<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>cissp CISSP training Certified Information Systems Security Professional</title>
<link>http://www.cccure.org</link>
<description>Knowledge Sharing and Giving Back to the community</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2012-02-04T12:48:04-05:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2012-02-04T12:48:04-05:00</sy:updateBase>

<item>
<title>Security Kaizen Magazine Issue 4 is released</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1583</link>
<description><![CDATA[<div><strong>Security Kaizen Magazine               Yearly issue. <br> An issue that you shouldn't miss</strong><br></div>
<blockquote>In Egypt : 30 % discount Coupon for EC council         Courses inside the Printed Copy.<br><br> <a href="https://spreadsheets9.google.com/viewform?hl=en&#38;formkey=dFhVbGFZUlpZM3BXMHpjWUdkUndqeXc6MQ#gid=0">Printed           Copy Request</a><br> Coming Soon : Arabic Version<br></blockquote>
<div><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/">Download the English Edition now<br> </a></div>
<p><br> <a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"></a></p>
<p style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><img src="https://mail.google.com/mail/u/0/?ui=2&#38;ik=0793b57c9a&#38;view=att&#38;th=135349096fe28fa9&#38;attid=0.1&#38;disp=emb&#38;realattid=a364c6ec898db2e0_0.1.1&#38;zw" border="0" alt height="507"></a></p>]]></description>
<guid isPermaLink="false">1583@http://www.cccure.org</guid>
<dc:subject>Training_News</dc:subject>
<dc:date>2012-02-03T14:52:58-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Modeling Security Pentests - New Issue of WebAppPentesting is Out!</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1582</link>
<description><![CDATA[<p><strong>Inside Web App Pentesting:</strong></p>
<p>Open Source Web Application Security Testing Tools by Vinodh Velusamy</p>
<p>Author  shows the significance of Open Source Web Application Security Testing  Tools. As he claims &#8222;When you choose and use good tools, you&#8217;ll know it.  Amazingly, you&#8217;ll minimize your time and effort installing them,  running your tests, reporting your results &#8211; everything from start to  finish. <br /><br />Most importantly, with a good web vulnerability scanner  you&#8217;ll be able to maximize the number of legitimate vulnerabilities  discovered to help reduce the risks associated with your information  systems. <br />At the end of the day and over the long haul, this will add up to considerable business value you can&#8217;t afford to overlook&#8221;. <br /><br /><strong>More Articles:</strong></p>
<p>- Modeling Security Penetration Tests with Stringent Time Constraints by Alan Cao <br />- The puzzlepices by Daniel Clemens <br />- WebAppSecurity for Newbies part 2 Herman Stevens <br />- Web Application Common Vulnerabilities &#8211; Part I by Bryan Soliman <br />- CYBER STYLETTO by Mike Brennan and Richard Siennon <br /><br /><br /><strong>SUBSCRIBE NOW AND GET 2 AMAZING E-BOOKS !</strong></p>
<p>1. CISO's Guide to Penetration Testing: A Framework to Plan, Manage,  and Maximize Benefits details the methodologies, framework, and  unwritten conventions penetration tests should cover to provide the most  value to your organization and your customers.<br /><br />2. In his new  book "Save the Database, Save the World!" John Ottman captures the  essence of the threats we face to the information that drives business.  Organized crime, underhanded competitors and even foreign governments  are looking to gain any financial, competitive or operational advantage  and these enemies are going directly after the databases and the  applications that access data.</p>
<p>After subscribing contact <strong><a href="mailto:katarzyna.zwierowicz@software.com.pl" target="_blank">katarzyna.zwierowicz@software.com.pl</a></strong> with "WAPT" in the tittle of the message.</p>
<p>You can visit us at: <a href="http://www.pentestmag.com" target="_blank"><strong>http://www.pentestmag.com</strong></a></p>]]></description>
<guid isPermaLink="false">1582@http://www.cccure.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-25T12:54:16-05:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>Sykipot variant hijacks DOD and Windows smart cards</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1581</link>
<description><![CDATA[<div class="title">January 12th, 2012 | Posted by <a href="http://labs.alienvault.com/labs/index.php/author/jaime-blasco/">jaime.blasco</a>&#160;<a href="http://labs.alienvault.com/labs/index.php/category/blog/windows/"></a></div>
<p>Defenses of any sort, virtual or physical,  are a means of forcing your attacker to attack you on your terms, not  theirs. As we build more elaborate defenses within information security,  we force our attacker&#8217;s hand. For instance, in many cases, implementing  multi-factor authentication systems just forces the attacker to go  after that system directly to achieve their goals. Take the breach at  RSA, for example. It has been attributed to attackers who needed the  SecurID information to go after their real targets in the defense  industry.</p>
<p>Recently, our lab has been talking about Sykipot:</p>
<ul>
<li><em><a href="http://labs.alienvault.com/labs/index.php/2011/are-the-sykipots-authors-obsessed-with-next-generation-us-drones/">Are the Sykipot&#700;s authors obsessed with next generation US drones</a>? </em></li>
<li><em><a href="http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/">Another Sykipot sample likely targeting US federal agencies</a></em></li>
</ul>
<p>&#160;</p>
<p>As we discussed, this malware has been used to launch targeted  attacks via &#8220;spear phishing&#8221; campaigns against targets mainly in the US,  since around 2007. According to our research, these attacks originate  from servers in China with what appears to be the purpose of obtaining  information from the defense sector: the same sector that makes  extensive use of PC/SC x509 Smartcards for authentication.</p>
<p>Smartcards have a long history of usage in the Defense Sector, for  both physical and information access management, and historically have  merely forced attackers to route around the smartcard authentication  system through other, more vulnerable attack vectors.</p>
