 |
| |
| |
|
Who's Online |
|
We have 40 guests and 1 member online |
|
| |
|
|
 |
|
EH-Net
|
|
May 25, 2013, 09:06:22 AM
|
Show Posts
|
|
Pages: 1 [2] 3 4 ... 273
|
|
16
|
Features / /root / [Article]-Human Intelligence to Navigate the Security Data Deluge
|
on: April 02, 2013, 02:34:54 PM
|
We have a new contributor in our midst. Give a hearty welcome to Bob Shaker. He has some great ideas on how to view security from different angles. Let us know what you think and offer honest feedback. Trust me, Bob can take it.  Permalink: [Article]-Human Intelligence to Navigate the Security Data DelugeBy Robert J. Shaker II, CISSP, CCSK, CGEIT, CRISC Since the dawn of man there has been intelligence. Hunter gatherers would venture out and learn from the world around them what each sound, smell, and taste meant. The growl of a large predator would alert them to prepare for a defensive effort or to change paths. The smell of smoke meant other humans were nearby, and the taste of bitter meant something wasn’t edible. As time marched forward, needing to learn more about the other packs of humans around them became more important. There was competition or cooperation for resources but this required getting to know the other pack. Sometimes the best way to do that was to spy on them, to gather intelligence about the way they behaved, the way they interacted with each other and to determine how strong or weak they were. Regardless of the point in history, this has always proven to be true. We can see it as we progress through our modern era. In fact, this became so important that commercial intelligence companies began forming. The Age of Exploration saw a boom in this industry as the colonial armies grew. Their need for intelligence required outside parties, whether to help with the sheer volume of work, geographic disbursement or to give plausible deniability. Is it so different now? Today, we are up against countless adversaries. They’re nameless, faceless and shrouded behind false information. The ships that are on the horizon, the spies in our midst and the fortress we protect are all in the digital domain. The virtual skies are foggy and visibility is low. Today’s environment is much more difficult to navigate. The one commonality between these two vastly different times is the importance of human intelligence, and I’d argue that today it’s even more important than ever. A couple scenarios below will illustrate just how important it is for our innately human talents to remain a vital part of cyber security. Here's to being human, Don
|
|
|
|
|
19
|
EH-Net / News Items and General Discussion About EH-Net / EH-Net Newsletter - March 2013 Released
|
on: March 30, 2013, 05:41:07 PM
|
For those of you who haven't signed up for our newsletter, I thought I'd share it with you. It's not overrun with advertising (just enough to pay the bills). It's just a quick view into what's been happening on EH-Net. So it contains recent articles, let's you know what articles are coming, Free Giveaway news, our Global Calendar of Events for the coming month, etc. It's a quick and easy way to get the latest from EH-Net. Take a look for yourself: If you sign up on our list, you'll get this newsletter no more than once a month. We also sent out email messages about upcoming events, webcasts, contests, special offers and discounts and more, but those go out no more than once a week on average. For more info, go to Vitals>About EH-Net> Thanks for Joining Our List. To become a member of the EH-Net Email List, click Subscribe Now. Thanks and as always, let us know what you think. We're always open to suggestions. Don
|
|
|
|
|
20
|
EH-Net / Calendar Of Events / Cyber Readiness Challenge - Rome
|
on: March 30, 2013, 03:26:46 PM
|
Cyber Readiness Challenge - IT May 23, 2013 Rome, ItalyRecruiting Security Experts Worldwide!! Join the Symantec Cyber Readiness Challenge!! An interactive competition taking place online and at live events around the world where IT security experts will have the chance to test their skills and knowledge in exciting scenarios inspired by real-life security issues. The competition will take the form of a 'capture the flag' style cyber attack simulation, with players competing against each other to solve IT security problems. Players have the opportunity to win prizes and gain points PLUS the best players from the worldwide events will take part in the Cyber Readiness Championship! VenueUniversita La Sapienza - CIS - Aula B2 Rome, Italy For more info on this and other Global Challenges: https://secure.e-ventcentral.com/events/CyberReadinessChallenge/?aeacode=9Don
|
|
|
|
|
21
|
EH-Net / Calendar Of Events / Cyber Readiness Challenge - Nashville
|
on: March 30, 2013, 03:24:16 PM
|
