The month of October has been designated as National Cyber Security Awareness Month and National Stop Bullying Month. securityorb.com/ plans to publish security tips on how to protect yourself, your information, and your computing devices as well as provide useful information on how to deal with cyber bullying.
We will take questions on both our Facebook and Twitter pages and answer them for you.
DerbyCon is a new hacker’s conference held this past weekend in Louisville, Kentucky. Hans Bosch (@hans_bosch ) of NY, a securityorb.com/ (@SecurityOrb) contributor had the opportunity to attend and shared some positive notes with me about the conference.
Hans stated, “The hacker space was the spot early on Friday night with fire breathing ponies igniting the alley way while attendees shared greetings and stories since their last encounter”. Hans also discussed the many informative presentations he attended at the conference but stated, “One of my favorite talks was presented by int0x80 (of Dualcore)”. int0x80’s presentation titled, “Anti-Forensics for the Louise” reviewed clever techniques to protect your OS from forensic analysis, these were not just discussions about encrypting your hard drive, but simple yet ingenious ways of preventing unauthorized access to your device. For example, one can remove the kernel from the hard drive, booting from a USB device and modifying the MBR to clean house when not booted correctly.
Hans also stated, the conference was held in a convenient location that offered other types of attractions, such as bars, restaurants, shop and even bowling at 4th Street Live. In addition to the above-mentioned venues, gambling on the casino boat was nice as well.
A Twitter post today also provided information the organizers of DebryCon raised $13,617.00 for Johnny Long’s organization, HackersforCharity which places computer classrooms in some of the world’s poorest countries in Africa.
In fact, I reviewed many positive tweets on Twitter over the weekend as well as today about the conference, presentations, presenters and new friendships. A tweet by @dualcoremusic, who provided entertainment for the Rapid 7 after-hours party, stated, “@Derbycon is a must-attend next year.” and I certainly plan too…
Congratulations to the DerbyCon organizers, staff and attendees for a successful event…
Organizations have traditionally invested most of their security in technology, with little e!ort in protecting their employees. As a result, many attackers today target the weakest link – the human. Awareness, not just technology, has become key to reducing risk and remaining compliant. This high-level talk designed for management explains why humans are so vulnerable, how they are being actively exploited, and what organizations can do about it.
Hands-on immersion training programs, including:
Security Essentials Bootcamp Style
Hacker Techniques, Exploits, and Incident Handling
00Kellep CharlesKellep Charles2011-09-25 18:42:142011-09-25 18:42:14Join SANS’ Lance Spitzner for a free lunch-n-learn, downtown Chicago Tue, 27 Sept. on how to secure the HumanOS.
Join government and industry experts at the Digital Forensics and E-Discovery Federal Executive Briefing, tomorrow at the Willard Hotel in Washington D.C.
Hear real-world examples of how digital forensics tools are being used to support cybercrime investigations while meeting requirements for evidence protection and chain of custody.
NOTE: This event is open to military and government personnel, government contractors, and systems integrators only. Due to the request of our sponsor, we reserve the right to decline any registration. Register Here
aspire to attain the highest regarded title within the information security profession – CISO,
already serve as an official CISO, or perform CISO functions in their organization without the official title.
The C|CISO designation is the recognition of your knowledge and achievements, and will award you with professional acknowledgement and propel your career.
C|CISO benefits
Independent validation of competency and experience in crucial CISO disciplines
Senior executive level business knowledge benchmark
Peer and Industry level recognition
Increased value of your information security role
Increased credibility, confidence and promotability
Access to the C|CISO community.The C|CISO certification recognizes an individual’s accumulated skills in developing and executing an information security management strategy in alignment with organizational goals.
The C|CISO equips information security leaders with the most effective toolset to defend organizations from cyber attacks.
C|CISOs are certified in the following domains:
Governance (Policy, Legal & Compliance)
IS Management Controls and Auditing Management (Projects, Technology & Operations)
Management – Projects and Operations
Information Security Core Competencies
Strategic Planning & Finance
Achieving a C|CISO Certification will differentiate you from others in the competitive ranks of senior Information Security Professionals. C|CISO will provide your employers with the assurance that as a C|CISO certified executive leader, you possess the proven knowledge and experience to plan and oversee information security for the entire corporation.
C|CISO is a unique designation that has been designed in cooperation with industry leaders to identify a solid blend of functional and executive IT Job Roles and skill requirements.