<p>It should come as no surprise, then, that we recently discovered a  variant of Sykipot with some new, interesting features that allow it to  effectively hijack DOD and Windows smart cards. This variant, which  appears to have been compiled in March 2011, has been seen in dozens of  attack samples from the past year.</p>
<p>Like we have shown with previous Sykipot attacks, the attackers use a  spear phishing campaign to get their targets to open a PDF attachment  which then deposits the Sykipot malware onto their machine (the  attackers here took advantage of a zero-day exploit in Adobe). Then,  unlike previous strains, the malware uses a keylogger to steal PINs for  the cards. When a card is inserted into the reader, the malware then  acts as the authenticated user and can access sensitive information. The  malware is controlled by the attackers from the command &#38; control  center.</p>
<p><a href="http://labs.alienvault.com/labs/index.php/http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs/">Click Here to get a whole lot more details on the attack</a></p>]]></description>
<guid isPermaLink="false">1581@http://www.cccure.org</guid>
<dc:subject>Virus</dc:subject>
<dc:date>2012-01-23T09:49:17-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>SOPA and PIPA -- What`s in it for you</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1579</link>
<description><![CDATA[<p>As seen on one of my hosting company mailing list:</p>
<p>Greetings <a href="http://www.site5.com/">Site5 Customers</a>!<br> <br> The U.S. Congress is currently considering two bills -- one in the House  of Representatives called SOPA (Stop Online Piracy Act) and another in  the Senate called PIPA (Protect IP Act). These bills both attempt to use  similar methods to further criminalize and police intellectual property  infringement. Although protecting intellectual property is important,  these bills would use heavy-handed tactics that would censor and  splinter the Internet.<br> <br> SOPA and PIPA would grant the U.S. government the ability to block  almost any website on the Internet if the site is perceived to be an  "infringing site." Search engines would be required to remove the site  from their search listings, payment processors and advertisement  networks would be forbidden from doing business with the site, and ISPs  could be forced to block access to the site for Americans. The bill  provides little detail about what would constitute an infringing site,  which makes the potential for abuse far greater. We have already seen  how these kind of systems can be abused. In 2010, ICE (Immigration and  Customs Enforcement) mistakenly seized a domain name belonging to a  music blog and labeled it as a "rogue site" &#8212; the domain name was not  returned until a year later (source: <a href="http://nyti.ms/uF73mZ">http://nyti.ms/uF73mZ</a>). If you would like to see a video explanation of how the bill works and its dangers, please go here: <a href="http://vimeo.com/31100268">http://vimeo.com/31100268</a><br> <br> Site5 has publicly declared our opposition to both bills, and we  encourage you to do the same. Contact your representatives in Congress  to let your opposition to these bills be known! To locate the contact  information for your representatives, visit one of the following  websites:<br> <br> <a href="http://www.contactingthecongress.org/">http://www.contactingthecongress.org</a><br> <a href="http://www.grassroutes.us/sopa">http://www.grassroutes.us/sopa</a><br> <br> If you're located outside the United States, you can let your voice be heard as well by sending your thoughts via this website:<br> <br> <a href="http://americancensorship.org/">http://americancensorship.org</a><br> <br> Another way to get involved in the fight against SOPA and PIPA is to  join in on the blackouts. Many well-known websites such as Wikipedia,  Google, and Reddit are demonstrating their opposition, and you can too.  Site5 has sponsored a WordPress plugin for participating in blackouts,  and it features an easy setup and configuration options within the  WordPress admin area:<br> <br> <a href="http://wordpress.org/extend/plugins/sopa-blackout-plugin/">http://wordpress.org/extend/plugins/sopa-blackout-plugin/</a><br> <br> We feel very strongly that the future of the Internet is at stake, and we urge everyone to get involved!<br> <br> Thanks,</p>
<p>The Site5 Management Team</p>]]></description>
<guid isPermaLink="false">1579@http://www.cccure.org</guid>
<dc:subject>Law</dc:subject>
<dc:date>2012-01-19T14:20:31-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>DARPA set to develop super-secure &quot;cognitive fingerprint&quot;</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1578</link>
<description><![CDATA[<div class="print-submitted">By <em>Layer 8</em></div>
<div class="print-created">Created <em>Jan 17 2012 - 12:54pm</em></div>
<p>&#160;</p>
<p>Developers at the Defense Advanced Research Projects Agency want to build <a href="http://www.networkworld.com/community/blog/who-really-sets-global-cybersecurity-standard">information technology security</a> [1] that goes beyond simply recognizing complex passwords but rather gets  in your head to confirm your identity before you get access or continue  to have access to important information.</p>
<p>Specifically, the agency's Active Authentication program looks to  develop what DARPA calls "novel ways of validating the identity of the  person at the console that focus on the unique aspects of the individual  through the use of software-based biometrics."</p>
<p><strong>More security news: <a href="http://www.networkworld.com/slideshows/2011/120111-security-layer8.html?ap1=rcb">From Anonymous to Hackerazzi: The year in security mischief-making</a> [2] </strong></p>
<p>Biometrics is defined as the characteristics used to uniquely  recognize humans based upon one or more intrinsic physical or behavioral  traits. Active Authorization focuses on the computational behavioral  traits that can be observed through how we interact with the world. Just  as when you touch something with your finger you leave behind a  fingerprint, when you interact with technology you do so in a pattern  based on how your mind processes information, leaving behind a  "cognitive fingerprint," DARPA said in officially announcing the  contracting process for the program.</p>
