
<?phpxml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
>
<channel>
<title>infosec news / admin / All</title>
<link>http://news.infosecinstitute.com</link>
<description>Your Source for Infosec News and Networking</description>
<pubDate>Wed, 16 May 2012 15:26:06 -0400</pubDate>
<language>en</language>
<item>
<title><![CDATA[USB Drives and Wax Seals]]></title>
<link>http://news.infosecinstitute.com/general/usb-drives-and-wax-seals/</link>
<comments>http://news.infosecinstitute.com/general/usb-drives-and-wax-seals/</comments>
<pubDate>Wed, 16 May 2012 15:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/usb-drives-and-wax-seals/</guid>
<description><![CDATA[Need some pre-industrial security for your USB drive? How about a wax seal? Neat, but I recommend combining it with encryption for even more security!...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Vulnerabilities in Airport Full-Body Scanners]]></title>
<link>http://news.infosecinstitute.com/general/security-vulnerabilities-in-airport-full-body-scanners/</link>
<comments>http://news.infosecinstitute.com/general/security-vulnerabilities-in-airport-full-body-scanners/</comments>
<pubDate>Wed, 16 May 2012 09:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/security-vulnerabilities-in-airport-full-body-scanners/</guid>
<description><![CDATA[According to a report from the DHS Office of Inspector General: Federal investigators "identified vulnerabilities in the screening process" at domestic airports using so-called "full body scanners," according to a classified internal Department of Homeland Security report. EPIC obtained an unclassified version of the report in a FOIA response. Here's the summary....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[U.S. Exports Terrorism Fears]]></title>
<link>http://news.infosecinstitute.com/general/u-s-exports-terrorism-fears/</link>
<comments>http://news.infosecinstitute.com/general/u-s-exports-terrorism-fears/</comments>
<pubDate>Tue, 15 May 2012 09:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/u-s-exports-terrorism-fears/</guid>
<description><![CDATA[To New Zealand: United States Secretary of Homeland Security Janet Napolitano has warned the New Zealand Government about the latest terrorist threat known as "body bombers." [...] "Do we have specific credible evidence of a [body bomb] threat today? I would not say that we do, however, the importance is that we all lean forward." Why the headline of this...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[SEC Guidance Is a Really Big Deal]]></title>
<link>http://news.infosecinstitute.com/general/sec-guidance-is-a-really-big-deal/</link>
<comments>http://news.infosecinstitute.com/general/sec-guidance-is-a-really-big-deal/</comments>
<pubDate>Mon, 14 May 2012 17:26:07 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/sec-guidance-is-a-really-big-deal/</guid>
<description><![CDATA[In November I wrote SEC Guidance Emphasizes Materiality for Cyber Incidents, my thoughts after reading an article by Senator Jay Rockefeller and former DHS Secretary Michael Chertoff.  They explained why the CF Disclosure Guidance: Topic No. 2, Cybersecurity issued by the SEC in October is a big deal. Since then I attended a conference on Director's and Officer's insurance in Connecticut, and spoke on a panel about that SEC guidance.  During the conference I learned that the SEC guidance isn't a big deal -- it's a really big deal.  We're talking a game changer, potentially on three fronts.  Here's what I heard at the conference. First, lawyers who read the language in the SEC guidance treated it as a "stop whatever you're doing and read this" moment.  The lawyers I spoke to said the SEC guidance absolutely defined new reporting duties for companies, despite talk of it being merely a "clarification" or restatement of existing guidance.  Clients bombarded insurance firms asking what lan<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[New INFILTRATE 2012 Movie is up! With surprise	introduction by Halvar!]]></title>
<link>http://news.infosecinstitute.com/general/new-infiltrate-2012-movie-is-up-with-surprise-introduction-by-halvar/</link>
<comments>http://news.infosecinstitute.com/general/new-infiltrate-2012-movie-is-up-with-surprise-introduction-by-halvar/</comments>
<pubDate>Mon, 14 May 2012 15:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/new-infiltrate-2012-movie-is-up-with-surprise-introduction-by-halvar/</guid>
<description><![CDATA[Posted by Dave Aitel on May 14OH: &quot;So....static analysis! Let&apos;s talk about it!&quot; (Long pause follows.)<br /><br />That&apos;s pretty much straight out of most parties I go to! Luckily, there<br />are a few people who can go into static analysis to great levels of<br />depth, and some of them give talks at INFILTRATE. :&gt;<br /><br />http://www.immunityinc.com/infiltratemovies/movies/JulienVanegue.mp4<br /><br />-dave<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Re: Mobile Phone Security Survey]]></title>
