<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Uncategorized</title>
	<atom:link href="http://infosec3t.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>Staying safe on public Wi-Fi</title>
		<link>http://infosec3t.com/2010/04/14/staying-safe-on-public-wi-fi/</link>
		<comments>http://infosec3t.com/2010/04/14/staying-safe-on-public-wi-fi/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 17:04:02 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2087</guid>
		<description><![CDATA[Picture this: You&#8217;re at a café with your laptop and latte in hand, getting ready to review new sales leads and the quarterly financial projections. First you hop on the free Wi-Fi that the shop&#8217;s management provides. Then you connect your laptop to a projector so that the entire café can take a look, and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2091" title="WiFiZone" src="http://infosec3t.com/wp-content/uploads/2010/04/WiFiZone-300x217.gif" alt="" width="213" height="154" />Picture this: You&#8217;re at a café with your laptop and latte in hand, getting ready to review new sales leads and the quarterly financial projections. First you hop on the free Wi-Fi that the shop&#8217;s management provides. Then you connect your laptop to a projector so that the entire café can take a look, and finally you hand out some printed copies of your confidential product specifications to the other patrons so that they can follow along. That may sound ridiculous, but if you&#8217;re using public-access Wi-Fi without taking the proper precautions, you might as well be asking your coffee compatriots to partake in confidential company information.</p>
<p>That&#8217;s an abstract from a pretty good article in NetworkWorld. I previously also posted about the <strong><a href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/">dangers of public wireless networks.<br />
</a></strong></p>
<p>Consider however, how probably is it that a competitor or anyone else for that matter is lurking steal your data? You don&#8217;t know and neither do I. Just remember that it&#8217;s very easy to do so protect yourself.</p>
<p>Read full article: <a href="http://www.networkworld.com/news/2010/041310-how-to-stay-safe-on.html" target="_blank">http://www.networkworld.com/news/2010/041310-how-to-stay-safe-on.html</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/issa-nova-chapter-december-meeting/' rel='bookmark' title='ISSA-NOVA Chapter December Meeting'>ISSA-NOVA Chapter December Meeting</a> <small>The Northern Virginia Chapter of the Information System Security Association...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/14/staying-safe-on-public-wi-fi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIST Guidelines for Secure Deployment of IPv6</title>
		<link>http://infosec3t.com/2010/02/26/nist-guidelines-for-secure-deployment-of-ipv6/</link>
		<comments>http://infosec3t.com/2010/02/26/nist-guidelines-for-secure-deployment-of-ipv6/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 19:17:17 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ipv6]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1625</guid>
		<description><![CDATA[If it ever happens&#8230;&#8230; Download link: http://csrc.nist.gov/publications/drafts/800-119/draft-sp800-119_feb2010.pdf Related posts: CISSP All In One Book FIFTH EDITION has been released The fifth edition of this best-selling comprehensive CISSP training resources... More on Forensics&#8230; Follow what the NOVA Information Assurance Strike Team is up... 2010 CyberSecurity Watch Survey Cybercrime threats posed to targeted organizations are increasing faster [...]]]></description>
			<content:encoded><![CDATA[<p>If it ever happens&#8230;&#8230;</p>
<p>Download link: http://csrc.nist.gov/publications/drafts/800-119/draft-sp800-119_feb2010.pdf</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/26/nist-guidelines-for-secure-deployment-of-ipv6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Guide to Computer Security</title>
		<link>http://infosec3t.com/2010/02/21/a-guide-to-computer-security/</link>
		<comments>http://infosec3t.com/2010/02/21/a-guide-to-computer-security/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 21:58:42 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1218</guid>
		<description><![CDATA[As the number of people connecting to the Internet continues to increase at a rapid pace, more and more of us are now creating our own home computer networks. With these we can enjoy the benefits of having high bandwidth, instant access to the Internet and make this connection available to multiple computers in and around the home. But for those unfamiliar with computer security, they are completely unaware of the risks they may be exposing their computer to.]]></description>
			<content:encoded><![CDATA[<p>As the number of people connecting to the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> continues to increase at a rapid pace, more and more of us are now creating our own home computer networks.<br />
With these we can enjoy the benefits of having high bandwidth, instant access to the Internet and make this connection available to multiple computers in and around the home.<br />
But for those unfamiliar with computer security, they are completely unaware of the risks they may be exposing their computer to.<br />
Without implementing a proper computer security solution, your computer may become infected with viruses, spyware, and/or adware.  These are all forms of malware than can play a part in rendering a computer unusable, destroy valuable information your storing, provide complete control of a computer to another person, allow someone to steal the information on your computer, record your keystrokes and give a 3rd party access to your online bank account, allow someone to use your computer to attack a computer belonging to somebody else, etc.<br />
And if you opted for a <a href="http://infosec3t.com/tag/wireless/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Wireless">wireless</a> network, you could be sharing out your Internet connection to your neighbors or that person who has been sitting outside your house in the car for the last few hours.  What is more, you are increasing the <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> of exposing your own computer to hackers as a result.<br />
<strong><span style="text-decoration: underline;">So What Are The Basics of Computer Security?</span></strong></p>
<ol>
<li>Make sure that the link between you and the Internet is safe.You need to have a hardware firewall installed between you and the Internet.  Most recent devices that connect you to the Internet have one built in, but in any case you need to make sure that what you have is a stateful firewall.It should give your computer full access to the Internet, but block all traffic trying to access your network when originated from the Internet side.</li>