<p>DARPA had talked about <a href="http://www.networkworld.com/community/blog/darpa-detail-program-radically-alters-securit">Active Authentication</a> [3] at its Colloquium on Future Directions in Cyber Security meeting last  October.&#160;&#160; "Active Authentication program to tie identity to level of  access within system. You're the key to your system.&#160; Want to make  machine aware of its operator and are working towards systems managing  authentication invisibly in the background," Such new systems might look  at the unique words a user types or examine length of sentences and use  of punctuation to determine user authenticity, said DARPA program  manager Richard Guidorizzi at the meeting.&#160;</p>
<p>In its <a href="https://www.fbo.gov/index?s=opportunity&#38;mode=form&#38;id=093ec9cdad8d8dc49e08855eae680084&#38;tab=core&#38;_cview=1">current announcement</a> [4] DARPA stated: "The current standard method for validating a user's  identity for authentication on an information system requires humans to  do something that is inherently difficult: create, remember, and manage  long, complex passwords. Moreover, as long as the session remains  active, typical systems incorporate no mechanisms to verify that the  user originally authenticated is the user still in control of the  keyboard. Thus, unauthorized individuals may improperly obtain extended  access to information system resources if a password is compromised or  if a user does not exercise adequate vigilance after initially  authenticating at the console."</p>
<p><strong>More news: <a href="http://www.networkworld.com/slideshows/2011/050911-anniversary-timeline.html?ap1=rcb">25 tech touchstones of the past 25 years</a> [5]</strong><strong></strong></p>
<p>DARPA said the current Broad Agency Announcement will address the  first phase of what it says will be a three phase development program.&#160;  In the first phase, the focus will be on researching biometrics that  does not require the installation of additional hardware sensors.  Rather, DARPA will look for research on biometrics that can be captured  through the technology already in use in a standard DoD office  environment, looking for aspects of the "cognitive fingerprint." A heavy  emphasis will be placed on validating any potential new biometrics with  tests to ensure they would be effective in large scale deployments.</p>
<p>Some examples of the computational behavior metrics of the cognitive fingerprint include:</p>
<ul>
<li>- keystrokes</li>
<li>- eye scans</li>
<li>- how the user searches for information (verbs and predicates used)</li>
<li>- how the user selects information (verbs and predicates used)</li>
<li>- how the user reads the material selected </li>
<li>- eye tracking on the page</li>
<li>- speed with which the individual reads the content</li>
<li>- methods and structure of communication (exchange of email)</li>
</ul>
<p>The later planned phases of the program will focus on developing a  system that integrates any available biometrics using a new  authentication platform suitable for deployment on a standard desktop or  laptop. The authentication platform is planned to be developed with  open Application Programming Interfaces (APIs) to allow the integration  of other software or hardware biometrics available in the future from  any source, DARPA stated.&#160;</p>
<p>The Active Authentication program is just one of DARPA's many plans  to improve system security. At its Colloquium meeting the agency  reminded everyone that it had a big hand in creating the Internet and  now its wants to get serious about protecting it.&#160; DARPA Director Regina  Dugan said that since 2009, the agency has steadily increased its cyber  research efforts and its budget submission for fiscal year 2012  increased cyber research funding by $88 million, from $120 million to  $208 million. In addition, over the next five years, the agency plans to  grow its top-line budget investment in cyber research from 8% to 12%.</p>
<p><em>Follow Michael Cooney on Twitter: </em><a href="http://twitter.com/NWWlayer8"><em>nwwlayer8</em></a> [6]<em>&#160;&#160;and on </em><a href="http://www.facebook.com/pages/Layer-8-By-Michael-Cooney/133875286655670"><em>Facebook</em></a> [7]</p>
<div class="print-source_url"><strong>Source URL:</strong> <a href="http://www.networkworld.com/community/blog/darpa-set-develop-super-secure-cognitive-fingerprint">http://www.networkworld.com/community/blog/darpa-set-develop-super-secure-cognitive-fingerprint</a></div>
<p><strong>Links:</strong><br>[1] http://www.networkworld.com/community/blog/who-really-sets-global-cybersecurity-standard<br> [2] http://www.networkworld.com/slideshows/2011/120111-security-layer8.html?ap1=rcb<br> [3] http://www.networkworld.com/community/blog/darpa-detail-program-radically-alters-securit<br> [4] https://www.fbo.gov/index?s=opportunity&#38;mode=form&#38;id=093ec9cdad8d8dc49e08855eae680084&#38;tab=core&#38;_cview=1<br> [5] http://www.networkworld.com/slideshows/2011/050911-anniversary-timeline.html?ap1=rcb<br> [6] http://twitter.com/NWWlayer8<br> [7] http://www.facebook.com/pages/Layer-8-By-Michael-Cooney/133875286655670<br> [8] http://www.networkworld.com/slideshow/25895<br> [9] http://www.networkworld.com/community/blog/nasa's-alternative-space-station-rocks-your-smartphone<br> [10] http://www.networkworld.com/community/blog/x-prize-offers-10m-competiton-build-star-trek-medical-tricorder<br> [11] http://www.networkworld.com/community/blog/who-are-go-cybersecurity-help-groups<br> [12] http://www.networkworld.com/community/blog/quick-look-creation-computer-language-translation-efforts-58-years-ago-month<br> [13] http://www.networkworld.com/community/blog/nasa-set-mars-bound-spacecrafts-biggest-thruster-blast<br> [14] http://www.networkworld.com/community/blog/epa-wants-your-environment-pictures-issues-public-photo-challenge<br> [15] http://www.networkworld.com/community/blog/thick-martian-dust-makes-nasa-pick-sunnier-locale-mars-rover<br> [16] http://www.networkworld.com/community/blog/dept-energy-developing-project-reinforce-grid-cybersecurity<br> [17] http://www.networkworld.com/community/blog/nasa-2012-its-really-not-end-world-we-know-it<br> [18] http://www.networkworld.com/community/blog/murder-it-security-and-other-mysteries-stories-layer-8-2011</p>]]></description>
<guid isPermaLink="false">1578@http://www.cccure.org</guid>
<dc:subject>Cryptography</dc:subject>
<dc:date>2012-01-18T10:26:03-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>New Issue of PenTest Extra Magazine is available</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1577</link>
<description><![CDATA[<table style="font-size: 12px;" border="0" cellpadding="10px">

