 was next on my list, so it worked out well.&lt;br /&gt;&lt;br /&gt;Many things going on of late.  Blog is suffering.  I just finished a major project (will write more  about it later), so things on the blog front should improve a little.&lt;br /&gt;&lt;br /&gt;This has become somewhat of a pilgrimage of sorts, as I took the 401 class in Chicago this same time last year.&lt;br /&gt;&lt;br /&gt;IDS here I come.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5285768128430066597?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5285768128430066597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5285768128430066597&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5285768128430066597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5285768128430066597'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/11/sans-chicago-2007.html' title='SANS Chicago 2007'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Ry3utlS1UlI/AAAAAAAAAJ0/LqqUFtlWgyk/s72-c/503.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-945606605068293960</id><published>2007-09-26T12:38:00.000-04:00</published><updated>2007-09-26T12:41:10.479-04:00</updated><title type='text'>(IN)SECURE - September 2007</title><content type='html'>The September edition of (IN)SECURE &lt;a href="http://www.net-security.org/insecuremag.php"&gt;magazine&lt;/a&gt; is out.  &lt;br /&gt;&lt;br /&gt;I love it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-945606605068293960?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/945606605068293960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=945606605068293960&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/945606605068293960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/945606605068293960'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/09/insecure-september-2007.html' title='(IN)SECURE - September 2007'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5077175435188999896</id><published>2007-08-15T15:57:00.000-04:00</published><updated>2007-08-15T16:00:22.536-04:00</updated><title type='text'>whitedust.net - sorry to see you go</title><content type='html'>&lt;a href="whitedust.net"&gt;whitedust.net&lt;/a&gt; is no more.  I am not sure what went down, but it was serious enough to kill the site.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;14 August 2007 - 23:58 GMT&lt;br /&gt;&lt;br /&gt;With the industry and those in it so seemingly hostile to Whitedust, and&lt;br /&gt;pure apathy from anyone who thinks otherwise. Why bother. This site is&lt;br /&gt;now closed permanently. It's staff have abandoned the scene and the industry&lt;br /&gt;for real world projects - for good, you won't be seeing us again. You "Won".&lt;br /&gt;&lt;br /&gt;Good luck out there. You'll need it.&lt;br /&gt;&lt;br /&gt;-The Staff&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5077175435188999896?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5077175435188999896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5077175435188999896&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5077175435188999896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5077175435188999896'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/08/whitedustnet-sorry-to-see-you-go.html' title='whitedust.net - sorry to see you go'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-3391405138157432126</id><published>2007-08-13T22:36:00.000-04:00</published><updated>2007-08-13T23:42:52.166-04:00</updated><title type='text'>Information Security Decisions - Chicago</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://infosecurityconference.techtarget.com/conference/index.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/RsEZTS4CtlI/AAAAAAAAAHg/cPKKPSsppRg/s200/ISD.gif" alt="" id="BLOGGER_PHOTO_ID_5098384072435218002" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://maps.google.com/maps?saddr=24+E+Congress+Pkwy,+Chicago,+IL+60605&amp;geocode=&amp;amp;daddr=151+East+Wacker+Drive,+chicago+il&amp;f=d&amp;amp;sll=41.875747,-87.626902&amp;sspn=0.012718,0.013711&amp;amp;amp;amp;ie=UTF8&amp;ll=41.880969,-87.622232&amp;amp;spn=0.025434,0.027423&amp;z=15&amp;amp;om=1"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/RsEaiy4CtmI/AAAAAAAAAHo/SSfuToxxGMs/s200/Chic.gif" alt="" id="BLOGGER_PHOTO_ID_5098385438234818146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Over November 5th and 6th I will be attending Information Security Decisions 2007 in Chicago.&lt;br /&gt;&lt;br /&gt;View the Information Security Decisions site &lt;a href="http://infosecurityconference.techtarget.com/conference/"&gt;here&lt;/a&gt;. They note "No sales pitches disguised as content!" Let's hope.&lt;br /&gt;&lt;br /&gt;Information Security Decisions has posted a "Top 10 reasons to attend" list. You can read it &lt;a href="http://infosecurityconference.techtarget.com/conference/html/attend.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Here are my top reasons to go:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Ask Bruce Schneier about Alice and Bob.&lt;/li&gt;&lt;li&gt;Meet other security nerds (hopefully some &lt;a href="http://www.sockpuppet.org/chisec/"&gt;chisec&lt;/a&gt; people).&lt;/li&gt;&lt;li&gt;Win the CTS.&lt;/li&gt;&lt;li&gt;Learn something new.&lt;/li&gt;&lt;li&gt;Enjoy a nice nerd vacation and some Chicago-land food.&lt;/li&gt;&lt;li&gt;Stay in the $33 a night hostel (visited for &lt;a href="http://stephenrmoore.blogspot.com/2006/09/sans-chicago.html"&gt;SANS Chicago in 06&lt;/a&gt;).&lt;/li&gt;&lt;/ol&gt;Please note, you must be approved for admission (you must work in security and sometimes buy things). Also, and this is &lt;span style="font-style: italic;"&gt;very&lt;/span&gt; important, this is a free event, but if you register and do not show up --- it is $195.&lt;br /&gt;&lt;br /&gt;Taken from the registration email:&lt;br /&gt;&lt;blockquote&gt;NOTE: Once your application has been approved we will call you to confirm your attendance. Information Security Decisions is free to all attendees....&lt;br /&gt;All Information Security Decisions delegates are required to reserve their conference seat by providing a valid credit card, which will not be charged.&lt;br /&gt;&lt;br /&gt;However, if you do not call ahead to cancel or simply do not show up on November 5th, you will be charged &lt;span style="font-weight: bold;"&gt;$195&lt;/span&gt; to cover the costs we incur for your attendance (meals, proceedings, etc.). This policy allows you to display your commitment to ....&lt;br /&gt;&lt;/blockquote&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.hihostels.com/dba/hostel060034.en.htm"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/RsEayy4CtnI/AAAAAAAAAHw/FTWkZYlcDXI/s200/HI.gif" alt="" id="BLOGGER_PHOTO_ID_5098385713112725106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I will be staying at the Hostel located just down the street.  It is quite nice and would remind you of a dorm room (in fact part of the building is just that).  The price is $33 a night.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;View photos of the hostel &lt;a href="http://www.hihostels.com/dba/photo.php?lang=E&amp;house=060034&amp;amp;amp;amp;amp;amp;p%5B0%5D=2&amp;p%5B1%5D=2&amp;amp;p%5B2%5D=2&amp;p%5B3%5D=2&amp;amp;p%5B4%5D=2&amp;p%5B5%5D=2&amp;amp;p%5B6%5D=2&amp;p%5B7%5D=2&amp;amp;p%5B8%5D=2&amp;picno=9&amp;amp;cou=US&amp;act=1&amp;amp;name=HI+-+Chicago"&gt;here&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;HI (Hostels International) Chicago site &lt;a href="http://www.hihostels.com/dba/hostel060034.en.htm"&gt;here&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;View a map from the Hostel to the event Hotel &lt;a href="http://maps.google.com/maps?saddr=24+E+Congress+Pkwy,+Chicago,+IL+60605&amp;geocode=&amp;amp;daddr=151+East+Wacker+Drive,+chicago+il&amp;f=d&amp;amp;sll=41.875747,-87.626902&amp;sspn=0.012718,0.013711&amp;amp;amp;amp;ie=UTF8&amp;ll=41.880969,-87.622232&amp;amp;spn=0.025434,0.027423&amp;z=15&amp;amp;om=1"&gt;here&lt;/a&gt;. &lt;/li&gt;&lt;/ul&gt;I have three open seats in my car.  I will cover gas, but would appreciate help with the parking costs. I will be going up Sunday night and plan on leaving Tuesday evening after dinner.&lt;br /&gt;&lt;br /&gt;Contact me if you are seriously interested.&lt;br /&gt;&lt;br /&gt;-Steve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-3391405138157432126?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/3391405138157432126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=3391405138157432126&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/3391405138157432126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/3391405138157432126'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/08/information-security-decisions-chicago.html' title='Information Security Decisions - Chicago'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/RsEZTS4CtlI/AAAAAAAAAHg/cPKKPSsppRg/s72-c/ISD.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-590418098057962245</id><published>2007-07-30T01:08:00.000-04:00</published><updated>2007-07-30T01:13:42.668-04:00</updated><title type='text'>Video overview of SANS/GIAC by Stephen Northcutt</title><content type='html'>A great overview for anyone thinking about taking SANS training and/or taking a GIAC certification. &lt;br /&gt;&lt;br /&gt;Video found &lt;a href="http://www.net-security.org/article.php?id=1007"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;... taken from the latest (IN)SECURE magazine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-590418098057962245?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/590418098057962245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=590418098057962245&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/590418098057962245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/590418098057962245'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/07/video-overview-of-sansgiac-by-stephen.html' title='Video overview of SANS/GIAC by Stephen Northcutt'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-6116024382074329233</id><published>2007-07-29T23:14:00.000-04:00</published><updated>2007-07-30T00:43:03.451-04:00</updated><title type='text'>(IN)SECURE - July 2007</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.insecuremag.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Rq1X88p4j0I/AAAAAAAAAHY/Fd8EhiAYzyc/s200/issue12.jpg" alt="" id="BLOGGER_PHOTO_ID_5092823458211467074" border="0" /&gt;&lt;/a&gt;Check out the July edition of (IN)SECURE &lt;a href="http://www.insecuremag.com/"&gt;magazine&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Better than the 2600 quarterly (imo) and the price is right.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-6116024382074329233?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/6116024382074329233/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=6116024382074329233&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/6116024382074329233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/6116024382074329233'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/07/insecure-july-2007.html' title='(IN)SECURE - July 2007'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Rq1X88p4j0I/AAAAAAAAAHY/Fd8EhiAYzyc/s72-c/issue12.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-364058846698290145</id><published>2007-06-06T15:30:00.000-04:00</published><updated>2007-06-06T15:41:45.972-04:00</updated><title type='text'>Password Reset Process</title><content type='html'>&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/RmcM2GY-GOI/AAAAAAAAAHI/TBA3IheQCwA/s200/pass.jpg" alt="" id="BLOGGER_PHOTO_ID_5073037628823967970" border="0"&gt;While doing some reading on &lt;a href="http://www.blogger.com/www.terminal23.net"&gt;terminal23.net&lt;/a&gt; I found a link to another cool security site, &lt;a href="http://www.blogger.com/www.mcgrewsecurity.com"&gt;mcgrewsecurity.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;On the McGrew site, there was a link to a &lt;a href="http://www.mcgrewsecurity.com/training/Intro_to_Web_Security.pdf"&gt;pdf&lt;/a&gt; on web security. The most interesting slide was titled "A cool experiment" and dealt with password storage for things like webmail and other online accounts.&lt;br /&gt;&lt;br /&gt;Point being, password recovery is extremely important and should be tested prior to using any system.&lt;br /&gt;&lt;br /&gt;From page 19 of the McGrew pdf:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Anytime you sign up for a new site, take the time to try out their password recovery system&lt;/li&gt;&lt;li&gt;Make note of the things it asks you&lt;/li&gt;&lt;li&gt;If they wind up emailing you your original password – Oh snap! They're not hashing them at all!&lt;/li&gt;&lt;li&gt;Otherwise, take a look at how their reset process works&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="margin-bottom: 12pt;"&gt;Important takeaways involving recovery:&lt;/p&gt;   &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;A password emailed back to      you in its original form has not been hashed, as listed above. &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;A non-hashed email means it      could be stored and sent in clear text (depending on supporting system      architecture).&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Systems which do not reveal      the original password are best. You should not be able to directly recover      the original password &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Users should have to provide      password "challenge" information. Just think of what your banking      institution makes to fill out. They get it.... however....&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;With the above in mind, what      happens when we start overusing the same questions?&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;What is your mother's maiden      name?!?