Grec’s Weekly Infosec Ramblings for 2009-09-25
As some of you may have noticed, our “Ramblings” post usually comes out on Monday. But, due to our new “Where You Want to Be” feature on Mondays, we’re doing our “Ramblings” post on Fridays.
As always, feel free to stop by and say hello @grecs. You can also check out the NovaInfosec Twits list for more awesome people to follow during the week on Twitter.
Has DojoSec changed your life or your career? If so, the tweet below is for you!
- RT @DojoSec: In need of DojoSec testimonials for a press release either tweet @DojoSec or email dojosec at saecur dot com #
Up for some free reading?
- FREE CISSP BOOK: Haven’t read but can’t beat price. RT @danphilpott: Rehman rel new draft of book 4 download. http://ow.ly/pUry #edu #
If you’d like some great reading from local security bloggers, look no further than below.
- RT @room362: [Blog] GPU Hash / password Cracking: http://ow.ly/pUcM #novablogger #
- WORK 4 @TAOSECURITY: Well, not 4 his blog but 4 his day job. They’re looking to fill a SIEM position. http://ow.ly/pUuq #novablogger #
- DIGITAL SAFE HAVENS: @moranned ponders if the web can substitute 4 a physical safe haven. http://ow.ly/pUwm #novablogger #
- CONTRATS @RYBOLOV: He was only non-govie 2 contribute 2 “Guidelines 4 Secure Use of Social Media..”. http://ow.ly/qduZ #novablogger #
- As usual .. bringing it all together for the rest of us. RT @room362: [Blog] Password / Word lists: http://ow.ly/q4Pu #novablogger #
- RT @alexhutton: I md blog post. http://is.gd/3zc03 It’s a/b stnds & how they can B reimagined 2 help mk infosec better place. #novablogger #
- S.773 CARTOON: 1st tweeted by @danphilpott, @rybolov dedicated entire blog post to it. http://ow.ly/qdvX #novablogger #
Speaking of reading… here’s some great articles you don’t want to miss.
- NEW TWITTER WORM: @SCMagazine has a story on this. Watch links in DMs. http://ow.ly/qOkw #
- Interesting bug scary. RT @DarkReading: New Free Web Service Confirms Theft Of Your Identity http://ow.ly/q4LG #
- RT @danphilpott: Very accessible introduction to SCAP in ISSA Journal, by Ken Halley of Gideon: http://bit.ly/2pquN3 (PDF) #
- RT @danphilpott: OMB published M-09-32 Update on the Trusted Internet Connections Initiative today: http://bit.ly/bQPci (PDF) #
- PRINTER SECURITY: I always appreciate an article on bringing awareness to this topic. Thanks @CSOonline. http://ow.ly/qoAx #
- SOCIAL NET SITES LACK SECURITY: Nother report showing obvious. “95% of user-gen cmts.. contain links 2 mal progs” http://ow.ly/qeQA #
- HACKING HISTORY: Nice visual timeline from 1960s through 2008. Fr Draper and Goldstein through Conficker and TJX. http://ow.ly/qeS0 #
- AVOID FACEBOOK SCAMS: Nice article to pass along to your non-security family & friends. http://ow.ly/qeTi #
Looking for some great security meetups? We’ve got you covered.
- BLOGGED: Baltimore Node Meetup Tuesday, 09-29: Normal Meeting http://ow.ly/15QmcZ #
- BLOGGED: HacDC Infosec Meetup Monday, 09-28: Microcontroller Mondays http://ow.ly/15Qmd1 #
- BLOGGED: Where You Want to Be This Week – 09-21 http://ow.ly/15Q8Qr #
- BLOGGED: CapSecDC Infosec Meetup Event – Wednesday, 09-30: Normal Meeting http://ow.ly/15QAKf #
I guess this is as close to gossip as the security community can get.
- PAINTER FILLING IN: @dustinlfritz points out FBI guy fills in for Hathaway until cybersec chief named. http://ow.ly/q7OG #
- Mis-named. RT @GovInfoSecurity Confessions of a Cybersecurity Czarist. Blame me for the Obama “czars” brouhaha! http://bit.ly/M19PR #
Now security is permeating comics? Awesome!
- Lol! RT @danphilpott: Wow, one comic that captures the depth of debate over S.773: http://ow.ly/qdrK #
Dan Philpott was really on a roll this week.
- RT @danphilpott: NIST has released draft SP 800-127 Guide to Security for WiMAX Technologies: http://bit.ly/nIXRk #
- RT @danphilpott: NIST has released SP 800-41 Rev 1 Guidelines on Firewalls and Firewall Policy: http://bit.ly/LPdc3 (PDF) #
- RT @danphilpott: NIST has released SP 800-102 Recommendation for Digital Signature Timeliness: http://bit.ly/qmLKt (PDF) #
- RT @danphilpott: NIST has released SP 800-120 Recommendation for EAP Methods in Wireless Net Access Auth: http://bit.ly/3lYlxX (PDF) #
- RT @danphilpott: Mitre released v1.4 of the Common Attack Pattern Enumeration and Classification (CAPEC) content: http://bit.ly/20MTb #
- Can’t pass this up. RT @danphilpott: Complete Fed Security Spotlight interview w/ Ron Ross of NIST been posted: http://ow.ly/q4NH #
AppSec DC is right around the corner. Perhaps you saw our latest interview?
- RT @AppSecDC09: 3 more days for Early Bird Discount 4 http://AppSecDC.org Register: http://bit.ly/2QvoZ Hotel: http://bit.ly/oo4J2 #con #
- RT @AppSecDC09: New Small Business & Expo-Only sponsorships levels avail 4 http://AppSecDC.org PDF w/ details here http://bit.ly/NPaMo #
- RT @AppSecDC09: LAST week for the Early Bird Discount for http://appsecdc.org Register: http://bit.ly/2QvoZ Hotel: http://bit.ly/oo4J2 #
And lastly, some food for thought with the tweet of the week.



BLOGGED: Grec’s Weekly Infosec Ramblings for 2009-09-25 http://ow.ly/15R4Ek
This comment was originally posted on Twitter
BLOGGED: Grec’s Weekly Infosec Ramblings for 2009-09-25 http://ow.ly/15R4El
This comment was originally posted on Twitter
RT @grecs: BLOGGED: Grec’s Weekly Infosec Ramblings for 2009-09-25 http://ow.ly/15R4El
This comment was originally posted on Twitter
Blog: Grec’s Weekly Infosec Ramblings for 2009-09-25 | NovaInfosecPortal.com http://bit.ly/fhB4S
This comment was originally posted on Twitter