<tr>
<td style="font-size: 12px;">New Issue of PenTest Extra Magazine is available! <a href="http://pentestmag.com/pentest-extra-012012/"><img style="margin-left: 10px;" src="http://mytalkoot.com/12all/images/zdalnymailing/pt/20120116pt.gif" alt width="343" height="493" align="right"></a> Download the Free Sample Issue to check the content and read Free article, just click <a href="http://pentestmag.com/pentest-extra-012012/">here</a>. <br><br> Read free article "XSS &#38; CSRF: Practical exploitation of  post-authentication vulnerabilities in web applications" by Marsel  Nizamutdinov The goal of this article is to demonstrate the real danger of  post-authenticated vulnerabilities. The author will not explain the  basics of web   application attacks in this article, as that has already been done many  times before by others. He will focus on a practical way to exploit   post-authentication XSS's and CSRF, which remain a highly underestimated  attack vector in the security scene.<br><br> Inside:   
<ul>
<li><strong>XSS &#38; CSRF: Practical exploitation of post-authentication vulnerabilities in web applications</strong> <em>by Marsel Nizamutdinov</em> </li>
<li><strong>Discovering Modern CSRF Patch Failures</strong> <em>by Tyler Borland</em></li>
<li><strong>Business Logic Vulnerabilities via CSRF</strong> <em>by Eugene Dokukin</em></li>
<li><strong>XSS Using Shell of the future</strong> <em>by Sow Ching Shiong</em></li>
<li><strong>Cross-Site Request Forgery</strong> <em>by Jamie</em></li>
<li><strong>Security Resolutions for 2012</strong> <em>by Rishi Narang</em></li>
<li><strong>Interview with Peter N. M. Hansteen</strong> <em>by PenTest Team</em></li>
</ul>
</td>
</tr>
<tr>
<td align="center"><a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52169&#38;l=-http--pentestmag.com/wp-login.php--Q-action--E-register--Q-a_aid--E-krzysztofmarczyk--A-a_bid--E-163efff7"><img src="http://mytalkoot.com/12all/images/zdalnymailing/subbut.png" alt width="272" height="68"></a> 
<hr>
</td>
</tr>
<tr>
<td>Get For Free "The Book of PF" by Peter N. M. Hansteen! <img style="margin-left: 10px;" src="http://mytalkoot.com/12all/images/zdalnymailing/pt/pf2.png" alt width="343" height="453" align="right"> <strong>Buy annual subscription of PenTest and receive:</strong> 
<ul>
<li><strong>Free Ebook</strong> <em>"The Book of PF: A No-Nonsense Guide to the OpenBSD Firewall"</em> <strong>worth $30.00</strong> Today's system administrators face increasing challenges in the quest  for network quality, and The Book of PF can help by demystifying the   tools of modern *BSD network defense. But, perhaps more importantly,  because we know you like to tinker, The Book of PF tackles a broad range    of topics that will stimulate your mind and pad your resume, including  how to:  
<ul>
<li>Create rule sets for all kinds of network traffic, whether it is  crossing a simple home LAN, hiding behind NAT, traversing DMZs, or   spanning bridges</li>
<li>Use PF to create a wireless access point, and lock it down tight with authpf and special access restrictions</li>
<li>Maximize availability by using redirection rules for load balancing and CARP for failover</li>
<li>Use tables for proactive defense against would-be attackers and spammers</li>
<li>Set up queues and traffic shaping with ALTQ, so your network stays responsive</li>
<li>Master your logs with monitoring and visualization, because you can never be too paranoid</li>
</ul>
</li>
</ul>
If you buy PenTest annual subscription, you will receive 48 Issues of PeneTest per year and get:   
<ul>
<li>PenTest (release date: 1st of each month) &#8211; 50 pages of content dedicated to penetration tests, few regular columns written by   specialists</li>
<li>PenTest Extra (release date: 15th of each month) &#8211; 50 pages of  strictly topical content dedicated each time to different hot topic</li>
<li>Mobile Pentesting (release date: 7th of each month) &#8211; 40 pages of content dedicated to latest mobile topics</li>
<li>Web App Pentesting (release date: 22nd of each month) &#8211; 40 pages of content dedicated to web application topics</li>
</ul>
Buy annual subscription and contact us at krzysztof.marczyk@software.com.pl. We will take care of everything for you!</td>
</tr>
<tr>
<td align="center"><a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52169&#38;l=-http--pentestmag.com/wp-login.php--Q-action--E-register--Q-a_aid--E-krzysztofmarczyk--A-a_bid--E-163efff7"><img src="http://mytalkoot.com/12all/images/zdalnymailing/subbut.png" alt width="304" height="76"></a></td>
</tr>