&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;   &lt;p class="MsoNormal" style="margin-left: 0.25in;"&gt;Counter point &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Overused passwords and weak      recovery processes will lead to endless access to personal information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;   &lt;p class="MsoNormal"&gt;Expanding upon the above information: &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Think about the systems you      use and the password recovery process. Is it too easy to get the password?      What information do they store about you and what type of verification checks      are in place to protect your information?&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Think personal, self-developed,      and or applications used by your employer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Building on the previous      points, think about password management in the enterprise. How does your      employer manage this process?  Automated? Manual? &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Another fun "lab"      is to test your web mail authentication process. Fire up a sniffer and see      what you can find. I know yahoo mail hashes the password in memory within      a java applet prior to post. The login ID is sent in the clear. &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Think about other systems      such as your VoIP softphones! How are those passwords stored and      transmitted? &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;   &lt;p class="MsoNormal"&gt;Get past the forgetfulness and eliminate the need for a password reset process. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Use a password keeper.       I have been testing Password Safe for almost a year with good results.       You can find the latest build &lt;a href="http://passwordsafe.sourceforge.net/"&gt;here&lt;/a&gt;. The tool was originally      a creation of &lt;a href="http://www.schneier.com/"&gt;Mr. Bruce Schneier&lt;/a&gt;. &lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Think about recovery,      transmission, and storage of your passwords.  &lt;font style=""&gt;&lt;br /&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; Cheers,&lt;br /&gt;Steve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-364058846698290145?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/364058846698290145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=364058846698290145&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/364058846698290145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/364058846698290145'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/06/password-reset-process.html' title='Password Reset Process'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/RmcM2GY-GOI/AAAAAAAAAHI/TBA3IheQCwA/s72-c/pass.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4729841179130145828</id><published>2007-05-13T22:25:00.000-04:00</published><updated>2007-05-13T22:28:16.626-04:00</updated><title type='text'>More on Virtual Machine Security</title><content type='html'>A colleague of mine shared this article about vm security.  Pretty good read.  &lt;a href="http://taviso.decsystem.org/"&gt;Tavis Ormandy&lt;/a&gt; is the author, with support from Google.&lt;br /&gt;&lt;br /&gt;Read the pdf &lt;a href="http://taviso.decsystem.org/virtsec.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I have listed the recommendations, in full, below.&lt;br /&gt;&lt;br /&gt;The following are some simple recommendations for safely deploying virtualization in production environments:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Treat Virtual Machines like services that can be compromised; use chroot, systrace, acls, least privileged users, etc.&lt;/li&gt;&lt;li&gt;Disable emulated hardware you don’t need, and external services you don’t use (DHCP daemons, etc.) to reduce the attack surface exposed to hostile users.&lt;/li&gt;&lt;li&gt;Xen is worth watching in future; separating domains should limit the impact of a compromise.&lt;/li&gt;&lt;li&gt;Maintain the integrity of guest operating systems, protect the kernel using standard procedures of disabling modules, /dev/mem, /dev/port, etc.&lt;/li&gt;&lt;li&gt;Take advantage of the securelevels features available on BSD systems.&lt;/li&gt;&lt;li&gt;Keep guest software up-to-date with published vulnerabilities.&lt;/li&gt;&lt;li&gt;If an attacker cannot elevate their privileges within the guest, the likelihood of compromising the VMM is significantly reduced.&lt;/li&gt;&lt;li&gt;Keep Virtual Machine software updated to ensure all known vulnerabilities have been corrected.&lt;/li&gt;&lt;li&gt;Avoid guests that do not operate in protected mode, and make use of any security features offered, avoid running untrusted code with root-equivalent privileges within the guest.&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4729841179130145828?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4729841179130145828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4729841179130145828&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4729841179130145828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4729841179130145828'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/05/more-on-virtual-machine-security.html' title='More on Virtual Machine Security'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5458123075189053056</id><published>2007-05-07T08:52:00.000-04:00</published><updated>2007-05-07T08:54:41.093-04:00</updated><title type='text'>(IN)SECURE - May 2007</title><content type='html'>&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px;" src="http://www.insecuremag.com/issue11.jpg" alt="" border="0" /&gt;Check out the May edition of (IN)SECURE &lt;a href="http://www.insecuremag.com/"&gt;magazine&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5458123075189053056?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5458123075189053056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5458123075189053056&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5458123075189053056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5458123075189053056'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/05/insecure-may-2007.html' title='(IN)SECURE - May 2007'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-3182734654437312948</id><published>2007-04-29T22:02:00.000-04:00</published><updated>2007-04-29T22:16:49.825-04:00</updated><title type='text'>SANS Vegas, Baby!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_LRSPJLcRRPw/RjVQRzAOltI/AAAAAAAAAHA/JwRU_HzrW7A/s1600-h/sansVegas.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/RjVQRzAOltI/AAAAAAAAAHA/JwRU_HzrW7A/s200/sansVegas.gif" alt="" id="BLOGGER_PHOTO_ID_5059038023099782866" border="0" /&gt;&lt;/a&gt;I am 99% sure I am going to SANS Network Security 2007 in fabulous Las Vegas.  This year, the event runs from September 22 through the 30th.  Read more about the event &lt;a href="http://www.sans.org/ns2007/?portal=2370654c8fd4c2c0620d67a2d083634c"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;No gambling or strip clubs --- just nerds, SANS and $26 Vegas buffets.  I love nerd vacations. &lt;br /&gt;&lt;br /&gt;Please send me an email if you plan on attending.&lt;br /&gt;&lt;br /&gt;-Steve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-3182734654437312948?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/3182734654437312948/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=3182734654437312948&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/3182734654437312948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/3182734654437312948'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/04/sans-vegas-baby.html' title='SANS Vegas, Baby!'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LRSPJLcRRPw/RjVQRzAOltI/AAAAAAAAAHA/JwRU_HzrW7A/s72-c/sansVegas.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-7810725484336366294</id><published>2007-04-29T21:50:00.000-04:00</published><updated>2007-04-29T22:01:43.063-04:00</updated><title type='text'>News from Steveland</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://stephenrmoore.blogspot.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_LRSPJLcRRPw/RjVNwDAOlqI/AAAAAAAAAGo/Q4ObdOt6fB4/s200/srm.gif" alt="" id="BLOGGER_PHOTO_ID_5059035244255942306" border="0" /&gt;&lt;/a&gt;Lots of new and exciting things occurring in Steveland.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. Even though I finished my degree months ago, I will finally receive my piece of paper for my &lt;a href="http://stephenrmoore.blogspot.com/2007/02/msia.html"&gt;MS in Information Assurance&lt;/a&gt;.&lt;br /&gt;2.  I have my &lt;a href="http://stephenrmoore.blogspot.com/2007/02/offensive-security-and-oscp.html"&gt;OSCP&lt;/a&gt; exam coming up soon.  Time to own or be owned.&lt;br /&gt;3. I just began a new chapter in my information assurance career --- writing technical security course ware. I am thrilled to be a part of this opportunity. Unfortunately, I can not share the details at the point in time.  Our time line for course completion is roughly six months.&lt;br /&gt;&lt;br /&gt;-Steve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-7810725484336366294?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/7810725484336366294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=7810725484336366294&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7810725484336366294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7810725484336366294'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/04/news-from-steveland.html' title='News from Steveland'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LRSPJLcRRPw/RjVNwDAOlqI/AAAAAAAAAGo/Q4ObdOt6fB4/s72-c/srm.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5676807741192179393</id><published>2007-04-27T14:24:00.001-04:00</published><updated>2007-04-29T21:49:30.305-04:00</updated><title type='text'>A great piece on VM Security</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.intelguardians.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_LRSPJLcRRPw/RjVLGDAOlpI/AAAAAAAAAGg/E1XaQDX7Kqo/s200/www.intelguardians.gif" alt="" id="BLOGGER_PHOTO_ID_5059032323678181010" border="0" /&gt;&lt;/a&gt;Should you care, take a look at this PDF on virtual machine detecting and security by Tom Liston and Ed Skoudis.  This presentation has been around for awhile, however, it is worth the read.&lt;br /&gt;&lt;br /&gt;One area of interest is the VMware's communication channel, which is used for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;shared clip board &lt;/li&gt;&lt;li&gt;file sharing &lt;/li&gt;&lt;li&gt;time sync &lt;/li&gt;&lt;/ul&gt;... the interesting thing, per this document, VMware uses a hard-coded value to authenticate to the command channel.   It is always the same value.&lt;br /&gt;&lt;br /&gt;Another interesting item is a deeper look at the guest's .vmx file.  Just as one would add or remove items on a new server, the same holds true for a guest VM.  In this case you would augment the settings within the .vmx file to limit the ability to fingerprint a VM (page 23).&lt;br /&gt;&lt;br /&gt;Read the PDF &lt;a href="http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5676807741192179393?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5676807741192179393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5676807741192179393&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5676807741192179393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5676807741192179393'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/04/great-piece-on-vm-security.html' title='A great piece on VM Security'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LRSPJLcRRPw/RjVLGDAOlpI/AAAAAAAAAGg/E1XaQDX7Kqo/s72-c/www.intelguardians.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4078557669825834500</id><published>2007-04-06T17:54:00.000-04:00</published><updated>2007-04-06T18:58:04.572-04:00</updated><title type='text'>Secunia Software Inspector</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://secunia.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/RhbKOaI18sI/AAAAAAAAAFo/YsKJkdrvyIg/s200/secunia.gif" alt="" id="BLOGGER_PHOTO_ID_5050446381025981122" border="0" /&gt;&lt;/a&gt;I wanted to share a tool, created by Secunia, called Software Inspector.  In short, it will scan your workstation or server and provide a patch level / vulnerability report.&lt;br /&gt;&lt;br /&gt;Per their site:&lt;br /&gt;&lt;blockquote&gt;The Secunia Software Inspector will inspect your operating system and software for insecure versions and missing security updates. A default inspection normally lasts 5-40 seconds, while a thorough inspection may take several minutes. Note: If you have anti-virus software or similar enabled, an inspection may increase significantly in duration.&lt;/blockquote&gt;&lt;br /&gt;This is a great tool for:&lt;br /&gt;&lt;br /&gt;1. a quick verification of an imaged (or re-imaged) workstation or server.&lt;br /&gt;2. establishing a quick baseline (or does your baseline need to be updated?)&lt;br /&gt;3. a simple first step to hardening a development, security, or customer workstation / laptop.&lt;br /&gt;&lt;br /&gt;Access the tool &lt;a href="http://secunia.com/software_inspector/?task=load"&gt;here&lt;/a&gt;.  Tested on Windows only.&lt;br /&gt;&lt;br /&gt;Remember to check the "Enable thorough ..." check box, as shown below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_LRSPJLcRRPw/RhbP66I18vI/AAAAAAAAAGA/RE7ieLRzOiY/s1600-h/cb.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/RhbP66I18vI/AAAAAAAAAGA/RE7ieLRzOiY/s200/cb.gif" alt="" id="BLOGGER_PHOTO_ID_5050452643088298738" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4078557669825834500?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4078557669825834500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4078557669825834500&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4078557669825834500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4078557669825834500'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/04/secunia-software-inspector.html' title='Secunia Software Inspector'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/RhbKOaI18sI/AAAAAAAAAFo/YsKJkdrvyIg/s72-c/secunia.