<li>Secure your Internet router.Change the administrator password and if possible the administrative account name as well.  Everyone who has bought that device will know what the default account and password is, so you must change these and make them difficult to guess.  This is especially important if you have a wireless network.</li>
<li>Install anti-virus software on your computer.Make sure it scans the computer for viruses at least once a week.  Keep the software up to date and make sure that the virus definitions are updated every day.  Also make sure that this is monitoring the computer all the time to help prevent it being infected in the first place.</li>
<li>Install a personal firewall on your computer.Not only should this help limit the damage malware can do to your computer, but it should also reduce the chances of this spreading to other computers.  Get in the habit of checking the dialogues that you are prompted with and only allow Internet access to applications that really need it.</li>
<li>Install anti-spyware software on your computer.Make sure it fully scans your computer for spyware at least every week.  Keep the software up to date and make sure that the definitions are updated every day.  Also make sure that this monitors your computer all the time.</li>
<li>Keep up to date with the security patches for your Operating System.<a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> release security updates for Windows every month.  However, make sure your computer is configured to automatically check for downloads every day and at a time when your computer is most likely to be turned on.</li>
<li>Secure your wireless network.Do not broadcast your SSID (Service Set IDentifier).  Although it can be learned by someone who is determined, there is no point making things easy.  So make sure this is disabled. Restrict access to your wireless network based on the MAC (Media Access Control) address of your computer.  Yes, these can be faked, once known, but why make things simple?Implement WPA (Wi-Fi Protected Access) or WPA2, if you can, to further secure your wireless network.  And use a pre-shared key which is not easy to guess.</li>
</ol>
<p><strong><span style="text-decoration: underline;">Conclusion</span></strong><br />
Although, you can never make a computer 100% secure, the objective is to put as many obstacles in the way and put off the casual hacker. So by following these 7 basic steps you will have a more secure computing environment. And remember, by implementing proper computer security on our own computer, we are making the Internet a safer place to surf for everyone.</p>
<p>Author: David S McKone<br />
Article Source: EzineArticles.com</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/' rel='bookmark' title='SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks'>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</a> <small>Across all industries, small businesses are increasingly facing new threats...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/interested-in-computer-forensics/' rel='bookmark' title='Interested in Computer Forensics?'>Interested in Computer Forensics?</a> <small>I recently went through an EC Council Computer Hacking Forensic...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/' rel='bookmark' title='Microsoft offering choice of browser to users in Europe'>Microsoft offering choice of browser to users in Europe</a> <small>Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221;...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/21/a-guide-to-computer-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defend your Small Business against Online Bank Fraud</title>
		<link>http://infosec3t.com/2010/02/08/defend-your-small-business-against-online-bank-fraud/</link>
		<comments>http://infosec3t.com/2010/02/08/defend-your-small-business-against-online-bank-fraud/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 00:08:34 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malicious Web site]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1421</guid>
		<description><![CDATA[Is your banking practices putting your business at risk? Protect your small business accounts from cybercriminals. The Wall Street Journal offers the following suggestions for small businesses seeking to ward off an attack: Defend your Computer Hackers often take aim at small firms&#8217; computers because they are easier to infiltrate than banks&#8217; systems. One common [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1423" title="credit-card-fraud" src="http://infosec3t.com/wp-content/uploads/2010/02/credit-card-fraud-300x271.jpg" alt="" width="252" height="228" />Is your banking practices putting your business at <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a>? Protect your small business accounts from cybercriminals. The <a href="http://online.wsj.com/article/SB10001424052748703483604574630690362605018.html?mod=WSJ_FinancingAndInvesting_LeadStory" target="_blank">Wall Street Journal</a> offers the following suggestions for small businesses seeking to ward off an attack:</p>
<p><strong>Defend your Computer</strong></p>
<p>Hackers often take aim at small firms&#8217; computers because they are easier to infiltrate than banks&#8217; systems. One common mode of attack is to send a &#8220;spear phishing&#8221; <a href="http://infosec3t.com/tag/email-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Email">email</a> containing an infected file or a link to a malicious Web site to employees with access to the firm&#8217;s financial accounts. Once the employee opens the attachment or goes to the Web site, malware is installed on the computer that allows criminals to access banking logins and passwords. While up-to-date antivirus software offers substantial protection against malware, it isn&#8217;t 100% effective.</p>
<p>Accessing your bank account through a computer that isn&#8217;t used for anything else—no email or Web surfing—and isn&#8217;t connected to the local network offers strong protection, says William Nelson, president of the Financial Services Information Sharing and Analysis Center, an industry group that collects and shares threat data.</p>
<p>Another option is to use an obscure computer operating system such as Ubuntu or Web browser such as Opera because attackers rarely create malware for them, security experts say.</p>
<p>If you use Microsoft Corp.&#8217;s <a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a> browser, make sure you have the latest version, IE 8, which includes security features to help prevent attacks. Consider using Explorer in &#8220;protected mode,&#8221; which restricts files that try to install on a computer without the user&#8217;s consent, and set your &#8220;Internet zone security&#8221; to &#8220;high,&#8221; which disables some of Explorer&#8217;s less-secure features, according to Microsoft.</p>
<p><strong>Protect your Accounts</strong></p>