Cyber Readiness Challenge - TN April 24, 2013 Nashville, TNRecruiting Security Experts Worldwide!! Join the Symantec Cyber Readiness Challenge!! An interactive competition taking place online and at live events around the world where IT security experts will have the chance to test their skills and knowledge in exciting scenarios inspired by real-life security issues. The competition will take the form of a 'capture the flag' style cyber attack simulation, with players competing against each other to solve IT security problems. Players have the opportunity to win prizes and gain points PLUS the best players from the worldwide events will take part in the Cyber Readiness Championship! VenueFranklin Marriott Cool Springs 700 Cool Springs Blvd. Franklin, TN 37067 For more info on this and other Global Challenges: https://secure.e-ventcentral.com/events/CyberReadinessChallenge/?aeacode=9Don
|
|
|
|
|
22
|
EH-Net / Calendar Of Events / Cyber Readiness Challenge - London
|
on: March 30, 2013, 03:22:26 PM
|
Cyber Readiness Challenge - UK April 23, 2013 London, UKRecruiting Security Experts Worldwide!! Join the Symantec Cyber Readiness Challenge!! An interactive competition taking place online and at live events around the world where IT security experts will have the chance to test their skills and knowledge in exciting scenarios inspired by real-life security issues. The competition will take the form of a 'capture the flag' style cyber attack simulation, with players competing against each other to solve IT security problems. Players have the opportunity to win prizes and gain points PLUS the best players from the worldwide events will take part in the Cyber Readiness Championship! VenueInfosecurity Europe Earls Court, London, UK For more info on this and other Global Challenges: https://secure.e-ventcentral.com/events/CyberReadinessChallenge/?aeacode=9Don
|
|
|
|
|
23
|
EH-Net / Calendar Of Events / Cyber Readiness Challenge - Prague, CZ
|
on: March 30, 2013, 03:19:59 PM
|
Cyber Readiness Challenge - Prague, CZ April 17, 2013 Prague, Czech RepublicRecruiting Security Experts Worldwide!! Join the Symantec Cyber Readiness Challenge!! An interactive competition taking place online and at live events around the world where IT security experts will have the chance to test their skills and knowledge in exciting scenarios inspired by real-life security issues. The competition will take the form of a 'capture the flag' style cyber attack simulation, with players competing against each other to solve IT security problems. Players have the opportunity to win prizes and gain points PLUS the best players from the worldwide events will take part in the Cyber Readiness Championship! VenueKonferencni centrum City Na Strzi 63/1676 140 62 Praha 4 For more info on this and other Global Challenges: https://secure.e-ventcentral.com/events/CyberReadinessChallenge/?aeacode=9Don
|
|
|
|
|
24
|
EH-Net / Calendar Of Events / Cyber Readiness Challenge - Las Vegas
|
on: March 30, 2013, 03:10:32 PM
|
Symantec Cyber Readiness Challenge - Las Vegas April 16 - 17, 2013 Las Vegas, NVRecruiting Security Experts Worldwide!! Join the Symantec Cyber Readiness Challenge!! An interactive competition taking place online and at live events around the world where IT security experts will have the chance to test their skills and knowledge in exciting scenarios inspired by real-life security issues. The competition will take the form of a 'capture the flag' style cyber attack simulation, with players competing against each other to solve IT security problems. Players have the opportunity to win prizes and gain points PLUS the best players from the worldwide events will take part in the Cyber Readiness Championship! VenueMGM Grand Hotel 3799 S Las Vegas Blvd Las Vegas, NV 89109 For more info on this and other Global Challenges: https://secure.e-ventcentral.com/events/CyberReadinessChallenge/?aeacode=9Don
|
|
|
|
|
25
|
Features / /root / [Article]-Network Forensics: The Tree in the Forest
|
on: March 30, 2013, 02:04:07 PM
|
Another cool article from Todd. Keep this up, and we just ight have to make you a columnist sooner rather than later. ;-) Permalink: http://www.ethicalhacker.net/content/view/466/2/ By Todd Kendall
Security professionals are often tasked with the unenviable position of wading through millions of bits of data, the review of thousands of systems, or the evaluation of hundreds of applications. At the end of the day it is their job to provide the ten thousand foot view of an organization and the highest rated findings that put it at risk. Information overload is a common theme in today’s society, and management requires the presentation of this material in a digestible manner of typically one page or less. The ability to provide this service requires what is often referred to as “seeing the forest for the trees.” In other words, don’t get distracted or bogged down by the minutiae of your discoveries at the risk of overlooking the big picture.
