<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JW Network Consulting &#187; open source</title>
	<atom:link href="http://www.jwnetworkconsulting.com/tag/open-source/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Thu, 22 Jul 2010 01:23:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>UTOS 2009 Presentation Resources</title>
		<link>http://www.jwnetworkconsulting.com/security/utos_2009_resources</link>
		<comments>http://www.jwnetworkconsulting.com/security/utos_2009_resources#comments</comments>
		<pubDate>Thu, 08 Oct 2009 05:27:40 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[utos 2009]]></category>
		<category><![CDATA[utos presentation]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=270</guid>
		<description><![CDATA[On Friday October 9th at 12:00 PM I will be speaking at the Utah Open Source Conference on how to put together a kit of security tools using open source software.  I discuss a fictional company that we work at and some of the things that we can put in place to help secure the [...]]]></description>
			<content:encoded><![CDATA[<p>On Friday October 9th at 12:00 PM I will be speaking at the <a href="http://2009.utosc.com/presentation/90/" target="_blank">Utah Open Source Conference</a> on how to put together a kit of security tools using open source software.  I discuss a fictional company that we work at and some of the things that we can put in place to help secure the environment and handle some of the requests that get thrown our way.  The slides can be <a href="http://www.jwnetworkconsulting.com/downloads/OpenSourceToolkit.pdf" target="_self">downloaded here</a>.  I hope to have video of the presentation up later.</p>
<p>Here are the apps I cover and where you can got to get more information on them.  I&#8217;ve also got some community resources to go check out.</p>
<p><strong>Network Security and Monitoring</strong><br />
Nmap &#8211; <a href="http://nmap.org/" target="_blank">http://nmap.org/</a><br />
OpenVAS &#8211; <a href="http://openvas.org/" target="_blank">http://openvas.org/</a><br />
Snort  &#8211; <a href="http://www.snort.org/" target="_blank">http://www.snort.org/</a><br />
Emerging Threats &#8211; Snort rules &#8211; <a href="http://www.emergingthreats.net/" target="_blank">http://www.emergingthreats.net/</a><br />
BASE &#8211; <a href="http://base.secureideas.net/" target="_blank">http://base.secureideas.net/</a><br />
Sguil &#8211; <a href="http://sguil.sourceforge.net/" target="_blank">http://sguil.sourceforge.net/</a><br />
OSSEC &#8211; <a href="http://www.ossec.net/" target="_blank">http://www.ossec.net/</a><br />
Kismet &#8211; <a href="http://www.kismetwireless.net/" target="_blank">http://www.kismetwireless.net/</a></p>
<p><strong>Web Security</strong><br />
Nikto &#8211; <a href="http://www.cirt.net/nikto2" target="_blank">http://www.cirt.net/nikto2</a><br />
Log Analysis &#8211; <a href="http://www.loganalysis.org" target="_blank">http://www.loganalysis.org</a><br />
PHPIDS &#8211; <a href="http://php-ids.org/" target="_blank">http://php-ids.org/</a><br />
ModSecurity &#8211; <a href="http://www.modsecurity.org/" target="_blank">http://www.modsecurity.org/</a></p>
<p><strong>Penetration Testing</strong><br />
WebGoat &#8211; <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project</a><br />
Mutillidae &#8211; <a href="http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10" target="_blank">http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10</a><br />
Hacme Bank, Books, etc &#8211; <a href="http://www.foundstone.com/us/resources-free-tools.asp" target="_blank">http://www.foundstone.com/us/resources-free-tools.asp</a><br />
Paros &#8211; <a href="http://www.parosproxy.org/" target="_blank">http://www.parosproxy.org/</a><br />
WebScarab &#8211; <a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" target="_blank">http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project</a><br />
Burp Suite &#8211; <a href="http://portswigger.net/suite/" target="_blank">http://portswigger.net/suite/</a><br />
Privoxy &#8211; <a href="http://www.privoxy.org/" target="_blank">http://www.privoxy.org/</a><br />
Tor &#8211; <a href="http://www.torproject.org/" target="_blank">http://www.torproject.org/</a><br />
w3af &#8211; <a href="http://w3af.sourceforge.net/" target="_blank">http://w3af.sourceforge.net/</a><br />
Beef &#8211; <a href="http://www.bindshell.net/tools/beef/" target="_blank">http://www.bindshell.net/tools/beef/</a><br />