<p>Ask your bank to set up &#8220;dual controls&#8221; on your account so that each transaction requires the approval of two people—a good guard against fraud, security experts say. Establish a daily limit on how much money can be transferred out of your account, and require that all transfers be prescheduled by phone or confirmed via phone call or text message. If possible, impose restrictions on adding new payees, security experts say.</p>
<p>Check bank balances and scheduled payments at the end of every workday, rather than the beginning, and immediately contact your bank if anything is amiss. Banks use the Automated Clearing House system to transfer funds to payees&#8217; banks. These transfers usually aren&#8217;t paid until the next morning, so timely action could halt the completion of a fraudulent transaction, Mr. Nelson says.</p>
<p><strong>Shop for a Bank</strong></p>
<p>Review your agreement with your bank and know what rights you may be waiving by not using certain security measures. While agreements between banks and commercial customers typically absolve banks of responsibility for fraud losses, the bank down the street may offer better protections, so shop around. Also, consider adding insurance coverage for fraud losses.</p>
<p>Many banks, concerned about damage to customer relationships, have stepped up their defenses against cyberattacks, rolled out new protections for customers and begun sharing more threat information with each other and law enforcement, Mr. Nelson says.</p>
<p>An emerging motivator may be a growing number of lawsuits by small companies claiming their banks didn&#8217;t have &#8220;commercially reasonable&#8221; security.</p>
<p>A judge in a closely watched case involving a self-employed couple&#8217;s personal and commercial accounts said in refusing to grant a summary judgment that a jury might find fault with the adequacy of the bank&#8217;s defenses, which the plaintiffs argued weren&#8217;t state of the art at the time of the theft. The case—Shames-Yeakel vs. Citizens Financial Bank—was settled in late December under confidential terms. The plaintiff&#8217;s lawyer, John Soumilas of Francis &amp; Mailman PC in Philadelphia, says he pursued the case as one of consumer-identify theft, where protections are ample.</p>
<p>Still, David D. Johnson, a digital-media lawyer at Jeffer, Mangels, Butler &amp; Marmaro LLP in Los Angeles who wasn&#8217;t involved in the case, says the judge&#8217;s action suggests that &#8220;a bank can&#8217;t simply rest on its laurels, on its security measures that worked last year,&#8221; and avoid liability. The judge declined to comment, and Citizens Financial didn&#8217;t return a call for comment.</p>
<p><strong>Reach Out</strong></p>
<p>Connect with law-enforcement agencies before an incident occurs, suggests Mr. Henry. He says small businesses should consider joining the FBI&#8217;s InfraGard, a group of businesses, academic institutions and state and local law-enforcement agencies that seek to ward off cyberattacks and other <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> by sharing information and intelligence.</p>
<p>He also urges companies to report all computer crimes immediately to the FBI. The agency has relationships with law-enforcement organizations around the world that are starting to bear fruit, he says, pointing to the recent arrest of 120 people tied to Romanian groups that allegedly stole money from U.S. companies and citizens.</p>
<p>&#8220;In the cases where we have put hands on somebody, it was the result of a victim company raising their hand and saying this happened,&#8221; Mr. Henry says. &#8220;If they hit you today, they&#8217;re hitting the guy down the street tomorrow.&#8221;</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/21/a-guide-to-computer-security/' rel='bookmark' title='A Guide to Computer Security'>A Guide to Computer Security</a> <small>As the number of people connecting to the Internet continues...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/online-creditdebit-card-security-failure/' rel='bookmark' title='Online Credit/Debit Card Security Failure'>Online Credit/Debit Card Security Failure</a> <small>Ross Anderson reports: Online transactions with credit cards or debit...</small></li>
<li><a href='http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/' rel='bookmark' title='SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks'>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</a> <small>Across all industries, small businesses are increasingly facing new threats...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/08/defend-your-small-business-against-online-bank-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shmoocon 2010 Videos Online</title>
		<link>http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/</link>
		<comments>http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 03:23:05 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1403</guid>
		<description><![CDATA[Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this year. The darn things sell out too quickly. If I had known Washington, DC would be buried under more than two feet of snow, I wouldn&#8217;t have been upset at my supposed misfortune. For the first time, the presentations were streamed live over the internet [...]]]></description>
			<content:encoded><![CDATA[<p><a title="Last chance for Shmoocon 2010 tickets!" href="http://infosec3t.com/2009/12/30/last-chance-for-shmoocon-2010-tickets/"><img class="alignright size-full wp-image-1404" title="shmoocon-hacker-conference-videos" src="http://infosec3t.com/wp-content/uploads/2010/02/shmoocon-hacker-conference-videos.gif" alt="" width="150" height="150" />Shmoocon</a> was this weekend. Unfortunately,I couldn&#8217;t get a ticket this year. The darn things sell out too quickly. If I had known Washington, DC would be buried under more than two feet of snow, I wouldn&#8217;t have been upset at my supposed misfortune. For the first time, the presentations were streamed live over the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">internet</a> as most who had gotten tickets would not have been able to make it due to the weather. The recorded presentations can be viewed at the <a href="http://infosec3t.com/tag/shmoocon/" class="st_tag internal_tag" rel="tag" title="Posts tagged with shmoocon">Shmoocon</a> web site.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/30/last-chance-for-shmoocon-2010-tickets/' rel='bookmark' title='Last chance for Shmoocon 2010 tickets!'>Last chance for Shmoocon 2010 tickets!</a> <small>Every year since 2005, security professionals and aspirants gather in...</small></li>
<li><a href='http://infosec3t.com/2010/01/01/clubhack-2009-presentations/' rel='bookmark' title='ClubHack 2009 Presentations'>ClubHack 2009 Presentations</a> <small>ClubHack is an &#8220;international&#8221; hacker conference in India started in...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Stop 11 Hidden Security Threats</title>
		<link>http://infosec3t.com/2010/01/25/stop-11-hidden-security-threats/</link>