<link>http://news.infosecinstitute.com/general/re-mobile-phone-security-survey/</link>
<comments>http://news.infosecinstitute.com/general/re-mobile-phone-security-survey/</comments>
<pubDate>Mon, 14 May 2012 11:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/re-mobile-phone-security-survey/</guid>
<description><![CDATA[Posted by Hamid on May 14There were some issues regarding some optional questions that has been<br />marked as mandatory mistakenly. Thanks to quick feedbacks they are<br />fixed now.<br /><br />Hamid<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[The Trouble with Airport Profiling]]></title>
<link>http://news.infosecinstitute.com/general/the-trouble-with-airport-profiling/</link>
<comments>http://news.infosecinstitute.com/general/the-trouble-with-airport-profiling/</comments>
<pubDate>Mon, 14 May 2012 09:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/the-trouble-with-airport-profiling/</guid>
<description><![CDATA[Why do otherwise rational people think it's a good idea to profile people at airports? Recently, neuroscientist and best-selling author Sam Harris related a story of an elderly couple being given the twice-over by the TSA, pointed out how these two were obviously not a threat, and recommended that the TSA focus on the actual threat: "Muslims, or anyone who...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Friday Squid Blogging: New Book on Squid]]></title>
<link>http://news.infosecinstitute.com/general/friday-squid-blogging-new-book-on-squid/</link>
<comments>http://news.infosecinstitute.com/general/friday-squid-blogging-new-book-on-squid/</comments>
<pubDate>Fri, 11 May 2012 19:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/friday-squid-blogging-new-book-on-squid/</guid>
<description><![CDATA[Kraken: The Curious, Exciting, and Slightly Disturbing Science of Squid. And a review. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[April 2012 Free Giveaway Winners of eLearnSecurity Training]]></title>
<link>http://news.infosecinstitute.com/hacking/april-2012-free-giveaway-winners-of-elearnsecurity-training/</link>
<comments>http://news.infosecinstitute.com/hacking/april-2012-free-giveaway-winners-of-elearnsecurity-training/</comments>
<pubDate>Fri, 11 May 2012 15:26:05 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>Hacking</category>
<guid>http://news.infosecinstitute.com/hacking/april-2012-free-giveaway-winners-of-elearnsecurity-training/</guid>
<description><![CDATA[We Have Winners!!<br /><br />On March 21, 2012 eLearnSecurity released a drastically improved verion of the course materials for their professional-level training course, Penetration Testing Course Professional. PTP2 now looks highly more sophisticated, polished and advanced than before with 4 hours of new up to date videos, 800 new slides and completely new modules. PTP2 aims at becoming the most hands-on training course on penetration testing with extremely in-depth course material and two different and highly advanced Virtual Labs integrated within the course itself: Coliseum for web application security and the newly announced Hera Lab. The Professional training course leads to the...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Mobile Phone Security Survey]]></title>
<link>http://news.infosecinstitute.com/general/mobile-phone-security-survey/</link>
<comments>http://news.infosecinstitute.com/general/mobile-phone-security-survey/</comments>
<pubDate>Fri, 11 May 2012 15:26:02 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/mobile-phone-security-survey/</guid>
<description><![CDATA[Posted by Hamid on May 11Hello DD!<br /><br />Few weeks ago I had a writeup about (in)security trends in mobile phones<br />and now I&apos;ve reached to a point that I need results of a survey to<br />validate and confirm some facts that are going to be covered in paper.<br /><br />I would appreciate your help by participating in this survey, or be even<br />more awesome and spread it among your friends that are not security geeks!<br /><br />Survey link:<br /><br />http://goo.gl/pQO02<br /><br />Thank you!<br />Hamid<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Smart Phone Privacy App]]></title>
<link>http://news.infosecinstitute.com/general/smart-phone-privacy-app/</link>
<comments>http://news.infosecinstitute.com/general/smart-phone-privacy-app/</comments>
<pubDate>Fri, 11 May 2012 09:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/smart-phone-privacy-app/</guid>
