CBT Nuggets Review of the Certified Ethical Hacker (CEH) Course

 Product Review by Ron McClellan, CISSP

1. The CBT Nuggets site is a good resource for online video training.  There were a few minor issues that come with age, such as the site intermemos.com no longer being available, but away from that, the content and presentation of the material was really good and easy to follow.

The training package went into a lot of detail and in some cases going over the really basic information that most candidates for the CEH should already have a full grasp on, at least in my opinion.  The prices are fair and consistent with other training sites, the one thing I would point out is if you get the 30 day license, you really need to make sure you have the time during that month to complete the training; there are approximately 11 and ½ hours of material in this course.


2. I tested the software through the web interface, using both Firefox 3.6 and Internet Explorer 8, and had no issues other than the one mentioned below on Figure 3.  Simply clicking on the “Launch Player” button will provide you with a list of the courses.  Very easy to navigate to the various courses and sub-sections.

3. CBTNuggets uses a nice web interface, as you see in the yellow square on Figure 2.; this is how each course is presented with each section listed below.  The center section provides a whiteboard view with an instructor overview of the information as it is presented.  One feature that I liked was the ability to keep notes for each section, as seen on the right side of Figure 2 and it also allows you to save and print those notes as well.


I did get recurring error messages at one point during one section of the review as shown below in Figure 3:

This issue was corrected by exiting from the site, clearing the cache and going back into the site and everything functioned correctly.

4. Usage

–  Downloading the MP3s is painfully slow, even with an OC3 pipe to the Internet, only getting an average of 65K download speed.


– Given the course name/content, sections 2-4 seem to be a little bit of too basic.

5. Overall, I will give the CBTNuggets’ CEH training course 4 out of 5 Orbs.


Since 1999, respected companies, non-profits, IT departments, and individuals trust CBT Nugget videos for their training needs.  For more information you can contact them with the below information:

http://www.cbtnuggets.com/

sales@cbtnuggets.com

1-888-507-6283

 

Enabling DVD playback in Ubuntu 9.04

I have just finished installing Ubuntu 9.04 on a Gateway laptop, everything worked well from video to wireless until I popped in a DVD to watch. Did the updates and still nothing, until I ran across this command on the Internet, tried it and everything is golden now.

sudo apt-get install ubuntu-restricted-extras totem-xine libxine1-ffmpeg libdvdread4

sudo /usr/share/doc/libdvdread4/install-css.sh

The explanation when the commands are needed are printed below:

The movie players provided in Ubuntu can play back unencrypted DVDs. However, many commercial DVDs are encrypted with a weak algorithm called Content Scrambling System (CSS). You can enable playback of encrypted DVDs with MPlayer, xine and Totem-xine by installing libdvdread4.

The CSS key sets are licensed to manufacturers who incorporate them into products such as DVD drives, DVD players and DVD movie releases. Most DVD players are equipped with a CSS Decryption module.

SC Magazine Strengthens Commitment to Canadian Information Security with Inaugural SC Congress Canada

New Event Features Expected to be Canada’s Largest IT Security Show – Canada’s Leading Security Experts Weigh In November 16-17, 2010

TORONTO – June 3, 2010:  Today, SC Magazine announced the SC Congress Canada, the newest venue for information security industry leaders to convene and discuss lessons learned and best practices to help organizations address the burgeoning landscape of security threats and regulatory mandates.  Public registration will soon open for the SC Congress Canada taking place in Toronto on November 16-17, 2010.

Leveraging the pattern of success of the past two SC World Congress events held in New York each year, SC Congress Canada will feature in-depth analysis of the latest security threats, industry trends and drivers that contribute to the overall profitability of organizations, all localized to the Canadian audience.  The new event is being supported by numerous Canadian information security executives including the following confirmed keynote speakers:

  • Canada’s Privacy Laws – Leading the Pack: Jennifer Stoddart, Canadian Privacy Commissioner

Since taking on the role as commission in 2003, Commissioner Stoddart has overseen a number of important investigations, including those concerning the privacy policies and practices of the popular social networking site Facebook and a massive data breach at U.S. retail giant TJX.  In her keynote, Commissioner Stoddart will provide insight and detail as to how and why the plethora of news around privacy and Office of the Privacy Commissioner of Canada benefits organizations, individuals and Canada.

  • Securing North Americas Power Grid: Dr. Ann Cavoukian, Ontario Information and Privacy Commissioner; Scott D. Swartz, Energy Infrastructure and Cyber Security Advisor, Federal Energy Regulatory Commission (FERC)

This keynote will look at the latest threats and attack vectors as well as major privacy concerns regarding the North American Power Grid. The session will focus on why this security is critical, why you need to know and how you can help.

  • Canada’s Health Sector Cracks Down on Removable Media with Encryption Laws: Dr. Ann Cavoukian, Ontario Information and Privacy Commissioner
    In this feature keynote, Commissioner Cavoukian addresses Canada’s recent crackdown on removable media with encryption laws. While a 2007 health order required sensitive health information to be encrypted, portable drives continue to walk out the door with private information. In this keynote, Cavoukian addresses the issue and questions why, as an industry, we are slow to learn the threat portable media poses to managing private information.

More keynotes will be announced in the coming weeks. In addition to the keynotes from two of Canada’s information security authorities, there will be high-quality breakout sessions led by other leading organizations in the following three tracks: Emerging Threats/Management, Technical, and Editor’s Choice. SC Congress Canada attendees will learn about trends affecting mobile banking, securing the North American power grid and Canadian Health sector privacy laws, among other timely and relevant security topics, all lead by Canadian subject matter experts.