Metasploit &#8211; <a href="http://metasploit.com/" target="_blank">http://metasploit.com/</a><br />
Backtrack -<a href="http://www.remote-exploit.org/backtrack.html" target="_blank"> http://www.remote-exploit.org/backtrack.html</a><br />
SamuraiWTF- <a href="http://samurai.inguardians.com/" target="_blank">http://samurai.inguardians.com/</a></p>
<p><strong>Forensics</strong><br />
Caine &#8211; <a href="http://www.caine-live.net/" target="_blank">http://www.caine-live.net/</a><br />
Deft Linux &#8211; <a href="http://www.deftlinux.net/" target="_blank">http://www.deftlinux.net/</a><br />
Helix &#8211; <a href="http://www.e-fense.com/" target="_blank">http://www.e-fense.com/</a></p>
<p><strong>Etc&#8230;</strong><br />
Top 100 Security Tools -<a href="http://sectools.org/" target="_blank"> http://sectools.org/</a></p>
<p><strong>Podcasts</strong><br />
Pauldotcom &#8211; <a href="http://pauldotcom.com/" target="_blank">http://pauldotcom.com/</a><br />
Exotic Liability &#8211; <a href="http://exoticliability.com/" target="_blank">http://exoticliability.com/</a><br />
Securabit &#8211; <a href="http://www.securabit.com/" target="_blank">http://www.securabit.com/</a><br />
CyberSpeak (forensics) &#8211; <a href="http://cyberspeak.libsyn.com/" target="_blank">http://cyberspeak.libsyn.com/</a></p>
<p><strong>Community Groups</strong><br />
ISSA &#8211; <a href="http://www.issa-utah.org/" target="_blank">http://www.issa-utah.org/</a><br />
OWASP &#8211; <a href="http://owasp.org/" target="_blank">http://owasp.org/</a><br />
Hack SLC hacker space &#8211; <a href="http://www.hackslc.com/forum/latestnews.php" target="_blank">http://www.hackslc.com/forum/latestnews.php</a><br />
Defcon &#8211; <a href="http://defcon.org/" target="_blank">http://defcon.org/</a></p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/open+source' rel='tag' target='_self'>open source</a>, <a class='technorati-link' href='http://technorati.com/tag/security+tools' rel='tag' target='_self'>security tools</a>, <a class='technorati-link' href='http://technorati.com/tag/utos+2009' rel='tag' target='_self'>utos 2009</a>, <a class='technorati-link' href='http://technorati.com/tag/utos+presentation' rel='tag' target='_self'>utos presentation</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/utos_2009_resources/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Open Source Project Created &#8211; Reconnoiter</title>
		<link>http://www.jwnetworkconsulting.com/security/web-application-security/new-open-source-project-created-reconnoiter</link>
		<comments>http://www.jwnetworkconsulting.com/security/web-application-security/new-open-source-project-created-reconnoiter#comments</comments>
		<pubDate>Wed, 16 Sep 2009 05:07:03 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[web app security]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=268</guid>
		<description><![CDATA[Earlier this month I decided to take the scripts for username generation and roll them into an open source project.  There were a couple of reasons for doing so.  First, I needed source control hosting and SourceForge provides that for free as long as you release the project to the public.  Second, I want to [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this month I decided to take the scripts for username generation and roll them into an open source project.  There were a couple of reasons for doing so.  First, I needed source control hosting and SourceForge provides that for free as long as you release the project to the public.  Second, I want to expand the scope of it to go beyond what I&#8217;ve done so far.  It&#8217;s great that people have found these scripts useful, but its hardly rocket science.  This should give me some more room to explore and share with others.</p>
<p>If you would like to check out the project, you can search for &#8220;Reconnoiter&#8221; on sourceforge.net or you can just follow this link:</p>
<p><a href="http://sourceforge.net/projects/reconnoiter/">http://sourceforge.net/projects/reconnoiter/</a></p>