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-1802090983093288619</id><published>2007-04-06T17:34:00.000-04:00</published><updated>2007-04-23T11:29:38.640-04:00</updated><title type='text'>RFP template from Foundstone</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.foundstone.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Rha-laI18rI/AAAAAAAAAFg/se15Nra5-Fg/s200/fs.jpg" alt="" id="BLOGGER_PHOTO_ID_5050433582023439026" border="0" /&gt;&lt;/a&gt;I was out playing on the Foundstone site for free security tools and found something quite nice.  They were kind enough to provide a &lt;a href="http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&amp;amp;subcontent=/resources/templates.htm"&gt;link&lt;/a&gt; to a RFP template.  This might not seem all that exciting, however, it is much better than creating the damn thing from scratch. It might save you some time in the future.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-1802090983093288619?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1802090983093288619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1802090983093288619'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/04/rfp-template-from-foundstone.html' title='RFP template from Foundstone'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Rha-laI18rI/AAAAAAAAAFg/se15Nra5-Fg/s72-c/fs.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-1526729799005280033</id><published>2007-02-28T18:23:00.000-05:00</published><updated>2007-02-28T18:40:10.213-05:00</updated><title type='text'>Offensive Security and the OSCP</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www.offensive-security.com/index.php"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/ReYP6Ncrb6I/AAAAAAAAAE8/S0-aCO1jqy4/s200/os.gif" alt="" id="BLOGGER_PHOTO_ID_5036730725977255842" border="0" /&gt;&lt;/a&gt;Take 10 minutes and check out the offensive security &lt;a href="https://www.offensive-security.com/index.php"&gt;site&lt;/a&gt;.  In case you do not know, these are are same people that brought you Auditor, Whoppix, Whax, and now Backtrack[2].&lt;br /&gt;&lt;br /&gt;If you haven't used Backtrack, check it out.  If you want to do more with it, consider their training, labs, and certification.&lt;br /&gt;&lt;br /&gt;For a syllabus outline and more information, click &lt;a href="https://www.offensive-security.com/documentation/offensive-security.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;You can download a demo training session &lt;a href="https://www.offensive-security.com/movies/01intro/01intro.html"&gt;here&lt;/a&gt;. Warning: this starts a video with sound.&lt;br /&gt;&lt;br /&gt;I really like the idea of this training because:  &lt;br /&gt;&lt;br /&gt;1. The tool is free.&lt;br /&gt;2. People actually use this tool for real security work.&lt;br /&gt;3. There are video examples that you can watch as many times as you like. &lt;br /&gt;4. There are labs and exercises which support the lectures. &lt;br /&gt;5. There is an applied certification (OSCP).&lt;br /&gt;6. For the certification "exam" you must apply what you have learned to attack a real environment (in a somewhat controlled environment --- you vpn in).&lt;br /&gt;7. The cost?  $400 USD.  In a day where a good IT security book is $50, this is a steal.&lt;br /&gt;8. Their support so far has been excellent. &lt;br /&gt;&lt;br /&gt;In short, I am down for this training.   I have one other guy that is going to jump in on this as well.  If we get 5 total (so 3 more), we get 10% off.  Let me know if you are interested.&lt;br /&gt;&lt;br /&gt;Cheers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-1526729799005280033?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/1526729799005280033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=1526729799005280033&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1526729799005280033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1526729799005280033'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/02/offensive-security-and-oscp.html' title='Offensive Security and the OSCP'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/ReYP6Ncrb6I/AAAAAAAAAE8/S0-aCO1jqy4/s72-c/os.gif' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-498933586676605889</id><published>2007-02-28T18:03:00.000-05:00</published><updated>2007-02-28T20:31:39.234-05:00</updated><title type='text'>MSIA - Master of Science in Information Assurance</title><content type='html'>&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/ReYU2dcrb7I/AAAAAAAAAFI/rCE65Cx9Xx8/s200/tu.gif" alt="" id="BLOGGER_PHOTO_ID_5036736159110885298" border="0" /&gt;I have been MIA for a month now.  I even missed indysec 5.  Shameful, I know.  I do however have some good news --- my MSIA (Master of Science in Information Assurance) is complete --- all 36 hours.&lt;br /&gt;&lt;br /&gt;That is right, I just received notification of my grade [A].   I can not say enough good things about &lt;a href="http://www.capitol-college.edu/academicprograms/graduateprograms/msiae/index.shtml"&gt;Capitol College&lt;/a&gt;. If you are looking for a distance ed offering in IA, Capitol is a great school to consider.&lt;br /&gt;&lt;br /&gt;I have discussed this &lt;a href="http://stephenrmoore.blogspot.com/2006/08/capitol-college.html"&gt;before&lt;/a&gt;, but the key selling point has to be the live lectures via the web. The &lt;a href="http://www.nsa.gov/"&gt;NSA&lt;/a&gt; seems to like &lt;a href="http://www.nsa.gov/ia/academia/caemap.cfm?MenuID=10.1.1.2#md"&gt;them&lt;/a&gt; as well.&lt;br /&gt;&lt;br /&gt;If you have any questions about the program, or anything else, just ask.&lt;br /&gt;&lt;br /&gt;Stephen R. Moore, MS&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-498933586676605889?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/498933586676605889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=498933586676605889&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/498933586676605889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/498933586676605889'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/02/msia.html' title='MSIA - Master of Science in Information Assurance'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LRSPJLcRRPw/ReYU2dcrb7I/AAAAAAAAAFI/rCE65Cx9Xx8/s72-c/tu.gif' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4506196378058088647</id><published>2007-02-14T13:37:00.000-05:00</published><updated>2007-02-15T11:06:36.886-05:00</updated><title type='text'>(IN)SECURE - February 2007</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.insecuremagazine.com/INSECURE-Mag-10.pdf"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/RdNX8w6O76I/AAAAAAAAAEw/Jrzh0zIbAeE/s320/insecure.gif" alt="" id="BLOGGER_PHOTO_ID_5031461910135893922" border="0" /&gt;&lt;/a&gt;Check out the February edition of (IN)SECURE &lt;a href="http://www.insecuremagazine.com/INSECURE-Mag-10.pdf"&gt;magazine&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I still haven't had time to dig in, but this edition may have some promise.  The spyware, infosec career, and vista article are of interest.&lt;br /&gt;&lt;br /&gt;Also, was it just me, or did the RSA conference get even more press this year than last?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATE&lt;/span&gt;:&lt;br /&gt;I must say I feel terrible.  As I said last night, I had not had a chance to completely read the entire publication.  It turns out I skipped over and left out a friend and colleague, Mr. Didier Stevens.  Take a look at his article on ROT13 and its use in Windows XP, then go visit his personal blog &lt;a href="http://didierstevens.wordpress.com/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;By the way, I love ROT13, which I talked about earlier in a light hearted post "Republican Aide Tries to Hire Hackers" &lt;a href="http://stephenrmoore.blogspot.com/2006/12/republican-aide-tries-to-hire-hackers.html"&gt;here&lt;/a&gt;. &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Additionally, I saw that Didier was "&lt;a href="http://digg.com/security/Reverse_Engineering_Mentoring_Scratchpad_Wiki_Labs_By_Didier_Stevensq"&gt;Dugg&lt;/a&gt;" on Digg for his work on "Reverse Engineering Mentoring" found &lt;a href="http://scratchpad.wikia.com/wiki/Reverse_Engineering_Mentoring"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Cheers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4506196378058088647?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4506196378058088647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4506196378058088647&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4506196378058088647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4506196378058088647'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/02/insecure-february-2007.html' title='(IN)SECURE - February 2007'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/RdNX8w6O76I/AAAAAAAAAEw/Jrzh0zIbAeE/s72-c/insecure.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-4521453473178290351</id><published>2007-01-15T17:41:00.000-05:00</published><updated>2007-03-14T13:46:43.593-04:00</updated><title type='text'>Passed the GIAC GSEC</title><content type='html'>I passed both of my exams for the &lt;a href="http://www.giac.org/"&gt;GIAC&lt;/a&gt; &lt;a href="http://www.giac.org/certifications/security/gsec.php"&gt;GSEC&lt;/a&gt;! I am now GSEC number 7131.  Passing both exams qualifies a candidate for the GSEC Silver certification.&lt;br /&gt;&lt;br /&gt;After passing the exams, there is an option to "Go Gold" where you complete a written practical on a selected security topic.  Over the next several weeks, I will select a topic and proceed with the &lt;a href="http://www.giac.org/gold/"&gt;Gold Certification&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Despite the cost of the training, the entire experience was very well worth it.  The content of the training material was top notch, the instruction was great, and the &lt;a href="http://stephenrmoore.blogspot.com/2006/09/sans-chicago.html"&gt;trip&lt;/a&gt; to Chicago was an event in itself.&lt;br /&gt;&lt;br /&gt;Around three months ago, I accepted a new position with my currently employer on our network security team. Going for the cert (I had not passed the exams at that point in time) and knowing I paid out of pocket, showed the interviewers I was truly interested and committed to the field of information security.  In this instance, certification mattered.&lt;br /&gt;&lt;br /&gt;For those that can attend, I highly recommend the training.&lt;br /&gt;&lt;br /&gt;See my scores &lt;a href="http://www.giac.org/certified_professionals/listing/gsec_100_7131.php"&gt;here&lt;/a&gt;.&lt;br /&gt;Search for others with the GSEC &lt;a href="http://www.giac.org/certified_professionals/listing/gsec.php"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-4521453473178290351?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/4521453473178290351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=4521453473178290351&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4521453473178290351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/4521453473178290351'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/01/passed-giac-gsec.html' title='Passed the GIAC GSEC'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-877547213816780166</id><published>2007-01-14T14:19:00.000-05:00</published><updated>2007-01-14T15:14:23.629-05:00</updated><title type='text'>ophcrack LiveCD - a nerd story</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://ophcrack.sourceforge.net/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/RaqCoaWGgWI/AAAAAAAAADE/cF7kzIitV9M/s200/ophcrack.gif" alt="" id="BLOGGER_PHOTO_ID_5019968365436240226" border="0" /&gt;&lt;/a&gt;Password cracking is nothing new.  Ophcrack and Ophcrack LiveCD have been all over Digg, Lifehacker, and the rest of the net. &lt;br /&gt;&lt;br /&gt;I read a couple of posts on Digg about the tool, but never had reason to test the tool.  Working in NetSec, there are always new and exciting things that appear on our radar.  In short, we had some vendor supplied (and supported) servers and they either lost or misplaced the local admin password. &lt;br /&gt;&lt;br /&gt;I made a quick visit to the ophcrack page for the &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=133599&amp;package_id=167699"&gt;ISO&lt;/a&gt; and also downloaded the Windows Server Resource Kit &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&amp;amp;DisplayLang=en"&gt;tools&lt;/a&gt; for cdburn.exe to burn the iso.&lt;br /&gt;&lt;br /&gt;The admin password was cracked in about 10 minutes.  The entire list of 10 accounts (including IUSR and IWAM) were cracked in maybe 25 minutes -- I wasn't keeping an exact count.&lt;br /&gt;&lt;br /&gt;Two things:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;The tool just worked.  It boots up and goes.  No real work involved. &lt;/li&gt;&lt;li&gt;This is a great way to audit local password strength.  We learned the vendor-selected passwords were pretty weak. &lt;/li&gt;&lt;/ol&gt; I had a small assignment in one of my classes at &lt;a href="http://www.capitol-college.edu/academicprograms/graduateprograms/msiae/index.shtml"&gt;Capitol College&lt;/a&gt; using &lt;a href="http://en.wikipedia.org/wiki/John_the_Ripper"&gt;John the Ripper&lt;/a&gt;.  It worked well, but it was not the most expedient process. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Rainbow_tables"&gt;Rainbow tables&lt;/a&gt; obviously speed things up.  Thanks ophcrack.&lt;br /&gt;&lt;br /&gt;This tool is obviously not hard to use. Might it change the way you manage (or think about managing) your workstations?  Privilege escalation anyone?  