security.crudtastic.com

Security Nerd Stuff

Browsing Posts published in March, 2009

NEWS JUST IN

SANS Canberra 2009 is coming up soon on 29 June – 4 July. The deadline
to receive a $350 tuition fee discount is 20 May. 2009. So don’t delay
- to get the best savings, start making your training and travel plans
now! (http://www.sans.org/info/41308)

First things first – make your course selection from the following top
SANS courses:

– SEC401: SANS Security Essentials Bootcamp Style – Mark Hofman
– SEC504: Hacker Techniques, Exploits & Incident Handling – John Strand
– SEC560: Network Penetration Testing and Ethical Hacking – Bryce Galbraith
– SEC508: Systems Forensics, Investigation & Response – Rob Lee

Complete course descriptions can be found by clicking on the links at

http://www.sans.org/info/41313.

Classes will be held at the National Convention Centre. This
contemporary facility places you close to accommodations as well as
stylish restaurants, trendy cafes, boutique shopping, and entertainment.
See our Web site for links to assist in finding accommodations.
(http://www.sans.org/info/41318)

Don’t miss the following evening events, the additional content that
makes SANS such a great value for your security training:

– SANS Welcome – Mark Hofman
– GIAC Program Overview – John Strand
– Incorporating Advanced MitM Attacks in Your Penetration Testing
Regimen — Bryce Galbraith
– Production Honeypots – John Strand
– State of the Hack: The Chinese Threat – Rob Lee
– SOA and XML security – Mark Hofman

“Lots of valuable info was provided that will be very helpful &
applicable to my work environment.” – Ian Phan, Centrelink

“It is excellent seeing technical implementations of attacks that I
have studied theoretically!” – Julian Gutmanis, CSC

SANS is the most trusted source for information security training, so
why go anywhere else? Register today for SANS Canberra 2009 at
http://www.sans.org/info/41318. We’ll see you there!

So we all know Conficker is meant to explode our brains, empty our bank accounts and then run off with our dog on the 1st of April right? There’s a bunch of people that have applied the MS08-067 patch that basically stops all this nastiness, they’re probably also the same people that have strong passwords and an up to date antivirus solution.

So I guess the next thing is trying to track down machines that are already infected. The guys at SkullSecurity have a great blog article on how to use nmap to scan your network and detect these infected hosts.

If you get any errors it’s really worth reading through all the comments, Ron has done a great job in trying to respond to everyone. There are apparently some other tools coming out soon from other vendors .. but who doesn’t love an excuse to bust out nmap in anger!

isc-thumb
Why not try the SANS Internet Storm Center?? They have handlers on keeping an eye on everything you should be keeping an eye on! The internet is a big bad world, make sure you are aware of everything as it happens or even before it happens!

Also, don’t forget to see if there’s some training in your local town .. You won’t regret it!

I originally saw this youtube video when I attended SANS last year. It’s Joshua Wright showing you how easy it is to inject and record audio on standard bluetooth headsets. Enjoy!

I saw this the other week and thought it was kinda cool