</table>
<p><br> <strong>Contact PenTest team!</strong><br> Please spread the word about PenTest magazine!<br><br> Enjoy reading!<br> Krzysztof Marczyk &#38; PenTest team<br> <a href="mailto:krzysztof-marczyk@software.com.pl">mailto:olga.glowala@software.com.pl</a><br> <a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52170&#38;l=-http--pentestmag.com/">PenTest Magazine</a></p>]]></description>
<guid isPermaLink="false">1577@http://www.cccure.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-16T11:34:15-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Sniffing an SSL Handshake using Wireshark -- Crypto Song</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1576</link>
<description><![CDATA[<p>My good friend Larry Greenblatt an instructor extraordinaire and a men of many talents has created a great song about SSL sniffing using Wireshark.&#160; Listen to it on UTube.&#160; See his note below:</p>
<p>I created a music video about Crypto using Wireshark to sniff a SSL  handshake with Google.&#160; I got some good comments from some Sharkfest  presenters and it looks like I am going to present this at Sharkfest  2012 in June!<br><br> <a href="http://www.youtube.com/watch?v=1dHsj1ZxDto">http://www.youtube.com/watch?v=1dHsj1ZxDto</a></p>]]></description>
<guid isPermaLink="false">1576@http://www.cccure.org</guid>
<dc:subject>Cryptography</dc:subject>
<dc:date>2012-01-15T13:00:23-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>OWASP Long Island Chapter</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1575</link>
<description><![CDATA[<p class="p1">The Open Web Application Security Project (OWASP) is a  501c3 not-for-profit worldwide charitable organization focused on  improving the security of application software. Our mission is to make  application security <a href="https://www.owasp.org/index.php/Category:OWASP_Video">visible,</a> so that <a href="https://www.owasp.org/index.php/Industry:Citations">people and organizations can make informed decisions</a> about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.</p>
<p class="p1">All Long Island chapter meetings are free. Please water our calendar for up coming events.</p>
<p class="p1">For more info contact:&#160; Helen Gao&#160; (helen.gao@wasp.org)</p>
<p class="p1"><strong><a href="https://www.owasp.org/index.php/Long_Island">https://www.owasp.org/index.php/Long_Island</a></strong></p>]]></description>
<guid isPermaLink="false">1575@http://www.cccure.org</guid>
<dc:subject>Vulnerabilities</dc:subject>
<dc:date>2012-01-14T11:43:00-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Live Online CISSP Boot Camp at 1/2 the price of our Live Classroom Boot Camp</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1574</link>
<description><![CDATA[<table id="body_holder" border="0" cellspacing="0" cellpadding="0" width="100%">

