Watch Live: Sub-Oversight Committee Hearing at 11AM ET on Cybersecurity
Watch Live: Sub-Oversight Committee Hearing at 11AM ET on Cybersecurity
Watch Live: Sub-Oversight Committee Hearing at 11AM ET on Cybersecurity
Course Author statement:
As a perpetual student of information security, I am excited to offer this course on advanced penetration testing. Often, when conducting an in-depth penetration test, we are faced with situations that require unique or complex solutions to successfully pull off an attack, mimicking the activities of increasingly sophisticated real-world attackers. Without the skills to do so, you may miss a major vulnerability or not properly assess its business impact. Target system personnel are relying on you to tell them whether or not an environment is secured. Attackers are almost always one step ahead and are relying on our nature to become complacent with controls we work so hard to deploy. This course was written to keep you from making mistakes others have made, teach you cutting edge tricks to thoroughly evaluate a target, and provide you with the skills to jump into exploit development.
-Stephen Sims, SANS Senior Instructor
Click here for more info and upcoming training events for SEC660: http://www.sans.org/info/82554
Save $150 off your registration by using promo code: Connect_SecOrb
SANS Network Security in Las Vegas, NV is from September 17-26 (SEC660 – Sept 19-24).
From Saint Newletter:
Key New Features in SAINT 7.9
Vulnerability Scanner
Microsoft Patch Tuesday scan policy – This scan policy checks for the latest published Microsoft Patch Tuesday vulnerabilities (2nd Tuesday of each month)
New Vulnerability Check Type Coverage now includes –
Blind SQL injection
Flash application –
PCI Special Notes for the PCI Executive report format (Part 3b) can be customized
Multitasking improvements –
Check Login button – Instantly reports whether the provided Windows authentication credentials are correct
Improved host type fingerprinting – Uses Nmap in conjunction with full port scan for the best possible fingerprint
Nmap Progress bar – Displays Nmap progress in the control panel during long Nmap runs
Ability to simultaneously select/deselect all scheduled scans (including scans set up as part of a scan window) on the scan schedule page that are related to the same scan
Custom email “display name” for email alerts of scans
Run local Unix/Linux/Mac checks using successfully guessed SSH login/password pairs
Penetration Testing
| Mac Camera Image Capture Exploit Tool – This tool attempts to retrieve an image file captured by an iSight camera such as the one built into a MacBook. If it is successful, the picture is displayed. |
Mac OS support in Download Connection exploit tool
Phishing improvements –
Easier, more intuitive exploit setup – Mouse over any input option on the exploit setup form to see hints.
SAINTmanager®
Load-balanced Discovery – Added support for the discovery portion of load balanced scans to also be load balanced.
SCAP/OVAL/XCCDF
Added support for file behaviors
Added OVAL detail report that provides the following details –
Added an OVAL definition detail viewer that allows users to see what checks will be run for the selected definition file, also provides details as to what each definition checks for on the target system
Added support for two more OVAL Operations (XOR, ONE, AND, OR are all now supported)
Added support for CPE-OVAL and CPE-DICTIONARY files contained in scap-data-streams (e.g., Vista system no longer scanned by XP benchmark)
ZIP files containing multiple data-streams can now be imported (e.g., USGCB-Win7)
Added XCCDF multi-target summary reports
Added new easier to use more organized XCCDF/OVAL results view page
Removed duplicates in system_characteristics output and added some other disk space saving features
Added OVAL multi-target report that provides below information –
SAINTwriter®
Phishing Assessment Report improvements (View sample report) –
WILMINGTON, Mass. – July 12, 2011 — Security Innovation today introduced its inaugural Software Security Summer Series, where the company will offer six free eLearning courses from its industry-leading curriculum over the next six weeks. The courses are part of TeamProfessorTM, the company’s computer-based training library with an emphasis on the software development lifecycle and defensive coding techniques. The courses were developed to train developers, architects, designers and group managers on how to build security into the core, fixing the systemic issues of insecure software.
By making portions of the industry’s largest application security training curriculum available for free, Security Innovation is delivering on its corporate strategy to be the authority on application security. The company firmly believes that providing the expertise and knowledge around how to identify and remediate software vulnerabilities, that this will help drive organizations to shift their strategy from reactive to proactive with the ultimate goal of eliminating software vulnerabilities in the development phase.
Courses will be available beginning Wednesday, July 20, when users will have 24-hour access to one of TeamProfessor’s eLearning courses. The series will continue every Wednesday for six weeks. Interested parties can register for access for up to six courses on the Security Innovation website (www.securityinnovation.com). The course titles and schedule follow:
“We’re declaring 2011 as the first Summer of Software Security. Offering free access to some of our most popular courses is our way helping the software world be a more secure place, ” said Fred Pinkett, Vice President of Product Management at Security Innovation. “We feel that extending these courses to developers, architects, designers, group managers and even security teams will drive home the need for building security in as an integral component throughout development process.”
More than 100,000 Security Innovation users from the industry’s largest financial services, energy and technology Fortune 500 organizations leverage TeamProfessor to build internal security expertise. By educating developers on how to code defensively, Security Innovation is helping enterprises and government entities protect critical data and cut costs. Security Innovation has the industry’s largest application security training curriculum with more than 40 courses and 65 hours of computer-based training content.
About Security Innovation
Security Innovation is an established leader in the application security and cryptography space. For over a decade the company has provided products, training and consulting services to help organizations build and deploy more secure systems and improve the process by which their applications are built.
