Tuesday Feb 7

Archive for August, 2009

Aug
28/09
Listen to our PCI Wireless Podcast
Last Updated on Tuesday, 31 January 2012 04:52
Written by jj
Friday, August 28th, 2009

Immediately after landing in Las Vegas for Black Hat and Defcon, I (literally) gathered my luggage and ran to the hotel to check in and hop on the StillSecureAfterAllTheseYears (SSAATY) Podcast with some of my favorite trouble-making colleagues for throw my two cents in on the PCI Wireless Podcast. (more…)

Tags: , , , , ,   |  Posted under Wireless  |  Comments  No Comments
Aug
17/09
Quick Update for Feed Subscribers
Last Updated on Saturday, 28 January 2012 06:43
Written by jj
Monday, August 17th, 2009

If you’re viewing this in your feed reader of choice, or perhaps just online at the site, I wanted to let you know about the email updates I’m sending out.

This is your notice and opportunity to hop on the email subscription list before the next set of sneak preview content is sent. (more…)

Aug
17/09
Network Security on a Budget: Video, Podcast and Tips
Last Updated on Monday, 17 August 2009 04:13
Written by jj
Monday, August 17th, 2009

Recently, I worked with the Tech Target team on content for the Network Security School for midmarket organizations. In this Midmarket Security School set, you’ll find tips and tricks on how to streamline your network security budget, retool the infrastructure for security and my personal list of top five security issues to avoid.

Find the video, podcast and top five tips at Search Midmarket Security.

Streamlining your network security infrastructure  – VIDEO
Learn how to save money by streamlining your network security infrastructure.
   1. Retooling the infrastructure for security
   2. Identifying and classifying tools and resources
   3. Leveraging your current personnel, experience and interests
   4. Exploring uncommon uses for software and hardware
   5. Reviewing overlooked functions of switches, routers and firewalls
   6. When shoestrings aren’t enough
.
How to rework your network infrastructure for security  – TIPS
NEW! Retooling your existing network infrastructure for security requires less complexity and more attention to basics such as switches, centralized authentication, UTMs and network segmentation.

Five network security issues to avoid  – PODCAST
NEW! This podcast covers some common network security issues and how you can go about avoiding them in your organization.
  
1. The management malady
   2. Partial lockdown
   3. Documentation
   4. Cutting with a spoon
   5. Vendor voo doo

If you get tired of listening to me after a couple of minutes, you can find more Midmarket Security School content online.

 

 

# # #

Aug
13/09
Support HFC and Sport a Three-of-a-kind Shirt
Last Updated on Thursday, 13 August 2009 10:50
Written by jj
Thursday, August 13th, 2009

As most of you may know, we have had the pleasure of hosting Johnny Long to speak at several events in the Southeast area, including our own Carolina Advanced Digital-hosted IT Hot Topics Conference hosted annually for customers.

And many of you probably know Johnny and his family embarked on a great adventure this year by MOVING to Africa. You can read the entire story of “The Long Journey” on his blog site to get a little background on the story.

We have a pretty tight community here, in the security world. When one member of our community undertakes a challenge such as this, we all tend to adopt the burden and try to help however possible.

And so, now we’re asking you to participate too – by checking out these one-of-a-kind t-shirts up for auction on eBay. You’ll see these shirts have been signed by some prominent names, including Johnny, Dan Kaminsky (he who keeps breaking the Interwebs), Jeff Moss (founder of Black Hat and Defcon), Kevin Mitnick (famous hacker turned author), Joe Grand (from Prototype This) and many others.

Right now these shirts are bidding from $30 – $70. This is to support a family’s efforts in Africa. I’d like to see them each go for a few hundred dollars. It’s a great investment!

Bid now. Auctions end Tuesday, August 18th around 9:00pm Eastern.

About the Charity T-Shirt Auctions…
All of the proceeds from these auctions except the ebay auction cost will be donated to “Hackers for Charity” http://johnny.ihackstuff.com/

These Shirts were Signed by Most of the Big names at Defcon 17.
Anyone that attended may have seen these shirts displayed at the “Hackers for Charity” booth on Sunday.
Everyone online and at defcon has seen the black “I hack charities” T-shirts. But not many have seen the white ones.  Well that is because there were only 4 white shirts printed!  Johnny Long has 1 and the
other 3 were all signed by the people below for these auctions. Each shirt is unique with the location of the signatures and the quotes written by the signers.
These shirts were signed by:
• Johnny Long 
• Dan Kaminsky
• Jeff “The Dark Tangent” Moss
• Kevin Mitnick
• Joe “$Kingpin$” Grand
• Bruce Potter
• Nikita
• Priest
• The Entire 2009 CTF winning team
• and many others.

Where to Find the Auctions

# # #

Tags: , ,   |  Posted under Random-izations  |  Comments  No Comments
Aug
05/09
Oh, did you think I was a recruiter?
Last Updated on Thursday, 6 August 2009 04:58
Written by jj
Wednesday, August 5th, 2009

Over the past several weeks, I have received an INORDINATE amount of emails, blog contacts, FaceBook and LinkedIn messages from eager IT beavers seeking out new opportunities for employment.

I’ve been receiving these pleas from people I do not know. Perhaps it’s due to my involvement in ISSA or other professional organization. So… did you think I was a recruiter? Does CISO now stand for Career Information and Search Organizer? Who knows.

Get IT Security Career Advice
Now, most of you that know me know I’ll gladly help whenever I can and pass along any contacts, tips and resources – some of my favorites being those from L.J. Kushner and Associates. You can find Kusher and Associates at their site there and read great advice on the Information Security Leaders site, run by Lee Kushner and Mike Murray- both extremely well connected and effective professionals. If you’re a Twit, find blog tweets at @LJKush or follow Mike at @mmurray.

On a much less serious note, I thought I’d post a fun little show and tell here.

Looking to Hire a Security Pro?
Your Friendly Job Placement Person (that’s me evidently) has qualified candidates seeking opportunities in a variety of IT security fields, including:

  • Log Management, Data Analysis and Data Visualization
  • Audit and Compliance Security Assessors
  • Audit and Compliance Policy Review Professionals
  • Firewall, IDS/IPS Systems Administrators
  • PHP and Application Programmer
  • Communications and PR Managers
  • Network Security SE Managers <- no, not me
  • We have two candidates seeking positions as astronauts
  • One candidate seeking a part-time position as a princess

I’m sure I’m missing a few people. Please feel free to add your candidate information below as ‘LOOKING’. Or, for organizations seeking candidates, please post a ‘SEEKING’ comment. You may post anonymously, but make sure there is valid contact information or direct people to a link containing the job listing if you’re using a recruiter. If you post something completely ridiculous and not serious, hopefully it is funny enough that readers know it’s a joke.

Some of the above positions are real; names have been changed to protect the innocent.

Become a Security Rockstar
If the resources on Kush’s and Murray’s sites are not enough, you can learn how to be a Security Rockstar from CyberWar CloudSec Master Luminary (and Virtual Social Media Expert) Chris Hoff by reading this recent post. If you’re an audial learner, you can listen to the Security Rockstar song here.

# # #

Tags: , , ,   |  Posted under Industry Insider  |  Comments  6 Comments

More Content

Find more of my content at
- Low Tech Hacking book
- Dark Reading
- Network Computing
- IANS
- SearchSecurity
- TechTarget

Get Social

RSSFacebookLinkedinYoutube