<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>cissp CISSP training Certified Information Systems Security Professional</title>
<link>http://www.cccure.org</link>
<description>Knowledge Sharing and Giving Back to the community</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2012-05-16T22:29:06-04:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2012-05-16T22:29:06-04:00</sy:updateBase>

<item>
<title>Job opportunities in Kuwait and Dubai</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1589</link>
<description><![CDATA[<p>&#160;</p>
<p class="MsoNormal">Good day everyone,</p>
<p class="MsoNormal">My good friend Balwant Rathore has jobs opening in both Kuwait and Dubai.</p>
<p class="MsoNormal">See the profiles he is looking for below. &#160;Please only answer if you have the full 5 years+ of practical experience and you're willing to work in Kuwait or Dubai.</p>
<p class="MsoNormal">See job offers below and contact information.</p>
<p class="MsoNormal">Best regards</p>
<p class="MsoNormal">Clement</p>
<p class="MsoNormal"><strong>SEE MESSAGE FROM BALWANT BELOW:</strong></p>
<p class="MsoNormal">I am looking for Freelancer/Consultant for followings projects:</p>
<p><strong>1.&#160;&#160;&#160;&#160;&#160;&#160;ITIL Implementation</strong></p>
<p><strong>2.&#160;&#160;&#160;&#160;&#160;&#160;Business Continuity Management (BCM) Implementation</strong></p>
<p><strong>3.&#160;&#160;&#160;&#160;&#160;&#160;Information Security Management System Implementation</strong></p>
<p class="MsoNormal"><strong>For all three categories some amount of training skills are also required.</strong></p>
<p class="MsoNormal">Experience required = 5+ years.</p>
<p class="MsoNormal">Project Location = Dubai and Kuwait</p>
<p class="MsoNormal">Start Date = As soon as possible, even today.</p>
<p class="MsoNormal">Payment &#8211; Best in Industry, as per experience.</p>
<p class="MsoNormal">If you know anybody who may be fit for above, please ask them to contact me at&#160;<a href="mailto:balwant_rathore@oissg.org">balwant_rathore@oissg.org</a></p>
<p class="MsoNormal">Kind regards,</p>
<p class="MsoNormal">Balwant</p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1589@http://www.cccure.org</guid>
<dc:subject>JOBS</dc:subject>
<dc:date>2012-03-24T21:33:20-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Hal Tipton passed away last week -  A great icon that will be missed</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1588</link>
<description><![CDATA[<p>I had the pleasure to meet Hal Tipton in person while doing my 8 days CISSP Seminar in 1998 in Vancouver, Canada. &#160;</p>
<p>I was always impressed by Hal's fatherly approach. &#160;I remember him telling me that I should wear my jacket as it was cold outside and I was chatting with some of the students out in the cold. &#160;He was worried I could get sick. &#160;That's the type of person he was.</p>
<p>That was the initial days of the CISSP certification. &#160; At the time there was no study resources that existed and one had to read a whole lot of books because Google did not exist in the way it exists today.</p>
<p>After the class I created the initial study guides along with my friend Chris Hare and this is how CCCure was born. &#160; Hal and Sandy Sheriden who were both of my instructors were happily distributing the link to the guides to all of their students. &#160;Quickly it did like a snowball and today we have helped more than 150,000 students in their studies.</p>
<p>Hal was one of the first person to contribute to our portal by giving us a copy of the Handbook of Information System Management in HTML format. &#160;He gave it freely to us to be posted for anyone to use. &#160;He did not ask for anything in return, he was happy to help the community and our project. &#160;Later he gave us his own slide show on the ten domains that he was using for his one day class.</p>
