Skip to content

Posts from the ‘Syracuse InfraGard’ Category

A book review on “Ghost in the Wires” by Steve Hunt – SecurityDreamer

Ghost in the Wires: My Adventures As the World’s Most Wanted Hacker, By Kevin Mitnick

Book Review by Steve Hunt

July 2011 Kevin Mitnick taught me how to play blackjack in Las Vegas. He sat next to me at the Golden Nugget and coached me while I played. I won several times and walked away $400 ahead. He lost about that much. He just didn’t know when to quit. As I read his memoir, I would sometimes shout out loud at the pages. “Kevin, what are you DOing?! It’s time to quit!”  …read the entire review by Steve Hunt

Reading and Review

 

Summer, 2011 – The Journal of Strategic Security- “In today’s information age, the People’s Republic of China has replaced and even improved upon KGB methods of industrial espionage to the point that the People’s Republic of China now presents one of the most capable threats to U.S. technology leadership and by extension its national security.” —Dan Verton, Cyber Warfare Expert .  This quote leads into The Journal of Strategic Security, Summer, 2011  http://www.henley-putnam.edu/templates/hpu/downloadables/journal/2011/JSS_Vol4No2_Summer2011.pdf

 

The Quadrennial Defense Review (QDR) is a legislatively-mandated review of Department of Defense strategy and priorities. The QDR will set a long-term course for DoD as it assesses the threats and challenges that the nation faces and re-balances DoD’s strategies, capabilities, and forces to address today’s conflicts and tomorrow’s threats http://www.defense.gov/qdr/images/QDR_as_of_12Feb10_1000.pdf

 

Source: IACA “International Association of Crime Analysts”

Over the past month, InfoSec Institute has developed a number of free training resources for your benefit. As a reminder, if you hold a professional certification such as the CPT, CISSP, CISA, CEH, etc, reading these resources can count for your required CPEs.

Here are some of the highlights from March 2011:

  1. HD Moore’s Process for Security Research- The creator of Metasploit and one of the most prolific exploit developers, reveals his process for security research. HD talks about his tools, techniques and provides some insight into what attacks will look like in the future.
  2. OWASP Top 10 Tools and Tactics- The OWASP Top 10 aggregates the 10 most prevalant application security vulnerabilities. We feel awareness is not enough. Russ McRee shows in this article how to actually test for these vulnerabilities, and shows tool usage on how to do so. Remediation strategies are discussed as well.
  3. OllyDbg Exploit Development Walkthrough - Following up on Stephen Bradshaw’s Learn to Fuzz with SPIKE walkthrough is an article series on how to write an exploit using OllyDbg as the primary runtime tool of choice. 
  4. Top 5 CCFE Computer Forensics Practicals- We release the Top 5 IACRB CCFE practicals submitted by InfoSec Institute students. Learn how our top students solved the case and wrote an in-depth forensics practical.
  5. Boy-In-The-Browser- Imperva’s Amichai Shulman discusses the latest malware research into the Boy-In-The-Browser variation of the Man-In-The-Browser attack. Learn how to detect compromised systems and repair hijacked hostifles in this article.
  6. iPhone Forensics / 10 iPhone Must Have Security SettingsKeatron Evans brings you a video tutorial on iPhone Forensics, what evidence can be retrieved and how to do it. He also talks over his Top 10 Tips for securing your iPhone, a must have for enterprises looking at adopting the popular smartphone.
  7. Strategies for Studying Each of the 10 CISSP Domains- Kenneth Magee takes you through his teaching process for the 10 CISSP domains. Learn what to focus on, what will be on the exam, and how to prepare for the exam.
  8. Charlie Miller and Joanna Rutkowska discuss their processes for security research. Charlie, famous for discovering/exploiting many Apple product vulnerabilities, as well as seeming to always win the pwn2own contest at CanSe cWest, discusses how he finds bugs and exploits. Joanna, the world’s foremost virtualization security expert, discusses her latest research techniques and the new Qubes OS.
  9. Standards for Penetration Testing? – I review the newly released Penetration Testing Execution Standard in detail, talking to the creators and getting a critical eye from others working on similar standards in the industry.

These popular articles and videos, are just a few of our recently posted articles. There is much more to read, watch, and learn on http://resources.infosecinstitute.com. If you’d like to write for Resources.InfoSecInstitute.com and be featured in industry publications (and here) please contact me, our Managing Editor, Terrence Miltner at terrence.miltner@infosecinstitute.com with an article or video topic idea.

Follow

Get every new post delivered to your Inbox.