<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Expanding Security - CISSP &#38; CEH training</title>
	<atom:link href="http://www.expandingsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.expandingsecurity.com</link>
	<description>The best live on line security training for CISSP or CEH</description>
	<lastBuildDate>Fri, 03 Feb 2012 20:50:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PainPi!! 1205 Crypto PKI for mail WHY?</title>
		<link>http://www.expandingsecurity.com/2012/02/painpi-1205-crypto-pki-for-mail-why/</link>
		<comments>http://www.expandingsecurity.com/2012/02/painpi-1205-crypto-pki-for-mail-why/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 22:04:16 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3214</guid>
		<description><![CDATA[This is the Security “Pain Pill” because only a few of us take vitamins. Every week I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If [...]]]></description>
			<content:encoded><![CDATA[<p><strong>This is the Security </strong><strong>“Pain Pill” because only a few of us take vitamins.</strong></p>
<p>Every week I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If you need continuing education credits, this counts. A related reading is posted to expandingsecurity.com</p>
<p>If you would like to learn about PKI in our live class <strong>Friday</strong> February 3, 2012 at 12:30 Central time, wait till class time and type your name <a href="http://bit.ly/painpill1205 ">Here</a></p>
<p>This post with the video is <a href="http://www.expandingsecurity.com/?p=3214">here</a>.<br />
<object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/oeIpGxybNUE&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/oeIpGxybNUE&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object><br />
PKI is often overlooked and underutilized by commercial entities for fear that they might lose. Lose what? When we want to get our message out to you, we don&#8217;t want to take any chance that your systems cannot read or receive our message. So we panic. The standard mantra is: &#8220;rip that security crap out of there so we can tell the world about our new thing.&#8221;</p>
<p>But all that is changing now in many ways. On the client side we have Sender Policy Framework (SPF) and the Microsoft specific version Sender ID framework. On the server side we use Domain Keys Identified Mail (DKIM) or DomainKeys. DomainKeys is being subsumed by DKIM. Only DKIM truly uses PKI. The other way to deal with suspect hosts and $PAM is to write some rules on your mail server configuration that look for use of PKI certificates.</p>
<p>If you want to know technically how to do the server side of DKIM look at the details link below.</p>
<p>So now we have tools that don&#8217;t force users to fight the PKI battle, but still keep the e-mail flowing. Remember the ultimate  goal is to make more security easier to implement, not get in the way of business.</p>
<p><strong>What can we do to make it better for us, for you?</strong></p>
<p><strong>Policy:</strong></p>
<ul>
<li>Verify PKI policy</li>
<li>Restrict inbound mail based upon need</li>
</ul>
<p><strong>Action items:</strong></p>
<ul>
<li>Research DKIM implementations for the server side</li>
<li>Research SPF implementations for the client side</li>
</ul>
<p>So all this makes me want to start sending mail with that PKI to improve my score with $PAM review engines.</p>
<p><strong>Don&#8217;t know how to do these activities? Come to our free class!</strong> CISSP: Crypto PKI &amp; PGP 2012-02-03 12:30:00</p>
<p>http://www.expandingsecurity.com/contact-us/adobe-connect-login?theclassid=3114&amp;company=pp1205&amp;namex=DB&amp;link=http%3A%2F%2Ftraining411.na3.acrobat.com%2Ff_23%2F</p>
<p>Or http://bit.ly/painpill1205</p>
<p>Some technical details you might want:</p>
<p>Miscrosofts version of SPF names Senderid: http://www.microsoft.com/mscorp/safety/technologies/senderid/default.mspx</p>
<p>Thanks diaryofaninja for the how to set up DKIM: http://www.diaryofaninja.com/blog/2011/11/16/when-you-really-need-your-email-delivered-ndash-signing-your-mail-using-domain-keysdkim</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/02/painpi-1205-crypto-pki-for-mail-why/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Painpi!! 1204 Pen Testing Virtual Teams</title>
		<link>http://www.expandingsecurity.com/2012/01/painpi-1204-pen-testing-virtual-teams/</link>
		<comments>http://www.expandingsecurity.com/2012/01/painpi-1204-pen-testing-virtual-teams/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 04:20:10 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3177</guid>
		<description><![CDATA[What is “The Pain Pill” ? I saw about 25 people try to attend class last week, and half made it. If you are trying and not getting in, drop me an email. I think everything is working, but I could be fooling myself. I certainly hope I&#8217;m not fooling or frustrating you. We had [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What is “The Pain Pill” ? </strong></p>
<p>I saw about 25 people try to attend class last week, and half made it. If you are trying and not getting in, drop me an email. I think everything is working, but I could be fooling myself. I certainly hope I&#8217;m not fooling or frustrating you. We had fun. This week Thursday 7-8PM Central we are going to discuss the Pen Testing topic of Scanning Networks. Click this <a href="bit.ly/painpill1204" target="_blank">link</a>, type your name, and you are in!</p>
<p>This post can be found online <a href="http://www.expandingsecurity.com/?p=3177">here</a>.</p>
<p>Once per month this year I am going to talk about a less technical topic and more of a business topic. This time:</p>
<p><strong>How do we manage virtual Pen testing teams?</strong></p>
<p>I would really like a cool office with lots of people jumping on planes flying all over the world like they do in the TV show Leverage, but brick-and-mortar is sooo last century. Further, the cost is crazy unless you are willing to rent a garage next to a drug dealer and take a middle seat with 3 plane changes. I certainly don&#8217;t want to pay the cost of having a team of experts sitting around. You know who pays that cost? The customer. So no one is happy doing this face-to-face.</p>
<p><strong>So let&#8217;s go VIRTUAL!</strong></p>
<p>Have you ever tried to manage a team of experts? Really smart people who get bored? The phrase herding cats (<a href="http://www.youtube.com/watch?v=Pk7yqlTMvp8" target="_blank">the old EDS commercial</a>) pops into my head. I have been doing it for a few years now. I learned a few things that should help you other pen testers. Basics items for everyone to keep in mind:</p>
<ul>
<li>Virtual cats are even more difficult to keep together.</li>
<li>More than 6 time zones are impossible for meetings.</li>
<li>Big meetings are a big mess where nothing gets done.</li>
<li>Never invite a technician to a high-level meeting.</li>
<li>Never invite a manager to a execution meeting.</li>
<li>Even if you like virtual meetings someone else does not.</li>
<li>Project management skills are even more critical.</li>
</ul>
<p><strong>Why should the customer care about my business problem and why should you?</strong></p>