		<comments>http://infosec3t.com/2010/01/25/stop-11-hidden-security-threats/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 23:48:32 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1010</guid>
		<description><![CDATA[Do you know how to guard against scareware? How about Trojan horse text messages? Or social network data harvesting? Malicious hackers are a resourceful bunch, and their methods continually evolve to target the ways we use our computers now. New attack techniques allow bad guys to stay one step ahead of security software and to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/isitsafe.jpg"><img class="alignleft size-thumbnail wp-image-1012" title="isitsafe" src="http://infosec3t.com/wp-content/uploads/2010/01/isitsafe-150x150.jpg" alt="" width="150" height="150" /></a>Do you know how to guard against scareware? How about Trojan horse text messages? Or social network data harvesting? Malicious    hackers are a resourceful bunch, and their methods continually evolve to target the ways we use our computers now. New attack    techniques allow bad guys to stay one step ahead of <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> software and to get the better of even cautious and well-informed PC users.</p>
<p>These threats include <a title="Brevity is the soul of…..getting yourself infected with all kinds of nasties!" href="http://infosec3t.com/2010/01/09/brevity-is-the-soul-of-getting-yourself-infected-with-all-kinds-of-nasties/">shortened urls</a>, <a title="Fake Security Software pose great risk" href="http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/">scareware</a>, <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/">rougue Wi-Fi hotspots</a>, etc.</p>
<p>Don&#8217;t let that happen to you. Here are  descriptions of 11 of the most recent and most malignant security threats, as well as complete advice on how to halt them in their tracks.</p>
<p>Read full article at <a title="Stop 11 Hidden Security Threats" href="http://www.networkworld.com/news/2010/012510-stop-11-hidden-security.html?page=1" target="_blank">http://www.networkworld.com/news/2010/012510-stop-11-hidden-security.html?page=1</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
<li><a href='http://infosec3t.com/2009/12/10/cloud-security-alliance/' rel='bookmark' title='Cloud Security Alliance'>Cloud Security Alliance</a> <small>For more information on Cloud Computing Security, a good resource...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/25/stop-11-hidden-security-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP All In One Book FIFTH EDITION has been released</title>
		<link>http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/</link>
		<comments>http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 04:52:57 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cissp]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=907</guid>
		<description><![CDATA[The fifth edition of this best-selling comprehensive CISSP training resources was released on January 15, 2010. After taking the CISSP certification examination, I found that this was by far the text that came closest to covering the breath of the concepts on the exam and in the appropriate depth. The CISSP exam is often referred [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.amazon.com/dp/0071602178?tag=intotith-20&amp;camp=213381&amp;creative=390973&amp;linkCode=as4&amp;creativeASIN=0071602178&amp;adid=08ABX1Y39BMWNCGH6H6R&amp;"><img class="size-thumbnail wp-image-908 alignleft" title="cissp" src="http://infosec3t.com/wp-content/uploads/2010/01/cissp-150x150.jpg" alt="" width="150" height="150" /></a>The fifth edition of this best-selling comprehensive <a href="http://infosec3t.com/tag/cissp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cissp">CISSP</a> <a href="http://infosec3t.com/tag/training/" class="st_tag internal_tag" rel="tag" title="Posts tagged with training">training</a> resources was released on January 15, 2010. After taking the <a href="http://infosec3t.com/tag/cissp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cissp">CISSP</a> certification examination, I found that this was by far the text that came closest to covering the breath of the concepts on the exam and in the appropriate depth. The <a href="http://infosec3t.com/tag/cissp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cissp">CISSP</a> exam is often referred to as &#8220;mile wide and inch deep&#8221; because it thrives to cover all aspects of information <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> without getting too far in the weeds.</p>
<p>This book is written by the bestselling author and a respected IT security trainer Shon Harris. It serves as both a comprehensive certification study guide and student work book, and a fundamental on-the-job reference. The included CD-ROM includes more than 800 simulated practice questions in a <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a>-based test engine, an electronic book, and video training from  the author. <a href="http://infosec3t.com/wp-content/uploads/2010/01/shonharris.jpg"><img class="alignright size-thumbnail wp-image-912" title="shonharris" src="http://infosec3t.com/wp-content/uploads/2010/01/shonharris-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p>I personally recommend it. Most people who had previously taken the CISSP exam told me how hard it was . I believed them. And as I did not intend to take it twice. I invested a lot of time ( 6 months ) in preparing.  I left the exam hall after three and a half hours feeling pretty confident. Thanks, partly to Shon Harris, I was well prepared and found the exam to be relatively easy.  More details on the text can be found<a title="CISSP All in One book" href="http://www.amazon.com/dp/0071602178?tag=intotith-20&amp;camp=213381&amp;creative=390973&amp;linkCode=as4&amp;creativeASIN=0071602178&amp;adid=08ABX1Y39BMWNCGH6H6R&amp;" target="_blank"><strong> here</strong></a>.</p>
<p>Other CISSP training can also be locate<a title="CISSP Prep" href="http://infosec3t.com/certifications/buy-cissp-prep/"> <strong>here</strong></a>.</p>
<div>
<p><strong> </strong></p>
</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/interested-in-computer-forensics/' rel='bookmark' title='Interested in Computer Forensics?'>Interested in Computer Forensics?</a> <small>I recently went through an EC Council Computer Hacking Forensic...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/issa-nova-chapter-december-meeting/' rel='bookmark' title='ISSA-NOVA Chapter December Meeting'>ISSA-NOVA Chapter December Meeting</a> <small>The Northern Virginia Chapter of the Information System Security Association...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of Haiti-Themed Scams and Attacks!</title>
		<link>http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/</link>
		<comments>http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 19:40:46 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=713</guid>