<tr>
<td>CISSP &#174; LIVE OnLine
<div style="padding: 10px; background: none repeat scroll 0% 0% #f3f3f3; width: 720px; margin: 0pt auto;">
<table style="background:#FFFFFF" border="0" cellspacing="0" cellpadding="0" width="720">

<tr>
<td width="700">
<table style="normal 12px Arial; color:#202020;" border="0" cellspacing="2" cellpadding="0" width="720">

<tr>
<td style="background:#ffffff; font:bold 18px Arial; padding:10PX; color:#f7f7f7" width="355" align="left" valign="middle"><a href="https://secureninja.com/cpid/70130000000Xyae/"><img src="http://www.insyte.us/www/secureninjas.png" border="0" alt="Secure Ninja" width="200" height="60"></a></td>
<td style="background:#ffffff; font:bold 18px Arial; padding:10PX; color:#E68F1B" colspan="2" width="363" align="right" valign="middle"><a href="http://cccure.org"><img src="http://insyte.us/www/cccurelogo.png" border="0" alt="cccure.org" width="219" height="72"></a><br></td>
</tr>
<tr>
<td colspan="3" align="center" valign="middle"><a href="https://secureninja.com/cpid/70130000000Xyae/"><img src="http://insyte.us/www/cissp_live_cd.png" border="0" alt="Get Certified and Save Big with Secure Ninja's Buy One Get One Promo" width="720" height="300"></a></td>
</tr>
<tr>
<td style="font:normal 13px Arial; background:#fff; padding:10px;" colspan="3" valign="top">
<table border="0" cellspacing="2" cellpadding="0" width="100%">

