<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1642559385219208464</id><updated>2011-07-07T20:58:12.157-04:00</updated><category term='Blackhat'/><category term='DCNYC Meetup'/><category term='reports'/><category term='New Law'/><category term='Websense'/><category term='metrics'/><category term='InfoSec'/><category term='SANS'/><category term='Infosources'/><category term='Forensics'/><category term='security research sites'/><category term='Security'/><category term='Resrtrictions on data forensics'/><category term='Private Investigator'/><title type='text'>mynfosec</title><subtitle type='html'>A space to collect and connect on infosec research and experiences.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-3758353544437611758</id><published>2009-12-10T10:23:00.001-05:00</published><updated>2009-12-10T10:27:24.208-05:00</updated><title type='text'>Regex dos = redos</title><content type='html'>OWASP podcast #56 with Jim Manico interviewing Adar Weidman.&lt;br /&gt;Good coverage of interesting aspect of regex parsing that can lead to  &lt;br /&gt;DOS at server and browser.&lt;br /&gt;&lt;a href="Http://www.owasp.org/index.php/Podcast_56"&gt;Http://www.owasp.org/index.php/Podcast_56&lt;/a&gt;&lt;p&gt;&lt;br /&gt;David Kadow&lt;br /&gt;--&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-3758353544437611758?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/3758353544437611758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/12/regex-dos-redos.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/3758353544437611758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/3758353544437611758'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/12/regex-dos-redos.html' title='Regex dos = redos'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-5445374936399270371</id><published>2009-09-21T21:09:00.004-04:00</published><updated>2009-09-21T22:14:53.104-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='New Law'/><category scheme='http://www.blogger.com/atom/ns#' term='Resrtrictions on data forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='Private Investigator'/><title type='text'>Data Forensics and New State Laws</title><content type='html'>According to an interview by Networkperformancedaily, with Matt Miller of the Institute for Justice, "Last year ( 2007 ), the state of Texas passed a law that basically said that to perform a lot of types of data analysis; you have to have a private investigator's license. And, if you perform that analysis without a license, or if you are a customer and you seek to have that analysis performed by somebody without a license, it is punishable by up to one year in jail and up to $14,000 in fines."&lt;br /&gt;&lt;br /&gt;ThiSo this is not a new case, but it's important, and it's not over, and you should follow this and similar cases in other states, as it could severely limit your ability to do parts of your job. &lt;br /&gt;&lt;br /&gt;As IT professionals, security and related operations have always been part of the job of designing and administering systems, maintaining uptime, and investigating problems. &lt;br /&gt;&lt;br /&gt;The summary statements of the laws we discuss here sound sensationalist, and indeed, the devil is in the details. However I'm not going to dissect the related laws from every state. I will review the important aspects, and try to avoid exaggeration. I will also provide POV from the Private Investigator, through interviews.&lt;br /&gt;&lt;br /&gt;For now, some good resources are :&lt;br /&gt;http://legal-beagle.typepad.com/wrights_legal_beagle/computer-forensics-license/&lt;br /&gt;http://hack-igations.blogspot.com/2008/12/digital-forensics-private-eye-pi.html&lt;br /&gt;http://www.networkperformancedaily.com/2008/07/interview_with_matt_miller_w_i.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-5445374936399270371?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/5445374936399270371/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/09/data-forensics-and-new-state-laws.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/5445374936399270371'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/5445374936399270371'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/09/data-forensics-and-new-state-laws.html' title='Data Forensics and New State Laws'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-542972093704621577</id><published>2009-09-17T12:45:00.004-04:00</published><updated>2009-09-17T12:58:15.562-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='metrics'/><category scheme='http://www.blogger.com/atom/ns#' term='Websense'/><category scheme='http://www.blogger.com/atom/ns#' term='reports'/><title type='text'>New SANS and WebSense reports point to where we should focus our defense.</title><content type='html'>NY Times picked this up with the headline that "Security Pros Are Focused on the Wrong Threats" ( By Riva Richmond )&lt;br /&gt;&lt;br /&gt;Not really alarmist, considering the facts.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sans.org/top-cyber-security-risks/"&gt;SANS&lt;/a&gt;: &lt;br /&gt;&lt;br /&gt;Summary:&lt;br /&gt;Point 1. PATCH!!!!!! What are you waiting for ?!?!?!?