<p>I have traded numerous emails with Hal over the years. &#160;He always responded to my many queries and sometimes complaints. &#160; What amazed me the most is how down to earth he has always been. &#160;For me he was an icon, &#160;he was the person who wrote the CBK, he was the person preaching security of systems way before security was even in the limelights. &#160;I was looking up at him and telling myself: &#160;when I grow up I wish I can be like Hal. &#160; I am still wishing the same today, &#160;when I will be in my eighties I hope that I will be doing work just like he did until his final days with us. &#160; &#160;</p>
<p>Hal is a friend that &#160;I will dearly missed.</p>
<p>Rest in peace my friend</p>
<p>Clement</p>
<p><strong>SEE BELOW A TESTIMONY FROM ROSS LEO ONE OF OUR INSTRUCTORS, A FRIEND, AND CO-WORKER AT SECURE NINJA:</strong></p>
<p>I too had the opportunity to get to know Hal. &#160;</p>
<p>I was luckier than most: &#160;he was my boss at Rockwell international, he was my mentor in our fledgling profession, and he was my co-instructor that brought me into ISC2 for mentoring and instructing CISSP candidates from 1998 until 2004. &#160;</p>
<p>He set me up and endorsed me as Chairman of curriculum development during that time. &#160;He was my mentor and my inspiration. &#160;It was Hal and his commitment to InfoSec that made me make my commitment to it, almost 30 years ago. Even after I left ISC2, he kept me connected to the process of maturing and developing my professional standing. &#160;</p>
<p>I may have coined the term CIA, but it was he that helped it to become the standard that it has for our profession and our profession descendents.</p>
<p>We would not be where we are today as the professionals and protectors of those systems that run our industries, government, and critical infrastructure without leaders like Harold Tipton. &#160;He will be much missed, but his memory will live on in each of us that remember him as we do this vital work that he helped give birth to. &#160;</p>
<p>I wish him fair winds, following seas, and safe journies. &#160;Thanks for all you have done, my friend and mentor.</p>
<p>Ross</p>]]></description>
<guid isPermaLink="false">1588@http://www.cccure.org</guid>
<dc:subject>ISC2</dc:subject>
<dc:date>2012-03-19T15:17:57-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>The CISSP exam is available online as of 1st of June 2012 at VUE testing</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1587</link>
<description><![CDATA[<p>After much speculation and questions as to when the exam would be available online in English, it is now official, (ISC)&#178;&#174; is going to offer the exam online for English speaking students as of  the 1st of June.&#160; This is a major change and it is very welcome. <br><br>You  can begin registering for computer-based testing (CBT) for CISSP,   CISSP concentrations and the SSCP certifications on June 1, 2012. <br><br>You  no longer have to wait for an exam to show up in your area a few times a  year or as it is the case with many countries once a year only.&#160; You  can now book your exam with VUE testing when&#160; you are ready and in a  location close to you as well.&#160; This is so much more flexible than the  outdated paper based approach they were using until now.</p>
<p align="start">Accordint to the ISC&#178;&#174; press release this transition  provides numerous benefits to  candidates, members and the information  security community, including:</p>
<ul>
<li>Fair and precise evaluation of a candidate&#8217;s competency </li>
<li>Rapid turnaround of exam results </li>
<li>More choices as to when and where to take the exam </li>
<li>Easier registration </li>
<li>Fortified&#160;exam security </li>
</ul>
<p align="start">All (ISC)&#178; credential exams will be offered globally at  approved Pearson VUE testing centers.</p>
<p align="start">Currently, all (ISC)&#178; exams offered via CBT are  available in  English, with the CISSP and SSCP exams also available in  Brazilian  Portuguese at any of the approved&#160; Pearson VUE testing centers in Latin America.&#160; The CISSP exam is also available in Spanish throughout Latin America.&#160; &#160;</p>
<p align="start">Candidates can register directly through <a href="http://www.pearsonvue.com/isc2">PearsonVUE</a></p>
<p align="start">This is really good news for all</p>
<p align="start">Best regards</p>
<p align="start">Clement</p>