<p>Every meeting is going virtual. You say &#8211; Dean we have been doing this for years. I am on 2-3 hours of concalls and webcasts per day&#8230; Yes, but we are talking about the business of pen testing. We are talking about many people, many IP addresses connecting to your business in an attack-like stance. The customer needs to be ready. The testing team needs to prepare a different way. I see three viewpoints that need to be addressed: the organization, the team tester, and the team leader. Some of what is listed below is common sense to you and I, but people need to hear it anyway.</p>
<p>As the organization who hires testers, these are some things you should think about:</p>
<ul>
<li>Short meetings with narrow scopes.</li>
<li>Prepare for meetings by sending questions in advance.</li>
<li>Require encryption on all work artifacts.</li>
<li>If you have EC2 instances get permission from Amazon early.</li>
<li>Crossing jurisdictional boundaries means contracts will be more strict.</li>
<li>Address third party service providers&#8217; contracts early in the process.</li>
<li>Do small scope tests first to see if the virtual process will work for you.</li>
<li>Connections to your network should be via virtual private network.</li>
</ul>
<p>For the pen testing team member:</p>
<ul>
<li>Get a multi-timezone clock.</li>
<li>The customer&#8217;s time zone is now your time zone.</li>
<li>Specialization is critical in global teams.</li>
<li>If you know a deadline is looming, be early.</li>
<li>Learn the skill-set of the other team members.</li>
<li>Slow down, explain more, delete the jargon.</li>
<li>Collect your data, review it, summarize.</li>
<li>Never argue; you are a unified team of experts.</li>
</ul>
<p>As the pen testing team leader:</p>
<ul>
<li>Let the client, not the team, lead the discussion.</li>
<li>Be ready to reschedule the test or the meeting.</li>
<li>Schedule meetings when the client is ready.</li>
<li>Rehearse your part before the meeting.</li>
<li>Have all your team&#8217;s notes the day before.</li>
<li>Be prepared to speak for your team members.</li>
<li>Let your team speak, you moderate and translate.</li>
<li>Internet connectivity is always in doubt; have a backup, have two.</li>
</ul>
<p>Over the past four years have been in virtual meetings and done virtual testing about 2-4 hours per day every day. For every minute online, I spend 3-5 preparing and planning. The reward has been that when things go wrong, I am not phased.  Oh and have fun with what you do. A joke or two goes a long way. To those who have been part of my virtual teams in the past I hope you remember the Olympics of 2008 and the special events at the end.</p>
<p><strong>What can we do to make it better for us, for you?</strong></p>
<ul>
<li>Think about how your teams work.</li>
<li>Think about how you can make them better at virtual meetings.</li>
</ul>
<p><strong> </strong></p>
<p><strong>Come to our free class!</strong> Thursday 7-8 PM Central - CEH: 03 Scanning Networks 2012-01-26 19:00:00</p>
<p>http://www.expandingsecurity.com/contact-us/adobe-connect-login?theclassid=4192&amp;company=ExpSec&amp;namex=pp1204&amp;link=http%3A%2F%2Ftraining411.adobeconnect.com%2Fceh03%2F</p>
<p>Or <a href="http://bit.ly/painpill1204">bit.ly/painpill1204</a></p>
<p>Details-</p>
<p><a href="https://community.rapid7.com/community/solutions/metasploit/blog/tags/ec2">Metasploit &#8211; EC2 Instance</a></p>
<p><a href="https://community.rapid7.com/community/solutions/metasploit/blog/tags/ec2"></a>If you don&#8217;t think HD virtual meetings are big look at Cisco/Webex, Citrix/Goto, Adobe/Connect, and Microsoft/Skype. Oh and don&#8217;t forget Logitech/Lifesize.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/painpi-1204-pen-testing-virtual-teams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MP Syllabus Law</title>
		<link>http://www.expandingsecurity.com/2012/01/mp-syllabus-law/</link>
		<comments>http://www.expandingsecurity.com/2012/01/mp-syllabus-law/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 00:24:00 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=2973</guid>
		<description><![CDATA[Please note: You will not be able to get files from the  server unless you are a paid student. The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through. Start of [...]]]></description>
			<content:encoded><![CDATA[<p>Please note: You will not be able to get files from the  server unless you are a paid student.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<h2><strong>Start of each week, Start of each domain process</strong></h2>
<p><strong>01: Prepare &#8211; Download</strong></p>
<p>Download all the meeting files below to your local drive and then copy to a USB drive.  You will open a new tab or window in your browser, authenticate, and then choose download. To make it easier, leave the authenticated window open until you download all files.</p>
<p>Download <a href="http://www.expandingsecurity.com/wp-content/uploads/2011/12/ISSMPStudentExcelTrackingSheet.xlsx" target="_blank">Excel tracking sheet</a> same each week</p>
<p>Download these weekly, per domain to a portable drive; print only when absolutely necessary.</p>
<ul>
<li>Cases Combined &#8211; <a href="http://training411.adobeconnect.com/cases_issmp_law_20120121/" target="_blank">M39<span style="color: #ff0000;"><span style="color: #000000;">-M40</span></span></a></li>
<li>Glossary &#8211; <a href="http://training411.adobeconnect.com/glossary_issmp_law_20120120/" target="_blank">Law</a></li>
<li>Readings -</li>
</ul>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_issmp_law_m39_com_p72/" target="_blank">M39-p71</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_issmp_law_m40_com_p55/" target="_blank">M40-p55</a></p>
<p style="padding-left: 60px;">M41 only ISC2 ethics on their site</p>
<p><strong>02: Print at the beginning of the week and add to binder. </strong></p>
<ul>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a> (once at beginning of the course)</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Template Case worksheet</a> (five  per week) or 44 total copies for class</li>
</ul>
<p><strong>03: Before any reading - Build Flash Cards from domain glossary download above</strong></p>
<ul>
<li>You will need 50 lined note cards per week. A pack of 300 for the whole course.</li>
<li>Get terms and definitions from 01 glossary download above.</li>
<li>Hand written: blank side has the term, lined side has the definition.</li>
<li>Write term big so you can see without your glasses</li>
<li>If you are weak in concepts or process: build extra flash cards from readings bold headings =  term</li>
</ul>
<p><strong>04: Least Crappy Answer review</strong></p>
<ul>
<li>2-4 times over the 10 weeks review our <a href="https://training411.adobeconnect.com/_a748905193/p54219551/" target="_blank">exam taking tips recording</a>.</li>
</ul>
<h2>Daily process: Before class. Repeat for each section of the domain.</h2>
<p><strong>05: Readings from 01 downloads section above</strong></p>
<p>Know how fast you read and how well you comprehend. Input these results on your Excel tracking sheet for your instructor (<a href="http://www.readingsoft.com" target="_blank">test is here</a>) These reading assignments are on a meeting by meeting basis.These can be as short as 20 pages and as long as 120. Please review the page counts and your reading speed to plan your readings before class. Try to read as much on your computer as possible to increase your portability. Reading 30-60 pages in pdf format is not optimal, but as a CISSP you must learn to do a great deal of reading on the computer. Sifting is a way of life.</p>