&lt;br /&gt;because &lt;br /&gt;Point 2. 60% of attacks are against legit websites, many of which are open to being sql-injected. This means unpatched users hitting those sites can easily be exploited while doing legitimate browsing. Point 2 was really FIX YOUR WEBSITES!, but the dual message is because so many sites are broken, patch your clients!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.websense.com/site/docs/whitepapers/en/WSL_Q1_Q2_2009_FNL.PDF"&gt;Websense&lt;/a&gt;: &lt;br /&gt;&lt;br /&gt;Highlights:&lt;br /&gt;• Websense Security Labs identified a 233 percent growth in the number of malicious Web sites in the last six months and a 671 percent growth during the last year.&lt;br /&gt;• 77 percent of Web sites with malicious code are legitimate sites that have been compromised. This remains unchanged from the last six-month period.&lt;br /&gt;• 87.7 percent of email messages were spam. This represents a three percent increase over the last six months.&lt;br /&gt;• 37 percent of malicious Web/HTTP attacks included data-stealing code. This remains unchanged from the last six-month period.&lt;br /&gt;• 57 percent of data-stealing attacks are conducted over the Web. This number has stayed consistent over the six-month period.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-542972093704621577?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/542972093704621577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/09/new-sans-and-websense-reports-point-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/542972093704621577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/542972093704621577'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/09/new-sans-and-websense-reports-point-to.html' title='New SANS and WebSense reports point to where we should focus our defense.'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-1245586368573191251</id><published>2009-09-10T08:05:00.002-04:00</published><updated>2009-09-10T08:09:49.746-04:00</updated><title type='text'>Online Security Conference - 6-&gt;8 Nov 2009</title><content type='html'>For those of us whose companies still have limited to no funding for travel and training "investment", this may be a welcome development.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;http://securitytubecon.org/cfp.html&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Quality will be interesting, with one parameter being "no rejection" of papers and talks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-1245586368573191251?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/1245586368573191251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/09/online-security-conference-6-8-nov-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/1245586368573191251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/1245586368573191251'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/09/online-security-conference-6-8-nov-2009.html' title='Online Security Conference - 6-&gt;8 Nov 2009'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-5526420250184981091</id><published>2009-08-21T09:36:00.002-04:00</published><updated>2009-08-21T09:47:58.929-04:00</updated><title type='text'>Cisco Team Infiltrates Botnet.</title><content type='html'>A great quote from the story is "Typically, administrators patch vulnerable machines or deploy some sort of  intrusion prevention system (IPS) to protect against exploits.  Both approaches  are effective the majority of the time, but neither approach protects systems  against the uneducated user." It's such a polite way of saying something I've heard several times a week since becoming responsible for infosec..."you can't secure 'stupid' ".&lt;br /&gt;In this story, that goes both ways. Read on.&lt;br /&gt;&lt;br /&gt;http://www.cisco.com/web/about/security/intelligence/bots.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-5526420250184981091?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/5526420250184981091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/08/cisco-team-infiltrates-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/5526420250184981091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/5526420250184981091'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/08/cisco-team-infiltrates-botnet.html' title='Cisco Team Infiltrates Botnet.'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-626808427427888109</id><published>2009-08-14T09:06:00.002-04:00</published><updated>2009-08-14T09:07:45.607-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='InfoSec'/><title type='text'>Blackhat Papers</title><content type='html'>In case you didn't go or didn't know....&lt;br /&gt;http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-626808427427888109?