When it comes to computer forensics, however, the tables are flipped. When an event turns into an incident and management must answer to a board or the company’s shareholders, the ten thousand foot level is no longer adequate. At this point, every packet that ever crossed your company’s domain becomes suspect, and expectations are set whereby the answers to the questions such as, how did it happen, what damage did it do, where did it come from, when exactly did it occur, and who did it, requires the puzzle to be unravelled and presented in such excruciating detail it would make Melville take up skim-reading.
As always, let us know what you think and share your experiences. Don
|
|
|
|
|
26
|
EH-Net / News Items and General Discussion About EH-Net / [Article]-February 2013 Free Giveaway Winner of SANS CyberCon Training
|
on: March 30, 2013, 11:18:05 AM
|
Hey All, Thanks in advance for understanding my position on this month's winner and the sometimes seemingly difficult decisions (or maybe I should say those decisions that may cause slight grief of the members) that need to be made. I do my best to treat everyone as best as I can. Hope it shows. Don Permalink: [Article]-February 2013 Free Giveaway Winner of SANS CyberCon TrainingWe Have a Winner!
In a slight twist but not completely out of the ordinary, I have an announcement. As most of you know, I pick the winners not only based on participation but also on the ability to utilize the prize. I have also in the past taken special requests and rearranged winners to meet the needs of those who contribute the most. This usually takes place behind the scenes and is often the reason it looks as though someone who didn't participate the most wins. Because many others couldn't utilize the prize, and I thus had to keep going down the list. That being said, I want to continue to be fair. Last month's winner was absolutely deserving but couldn't use the prize. So I'm making an executive decision and announcing that UNIX will receive the seat at SANS CyberCon beginning April 22 with his choice of the following: - SEC401: Security Essentials Bootcamp Style ($4,645) - SEC504: Hacker Techniques, Exploits & Incident Handling ($4,845) - SEC575: Mobile Device Security and Ethical Hacking ($4,845) - FOR408: Computer Forensic Investigations - Windows In-Depth ($4,845) - MGT414: SANS +S Training Program for the CISSP Certification Exam ($3,995) SANS is also offer two NEW Audit courses at CyberCon, running back-to-back. - AUD444: Auditing Security and Controls of Active Directory and Windows ($2400) - AUD445: Auditing Security and Controls of Oracle Databases ($2400) So yes, this means that there's still a chance to win last month's prize of a full version of Metasploit Pro with 1 year of support. I will be contacting deserving EH-Netters very soon to give this prize away. I'll make the announcement in the forum thread for the Holiday Giveaway. Congrats and good luck to all of you as the prizes continue throughout 2013. PS - If you didn't win, you still get a prize of 5% Off w/ Coupon Code: EHN_5Participation is the ONLY way to win. Start a thread that sparks lots of interest; share thoughts and experiences; help a newbie... quality is more important than quantity. Only members are eligible! Registration Is FREE! Until next month... Don
|
|
|
|
|
27
|
Columns / Haddix / [Article]-Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
|
on: March 29, 2013, 10:21:50 AM
|
Jason Haddix is back with a great interview with great guys doing a great project. Can I say great one more time? Check it out. If you've got the talent and have been looking for some extra money or another item for the resume, this is for you. Permalink: [Article]-Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug BountiesLove it or hate it, crowdsourcing is here to stay. While it’s been mostly confined to development and design, eventually it was going to come to security. Two such gentlemen trying to pioneer the space are Casey Ellis and Sergei Belokamen. Being long-time hackers and having seen how the security space works, they decided to start Bugcrowd. Here’s a description directly from the source: “Bugcrowd is by far the most comprehensive and cost-effective way to secure websites and mobile apps. We’ll do a brief consultation