<p><strong>06: Practice your note cards</strong></p>
<ul>
<li>Carry your cards with you for that 5 minutes of study opportunity</li>
<li>Get a partner to quiz you on the cards</li>
<li>20 seconds each</li>
<li>Make one pile for Yes and No</li>
<li>As you get a pile of Yes&#8217;s, move them to the big stack stored at home</li>
<li>Keep working the No&#8217;s until they are gone</li>
</ul>
<p><strong>07: Do case study</strong></p>
<ul>
<li>Use the combined cases from downloads section 01</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a></li>
<li>Use the <a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Case worksheet</a> to write out your notes and thoughts on the business problem and solution</li>
<li>Use your computer&#8217;s notepad or text editor to rewrite your problem and solution</li>
<li>At class time, you will copy and paste to the chat for the case</li>
<li>If you feel like you want more help on cases, email your notes to the instructor for input</li>
</ul>
<h2>Daily Process: At class time</h2>
<p><strong>08: Prepare notepad/text editor for Case notes from 06</strong></p>
<ul>
<li>Copy and paste separately: problem and solution when directed by instructor</li>
<li>Don&#8217;t do both at same time because we want to see what everyone says</li>
</ul>
<h2>Daily Process: After class</h2>
<p><strong>09: Write last flash card definitions from class</strong></p>
<ul>
<li>Carry over all No&#8217;s to next week</li>
</ul>
<p><strong>LET IT GO! MOVE ON! DO NOT DOUBLE UP.</strong></p>
<h2>If you miss class</h2>
<p><strong>10: Recording Links: for your review of class presentations. </strong></p>
<p>These are updated no later than one week after the new class has recorded.</p>
<p>You can get your quiz  in the recording, by pausing the recording and clicking through your quiz. See the orientation for more details. These will be post at the end of the week.</p>
<p><a href="http://training411.adobeconnect.com/p4ryhd64ccx/" target="_blank">MP 40 Class Recording</a></p>
<p><a href="http://training411.adobeconnect.com/p79mzz0xj85/" target="_blank">MP 41 Class Recording</a></p>
<h2>End of week</h2>
<p><strong>11: Submit your completed Excel tracking sheet</strong></p>
<ul>
<li>Your goal is to pass the exam on your first attempt</li>
<li>We can find trends and problems before they become a failure</li>
<li>If you are not ready for your exam we can help</li>
<li>If you are not sure what to do, your instructor will use this data to make decisions</li>
<li>We realize you have a life, a job, and a family and you need to get it all done</li>
<li>Sometimes class and the exam are not a priority</li>
<li>We still need the true data to make good decisions</li>
</ul>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security.  You are not permitted to copy and distribute these materials in any way.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/mp-syllabus-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP Customers</title>
		<link>http://www.expandingsecurity.com/2012/01/hp-customers/</link>
		<comments>http://www.expandingsecurity.com/2012/01/hp-customers/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 20:56:08 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3090</guid>
		<description><![CDATA[HP CSG Team Members:  Welcome!  Thank you for choosing Expanding Security for your certification training.  We will do our utmost for your success. 2012 HP Training Agreement:  Please read this page before making your certification training selection. We are very happy to support the C.S.G. team at HP.  After you enroll, you will receive an [...]]]></description>
			<content:encoded><![CDATA[<p><strong>HP CSG Team Members:  Welcome!  Thank you for choosing Expanding Security for your certification training.  We will do our utmost for your success.</strong></p>
<p><strong>2012 HP Training Agreement:  Please read this page before making your certification training selection.</strong></p>
<p>We are very happy to support the C.S.G. team at HP.  After you enroll, you will receive an account login for Adobe Connect and class information.  Orientations are held every two weeks.</p>
<p>Your HP certification training agreement comes with exam costs included- You must buy from the links below in order for us to process your enrollment correctly.</p>
<p><strong>You must use your valid HP email address ending in @hp.com.  Also, please use your HP code to receive the HP price with exam fees included.</strong></p>
<p>When asked for payment arrangements, our main site and payment gateway accepts Visa, Master card and Amex. There are no other fees.</p>
<p>Our regular training posted elsewhere doesn&#8217;t include extra exam fees.</p>
<p>Your training options are:</p>
<p><a href="https://www.expandingsecurity.com/bu/hpcertifiedethicalhacker/" target="_blank">Click here for CEH</a> &#8211; Certified Ethical Hacker &#8211; 10 week course meets live online Tuesdays and Thursdays 7pm Central for one-hour.  Class Recordings are always available if you miss class.</p>
<p><a href="https://www.expandingsecurity.com/bu/hpcissp/" target="_blank">Click here for CISSP </a>- Certified Information Systems Security Professional &#8211; 10 week course meets live online, 3 to 5 times per week, depending on the Domain.  Tuesday and Thursday classes are 6 &#8211; 7pm Central [CST/CDT]; Wednesday, Friday, and sometimes Saturday classes are 12:30 &#8211; 1:30pm Central [CST/CDT]. Class Recordings are always available if you miss class.</p>
<p><a href="https://www.expandingsecurity.com/bu/hpcombocehcissp/" target="_blank">Click here for CEH &amp; CISSP</a> &#8211; Combination each class can be started when you are ready, you do not need to take them back-to-back.  Orientations are held every two weeks.</p>
<p>In order to take advantage of the offer, you  must be an active HP employee and use the reference discount code starting with &#8220;DV&#8221;</p>
<p>If you are not an HP customer, you can not receive these pricing options.</p>
<p>If you have any questions about the training Dean Bushmiller is your point of contact.</p>
<ul>
<li>dean(D0T)bushmiller@ExpandingSecurity.com</li>
<li>347-927-9786</li>
</ul>
<p>If you have any payment questions Helaine Thornton is your point of contact.</p>
<ul>
<li>Helaine(d0T)Thornton@ExpandingSecurity.com</li>
<li>619-327-9786</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/hp-customers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Painpi!! 1203 Business Impact Assessment why not Risk Assessment</title>
		<link>http://www.expandingsecurity.com/2012/01/painpi-1203-business-impact-assessment-why-not-risk-assessment/</link>
		<comments>http://www.expandingsecurity.com/2012/01/painpi-1203-business-impact-assessment-why-not-risk-assessment/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 03:59:02 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3075</guid>
		<description><![CDATA[What is “The Pain Pill” ? Every week I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. Come to class Wednesday at 12:30 Central time. Click this [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What is “The Pain Pill” ? </strong></p>