Do you know who might be on your outsourced overnight cleaning staff? &lt;br /&gt;&lt;br /&gt;Good thing people don't store files locally on their workstations ... I mean, uh. &lt;br /&gt;Here comes full drive &lt;a href="http://indysec.blogspot.com/2007/01/indysec-4-birk.html"&gt;encryption&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-877547213816780166?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/877547213816780166/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=877547213816780166&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/877547213816780166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/877547213816780166'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/01/ophcrack-livecd-nerd-story.html' title='ophcrack LiveCD - a nerd story'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/RaqCoaWGgWI/AAAAAAAAADE/cF7kzIitV9M/s72-c/ophcrack.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5192753890839461693</id><published>2007-01-13T14:03:00.000-05:00</published><updated>2007-04-23T10:11:14.501-04:00</updated><title type='text'>Firm: Seven steps for a more secure network</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.perimeterusa.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/Rak15aWGgUI/AAAAAAAAACs/YqlCLuNuljU/s200/ps.gif" alt="" id="BLOGGER_PHOTO_ID_5019602520121966914" border="0" /&gt;&lt;/a&gt;Combine New Years resolutions and this SC magazine &lt;a href="http://www.scmagazine.com/us/news/article/623764/firm-seven-steps-secure-network/"&gt;article&lt;/a&gt; and what do you get?  Questionable advice.&lt;br /&gt;&lt;br /&gt;The article starts out great.&lt;br /&gt;&lt;blockquote&gt;IT security professionals should rely on personal vigilance and implemented methodologies - not just the slew of new products hitting the marketplace - to protect their networks in 2007.&lt;/blockquote&gt;Sounds good.  Yes to vigilance and yes to method.  Just buying things is bad.  Nice work.&lt;br /&gt;&lt;br /&gt;Now for the fun.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;1. &lt;/span&gt;Change every password before the year's end. By taking this first step, you will enhance the security of every online commerce site visited, every computer, and every other password-protected device or website in use. Avoid easily discovered passwords, such as names or numeric series. Change your passwords at least quarterly in 2007.&lt;/blockquote&gt;Sound advice, except he didn't mention anything about pass phrases.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;2.&lt;/span&gt; Download patches and updates. Even some off-the-shelf computer security programs offer downloadable updates or "patches" capable of detecting the newest viruses and closing "backdoors" that hackers have discovered. Operating systems should be patched and upgraded at year-end, and regularly as well.&lt;br /&gt;&lt;/blockquote&gt;Nice work.  Patch your systems.  Someone send this guy a check.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;3. &lt;/span&gt;Hire a hacker. The holiday lull is the perfect time to conduct a "penetration test" to pinpoint weaknesses in a network's security. These tests emulate a hacker's invasion of a network; but rather than attacking databases and network tools, these scans identify specific vulnerabilities and propose solutions.&lt;/blockquote&gt;Hire a hacker? Not even going to touch the hacker versus cracker definition.  A pen test over the holidays is not a bad idea, however it would depend on what type of test you are running.  Blackbox, Whitebox, or something in between?  At times you want ops around to assist and they can't do that while eating honey ham seven states away.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;4.&lt;/span&gt; Conduct regular e-security check-ups. Automated, monthly remote risk assessments can be conducted for less cost than a single onsite review. These tests assure that confidential data is as secure as possible from external attack. In a hacker prone era rife with data theft, high levels of spam, and increasingly innovative computer fraud, waiting a full year between assessments is no longer a viable option.&lt;/blockquote&gt;What the hell is this guy talking about here?  Isn't that our goal to protect data --- each day?  And what exactly does he mean by "Automated, monthly remote risk assessments"?  "Make sure things are good" would have been just as powerful.  Sigh.  I assume he is talking about using a service such as Qualys to scan and report on your external facing.  These results can then be compared against preexisting baselines or standards to evaluate compliance and document change.&lt;br /&gt;&lt;br /&gt;While I agree with looking at your risks from the outside in, what about from the other direction?  What is being sent outbound? How about monitoring / measuring that?!? Aren't these guys an email security company?&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;5. &lt;/span&gt;Communicate your data security policy. All personnel should be briefed on the importance of protecting confidential customer data. Disseminate a policy on how and when, if ever, this data should be included in unsecured email correspondence with customers and others. Implementation of an encrypted email system would be a major security step forward.&lt;/blockquote&gt;Yes. Finally something I can agree with.  I would also like to add that one should begin looking at mail filtering outbound.  It helps to know how your customer service reps, execs, and IT professionals are sending their electronic communications (primarily for the unencrypted mail).&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;6. &lt;/span&gt;Keep your network virus-free. A thorough evaluation of your network is essential to protect entry points (such as email attachments, shared files, infected websites, downloads), and to minimize infection. Simply installing anti-virus (AV)software is not enough. The AV system still needs to be monitored to make sure the most recent definition files are updated on all devices and you are alerted when a device is not "up-to-date." Look to providers which offer a full suite of AV services that can keep current with fresh outbreaks.&lt;/blockquote&gt;10-4 good buddy.  Also think of reporting.  Metrics mean money!  Remember that.  When you need head count, funding, or a promotion --- you must have metrics.  Also remember that one vendor for all the environment isn't always the answer.  What is best for clients is not necessarily what is best for servers.  Moreover, AV vendors differ greatly from platform to platform.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;7. &lt;/span&gt;Consider "giving up" on do-it-yourself security. The New Year is a good time to consider outsourcing network security to a company dedicated to keeping up with the latest demands of computer network security.&lt;/blockquote&gt;Depending on the size and nature of the company, I agree.  Small shops should think about getting some help.  If noting else, a plan for security with periodic checkups.  Larger shops need IT Security professionals (even if just a few) to check up on the outsourced work.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5192753890839461693?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5192753890839461693/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5192753890839461693&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5192753890839461693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5192753890839461693'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2007/01/firm-seven-steps-for-more-secure.html' title='Firm: Seven steps for a more secure network'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/Rak15aWGgUI/AAAAAAAAACs/YqlCLuNuljU/s72-c/ps.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-8824651439769995164</id><published>2006-12-28T17:26:00.000-05:00</published><updated>2007-01-13T14:01:27.470-05:00</updated><title type='text'>How to Obscure Any URL</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://en.wikipedia.org/wiki/Obfuscated_code"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_LRSPJLcRRPw/RakrmKWGgTI/AAAAAAAAACg/cINELqN4MbU/s200/obfuscation.gif" alt="" id="BLOGGER_PHOTO_ID_5019591194293207346" border="0" /&gt;&lt;/a&gt;Well, maybe not.  I found this &lt;a href="http://www.pc-help.org/obscure.htm"&gt;article&lt;/a&gt; off of Digg and stored to view at a later time.  Initially, I was very excited as you will encounter url obfuscation when working with malware and phishing.&lt;br /&gt;&lt;br /&gt;Unfortunately, the specific techniques no longer work on Firefox 2.X or IE 6. The concept is something worth investing some time into. &lt;br /&gt;&lt;br /&gt;I need  to research if any, more recent, documents are available.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-8824651439769995164?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/8824651439769995164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=8824651439769995164&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8824651439769995164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8824651439769995164'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/how-to-obscure-any-url.html' title='How to Obscure Any URL'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LRSPJLcRRPw/RakrmKWGgTI/AAAAAAAAACg/cINELqN4MbU/s72-c/obfuscation.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5571891814807221044</id><published>2006-12-27T17:50:00.000-05:00</published><updated>2006-12-28T17:33:21.663-05:00</updated><title type='text'>The new migration from D.C.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.washingtonpost.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_LRSPJLcRRPw/RZL46kcrstI/AAAAAAAAACI/w2JJPhi-ndY/s200/wp.gif" alt="" id="BLOGGER_PHOTO_ID_5013343020316865234" border="0" /&gt;&lt;/a&gt;The Washington Post has a story about a new migration taking place on the east coast.  It seems some of our federal agencies see it fit to move just a bit west, out of D.C. -- just enough to be outside of a blast zone (a 50 mile radius).  Sounds like data center move time!&lt;br /&gt;&lt;br /&gt;Link the the complete article &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/12/25/AR2006122500637.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Blast zone or not, I welcome the move. I am pretty shocked this hasn't started sooner ... unless this is just an article to hype the local real estate markets. Hmm.&lt;br /&gt;&lt;br /&gt;Anyone want to invest in some local data carriers in the Winchester, VA area?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5571891814807221044?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5571891814807221044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5571891814807221044&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5571891814807221044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5571891814807221044'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/new-migration-from-dc.html' title='The new migration from D.C.'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LRSPJLcRRPw/RZL46kcrstI/AAAAAAAAACI/w2JJPhi-ndY/s72-c/wp.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-5661620893965903216</id><published>2006-12-26T23:28:00.000-05:00</published><updated>2006-12-26T23:41:57.792-05:00</updated><title type='text'>Online Nmap Scanner</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://insecure.org/nmap/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/RZH4nUcrssI/AAAAAAAAAB8/6xA9d4qznCE/s200/nmap.gif" alt="" id="BLOGGER_PHOTO_ID_5013061214627672770" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.matousec.com/"&gt;Matousec&lt;/a&gt; also provides an online Nmap scanner.   Fun stuff.&lt;br /&gt;&lt;br /&gt;Play with it &lt;a href="http://nmap-online.com/"&gt;here&lt;/a&gt;.&lt;br /&gt;Get the old school edition &lt;a href="http://insecure.org/nmap/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-5661620893965903216?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/5661620893965903216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=5661620893965903216&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5661620893965903216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/5661620893965903216'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/online-nmap-scanner.html' title='Online Nmap Scanner'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/RZH4nUcrssI/AAAAAAAAAB8/6xA9d4qznCE/s72-c/nmap.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-7855657568191791462</id><published>2006-12-26T22:52:00.000-05:00</published><updated>2006-12-26T23:17:39.306-05:00</updated><title type='text'>Personal Firewall Analysis (Windows)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_LRSPJLcRRPw/RZHufEcrsqI/AAAAAAAAABk/Y38E9RSAdV0/s200/ms.gif" alt="" id="BLOGGER_PHOTO_ID_5013050077777474210" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.matousec.com/"&gt;Matousec&lt;/a&gt; has posted a very interesting &lt;a href="http://www.matousec.com/projects/windows-personal-firewall-analysis/introduction-firewall-leak-testing.php#what-is-firewall-leak-test"&gt;leak-test&lt;/a&gt; report on Windows firewall software.  Most all the big names made the party, but few faired very well.&lt;br /&gt;&lt;br /&gt;In short, &lt;a href="http://www.personalfirewall.comodo.com/"&gt;Comodo&lt;/a&gt; and &lt;a href="http://www.jetico.com/index.htm#/jpfirewall.htm"&gt;Jetico&lt;/a&gt; own, while &lt;a href="http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfintro.mspx"&gt;Windows Firewall&lt;/a&gt; is horrible.&lt;br /&gt;Read the complete report &lt;a href="http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Note: they later go and slam &lt;a href="http://www.personalfirewall.comodo.com/"&gt;Comodo&lt;/a&gt; &lt;a href="http://www.matousec.com/projects/windows-personal-firewall-analysis/Comodo-Personal-Firewall-2.3.6.81/"&gt;here&lt;/a&gt; -- however, they slam everyone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-7855657568191791462?