Pages

Showing posts with label sans. Show all posts
Showing posts with label sans. Show all posts

Friday, June 25

Live CD for Remote Incident Handling

This paper was written by Bert Hayes. Bert Hayes is a security professional at the University of Texas. When Bert originally wrote this paper, he submitted it to me for the SANS Gold process, and I helped push the paper in the right direction, however, while it was an excellent paper and well written, it didn't really meet the criteria we were looking for.

However, I thought "Wow, what a great idea, what a great paper. I am sure a lot of organizations will benefit from this."

Of course Bert nor I can be held liable for any damage you to do a computer while using this, (just to get that disclaimer out of the way), and it's recommended that if you are going to use the contents of the computer you are doing the investigation on for a prosecution, don't use this. (Changing the state of the data on the drive during a forensic investigation is generally frowned upon.)

But, as I said, this is a great paper and you should definitely download it and give it a read.

  • http://security.utexas.edu/consensus/How_To_UTIRD2.pdf


Enjoy

Wednesday, May 19

6 Tech Certifications That Will Get You Hired as a Security Pro

I'm not a gigantic fan of Security Certifications, but this is interesting, as it allows you to know your audience, and it allows the audience to know what to look for.

Why am I not a Gigantic Fan of Certifications?

  • Anything that can be bootcamp'ed is worthless.

  • Anything where all the answers can be found in the book for the classware, and you are allowed to take the classware book with you to the test.. worthless

  • Anything that does not require a practical exam.  (Either written or physically typing something) is worthless.  Which is why I am a slightly larger fan of the Gold GIAC certifications.  As they require you to write a practical.  Or the harder Cisco ones, or the Redhat exams.


Personally I'd rather hire someone that can do the job, do it well, and if they don't know the answer, know where to find it.

6 Tech Certifications That Will Get You Hired as a Security Pro | ITBusinessEdge.com.

Tuesday, February 16

Will Hack For SUSHI » MiFi Config Hack

Will Hack For SUSHI » MiFi Config Hack.

A post by friend and collegue at SANS Joshua Wright.  Joshua is one of the guys I know that is really proficient at hacking wireless.  Bluetooth, wifi, etc.  He does some really wonderful work at that, and he's fantastic at it.

This post is about him hacking his Mifi (Verizon).  He has two posts on the subject you should check out if you have a Mifi.

The other post is here.

Friday, January 15

Haiti domain registrations on the rise

Over the past couple days I've been reporting over on the Internet Storm Center about the number of domains that have been registered (either legitimately for good use, or for malicious use) concerning the Haitian Earthquake disaster.  Read the original article here.

Like I said in that article, we're assuming that these domains are being registered for legitimate and helpful use, but we try and keep our eye out for the illegitimate ones, just in case someone wants to put some malware on a site, or try and trick you into giving up your credit card numbers or donating money via Paypal to a "cause" that never donates the money to Haiti on the backend.  We saw this with Hurricane Katrina, we saw it with the Tsunami disaster, and now, we are seeing it with the Haitian Earthquake.  (See the article here.)

But the number of registered domains is on the rise.  We saw 38 on Wednesday, 445 on Thursday, and today we saw 680.   (So, well over 1,000) It's practically impossible to check these domains by hand, so we are working with a couple partners in the Internet Space to take a look at these domains with us to ensure that they are clean.

Please exercise caution when visiting these sites, and please, donate money for the cause.  But please be extra cautious about who you are donating money to.  You know you can donate to legitimate sites like the RedCross, but do you also know you can donate to these other organizations:

(Thanks Kevin for those links)

Thursday, October 23

ISC Podcast Episode Eleven Posted

Hey everyone, sorry it has taken so long to get around to recording another podcast episode. Travel schedules have been very crazy between us lately. Anyway, enough excuses, here is episode eleven. Thanks for all the emails asking me where it is! :) It helps to remind me....

All the podcasts
Just this podcast
Podcast through iTunes

Subscribe in a reader

ISC Podcast Episode Eleven Posted

Hey everyone, sorry it has taken so long to get around to recording another podcast episode. Travel schedules have been very crazy between us lately. Anyway, enough excuses, here is episode eleven. Thanks for all the emails asking me where it is! :) It helps to remind me....