<p>Every week I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. Come to class Wednesday at 12:30 Central time. Click this <a href="http://bit.ly/painpill1203">link</a></p>
<p>Type your name and Turn up your speakers.</p>
<p>If you need continuing education credits, this counts.</p>
<p>This is your last chance to get the ethical hacker class in January. Pen testing is fun; where else can you get paid to attack other people&#8217;s networks?</p>
<p>This post  and video are located <a href="http://www.expandingsecurity.com/?p=3075">here</a>.<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/LnX2Qw5zuAw&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/LnX2Qw5zuAw&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p><strong>Business Impact Assessment (BIA) as a part of continuity planning is very different than Risk Assessment (RA).</strong></p>
<p>I get a lot of people who start learning BIA and make the mistake of thinking that it is the same thing as Risk Assessment.  They look the same, but they have a very different goal and you must adopt a very different attitude when developing each.</p>
<p>BIA has a time element and is focused around a service or process.</p>
<ul>
<li>How long could we be without that mail server?</li>
<li>What resiliency or fault-tolerance do we have?</li>
<li>Availability</li>
</ul>
<p>RA assumes no time and focus is set by the scope of asset(s).</p>
<ul>
<li>What are the chances of something bad happening to this asset?</li>
<li>With what controls will we secure this?</li>
<li>Integrity or Confidentiality</li>
</ul>
<p>Both address:</p>
<ul>
<li>What is the value of the asset or service to us?</li>
<li>How do we protect it?</li>
</ul>
<p><strong>Where is the problem?</strong></p>
<p>In large organizations we seek out ways to reduce cost by consolidation of process. What happens is:  Process optimization people looks at this from an enterprise architecture view and see a great deal of the same data is being collected by two different groups. This begs the question: Why not consolidate these into one data collection process?</p>
<p>In most cases you would be correct. In this case, you lose.</p>
<p>By only looking at a business process from a support of availability or fault tolerance view, we might use an old system to keep the business running. When would a controls person ever think about using the old firewall when the new one protects us against the current threat? Never? In this case we are framing the problem as a purely availability problem.  When you focus on availability with a goal of limping along until the optimized process is recovered, the business wins.</p>
<p><strong>What about the other way? </strong></p>
<p>Let&#8217;s throw that RA out the door and do BIA with a little added security? No, because now you have stopped looking at the evil, the adversarial issues, and the new vectors of attack. You&#8217;ve lost your edge in areas like: defense-in-depth.</p>
<p><strong>What can we do to make it better for us, for you?</strong></p>
<p><strong>Keep them both and let them feed each other!</strong></p>
<p><strong>Policy:</strong></p>
<ul>
<li>Require all BIA data to be communicated to the RA team</li>
<li>Communicate in terms of Availability, Integrity and Confidentiality</li>
</ul>
<p><strong>Action items:</strong></p>
<ul>
<li>Reset your BIA and RA to be at opposite ends of a time cycle</li>
<li>Validate the focus of BIA is Availability</li>
<li>Validate the focus of RA is Integrity and Confidentiality</li>
</ul>
<p><strong>Don&#8217;t know how to do these activities? Come to our free class!</strong></p>
<p>CISSP: Bus. Continuity Planning Understanding Organization 2012-01-18 CENTRAL 12:30:00</p>
<p>Click <a href="http://www.expandingsecurity.com/contact-us/adobe-connect-login?theclassid=3100&amp;company=ES&amp;namex=pp1203&amp;link=http%3A%2F%2Ftraining411.na3.acrobat.com%2Ff_35%2F">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/painpi-1203-business-impact-assessment-why-not-risk-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Connect troubleshooting</title>
		<link>http://www.expandingsecurity.com/2012/01/adobe-connect-troubleshooting/</link>
		<comments>http://www.expandingsecurity.com/2012/01/adobe-connect-troubleshooting/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 22:56:04 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3070</guid>
		<description><![CDATA[If you are having serious problems here are some steps that we think will solve your problem. Adobe connect is very stable. The way the server works when dealing with upgrades is assuming the worst about the client environment.  Every time the server is upgraded, the default behavior is to require a new install of [...]]]></description>
			<content:encoded><![CDATA[<p>If you are having serious problems here are some steps that we think will solve your problem.</p>
<p>Adobe connect is very stable. The way the server works when dealing with upgrades is assuming the worst about the client environment.  Every time the server is upgraded, the default behavior is to require a new install of the add-in for each client. Depending on your client  O.S. and the security configurations, this could problematic.</p>
<p>The theory is default behavior overwrite will work. It may or may not cleanly install or overwrite the previous installation.</p>
<p>So you need to track down the data and check for yourself:</p>
<p>when you are in the classroom  identify your current install in adobe room</p>
<ul>
<li>Top Left side Help |about adobe connect</li>
</ul>
<p>Note your client environment:</p>
<ul>
<li> O.S. and service pack.</li>
<li>Browser and version</li>
<li>Flash Version</li>
</ul>
<p>1. Test to see if you have an existing install</p>
<p>For windows</p>
<ul>
<li>Add and remove software</li>
<li>Then remove the old folders</li>
<li>Application data is a hidden folder- you might need to show</li>
<li>In Windows XP: Delete the bin folder &#8216;C:\Documents and Settings\&lt;&lt;USER&gt;&gt;\Application Data\Macromedia\Flash Player\www.macromedia.com&#8217;</li>
<li>In Windows Vista/7:  Delete the bin folder C:\User\&lt;&lt;USER NAME&gt;&gt;\App Data\Roaming\Macromedia\Flash Player\www.macromedia.com&#8217;</li>
</ul>
<p>For Mac</p>
<ul>
<li>Drag and Drop  Adobe Connect Add in from applications folder  to trash</li>
<li>Remove bin folder from User/Library/Preferences/Macromedia/Flash Player/www.macromedia.com</li>
</ul>
<p>This is the most current install for each O.S.</p>
<ul>
<li><a href="http://www.connectusers.com/downloads/">http://www.connectusers.com/downloads/</a></li>
</ul>
<p>If you are still having problems adobeconnect will support you</p>
<ul>
<li> 800-422-3623</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/adobe-connect-troubleshooting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Painpi!! 1202 Database Security</title>
		<link>http://www.expandingsecurity.com/2012/01/painpi-1202-database-security/</link>
		<comments>http://www.expandingsecurity.com/2012/01/painpi-1202-database-security/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 23:39:41 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=3020</guid>
		<description><![CDATA[What is “The Pain Pill” ? Every Tuesday I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If you need continuing education credits, this counts. CEH [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What is “The Pain Pill” ? </strong></p>