<p align="start">Clement Dupuis, CD<br>Owner and Founder of CCCure<br>CLO at Secure Ninja</p>]]></description>
<guid isPermaLink="false">1587@http://www.cccure.org</guid>
<dc:subject>ISC2</dc:subject>
<dc:date>2012-03-06T03:46:41-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Secure Ninja Appoints Leonard Chin as VP to Lead International Expansion</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1586</link>
<description><![CDATA[<p>&#160;</p>
<p>With 80% of its target market overseas Secure  Ninja expands globally  to meet the growing demand for Information  Security training and  service solutions.</p>
<p>Secure Ninja is pleased to announce the appointment of Leonard Chin  as Vice  President to lead its international marketing and business  development. &#160; In response to the global opportunity for its leading  edge security  services, Secure Ninja also announces its expansion into  Europe, the  Middle East and Africa (EMEA), along with select markets in  Asia Pacific  and South America. <br><br>With a decade of experience in  developing new  business and driving international sales, Leonard will  be a key asset to  Secure Ninja as the company grows its customer and  value-added reseller  (VAR) base in the coming year.</p>
<p>Leonard possesses extensive field experience specializing in sales   and marketing functions across numerous industries including finance,   conference, seminars, franchise, technical training and education.    Leonard has established countless strategic partnerships with numerous   Fortune 500 companies and government organizations.  Leonard is well   known as a conference specialist, having successfully managed a string   of highly successful EC-Council conferences during his tenure.  He was   instrumental in conceptualizing and organizing the first Hacker Halted   USA in 2008 and thereafter making it a mainstay in Miami. Leonard was   responsible for launching, designing and directing the highly technical   TakeDownCon series, which was recently hosted in Dallas and Las Vegas  in  2011.</p>
<p>&#8220;We are delighted to have Leonard Chin on our team.  He is an   extremely knowledgeable and well-connected infosec business professional   who possesses great leadership ability and outstanding communication   skills, which are crucial elements to effectively manage and influence   people towards meeting our company&#8217;s international business objectives,&#8221;   said Ned Snow, President, Secure Ninja.  &#8220;By combining Leonard&#8217;s   expertise to manage a strong team of subject matter experts and sales   engineers in key regions, Secure Ninja will be well positioned for our   next phase of innovation and growth.&#8221;</p>
<p>Prior to this appointment, Leonard was a key executive at EC-Council,   creator of the world renowned Certified Ethical Hacker (CEH) programs   as well as numerous other recognized certifications such as the CHFI,   ECSA and Licensed Penetration Tester (LPT). He held various roles within   the organization including Director of Marketing, and Director of   Conferences &#38; Events, as well as concurrently being the Conference   Director for both the TakeDownCon and Hacker Halted conference series.   And in 2011, he was appointed as the Vice Chair of the world&#8217;s first   international team ethical hacking games - the Global CyberLympics.</p>
<p>"It is an honor and I&#8217;m excited to be part of Secure Ninja&#8217;s   immensely qualified team, which is on the leading edge of information   security services and training methodology development," said Leonard.   "I'm looking forward to expanding Secure Ninja&#8217;s suite of security   services and training offerings internationally, ensuring its growth and   market captivity, as well as attaining global branding.&#8221;</p>