All the podcasts
Just this podcast
Podcast through iTunes

Subscribe in a reader

Friday, August 29

Internet Storm Center Podcast Episode 10 posted

Just a quick note to let everyone know that we put out Podcast Episode 10.

iTunes users, go here to subscribe.
Non-iTunes users, go here to download.

As always we are looking for listener feedback, be sure and write in!

Subscribe in a reader

Internet Storm Center Podcast Episode 10 posted

Just a quick note to let everyone know that we put out Podcast Episode 10.

iTunes users, go here to subscribe.
Non-iTunes users, go here to download.

As always we are looking for listener feedback, be sure and write in!

Subscribe in a reader

Monday, August 25

Podcast Episode X Record Notice

Tomorrow night at 7:30 EDT (Eastern Daylight Savings Time) Johannes, John, and I will be recording Episode X of the Internet Storm Center Podcast.

We'll be broadcasting live at http://www.stickam.com/joelesler

Please come and join! We love live feedback, talk with us in the stickam interface or via IRC in #dshield on irc.freenode.net.

Thanks!


Subscribe in a reader

Wednesday, August 13

Podcast Episode Nine Posted

Okay, so after much crazyness concerning the Live Podcast from SANSFIRE of Episode 9, its finally posted.

So to give you a quick run down on what took us so long to get this thing posted, all of the mics that we were being used was going into a Soundboard, and the Soundboard audio was going directly out to a DVD recorder. The DVD recorder also had video In from a camera in the back of the room that was being manned during the podcast.

Turns out, the camera was also recording! Isn't that awesome? Well, turns out, there is alot of FAIL in this story.

The camera, has mysteriously vanished. Don't know where it went, but in it somewhere wherever it is, is a recording of the podcast. If someone finds this mythical recording, please, feel free to give me the video/audio off of what is inside it.

Wait, you say, what about the DVD Recorder? Well, we got the DVD, but the DVD has a big fat scratch down the middle of it, and we can't get the video off of it.

But luckily, I had garageband open, and I recorded the podcast using my built in mic on my macbook pro. Now, this is not the best audio in the whole wide world, but at the time, we had no alternative. So THAT's what the audio from the podcast is. Not out of the soundboard, not off of a video camera, but off of my built in mic on the MacBook Pro.

As a result the audio of some of the people, unless they were loud, or speaking into a mic, is not the best. You'll hear some of this in the beginning, but once we got everyone speaking into mics, and being loud, it gets a bit better.

You'll also hear me whispering for beer at some point in the beginning, just disregard that, beer was needed. :)

Enjoy.

UPDATE: Probably helps if I put a URL right?

All the podcasts

Just this podcast

Podcast through iTunes

Subscribe in a reader

Podcast Episode Nine Posted

Okay, so after much crazyness concerning the Live Podcast from SANSFIRE of Episode 9, its finally posted.

So to give you a quick run down on what took us so long to get this thing posted, all of the mics that we were being used was going into a Soundboard, and the Soundboard audio was going directly out to a DVD recorder. The DVD recorder also had video In from a camera in the back of the room that was being manned during the podcast.

Turns out, the camera was also recording! Isn't that awesome? Well, turns out, there is alot of FAIL in this story.

The camera, has mysteriously vanished. Don't know where it went, but in it somewhere wherever it is, is a recording of the podcast. If someone finds this mythical recording, please, feel free to give me the video/audio off of what is inside it.

Wait, you say, what about the DVD Recorder? Well, we got the DVD, but the DVD has a big fat scratch down the middle of it, and we can't get the video off of it.

But luckily, I had garageband open, and I recorded the podcast using my built in mic on my macbook pro. Now, this is not the best audio in the whole wide world, but at the time, we had no alternative. So THAT's what the audio from the podcast is. Not out of the soundboard, not off of a video camera, but off of my built in mic on the MacBook Pro.

As a result the audio of some of the people, unless they were loud, or speaking into a mic, is not the best. You'll hear some of this in the beginning, but once we got everyone speaking into mics, and being loud, it gets a bit better.

You'll also hear me whispering for beer at some point in the beginning, just disregard that, beer was needed. :)

Enjoy.

UPDATE: Probably helps if I put a URL right?

All the podcasts

Just this podcast

Podcast through iTunes

Subscribe in a reader

Thursday, July 24

Podcast Last night

The podcast last night (and my speech) went great, we had a great attendance (about 50-70 ish) turn out.