		<description><![CDATA[Our thoughts and prayers go out to all those affected by the tragedy in Haiti. To make matters worse, as is often the case with any incident that captures the attention of the multitudes, cyber-crooks are doing all they can to take advantage of the unsuspecting web browser looking for information of ways to help. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/scam.jpeg"><img class="alignleft size-full wp-image-714" title="scam" src="http://infosec3t.com/wp-content/uploads/2010/01/scam.jpeg" alt="" width="130" height="73" /></a> Our thoughts and prayers go out to all those affected by the tragedy in Haiti. To make matters worse, as is often the case with any incident that captures the attention of the multitudes, cyber-crooks are doing all they can to take advantage of the unsuspecting web browser looking for information of ways to help.</p>
<p>There are a large number of domains being registered and parked relating to the disaster. Not all of these are malicious naturally however if we learned anything from Hurricane Katrina, this is a precedent to cynical <a href="http://infosec3t.com/tag/scams/" class="st_tag internal_tag" rel="tag" title="Posts tagged with scams">scams</a> attempted to exploit the generosity of the unsuspecting. Scammers use a variety of means to drive traffic including promoting on social networks like <a href="http://infosec3t.com/tag/twitter/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Twitter">Twitter</a>, <a href="http://infosec3t.com/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> and MySpace, paid advertising, and search engine manipulation. <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> Research Firm Websense reported that search terms relating to the earthquake are leading to a rouge anti-virus program. Since you should already have anti-virus software installed, updated and running on your computer, cancel out of any suspicious alerts and run a scan using your own anti-virus software. A video demonstrating search engine manipulation can be found <a href="http://www.youtube.com/user/wslabsutube#p/a/u/1/XjqVp5mc7DM" target="_blank">here</a>. Once on the site, attackers may also tempt users to download malware in the guise of video reports about the disaster.</p>
<p>Those looking to make donations will be well-advised to go directly to the <a title="IFRC" href="http://www.ifrc.org/" target="_blank">web site</a> of the International Federation of Red Cross and Red Crescent  Societies. The FBI has also posted an alert warning of possible charity donation scams. The IRS also maintain a <a title="IRS List" href="http://www.irs.gov/app/pub-78/" target="_blank">list</a> of tax exempt charitable organizations. This can serve as a check as well.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/28/beware-of-chile-earthquake-scams/' rel='bookmark' title='Beware of Chile Earthquake Scams'>Beware of Chile Earthquake Scams</a> <small>An 8.8 magnitude earthquake struck Santiago, Chile in the early...</small></li>
<li><a href='http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/' rel='bookmark' title='Fake Security Software pose great risk'>Fake Security Software pose great risk</a> <small>Desktop Security 2010 is the proverbial wolf in sheep&#8217;s clothing....</small></li>
<li><a href='http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/' rel='bookmark' title='If Microsoft can do it, why not McAfee?'>If Microsoft can do it, why not McAfee?</a> <small>Yesterday, a faulty McAfee anti-virus update labeled a critical Microsoft...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Black Hat DC -2010 is here!</title>
		<link>http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/</link>
		<comments>http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/#comments</comments>
		<pubDate>Sat, 02 Jan 2010 21:04:55 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=584</guid>
		<description><![CDATA[Black Hat, one of the biggest and most popular security conferences in the world, will have its DC event at the Crystal City Hyatt Regency from Jan 31 to Feb 3. Black Hat was founded by Jeff Moss, one of the most sought after security voices in the world. The conference is composed of two [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/tag/black-hat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Black Hat">Black Hat</a>, one of the biggest and most popular <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> conferences in the world, will have its DC event at the Crystal City Hyatt Regency from Jan 31 to Feb 3. <a href="http://infosec3t.com/tag/black-hat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Black Hat">Black Hat</a> was founded by Jeff Moss, one of the most sought after security voices in the world. The conference is composed of two major sections, Presentations and <a href="http://infosec3t.com/tag/training/" class="st_tag internal_tag" rel="tag" title="Posts tagged with training">Training</a>. Regular tickets for the presentations ( referred to as briefings)  go for $1495 (ouch) until Jan 15 and then  for $1695 until Jan 30. Tickets will be sold on site for $1995. The list for speakers and topics can be found at <a title="Black Hat 2010 Speakers" href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-briefings.html" target="_blank">www.blackhat.com</a>. There are also a host of security related training courses held during the event. The course cost from $1800 to $3800 per course. The complete list can be found <a title="Black Hat Training" href="http://www.blackhat.com/html/bh-dc-10/training/bh-dc-10-training_complete.html" target="_blank">here</a>.</p>
<p>An archive of presentations from previous years can be found at <a title="Black Hat Archives" href="http://www.blackhat.com/html/bh-media-archives/bh-multi-media-archives.html" target="_blank">Black Hat Media Archives</a>. This includes presentations from all Back Hat events.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/12/black-hat-dc-2010-presentations-are-now-available/' rel='bookmark' title='Black Hat DC 2010 Presentations are now available'>Black Hat DC 2010 Presentations are now available</a> <small>If you couldn&#8217;t afford to make it to Black Hat...</small></li>
<li><a href='http://infosec3t.com/2010/01/01/clubhack-2009-presentations/' rel='bookmark' title='ClubHack 2009 Presentations'>ClubHack 2009 Presentations</a> <small>ClubHack is an &#8220;international&#8221; hacker conference in India started in...</small></li>
<li><a href='http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/' rel='bookmark' title='Shmoocon 2010 Videos Online'>Shmoocon 2010 Videos Online</a> <small>Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ClubHack 2009 Presentations</title>
		<link>http://infosec3t.com/2010/01/01/clubhack-2009-presentations/</link>
		<comments>http://infosec3t.com/2010/01/01/clubhack-2009-presentations/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 16:02:01 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=581</guid>