<p><strong>About Secure Ninja </strong><br><br>Secure Ninja is a leader in  Information Security, IT training and  certification such as CISSP,  Security+, CEH, CAP, CISM, ISSEP, ISSMP,  ISSAP, Cloud Security,  Wireless Security and Computer Forensics to name a  few. Secure Ninja  has been providing businesses with programs that  answer regulatory  needs and skills gaps for over 8 years.  Our training  programs educate  and certify employees in the areas that are critical to  business  operations.  With certified professionals on staff, the  company  demonstrates that it is seriously engaged in producing ROI on   technology investments and handling compliance requirements competently.    Our programs also create solutions for the DOD and the system   integrator community by answering the certification needs of the   8570.01-M mandate. Secure Ninja&#8217;s assessment, consulting and security   services division specializes in governance, risk and compliance   programs for both corporate &#38; government agencies including   information assurance, IV&#38;V security audits and cyber-security   solutions.&#160;  For more information visit <a href="http://www.secureninja.com/">http://www.secureninja.com</a></p>
<p>&#160;</p>
<table border="0" cellspacing="1" cellpadding="6" width="100%">

<tr>
<td bgcolor="#D9E0E8"><strong>Contact Information</strong></td>
</tr>
<tr>
<td bgcolor="#EBEFF3"><strong>Ned Snow</strong><br>Secure Ninja<br><a href="http://www.secureninja.com/">http://www.secureninja.com</a><br>(703) 535-8600 ext. 15</td>
</tr>

</table>]]></description>
<guid isPermaLink="false">1586@http://www.cccure.org</guid>
<dc:subject>CISSP</dc:subject>
<dc:date>2012-02-22T21:34:33-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>CISSP&reg; CBK&reg; introduced as of January 2012 -- What does it means to me</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1585</link>
<description><![CDATA[<p>Good day to all,</p>
<p>I am still receiving numerous inquiries about the changes that were introducted in the<a href="https://www.isc2.org/CIB/CISSP-CIB.pdf"> <strong>new CISSP&#174; CBK&#174;</strong></a> that was released as of January 2012.<br><br>As I have mentioned in <strong><a href="article1552.html">my full review of the old CBK</a></strong><a href="https://www.isc2.org/CIB/CISSP-CIB.pdf"><strong>&#174;</strong></a><strong><a href="article1552.html"> compared with the new CBK</a></strong><a href="https://www.isc2.org/CIB/CISSP-CIB.pdf"><strong>&#174;</strong></a> there is almost no changes that were introduced.&#160; The changes are mostly semantics, lots of the changes are rewording within the <strong><a href="https://www.isc2.org/CIB/CISSP-CIB.pdf">Candidate Information Bulletin (CIB)</a></strong>.&#160;&#160; So there is no worries,&#160; the material you have will still match perfectly well with the current exam offered by ISC2&#174; and you don't need new books or new resources.</p>
<p>This is not just hearsay or rumors, the ISC2&#174; website has a series of documents that talks about the process and this topic. &#160; They give you details on what to expect.&#160; The documents available on the ISC2&#174; website all say very clearly:</p>
<ol>
<li><strong>The candidates should not expect big changes in any examination (or test question)</strong></li>
<li><strong>No domains were deleted or added to the CISSP&#174; certification, only one domain was renamed</strong></li>
<li><strong>The content changes mostly involved relocating and renaming of some of the topics</strong></li>
<li><strong>There will be no new questions in the forms that will require major changes to any education programs</strong></li>
<li><strong>All changes can be easily covered by instructors using the current education material</strong></li>
</ol>
<p>So it is business as usual.&#160; Do not let rumour throw you off you study plan.&#160;&#160; What you put in is what you will get out of it.</p>
<p>Remember to look at my tips and tricks before you start your studies.&#160; You will find them at:</p>
<p><strong><a href="article1477.html">http://www.cccure.org/article1477.html</a></strong></p>
<p>Take care</p>
<p>Clement</p>
<p>&#160;</p>
<p><strong>References:</strong></p>
<p><a href="https://www.isc2.org/uploadedFiles/Credentials_and_Certifcation/About_Our_Credentials_and_Process/CIB%20white%20paper2.pdf">ISC2&#174; Paper about their education process and Job Task Analysis</a></p>
<p><a href="https://www.isc2.org/uploadedFiles/Credentials_and_Certifcation/About_Our_Credentials_and_Process/2012-CIB-Updates.pdf">Slide show on changes withing the ISC2&#174; CBK&#174;</a></p>
