People occasionally ask me what kind of training and courses to take to get into IT Security.
I think the best summary I have found is in this CompTIA Roadmap graphic: (click to go to the interactive one on CompTIA's website)
Basically, get your self started in IT. If you have absolutely no computer experience start with an A+.
Then, for the most part, I agree with this map in terms of what falls into the Beginner, intermediate, Advanced, Specialist and Expert categories. I think C|EH could probably be moved down a notch or two though.
I don't like CompTIA's career path lines though. If you think you can go MTA Security, Sec+, CASP, CISA, CISSP and ignore all the stuff on other lines... you will be really disappointed.
Basically you want to get on any other line besides the training path (that's pretty much a dead end unless you just want to teach) I would say Networking, Network Admin, or Services/Helpdesk would be good starting points, and pick up equal level certs on the security line as you go along.
If you don't have a solid background in SOMETHING, whether that be networks, operating systems, databases, whatever... you won't be able to handle the security.
Early bird registration for SecTor (Toronto's fall Information Security conference) has opened today.
If you hunt around there are 10% discount codes being passed about by the sponsors like TASK.
If you can organize a group of 5 or more you can get 20% off. Contact renu@sector.ca
If you are interested in Information Security and will be in Toronto the first week of Oct. sign up. http://sector.ca
[Update Mar28 2012:]
From the announcement e-mail sent out today:
What's new for SecTor 2012?
• A larger expo area featuring activity centres and vendor demos on the latest technology solutions
• An expo theatre where you can learn from industry sponsors
• Larger breakout rooms to accommodate our growing numbers
• A coffee lounge were you can "plug-in" and recharge throughout the day
• Larger breakout rooms to accommodate our growing numbers
• We have added a bits and bites track to our already popular, technical, management and turbo tracks, giving you more opportunity to learn about the latest threats facing our community today
Keynote Speakers Announced
Dr. Michael Geist is a law professor at the University of Ottawa where he holds the Canada Research Chair in Internet and E-commerce Law. Dr. Geist is an internationally syndicated columnist on technology law issues with his regular column appearing in the Toronto Star and the Ottawa Citizen. Check our speaker page for Dr. Geist's complete bio.
Charlie Miller is Principal Research Consultant at Accuvant Labs. Mr. Miller was the first with a public remote exploit for both the iPhone and a phone running Android and has won the CanSecWest Pwn2Own competition for the last four years. He has authored two (and a half) information security books . More...
Jim Reavis, the Co-founder and Executive Director of CSA, was recently named as one of the Top 10 cloud computing leaders by SearchCloudComputing.com. Jim is the President of Reavis Consulting Group, LLC, where he advises security companies, large enterprises and other organizations on the implications of new trends and how to take advantage of them. More...
Monday, March 19, 2012
As an IT professional a lot of people ask me what kind of computer to get. So, I have found a video from Eli the Computer Guy that explains well what to look for in computers.
Unfortunately Eli still believes the old lie that you can't get a virus or spyware on a Mac. Don't believe that. Mac's get sick too. Mind you, this is an old video from back in Jan 2010. A lot of people believed that back then.
For more about that see About.com's Mac Virus FAQ, or this PCworld article from October, or this Computerworld article from last month, or just Google it. The biggest class of Mac malware is trojan horses, just like on Windows these days, and second to that is malware that targets an application like flash or Java or Office that works on both Mac and Windows. A trojan usually comes with other software so anyone telling you that a Mac won't get malware because you have to give it permission to install a program shouldn't be listened to. If you think you are giving your password to give it permission to install iWork and you are really giving it permission to install iWork and a trojan horse, then that piece of protection doesn't work.
Other than that one point I think Eli's advice is spot on.
A little bit of an update to his recommendations, He was right, even then, that if you are buying new and are faced with a choice between 32 and 64 bit Windows go with the machine with the 64 bit, but don't go 64bit on a netbook/nettop if it's offered, even though they can do it these days, the biggest reason for 64bit Windows is to get more than 4GB of RAM and no netbook ever made can handle that much RAM. 64bit programs eat up a little bit more RAM than the 32bit ones, so you want to conserve what little RAM you have on a netbook/nettop.