		<description><![CDATA[ClubHack is an &#8220;international&#8221; hacker conference in India started in 2007. Although this is only the third year, some of the presentations are pretty interesting. See  http://clubhack.com/2009/presentations Related posts: CISSP All In One Book FIFTH EDITION has been released The fifth edition of this best-selling comprehensive CISSP training resources... More on Forensics&#8230; Follow what the [...]]]></description>
			<content:encoded><![CDATA[<p>ClubHack is an &#8220;international&#8221; hacker conference in India started in 2007. Although this is only the third year, some of the presentations are pretty interesting. See  <a title="ClubHack Presentations" href="http://clubhack.com/2009/presentations" target="_blank">http://clubhack.com/2009/presentations</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/01/clubhack-2009-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Best Practices for Security Assurance in the Cloud</title>
		<link>http://infosec3t.com/2010/01/01/new-practices-for-security-assurance-in-the-cloud/</link>
		<comments>http://infosec3t.com/2010/01/01/new-practices-for-security-assurance-in-the-cloud/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 15:34:07 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cloud computing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=577</guid>
		<description><![CDATA[The Cloud Security Alliance (CSA) produced version 2 of its &#8220;Guidance for Critical Areas of Focus in Cloud Computing&#8221; whitepaper.  CSA is a non-profit organization formed to promote the use of best practices for providing security assurance within cloud computing, and provide education on the uses  of cloud computing to help secure all other forms [...]]]></description>
			<content:encoded><![CDATA[<p>The <a title="Cloud Security Alliance" href="http://infosec3t.com/2009/12/10/cloud-security-alliance/">Cloud Security Alliance (CSA)</a> produced version 2 of its &#8220;Guidance for Critical Areas of Focus in <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">Cloud Computing</a>&#8221; whitepaper.  CSA is a non-profit organization formed to promote the use of best practices for providing <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> assurance within cloud computing, and provide education on the uses  of cloud computing to help secure all other forms of computing. The whitepaper outlines key issues and offers advice both to customers and providers in 13 strategic domains. This version takes into account experience and lessons learn from real world deployments over the past six months.</p>
<p>See <a title="Cloud computing Guidance" href="http://www.cloudsecurityalliance.org/guidance" target="_blank">www.cloudsecurityalliance.org/guidance</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/10/cloud-security-alliance/' rel='bookmark' title='Cloud Security Alliance'>Cloud Security Alliance</a> <small>For more information on Cloud Computing Security, a good resource...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/' rel='bookmark' title='The real arguments for Cloud Computing'>The real arguments for Cloud Computing</a> <small>As more vendors dive into the cloud computing market, every...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/01/new-practices-for-security-assurance-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Happy New Year 2010!</title>
		<link>http://infosec3t.com/2009/12/31/happy-new-year-2010/</link>
		<comments>http://infosec3t.com/2009/12/31/happy-new-year-2010/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 03:18:15 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=485</guid>
		<description><![CDATA[Here&#8217;s to a more prosperous 2010. Related posts: Security Management Series &#8211; Part I -The Foundation The foundation of any security program should be based on... United States Department of Defense Embraces Hacker Certification Mar 01, 2010 – The U.S. Department of Defense (DoD)... More on Forensics&#8230; Follow what the NOVA Information Assurance Strike Team [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here&#8217;s to a more prosperous 2010. </strong></p>
<p><a href="http://infosec3t.com/wp-content/uploads/2009/12/happy-new-year.jpg"><img class="size-full wp-image-493 alignleft" title="happy-new-year" src="http://infosec3t.com/wp-content/uploads/2009/12/happy-new-year.jpg" alt="" width="512" height="384" /></a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/30/security-management-series-part-i-the-foundation/' rel='bookmark' title='Security Management Series &#8211; Part I -The Foundation'>Security Management Series &#8211; Part I -The Foundation</a> <small>The foundation of any security program should be based on...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/31/happy-new-year-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Last chance for Shmoocon 2010 tickets!</title>
		<link>http://infosec3t.com/2009/12/30/last-chance-for-shmoocon-2010-tickets/</link>
		<comments>http://infosec3t.com/2009/12/30/last-chance-for-shmoocon-2010-tickets/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 19:50:21 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=204</guid>
		<description><![CDATA[Every year since 2005, security professionals and aspirants gather in Washington, D.C. for Shmoocon. Shmoocon is an annual hacker convention held by the Shmoo Group. It is three days of informative, fun, entertaining presentations about new hacking exploits, methodology and technology. The 2010 convention will be held on February 5-7. Space is limited and it [...]]]></description>
			<content:encoded><![CDATA[<p>Every year since 2005, <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> professionals and aspirants gather in Washington, D.C. for <a href="http://www.shmoocon.org/">Shmoocon</a>. <a href="http://infosec3t.com/tag/shmoocon/" class="st_tag internal_tag" rel="tag" title="Posts tagged with shmoocon">Shmoocon</a> is an annual hacker convention held by the Shmoo Group. It is three days of informative, fun, entertaining presentations about new <a href="http://infosec3t.com/tag/hacking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hacking">hacking</a> exploits, methodology and technology. The 2010 convention will be held on February 5-7. Space is limited and it has sold out every year since its inception. Compared to other security conventions, it is very affordable. Tickets are sold from $100 to $300 in three rounds. The first two round sold out within 2-3 minutes. Even if you try to register at the very minute the tickets are made available, you might not make it as the demand is so great. I was one of those unfortunately souls hitting refresh feverishly during round two but didn&#8217;t make the cut. There is hope, however. Round 3 sales begin on January 1 at 12 noon. I shall certainly give it another go. I have thoroughly enjoyed the convention in the past and it&#8217;s a great bargain for the price.</p>
