Grec’s Weekly Infosec Ramblings for 2009-08-31
Like to know what’s going on in the local security community? Follow us @grecs during the week to get all the local news via the comfort of your Twitter feed.
Always great to start this post off on a good note. We couldn’t think of anything better than helping out the good folks at Hackers for Charity.
- Everybody follow @marcusjcarey ‘ s lead! RT @marcusjcarey: Just donated $100 to Hackers for Charity http://www.hackersforcharity.org #
Speaking of Marcus J. Carey, seems that he and DojoSec are hosting a conference in November.
- This is a new twist. RT @marcusjcarey @securitytwits Mark it down! DojoCon (DojoSec Conference) benefiting HFC, Nov 6-7 in Maryland #con #
- RT @AppSecDC09: #AppSecDC now has new look launched last wk http://appsecdc.org/ . Thks to @nclud design studio for site design. #con #
- RT @marcusjcarey: METASPONSE: Incident Response with Metasploit, added to Techno Forensics Agenda – http://bit.ly/qfAPR #con #
- RT @bobgourley Just added 5th Annual IT Security Automation Expo (27-28 Oct )to Fed Tech Events Cal: http://bit.ly/Pfnf0 #con #
- RT @AppSecDC09 How to 2 attnd #AppSecDC? 1st u reg http://bit.ly/2QvoZ Then u get hotel room! http://bit.ly/oo4J2 Early Bird 9/25! #con #
In addition to the DojoSec meetup that’s coming up this week, here’s some more meetups to think about.
- RT @charmsec: Expecting new faces Wed! Ask @grantstavely a/b CPE points & free beers thks 2 our sponsors. Fnord. Sláinte is all ages. #mtg #
- RT @dallendoug: RT @CapSecDC is THIS EVENING, starting at Stetson’s at 5 PM. 1610 U St NW. May wander down U Street, so follow us! #mtg #
- RT @rybolov @OWASP_podcast: OWASP Podcast FISMA Roundtable is on, Mon at 5:30 at Wash Circle Hotel. Live participants only. DM for details. #
- RT @baltimorenode: Reminder: Last meeting of the month tomorrow @ 7:30. Its perfect time 2 become new member! http://ow.ly/l7dP #mtg #
- RT @owaspdc: Nxt @OWASPDC #Mtg 9/2/09 @ 6:30 PM in Foggy Bottom. M. Flick & J. Yestrumskas on Cross-Site Anon Browser. http://bit.ly/m3BF0 #
These should keep your Monday interesting if you haven’t had the chance to read them already.
- Figured I join in. RT @ksignal9 German hackers crack GSM encryption, Chaos Computer Club to release to the public. http://bit.ly/Qjy9o #
- INSIDER LEAKS – AN ACCIDENT?: @DarkReading reports that most insider leaks happen by accident. Interesting.. http://bit.ly/4ti7Fn #
- FISMA REPORTING: @GovInfoSecurity sums OMB’s new FISMA auto sys. Lots of critisism too. mayB small step in rt direct? http://bit.ly/mdg5p #
- Is this legit or just theoretical? RT @packetwerks WPA broken in few minutes. Article: http://bit.ly/8Uz4G, Paper: http://bit.ly/DaHMk #
- RT @danphilpott NIST released a draft version 2.0 of the Open Checklist Interactive Language (part of SCAP): http://bit.ly/Oq0Av #
Loca security bloggers sure seemed to be busy this past week. Wonder if it will slow down toward the holidays.
- SANS WHATWORKS IN INCIDENT DETECTION SUMMIT: @taosecurity blogged web site 4 #con is now active. http://ow.ly/nlSV #novablogger #
- KEEPING BSD UP-TO-DATE: @taosecurity continues to update this guide. http://ow.ly/nlTI #novablogger #
- APACHE STRESS TEST: @rybolov web svr has been having probs. 2 debug he needed load. Here is his howto. http://bit.ly/3nJ4rx #novablogger #
- RT @rybolov New blog thingy by @danphilpott: OMB online FISMA reporting and other changes. http://bit.ly/mQpxC #novablogger #
- RT @geminisecurity New blog post: WinSCP for Secure FTP http://bit.ly/KDfxu #novablogger #
- NEWS & COMMENTARY: @wadew is at it again w/ commentary on this week’s news. Looks 2 b weekly post. http://bit.ly/3n5fH #novablogger #
- NEW SECURITY MODEL: @rybolov is @ it again. Chck out his new layered model 4 large-scaled sec mgmt http://bit.ly/WxWEs #novablogger #
- RFI: Wow, 2 posts in 1 night fr @rybolov. Be sure to cp his template & submit to Data.gov! http://bit.ly/ZJGaU #novablogger #
- PTH METASPLOIT DEMO: @mubix put together a gr8 vid on this. http://ping.fm/pxBRe #novablogger #
If you’ve been wondering what to read next, look no further.
- CYPHERPUNK READING LIST: Nice find by @rybolov. http://bit.ly/B3feK #toread #
- GEEKANOMICS: Heard this is a book sec pros should read. Thoughts? #toread #
- Another #toread RT @electricfork: Finished “new school of infosec” . cross b/t rant & manifesto but can’t disagree w/ conclusions. #
- RT @pauldotcom Who is Daniel Suarez you ask? What is “Daemon”? Only one of the best books ever! Read my full review: http://bit.ly/4RAnY #
Everyone’s favorite; more cheatsheets!
- CHEATSHEET OVERLOAD: U want cheatsheets.. I’ll give u cheatsheets. RT @mubix RT @craiglawson: Security Cheatsheets http://bit.ly/EJf2C #
- Yeah, more cheatsheets! RT @pauldotcom RT @RonGula: Very cool security cheat sheets. Nessus, Nmap, netcat, +: http://bit.ly/18SJoe #
If you’re looking for something interesting to do, try this! (Hopefully it’s still going.)
- Nother weekend chal. RT @dallendoug Part of my weekend now! RT @tqbf Go 2 http://bit.ly/d309c, sign up, leave comments on Cybersecurity Act. #
And lastly—in case you missed it—our #totw.
- RT @danphilpott @cyberhiker @jack_daniel I prefer to think of it as outsourcing my competence to focus on core incompetence. #totw #



New blog post: Grec’s Weekly Infosec Ramblings for 2009-08-31 http://bit.ly/37qMg
This comment was originally posted on Twitter
BLOGGED: Grec’s Weekly Infosec Ramblings for 2009-08-31 http://bit.ly/r2czD
This comment was originally posted on Twitter