That said, 4GB should be a nice target number to aim for for RAM with expansion room to go to more when it's needed.
With hard disks, bigger is better. You can never have too much storage space... and pick up an external USB hard disk of at least equal size if you have a spare $100. This will be your back up disk you can set the computer up to make an automatic back up to the back up disk. Do not store anything on that disk, just the back up. believe me you will be happy you did when you need to get something from your backup that would have otherwise been lost. If you use the computer for a small business get at least 2 of these back up disks and rotate them out once in a while, connecting one to the computer and storing the other off site in case there is ever a fire.
While I was in Barcelona, visiting my wife, who is working over there, Microsoft was in another part of town unveiling the Consumer Preview edition (*cough* BETA *cough*) of Windows 8.
and download the setup file. They ask for your e-mail address, but you can skip that.
The idea of the consumer preview (what they used to call a beta) is to get feedback from real customers, so you don't need to give them any money or be part of an in-crowd to get it. The CP, like all previous betas is time limited. There will come a day when it will simply not boot anymore, so only install it on a test machine.
It is a very cool looking product aimed at being an iPad killer, by bringing the whole world of windows software to a new generation of Windows 8 based iPad-like tablets.
I have to admit, I have not yet had a chance to play with it, but I do have it downloaded and will be installing it to test on my netbook in the next few days. I am guessing though that Win8 will need something more than that to function properly though. It barely handles 7.
or register for an evaluation of Pro Feed for Nessus if you are a business,
government or organization (pro feed includes support and access to more
features such as regulatory compliance checks, and is the only legal option if
you are not using it at home for personal use):
I know, I've been awfully quiet the last few months. I said in a Youtube video a while back that I was going to post some security/hacking related videos and haven't really gotten around to it... but if you are in Atlantic Canada there is good news!
The Atlantic Security Conference is coming up in March and the line-up
is getting better each day.
Travis Barlow says you can share it, so give it to all of your geeky/security minded friends on the East coast, or even ones who are willing to go to the Maritimes this March.
This video is the result of trying to answer my own curiosity about what kinds of WiFi networks are people actually using out there in the real world?
I decided that I wanted to know what other folks in my area were doing in the wireless space.
On the train ride home from this year's SecTor Security Conference this year I did a little survey.
This is actually the second time I've done this, the first was a year ago, on my way home from the November TASK meeting. but I never posted results of that.. I started to write a blog post but then scrapped it.
Anyway, I was curious...
...so I pulled out my netbook and fired up airodump-ng for a little war-driving (war-training?).
Please note, I did not attempt to connect to any of the networks I found. This was just a listening exercise to see who was out there. I chose the program airodump-ng specifically because I know it does not attempt to communicate with the Access Point, it just logs who was sending as it sees it. I also did not use it, like Google, to capture and record any transmitted payload data. I was not interested in who was connected, or what they were doing, just how the APs were configured.
When I got home I started compiling the data that I collected into a spreadsheet so that I could make some sense of it.
Note: this wireless survey only covered a small area, the stretch along the train tracks (and major highway) between downtown Toronto's Union Station, and the Whitby station to the east, about a 1 hour train ride.
I updated ZoneAlarm on one of my PCs today, and was greeted by this screen making some of the grandest claims I've ever seen from a computer security product.
Claim #1 isn't so bad. "Your computer is protected against hackers" I should hope that the firewall provides some degree of protection. ...of course, just like a condom, the firewall doesn't provide 100% effectiveness in that protection, but it does provide protection.
The second and third claims with their absolute statements are misleading. "Your Web browsing is safe from phishing" and "Your identity and data are safe from theft and loss".
Let's be realistic folks. Nothing is going to make you absolutely safe from these things. No phishing filter, no matter how good it is is going to stop you from going to every phishing site ever conceived. Nothing can provide absolute protection from identity and/or data theft. No matter how many ways they try to protct you, somone will think of a different way to get the info from you.
Since ZA does not provide a backup solution, I can't see how it even attempts to protect you from data loss.