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/7855657568191791462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=7855657568191791462&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7855657568191791462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7855657568191791462'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/personal-firewall-analysis-windows.html' title='Personal Firewall Analysis (Windows)'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LRSPJLcRRPw/RZHufEcrsqI/AAAAAAAAABk/Y38E9RSAdV0/s72-c/ms.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-7517904820037995901</id><published>2006-12-26T21:38:00.000-05:00</published><updated>2006-12-28T17:34:49.771-05:00</updated><title type='text'>Bootable security distro on your USB stick</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.remote-exploit.org/index.php/BackTrack"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_LRSPJLcRRPw/RZHlY0crsoI/AAAAAAAAABM/C4_-bjD0-PQ/s200/bt.gif" alt="" id="BLOGGER_PHOTO_ID_5013040074798641794" border="0" /&gt;&lt;/a&gt;Ever use BackTrack? Here is a very nice article on how you can boot the OS from your USB stick.  They even have a bit about using it with Windows and the ever-handy VMware Server.&lt;br /&gt;Get the article &lt;a href="http://www.oiepoie.nl/2006/12/20/bootable-security-distro-on-your-usb-stick/#"&gt;here&lt;/a&gt;.&lt;br /&gt;Find other fun tutorials &lt;a href="http://www.remote-exploit.org/index.php/Tutorials"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;... sort of like making BackTrack something you would find on &lt;a href="http://portableapps.com/"&gt;portableapps.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-7517904820037995901?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/7517904820037995901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=7517904820037995901&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7517904820037995901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/7517904820037995901'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/bootable-security-distro-on-your-usb.html' title='Bootable security distro on your USB stick'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LRSPJLcRRPw/RZHlY0crsoI/AAAAAAAAABM/C4_-bjD0-PQ/s72-c/bt.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-8626507541874822127</id><published>2006-12-23T11:50:00.000-05:00</published><updated>2006-12-28T17:26:16.676-05:00</updated><title type='text'>Republican Aide Tries to Hire Hackers</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://politics.slashdot.org/article.pl?sid=06/12/22/1550250"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/RY1gkUcrsmI/AAAAAAAAAA0/WI5gm9Q4hlo/s200/sd.jpg" alt="" id="BLOGGER_PHOTO_ID_5011768137413800546" border="0" /&gt;&lt;/a&gt;Yesterday, /. posted news about a Republican Aide that wanted hire hackers to change his grades.  Let me lead off by saying I do not care about political affiliation or even the fact this is a government employee. So what? Not my blog.&lt;br /&gt;&lt;br /&gt;I will assume this guy had a bad G.P.A and was looking to get into a good grad program at Foo U. I do think it is interesting he went to Texas &lt;span style="font-weight: bold; font-style: italic;"&gt;Christian&lt;/span&gt; University, whose mission is evidently not shared by at least one of their former students.&lt;br /&gt;&lt;blockquote&gt;Our Mission&lt;br /&gt;To educate individuals to think and act as &lt;span style="font-style: italic;"&gt;ethical leaders&lt;/span&gt; and responsible citizens in the global community.&lt;/blockquote&gt;Anyway, enough of that stuff.  Let's get on with the humor!&lt;br /&gt;&lt;br /&gt;Take a moment and read the entire email &lt;a href="http://www.attrition.org/postal/z/033/0871.html"&gt;thread&lt;/a&gt; from the fine people at Attrition.org.  Trust me, it is worth it.  &lt;a href="http://www.networkworld.com/community/?q=node/9999"&gt;Here&lt;/a&gt; is also the link to the Network World news article.&lt;br /&gt;&lt;br /&gt;I loved the humor factor - rot 26 is some pretty serious stuff!  I remember a rot 13 question in the text "&lt;a href="http://www.amazon.com/Puzzles-Hackers-Ivan-Sklyarov/dp/1931769451"&gt;Puzzles for Hackers&lt;/a&gt;", and who asks for photos of pigeons or squirrels? Classic. Who doesn't love a squirrel?  Thanks to this email thread a new form of squirrel authentication has been born!  Thank you squirrels!&lt;br /&gt;&lt;br /&gt;A bit more on my above reference to rot 13 / 26.&lt;br /&gt;Check out rot13.org &lt;a href="http://rot13.com/info.php"&gt;here&lt;/a&gt;.&lt;br /&gt;They also have a calculator of sorts &lt;a href="http://rot13.com/index.php"&gt;here&lt;/a&gt;.&lt;br /&gt;With rot 13 the letter "a" would equal "n", "b" is "o", and so on.  If you think about it, rot 26 would start you right back at the beginning.  "a" to "n" and back to "a" -- thus the humor.&lt;br /&gt;&lt;br /&gt;In short, rot 13 is a prepackaged Caesar-cypher with a known jump of 13 places.&lt;br /&gt;&lt;br /&gt;I seriously wish they would have asked for a photo of a horned frog.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.admissions.tcu.edu/i/killer_frog2.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 116px; height: 119px;" src="http://www.admissions.tcu.edu/i/killer_frog2.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-8626507541874822127?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/8626507541874822127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=8626507541874822127&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8626507541874822127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8626507541874822127'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/republican-aide-tries-to-hire-hackers.html' title='Republican Aide Tries to Hire Hackers'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/RY1gkUcrsmI/AAAAAAAAAA0/WI5gm9Q4hlo/s72-c/sd.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-1329792744892067310</id><published>2006-12-18T18:35:00.000-05:00</published><updated>2006-12-28T16:51:45.292-05:00</updated><title type='text'>Gartner Highlights Key Predictions for IT Organizations in 2007 and Beyond</title><content type='html'>&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_LRSPJLcRRPw/RYyZ2kcrslI/AAAAAAAAAAo/yhgkubG29fY/s200/g.gif" alt="" id="BLOGGER_PHOTO_ID_5011549648132485714" border="0" /&gt;While reading the &lt;a href="http://www.it-observer.com/news/7010/gartner_75_networks_have_undetected_malware/"&gt;IT-Observer&lt;/a&gt;, I found a link to the 2007 Gartner Key Predictions for 2007.  I was very thankful for the lead on the article, however I wanted the other predictions.&lt;br /&gt;&lt;br /&gt;Egovernment.com wasn't afraid to fill me in ... link to &lt;a href="http://egovernment.govtech.net/magazine/channel_story.php/102846"&gt;article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;And the eye opener&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;blockquote&gt;&lt;b&gt;By the end of 2007, 75 percent of enterprises will be infected with undetected, financially motivated, targeted malware that evaded their traditional perimeter and host defenses.&lt;/b&gt; The threat environment is changing -- financially motivated, targeted attacks are increasing, and automated malware-generation kits allow simple creation of thousands of variants quickly -- but our security processes and technologies haven't kept up.&lt;/blockquote&gt;I break it down on the following points&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Financially Motivated Malware? An example would be nice.  If we locked down our web browsing and quit running our browsers with administrative privilege, this wouldn't be as big of an issue.   No, myspace is not work appropriate -- even if you work in skip tracing.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;75% will be infected -- what about the other 25%?  Are they "clean" from habit or luck?&lt;/li&gt;&lt;li&gt;Financially Motivated -- this is important. &lt;span style="font-weight: bold; font-style: italic;"&gt;If &lt;/span&gt;we have monetary value associated with a risk, then follow the money.  Gone are the days of nerds just playing, where attacks were loud and obvious (think Nimda, Code Red).  Now we have state sponsored hacking and even mafia supported attacks -- not to mention your own employees.  &lt;/li&gt;&lt;/ol&gt;Some thoughts&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Lock down internet access - proxy, white list -- whatever, just clean it up.&lt;/li&gt;&lt;li&gt;Monitor your email.  You would cry if you saw what was being sent outbound each day.  &lt;/li&gt;&lt;li&gt;Use&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;a href="http://www.balijon.net/marc/howto_limited.htm"&gt;&lt;/a&gt; psexec to limit browser rights or use another OS all together. Link &lt;a href="http://blogs.technet.com/markrussinovich/archive/2006/03/02/running-as-limited-user-the-easy-way.aspx"&gt;here&lt;/a&gt; -- Thanks Allen.  &lt;/li&gt;&lt;li&gt;Start thinking from the inside out.  Do you have low paid, high turnover employees, with access to valuable information? -- stuff like that. &lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-1329792744892067310?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/1329792744892067310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=1329792744892067310&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1329792744892067310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/1329792744892067310'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/gartner-highlights-key-predictions-for.html' title='Gartner Highlights Key Predictions for IT Organizations in 2007 and Beyond'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LRSPJLcRRPw/RYyZ2kcrslI/AAAAAAAAAAo/yhgkubG29fY/s72-c/g.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-8538418528822438068</id><published>2006-12-17T12:38:00.000-05:00</published><updated>2006-12-17T13:02:42.022-05:00</updated><title type='text'>Legal Aspects of Computer Security and Information Privacy</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.capitol-college.edu/academicprograms/graduateprograms/msiae/index.shtml"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_LRSPJLcRRPw/RYWBDkcrskI/AAAAAAAAAAc/Ope83CHMHPY/s200/capitol.gif" alt="" id="BLOGGER_PHOTO_ID_5009552058843116098" border="0" /&gt;&lt;/a&gt;Last week I registered for my last class at Capitol College.  My thirty fourth, fifth, and sixth credits will come from IAE-671, Legal Aspects of Computer Security and Information Privacy.  &lt;br /&gt;&lt;br /&gt;Two of the texts are: &lt;a href="http://www.amazon.com/No-Place-Hide-Robert-OHarrow/dp/0743287053/sr=8-2/qid=1166377626/ref=pd_bbs_2/002-8434322-5377654?ie=UTF8&amp;s=books"&gt;No Place to Hide&lt;/a&gt; and &lt;a href="http://www.amazon.com/Darknet-Hollywoods-Against-Digital-Generation/dp/0471683345/sr=8-1/qid=1166377626/ref=pd_bbs_sr_1/002-8434322-5377654?ie=UTF8&amp;amp;s=books"&gt;Darknet : Hollywood's War Against the Digital Generation&lt;/a&gt; (possible yawnsville).  The good news is most of our reading is provided via links to PDFs and other online information, hopefully it won't be too dated.&lt;br /&gt;&lt;br /&gt;Our professor, David Ward, is an attorney for the &lt;a href="http://www.fcc.gov/"&gt;Federal Communications   Commission&lt;/a&gt; and worked on the Communications Assistance for Law Enforcement Act (&lt;a href="http://www.fcc.gov/calea/"&gt;CALEA&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;I have high hopes for this course.  It begins the first Wednesday of the new year.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-8538418528822438068?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/8538418528822438068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=8538418528822438068&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8538418528822438068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/8538418528822438068'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/legal-aspects-of-computer-security-and.html' title='Legal Aspects of Computer Security and Information Privacy'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LRSPJLcRRPw/RYWBDkcrskI/AAAAAAAAAAc/Ope83CHMHPY/s72-c/capitol.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-2359481239529001958</id><published>2006-12-14T23:31:00.000-05:00</published><updated>2006-12-14T23:34:36.262-05:00</updated><title type='text'>IndySec 3</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://indysec.blogspot.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px;" src="http://photos1.blogger.com/blogger/1305/3581/200/indysec.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;a href="http://indysec.blogspot.com/2006/12/indysec-3-rockbottom-brew-pub.html"&gt;IndySec 3&lt;/a&gt; is December 20th.  &lt;br /&gt;&lt;br /&gt;Ain't no party like a laptop party.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-2359481239529001958?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/2359481239529001958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=2359481239529001958&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/2359481239529001958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/2359481239529001958'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/12/indysec-3.html' title='IndySec 3'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116493433858212739</id><published>2006-11-30T19:43:00.000-05:00</published><updated>2006-12-09T20:37:28.927-05:00</updated><title type='text'>(IN)SECURE</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.insecuremag.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/x/blogger/1305/3581/200/946041/insecure.png" alt="" border="0" /&gt;&lt;/a&gt;Check out the new &lt;a href="http://www.insecuremag.com/"&gt;December&lt;/a&gt; edition of (IN)SECURE magazine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116493433858212739?