Grec’s Weekly Infosec Ramblings for 2009-05-31
Unless you were a) on vacation, b) avoided all electronic devices, or c) locked yourself away so human contact was impossible for the past week, you are at least a little aware of the big discussion surrounding President Obama’s Cybersecurity speech.
While the Cybersecurity discussion captivated most of the Twittersphere this week, there was some other interesting stuff that happened. (We promise!)
First, the obvious topic of choice.
- RT @TruSecure A Cybersecurity Quiz: Can you tell Obama from Bush?: Shared by Kennedy Risk impact (0)GRC, Mgt Tre.. http://tinyurl.com/lnx74t #
- As expected. RT @truland Still digesting Cybersec speech & report. Nothing really different, now hard part. Will OMB agencies be funded? #
- RT @txitua Next Wk is #cfp09. Follow @edfelten @digitalsista @Gauravonomics @wonderwillow @hellrazr @jdp23 @netfreedom @txitua #privacy #con #
- Wow it’ll be streaming too. RT @txitua Follow Computer, Freedom & Privacy online at http://www.ustream.tv/channel/cfp09 #cfp09 Pls. RT #
- And even a streaming schedule! RT @txitua Online schedule for #cfp09 stream is at http://bit.ly/3pCqj #
- RT @RodBeckstrom Obama cyber speech: http://bit.ly/c8hfB #
- RT @bobgourley New post: White House Cyber Policy Review: And a Cyber Czar (http://cli.gs/sV0Jyz) #novablogger #
- RT @SCMagazine Industry reacts to Obama’s cybersecurity speech: Cybersecurity industry was abuzz Friday after Pr.. http://tinyurl.com/n335e4 #
- RT @securitytwits RT @tqbf: “Jaquith’s review on the ‘Cybersecurity Review’, on HN… http://bit.ly/kCJ43” #
- RT @CSOonline NEW: Cybersecurity Announcement: Obama Moves in the Right Direction http://tinyurl.com/m6fede #
- RT @CSOonline Blog: Will Obama’s New Cyber-Security Plan Make a Difference? We Can Only Hope: Andrew Jaquith read more http://bit.ly/3VelAc #
- RT @werntzp Devil in the details and prose sloppy in places but I think overall Obama said right things in #cybersecurity speech. #
- RT @IBMFedCyber its clear Obama nderstands following: 1.) the threat 2.) the tech & 3.) the mission – wlkng away hopeful. #whitehousecyber #
With the Cyber Czar debate coming in at a close second.
- RT @packetwerks New cyber czar not cab level, no budget, no authority. 2000 called, it’s NIPC and they are laughing. #
- RT @bobgourley My view of wht ths means: He will not choose anyone as Czar that press has pontificated on. None of those met his criteria. #
- RT @cyberwar Cyber Security Czar may be named by end of week. http://tinyurl.com/opgdnv Or at least the position will be announced. #
- RT @danphilpott RT @vaklove: Obama Set to Create A Cybersecurity Czar With Broad Mandate http://ow.ly/9aTM (via @NickHeller) #
We featured Richard Bejtlich’s take on the whole Cybersecurity issue in our “Top 3 NoVA Infosec Blog Posts of the Week” this week along with posts by @mubix and @geminisecurity.
- RT @mubix Blogged Getting your fill of Security – Room362.com: I recently posted blog post to Ex .. http://tinyurl.com/l6pfhw #novablogger #
- RT @geminisecurity New blog post: How does SSL work anyway? http://bit.ly/hVuWr #novablogger #
While the Cybersecurity buzz captured most people’s attention this week, there was some other news.
- NEWSBITES: Playing news catchup. http://bit.ly/7pYN6 #
- GAO SEC REPORT: Getting better but still not good. It’s a hard problem to solve. http://tinyurl.com/pqxcts #
- FBI/U.S. MARSHALS MYSTERY VIRUS: Type of thing we have 2 worry a/b – the unknown unknowns. http://tinyurl.com/phhe78 #cmt #
- SECURITY METRICS GALORE: Nice summary of efforts going on. Did we need another one? http://tinyurl.com/rd8vlk #cmt #
- ADOBE QUARTERLY PATCHES: Slow response should not mean scheduling something to happen 4x/yr. http://www.securityfocus.com/brief/965 #cmt #
As well as a few new tools worth checking out.
- RT @danphilpott RT @DidierStevens: PDF Structazer tool pres at BH EU 2008 released: http://bit.ly/2lqVX <- Deep PDF analysis tool! #tool #
- RT @mubix RT @PortSwigger: Burp Suite Pro v1.2.10 released – http://releases.portswigger.net/2009/05/v1210.html #tool #
- Love these things. RT @sans_isc [Diary] Host file black lists , (5/27): Henry Hertz Hobbit who maintains .. http://tinyurl.com/qq3w94 #tool #
- RT @mubix RT @_defcon_: New DEFCON Tools page is up! Thanks to @mubix for providing the content! http://bit.ly/Qtvz9 #tool #
- RT @ksignal9 The Register covers the ressurection of l0phtcrack: http://bit.ly/TdXUN #tool #
Some of them might come in handy if you end up searching for the most ‘dangerous’ keywords out there.
- Looks interesting. RT @TruSecure Web’s most dangerous keywords 2 search 4: Shared by Kennedy Risk impact (?)Dece.. http://tinyurl.com/ojmnp3 #
- Scary! RT @TruSecure Microsoft Update Quietly Installs Firefox Extension: Shared by Kennedy Risk impact (?)WTF? .. http://tinyurl.com/ncttup #
But moving on, it looks like there’s quite a few cool events that have happened recently/will be happening soon.CharmSec is one of them.
- RT @charmsec CharmSec 13: tomorrow at 7PM, Sláinte, Fells Point, Balt, MD, Earth, Sol System, Western Spiral … http://is.gd/ENF7 #mtg #
As is Dojosec…
- RT @dojosec DojoSec Monthly Briefings next Thursday. Visit http://www.dojosec.com for details. #mtg #
And HacDC.
- RT @hacdc New post: Peter W. Singer and “Wired for War” at HacDC on June 2 http://tinyurl.com/lopsnr #mtg #
There’s also some new information about SANSFIRE that you don’t want to miss.
- RT @charmsec .@sdwilkerson SANSFIRE 09 is in Balt 6/13-22. #charmsec 13.5 the 14th? 21st Tough 2 not clash w/ SANS http://is.gd/HcFD #con #
- And more. Wow, wish could have made it. RT @charmsec …Univ accreditation, and where CharmSec 13.5 should be during SANSFIRE 2009, June 14. #
- RT @charmsec .@sdwilkerson 6/14 it is. There’re lots of places closer 2 SANSFIRE than Sláinte. Will pick one soon (open to suggestions) #mtg #
If you didn’t get a chance to look at it already, there’s also some cool stuff about the history of Memorial Day.
- Remember. RT @planetrussell The Birthplace of Memorial Day, Boalsburg, PA – 5 mins from my home: http://tr.im/boals + http://tr.im/boals2 #
Since there’s no better way to end a post than with a challenge, here’s a packet challenge posted by Chris Christianson.
- RT @mubix FB RT: Chris Christianson Posted a new packet challenge. Have fun. http://bit.ly/p6XTr #edu #
o o o o o
How Ironclad is your information?