Likewise, CheckPoint (the makers of ZA) isn't in the counselling business, they can't do much about your loss of identity. If you don't know who you are anymore I doubt there is much they can do to help. :)
All that said, I still think ZA is one of the best software firewalls for Windows out there. It is light-years beyond the built-in "firewall"....and it's free!
I like the keypad on the Kindles of the current generation, but the touch would be nice. No mention in this article of whether the Fire uses LCD or the new colour E-ink, but it turns out it is only an IPS LCD panel (IPS is good for LCD, and being a tablet rather than a colour e-book LCD makes sense, but I was hoping to see some colour e-ink this fall.
The good news for consumers is that they're all priced below $200, with the low end, smaller kindle at only $79 USD.
Sadly, no new DX model yet. I like the DX size for reading Adobe PDF formatted e-books (computer manuals, text books, gaming books). Maybe the next DX will be the colour e-ink model???
If you still run Microsoft Vista (what are you crazy? update to Windows 7, it'll be like getting a new computer) and you haven't got SP2 (Service Pack # 2) installed yet, get on it.
MS is not going to offer any more patches to SP1.
If you don't have SP2 installed download it now. You can use automatic update, or you can download it from here and burn it to a CD if you have more than 1 computer that needs it:
http://technet.microsoft.com/en-us/windows/dd262148
Apparently not, there's not a single hacker in the bunch at
http://www.badpeopleproject.org;)
Guess they're not scary enough.
We upgraded the Bad People research project and gallery and now need
your submissions too.
Hand a child paper and pencil to draw you a picture of a bad person.
Don't give hints, suggestions, or influence the child in any way. Ask
the child to explain the picture to you. Scan/photograph that picture
with explanation and e-mail it to the Bad People Project. We don't
need names but we do need regional location, gender, and age. It's
that easy!
All your submissions count and you ISECOM readers are from all around
the world which makes it even better as a cultural study in security.
Thanks in advance for your participation and enjoy the new gallery.
Sincerely,
-pete.
If you have kids in the taget age group help them do this research, have your kids draw what they think a bad person looks like. There are some really reallly bad looking people in the gallery already. (knife and gun toting mummies, etc.) but it's not a contest to see who comes up with the worst bad-guy, they want to see all of the the variety of what kids think real-life bad-guys are like.
I attended SC Congress Canada 2011 on Tuesday and Wednesday this week, and perhaps the most interesting talk I attended was Stonesoft and ICSA's Advanced Evasion Techniques.
Stonesoft discovered that with certain evasion techniques (particularly when combined in particular combinations) they could sneak common exploits past many (including their own, at the time) IDS/IPS systems. They built a tool to repeat these tests on a variety of systems, and proved that with the right know how, and the right tool set (including a custom TCP/IP stack) attackers could sneak past our best defenses. Packet captures were sent to ICSA along with info so they could try to reproduce these results in their own labs. They did!
This is real and they foresee a not -too distant future where things like botnet kits will have this as a checkbox feature.
These evasion techniques are not attacks on their own, but rather a sneaky way to get whatever attack you want to use past the network monitoring and policing systems to the target host.
It's not about the bad-guy asking "How can I hack in?", but "How can I hack in without being seen?"
I used to be dumb enough to give my credit card number to Sony PSN. (No more! From now on I will be using gift cards for online services like that)
I had a MasterCard registered with Sony. I bought some PSN credit in January.
My card changed in Feb. (same card number (PAN), new expiry and CVC numbers)
I had never given Sony my new expiry # so I thought I was OK despite the hacking. After all, when I got the new card the activation instructions said that once you activate the new card, the old one becomes useless and should be destroyed.
I logged into PSN on the weekend to double check what card they had and it was that card.
I started a transaction for $5 worth of credit to see if it would show me for sure the expiry date was the old one... I clicked next and got back a thank you. A minute later an e-mail receipt arrived showing I had just purchased $5 of wallet credit in PSN. WHAT!?!!?
How was Sony able to process a purchase without the new expiry?
I got on the phone with the credit card company and asked them. They told me that because the old card has not yet expired, even though the new one is activated, they still keep the old one active too, and that is why they ask you to cut up the card when you have activated the new one. (funny that's not how they explain the process in the letter that comes with the new card)
So I reported my card lost and had a new one with all new numbers issued.