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116493433858212739/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116493433858212739&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116493433858212739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116493433858212739'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/11/insecure.html' title='(IN)SECURE'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116380582911403266</id><published>2006-11-17T18:18:00.000-05:00</published><updated>2007-01-02T19:20:17.619-05:00</updated><title type='text'>From www.security-forums.com</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.windowsecurity.com/img/logo-sec.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px;" src="http://www.windowsecurity.com/img/logo-sec.gif" alt="" border="0" /&gt;&lt;/a&gt;I thought I would post a reply I made to www.security-forums.com.  A poster wanted to know how he, a programmer, could go about getting into security.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.security-forums.com/viewtopic.php?p=252291#252291"&gt;Link&lt;/a&gt; to my post at www.security-forums.com&lt;br /&gt;Registration required, I know. Dumb.&lt;br /&gt;&lt;br /&gt;Hello,&lt;o:p&gt;&lt;/o:p&gt;    &lt;p class="MsoNormal"&gt;Use your background as a web programmer to boost your chance to get into infosec.&lt;span style=""&gt;   &lt;/span&gt;Start looking into application security, something like owasp.&lt;span style=""&gt;  &lt;/span&gt;I would also recommend you also shore up any weakness in networking or systems administration. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Pass&lt;/b&gt;.&lt;span style=""&gt;  &lt;/span&gt;Pass on the hype. As far as certs, pass on the CISSP - that is a management cert.&lt;span style=""&gt;  &lt;/span&gt;You are not ready for it anyway.&lt;span style=""&gt;  &lt;/span&gt;The CISSP is a management-centered cert for people with 4 years direct, full time security experience.&lt;span style=""&gt;  &lt;/span&gt;I recognize this cert blows the doors off the HR dept door.&lt;span style=""&gt;  &lt;/span&gt;I am not addressing this amazingly confusing fact in this post.&lt;span style=""&gt;  &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Read&lt;/b&gt;.&lt;span style=""&gt;   &lt;/span&gt;Read blogs, read books, just read.&lt;span style=""&gt;  &lt;/span&gt;Make best efforts to learn while reading.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Here are some of my favorites &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;*Protect Your Windows Network &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;*The TAO of Network Security Monitoring &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;*Inside Network Perimeter Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;*Malware: Fighting Malicious Code&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;*Counter Hack Reloaded&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Volunteer&lt;/b&gt;.&lt;span style=""&gt;  &lt;/span&gt;Find a church, school, a not for profit, or a networked dumpster that might let you help.&lt;span style=""&gt;  &lt;/span&gt;Maybe they need some help rolling out a new AV solution, maybe they do not have one, and maybe their only server sits under a sprinkler head – who knows. Who cares?!?&lt;span style=""&gt;  &lt;/span&gt;You do!&lt;span style=""&gt;  &lt;/span&gt;Help them, make something better, and build your experience. &lt;span style=""&gt; &lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Build a lab&lt;/b&gt;.&lt;span style=""&gt;  &lt;/span&gt;Learn VMware. Understand the value of a good lab.&lt;span style=""&gt;  &lt;/span&gt;Get access to some networking equipment.&lt;span style=""&gt;  &lt;/span&gt;Do not forget to download your favorite ISO files from the newest *.nix distro.&lt;span style=""&gt;  &lt;/span&gt;Download / Burn / Install or if using VMware&lt;span id="__firefox-findbar-search-id" style="padding: 0pt; background-color: yellow; display: inline;font-size:inherit;color:black;"  &gt;&lt;/span&gt;, download the distro, mount it under “use ISO Image” and boot away.&lt;span style=""&gt;  &lt;/span&gt;Simple. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Team Up&lt;/b&gt;.&lt;span style=""&gt;  &lt;/span&gt;Find someone who will have nerd-night with you.&lt;span style=""&gt;  &lt;/span&gt;Nerd night is your officially allocated learning time, with someone who has similar interests. Build that VM server, test running IE as an unprivileged account using psexec and visit a bunch a bad sites and scan for malware …. This is something I will be testing soon, for no real reason. &lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;Get your degree&lt;/b&gt;. If you do not have your BS, go get it.&lt;span style=""&gt;  &lt;/span&gt;View the "centers of academic excellence" of the NSA. Google on it.&lt;span style=""&gt;  &lt;/span&gt;I am working on my masters in information assurance / network security at &lt;st1:place&gt;&lt;st1:placename&gt;Capitol&lt;/st1:placename&gt;  &lt;st1:placetype&gt;College&lt;/st1:placetype&gt;&lt;/st1:place&gt;.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;b style=""&gt;Meet people.&lt;/b&gt; Want to learn more and meet others in the industry?&lt;span style=""&gt;  &lt;/span&gt;Search for local 2600 or ISSA groups.&lt;span style=""&gt;  &lt;/span&gt;If nothing is available or if those groups do not meet your needs, start your own group.&lt;span style=""&gt;  &lt;/span&gt;I started IndySec -&gt; Indysec.blogspot.com &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;b style=""&gt;Do not quit&lt;/b&gt;.&lt;span style=""&gt;  &lt;/span&gt;I put a lot of time, money, and effort to get my position in Infosec.&lt;span style=""&gt;  &lt;/span&gt;I failed several times to land a position in Infosec.&lt;span style=""&gt;  &lt;/span&gt;I could have quit and not swallowed my pride to try again, but then I would not have a rewarding career.&lt;span style=""&gt;  &lt;/span&gt;&lt;span style=""&gt;   &lt;/span&gt;&lt;br /&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;b style=""&gt;Who am I?&lt;/b&gt;&lt;span style=""&gt;  &lt;/span&gt;I am a simple person that works hard.&lt;span style=""&gt; &lt;/span&gt;&lt;br /&gt;I understand I have a lot to learn. I am also somewhat of a newbie to Infosec. &lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;              &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;Know your goals, do your best, when unsure – ask someone who knows, and never quit.&lt;span style=""&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116380582911403266?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116380582911403266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116380582911403266&amp;isPopup=true' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116380582911403266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116380582911403266'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/11/from-wwwsecurity-forumscom.html' title='From www.security-forums.com'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116328356151421189</id><published>2006-11-11T17:07:00.000-05:00</published><updated>2006-11-11T17:22:10.586-05:00</updated><title type='text'>Google Chat</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://mail.google.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 141px; height: 58px;" src="http://photos1.blogger.com/blogger/1305/3581/200/gmail.gif" alt="" border="0" /&gt;&lt;/a&gt;I use gmail and enjoy their in-browser chat client. In case you don't already know, that communication is in clear text ... sniff sniff.&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;A quick solution is to add an "s" to your url string (nothing new here).&lt;br /&gt;httpS://mail.google.com/&lt;br /&gt;&lt;br /&gt;When I have more time I will take a look at the cookie that's set by gmail chat and the related communication / reference. During a quick test last night, Wireshark complained about some of the captured traffic not being compliant ... more to come.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116328356151421189?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116328356151421189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116328356151421189&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116328356151421189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116328356151421189'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/11/google-chat.html' title='Google Chat'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116319208366769420</id><published>2006-11-10T15:54:00.000-05:00</published><updated>2006-11-11T17:42:01.343-05:00</updated><title type='text'>NIST</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://csrc.nist.gov/publications/drafts.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/Nist.gif" alt="" border="0" /&gt;&lt;/a&gt;NIST has a new draft on Intrusion Detection titled:  "Guide to Intrusion Detection and Prevention Systems".&lt;br /&gt;&lt;br /&gt;Here is a link to the &lt;a href="http://csrc.nist.gov/publications/drafts/Draft-SP800-94.pdf"&gt;PDF&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I have *not* had a chance to read the entire paper, however I did find Appendix C very interesting.&lt;br /&gt;&lt;br /&gt;Snip:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size:85%;"&gt;The lists below provide examples of tools and resources that may be helpful.&lt;br /&gt;Print Resources&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Bace, Rebecca, Intrusion Detection, Macmillan Technical Publishing, 2000.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Bejtlich, Richard, Extrusion Detection, Addison-Wesley, 2005.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Bejtlich, Richard, The Tao of Network Security Monitoring: Beyond Intrusion Detection, Addison-Wesley, 2004.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Crothers, Tim, Implementing Intrusion Detection Systems: A Hands-On Guide for Securing the Network, 2002.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Endorf, Carl et al, Intrusion Detection and Prevention, McGraw-Hill Osborne Media, 2003.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Kruegel, Chris et al, Intrusion Detection and Correlation: Challenges and Solutions, Springer, 2004.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Nazario, Jose, Defense and Detection Strategies Against Internet Worms, Artech House Publishers, 2003.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Northcutt, Stephen and Novak, Judy, Network Intrusion Detection: An Analyst’s Handbook, Third Edition, New Riders, 2003.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Rash, Michael et al, Intrusion Prevention and Active Response: Deployment Network and Host IPS, Syngress, 2005.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;It is interesting to see who did and did not make the list. I would have added a few others, however I am not NIST.  Additionally, I found this publication to be more of a management overview as opposed to a technical document.   Better off reading number 2 and 3 from the above list IMO.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116319208366769420?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116319208366769420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116319208366769420&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116319208366769420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116319208366769420'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/11/nist.html' title='NIST'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116317268105056318</id><published>2006-11-10T10:29:00.000-05:00</published><updated>2006-11-10T10:31:21.066-05:00</updated><title type='text'>IndySec 2</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://indysec.blogspot.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/indysec.jpg" alt="" border="0" /&gt;&lt;/a&gt;IndySec 2 is next Thursday, November 16th @ 6:30PM&lt;br /&gt;&lt;br /&gt;IndySec 2 Blog &lt;a href="http://indysec.blogspot.com/2006/11/indysec-2-meeting-location.html"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116317268105056318?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116317268105056318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116317268105056318&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116317268105056318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116317268105056318'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/11/indysec-2.html' title='IndySec 2'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-116118213648014362</id><published>2006-10-18T10:22:00.000-04:00</published><updated>2006-10-18T19:53:10.190-04:00</updated><title type='text'>Apologies and Job Change Information</title><content type='html'>Whew.&lt;span style=""&gt;  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Well after several application attempts, general nerding around, and study I have my first full time position in Information Security.  I will be working on the host and network protection team for a large financial firm in the &lt;st1:place&gt;Midwest&lt;/st1:place&gt;.&lt;br /&gt;&lt;p class="MsoNormal"&gt; Sorry for the lack of posts of late (looking in the mirror).  It has been a mix of SANS study, job interviews, and some other "life" events.&lt;br /&gt;&lt;br /&gt;Cheers!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-116118213648014362?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/116118213648014362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=116118213648014362&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116118213648014362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/116118213648014362'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/10/apologies-and-job-change-information.html' title='Apologies and Job Change Information'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115826852781632534</id><published>2006-09-14T16:44:00.000-04:00</published><updated>2006-09-14T17:21:21.696-04:00</updated><title type='text'>SANS Chicago</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sans.org/chicago06/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/sans_c.png" alt="" border="0" /&gt;&lt;/a&gt;SANS Chicago is only a couple of days away - I cannot wait!