It wasn’t Tahrir Square, exactly, but the anti-Wall Street demonstration that began on Saturday succeeded in disrupting the Monday morning commutes of the area’s workers. The J/Z Broad Street subway stop was shut down this morning, and the large police presence, along with chanting, meant that Wall Streeters had to pass a gauntlet of sorts to get to the office this morning. The turnout was lower than the organizers hoped for — “hundreds” seems to be the unofficial consensus for now, compared with the hoped-for 20,000.
Today Facebook and Time Warner are launching the Stop Bullying: Speak Up Social Pledge App. The Facebook app is aimed at educating people about the harm that bullying can cause and inspiring bystanders to speak up whenever they see bullying. The app is full of great resources, including the ability to create bullying prevention groups in schools and expert tips from safety organizations. We encourage everyone to pledge to stop bullying by speaking up, and help us spread the word.
SAINT Professional is now available on Mac OS X Lion (10.7).
You can now fingerprint iPhones and iPads connected to your network. SAINT includes OS Fingerprinting during network discovery and/or vulnerability scanning.
New OWASP Top 10 Web Application scanning policy including 12 new web application checks.
DoD IAVA – Department of Defense Information Assurance Vulnerability Alert scanning policy and report template added (Requires IAVA plugin).
A new OS Password Guess policyhas been added including:
all SAINT password-guessing features (excluding password configuration policies) designed to guess the operating system password
checks for default FTP passwords
the capability to provide dictionary-based password guessing for operating systems (Windows, *nix), including Cisco and other devices, that have Telnet, SSH or FTP. These checks to do not include password guessing for databases or Web Auth.
Enhanced content scanning probe now includes performance enhancements as well as assessments on numerous file formats for Linux and UNIX OSs, in addition to Windows.
Live hosts that were identified during network discovery can now be displayed within the GUI. A report can also be generated from this discovery file.
Enhancements have been made to the backup & restore functionality to include credentials, custom logos, and additional configuration data.
New menu-driven launcher application allows starting SAINTmanager, SAINT nodes, and SAINT web listeners from the desktop menu without command-line knowledge.
New SAINTmanager RPM and DEB packages for easier SAINTmanager installation on Linux.
00Kellep CharlesKellep Charles2011-09-16 14:45:472011-09-16 14:45:47Key New Features in SAINT 7.10
The 2nd Annual NSA Trusted Computing Conference and Exposition, hosted by the National Security Agency, kicks off in less than one week, September 20 – 22, in Orlando, FL! This year’s conference presents the theme, “Using COTS Technologies to Deliver Decisive Defensive Advantage.” Don’t miss the opportunity to be a part of the discussions about the security of vital data, networks and critical enterprise application and define the future of Trusted Computing!
It is not too late, registration is still open! Take a look at the extensive topics addressed, explore the expertise of our speakers, and consider the benefits of this conference for you personally and for your organization as a whole.
Below are some of the distinguished keynote speakers who will be presenting at the conference. To see a full list of speakers, please view the conference agenda:
Mr. Tony W. Sager Chief Operating Officer for the Information Assurance Directorate, National Security Agency
Mr. Michael A. Lamont Chief, Network Solutions Office, National Security Agency/Central Security Service (NSA/CSS) Commercial Solutions Center (NCSC)
Mr. Howard J. Ettinger Chief, Trusted Computing and Platform Services Division, National Security Agency/Central Security Service (NSA/CSS) Commercial Solutions Center (NCSC)
Mr. Neil Kittleson Trusted Computing Portfolio Manager, National Security Agency/Central Security Service (NSA/CSS) Commercial Solutions Center (NCSC)
Mr. John Lambert Senior Director, Security Engineering and Network Security, Trustworthy Computing, Microsoft
Ms. Frances Fragos Townsend Senior Vice President, MacAndrews and Forbes Holdings, Inc.; Former Homeland Security Advisor
Mr. Sumit Gwalani Product Manager for Chrome OS Security, Google
In between sessions, take the opportunity to view some of the featured technologies from our 50+ exhibitors. These technologies include, but are not limited to:
Don’t forget to follow NSA Trusted Computing Conference & Exposition on Twitter @NSA_TC_Con!
For the more information about this and additional conferences, please visit www.ncsi.com or call 888-603-8899.
00Kellep CharlesKellep Charles2011-09-14 13:13:062011-09-14 13:13:06Last Chance to register for 2nd Annual NSA Trusted Computing Conference & Exposition