<p>Every Tuesday I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If you need continuing education credits, this counts.</p>
<p>CEH class starts January 21st! If you know someone, we are at least going to get certified, we will have fun, and we will definitely learn something about ethical hacking and penetration testing.</p>
<p>This post  is located <a href="http://www.expandingsecurity.com/?p=3020" target="_blank">here</a>.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/JtneqJDYEgY&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/JtneqJDYEgY&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p>I know the world runs on databases, but I wish they all would get along, interoperate, or allow migration from one to another without an act of congress or a connector that blows my programming budget for the whole year. While I am wishing, let&#8217;s go for the whole enchilada: I wish security were not so squishy. What I mean is the claim that: if the operating system is secure, then the database is secure. With all the  the other tools that we use, we require that the tool stand on its own and not be dependent on the security of something else. Some database tools like encryption are a good idea in spirit, but as soon as availability goes down, management screams and the encryption is out the window.</p>
<p>How you deal with protection. Let&#8217;s limit our discussion:</p>
<p>The scope of database security:</p>
<ul>
<li>Authentication &#8211; yes or no you have an account</li>
<li>Authorization &#8211; Permissions by role</li>
<li>Auditing &#8211; Transaction details</li>
</ul>
<p>Threats that are difficult to address:</p>
<ul>
<li>Inference &#8211; a guess</li>
<li>Aggregation &#8211; combining two data points</li>
</ul>
<p>Now if you cannot stay away from vendor specific options I understand, but try. Here are my suggestions until we come up with something better.</p>
<p><strong>What can we do to make it better for us, for you?</strong></p>
<p><strong>Policy:</strong></p>
<ul>
<li>Set expectations that databases are an integrity and availability tool, not a confidentiality tool</li>
<li>Build roles examination into early phases of SDLC projects.</li>
</ul>
<p><strong>Action items:</strong></p>
<ul>
<li>Research Tokenization</li>
<li>Segregate data when you are dealing with internet facing databases</li>
</ul>
<p><strong>Don&#8217;t know how to do these activities? Come to our free class!</strong> Tonight!</p>
<p>CISSP: Application Security Databases</p>
<p>2012-01-10 18:00:00 Central</p>
<p>http://www.expandingsecurity.com/contact-us/adobe-connect-login?theclassid=3093&amp;company=expsec&amp;namex=drb1202&amp;link=http%3A%2F%2Ftraining411.na3.acrobat.com%2Ff_15%2F</p>
<p>Or http://bit.ly/painpill1202</p>
<p>FROM DON MURDOCH</p>
<p>Modern databases can do more than just manipulate data in tables. In particular, they can run stored procedures which interact with the operating system by running operating system commands, or running object code that can do a myriad of tasks.</p>
<p>In order to accommodate these features, many organizations run database under a specific account.  And herein lays a hidden weakness which can be very, very difficult to detect. If an organization runs all of its database servers under the same account &#8211; say &#8220;DBServ&#8221; &#8211; then anyone with the account credentials can login to one database server, use those credentials to connect to a second server, install code or a stored procedure which can then go out and perform a malicious act. Even if the organization runs each database server with its own specific account, there is still a potential avenue of exploitation &#8211; a privileged entity that has access to multiple accounts can login to one database server with one account, connect to a second server with its specific account, and execute the same exploit.</p>
<p>What can we do to make it better for us, for you?</p>
<ul>
<li>Segregation &#8211; organize databases and their respective DBA users very carefully.</li>
<li>Control accounts &#8211; segregate password management. Have someone other than the DBA assign the service account startup account properties.</li>
<li>Set expectations &#8211; as we said previously …</li>
<li>Logon trigger &#8211; Most modern DBMS systems can be setup so that a logon trigger fires whenever a logon occurs which records the source IP, application, and other details which can help respond.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/painpi-1202-database-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MP Syllabus BCP</title>
		<link>http://www.expandingsecurity.com/2012/01/mp-syllabus-bcp/</link>
		<comments>http://www.expandingsecurity.com/2012/01/mp-syllabus-bcp/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 17:13:55 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=2972</guid>
		<description><![CDATA[Please note: You will not be able to get files from the  server unless you are a paid student. The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through. PREREQUISITE FOR [...]]]></description>
			<content:encoded><![CDATA[<p>Please note: You will not be able to get files from the  server unless you are a paid student.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>PREREQUISITE FOR THIS DOMAIN: REVIEW ALL BCP CISSP CLASS RECORDINGS:</p>
<p><a href="http://training411.adobeconnect.com/p6hzm8ixlji/" target="_blank">F34 Recording</a> CISSP</p>
<p><a href="http://training411.adobeconnect.com/p8081h62dor/" target="_blank">F35 Recording</a> CISSP</p>
<p><a href="http://training411.adobeconnect.com/p4eua0j3efn/" target="_blank">F36 Recording</a> CISSP</p>
<p><a href="http://training411.adobeconnect.com/p8jd3yn72b0/" target="_blank">F37 Recording</a> CISSP</p>
<p><a href="http://training411.adobeconnect.com/p79my6l2vhr/" target="_blank">F38 Recording</a> CISSP</p>
<p><a href="http://training411.adobeconnect.com/p61om6b3z2d/" target="_blank">MOL BCP</a> CISSP</p>
<h2><strong>Start of each week, Start of each domain process</strong></h2>
<p><strong>01: Prepare &#8211; Download</strong></p>
<p>Download all the meeting files below to your local drive and then copy to a USB drive.  You will open a new tab or window in your browser, authenticate, and then choose download. To make it easier, leave the authenticated window open until you download all files.</p>
<p>Download <a href="http://www.expandingsecurity.com/wp-content/uploads/2011/12/ISSMPStudentExcelTrackingSheet.xlsx" target="_blank">Excel tracking sheet</a> same each week</p>
<p>Download these weekly, per domain to a portable drive; print only when absolutely necessary.</p>
<ul>
<li>Cases Combined &#8211; <a href="http://training411.adobeconnect.com/cases_issmp_bcp_20120108/"><span style="color: #3366ff;">M34-M38</span></a></li>
<li>Glossary &#8211; BCP Use Regular size <a href="http://training411.adobeconnect.com/glossary_issmp_bcp_reg_20120108/">(here)</a>, if you cannot find it and you need more use the BIG <a href="http://training411.adobeconnect.com/glossary_issmp_bcp_big_20120108/">(here)</a></li>
<li>Readings -</li>
</ul>
<p style="padding-left: 60px;">Memorize  <a href="http://training411.adobeconnect.com/bcp_sr01/" target="_blank">DRII 7 steps</a> <a href="http://training411.adobeconnect.com/bcp_sr02/" target="_blank">BCI primer</a></p>