<description><![CDATA[MobileScope looks like a great tool for monitoring and controlling what information third parties get from your smart phone apps: We built MobileScope as a proof-of-concept tool that automates much of what we were doing manually; monitoring mobile devices for surprising traffic and highlighting potentially privacy-revealing flows [...] Unlike PCs, we have little control over the underlying privacy and security...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Fail]]></title>
<link>http://news.infosecinstitute.com/general/security-fail/</link>
<comments>http://news.infosecinstitute.com/general/security-fail/</comments>
<pubDate>Thu, 10 May 2012 07:26:03 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/security-fail/</guid>
<description><![CDATA[Funny....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[A Foiled Terrorist Plot]]></title>
<link>http://news.infosecinstitute.com/general/a-foiled-terrorist-plot/</link>
<comments>http://news.infosecinstitute.com/general/a-foiled-terrorist-plot/</comments>
<pubDate>Wed, 09 May 2012 13:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/a-foiled-terrorist-plot/</guid>
<description><![CDATA[We don't know much, but here are my predictions: There's a lot more hyperbole to this story than reality. The explosive would have either 1) been caught by pre-9/11 security, or 2) not been caught by post-9/11 security. Nonetheless, it will be used to justify more invasive airport security....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[RuggedCom Inserts Backdoor into Its Products]]></title>
<link>http://news.infosecinstitute.com/general/ruggedcom-inserts-backdoor-into-its-products/</link>
<comments>http://news.infosecinstitute.com/general/ruggedcom-inserts-backdoor-into-its-products/</comments>
<pubDate>Wed, 09 May 2012 09:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/ruggedcom-inserts-backdoor-into-its-products/</guid>
<description><![CDATA[All RuggedCom equipment comes with a built-in backdoor: The backdoor, which cannot be disabled, is found in all versions of the Rugged Operating System made by RuggedCom, according to independent researcher Justin W. Clarke, who works in the energy sector. The login credentials for the backdoor include a static username, "factory," that was assigned by the vendor and can't be...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Overreacting to Potential Bombs]]></title>
<link>http://news.infosecinstitute.com/general/overreacting-to-potential-bombs/</link>
<comments>http://news.infosecinstitute.com/general/overreacting-to-potential-bombs/</comments>
<pubDate>Tue, 08 May 2012 09:26:05 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/overreacting-to-potential-bombs/</guid>
<description><![CDATA[This is a ridiculous overreaction: The police bomb squad was called to 2 World Financial Center in lower Manhattan at midday when a security guard reported a package that seemed suspicious. Brookfield Properties, which runs the property, ordered an evacuation as a precaution. That's the entire building, a 44-story, 2.5-million-square-foot office building. And why? The bomb squad determined the package...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Naval Drones]]></title>
<link>http://news.infosecinstitute.com/general/naval-drones/</link>
<comments>http://news.infosecinstitute.com/general/naval-drones/</comments>
<pubDate>Mon, 07 May 2012 09:26:05 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/naval-drones/</guid>
<description><![CDATA[With all the talk about airborne drones like the Predator, it's easy to forget that drones can be in the water as well. Meet the Common Unmanned Surface Vessel (CUSV): The boat -- painted in Navy gray and with a striking resemblance to a PT boat -- is 39 feet long and can reach a top speed of 28 knots....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Friday Squid Blogging: Squid Bicycle Parking Sculpture]]></title>
<link>http://news.infosecinstitute.com/general/friday-squid-blogging-squid-bicycle-parking-sculpture/</link>
<comments>http://news.infosecinstitute.com/general/friday-squid-blogging-squid-bicycle-parking-sculpture/</comments>
<pubDate>Fri, 04 May 2012 17:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/friday-squid-blogging-squid-bicycle-parking-sculpture/</guid>
<description><![CDATA[Neat. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Tampon-Shaped USB Drive]]></title>
<link>http://news.infosecinstitute.com/general/tampon-shaped-usb-drive/</link>
<comments>http://news.infosecinstitute.com/general/tampon-shaped-usb-drive/</comments>
<pubDate>Fri, 04 May 2012 15:26:07 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/tampon-shaped-usb-drive/</guid>
<description><![CDATA[This vendor is selling a tampon-shaped USB drive. Although it's less secure now that there are blog posts about it....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Facial Recognition of Avatars]]></title>
<link>http://news.infosecinstitute.com/general/facial-recognition-of-avatars/</link>
<comments>http://news.infosecinstitute.com/general/facial-recognition-of-avatars/</comments>