“For the past two years, the SC World Congress events have had tremendous success and engaged many of North America’s security experts – helping educate security professionals on the current threat landscape and how to protect businesses and consumers from existing and emerging threats,” said Illena Armstrong, editor-in-chief, SC Magazine.  “We are excited to take that success and provide a more concentrated focus on Canadian information security. With an agenda packed with best practices from industry leaders, we are confident this event will be challenging and thought-provoking and will deliver solutions and discussions designed to help take the lead against today’s cybercriminals.”

“IBM’s Platinum Sponsorship of the SC Congress event in Canada demonstrates a global commitment to improving risk management in the areas of Security and Business Resiliency across all industries and organizations,” said William Wong, Market Segment Manager-Managing Risk Program, IBM Security Solutions and Business Continuity & Resiliency Services.

IBM joins fellow Platinum sponsors, Fortinet, Panda Security, Sophos and Symantec and Gold Sponsor MTS Allstream in helping to bring the event to Canada.

A full list of speakers, a conference agenda, media partners, sponsors and participant registration can be found at http://www.scmagazineus.com/sc-congress-canada/section/1502/.

“I am looking forward to speaking at the inaugural SC Congress Canada event, with a view to adding a fresh, Canadian perspective to some complex global IT security issues,” said Dr. Cavoukian, Information and Privacy Commissioner, Ontario, Canada. “The event promises to be an important addition to the calendar for IT security professionals in Canada.”

About SC Magazine

SC Magazine provides IT security professionals with in-depth and unbiased information through timely news, comprehensive analysis, cutting-edge features, contributions from thought leaders and the best, most extensive collection of product reviews in the business.  By offering a consolidated view of IT security through independent product tests and well-researched editorial content that provides the contextual backdrop for how these IT security tools will address larger demands put on businesses today, SC Magazine enables IT security pros to make the right security decisions for their companies.  The brand’s portfolio includes the SC World Conference and Expo,  SC Magazine Awards, SC Directory, SC Magazine Newswire and SC Magazine IT Security Executives Forums

Contacts:

Sponsorship / vendor showcase:

Mike Alessie

Haymarket Media

mike.alessie@haymarketmedia.com

646-638-6002

Media:

Matthew Mors

MIX Public Relations for SC Magazine

matthew@mix-pr.com

206-992-7518

Webcams and your Privacy…

Cybercrime expert Gregory Evans explains the potential risks hackers can pose to webcams on your system and how to ensure your safety and privacy online.

This issue is a problem as in the case against a Pennsylvania school district that turned on the webcam of various student’s school-issued laptops while the computers and captured images of “inappropriate activity” in the student’s home.

The school then confronted the student and it was discovered the webcams in all 2,300 laptops given to students could be turned on remotely by the IT guys.  In addition, the recent tragic event of of the Rutgers University student who comitted suicide due to his roommate capturing personal events and posting them on the web.  The Twitter posting on Sept. 19 stated, “Roommate asked for the room till midnight. I went into molly’s room and turned on my webcam. I saw him making out with a dude. Yay.”

Check this the video:

October is National Cybersecurity Awareness Month

The National Cybersecurity Awareness Month officially kicked off today Monday, October 4, 2010 in Washington DC at The Lockheed Martin’s Global Vision Center (GVC).  The campaign for this year is titled, “Stop. Think. Connect.” This aims to empower citizens to make choices that contribute to the overall security of the Internet; according to a White House proclamation issued last Friday.

President Obama stated today “All Americans must understand they have a responsibility to secure cyber networks.”  He further stated, “America relies on our digital infrastructure daily, and protecting this strategic asset is a national security priority”.

The comments reflect the president’s continued commitment to cybersecurity as a national priority.

Cyber networks connect people around the world at the blink of an eye, Obama stated. However, attacks on computer systems, he added, can freeze the networks, compromise confidentiality and endanger children.

Organizations are encouraged to participate in the event by visiting the National Cyber Security Awareness Month Web portal, which contains resources for businesses.

Founded in 2003, National Cybersecurity Awareness Month takes place each year in October to educate consumers, schools, businesses and government agencies on staying safe and secure online.

The event is sponsored by the National Cybersecurity Alliance (NCSA) a Washington DC-based nonprofit dedicated to fostering a culture of cybersecurity along with the U.S. Department of Homeland Security and the Multi-State Information Sharing and Analysis Center, a cybersecurity prevention and protection collaboration for state and local governments.  In 2009, NCSA’s efforts alone (not including partner activities) reached an estimated 40,000,000 people through media and other activities.

Check out the 2009 Video by President Obama:

MGT414: SANS® +S™ Training Program for the CISSP® Certification Exam

MGT414: SANS® +S™ Training Program for the CISSP® Certification Exam will prepare you to pass the CISSP® Certification Exam. This course is an accelerated review course that focuses solely on the ten domains of knowledge as determined by ISC2. Test-taking tips and strategies are also discussed.

Each domain of knowledge is dissected into its critical components. Every component is discussed, explaining its relationship to other components and other areas of network security. After completing the course you will have a solid understanding of the ten domains of knowledge.

Eric Conrad, author of CISSP Study Guide (Syngress), will be teaching this course LIVE in a vLive! virtual classroom. The class will begin on November 1st and will meet on Monday, Tuesday and Wednesday evenings for five weeks. Don’t worry if you have to miss a night — classes will be recorded and you will be able to review the archives for SIX MONTHS.

We are excited to announce that any student who registers for MGT414 and enters promo code Connect_SecOrb10 will receive an autographed copy of Eric’s book, “CISSP(R) Study Guide”, published by Syngress.  It is a great supplement to your SANS course materials!  Plus you are already receiving 10% off the course by using discount code: Connect_SecOrb10.
To register please click here: https://www.sans.org/info/65313