<p style="padding-left: 60px;">These are all combined readings below</p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_m34_combined_p55/">M34 p55</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_m35_combined_p47/">M35 p47</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_m36_combined_p34/">M36 p34</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_m37_combined_p38/">M37 p38</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_m38_combined_p71/">M38 p71</a></p>
<p style="padding-left: 60px;"><a href="http://training411.adobeconnect.com/readings_bcp_all_extra_sp80043_p149/">Extras SP800-34 p149</a> <a href="http://training411.adobeconnect.com/readings_bcp_all_extra_poa_p36/">Disaster recovery p36</a></p>
<p><strong>02: Print at the beginning of the week and add to binder. </strong></p>
<ul>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a> (once at beginning of the course)</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Template Case worksheet</a> (five  per week) or 44 total copies for class</li>
</ul>
<p><strong>03: Before any reading - Build Flash Cards from domain glossary download above</strong></p>
<ul>
<li>You will need 50 lined note cards per week. A pack of 300 for the whole course.</li>
<li>Get terms and definitions from 01 glossary download above.</li>
<li>Hand written: blank side has the term, lined side has the definition.</li>
<li>Write term big so you can see without your glasses</li>
<li>If you are weak in concepts or process: build extra flash cards from readings bold headings =  term</li>
</ul>
<p><strong>04: Least Crappy Answer review</strong></p>
<ul>
<li>2-4 times over the 10 weeks review our <a href="https://training411.adobeconnect.com/_a748905193/p54219551/" target="_blank">exam taking tips recording</a>.</li>
</ul>
<h2>Daily process: Before class. Repeat for each section of the domain.</h2>
<p><strong>05: Readings from 01 downloads section above</strong></p>
<p>Know how fast you read and how well you comprehend. Input these results on your Excel tracking sheet for your instructor (<a href="http://www.readingsoft.com" target="_blank">test is here</a>) These reading assignments are on a meeting by meeting basis.These can be as short as 20 pages and as long as 120. Please review the page counts and your reading speed to plan your readings before class. Try to read as much on your computer as possible to increase your portability. Reading 30-60 pages in pdf format is not optimal, but as a CISSP you must learn to do a great deal of reading on the computer. Sifting is a way of life.</p>
<p><strong>06: Practice your note cards</strong></p>
<ul>
<li>Carry your cards with you for that 5 minutes of study opportunity</li>
<li>Get a partner to quiz you on the cards</li>
<li>20 seconds each</li>
<li>Make one pile for Yes and No</li>
<li>As you get a pile of Yes&#8217;s, move them to the big stack stored at home</li>
<li>Keep working the No&#8217;s until they are gone</li>
</ul>
<p><strong>07: Do case study</strong></p>
<ul>
<li>Use the combined cases from downloads section 01</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a></li>
<li>Use the <a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Case worksheet</a> to write out your notes and thoughts on the business problem and solution</li>
<li>Use your computer&#8217;s notepad or text editor to rewrite your problem and solution</li>
<li>At class time, you will copy and paste to the chat for the case</li>
<li>If you feel like you want more help on cases, email your notes to the instructor for input</li>
</ul>
<h2>Daily Process: At class time</h2>
<p><strong>08: Prepare notepad/text editor for Case notes from 06</strong></p>
<ul>
<li>Copy and paste separately: problem and solution when directed by instructor</li>
<li>Don&#8217;t do both at same time because we want to see what everyone says</li>
</ul>
<h2>Daily Process: After class</h2>
<p><strong>09: Write last flash card definitions from class</strong></p>
<ul>
<li>Carry over all No&#8217;s to next week</li>
</ul>
<p><strong>LET IT GO! MOVE ON! DO NOT DOUBLE UP.</strong></p>
<h2>If you miss class</h2>
<p><strong>10: Recording Links: for your review of class presentations. </strong></p>
<p>These are updated no later than one week after the new class has recorded.</p>
<p>You can get your quiz  in the recording, by pausing the recording and clicking through your quiz. See the orientation for more details. These will be post at the end of the week.</p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p3xtstnytce/" target="_blank">MP 34 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p3i8bi7od69/" target="_blank">MP 35 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p47r3v0fkr4/" target="_blank">MP 36 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p47r3v0fkr4/" target="_blank">MP 37 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p5ldmzuhtql/" target="_blank">MP 38 Class Recording</a></span></p>
<h2>End of week</h2>
<p><strong>11: Submit your completed Excel tracking sheet</strong></p>
<ul>
<li>Your goal is to pass the exam on your first attempt</li>
<li>We can find trends and problems before they become a failure</li>
<li>If you are not ready for your exam we can help</li>
<li>If you are not sure what to do, your instructor will use this data to make decisions</li>
<li>We realize you have a life, a job, and a family and you need to get it all done</li>
<li>Sometimes class and the exam are not a priority</li>
<li>We still need the true data to make good decisions</li>
</ul>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security.  You are not permitted to copy and distribute these materials in any way.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/mp-syllabus-bcp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PainPi!! 2012 #1 Securing the report of a Pen Test</title>
		<link>http://www.expandingsecurity.com/2012/01/painpi-2012-1-securing-the-report-of-a-pen-test/</link>
		<comments>http://www.expandingsecurity.com/2012/01/painpi-2012-1-securing-the-report-of-a-pen-test/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 04:01:54 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=2991</guid>
		<description><![CDATA[What is “The Pain Pill” ? Every Tuesday I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If you need continuing education credits, this counts. A [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What is “The Pain Pill” ? </strong></p>
<p>Every Tuesday I talk about a security topic in simple terms to reduce our security load, increase our efficiency, and make our security work better. There is a free class on the topic so you can have a deep dive. If you need continuing education credits, this counts. A related reading is posted to expandingsecurity.com</p>
<p>Commercial-</p>
<ul>
<li>We have online classes come see if you like it. (see  below)</li>
<li>CISSP starts Jan 14- Pass or we pay guarantee.</li>
<li>CEH starts Jan 21</li>
</ul>
<p>This post  is located <a href="http://www.expandingsecurity.com/?p=2991" target="_blank">here</a>. Video is located <a href="http://www.youtube.com/watch#!v=IYltty81UzM" target="_blank">here</a>.<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/IYltty81UzM&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/IYltty81UzM&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object><br />