<pubDate>Fri, 04 May 2012 09:26:03 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/facial-recognition-of-avatars/</guid>
<description><![CDATA[I suppose this sort of thing might be useful someday. In Second Life, avatars are easily identified by their username, meaning police can just ask San Francisco-based Linden Labs, which runs the virtual world, to look up a particular user. But what happens when virtual worlds start running on peer-to-peer networks, leaving no central authority to appeal to? Then there...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Criminal Intent Prescreening and the Base Rate Fallacy]]></title>
<link>http://news.infosecinstitute.com/general/criminal-intent-prescreening-and-the-base-rate-fallacy/</link>
<comments>http://news.infosecinstitute.com/general/criminal-intent-prescreening-and-the-base-rate-fallacy/</comments>
<pubDate>Thu, 03 May 2012 08:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/criminal-intent-prescreening-and-the-base-rate-fallacy/</guid>
<description><![CDATA[I've often written about the base rate fallacy and how it makes tests for rare events -- like airplane terrorists -- useless because the false positives vastly outnumber the real positives. This essay uses that argument to demonstrate why the TSA's FAST program is useless: First, predictive software of this kind is undermined by a simple statistical problem known as...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Al Qaeda Steganography]]></title>
<link>http://news.infosecinstitute.com/general/al-qaeda-steganography/</link>
<comments>http://news.infosecinstitute.com/general/al-qaeda-steganography/</comments>
<pubDate>Wed, 02 May 2012 14:26:03 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/al-qaeda-steganography/</guid>
<description><![CDATA[The reports are still early, but it seems that a bunch of terrorist planning documents were found embedded in a digital file of a porn movie. Several weeks later, after laborious efforts to crack a password and software to make the file almost invisible, German investigators discovered encoded inside the actual video a treasure trove of intelligence -- more than...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cybercrime as a Tragedy of the Commons]]></title>
<link>http://news.infosecinstitute.com/general/cybercrime-as-a-tragedy-of-the-commons/</link>
<comments>http://news.infosecinstitute.com/general/cybercrime-as-a-tragedy-of-the-commons/</comments>
<pubDate>Wed, 02 May 2012 10:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/cybercrime-as-a-tragedy-of-the-commons/</guid>
<description><![CDATA[Two very interesting points in this essay on cybercrime. The first is that cybercrime isn't as big a problem as conventional wisdom makes it out to be. We have examined cybercrime from an economics standpoint and found a story at odds with the conventional wisdom. A few criminals do well, but cybercrime is a relentless, low-profit struggle for the majority....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[May 2012 Free Giveaway Sponsor - iSWAT by FishNet Security]]></title>
<link>http://news.infosecinstitute.com/hacking/may-2012-free-giveaway-sponsor-iswat-by-fishnet-security/</link>
<comments>http://news.infosecinstitute.com/hacking/may-2012-free-giveaway-sponsor-iswat-by-fishnet-security/</comments>
<pubDate>Tue, 01 May 2012 13:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>Hacking</category>
<guid>http://news.infosecinstitute.com/hacking/may-2012-free-giveaway-sponsor-iswat-by-fishnet-security/</guid>
<description><![CDATA[Win 1 Free Training Seat at iSWAT 2012 Worth $3995!!<br /><br />Information Security Warrior Authorized Training (iSWAT) (http://www.iswatevent.com/) event. During this training event, you will gain tactical insights and strategies to conquer your career and corporate goals with: <br /><br /><br />	<br />	&bull; Nationally recognized elite instructors offering multi-vendor training programs<br />	&bull; Network with industry leaders<br />	&bull; Onsite certification testing<br />	&bull; Reduced costs with a single training event  <br />	<br /><br /><br />So what's in it for you? Not just a ticket to another security conference, but this month's chosen winner gets a full seat in the training course of their choice... and there are plenty from which to choose. To see...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[With a real team, it's not about the numbers]]></title>
<link>http://news.infosecinstitute.com/general/with-a-real-team-its-not-about-the-numbers/</link>
<comments>http://news.infosecinstitute.com/general/with-a-real-team-its-not-about-the-numbers/</comments>
<pubDate>Tue, 01 May 2012 11:26:01 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/with-a-real-team-its-not-about-the-numbers/</guid>