<p>The list of presentations are post here.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/' rel='bookmark' title='Shmoocon 2010 Videos Online'>Shmoocon 2010 Videos Online</a> <small>Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/30/last-chance-for-shmoocon-2010-tickets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Attack Is Only Funny When It&#039;s Bill The Cat!</title>
		<link>http://infosec3t.com/2009/12/29/hack-attack-is-only-funny-when-its-bill-the-cat/</link>
		<comments>http://infosec3t.com/2009/12/29/hack-attack-is-only-funny-when-its-bill-the-cat/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 00:06:24 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=155</guid>
		<description><![CDATA[How a hack attach can happen, what to do when you suspect it has and information that can help you.]]></description>
			<content:encoded><![CDATA[<p>We were hacked. Bet the thought of it gives you shivers. It sure did me, and more!</p>
<p>As a web designer I use many <a href="http://infosec3t.com/tag/tools/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Tools">tools</a> to monitor my site and stats.  I signed up for <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> Webmaster <a href="http://infosec3t.com/tag/tools/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Tools">Tools</a> and was horrified to see a list of keywords that were pornographic AND not on my site. The first question, of course, was where on earth were these coming from.</p>
<p>The next step was to go through every page on the server and check for files / folders that appear suspicious. My main site was fine. What was not fine were archived folders (2) outside of my main site.</p>
<p>I downloaded one of the pages to view the code and saw that there was a script underneath. On further research (Google search) I discovered that these pages were simply jumping off points, due to the script, to actual pornographic sites. But there was my url listed with these awful pornographic words &#8211; in Google&#8217;s search index.</p>
<p><strong>What I Did Once Found</strong></p>
<p>I removed the files.  I created a 400, 403, 404 page stating &#8220;PLEASE NOTE: WE HAVE HAD A PROBLEM RECENTLY OF FILES BEING UPLOADED TO OUR WEBSITE THAT WERE NOT CREATED BY THIS COMPANY AND CONTAIN OFFENSIVE MATERIAL. IF YOU ARE LOOKING FOR THESE FILES, THEY NO LONGER EXIST.&#8221;</p>
<p><strong>Seeking Extra Resources</strong></p>
<p>My next step was to go to upload an htaccess file loaded with all of words. So we went through all the keywords we had (don&#8217;t do this on a full stomach folks) and added to the list and put it up.</p>
<p><strong>How Did This Happen?</strong></p>
<p>It appears that <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a> has been downloading to unsuspecting websites with a software update.</p>
<p>What Can You Do To Check Your Site?</p>
<p>A good place to start is Google Webmaster Tools and Google Analytics because (increasingly) Google is using the Google Webmaster Tools to inform webmasters of problems with their sites. If you see strange page names being accessed and keywords that do not relate to your site you very well may have a problem. If this is the case contact your hosting company AND check every file in every folder.</p>
<p>Author: Jan Carroll<br />
Article Source: EzineArticles.com<br />
Provided by: <a href="http://wealthynetizen.com/wordpress-plugin-guest-blogger/">Guest blogger</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/23/skipfish-web-scanning-security-tool-from-google/' rel='bookmark' title='Skipfish-Web Scanning Security Tool from Google'>Skipfish-Web Scanning Security Tool from Google</a> <small>Google has released an open-source Web security scanner called Skipfish...</small></li>
<li><a href='http://infosec3t.com/2010/06/01/pause-your-google-history/' rel='bookmark' title='Pause your Google History'>Pause your Google History</a> <small>Have you ever used your Google search history? If you...</small></li>
<li><a href='http://infosec3t.com/2010/02/16/1533/' rel='bookmark' title='Enter the Dragon browser, the more secure Google Chrome'>Enter the Dragon browser, the more secure Google Chrome</a> <small>The open source engine that forms the basis for Google&#8217;s...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/29/hack-attack-is-only-funny-when-its-bill-the-cat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Merry Christmas, One and All!</title>
		<link>http://infosec3t.com/2009/12/24/merry-christmas-one-and-all/</link>
		<comments>http://infosec3t.com/2009/12/24/merry-christmas-one-and-all/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 20:41:40 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=135</guid>
		<description><![CDATA[Related posts: Cloud Computing = Loss of Confidentiality? Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer... United States Department of Defense Embraces Hacker Certification Mar 01, 2010 – The U.S. Department of Defense (DoD)... More on Forensics&#8230; Follow what the NOVA Information Assurance Strike Team is up...]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><img class="aligncenter size-medium wp-image-141" title="white-christmas-tree-decorations" src="http://infosec3t.com/wp-content/uploads/2009/12/white-christmas-tree-decorations-228x300.jpg" alt="white-christmas-tree-decorations" width="228" height="300" /></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/24/merry-christmas-one-and-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>More security videos&#8230;</title>
		<link>http://infosec3t.com/2009/12/15/more-security-videos/</link>
		<comments>http://infosec3t.com/2009/12/15/more-security-videos/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 19:47:52 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=110</guid>
		<description><![CDATA[Here is another assortment of security related videos ( in no particular order ): http://www.milw0rm.com/video/ http://whitehatworld.com/archives.html http://www.hak5.org/category/episodes http://www.theacademypro.com/index.php http://www.irongeek.com/i.php?page=security/hackingillustrated http://www.securitytube.net/ http://www.veryangrytoad.com/categories/8/ http://m3gabyt3.blip.tv/posts?view=archive&#38;nsfw=dc http://hopetracker.donthax.me/ http://adventuresinsecurity.com/resources http://www.security-freak.net/videos.html http://www.youtube.com/helpnetsecurity?gl=GB&#38;hl=en-GB http://vimeo.com/user595761/videos/sort:date http://blip.tv/search?q=backtrack&#38;x=0&#38;y=0 http://www.knowledgecave.com/modules.php?name=Video_Stream http://www.youtube.com/theacademypro http://infinityexists.com/ http://www.youtube.com/user/ImpervaChannel http://vimeo.com/pauldotcom/videos http://vimeo.com/user1781217/videos/sort:date http://www.hackerscenter.com/index.php?/Video/General/ http://securityoverride.com/about/ http://www.social-engineer.org/blog/resources/ http://pentest.cryptocity.net/ http://yehg.net/lab/pr0js/training/webgoat.php Related posts: Shmoocon 2010 Videos Online Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this... [...]]]></description>