<tr>
<td width="70%" valign="top">
<div style="font: bold 18px Arial; padding-top: 15px;"><a href="https://secureninja.com/cpid/70130000000Xyae/">Act Now. Special Holiday Pricing.</a></div>
<ul>
<li>Accessible from any Location</li>
<li>No Daily Commute in traffic</li>
<li>No Airfare Fees</li>
<li>No Hotel fees</li>
<li>Same quality of delivery as a brick and mortar class</li>
<li>All sessions are recorded</li>
<li>Listen as many times as you wish</li>
<li>Do it from the comfort of your home</li>
<li>Let Clement guide you to success (pre-present-post mentoring)</li>
<li>5 Day CISSP Immersion Training</li>
<li>Award Winning Proprietary Curriculum</li>
<li>Highest CISSP Exam Pass Rates</li>
<li>Day, Evening,Weekend &#38; Live Online classes to meet your busy schedule</li>
<li>Pre/Present/Post Class Paid Account to CCCure Quiz Engine (World's best CISSP 2000+ exam questions)</li>
<li>Exclusive CISSP Scenario Based Exam Questions</li>
<li>Get DoD 8570.1-M CISSP Compliant</li>
<li>WIA (Workforce Investment Act) Approved</li>
<li>Veterans Benefits &#38; GI Bill Approved - Welcome Military!</li>
<li>Option to resit &#160;Live Online CISSP class for up to one (1) year</li>
</ul>
<div style="font: bold 18px Arial; padding-top: 15px; margin-top: 30px;">Clement Dupuis, CD<br> Your Live Online mentor Before, During  &#38; After class</div>
</td>
<td style="padding:10px 10px 10px 10px;border:1px dashed #ccc; font:bold 13px Arial;" width="30%" valign="top">
<table style="background:#f5f5f5" border="0" cellspacing="3" cellpadding="0" width="100%">

<tr>
<td width="25%" align="center"><a href="https://www.linkedin.com/groups/Secure-Ninja-4209479"><img src="http://insyte.us/www/linkedin.png" border="0" alt="Secure Ninja @ Linkedin" width="28" height="28"></a></td>
<td width="25%" align="center"><a href="https://www.youtube.com/user/Secureninja/featured"><img src="http://insyte.us/www/socialicon_youtube.png" border="0" alt="See Us @ Youtube" width="28" height="28"></a></td>
<td width="25%" align="center"><a href="https://www.facebook.com/SecureNinja"><img src="http://insyte.us/www/socialicon_facebook.png" border="0" alt="Like us on Facebook" width="28" height="28"></a></td>
<td width="25%" align="center"><a href="https://twitter.com/SecureNinjaCom"><img src="http://insyte.us/www/socialicon_twit.png" border="0" alt="Fallow us Twitter" width="28" height="28"></a></td>
</tr>

</table>
<br>
<div style="font: bold 18px Arial; color: #0d2122; margin-bottom: 30px;">Get Live Online Instructor Led Learning for 1/2 the price of our Classroom Based Boot Camps.</div>
<div><a href="https://secureninja.com/cpid/70130000000Xyae/"><img style="margin:0 auto;" src="http://insyte.us/www/bookit.png" border="0" alt="Book it Now" width="110" height="110"></a></div>
Class is filling fast. Call Enrique to secure your seat today.
<p align="start">Phone: +1 703 535 8600 x16<br> Mobile: +1 305 467 7436<br> <br> <a href="mailto:enrique@secureninja.com">Enrique@secureninja.com</a></p>
</td>
</tr>

</table>
</td>
</tr>

</table>
</td>
</tr>
<tr>
<td bgcolor="#f3f3f3">
<table border="0" cellspacing="10" cellpadding="0" width="100%">

<tr>
<td width="31%" height="15" align="left">Secure Ninja<br> 901 North Pitt St. Suite 105<br> Alexandria, VA 22314<br></td>
<td colspan="2" align="center"></td>
<td colspan="2" width="30%" align="right">Phone: 703.535.8600<br> Fax: 703.535.8656<br> Email : <a href="mailto:info@secureninja.com">info@secureninja.com</a></td>
</tr>

</table>
</td>
</tr>

</table>
</div>
</td>
</tr>

</table>]]></description>
<guid isPermaLink="false">1574@http://www.cccure.org</guid>
<dc:subject>Training_News</dc:subject>
<dc:date>2011-12-21T21:45:54-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>WebApp Pentesting for charity</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1573</link>
<description><![CDATA[<table border="0" cellpadding="10px">

