Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow Latest security Trend,
EH-Net
May 24, 2013, 12:02:33 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Latest security Trend,  (Read 10878 times)
0 Members and 1 Guest are viewing this topic.
sajeeva
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: March 22, 2010, 04:01:21 AM »

hi..
I went to an interview and they asked me to do a presentation on "the latest security  trend". they expect something new. for ex, it shoud not be firewalls, since everybody knows about it. the topic should be bit advance. it should be up to my level. im a graduate and reading for CEH. your suggstions are wrmly welcome.
thnks...
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #1 on: March 22, 2010, 04:33:59 AM »

does it have to be technical or more management level? things like botnets or cloud computing are always good material to educate about. another thing that is interesting is VMware hacking (if it has to be about hacking). i've been to a vmware hacking presentation last week and dispite its shortness (about 20min) it was very interesting.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #2 on: March 22, 2010, 05:38:02 AM »

Yeah, with MANY of my clients leaning on VMWare and various definitions of 'cloud computing,' I find that virtualization security is a very hot topic right now.  I've spoken to two local government agencies, recently, who are discussing pentests with me, who have had their outsourced VM / cloud services hacked, within the past 3 months.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #3 on: March 22, 2010, 05:44:59 AM »

Maybe you can get some ideas from the Top Security Predictions for 2010 thread.

btw, welcome to the forums, sajeeva.
Logged
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #4 on: March 22, 2010, 09:33:11 AM »

I'm not sure in what field your company is active, but just spouting a few idea's on recent stuff that I find interesting.

There has been some news about successful blows against criminal botnets. That's always something that speaks to the imagination:

Also, along the line of awesec: If this company's focus is towards development, the OWASP TOP 10 project (Top 10 application security vulnerabilities) might give some inspiration. You might pick an interesting application vulnerability and expand on that. If I'm correct, knowledge of application security is very limited in most circles :-)
http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project

(Edit) Or, concerning new tools: the new webapp security tool from Google, Skipfish. You can hardely go more recent then that ;-)
There is a nice review from Jason (Jhaddix):
http://www.redspin.com/blog/2010/03/19/skipfish-google-enters-the-web-scanner-fray/

Good luck!
« Last Edit: March 22, 2010, 11:07:05 AM by Anquilas » Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
sajeeva
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: March 22, 2010, 12:53:05 PM »

j0rdy, hayabusa, awesec and Anquilas, thank you all for ur replies..

@ Anquilas, thnks for ur reply,yep, that company i went for the interview has a team consists of ethical hackers, and they do pen testing and suggest the solutions for vulnrbilities found. 

wel, the topic "cloud computing" got my attention. hope it wuld be ok for the presntation. if you know any good sources to find the knowldge, plz let me know,
thnks  Smiley
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #6 on: March 22, 2010, 01:03:47 PM »

You should be able to find some resources from conferences such as BlackHat and similar ones, e.g. there was a presentation titled Cloud Computing Models and Vulnerabilities: Raining on the Trendy New Parade. There were some more presentations on this topic throughout various other security conferences as well.
Logged
rvs
Jr. Member
**
Offline Offline

Posts: 94


View Profile
« Reply #7 on: March 22, 2010, 02:55:22 PM »

Try this topic. Cross Application Scripting

http://www.backtrack-linux.org/backtrack/cross-application-scripting-all-you-kde-are-belong-to-us/
Logged
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #8 on: March 22, 2010, 04:48:43 PM »

You're most welcome m8.

There is a seminar about Virtualization & Cloud Security on the InfoSecurity.be event that I'm going to this week.
If I get my hands on some (digital) material, I'll be sure to let you know.

Cheers,

Anq
Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #9 on: March 22, 2010, 06:06:19 PM »


Another hot topic --> APT (Advanced Persistent Threat):

http://taosecurity.blogspot.com/2010/01/what-is-apt-and-what-does-it-want.html

http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=222600139
Logged

Security+, OSCP, CEH
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #10 on: March 23, 2010, 03:46:29 AM »

if your still not sure what "black hat" topic to choose:

http://www.defcon.org/html/links/defcon-media-archives.html

a very good resource for the latest topics!
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #11 on: March 23, 2010, 04:41:29 AM »

Sweet link :-) Cheers!
Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
n1p
Jr. Member
**
Offline Offline

Posts: 89


View Profile WWW
« Reply #12 on: March 23, 2010, 03:39:36 PM »

Advanced Persistent Threat may be a good topic, if you are interested in malware and targeted attacks that is! However, if it is an interview, you could demonstrate up-to-date security knowledge, with technical ability (through demo of PDF reversing and shellcode extraction for example) and also an appreciation of the business side of things. Such attacks are targeted against business and as such may have a direct effect on revenue, profit and reputation. Things business execs are all too careful about. Therefore you would demonstrate various aspects of your skillset that interviewers are looking for, whilst getting to talk about something interesting... Again helping you to demonstrate your enthusiasm for security as a whole

Just a thought...

n1p
Logged
sajeeva
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #13 on: March 24, 2010, 02:14:25 AM »

hi.. all thanks for your replies.links you provide are very usefull.
since cloud computing is sorta broad topic, they askd me to do the presentation on "heuristic scanning". have any idea about it?
thnks
Logged
sajeeva
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #14 on: March 24, 2010, 02:16:07 AM »

if your still not sure what "black hat" topic to choose:

http://www.defcon.org/html/links/defcon-media-archives.html

a very good resource for the latest topics!

nice link Smiley thnnks
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.167 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.