December 2009

I have made an important update to the Backtrack 4 USB "Full" Encryption How-to.

I forgot to include the step where you select the drive install the boot loader to. Missing this step can cause the operating system on the machine you are using to not boot. Please review the how-to.

Below are some links to instructions on repairing boot records for a few common operating systems in case I am too late with this update:

Windows XP: http://pcsupport.about.com/od/fixtheproblem/ht/repairmbr.htm

Windows Vista/7: http://www.tomstricks.com/how-to-repair-and-restore-windows-vista-master-boot-record-mbr/

Ubuntu Linux: https://help.ubuntu.com/community/RecoveringUbuntuAfterInstallingWindows

I apologize for any issues that may have occurred due to my oversight.

-Kevin

{ 3 comments }

I have published my latest Backtrack 4 how-to.

Backtrack 4 - Bootable USB Thumb Drive with "Full" Disk Encryption

This is a step-by-step guide showing how to create a encrypted bootable Backtrack 4 USB thumb drive. I put quotes around full in the title because technically the whole disk isn't encrypted.

We use LVM and the native encryption routines included in Ubuntu 8.10 to encrypt all partitions except for a small boot partition that never contains any data.

This how-to is a departure from the persistent install method I have documented in the past. It also means we don't have to mess with Truecrypt or do the home directory shennanigins we were going through. I will be incorporating it into the main how-to in the near future.

As always, I am interested in your thoughts and feedback.

-Kevin

{ 2 comments }

Hello there! Just wanted to let you know that this Bits post is the last one you will likely see this year. I am taking some time off from the day gig and decided I am also going to do the same here. You might see a post or two if something strikes my fancy, but the Bits posts will be on hiatus.

We'llĀ  be picking back up on January 4th.

Here are today's Interesting Information Security Bits from around the web.

  1. Another great FUDSec article.
    FUD and Other Sales Errors - fudsec.com
    Tags: ( fud )
  2. Want to build a custom wordlist based on a website for password cracking? Look no further. Here is nice how-to on getting that setup.
    Will Hack For SUSHI >> Wordlist Generation - CeWL on Ubuntu
    Tags: ( wordlist password )
  3. George has put together a nice how-to on setting up a logging virtual machine using syslog-ng, splunk and vmware. Very good stuff.
    Building a logging VM - syslog-ng and Splunk | George Starcher
    Tags: ( loging splunk )
  4. Some good information on NTLM reflection.
    Reflecting on NTLM Reflection
    Tags: ( ntlm reflection )
  5. Here is a fun fictional story about a 'lost' laptop.
    The Confessions of a Chief Executive and his lost laptop | Infosec Cynic
    Tags: ( story laptop encryption )
  6. I always get a kick of walk-through/how-we-did-it stories. This is the beginning of a series about a physical pen test.
    Red Team Physical Security Penetration Test
    Tags: ( pentest )
  7. This is absolutely full of awesome sauce. Go check it out.
    'Twas the night before D-DoS << wirewatcher
    Tags: ( poem )
  8. If you are not familiar with SteadyState and are responsible or kiosks, labs, etc., you should check out this page.
    Maintain Shared Computers with the Free Windows SteadyState Tool
    Tags: ( kiosk )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 0 comments }

A Charlie Brown Compliance

by kriggins on December 18, 2009

in Risk Management

I wish I could take credit for the idea below, but I cannot. This was sent to me by someone who works in a marketer compliance department.

With his permission, I modified it a little to be information security centric and now present it to you. Enjoy.

BTW - I won't be surprised if I get a take down notice so tell your friends quickly if you find it worth sharing. :)

{ 0 comments }

Good afternoon everybody! I hope your day is going well.

Here are today's Interesting Information Security Bits from around the web.

  1. Like the title below says, a new version of the SANS Consensus Audit Guidelines has been published.
    New Version of SANS 20 Critical Security Controls is Available << Security is Golden
    Tags: ( sans )
  2. Chet offers up some tips on being a safer Twitter user in 2010.
    12 tips of Christmas - A safer Twitter for 2010 | Chester Wisniewski's Blog
    Tags: ( twitter safety )
  3. Surprise, surprise. Another adobe reader o-day vulnerability.
    New Adobe 0-day
    Tags: ( adobe vulnerability 0day )
  4. If you are concerned about your privacy as you surf the internet you should read this article. It provides some guidance on doing so in a more anonymous manner.
    How to surf anonymously without a trace
    Tags: ( privacy internet )
  5. Wow. Andrew is really cranking out the interviews. This time it is another good friend, Michael Santarcangelo.
    Andrew Hay >> Blog Archive >> Information Security D-List Interview: Michael Santarcangelo
    Tags: ( interviews )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 0 comments }

Good afternoon everybody! I hope your day is going well.

Here are today's Interesting Information Security Bits from around the web.

  1. Learn more about Nick Owen.
    Andrew Hay >> Blog Archive >> Information Security D-List Interview: Nick Owen
    Tags: ( interviews )
  2. Listen to Brian. Go check your privacy settings on Facebook. Details inside.
    Security Fix - Check your Facebook 'privacy' settings now
    Tags: ( facebook privacy )
  3. The next Ethical Hacker challenge is ready for you to try your hand.
    The Ethical Hacker Network - Miracle on Thirty-Hack Street
    Tags: ( challenge )
  4. Andrew's next interview is up. This time my good friend Brian Honan shares some interesting information about himself and information security in Ireland.
    Andrew Hay >> Blog Archive >> Information Security D-List Interview: Brian Honan
    Tags: ( interviews )
  5. Jeff learned some very hard lessons recently when Coding Horror died. You will be well served by reading this post and taking those lessons to heart.
    International Backup Awareness Day
    Tags: ( backup recovery )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 1 comment }

I am very pleased to announce that my Peer2Peer session submission for RSA 2010 was accepted.