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/626808427427888109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/08/blackhat-papers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/626808427427888109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/626808427427888109'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/08/blackhat-papers.html' title='Blackhat Papers'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-1479654751426532475</id><published>2009-08-07T12:00:00.007-04:00</published><updated>2009-08-07T12:40:44.590-04:00</updated><title type='text'>Personal Safety. Personal Responsibility.</title><content type='html'>&lt;span style="font-family: arial;"&gt;Look, it's &lt;/span&gt;&lt;span style="font-weight: bold; font-family: arial;"&gt;BAD &lt;/span&gt;&lt;span style="font-family: arial;"&gt;out there. Trust me. (&lt;span style="font-style: italic;"&gt; OR start reading any of the material linked here on a regular basis&lt;/span&gt; ) Being aware of &lt;span style="font-style: italic;"&gt;how to compute securely&lt;/span&gt; is no less important than knowing how to drive a car. For that you need to be a certain age and pass a couple exams. It's too bad we can't enforce this for computing yet. But to be truly safe you really need to internalize and &lt;span style="font-style: italic;"&gt;live &lt;/span&gt;the information you learned in driver's ed. Plus practice quite a bit ( every day for the rest of your life, eh ? ). Otherwise you can get really hurt, and your actions can hurt others.&lt;br /&gt;&lt;br /&gt;Computing is very much the same. If you're not operating with certain basic awareness and protections, you will definitely get &lt;a href="http://en.wikipedia.org/wiki/Pwn"&gt;pwned&lt;/a&gt;, and in getting pwned, your system will be used by "the dark side" as part of a botnet to conduct attacks on others. Millions of home systems are "serving two masters" every day.&lt;br /&gt;&lt;br /&gt;Do the right things and you can lower your risk.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-family: arial;"&gt;At Home&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;1. Sign up for OpenDNS, and configure your home router ( you DO use a router, don't you ?!?!?!? [ Linksys, Netgear, etc...] ) with OpenDNS DNS Servers in place of your ISP's DNS servers.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;2. Configure your router and it's clients with &lt;span style="font-style: italic;"&gt;AT LEAST &lt;/span&gt;WPA2 security.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;On the road, or at the coffee shop&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-family: arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;1. If you really must join someone else's wireless, first disable all sharing on your laptop and turn on the firewall.&lt;br /&gt;2. DO run some comprehensive endpoint protection ( this is MORE than just anti-virus ). And yes, do this even on a Mac. ( &lt;a href="http://search.barnesandnoble.com/The-Mac-Hackers-Handbook/Charlie-Miller/e/9780470395363/?itm=2"&gt;Here's why&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;In General, everywhere&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;1. &lt;/span&gt;&lt;span style="font-style: italic;"&gt;Patch your systems !!!! Windows, MacOS, Ubuntu...they all need it ! Do it! Daily!&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;2. Whenever possible browse the web only with Firefox loaded with the essential add-ons &lt;a href="http://noscript.net/"&gt;NoScript &lt;/a&gt;and &lt;a href="http://www.mywot.com/"&gt;WOT &lt;/a&gt;( Web of Trust )&lt;br /&gt;This is &lt;span style="font-weight: bold; font-style: italic;"&gt;key &lt;/span&gt;because 90% of the way you'll be pwned on the web will be through malicious javascript hidden in legit websites ( and definitely on illegit sites ! Shame on you ! )&lt;br /&gt;3. Be careful links, attachments in email, and all content. Where is it from? Who is it from? Do you really need to open it ?&lt;br /&gt;&lt;br /&gt;Do you have other tips ? Add-'em ! C'mon!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-1479654751426532475?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/1479654751426532475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/08/personal-safety-personal-responsibility.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/1479654751426532475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/1479654751426532475'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/08/personal-safety-personal-responsibility.html' title='Personal Safety. Personal Responsibility.'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-2462433834180706308</id><published>2009-07-21T21:49:00.000-04:00</published><updated>2009-07-21T21:51:03.880-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DCNYC Meetup'/><title type='text'>The-DCNYC-Hacking-Meetup-Group- 22-July meeting</title><content type='html'>The-DCNYC-Hacking-Meetup-Group-announce@meetup.com&lt;br /&gt;&lt;br /&gt;( from Marco ) Hi All,&lt;br /&gt;&lt;br /&gt;This Wednesday (tomorrow) we have a great meetup with 2 powerful presentations, The first is Scapy... If you use nmap, hping, tcpdump, wireshark, tracert, icmp or any of your favorite tools chances are Scapy can replace it. Why learn so many tools and there flags when you can just use Scapy. We are also having R3L1k the creator of Fast Track he will give a small presentation and a demo. We also have alot of giveaways, anyone who RSVP's receives a free domain name and we will be raffling away alot of goodies like last month.