<p><a href="https://www.isc2.org/CIB/CISSP-CIB.pdf">The CISSP Candidate Information Bulletin (CIB)</a></p>]]></description>
<guid isPermaLink="false">1585@http://www.cccure.org</guid>
<dc:subject>ISC2</dc:subject>
<dc:date>2012-02-16T09:51:03-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>4th Cyber Security Summit, Huntsville, Alabama</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1584</link>
<description><![CDATA[Fourth Annual Cyber Security Summit
<table border="0">

<tr>
<td style="padding: 3px;">
<strong>June 7th, 2012 @ The Von Braun Center</strong>
<strong>&#62;&#62;&#62;&#62;&#62;CALL FOR&#160;PAPERS&#60;&#60;&#60;&#60;&#60;&#60;</strong>
Submission Deadlines:
<p>Proposed topic and abstract &#8211; 01 March 2012</p>
<p>Speaker selection notifications &#8211; 30 March 2012</p>
<p>Final presentation material due &#8211; 1 June 2012</p>
<p>Submission POC: <a href="mailto:callforpapers2012@northalabama.issa.org?subject=RESPONSE%20%3A%20Cyber%20Security%20Summit%20-%20Call%20for%20Papers">callforpapers2012@northalabama.issa.org</a></p>

</td>
<td style="padding: 3px;">
Co-Presented by:
<img style="border-width: 0px;" src="http://northalabama.issa.org/userfiles/csc_rgb_pos.jpg" alt width="0" height="0"><img src="http://northalabama.issa.org/userfiles/cyber_huntsville_page_header.jpg" alt width="300" height="105">
<p style="margin-top: 0.5em; margin-bottom: 0.9em;">&#160;</p>
</td>
</tr>

</table>

<p class="rtecenter">&#160;<img src="http://northalabama.issa.org/userfiles/2012CallforSpeakers.PNG" alt width="745" height="740"></p>

<table style="margin: 0px; width: 910px; border-collapse: collapse; font-size: 1em; height: 237px;" border="0">

<tr>
<td style="padding: 3px;">&#160;</td>
<td style="padding: 3px;">&#160;</td>
</tr>

</table>

]]></description>
<guid isPermaLink="false">1584@http://www.cccure.org</guid>
<dc:subject>Training_News</dc:subject>
<dc:date>2012-02-09T11:20:34-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Security Kaizen Magazine Issue 4 is released</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1583</link>
<description><![CDATA[<div><strong>Security Kaizen Magazine               Yearly issue. <br> An issue that you shouldn't miss</strong><br></div>
<blockquote>In Egypt : 30 % discount Coupon for EC council         Courses inside the Printed Copy.<br><br> <a href="https://spreadsheets9.google.com/viewform?hl=en&#38;formkey=dFhVbGFZUlpZM3BXMHpjWUdkUndqeXc6MQ#gid=0">Printed           Copy Request</a><br> Coming Soon : Arabic Version<br></blockquote>
<div><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/">Download the English Edition now<br> </a></div>
<p><br> <a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"></a></p>
<p style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><img src="https://mail.google.com/mail/u/0/?ui=2&#38;ik=0793b57c9a&#38;view=att&#38;th=135349096fe28fa9&#38;attid=0.1&#38;disp=emb&#38;realattid=a364c6ec898db2e0_0.1.1&#38;zw" border="0" alt height="507"></a></p>]]></description>
<guid isPermaLink="false">1583@http://www.cccure.org</guid>
<dc:subject>Training_News</dc:subject>
<dc:date>2012-02-03T14:52:58-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Modeling Security Pentests - New Issue of WebAppPentesting is Out!</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1582</link>
<description><![CDATA[<p><strong>Inside Web App Pentesting:</strong></p>
<p>Open Source Web Application Security Testing Tools by Vinodh Velusamy</p>
<p>Author  shows the significance of Open Source Web Application Security Testing  Tools. As he claims &#8222;When you choose and use good tools, you&#8217;ll know it.  Amazingly, you&#8217;ll minimize your time and effort installing them,  running your tests, reporting your results &#8211; everything from start to  finish. <br /><br />Most importantly, with a good web vulnerability scanner  you&#8217;ll be able to maximize the number of legitimate vulnerabilities  discovered to help reduce the risks associated with your information  systems. <br />At the end of the day and over the long haul, this will add up to considerable business value you can&#8217;t afford to overlook&#8221;. <br /><br /><strong>More Articles:</strong></p>