<description><![CDATA[Posted by Dave Aitel on May 01I find articles like the recent one in Forbes <br />&lt;http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/&gt;<br /> quite funny in a way - and likewise talks about &quot;rootite&quot; and bug mining and so forth. Part of this is because <br />philosophically I know that teams who focus on the money tend to lose. Obviously you need a lot of money to get things <br />done in...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[When Investigation Fails to Prevent Terrorism]]></title>
<link>http://news.infosecinstitute.com/general/when-investigation-fails-to-prevent-terrorism/</link>
<comments>http://news.infosecinstitute.com/general/when-investigation-fails-to-prevent-terrorism/</comments>
<pubDate>Tue, 01 May 2012 09:26:05 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/when-investigation-fails-to-prevent-terrorism/</guid>
<description><![CDATA[I've long advocated investigation, intelligence, and emergency response as the places where we can most usefully spend our counterterrorism dollars. Here's an example where that didn't work: Starting in April 1991, three FBI agents posed as members of an invented racist militia group called the Veterans Aryan Movement. According to their cover story, VAM members robbed armored cars, using the...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Interview with MAKE: The End of chumby, New Adventures]]></title>
<link>http://news.infosecinstitute.com/general/interview-with-make-the-end-of-chumby-new-adventures/</link>
<comments>http://news.infosecinstitute.com/general/interview-with-make-the-end-of-chumby-new-adventures/</comments>
<pubDate>Mon, 30 Apr 2012 21:26:10 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/interview-with-make-the-end-of-chumby-new-adventures/</guid>
<description><![CDATA[Last week, the Internet discovered the end of chumby as you have known it. My exit from the company five months ago was deliberately discreet. It was a good run, but it was also time for me to move on. Upon hearing the news, my good friend Phil Torrone reached out to do an interview, [...]<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Course Review: Penetration Testing Professional v2 by eLearnSecurity]]></title>
<link>http://news.infosecinstitute.com/hacking/course-review-penetration-testing-professional-v2-by-elearnsecurity/</link>
<comments>http://news.infosecinstitute.com/hacking/course-review-penetration-testing-professional-v2-by-elearnsecurity/</comments>
<pubDate>Mon, 30 Apr 2012 13:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>Hacking</category>
<guid>http://news.infosecinstitute.com/hacking/course-review-penetration-testing-professional-v2-by-elearnsecurity/</guid>
<description><![CDATA[second release of Penetration Testing Professional (affectionately known as PTP2) (http://www.elearnsecurity.com/course/penetration_testing/), which most notably contains expanded content and new lab environments. <br /><br /><br />The course is delivered through a web-based Flash interface. The presentation will be familiar to anyone who has experience with the first iteration of the course, but at the same time the overall feel is cleaner and more polished. A colleague was recently considering web app training, and he was torn between a book and this course. He stated something along the lines of, &ldquo;My brain is telling me to be economical and just get a book, but my...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[JCS Chairman Sows Cyberwar Fears]]></title>
<link>http://news.infosecinstitute.com/general/jcs-chairman-sows-cyberwar-fears/</link>
<comments>http://news.infosecinstitute.com/general/jcs-chairman-sows-cyberwar-fears/</comments>
<pubDate>Mon, 30 Apr 2012 09:26:07 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/jcs-chairman-sows-cyberwar-fears/</guid>
<description><![CDATA[Army General Martin E. Dempsey, the chairman of the Joint Chiefs of Staff, said: A cyber attack could stop our society in its tracks. Gadzooks. A scared populace is much more willing to pour money into the cyberwar arms race....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Vote for Liars and Outliers]]></title>
<link>http://news.infosecinstitute.com/general/vote-for-liars-and-outliers/</link>
<comments>http://news.infosecinstitute.com/general/vote-for-liars-and-outliers/</comments>
<pubDate>Fri, 27 Apr 2012 21:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/vote-for-liars-and-outliers/</guid>
<description><![CDATA[Actionable Books is having a vote to determine which of four books to summarize on their site. If you are willing, please go there and vote for Liars and Outliers. (Voting requires a Facebook ID.) Voting closes Monday at noon EST, although I presume they mean EDT....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Bringing the Unsexy Back: The Process of Selling SE Penetration Tests]]></title>