<tr>
<td>WebAppPentesting Magazine - new December issue is out!
<p>Why don't we start thinking of those who really need help? Please consider help to those who don't have warm home to spend   Christmas in, who suffer hunger when our tables are full of delicious food, who sleep alone in the shelter, or who spend   their holidays in hospital.</p>
</td>
</tr>
<tr>
<td>Download the Free Teaser Issue to check the content and read <strong>Free Article</strong>, just click <strong><a href="http://mytalkoot.com/12all/lt.php?c=1899&#38;m=1287&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=51329&#38;l=-http--pentestmag.com/category/teasers/">here</a></strong></td>
</tr>
<tr>
<td>What's more you can find inside is:   
<ul>
<li>Web Application Security for Newbies part 1. By Herman Stevens</li>
<li>Web Session Management &#8211; reality is a nightmare! By Rishi Narang</li>
<li>A chance to ease automated Web Site testing. By Marek Zachara</li>
<li>Cyber Security War &#8211; ofensive vs defensive. By Jatin Jain</li>
<li>Web Application Security &#8211; Preservation and Hacking. By Priyanka Tomar</li>
<li>E-banking ghosts. By Sebastien Bischof and Jean-Marc Bost</li>
<li>Mike Brennan and Richard Stiennon &#8220;Cyber Styletto&#8221;</li>
</ul>
</td>
</tr>
<tr>
<td><strong>SUBSCRIBE NOW!</strong></td>
</tr>
<tr>
<td>Christmas offer! Receive Ebook, coupon for Cyber Styletto for 99 cents, 6 months Subscription For Free! <br><br> If you buy PenTest annual subscription, you will receive 48 Issues of PenTest per year and get:   
<ul>
<li>PenTest (release date: 1st of each month) &#8211; 50 pages of content dedicated to penetration tests, few regular columns   written by specialists</li>
<li>PenTest Extra (release date: 15th of each month) &#8211; 50 pages of strictly topical content dedicated each time to different   hot topic</li>
<li>Mobile Pentesting (release date: 7th of each month) &#8211; 40 pages of content dedicated to latest mobile topics</li>
<li>Web App Pentesting (release date: 22nd of each month) &#8211; 40 pages of content dedicated to web application topics</li>
</ul>
<strong>Sounds good? Isn't it?</strong><br></td>
</tr>
<tr>
<td><img src="http://mytalkoot.com/12all/images/zdalnymailing/pt/13_12/okladka_ksiazka.jpg" alt align="left"> 1. FIRST FIVE subscribers will get a free e-book "Network your Computers and Devices" by Cyprian A. Rusen. Don't let the   others take them from you!<br><br> Have you ever wondered about the book which not only can help you to step by step network you computer and devices, but also   can be useful for your relatives? New Step by Step Network your computers and Devices book is best useful tutorial for whole your family. <br><br> <a href="http://mytalkoot.com/12all/lt.php?c=1899&#38;m=1287&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=51330&#38;l=-http--www.7tutorials.com/">Visit 7 Tutorial Website</a></td>
</tr>
<tr>
<td><img style="margin-right: 10px;" src="http://mytalkoot.com/12all/images/zdalnymailing/pt/cyberstyletto2.jpg" alt width="134" height="201" align="left"> 2. For all interested readers we have prepared special coupon for "Cyber Styletto" by Mike Brennan. Get your ebook just for   <strong>99 cents!</strong></td>
</tr>
<tr>
<td><strong>Special Offer! If you buy 1 Year Subscription, you will get from us Additional Six Months for Free! </strong></td>
</tr>
<tr>
<td align="center" bgcolor="4da5ff"><a href="http://pentestmag.com/wp-login.php?action=register?a_aid=katarzynazwierowicz&#38;a_bid=163efff7"><strong>CLICK HERE TO SUBSCRIBE</strong></a></td>
</tr>
<tr>
<td>After subscrinig contact <a href="mailto:katarzyna.zwierowicz@software.com.pl">katarzyna.zwierowicz@software.com.pl</a> with "Subscription" in the tittle of the message</td>
</tr>
<tr>
<td>
<p><img src="http://mytalkoot.com/12all/images/zdalnymailing/pt/hakin9_EN.png" alt><br> Buy one year PenTest Subscription until <strong>December 25th, 11:59 pm GMT+1</strong>, and you&#8217;ll get <strong>one year of Hakin9   Subscription for free!</strong> <br><br> <a href="http://pentestmag.com/get-1-year-hakin9-subscription-for-free/">Don&#8217;t wait for Santa, all is in your   hands!</a></p>
<p>&#160;</p>
<p>&#160;</p>
</td>
</tr>

</table>]]></description>
<guid isPermaLink="false">1573@http://www.cccure.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2011-12-21T11:47:12-05:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

</channel>
</rss>