<p>- Modeling Security Penetration Tests with Stringent Time Constraints by Alan Cao <br />- The puzzlepices by Daniel Clemens <br />- WebAppSecurity for Newbies part 2 Herman Stevens <br />- Web Application Common Vulnerabilities &#8211; Part I by Bryan Soliman <br />- CYBER STYLETTO by Mike Brennan and Richard Siennon <br /><br /><br /><strong>SUBSCRIBE NOW AND GET 2 AMAZING E-BOOKS !</strong></p>
<p>1. CISO's Guide to Penetration Testing: A Framework to Plan, Manage,  and Maximize Benefits details the methodologies, framework, and  unwritten conventions penetration tests should cover to provide the most  value to your organization and your customers.<br /><br />2. In his new  book "Save the Database, Save the World!" John Ottman captures the  essence of the threats we face to the information that drives business.  Organized crime, underhanded competitors and even foreign governments  are looking to gain any financial, competitive or operational advantage  and these enemies are going directly after the databases and the  applications that access data.</p>
<p>After subscribing contact <strong><a href="mailto:katarzyna.zwierowicz@software.com.pl" target="_blank">katarzyna.zwierowicz@software.com.pl</a></strong> with "WAPT" in the tittle of the message.</p>
<p>You can visit us at: <a href="http://www.pentestmag.com" target="_blank"><strong>http://www.pentestmag.com</strong></a></p>]]></description>
<guid isPermaLink="false">1582@http://www.cccure.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-25T12:54:16-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>Sykipot variant hijacks DOD and Windows smart cards</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1581</link>
<description><![CDATA[<div class="title">January 12th, 2012 | Posted by <a href="http://labs.alienvault.com/labs/index.php/author/jaime-blasco/">jaime.blasco</a>&#160;<a href="http://labs.alienvault.com/labs/index.php/category/blog/windows/"></a></div>
<p>Defenses of any sort, virtual or physical,  are a means of forcing your attacker to attack you on your terms, not  theirs. As we build more elaborate defenses within information security,  we force our attacker&#8217;s hand. For instance, in many cases, implementing  multi-factor authentication systems just forces the attacker to go  after that system directly to achieve their goals. Take the breach at  RSA, for example. It has been attributed to attackers who needed the  SecurID information to go after their real targets in the defense  industry.</p>
<p>Recently, our lab has been talking about Sykipot:</p>
<ul>
<li><em><a href="http://labs.alienvault.com/labs/index.php/2011/are-the-sykipots-authors-obsessed-with-next-generation-us-drones/">Are the Sykipot&#700;s authors obsessed with next generation US drones</a>? </em></li>
<li><em><a href="http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/">Another Sykipot sample likely targeting US federal agencies</a></em></li>
</ul>
<p>&#160;</p>
<p>As we discussed, this malware has been used to launch targeted  attacks via &#8220;spear phishing&#8221; campaigns against targets mainly in the US,  since around 2007. According to our research, these attacks originate  from servers in China with what appears to be the purpose of obtaining  information from the defense sector: the same sector that makes  extensive use of PC/SC x509 Smartcards for authentication.</p>
<p>Smartcards have a long history of usage in the Defense Sector, for  both physical and information access management, and historically have  merely forced attackers to route around the smartcard authentication  system through other, more vulnerable attack vectors.</p>
<p>It should come as no surprise, then, that we recently discovered a  variant of Sykipot with some new, interesting features that allow it to  effectively hijack DOD and Windows smart cards. This variant, which  appears to have been compiled in March 2011, has been seen in dozens of  attack samples from the past year.</p>
