<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; blog</title>
	<atom:link href="http://www.novainfosecportal.com/tag/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/07/27/top-3-nova-infosec-blog-posts-of-the-week-18/</link>
		<comments>http://www.novainfosecportal.com/2009/07/27/top-3-nova-infosec-blog-posts-of-the-week-18/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 15:00:42 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[local-bloggers]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1849</guid>
		<description><![CDATA[Richard Bejtlich and @rybolov return to the top three this week with posts that sum up the recent SANS event and the need for more security folks. @geminisecurity makes the top three with their practical post &#8220;DVWA &#8211; Damn Vulnerable Web App.&#8221; But before we get on to the posts, a small tangent for this week&#8217;s tweet of the week (#totw). grecs: LOL. RT @mckeay Ah the buddy system: I don&#8217;t have to run fast, I just have to run faster than my buddy. totw For those of you who don&#8217;t understand the reference, this tweet is making a play on the classic security philosophy of the buddy system. The philosophy basically goes like this: If a cheetah goes to eat two gazelles, there&#8217;s a good chance that one gazelle will survive—if he&#8217;s faster than his buddy, that is. The cheetah will catch the slower of the two gazelles while the other gazelle is free to run away to live another day. We apply that to security by saying &#8220;always be faster than your buddy&#8221; which means that your security doesn&#8217;t always have to be 100 percent, it just needs to be more secure than others. Now, on to the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FncL5J8" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/07/27/top-3-nova-infosec-blog-posts-of-the-week-18/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p style="text-align: left;">Richard Bejtlich and <a href="http://www.twitter.com/rybolov">@rybolov</a> return to the top three this week with posts that sum up the recent SANS event and the need for more security folks. <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> makes the top three with their practical post &#8220;DVWA &#8211; Damn Vulnerable Web App.&#8221;</p>
<p style="text-align: left;">But before we get on to the posts, a small tangent for this week&#8217;s tweet of the week (#totw).</p>
<div class="msg">
<ul>
<li><a onclick="pageTracker._trackPageview('/exit/to/grecs');" href="http://twitter.com/grecs" target="_blank">grecs</a>: <span id="msgtxt2809316982" class="msgtxt en">LOL. RT <a onclick="pageTracker._trackPageview('/exit/to/mckeay')" href="http://twitter.com/mckeay" target="_blank">@mckeay</a> Ah the buddy system:  I don&#8217;t have to run fast, I just have to run faster than my buddy. <strong>totw</strong></span></li>
</ul>
</div>
<div class="msg">For those of you who don&#8217;t understand the reference, this tweet is making a play on the classic security philosophy of the buddy system. The philosophy basically goes like this: If a cheetah goes to eat two gazelles, there&#8217;s a good chance that one gazelle will survive—if he&#8217;s faster than his buddy, that is. The cheetah will catch the slower of the two gazelles while the other gazelle is free to run away to live another day. We apply that to security by saying &#8220;always be faster than your buddy&#8221; which means that your security doesn&#8217;t always have to be 100 percent, it just needs to be more secure than others.</div>
<div class="msg"></div>
<div class="msg">Now, on to the posts!</div>
<div class="msg"></div>
<div class="msg"><strong>#3 &#8211; Vulnerability Apps Make Us Curse</strong>: Not really, but we were a little surprised when we came across the &#8220;DVWA &#8211; Damn Vulnerable Web App&#8221; post by <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a>. Aside from what the name implies, the DVWA is actually a help, not a menace. A PHP/mySQL web application that is made to be attacked, @geminisecurity says that it is &#8220;intended to be run on a local (closed) network as a learning tool for exploits and vulnerabilities.&#8221; They go on to say that &#8220;[a]s it sits now, it pretty much contains a lot of the basics – brute force, command execution, file inclusion, SQL injection, and XSS.&#8221; While DVWA got pretty positive reviews overall, @geminisecurity did warn experienced users that they might not find DVWA as useful as someone who&#8217;s just starting out. You can read the full review <a href="http://securitymusings.com/article/1350/dvwa-damn-vulnerable-web-app">here</a>.<span id="more-1849"></span></div>