and help you set the budget, the duration, and which websites or apps you’d like our curated crowd of researchers to test. The Bugcrowd researchers get to work finding security flaws in your applications. All testing can be routed through Bugcrowd’s crowd-control system, providing control and accountability. Any bugs are submitted to our Secure Operations Centre as soon as they are found. We validate the flaws and, at the end of the bounty, reward the first researcher to find each unique flaw. We provide you with an easy to understand report for you to hand to your developers… We can even recommend partners to help you fix what we find!” Join me as I interview them both about their new venture and uncover some interesting information about security testing on a massive scale, as well as how to start. For example, if you are a tester looking to participate, it couldn’t be easier. Fill out the “Ninja” form and create an online profile (public or private) in which you provide Bugcrowd with your PayPal email address. Then you wait until you receive an email message announcing a new bounty… and it looks a little something like this… Join, discuss, share prior experience with Bugcrowd... Don
|
|
|
|
|
28
|
Resources / Career Central / Re: Am I too old for a career change into security?
|
on: March 22, 2013, 12:16:41 AM
|
|
OK... I'll chime in. Since I was in grade school, I was playing with computers. Anyone remember 808x processors, the Osborne "portable" computer or The Source? At 30 I was a partner in a software company, but I didn't get my first certification until after that when the tech and telecom bubbles burst. Since then I earned MCSE, Security+, CISSP et al. It wasn't until I was 34 that I started EH-Net. On a personal note, I started martial arts at 40, I'm now 42 and a brown belt. If I keep going (and I plan to), I could earn black before the end of the year... that would make me 43. I didn't get married until 32 which makes my 10th anniv this year. BTW - I'm a stay-at-home Dad.
You are the decisions you make, and you can be whatever you set as your goals regardless of age. I have more goals than I can ever accomplish in a lifetime, but that will never paralyze me into achieving none of them.
Take this as you will, and I hope for the best possible future for you and all EH-Netters.
Don
|
|
|
|
|
29
|
EH-Net / Calendar Of Events / Cybit Expo 2013
|
on: March 21, 2013, 11:55:28 AM
|
Cybit Expo 2013 May 8 - 9, 2013 New York, NYWe are proud to announce Cybit (Cyber Security and IT Security), The Computer Forensics Show and The ASIS Show, May 8-9, 2013 at the Jacob Javits Center, New York City, NYThe ONLY industry events that incorporate IT Security, Cyber Security, Investigations, Electronic Discovery, Records & Document Management, and Computer Forensics in one venue. Security is in the news almost every day. Companies and organizations need to stay abreast of the latest issues. The events will provide real word answers to the issues facing us and will highlight exhibits from leading companies, complemented by a comprehensive conference program to provide attendees with important information about the latest technological advancements, ideas and practical information available today. VenueJacob Javits Center New York City, NY For more info: http://www.cybitexpo.comDon
|
|
|
|
|
30
|
EH-Net / Calendar Of Events / SOURCE Dublin 2013
|
on: March 21, 2013, 11:47:09 AM
|
SOURCE Dublin 2013 May 23 - 24, 2013 Dublin, IrelandSOURCE Dublin combines cutting-edge business, technology, and application security presentations, providing security experts and industry professionals the opportunity to share insights and develop future business prospects. Our intimate environment provides a unique and rare opportunity to develop deep professional relationships and to gain insight into individual perspectives and experiences within the security industry. Dublin attracts technology, innovation, and cutting-edge industry leadership, making it the ideal place to present a one-of-a-kind professional computer conference that explores important new trends in a fun and educational environment. VenueTrinity College Dublin College Green, Dublin 2 http://www.tcd.ieFor more info: http://www.sourceconference.com/dublin/Don
|
|
|
|
|
Loading...
|
|
 |
|