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#888888;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-2462433834180706308?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/2462433834180706308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/07/dcnyc-hacking-meetup-group-22-july.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/2462433834180706308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/2462433834180706308'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/07/dcnyc-hacking-meetup-group-22-july.html' title='The-DCNYC-Hacking-Meetup-Group- 22-July meeting'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1642559385219208464.post-2862274350180268830</id><published>2009-07-21T14:16:00.005-04:00</published><updated>2009-09-14T12:18:07.690-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security research sites'/><category scheme='http://www.blogger.com/atom/ns#' term='Infosources'/><title type='text'>myinfo sources</title><content type='html'>These are the sites I check out frequently. It's a ton, so I'm moving more to pulling all of these that have rss into google reader. But the original sites are always a richer experience anyway, so listing them here. Bill Blunden has a great listing at belowgotham, organized by subject. I'll get around to doing that here. For now though.....&lt;div id="content"&gt;&lt;div class="wiki-content" style="margin-right: 10px;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Risk&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;a href="http://www.nist.org/news.php" rel="nofollow"&gt;http://www.NIST.org/news.php&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.riskinfo.com/" rel="nofollow"&gt;http://www.riskinfo.com/&lt;/a&gt;&lt;/p&gt; &lt;hr /&gt;  &lt;h2&gt;&lt;span style="font-size:130%;"&gt;&lt;a name="Research-InfoSources-Security"&gt;&lt;/a&gt;Security&lt;/span&gt;&lt;/h2&gt; &lt;table style="width: 671px; height: 918px;" class="confluenceTable"&gt; &lt;tbody&gt; &lt;tr&gt;  &lt;th class="confluenceTh"&gt;site &lt;/th&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://blogs.vmware.com/security/" rel="nofollow"&gt;http://blogs.vmware.com/security/&lt;/a&gt; ( VMware ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://carnal0wnage.attackresearch.com/" rel="nofollow"&gt;http://carnal0wnage.attackresearch.com/&lt;/a&gt; ( Chris Gates )  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://lists.immunitysec.com/pipermail/dailydave/" rel="nofollow"&gt;http://lists.immunitysec.com/pipermail/dailydave/&lt;/a&gt; ( "Daily  Dave" by Dave Aitel ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://datalossdb.org/" rel="nofollow"&gt;http://datalossdb.org/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://episteme.ca/" rel="nofollow"&gt;http://episteme.ca/&lt;/a&gt; ( Mike Murray ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://feeds.feedburner.com/techtarget/Searchsecurity/SecurityWire" rel="nofollow"&gt;http://feeds.feedburner.com/techtarget/Searchsecurity/SecurityWire&lt;/a&gt;  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://googleonlinesecurity.blogspot.com/" rel="nofollow"&gt;http://googleonlinesecurity.blogspot.com/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://ha.ckers.org/blog/" rel="nofollow"&gt;http://ha.ckers.org/blog/&lt;/a&gt; ( Robert 'rsnake' Hanson blog )  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://isc.sans.org/" rel="nofollow"&gt;http://isc.sans.org/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://metasploit.com/home/" rel="nofollow"&gt;http://metasploit.com/home/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://packetstormsecurity.org/" rel="nofollow"&gt;http://packetstormsecurity.org/&lt;/a&gt; ( propecia tool is here )  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://searchsecurity.techtarget.com/" rel="nofollow"&gt;http://searchsecurity.techtarget.com&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://secunia.com/advisories/historic/" rel="nofollow"&gt;http://secunia.com/advisories/historic/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://skeptikal.org/index.php" rel="nofollow"&gt;http://skeptikal.org/index.php&lt;/a&gt; ( mckt blog ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://t-rob.net/wmq/" rel="nofollow"&gt;http://t-rob.net/wmq/&lt;/a&gt; T.Robert Wyatt's MQ-Security Blog  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://taosecurity.blogspot.com/" rel="nofollow"&gt;http://taosecurity.blogspot.com/&lt;/a&gt; (Richard Bejtlich ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://thedigitalstandard.blogspot.com/" rel="nofollow"&gt;http://thedigitalstandard.blogspot.com/&lt;/a&gt; Chris Pogue ( co-Author  w/Harlan Carvey ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://vrt-sourcefire.blogspot.com/" rel="nofollow"&gt;http://vrt-sourcefire.blogspot.com/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://windowsir.blogspot.com/" rel="nofollow"&gt;http://windowsir.blogspot.com/&lt;/a&gt; &lt;b&gt;Windows Forensics&lt;/b&gt;  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.2600.com/" rel="nofollow"&gt;http://www.2600.com/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.attackresearch.com/" rel="nofollow"&gt;http://www.attackresearch.com/&lt;/a&gt; (ValSmith ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.cisco.com/en/US/products/products_security_advisories_listing.html" rel="nofollow"&gt;http://www.cisco.com/en/US/products/products_security_advisories_listing.html&lt;/a&gt;  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.darknet.org.uk/" rel="nofollow"&gt;http://www.darknet.org.uk/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.doxpara.com/" rel="nofollow"&gt;http://www.doxpara.com/&lt;/a&gt; ( kaminsky's site ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.exoticliability.com/" rel="nofollow"&gt;http://www.exoticliability.com/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.grc.com/securitynow.htm" rel="nofollow"&gt;http://www.grc.com/securitynow.htm&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.matasano.com/log/" rel="nofollow"&gt;http://www.matasano.com/log/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.microsoft.com/technet/security/default.mspx" rel="nofollow"&gt;http://www.microsoft.com/technet/security/default.mspx&lt;/a&gt;  &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.pauldotcom.com/" rel="nofollow"&gt;http://www.pauldotcom.com/&lt;/a&gt; ( Paul Asadoorian ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.rationalsurvivability.com/blog/" rel="nofollow"&gt;http://www.rationalsurvivability.com/blog/&lt;/a&gt; ( Chris Hoff's rants  on Security. Good focus on Cloud Security, Virtualisation Security ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.schneier.com/blog/" rel="nofollow"&gt;http://www.schneier.com/blog/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.securityfocus.com/vulnerabilities" rel="nofollow"&gt;http://www.securityfocus.com/vulnerabilities&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://securitymetrics.org/" rel="nofollow"&gt;http://securitymetrics.org/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://appsecstreetfighter.com/" rel="nofollow"&gt;http://appsecstreetfighter.com/&lt;/a&gt; ( SANS ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.us-cert.gov/cas/alerts/" rel="nofollow"&gt;http://www.us-cert.gov/cas/alerts/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.us-cert.gov/cas/techalerts/index.html" rel="nofollow"&gt;http://www.us-cert.gov/cas/techalerts/index.html&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.vmware.com/resources/techresources/cat/91,98" rel="nofollow"&gt;http://www.vmware.com/resources/techresources/cat/91,98&lt;/a&gt; (  VMware Security White papers ) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.windowsecurity.com/" rel="nofollow"&gt;http://www.WindowSecurity.com/&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://news.zdnet.com/" rel="nofollow"&gt;http://news.zdnet.com/&lt;/a&gt; ...Especially the &lt;a href="http://blogs.zdnet.com/security/" rel="nofollow"&gt;ZeroDay Blog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size:130%;"&gt;Security Metrics&lt;br /&gt;&lt;/span&gt;&lt;/h2&gt; &lt;table class="confluenceTable"&gt; &lt;tbody&gt; &lt;tr&gt;  &lt;th class="confluenceTh"&gt;&lt;/th&gt;&lt;/tr&gt; &lt;tr&gt;  &lt;td class="confluenceTd"&gt;&lt;a href="http://www.securitymetrics.org/content/Wiki.jsp"rel="nofollow"&gt;http://www.securitymetrics.org/content/Wiki.jsp&lt;/a&gt; ( SecurityMetrics.org)&lt;br /&gt;&lt;a href="https://www.metricscenter.net/"&gt;https://www.metricscenter.net/ ( MetricsCenter.net )&lt;/a&gt;&lt;br /&gt;&lt;a href="https://www.metricscenter.net/index.php/mc-catalog.html"&gt;https://www.metricscenter.net/index.php/mc-catalog.html ( Public Catalogue )&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.sans.org/reading_room/whitepapers/auditing/a_guide_to_security_metrics_55?show=55.php&amp;amp;cat=auditing"&gt;http://www.sans.org/.../a_guide_to_security_metrics_55 ( SANS Metrics paper )&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1642559385219208464-2862274350180268830?l=mynfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mynfosec.blogspot.com/feeds/2862274350180268830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mynfosec.blogspot.com/2009/07/myinfo-sources.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/2862274350180268830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1642559385219208464/posts/default/2862274350180268830'/><link rel='alternate' type='text/html' href='http://mynfosec.blogspot.com/2009/07/myinfo-sources.html' title='myinfo sources'/><author><name>3dk</name><uri>http://www.blogger.com/profile/17037197914965778558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_S1SCQ8TX1S4/SZ7LuX8VJfI/AAAAAAAAAJw/pTJHSzctuEE/S220/loginbox.gif'/></author><thr:total>0</thr:total></entry></feed>