Here is the definition of a Peer2Peer session from RSA in case you are not familiar with them:

Have a security issue you would like to discuss with your peers? Want to share your experiences with a new technology? Care to explore best practices with colleagues? Then submit a P2P session!

Peer2Peer sessions are limited to 25 people who share a common interest and want to discuss or learn more about a particular security issue. The sessions are interactive and moderated by someone who knows the subject at hand and also can keep the conversation flowing. No PowerPoint allowed!

The first Yay! is that you won't be subjected to a PowerPoint; the second is that you will get to help shape the conversation and learn from your peers.

The title of my session is Risk Management: Getting Engaged.

Before we can effectively practice risk management in our organizations, a number of things have to happen. One of the key things that must occur is getting our business partners to engage with us. In this Peer2Peer session we will explore different ways to capture our business partners attention so that we can effectively and efficiently provide the risk management activities that help our organizations make appropriate risk based decisions.

Here are the details:

Session Track: Peer2Peer
Session Code: P2P-203B
Scheduled Date: 3/3/2010
Scheduled Time: 10:40 AM - 11:30 AM
P2P Session Title: Risk Management: Getting Engaged

I hope to see you there!

-Kevin

Reblog this post [with Zemanta]

{ 0 comments }

Good afternoon everybody! I hope your day is going well.

Here are today's Interesting Information Security Bits from around the web.

  1. I think I pointed to part 1 of this article, but can't remember and am a bit too lazy at the moment to go look :) Either way, the second part is up and you will find a link to the first part inside. It is some pretty cool stuff from a visualization perspective.
    Detailed look at using Circos for IT Investigation - Part II << fifth.sentinel
    Tags: ( tools )
  2. This is a must read. I'm not saying anything else other than go read it. Now. Hurry!
    Verizon Business Security Blog >> Blog Archive >> 2009 Data Breach Investigations Supplemental Report
    Tags: ( verizon dbir )
  3. Heh. The first of a series of interviews by Andrew.
    Andrew Hay >> Blog Archive >> Information Security D-List Interview: Paul Asadoorian
    Tags: ( interviews )
  4. Here is an interesting perspective on the wonderful addition of Google and Bing integrating Facebook and Twitter status updates into search results.
    Google, Bing open new criminal opportunities by adding Twitter, Facebook feeds | The Last Watchdog
    Tags: ( malware facebook twitter search google )
  5. The Social Security Blogger Awards will be happening again at RSA 2010. If you have a security blog and want to be considered you need to become a member of the Security Bloggers Network. Check inside for details.
    The Ashimmy Blog: Social Security Blogger Awards 2010
    Tags: ( sbn awards )
  6. Chris's slides and handouts from his State of (In)Security talk at the 2009 MN-GTS conference are available for a short while.
    Dr. InfoSec: MN-GTS - The State of (In)Security in 2009
    Tags: ( general )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 0 comments }

Good afternoon everybody! I hope your day is going well.

Here are today's Interesting Information Security Bits from around the web.

  1. Security Catalyst has announced the 2010 lineup of contributors. Looks like it is going to be a great year.
    Amplifying the Good: The Security Catalyst Online Experience 2010 : The Security Catalyst
    Tags: ( general )
  2. This article takes a look at the recent issue that the TSA had with a document that was not correctly redacted.
    TSA Leaks Sensitive Airport Screening Manual | Threat Level | Wired.com
    Tags: ( tsa redacting )
  3. A nice interview with Nigel Stanley discussing whitelisting.
    Winning the Malware Battle: The Move Towards Whitelisting | Optimal Security: The Lumension Blog
    Tags: ( malware whitelisting )
  4. Very nice article on VOIP and UCS attacks.
    The Forrester Blog For Security & Risk Professionals
    Tags: ( voip interception )
  5. Insider threats do exist.
    Insider Threat is Happening - Security Views - Dark Reading
    Tags: ( threat insider )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 1 comment }

Good afternoon everybody! I hope your day is going well.

Here are today's Interesting Information Security Bits from around the web.

  1. Guest blog: Evil Maids on the rise | Graham Cluley's blog
    Tags: ( bitlocker tpm )
  2. Could a rubber duck steal your identity on Facebook? | Graham Cluley's blog
    Tags: ( facebook malware )
  3. AOL Ditches Security Tokens To Make Logging In Easier | Threat Level | Wired.com
    Tags: ( general )
  4. Can quantitative risk estimation serve as a guide for every-day policy decisions? << The New School of Information Security
    Tags: ( risk-management policy quantitative )
  5. Security Uncorked >> Four Options for Secure Wireless Authentication with 802.1X
    Tags: ( 80211x )
  6. Great InformationWeek/Dark Reading/Black Hat Cloud & Virtualization Security Virtual Panel on 12/9 | Rational Survivability
    Tags: ( webinar virtualization cloud )
  7. Digital Soapbox - The White Rabbit Commeth...: Exposing Malware - Part 2: Infestation
    Tags: ( malware )
  8. McAfee Gives Stats on the Riskiest Domains | CNET Security | danielmiessler.com
    Tags: ( general )
  9. Economic Recovery: Will Your IT Security Department Jump Ship? - CSO Online - Security and Risk
    Tags: ( career jobs )

That's it for today. Have fun!

Subscribe to my RSS Feed if you enjoy these daily Interesting Bits posts.

Kevin

{ 0 comments }