Unfortunately we were not able to broadcast it live since we had no internet, but we did get video and audio recordings of the whole thing.  We'll try and make those available soon!

Thanks for all those that turned out!

UPDATE:  I received word that there were 65 in the speech.  Even more in the podcast!

 Subscribe in a reader

Podcast Last night

The podcast last night (and my speech) went great, we had a great attendance (about 50-70 ish) turn out.

Unfortunately we were not able to broadcast it live since we had no internet, but we did get video and audio recordings of the whole thing.  We'll try and make those available soon!

Thanks for all those that turned out!

UPDATE:  I received word that there were 65 in the speech.  Even more in the podcast!

 Subscribe in a reader

Tuesday, July 8

Podcast Episode 8 Record Notice

Hey everyone, we're going to have a live Podcast record tomorrow at 6 pm EDT.  (That's Eastern Daylight Savings Time)

We'll be streaming it live via Stickam, and as always we welcome your feedback.  The link we'll be stream from is: http://www.stickam.com/joelesler

Please feel free to join us, we look forward to hearing your live feedback either in the Stickam Chat room, or in #dshield on irc.freenode.net.

 Subscribe in a reader

Wednesday, June 25

Podcast Episode Seven has been posted

The publishment (like that word don't you) of Podcast Episode Seven of the Internet Storm Center Podcast.

I'd like to thank all the viewers that were live on the show while broadcasting, it was great having you, maybe next time we'll be able to get more?  We had about 20 I believe (I didn't count) at one point.  It would be great if we could increase this count, as I'd like to do a live Q&A via the listeners.  (Couple new segments I'm working on)

We had Paul Asadoorian of PaulDotCom Security Weekly as a guest, and it's probably our best podcast yet!

Go grab it through iTunes, and for those of you that are not listeners of PaulDotCom, please subscribe to that one too!

 Subscribe in a reader

Podcast Episode Seven has been posted

The publishment (like that word don't you) of Podcast Episode Seven of the Internet Storm Center Podcast.

I'd like to thank all the viewers that were live on the show while broadcasting, it was great having you, maybe next time we'll be able to get more?  We had about 20 I believe (I didn't count) at one point.  It would be great if we could increase this count, as I'd like to do a live Q&A via the listeners.  (Couple new segments I'm working on)

We had Paul Asadoorian of PaulDotCom Security Weekly as a guest, and it's probably our best podcast yet!

Go grab it through iTunes, and for those of you that are not listeners of PaulDotCom, please subscribe to that one too!

 Subscribe in a reader

Tuesday, June 24

Podcast Episode Seven Record Notice

Hey all, just to let you all know Johannes, Paul Asadoorian, (Of PaulDotCom Security Weekly fame) and I will be recording the Internet Storm Center Podcast (Episode 7) tonight at 7:30 pm EDT. 

I'll be broadcasting it live on Stickam (Ustream seems to be having issues today):


See you there if you can make it!

 Subscribe in a reader

Podcast Episode Seven Record Notice

Hey all, just to let you all know Johannes, Paul Asadoorian, (Of PaulDotCom Security Weekly fame) and I will be recording the Internet Storm Center Podcast (Episode 7) tonight at 7:30 pm EDT. 

I'll be broadcasting it live on Stickam (Ustream seems to be having issues today):


See you there if you can make it!

 Subscribe in a reader

Friday, June 13

Podcast Episode Six

As always, for your enjoyment, we have published Podcast Episode Six of the Internet Storm Center Podcast.

I'd like to thank all the viewers that were live on the show while broadcasting, it was great having you, maybe next time we'll be able to get more?

We again, had Larry Pesce of PaulDotCom Security Weekly.

Go grab it through iTunes.

As I said in my after-show notes, subscribe to PaulDotCom and our show through iTunes, that way together, we can become more powerful than you can possibly imagine.

Subscribe in a reader

Podcast Episode Six

As always, for your enjoyment, we have published Podcast Episode Six of the Internet Storm Center Podcast.

I'd like to thank all the viewers that were live on the show while broadcasting, it was great having you, maybe next time we'll be able to get more?

We again, had Larry Pesce of PaulDotCom Security Weekly.

Go grab it through iTunes.

As I said in my after-show notes, subscribe to PaulDotCom and our show through iTunes, that way together, we can become more powerful than you can possibly imagine.

Subscribe in a reader