In the penetration test that I perform, the first thing I ask for is the last report; the outcome of the last penetration test. You would be surprised at the number of emails forwarded with the original report in plain text. Yes, the original email from the last testing team. Think about it. This is a list of everything that is or was wrong with the environment. Details such as servers, IP addresses, software versions, and screen captures are commonly communicated in plain sight.</p>
<p>Some would say there are many things wrong with the request. Some would say my request should be refused. They are all missing the point. Some penetration tester thought it would be easy or convenient for the client to have the details of their flaws forever floating around in the clear.  Where is this data? In email backup tapes or server snapshots, or local workstation .pst files copied to some cloud storage drive totally out of control and unprotected.</p>
<p><strong> So how do we as penetration testers protect the client from themselves?</strong></p>
<p>A few rules:</p>
<ol>
<li>Encryption for all things not public</li>
<li>Abstraction of details when possible</li>
<li>Small chunks of sensitive details</li>
</ol>
<p><strong> 1. Encryption for all things not public</strong></p>
<p>Last week I walked into a meeting and the first thing we did was pick a password. There were four of us in that meeting. I took a little bit from each person and made a password that we all could remember, and then I added my own complexity. We agreed at that moment not to transmit that password ever in any digital communications. If any of us were to break that rule, a new password would be generated immediately. We agreed that any data that was not public would be encrypted with this password and we would use the heaviest encryption possible. For encryption tools: I suggest some tool that is cross-platform capable and easily available to all, like truecrypt.</p>
<p>So let us go back to the example from above. Yes the report could be floating around in cyberspace, in back up tapes, in archives of your .pst file, but now unless you have the password and the encryption algorithm, you would be hard pressed to decrypt the sensitive data.  This is not enough…</p>
<p><strong> 2. Abstraction of details when possible</strong></p>
<p>You can easily communicate what the weakness is and how to fix it without exposing your client directly.</p>
<p style="text-align: center;"><em><strong> A bad report example</strong></em></p>
<p>For the domain, ‘myclient.online.com’ the below listed IPs were scanned. The listed ports appear to be open on the server.</p>
<ul>
<li>Domain: myclient.online.com</li>
<li>IP Address: 1.0.1.256</li>
<li>Port No: 25 80 143 443</li>
</ul>
<p>Apache Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate input to the /server/ mappings. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user&#8217;s browser within the trust relationship between the browser and the server, leading to a loss of integrity.</p>
<p style="text-align: center;"><strong><em>The same data with abstraction</em></strong></p>
<p>The main server described in the scope of the test was found to have three critical services running when only one was described as reasonable for that type of server.  The main service has a flaw that is considered extreme with a CVSSv2 Base Score between 7 and 8. For details please see item number 2011.12.30.123.a</p>
<p>Notice we did not need to give the IP address or the exact flaw to communicate how important this problem is to fix. People within the organization would know exactly what server we are talking about and with a score stated between two numbers we would not allow someone to do research to find the exact flaw from the CVSS or osbdb.org database. Lastly, we pointed the reader to exact details and an identifying number if they really needed to know more.</p>
<p><strong> 3. Small chunks of sensitive details.</strong></p>
<p>I was given a past report from a client of mine that made a THUD when it hit the desk. Some would say this is impressive. I say taking a data dump on the client’s desk shows you only know how to kill trees, not how much you know about their business. Do we really need that much data <strong>AND</strong> all at once? No one is going to actually act on these items as if it were checklist. They are going to divide this up and give it to the people who need to patch, or to other people who are going to change the authentication, or to others that will address something else.</p>
<p>I suggest you do the work for the client if you can.  This entails identifying who will be taking what actions, cutting the report into smaller pieces, and distributing these smaller reports. This will limit the exposure of the infrastructure to those smaller chunks. These chunks should be encrypted, but you knew that from rule number 1.</p>
<p><strong>Summary</strong></p>
<p>Following these rules is a question of methodical planning and a good understanding of the client’s environment. You may not have visibility into the business process when you do your black-box test. You may not be given a tight scope. Your report may be four pages long and it might not be worth it to abstract the details. I doubt it.</p>
<p>I am betting your client will know you mean business about security when you take the time to protect report data from situations that arise long after you are gone. It is more likely that the client will hire you again if you secure the report.</p>
<p><strong>What can we do to make it better for us, for you?</strong></p>
<p><strong>Policy:</strong></p>
<ul>
<li>Email content scanning policy for pen testing</li>
<li>Define pen test report as highest label possible</li>
</ul>
<p><strong>Action items:</strong></p>
<ul>
<li>Tag sensitive inbound reports</li>
<li>Remove attachments</li>
<li>Search for key words relating to test, audit, vulnerability</li>
</ul>
<p><strong>Don&#8217;t know how to do these activities? Come to our free class!</strong></p>
<p><strong>CISSP: Operations Security IDS &amp; IPS<br />
2012-01-06<br />
12:30:00 Central time</strong></p>
<p><strong><span style="font-weight: normal;">Click <a href="http://www.expandingsecurity.com/contact-us/adobe-connect-login?theclassid=3091&amp;company=pp1201&amp;namex=DRB&amp;link=http%3A%2F%2Ftraining411.na3.acrobat.com%2Ff_33%2F" target="_blank">here</a> 5 minutes before class</span></strong></p>
<p>Or bit.ly/painpill1201</p>
<p>Details-</p>
<p>Content filtering via email- <a href="http://www.scmagazine.com/email-content-filtering-2007/grouptest/47/" target="_blank">product review</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/painpi-2012-1-securing-the-report-of-a-pen-test/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MP Syllabus Sys Dev</title>
		<link>http://www.expandingsecurity.com/2012/01/mp-syllabus-sys-dev/</link>
		<comments>http://www.expandingsecurity.com/2012/01/mp-syllabus-sys-dev/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 01:55:14 +0000</pubDate>
		<dc:creator>Dean Bushmiller</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=2970</guid>
		<description><![CDATA[Please note: You will not be able to get files from the  server unless you are a paid student. The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through. Start of [...]]]></description>