<div class="msg"><strong><br />
</strong></div>
<div class="msg"><strong>#2 &#8211; Bejtlich Strikes Again</strong>: Offering an awesome breakdown of what white hat could do with a million dollars in his post &#8220;White Hat Budgeting&#8221; <a href="http://www.novainfosecportal.com/2009/07/20/top-3-nova-infosec-blog-posts-of-the-week-17/">last week</a>, this week Bejtlich gave an interesting summary of the &#8220;SANS WhatWorks Summit in Forensics and Incident Response&#8221; in his post &#8220;SANS Forensics and Incident Response 2009 Summit Round-Up.&#8221; While he gives a brief overview of the event, what makes the post really interesting is the Q&amp;A style that he uses. Saying that &#8220;I was given a few questions which I promised to answer on this blog,&#8221; Bejtlich gives thoughtful answers to questions that deal with everything from cyber command to the 2014 Verizon Data Breach Report. If you&#8217;re interested in hearing more of Bejtlich&#8217;s answers, you can read them <a href="http://taosecurity.blogspot.com/2009/07/sans-forensics-and-incident-response.html">here</a>.</div>
<div class="msg"></div>
<div class="msg"><strong>#1 &#8211; More Security, Stat</strong>: According to the &#8220;Surprise Report: Not Enough Security Staff&#8221; post by <a href="http://www.twitter.com/rybolov">@rybolov</a>, there isn&#8217;t enough security professionals to go around. There&#8217;s no getting around the fact that security is a quickly growing field and that we need more people to fill the growing job force. But the problem is that many jobs in the security field require years of expertise that recent grads may or may not have. Throw public verses private sector business into the mix and you have a recipe for disaster. @rybolov explains it much better than we can though, so be sure to <a href="http://www.guerilla-ciso.com/archives/1229">check out his post</a> to get the whole scoop.</div>
<div class="msg"></div>
<div class="msg">Well, that&#8217;s all the NoVA Infosec Blog goodness for this week; if you want to find more great posts by local bloggers during the week, be sure to follow us <a href="http://www.twitter.com/grecs">@grecs</a>.</div>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;"><em>Know a blog that should be considered for our “Top 3 NoVA Infosec Blog Posts of the Week” feature? If so, <a href="http://www.twitter.com/grecs">send us a tweet</a> with a link to the blog and the request for us to check it out.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FncL5J8" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/07/27/top-3-nova-infosec-blog-posts-of-the-week-18/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/07/27/top-3-nova-infosec-blog-posts-of-the-week-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Infosec Blogs/Podcasts Resource Section</title>
		<link>http://www.novainfosecportal.com/2008/03/01/new-infosec-blogs-podcasts-resource-section/</link>
		<comments>http://www.novainfosecportal.com/2008/03/01/new-infosec-blogs-podcasts-resource-section/#comments</comments>
		<pubDate>Sun, 02 Mar 2008 00:25:58 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[northern virginia]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/2008/03/01/welcome-to-blogspodcasts/</guid>
		<description><![CDATA[We&#8217;ve added a new Blogs/Podcasts resource section that will provide an in-depth look into relevant security blogs and podcasts for infosec professionals based in or around the Northern Virginia (NoVA) area.]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=New+Infosec+Blogs%2FPodcasts+Resource+Section+http%3A%2F%2Fj.mp%2Fpdtidf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/03/01/new-infosec-blogs-podcasts-resource-section/&amp;t=New+Infosec+Blogs%2FPodcasts+Resource+Section" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>We&#8217;ve added a new Blogs/Podcasts resource section that will provide an in-depth look into relevant security blogs and podcasts for infosec professionals based in or around the Northern Virginia (NoVA) area.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=New+Infosec+Blogs%2FPodcasts+Resource+Section+http%3A%2F%2Fj.mp%2Fpdtidf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/03/01/new-infosec-blogs-podcasts-resource-section/&amp;t=New+Infosec+Blogs%2FPodcasts+Resource+Section" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2008/03/01/new-infosec-blogs-podcasts-resource-section/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