			<content:encoded><![CDATA[<p>Here is another assortment of <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> related videos ( in no particular order ):</p>
<p>http://www.milw0rm.com/video/</p>
<p><a href="http://whitehatworld.com/archives.html" target="_blank">http://whitehatworld.com/archives.html</a><br />
<a href="http://www.hak5.org/category/episodes" target="_blank">http://www.hak5.org/category/episodes</a><br />
<a href="http://www.theacademypro.com/index.php" target="_blank">http://www.theacademypro.com/index.php</a><br />
<a href="http://www.irongeek.com/i.php?page=security/hackingillustrated" target="_blank">http://www.irongeek.com/i.php?page=security/hackingillustrated</a><br />
<a href="http://www.securitytube.net/" target="_blank">http://www.securitytube.net/</a></p>
<p>http://www.veryangrytoad.com/categories/8/</p>
<p><a href="http://m3gabyt3.blip.tv/posts?view=archive&amp;nsfw=dc" target="_blank">http://m3gabyt3.blip.tv/posts?view=archive&amp;nsfw=dc</a></p>
<p>http://hopetracker.donthax.me/</p>
<p><a href="http://adventuresinsecurity.com/resources" target="_blank">http://adventuresinsecurity.com/resources</a><br />
<a href="http://www.security-freak.net/videos.html" target="_blank">http://www.security-freak.net/videos.html</a><br />
<a href="http://www.youtube.com/helpnetsecurity?gl=GB&amp;hl=en-GB" target="_blank">http://www.youtube.com/helpnetsecurity?gl=GB&amp;hl=en-GB</a><br />
<a href="http://vimeo.com/user595761/videos/sort:date" target="_blank">http://vimeo.com/user595761/videos/sort:date</a><br />
<a href="http://blip.tv/search?q=backtrack&amp;x=0&amp;y=0" target="_blank">http://blip.tv/search?q=backtrack&amp;x=0&amp;y=0</a><br />
<a href="http://www.knowledgecave.com/modules.php?name=Video_Stream" target="_blank">http://www.knowledgecave.com/modules.php?name=Video_Stream</a><br />
<a href="http://www.youtube.com/theacademypro" target="_blank">http://www.youtube.com/theacademypro</a><br />
<a href="http://infinityexists.com/" target="_blank">http://infinityexists.com/</a><br />
<a href="http://www.youtube.com/user/ImpervaChannel" target="_blank">http://www.youtube.com/user/ImpervaChannel</a><br />
<a href="http://vimeo.com/pauldotcom/videos" target="_blank">http://vimeo.com/pauldotcom/videos</a><br />
<a href="http://vimeo.com/user1781217/videos/sort:date" target="_blank">http://vimeo.com/user1781217/videos/sort:date</a></p>
<p>http://www.hackerscenter.com/index.php?/Video/General/</p>
<p>http://securityoverride.com/about/</p>
<p>http://www.social-engineer.org/blog/resources/</p>
<p><a href="http://pentest.cryptocity.net/" target="_blank">http://pentest.cryptocity.net/</a><br />
<a href="http://yehg.net/lab/pr0js/training/webgoat.php" target="_blank">http://yehg.net/lab/pr0js/training/webgoat.php</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/' rel='bookmark' title='Shmoocon 2010 Videos Online'>Shmoocon 2010 Videos Online</a> <small>Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this...</small></li>
<li><a href='http://infosec3t.com/2010/04/02/cloud-computing-security-an-insiders-view/' rel='bookmark' title='Cloud Computing Security: An Insider&#039;s View'>Cloud Computing Security: An Insider&#039;s View</a> <small>As CSO of Qualys, Randy Barr is responsible for security,...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/15/more-security-videos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Security Alliance</title>
		<link>http://infosec3t.com/2009/12/10/cloud-security-alliance/</link>
		<comments>http://infosec3t.com/2009/12/10/cloud-security-alliance/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 21:02:26 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cloud computing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=94</guid>
		<description><![CDATA[For more information on Cloud Computing Security, a good resource is the Cloud Computing Alliance, a &#8220;non-profit organization formed to promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing&#8221;. The list of founding members [...]]]></description>
			<content:encoded><![CDATA[<p>For more information on <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">Cloud Computing</a> <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a>, a good resource is the <a title="Cloud Computing Alliance" href="http://www.cloudsecurityalliance.org/" target="_blank">Cloud Computing Alliance</a>, a &#8220;non-profit organization formed to promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing&#8221;. The list of founding members includes names from companies like Dell, PGP, McAfee, Sun,  and a host of other recognizable names.</p>
<p>They also have a <a title="Cloud Security Alliance Google Group" href="http://groups.google.com/group/cloudsecurityalliance" target="_blank">Google Group</a> set up for discussion that anyone can view and/or participate.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/01/new-practices-for-security-assurance-in-the-cloud/' rel='bookmark' title='New Best Practices for Security Assurance in the Cloud'>New Best Practices for Security Assurance in the Cloud</a> <small>The Cloud Security Alliance (CSA) produced version 2 of its...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/' rel='bookmark' title='Exploring Cloud Computing Information Leakage'>Exploring Cloud Computing Information Leakage</a> <small>If you are in cloud computing security (or part of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/10/cloud-security-alliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ISSA-NOVA Chapter December Meeting</title>
		<link>http://infosec3t.com/2009/12/09/issa-nova-chapter-december-meeting/</link>
		<comments>http://infosec3t.com/2009/12/09/issa-nova-chapter-december-meeting/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 00:42:24 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Application Security]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=80</guid>
		<description><![CDATA[The Northern Virginia Chapter of the Information System Security Association ( ISSA ) will be hosting its monthly chapter meeting for December tomorrow. The speaker with be LTC Ken Fritzshe, Phd, CISSP of the US Army. He will be discussing Application Security. More info at the ISSA-NOVA website. Related posts: United States Department of Defense [...]]]></description>
			<content:encoded><![CDATA[<p>The Northern Virginia Chapter of the Information System <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> Association ( ISSA ) will be hosting its monthly chapter meeting for December tomorrow. The speaker with be LTC Ken Fritzshe, Phd, <a href="http://infosec3t.com/tag/cissp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cissp">CISSP</a> of the US Army. He will be discussing Application <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a>. More info at the ISSA-NOVA <a title="ISSA-NOVA Website" href="http://www.issa-nova.org" target="_blank">website</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/09/issa-nova-chapter-december-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

