<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JW Network Consulting &#187; SANS</title>
	<atom:link href="http://www.jwnetworkconsulting.com/tag/sans/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Thu, 22 Jul 2010 01:23:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Upcoming SANS Mentor Session &#8211; Security 504: Hacker Techniques, Exploits &amp; Incident Handling</title>
		<link>http://www.jwnetworkconsulting.com/security/upcoming-sans-mentor-session-security-504-hacker-techniques-exploits-incident-handling</link>
		<comments>http://www.jwnetworkconsulting.com/security/upcoming-sans-mentor-session-security-504-hacker-techniques-exploits-incident-handling#comments</comments>
		<pubDate>Fri, 21 May 2010 03:07:28 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[incident handling]]></category>
		<category><![CDATA[salt lake city]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[sec504]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=338</guid>
		<description><![CDATA[This is something that I&#8217;ve really been looking forward to announcing for a while now.  I will be running a Mentor session for SANS starting on Sept 21 and running until November 23, 2010.  We will be meeting once per week for two hours to cover course material, discuss what we&#8217;ve studied and do some [...]]]></description>
			<content:encoded><![CDATA[<p>This is something that I&#8217;ve really been looking forward to announcing for a while now.  I will be running a Mentor session for SANS starting on Sept 21 and running until November 23, 2010.  We will be meeting once per week for two hours to cover course material, discuss what we&#8217;ve studied and do some of the labs.  We will be meeting in South Jordan, so its fairly central to the Salt Lake and Provo area.</p>
<p>The course will cover how to handle security incidents, demonstrate what tools attackers use and how they exploit systems.  I took this course in 2009 and I can&#8217;t say enough how good it is.  It&#8217;s one thing to read about how an exploit works.  It brings a whole new level of awareness when you actually run an exploit and start pulling data from the target system.</p>
<p>What was most valuable to me was the background on how to prepare, respond and recover from a security incident.  There is quite a bit of preparation that you need to take so that you are ready to conduct incident response in a way which will stand up in civil or criminal proceedings.  There are lots of pitfalls that you want to avoid so that you protect your employer and don&#8217;t get in trouble yourself.</p>
<p>Here are two key things you can use to &#8220;sell&#8221; this course to management.</p>
<ol>
<li>You will learn how to handle an incident in a way that best protects your company, is thorough and preserves the company&#8217;s legal options.</li>
<li>You will see what exploits can do to a system, how they are used and what they look like.  Every exploit covered includes how to defend against them.</li>
</ol>
<p>If you are in the Salt Lake City area and would like to read more about this course or sign up, use the link below.</p>
<h5><a title="Security 504: Hacker Techniques, Exploits &amp; Incident Handling " href="http://www.sans.org/mentor/details.php?nid=22153" target="_self">Security 504: Hacker Techniques, Exploits &amp; Incident Handling</a></h5>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/incident+handling' rel='tag' target='_self'>incident handling</a>, <a class='technorati-link' href='http://technorati.com/tag/salt+lake+city' rel='tag' target='_self'>salt lake city</a>, <a class='technorati-link' href='http://technorati.com/tag/SANS' rel='tag' target='_self'>SANS</a>, <a class='technorati-link' href='http://technorati.com/tag/sec504' rel='tag' target='_self'>sec504</a>, <a class='technorati-link' href='http://technorati.com/tag/security+training' rel='tag' target='_self'>security training</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/upcoming-sans-mentor-session-security-504-hacker-techniques-exploits-incident-handling/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Quick Update on the Latest Activity</title>
		<link>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity</link>
		<comments>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity#comments</comments>
		<pubDate>Mon, 15 Feb 2010 05:57:04 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[GCIH]]></category>
		<category><![CDATA[Incident Handler]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Reconnoiter]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=320</guid>
		<description><![CDATA[It has been a busy couple of months, but my posts have been fairly quiet on the blog. Between attending the SANS Security 504 Incident Handling class, traveling for work, moving my family and the holidays things have been moving at a rapid pace.  I&#8217;m going to be trying to comment more here, but for [...]]]></description>
			<content:encoded><![CDATA[<p>It has been a busy couple of months, but my posts have been fairly quiet on the blog.  Between attending the SANS Security 504 Incident Handling class, traveling for work, moving my family and the holidays things have been moving at a rapid pace.  I&#8217;m going to be trying to comment more here, but for now a brief update.</p>
<p>First off, I took the examination for the SANS Incident Handler certification on Friday the 12th.  All the time put into preparation paid off and I passed with 96%!  It was extremely satisfying to pass this exam, since I have been spending the last several weeks studying for it.  On top of just earning the certification, my score was high enough that I can apply to become a SANS Mentor now too.  This is something that I think would be a lot of fun and I really want to do.  Time to start writing up my application and hoping for the best.</p>
<p>Last, I&#8217;ve started working on rewriting Reconnoiter to run as a Metasploit module.  I started on this late last week and have made some headway in the process.  Scrapping HTML and using the data in a script or program isn&#8217;t much fun.  The main problem I&#8217;ve run into is that Google really doesn&#8217;t want anyone doing this type of stuff.  While Yahoo! has provided a nice XML web service to aid in accessing data, Google appears to be going out of their way to make this difficult.  I&#8217;m actually a bit irritated by this since Google has taken great pains to convince everyone (with good reason on our part to do so) that we need to make it easy for Google to crawl our sites.  Just don&#8217;t expect them to return the favor.  Ah well.</p>
<p>Anyhow, I hope to have a rough module up and running by the end of this week.  Current plans are to have the ability to pull results from Google and Yahoo both.  You will be able specify an output directory to save username lists.  Plus, since this is in Metasploit, you can choose between the command line or a web interface to run the module.  That alone may be a real kicker for folks.</p>
<p>The Google query is going to be pretty buggy and a pain to maintain.  The Yahoo! query should be very solid since the script pulls from their XML web service.  The down side is that you will need an AppID to use the Yahoo! query.  So the decision is whether you want to be (relatively) anonymous but have iffy results or if you don&#8217;t mind losing some of that anominity for more accurate results.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/GCIH' rel='tag' target='_self'>GCIH</a>, <a class='technorati-link' href='http://technorati.com/tag/Incident+Handler' rel='tag' target='_self'>Incident Handler</a>, <a class='technorati-link' href='http://technorati.com/tag/Metasploit' rel='tag' target='_self'>Metasploit</a>, <a class='technorati-link' href='http://technorati.com/tag/Reconnoiter' rel='tag' target='_self'>Reconnoiter</a>, <a class='technorati-link' href='http://technorati.com/tag/SANS' rel='tag' target='_self'>SANS</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