<link>http://news.infosecinstitute.com/hacking/bringing-the-unsexy-back-the-process-of-selling-se-penetration-tests/</link>
<comments>http://news.infosecinstitute.com/hacking/bringing-the-unsexy-back-the-process-of-selling-se-penetration-tests/</comments>
<pubDate>Fri, 27 Apr 2012 17:26:09 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>Hacking</category>
<guid>http://news.infosecinstitute.com/hacking/bringing-the-unsexy-back-the-process-of-selling-se-penetration-tests/</guid>
<description><![CDATA[By Chris Hadnagy <br /><br /><br />For the past few months, I&rsquo;ve brought you articles on launching your career as a social engineer, the psychology and history behind hacking humans and even some scams you can pull on your clients for their own good.  As wonderful as it is to talk about the methods, the tricks and the sexy stories of social engineering pwnage, we need to take a step back and discuss the business end of this spectrum. <br /><br /><br />Yes, I said it&hellip; business side.  After all, most of us reading this article either are in IT/Security or want to be....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Friday Squid Blogging: Chesapeake Bay Squid]]></title>
<link>http://news.infosecinstitute.com/general/friday-squid-blogging-chesapeake-bay-squid/</link>
<comments>http://news.infosecinstitute.com/general/friday-squid-blogging-chesapeake-bay-squid/</comments>
<pubDate>Fri, 27 Apr 2012 14:26:02 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/friday-squid-blogging-chesapeake-bay-squid/</guid>
<description><![CDATA[Great pictures. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Attack Mitigation]]></title>
<link>http://news.infosecinstitute.com/general/attack-mitigation/</link>
<comments>http://news.infosecinstitute.com/general/attack-mitigation/</comments>
<pubDate>Fri, 27 Apr 2012 08:26:02 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/attack-mitigation/</guid>
<description><![CDATA[At the RSA Conference this year, I noticed a trend of companies that have products and services designed to help victims recover from attacks. Kelly Jackson Higgins noticed the same thing: "Damage Mitigation as the New Defense." That new reality, which has been building for several years starting in the military sector, has shifted the focus from trying to stop...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[72 hours]]></title>
<link>http://news.infosecinstitute.com/general/72-hours/</link>
<comments>http://news.infosecinstitute.com/general/72-hours/</comments>
<pubDate>Thu, 26 Apr 2012 19:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/72-hours/</guid>
<description><![CDATA[Posted by Shari Bermudez on Apr 26Just a reminder that there are only 72 business hours remaining before<br />registration closes for the WebHacking and Master training classes.<br />Sign up today. Call 786-220-0600 or email training () immunityinc com <br />The 20% discount offer for re-tweeting still stands.<br /><br />http://immunityinc.com/education-currentschedule.shtml<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Spooked at RSA 2012]]></title>
<link>http://news.infosecinstitute.com/general/spooked-at-rsa-2012/</link>
<comments>http://news.infosecinstitute.com/general/spooked-at-rsa-2012/</comments>
<pubDate>Thu, 26 Apr 2012 12:26:02 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/spooked-at-rsa-2012/</guid>
<description><![CDATA[Posted by Dave Aitel on Apr 26So we put my RSA 2012 talk up, along with the comments from the viewers that RSA collected. <br /><br />I 100% agree with every comment in the feedback form, which include such bon mots such as &quot;You reek of pride&quot;. Frankly, <br />I am quite proud of what the offensive community has been able to do over the last ten years. And I was a bit hurried <br />during the actual talk (the one below is from my 6am-dry-run-in-hotel-room since they didn&apos;t record...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Biometric Passports Make it Harder for Undercover CIA Officers]]></title>
<link>http://news.infosecinstitute.com/general/biometric-passports-make-it-harder-for-undercover-cia-officers/</link>
<comments>http://news.infosecinstitute.com/general/biometric-passports-make-it-harder-for-undercover-cia-officers/</comments>
<pubDate>Thu, 26 Apr 2012 09:26:02 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/biometric-passports-make-it-harder-for-undercover-cia-officers/</guid>
<description><![CDATA[Last year, I wrote about how social media sites are making it harder than ever for undercover police officers. This story talks about how biometric passports are making it harder than ever for undercover CIA agents. Busy spy crossroads such as Dubai, Jordan, India and many E.U. points of entry are employing iris scanners to link eyeballs irrevocably to a...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Book Review: Metasploit  The Penetration Tester's Guide]]></title>