<p>Like we have shown with previous Sykipot attacks, the attackers use a  spear phishing campaign to get their targets to open a PDF attachment  which then deposits the Sykipot malware onto their machine (the  attackers here took advantage of a zero-day exploit in Adobe). Then,  unlike previous strains, the malware uses a keylogger to steal PINs for  the cards. When a card is inserted into the reader, the malware then  acts as the authenticated user and can access sensitive information. The  malware is controlled by the attackers from the command &#38; control  center.</p>
<p><a href="http://labs.alienvault.com/labs/index.php/http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs/">Click Here to get a whole lot more details on the attack</a></p>]]></description>
<guid isPermaLink="false">1581@http://www.cccure.org</guid>
<dc:subject>Virus</dc:subject>
<dc:date>2012-01-23T09:49:17-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>SOPA and PIPA -- What`s in it for you</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1579</link>
<description><![CDATA[<p>As seen on one of my hosting company mailing list:</p>
<p>Greetings <a href="http://www.site5.com/">Site5 Customers</a>!<br> <br> The U.S. Congress is currently considering two bills -- one in the House  of Representatives called SOPA (Stop Online Piracy Act) and another in  the Senate called PIPA (Protect IP Act). These bills both attempt to use  similar methods to further criminalize and police intellectual property  infringement. Although protecting intellectual property is important,  these bills would use heavy-handed tactics that would censor and  splinter the Internet.<br> <br> SOPA and PIPA would grant the U.S. government the ability to block  almost any website on the Internet if the site is perceived to be an  "infringing site." Search engines would be required to remove the site  from their search listings, payment processors and advertisement  networks would be forbidden from doing business with the site, and ISPs  could be forced to block access to the site for Americans. The bill  provides little detail about what would constitute an infringing site,  which makes the potential for abuse far greater. We have already seen  how these kind of systems can be abused. In 2010, ICE (Immigration and  Customs Enforcement) mistakenly seized a domain name belonging to a  music blog and labeled it as a "rogue site" &#8212; the domain name was not  returned until a year later (source: <a href="http://nyti.ms/uF73mZ">http://nyti.ms/uF73mZ</a>). If you would like to see a video explanation of how the bill works and its dangers, please go here: <a href="http://vimeo.com/31100268">http://vimeo.com/31100268</a><br> <br> Site5 has publicly declared our opposition to both bills, and we  encourage you to do the same. Contact your representatives in Congress  to let your opposition to these bills be known! To locate the contact  information for your representatives, visit one of the following  websites:<br> <br> <a href="http://www.contactingthecongress.org/">http://www.contactingthecongress.org</a><br> <a href="http://www.grassroutes.us/sopa">http://www.grassroutes.us/sopa</a><br> <br> If you're located outside the United States, you can let your voice be heard as well by sending your thoughts via this website:<br> <br> <a href="http://americancensorship.org/">http://americancensorship.org</a><br> <br> Another way to get involved in the fight against SOPA and PIPA is to  join in on the blackouts. Many well-known websites such as Wikipedia,  Google, and Reddit are demonstrating their opposition, and you can too.  Site5 has sponsored a WordPress plugin for participating in blackouts,  and it features an easy setup and configuration options within the  WordPress admin area:<br> <br> <a href="http://wordpress.org/extend/plugins/sopa-blackout-plugin/">http://wordpress.org/extend/plugins/sopa-blackout-plugin/</a><br> <br> We feel very strongly that the future of the Internet is at stake, and we urge everyone to get involved!<br> <br> Thanks,</p>
<p>The Site5 Management Team</p>]]></description>
<guid isPermaLink="false">1579@http://www.cccure.org</guid>
<dc:subject>Law</dc:subject>
<dc:date>2012-01-19T14:20:31-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

</channel>
</rss>