			<content:encoded><![CDATA[<p>Please note: You will not be able to get files from the  server unless you are a paid student.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<h2><strong>Start of each week, Start of each domain process</strong></h2>
<p><strong>01: Prepare &#8211; Download</strong></p>
<p>Download all the meeting files below to your local drive and then copy to a USB drive.  You will open a new tab or window in your browser, authenticate, and then choose download. To make it easier, leave the authenticated window open until you download all files.</p>
<p>Download <a href="http://www.expandingsecurity.com/wp-content/uploads/2011/12/ISSMPStudentExcelTrackingSheet.xlsx" target="_blank">Excel tracking sheet</a> same each week</p>
<p>Download these weekly, per domain to a portable drive; print only when absolutely necessary.</p>
<ul>
<li>Cases Combined &#8211; <a href="http://training411.adobeconnect.com/cases_sds_20120101/" target="_blank">M15</a><span style="color: #ff0000;"><span style="color: #000000;"><a href="http://training411.adobeconnect.com/cases_sds_20120101/" target="_blank">-M18</a></span></span></li>
<li>Glossary &#8211; <a href="http://training411.adobeconnect.com/glossary_sds_20120101/">SDLC</a></li>
<li>Readings &#8211; please note readings are long this week</li>
</ul>
<p style="padding-left: 60px;">M15 <a href="http://training411.adobeconnect.com/readings_sd_m15_combined_p54/" target="_blank">Readings_SD_M15_Combined_p54</a></p>
<p style="padding-left: 60px;">M16 <a href="http://training411.adobeconnect.com/readings_sd_m16_combined_p101/" target="_blank">Readings_SD_M16_Combined_p101</a></p>
<p style="padding-left: 60px;">M17 <a href="http://training411.adobeconnect.com/readings_sd_m17_combined_p119/" target="_blank">Readings_SD_M17_Combined_p119</a></p>
<p style="padding-left: 60px;"><a href="https://training411.adobeconnect.com/admin/content/sco/info?sco-id=1113630545&amp;tab-id=748905194"></a>M18 <a href="http://training411.adobeconnect.com/readings_sd_m19_combined_p31/" target="_blank">Readings_SD_M18_Combined_p31</a></p>
<p style="padding-left: 60px;"><span style="color: #ff0000;">There is no M19 class</span></p>
<p><strong>02: Print at the beginning of the week and add to binder. </strong></p>
<ul>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a> (once at beginning of the course)</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Template Case worksheet</a> (five  per week) or 44 total copies for class</li>
</ul>
<p><strong>03: Before any reading - Build Flash Cards from domain glossary download above</strong></p>
<ul>
<li>You will need 50 lined note cards per week. A pack of 300 for the whole course.</li>
<li>Get terms and definitions from 01 glossary download above.</li>
<li>Hand written: blank side has the term, lined side has the definition.</li>
<li>Write term big so you can see without your glasses</li>
<li>If you are weak in concepts or process: build extra flash cards from readings bold headings =  term</li>
</ul>
<p><strong>04: Least Crappy Answer review</strong></p>
<ul>
<li>2-4 times over the 10 weeks review our <a href="https://training411.adobeconnect.com/_a748905193/p54219551/" target="_blank">exam taking tips recording</a>.</li>
</ul>
<h2>Daily process: Before class. Repeat for each section of the domain.</h2>
<p><strong>05: Readings from 01 downloads section above</strong></p>
<p>Know how fast you read and how well you comprehend. Input these results on your Excel tracking sheet for your instructor (<a href="http://www.readingsoft.com" target="_blank">test is here</a>) These reading assignments are on a meeting by meeting basis.These can be as short as 20 pages and as long as 120. Please review the page counts and your reading speed to plan your readings before class. Try to read as much on your computer as possible to increase your portability. Reading 30-60 pages in pdf format is not optimal, but as a CISSP you must learn to do a great deal of reading on the computer. Sifting is a way of life.</p>
<p><strong>06: Practice your note cards</strong></p>
<ul>
<li>Carry your cards with you for that 5 minutes of study opportunity</li>
<li>Get a partner to quiz you on the cards</li>
<li>20 seconds each</li>
<li>Make one pile for Yes and No</li>
<li>As you get a pile of Yes&#8217;s, move them to the big stack stored at home</li>
<li>Keep working the No&#8217;s until they are gone</li>
</ul>
<p><strong>07: Do case study</strong></p>
<ul>
<li>Use the combined cases from downloads section 01</li>
<li><a href="https://training411.adobeconnect.com/_a748905193/p29366545/" target="_blank">Case study overview</a></li>
<li>Use the <a href="https://training411.adobeconnect.com/_a748905193/casews/" target="_blank">Case worksheet</a> to write out your notes and thoughts on the business problem and solution</li>
<li>Use your computer&#8217;s notepad or text editor to rewrite your problem and solution</li>
<li>At class time, you will copy and paste to the chat for the case</li>
<li>If you feel like you want more help on cases, email your notes to the instructor for input</li>
</ul>
<h2>Daily Process: At class time</h2>
<p><strong>08: Prepare notepad/text editor for Case notes from 06</strong></p>
<ul>
<li>Copy and paste separately: problem and solution when directed by instructor</li>
<li>Don&#8217;t do both at same time because we want to see what everyone says</li>
</ul>
<h2>Daily Process: After class</h2>
<p><strong>09: Write last flash card definitions from class</strong></p>
<ul>
<li>Carry over all No&#8217;s to next week</li>
</ul>
<p><strong>LET IT GO! MOVE ON! DO NOT DOUBLE UP.</strong></p>
<h2>If you miss class</h2>
<p><strong>10: Recording Links: for your review of class presentations. </strong></p>
<p>These are updated no later than one week after the new class has recorded.</p>
<p>You can get your quiz  in the recording, by pausing the recording and clicking through your quiz. See the orientation for more details. These will be post at the end of the week.</p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p1pptqxqgye/" target="_blank">MP 15 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p2fldi2mq9o/" target="_blank">MP 16 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p8ylvici8ts/" target="_blank">MP 17 Class Recording</a></span></p>
<p><span style="color: #ff0000;"><a href="http://training411.adobeconnect.com/p6quny8958z/" target="_blank">MP 18 Class Recording</a></span></p>
<h2>End of week</h2>
<p><strong>11: Submit your completed Excel tracking sheet</strong></p>
<ul>
<li>Your goal is to pass the exam on your first attempt</li>
<li>We can find trends and problems before they become a failure</li>
<li>If you are not ready for your exam we can help</li>
<li>If you are not sure what to do, your instructor will use this data to make decisions</li>
<li>We realize you have a life, a job, and a family and you need to get it all done</li>
<li>Sometimes class and the exam are not a priority</li>
<li>We still need the true data to make good decisions</li>
</ul>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security.  You are not permitted to copy and distribute these materials in any way.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2012/01/mp-syllabus-sys-dev/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