<p>One last note.  There are some changes in the 0.2 release of Reconnoiter that may be useful.  I found a nasty bug in the Yahoo script that needed to be fixed badly.  That&#8217;s been done and committed to the release.  Last, I made the output a lot more useful.  There was no filtering at all for results that included HTML code in them.  This caused some obviously bad usernames.  Unless you logged in as &#8220;&lt;b&gt;jwood&lt;/b&gt;&#8221; often.  To help with that I&#8217;ve added some filtering which should improve the quality of the results.  Enjoy!</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/open+source' rel='tag' target='_self'>open source</a>, <a class='technorati-link' href='http://technorati.com/tag/penetration+testing' rel='tag' target='_self'>penetration testing</a>, <a class='technorati-link' href='http://technorati.com/tag/web+app+security' rel='tag' target='_self'>web app security</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/web-application-security/new-open-source-project-created-reconnoiter/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at the 2009 Utah Open Source Conference</title>
		<link>http://www.jwnetworkconsulting.com/consulting/speaking-at-the-2009-utah-open-source-conference</link>
		<comments>http://www.jwnetworkconsulting.com/consulting/speaking-at-the-2009-utah-open-source-conference#comments</comments>
		<pubDate>Tue, 15 Sep 2009 16:53:32 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Consulting]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security tool]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[tech conference]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=257</guid>
		<description><![CDATA[Last month I sent the Utah Open Source Conference a proposal for a presentation on &#8220;Building an Open Source Security Tool Set&#8220;.  Presentations are voted on by the registered attendees and the other folks who have submitted a presentation.  When I was making my votes, I saw that there were a lot of great abstracts.  [...]]]></description>
			<content:encoded><![CDATA[<p>Last month I sent the Utah Open Source Conference a proposal for a presentation on &#8220;<a title="Building an Open Source Security Tool Set" href="http://2009.utosc.com/presentation/90/" target="_blank">Building an Open Source Security Tool Set</a>&#8220;.  Presentations are voted on by the registered attendees and the other folks who have submitted a presentation.  When I was making my votes, I saw that there were a lot of great abstracts.  In fact, there were a lot of abstracts period.  Because of this, I really didn&#8217;t expect to get selected.  Turns out I was wrong!</p>
<p>I received word on September 3rd that my presentation was accepted and that I will be speaking at the Utah Open Source Conference.  The current time scheduled is on October 9th at 12:00 PM.  Here is my description of the proposal.</p>
<div class="code panel" style="border-width: 1px;">
<div class="codeContent panelContent">
If you want to build out a kit of commercial security tools, bring a big bank account to pay for it. Not only that, you&#8217;ll find that there are still gaps in your setup that need to be filled. What do you do if you have a finite budget (who doesn&#8217;t?) or have no budget? Does testing your security require a fat wallet? Fortunately, no.<br />
<br />
In this presentation I&#8217;ll go over a number of open source security tools, what they do and where you can get them. Individual tools will be discussed as well as Live CDs which have a collection of the tools all together.
</div>
</div>
<p>I&#8217;m very excited to have been selected to give this presentation.  It should be a lot of fun and I hope it will be useful to those in attendance.  I&#8217;m trying to have some goodies for the attendees, but I&#8217;m not sure how many I&#8217;ll need.  We will see.  <img src='http://www.jwnetworkconsulting.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>You can register for the conference using the UTOS 2009 banner on the right or you can use the link below.  Hope to see you there!</p>
<p><a href="http://register.utosc.com/utoscreg/">http://register.utosc.com/utoscreg/</a></p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/open+source' rel='tag' target='_self'>open source</a>, <a class='technorati-link' href='http://technorati.com/tag/security+tool' rel='tag' target='_self'>security tool</a>, <a class='technorati-link' href='http://technorati.com/tag/speaking' rel='tag' target='_self'>speaking</a>, <a class='technorati-link' href='http://technorati.com/tag/tech+conference' rel='tag' target='_self'>tech conference</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/consulting/speaking-at-the-2009-utah-open-source-conference/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