<link>http://news.infosecinstitute.com/hacking/book-review-metasploit-/</link>
<comments>http://news.infosecinstitute.com/hacking/book-review-metasploit-/</comments>
<pubDate>Wed, 25 Apr 2012 17:26:06 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>Hacking</category>
<guid>http://news.infosecinstitute.com/hacking/book-review-metasploit-/</guid>
<description><![CDATA[&ldquo;Metasploit &ndash; The Penetration Tester's Guide&rdquo; (http://nostarch.com/metasploit) by David Kennedy, Jim O&rsquo;Gorman, Devon Kearns, and Mati Aharoni is perhaps the most enjoyable book I have come across regarding the uses and functionality of Metasploit (http://www.metasploit.com). There were so many concepts it refreshed me on, many functions I didn&rsquo;t know existed and other functions I did not correctly understand even with my years of using Metasploit. Let&rsquo;s take an in-depth look into this stellar publication by No Starch Press. <br /><br /><br />Initially I skipped through the first chapter of the book, &ldquo;The Absolute Basics of Penetration Testing.&rdquo; However, I went back to the...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[What's happening at SyScan'12 Singapore]]></title>
<link>http://news.infosecinstitute.com/general/whats-happening-at-syscan12-singapore/</link>
<comments>http://news.infosecinstitute.com/general/whats-happening-at-syscan12-singapore/</comments>
<pubDate>Wed, 25 Apr 2012 11:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/whats-happening-at-syscan12-singapore/</guid>
<description><![CDATA[Posted by Thomas Lim on Apr 25Dear Dailydave readers<br /><br />Do you know what&apos;s going to happen at SyScan&apos;12 Singapore next week?<br /><br />BEER, BEER, BEER, BEER, BEER, BEER, BEER, BEER....<br /><br />13 AWESOME SPEAKERS:<br />a. Stefan Esser (i0n1c)<br />b. Chris Valasek (nudeaberdasher)<br />c. Tarjei Mandt (kernelpool)<br />d. Alex Ionescu<br />e. Edgar Barbosa (0pC0de)<br />f. Jon Oberheide<br />g. Brett Moore (antic0de)<br />h. James Burton (Jayji)<br />i. Seung Jin Lee (Beist)<br />j. Ryan MacArthur (Backpacker)<br />k. Loukas (snare)<br />l....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Fear and the Attention Economy]]></title>
<link>http://news.infosecinstitute.com/general/fear-and-the-attention-economy/</link>
<comments>http://news.infosecinstitute.com/general/fear-and-the-attention-economy/</comments>
<pubDate>Wed, 25 Apr 2012 09:26:03 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/fear-and-the-attention-economy/</guid>
<description><![CDATA[danah boyd is thinking about -- in a draft essay, and as a recording of a presentation -- fear and the attention economy. Basically, she is making the argument that the attention economy magnifies the culture of fear because fear is a good way to get attention, and that this is being made worse by the rise of social media....<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Amazing Round of "Split or Steal"]]></title>
<link>http://news.infosecinstitute.com/general/amazing-round-of-split-or-steal/</link>
<comments>http://news.infosecinstitute.com/general/amazing-round-of-split-or-steal/</comments>
<pubDate>Tue, 24 Apr 2012 10:26:07 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/amazing-round-of-split-or-steal/</guid>
<description><![CDATA[In Liars and Outliers, I use the metaphor of the Prisoner's Dilemma to exemplify the conflict between group interest and self-interest. There are a gazillion academic papers on the Prisoner's Dilemma from a good dozen different academic disciplines, but the weirdest dataset on real people playing the game is from a British game show called Golden Balls. In the final...<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Save yourself 20% by tweeting]]></title>
<link>http://news.infosecinstitute.com/general/save-yourself-20-by-tweeting/</link>
<comments>http://news.infosecinstitute.com/general/save-yourself-20-by-tweeting/</comments>
<pubDate>Mon, 23 Apr 2012 17:26:04 -0400</pubDate>
<dc:creator>admin</dc:creator>
<category>General</category>
<guid>http://news.infosecinstitute.com/general/save-yourself-20-by-tweeting/</guid>
<description><![CDATA[Posted by Shari Bermudez on Apr 23Want to come to our June Master or WebHacking class but do not want to<br />pay full price?  You can save yourself 20% in ~5 minutes by following<br />these simple steps:<br /><br />(1) If you are not already doing so, follow us on Twitter @immunityinc<br />and/or @infiltratecon.<br /><br />(2) ReTweet this tweet from today: &quot;RT and receive 20% off June<br />training classes when you sign up before 4/27! ow.ly/asvSG e-mail<br />admin () immunityinc for info!&quot;<br /><br />(3) Email training...<br/><br/>1 Vote(s) ]]></description>
</item>

</channel>
</rss>