&lt;br /&gt;&lt;br /&gt;I just spoke with Scott Weil, Program Director, to verify some event details.  It seems the evening labs have been canceled due to Micro Closing at 6:00 PM each night and they also load us down with books.&lt;br /&gt;&lt;br /&gt;I am headed from Indianapolis to Chicago by train and have reserved a bunk at the local &lt;a href="http://www.hichicago.org/"&gt;Hostel&lt;/a&gt; about a mile away from the training facility.  As this event is being completely financed by Steve Moore Inc., being frugal was of high importance (anyone who has purchased SANS training will know what I am talking about).&lt;br /&gt;&lt;br /&gt;FYI, the train is ~ $40 US round trip and the Hostel is $28 a night.  Compared to $140 a night for a hotel, plus parking.&lt;br /&gt;&lt;br /&gt;I will do my best to report to the blog each night and share what was learned in my GSEC training.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115826852781632534?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115826852781632534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115826852781632534&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115826852781632534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115826852781632534'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/09/sans-chicago.html' title='SANS Chicago'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115782168483790343</id><published>2006-09-09T12:25:00.000-04:00</published><updated>2006-09-14T09:41:32.810-04:00</updated><title type='text'>Indianapolis ISWT</title><content type='html'>&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/indy_date.png" alt="" border="0" /&gt;Last Thursday I attended the Indianapolis Information Security &amp; Wireless Technology Conference. It was a standard event with vendors and such, with one added bonus: &lt;a href="http://www.kevinmitnick.com/"&gt;Kevin Mitnick&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Kevin spoke for around an hour about standard social engineering and then had some "live" interactive events. He shared information on how he stole the Microtek source code from Motorola and how he himself had been socially engineered prior to the release of his latest book &lt;a href="http://www.amazon.com/Art-Intrusion-Exploits-Intruders-Deceivers/dp/0764569597/sr=8-1/qid=1157821118/ref=pd_bbs_1/104-7439936-4989517?ie=UTF8&amp;amp;s=books"&gt;The Art of Intrusion&lt;/a&gt;.  During these events, he would call up audience members to participate in different activities.&lt;br /&gt;&lt;br /&gt;The most interesting portion of his speech was about a phishing / IVR dupe.  We all know about phishing and what it entails, however, now there are hackers who are recreating IVR systems and then phishing for marks to call in.  This new attack recreates an IVR (intelligent voice response) system for purposes of data collection, such as banking logins and passwords.  Kevin had used a service called &lt;a href="http://www.ipkall.com/"&gt;IPKall&lt;/a&gt; to bind a POTS number to an IP.  The IP was bound to a *nix based IVR software.  The interesting thing is Kevin also took the steps to copy the real IVR responses (and tree logic) from a real bank. With the system recreated, one could then "spear phish" customers in the area of bank X.  All password entries would give an error message, noting an incorrect password.  Kevin displayed this real time as his IVR scooped up his own self-generated traffic.&lt;br /&gt;&lt;br /&gt;Amazing.&lt;br /&gt;&lt;p style="margin-bottom: 0.2in;"&gt;Also, his business cards are metal and break up into a lock pick set.&lt;br /&gt;&lt;br /&gt;For those that may complain, I understand he is a criminal, however, it behooves us all to understand how these guys think.  They truly have no limits to their thinking and as a result are very creative.  At times, in the professional world, we allow ourselves to become too systematic in our thinking.  &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115782168483790343?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115782168483790343/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115782168483790343&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115782168483790343'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115782168483790343'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/09/indianapolis-iswt.html' title='Indianapolis ISWT'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115781651821285261</id><published>2006-09-09T11:37:00.000-04:00</published><updated>2006-11-02T16:32:08.056-05:00</updated><title type='text'>IndySec Formed</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://indysec.blogspot.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/indysec.jpg" alt="" border="0" /&gt;&lt;/a&gt;IndySec has been formed.  This is a work in progress - more information to come!&lt;br /&gt;&lt;br /&gt;IndySec Blog &lt;a href="http://indysec.blogspot.com/"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115781651821285261?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115781651821285261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115781651821285261&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115781651821285261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115781651821285261'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/09/indysec-formed.html' title='IndySec Formed'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115705003124300953</id><published>2006-08-31T13:54:00.000-04:00</published><updated>2006-08-31T14:48:31.873-04:00</updated><title type='text'>SSL Explorer</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3sp.com/showSslExplorerCommunity.do?referrer=sslexplorer"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/sslex-community.jpg" alt="" border="0" /&gt;&lt;/a&gt;While researching open source anti-virus solutions, I ran across ssl explorer from &lt;a href="http://3sp.com/"&gt;3sp&lt;/a&gt;.  SSL explorer - Community Edition is a free (as in beer) desktop-over-HTTPS tool.  The tool allows for remote management of desktops, servers and intranet resources.    &lt;br /&gt;&lt;br /&gt;I just finished watching their online Flash demonstrations and I am quite impressed.  From their site:&lt;br /&gt;&lt;blockquote&gt;SSL-Explorer is the world's first open-source, browser-based SSL VPN solution. This unique remote access solution provides users and businesses alike with a means of securely accessing network resources from outside the network perimeter using only a standard web browser.&lt;br /&gt;&lt;/blockquote&gt;While the tool looks great, their self definition is not completely correct.  SSL VPN - that's a problem.  According to the text &lt;a href="http://www.amazon.com/gp/product/0321336437/103-1270570-4361421?v=glance&amp;amp;n=283155"&gt;Protecting Your Windows Network&lt;/a&gt;, in order to be considered a VPN a tool must:&lt;br /&gt;&lt;blockquote&gt;"authenticate the end user and assign the remote node and IP address routable on the local network" p. 202.&lt;br /&gt;&lt;/blockquote&gt;A few more notables:&lt;br /&gt;1. you do not get two factor authentication with the community edition.&lt;br /&gt;2. you can register for a full featured  VMware appliance running in enterprise mode &lt;a href="http://3sp.com/showSslExplorerVMWareRegistration.do"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Visit the ssl explorer page &lt;a href="http://3sp.com/showSslExplorerCommunity.do?referrer=sslexplorer"&gt;here&lt;/a&gt;.&lt;br /&gt;And on SourceForge &lt;a href="http://sourceforge.net/projects/sslexplorer"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115705003124300953?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115705003124300953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115705003124300953&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115705003124300953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115705003124300953'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/ssl-explorer.html' title='SSL Explorer'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115696666668821748</id><published>2006-08-30T15:17:00.002-04:00</published><updated>2008-12-01T16:56:51.232-05:00</updated><title type='text'>Helix &amp; Live View</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://liveview.sourceforge.net/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/helix_live.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I just finished a class on Incident Response and Computer Forensics, so this is very exciting to me.&lt;br /&gt;&lt;br /&gt;In short, you can take Helix  and create an image using dd.  Depending on the incident, you may need to create a duplicate of the system in question.  Live View is one way an investigator can use a .dd file for some further analysis, without altering the copy!&lt;br /&gt;&lt;br /&gt;As part of my final project, I used Helix Live Acquisition software to create a copy of a logical drive.  I remember thinking how cool it would be to take that copy and somehow run it in VMware.&lt;br /&gt;&lt;br /&gt;Fast-forward a month, now we Live View. According to the Live View site:&lt;br /&gt;&lt;blockquote&gt;   Live View is a Java-based graphical forensics tool that creates a  VMware virtual machine out of a raw (dd-style) disk image or physical  disk. This allows the forensic examiner to "boot up" the image or disk  and gain an interactive, user-level perspective of the environment, all  without modifying the underlying image or disk.&lt;/blockquote&gt;So is this forensically sound?&lt;br /&gt;&lt;blockquote&gt;Because all changes made to the disk are written to a separate file, the examiner can instantly revert all of his or her changes back to the original pristine state of the disk. The end result is that one need not create extra "throw away" copies of the disk or image to create the virtual machine.&lt;/blockquote&gt;Sounds pretty nice.&lt;br /&gt;&lt;br /&gt;Live View has been talked about &lt;a href="http://isc.sans.org/diary.php?storyid=1648"&gt;here&lt;/a&gt; and &lt;a href="http://taosecurity.blogspot.com/2006/08/liveview.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Get Live View &lt;a href="http://liveview.sourceforge.net/"&gt;here&lt;/a&gt;.&lt;br /&gt;Get Helix &lt;a href="http://www.e-fense.com/helix/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115696666668821748?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115696666668821748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115696666668821748&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115696666668821748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115696666668821748'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/helix-live-view.html' title='Helix &amp; Live View'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115645096095449306</id><published>2006-08-24T16:14:00.000-04:00</published><updated>2006-08-28T08:40:09.823-04:00</updated><title type='text'>Article Review: Why home firewall software is a leaky dike</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.mg.co.za/articlePage.aspx?articleid=275381&amp;area=/insight/insight_tech/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/mail.png" alt="" border="0" /&gt;&lt;/a&gt;Awhile back, MG.com posted an interesting article on home software firewalls .  This article was also featured on &lt;a href="http://it.slashdot.org/article.pl?sid=06/08/24/136257"&gt;Slashdot.org&lt;/a&gt;.  To me there were a couple of points I wanted to blog about as some items just didn't add up.  The point of the article was to warn readers that software based firewalls are not safe, even referencing the point that if using a router with "firewall functionality", then no software firewall is needed.&lt;br /&gt;&lt;br /&gt;The article continues:&lt;br /&gt;&lt;blockquote&gt;The configuration of a personal firewall is usually more than most users can handle anyway. To understand the system's warning, the user must understand the meaning of IP addresses, host and client names as well as ports, the BSI reports. &lt;/blockquote&gt;Huh? So the software firewall is too much, but the undefined hardware router / firewall management is suitable for most "lay" (a term used later in the article) users.  And what about the idea of defense in depth?&lt;br /&gt;&lt;blockquote&gt;Users who still prefer a firewall should first check whether they are using a router with firewall functionality. If so, then no firewall is needed, including the one build in to Windows XP&lt;br /&gt;&lt;/blockquote&gt;So what kind of firewall functionality are we talking about here?  Any example? How should we configure this firewall / router?  We already identified that our reader is a lay person, so hardware is the way to go?  While having a router is a plus, all it is going to do is block ports.  Even packet filtering and stateful-inspection firewalls are not going to provide any more protection, and that is IF they have been configured properly.&lt;br /&gt;&lt;br /&gt;Software firewalls are mentioned as "extraneous" as long as the user abides by the basic rules of web surfing.  A couple of points here; first, no "rules" list was provided and second; what about other hacking related activities, such as scanning and enumeration with nmap?  A software firewall wouldn't help with that?  I know first hand it will.  A quick look at nmap versus Windows firewall will tell you that.  While on the quick topic of the Windows firewall (or any other for that matter), it will not block outbound traffic unless told to do so. This includes most of the magic "firewall routers" discussed in the article.  The thought being, "if it originates from within, it must be ok", comes to mind (which is obviously not the case).  