Security Innovation built upon its core competencies in application security with the acquisition of NTRU CryptoSystems in 2009, a company that developed proprietary, standardized algorithms. This resulted in the strongest and fastest public key cryptography available and the means to overcome historical performance barriers that have plagued the encryption industry. With these core strengths intact, Security Innovation is in a position to help organizations protect their data at two critical points: while applications are accessing it and during transmission. The company’s flagship products include TeamProfessor, the industry’s largest library of application eLearning courses; and TeamMentor, a web-based secure development methodologies product.
Security Innovation is privately held and is headquartered in Wilmington, MA USA.
Note to Editors: Security Innovation, NTRUEncrypt, TeamMentor, TeamProfessor and the Security Innovation logo are trademarks of Security Innovation. All other brand names may be trademarks of their respective owners.
Consumer-oriented devices are used to access the enterprise network, email and applications on the move. While the productivity gains and strategic opportunities of accessing data remotely are real, enterprise decision makers are increasingly challenged by cost and security.
Join industry experts, analysts and end users as they identify the key vulnerabilities you should be aware of and the solutions that will allow you to keep your business running securely.
Sign up to attend the live interactive webcasts on Wednesday, July 13, 2011, or view them afterward on demand here: http://www.brighttalk.com/r/
Presentations include:
‘Thriving in the Era of the Mobile Workforce’
Christian Kane, Forrester Research; Gaston Brown, Hobart Brothers Co.; Matthew Dieckman, SonicWALL
‘Strategic Mobile Security: A Practitioner Panel’
Chenxi Wang, Forrester; Anil Karmel, Los Alamos Nat’l Lab; Terrell Herzig, UA Medical Center
‘The Composition of Mobile Security – Risks and Results’
Daniel Miessler; Principal Security Consultant, HP Application Security
‘Top 10 Mobile Risks’
Vladimir Jirasek, Senior Enterprise Security Architect, Nokia
‘Leveraging Mobile Devices for Strong Authentication’
David Mahdi, Product Manager, Entrust
You can view the full lineup and sign up to attend any or all presentations at http://www.brighttalk.com/r/
Morgan Cantrell, Marketing Program Manager
501 Folsom Street, 2nd Floor, San Francisco, CA 94105
www.brighttalk.com
T: +1.415.625.1523 F: +1.415.625.1555 E: mcantrell@brighttalk.com
The Future of Privacy Forum (FPF) invites privacy scholars and authors with an interest in privacy issues to submit papers to be considered for FPF’s second edition of “Privacy Papers for Policy Makers.”
PURPOSE
• To highlight important research and analytical work on a variety of privacy topics for policy makers
• Specifically, to showcase papers that analyze current and emerging privacy issues and either propose achievable short-term solutions, or propose new means of analysis that could lead to solutions.
REVIEW PROCESS
• Academics, privacy advocates and Chief Privacy Officers on FPF’s Advisory Board will review the submitted papers to determine which papers are best suited and most useful for policy makers in Congress, at federal agencies and for distribution to data protection authorities internationally.
• Two papers selected by the chairs of the Privacy Law Scholars Conference will be included in the publication and will receive a cash award from the International Association of Privacy Professionals.
• The Future of Privacy Forum will announce the selected papers at an event with privacy leaders in September and will provide a printed digest to policy makers in the United States and abroad.
SUBMISSION
Paper Submission Deadline: July 29, 2011
Please include: author’s full name, phone number, current postal address and e-mail address.
Send via e-mail to papersubmissions@futureofprivacy.org with the subject line “Privacy Papers for Policy Makers 2011,” or send by mail to:
Future of Privacy Forum
919 18th Street, NW, Suite 925
Washington, D.C. 20006
The entry can provide a link to a published paper or a draft paper that has a publication date. FPF will work with the authors of the selected papers to develop a digest.
Visit www.futureofprivacy.org/the-privacy-papers to view the 2010 edition of Privacy Papers for Policy Makers.
Source: http://www.futureofprivacy.org/2011/06/02/privacy-papers-for-policy-makers-2011/
On Monday July 4th, a hacker group called the “Script Kiddies” hacked into the Fox News Politics Twitter account and posted six tweets reporting that President Obama had been assassinated.
The “@foxnewspolitics” Twitter account has a badge with a check mark, which means it has been verified by Twitter for authenticity and also has more than 34,000 followers. Data pertaining to the twitter account shows the tweets were first posted at 2 a.m. Eastern Time.
George Ogilvie, a spokesman for Secret Service stated they would look into the false postings and “conduct the appropriate follow-up.” The Secret Service ensures the safety of current and former national leaders and their families, such as the President, past Presidents, Vice Presidents and
presidential candidates.
The false postings about President Obama’s assassination remained visible to the public for at least six hours before Fox News system administrators apparently regained control of the Twitter account and deleted the tweets.
Jeff Misenti, vice president and general manager of Fox News Digital, said FoxNews.com is working with Twitter to address the situation as quickly as possible. He later added, “We will be requesting a detailed investigation from Twitter about how this occurred, and measures to prevent future unauthorized access into FoxNews.com accounts.” Then closed by stating,”FoxNews.com regrets any distress the false tweets may have created.”
Due to privacy reasons, officials at Twitter stated they would not comment or provide information on specific accounts, but added that users should follow its strong password advice.
securityorb.com/, an information security and privacy organization published a guideline to creating strong passwords for online accounts. We regard passwords as the first line of defense when it comes to protecting computers and information assets.
On a brighter note, President Obama actually spent the holiday at a barbecue at the White House with military families and administration staffers.