This entire theme is skillfully discussed in the book, &lt;a href="http://www.amazon.com/gp/product/0321349962/104-4812721-8390360?v=glance&amp;n=283155"&gt;Extrusion Detection&lt;/a&gt;, by Richard Bejtlich (pronounced Bate-lik*).&lt;br /&gt;&lt;br /&gt;Here we get into usability versus security.  Many of the software vendors will not ship software that is not useable, even in the face of security. An exception to this thought - just today, a colleague told me about a new laptop that shipped with MacAfee security suite.  Security was enabled and set to "paranoid" by default. The only problem was the machine could not reach the default gateway and the NIC would not come online. How many people would have disabled the entire suite to get online?&lt;br /&gt;&lt;br /&gt;The author does get points for discussing the dangers of using administrator account(s) for anything other than installing software (or using fport!), scanning attachments,  and proper patch management.  Furthermore, end user awareness and surfing habits are covered, which is a nice to see.&lt;br /&gt;&lt;br /&gt;Pats on the back are over.  The author says JavaScript should be disabled, but fails to mention ActiveX ...  hmm.  Backups?  Covered, but mentions nothing about offsite storage.&lt;br /&gt;&lt;blockquote&gt;Backups are the safe way to go, Wolf recommends. "All important data should be regularly burned to CD or stored on a USB stick," Wolf says.&lt;br /&gt;&lt;/blockquote&gt;My problem with this article was the incomplete answers and misleading information.  I meant not to criticize, but to discuss a noteworthy article.&lt;br /&gt;&lt;br /&gt;Should you choose, you may read the full article &lt;a href="http://www.mg.co.za/articlePage.aspx?articleid=275381&amp;amp;area=/insight/insight_tech/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;*update:  The author of &lt;a href="http://www.amazon.com/gp/product/0321349962/104-4812721-8390360?v=glance&amp;n=283155"&gt;Extrusion Detection&lt;/a&gt;, Richard Bejtlich, was kind enough to correct my error.  His last name is pronounced "Bate-lik", not "bay-lic" as previously noted.  Even podcasts could not save me!  Thank you Mr. Bejtlich.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115645096095449306?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115645096095449306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115645096095449306&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115645096095449306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115645096095449306'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/article-review-why-home-firewall.html' title='Article Review: Why home firewall software is a leaky dike'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115634061499057669</id><published>2006-08-23T09:43:00.001-04:00</published><updated>2006-12-26T22:27:55.875-05:00</updated><title type='text'>CCNA</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.cisco.com/web/learning/le3/le2/le0/le9/learning_certification_type_home.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_LRSPJLcRRPw/RZHoFUcrspI/AAAAAAAAABY/i4ElmvPiVho/s200/ccna.gif" alt="" id="BLOGGER_PHOTO_ID_5013043038326076050" border="0" /&gt;&lt;/a&gt;I have decided to go for my CCNA to help round out my routing and networking skills.  Why a cert? I view certs as a way to organize my studies, enjoy learning, and set a level of achievement.  Simple.&lt;br /&gt;&lt;br /&gt;So far, my primary study method has been &lt;a href="http://www.amazon.com/gp/product/078214392X/ref=wl_it_dp/104-4812721-8390360?ie=UTF8&amp;coliid=I21W4T8XYQFY00&amp;amp;colid=IFEK5691GSYY"&gt;this&lt;/a&gt; book by Sybex; however, I will be purchasing some 2501 routers for the hands on exercises.&lt;br /&gt;&lt;br /&gt;As it stands I am on my first reading pass.  After complete my &lt;a href="http://stephenrmoore.blogspot.com/2006/08/sans-gsec.html"&gt;SANS&lt;/a&gt; training and testing, I will concentrate my studies on the CCNA. So far, I have enjoyed my new learning opportunity. I know it will be worth the effort.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115634061499057669?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115634061499057669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115634061499057669&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115634061499057669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115634061499057669'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/ccna.html' title='CCNA'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_LRSPJLcRRPw/RZHoFUcrspI/AAAAAAAAABY/i4ElmvPiVho/s72-c/ccna.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115634055059382963</id><published>2006-08-23T09:08:00.000-04:00</published><updated>2006-12-26T22:21:31.526-05:00</updated><title type='text'>New Laptop</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dell.com/content/products/productdetails.aspx/entnb_e1505?%7Eck=mn&amp;c=us&amp;amp;cs=19&amp;l=en&amp;amp;s=dhs"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 82px; height: 62px;" src="http://photos1.blogger.com/blogger/1305/3581/200/e1505-1.jpg" alt="" border="0" /&gt;&lt;/a&gt;For academic, training, and business purposes, I finally broke down and bought a laptop.  My current employer provides a very nice Dell Latitude D800; however, there are limits and strict rules as to how this hardware can be used (no SNORT allowed!).  Another motivating factor was my scheduled SANS training in Chicago. For those of you who aren't aware, SANS requires a laptop for most of the "boot camp" style training.&lt;br /&gt;&lt;br /&gt;I ended up choosing the Dell e1505 primarily based on features and value.  The e1405 is slightly smaller and around $100 more, while the e1705 is interesting, but it's just too big for my needs. From my perspective, the only important additions were the additional memory (2 GB) for running virtual machines and the WSXGA+ display for better resolution (1680x1050) and additional real-estate.&lt;br /&gt;&lt;br /&gt;Desktop space comes at a premium while doing lab work.&lt;br /&gt;&lt;br /&gt;My next step is to research the newer &lt;a href="http://en.wikipedia.org/wiki/EVDO"&gt;EVDO&lt;/a&gt;  &lt;a href="http://www.verizonwireless.com/b2c/mobileoptions/broadband/index.jsp"&gt;services&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115634055059382963?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115634055059382963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115634055059382963&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115634055059382963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115634055059382963'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/new-laptop.html' title='New Laptop'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115583680775663439</id><published>2006-08-17T13:34:00.000-04:00</published><updated>2006-08-31T16:35:45.226-04:00</updated><title type='text'>NSA Wiretaps Unconstitutional</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.nsa.gov"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/NSA-713038.jpg" alt="" border="0" /&gt;&lt;/a&gt;I have not had a chance to read all 44 pages of the .&lt;a href="http://i.a.cnn.net/cnn/2006/images/08/17/nsa.lawsuit.pdf"&gt;pdf&lt;/a&gt;, but I found this article, on &lt;a href="http://www.cnn.com/2006/POLITICS/08/17/domesticspying.lawsuit/index.html"&gt;CNN.com&lt;/a&gt;, quite interesting.&lt;br /&gt;&lt;br /&gt;A U.S. District Judge has struck down the National Security Agency’s warrentless wiretapping (and electronic surveillance) program, which was said to be a violation of privacy. Furthermore, she states:&lt;br /&gt;&lt;blockquote&gt;The president of the United States ... has undisputedly violated the Fourth in failing to procure judicial orders.&lt;br /&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115583680775663439?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115583680775663439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115583680775663439&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115583680775663439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115583680775663439'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/nsa-wiretaps-unconstitutional.html' title='NSA Wiretaps Unconstitutional'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115565490148316396</id><published>2006-08-15T11:11:00.000-04:00</published><updated>2006-08-15T18:22:31.466-04:00</updated><title type='text'>Capitol College</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.capitol-college.edu/index.php"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/320/logo1.gif" alt="" border="0" /&gt;&lt;/a&gt;I am a student at &lt;st1:place&gt;&lt;st1:placename&gt;Capitol&lt;/st1:placename&gt;  &lt;st1:placetype&gt;College&lt;/st1:placetype&gt;&lt;/st1:place&gt;, &lt;a href="http://www.capitol-college.edu/academicprograms/graduateprograms/msns/index.shtml"&gt;Graduate School of Network Security and Information Assurance&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;  &lt;p class="MsoNormal"&gt;Currently I am completing my final paper for IAE-675 Computer Forensics and Incident Handling.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;I researched live acquisition of forensic data on compromised hosts, using &lt;a href="http://www.e-fense.com/helix/"&gt;Helix&lt;/a&gt; from &lt;a href="http://www.e-fense.com"&gt;e-fense&lt;/a&gt;. On August 9, I presented my findings to my peers.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Capitol offers online, live graduate classes in Information Assurance. Download a PDF fact sheet &lt;a href="http://www.capitol-college.edu/Asset/iu_files/msiaefacts.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115565490148316396?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115565490148316396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115565490148316396&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115565490148316396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115565490148316396'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/capitol-college.html' title='Capitol College'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115561432643546811</id><published>2006-08-14T23:35:00.000-04:00</published><updated>2006-08-17T14:07:31.346-04:00</updated><title type='text'>ISSA</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.issa.org"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/issa.0.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I am a student member of the &lt;a href="http://www.issa.org"&gt;Information Systems Security Association&lt;/a&gt;. The ISSA is looking for volunteers to help with various activities.  As they are a worthwhile organization, I offered to volunteer my time.&lt;br /&gt;&lt;br /&gt;My query went to Mr. Tierney to learn more about their certification programs committee. I have a natural interest in teaching, education and the value of certifications. I will send an update when I receive a reply.&lt;br /&gt;&lt;p class="MsoNormal"&gt; What is the Certification Programs Committee? From their web site:&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;b&gt;&lt;i&gt;Certification Programs Committee&lt;/i&gt;:&lt;/b&gt; To evaluate and report to the membership on industry certification programs, and to offer suggestions for their improvement.&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115561432643546811?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115561432643546811/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115561432643546811&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115561432643546811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115561432643546811'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/issa.html' title='ISSA'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32727974.post-115561229790646053</id><published>2006-08-14T23:06:00.000-04:00</published><updated>2006-08-31T16:35:15.093-04:00</updated><title type='text'>SANS GSEC</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sans.org"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/1305/3581/200/sans.0.gif" alt="" border="0" /&gt;&lt;/a&gt;I will be going to SANS Chicago GSEC training. This is something I have wanted to do for quite some time, but couldn't spare the money.&lt;br /&gt;&lt;br /&gt;From this event I hope to meet some new security professionals, add to my skills and bolster my security marketability.&lt;br /&gt;&lt;br /&gt;Learn more about the class &lt;a href="http://www.sans.org/chicago06/description.php?tid=240"&gt;here&lt;/a&gt;. After the 6 days training, I will sit for the exam and begin working on my research paper.&lt;br /&gt;&lt;br /&gt;The training runs from Monday September 18, 2006 to Saturday September 23, 2006.&lt;br /&gt;&lt;br /&gt;Per the GIAC &lt;a href="http://www.giac.org/certifications/security/gsec.php"&gt;site&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;GIAC Security Essentials Certification graduates have been taught the knowledge, skills and abilities required to incorporate good information security practice in any organization. The GSEC tests the essential knowledge and skills required of any individual with security responsibilities within an organization.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32727974-115561229790646053?l=stephenrmoore.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stephenrmoore.blogspot.com/feeds/115561229790646053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32727974&amp;postID=115561229790646053&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115561229790646053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32727974/posts/default/115561229790646053'/><link rel='alternate' type='text/html' href='http://stephenrmoore.blogspot.com/2006/08/sans-gsec.html' title='SANS GSEC'/><author><name>Steve</name><uri>http://www.blogger.com/profile/02879524826537107461</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
