• 17 Jun 2010

    Ethical hacking and Windows

    I recently recorded a podcast with my esteemed editor at SearchWindowsServer.com, Brendan Cournoyer, where we talked about ethical hacking, finding the things that matter in your environment, testing tools and my new book Hacking For Dummies, 3rd edition. Check it out:How ethical hacking fits into Windows security tests...

    Continue Reading...
  • 07 Apr 2010

    Tools & techniques for hacking Windows servers & workstations

    Ever wonder how Windows servers get hacked? Perhaps you're unsure of which approach you need to use the get the most out of your security testing at the server and desktop levels? Or you may be wondering what you need to do to lock down Windows-based Web servers? Maybe you're curious about how Windows Server 2008 R2 stands up to security tests?Well, I've got just what you need to know ...

    Continue Reading...
  • 02 Apr 2010

    THE process for successful Web security testing

    Here's a new piece I wrote for SearchSoftwareQuality.com where I talk about the lifecycle of testing for Web security flaws. From obtaining buy-in to reporting to the stakeholders, it's a process you need to master.Security testing best practices for today's Web 2.0 applications...

    Continue Reading...
  • 11 Jan 2010

    Introducing my new book – Hacking For Dummies, 3rd edition

    Well, after months of edits, additions, and subtractions my new piece of work has finally arrived: Hacking For Dummies, 3rd edition I just received my copies last week and it should be in bookstores any time - if it's not already. Hacking For Dummies, 3rd edition is also available on Amazon.com (at a 34% discount to boot!).So, how is this 3rd edition different or better from the previous editions? In ...

    Continue Reading...
  • 12 May 2009

    New version of Acunetix WVS is coming

    I just downloaded and am eager to try out the latest from the guys at Acunetix: Acunetix Web Vulnerability Scanner version 6.5 beta. It seems like they just came out with version 6.0! My last post on it was only a couple of months ago.Acunetix WVS 6.5 beta has a new feature called "file upload forms vulnerability checks" which they claim is an industry first. This is interesting because I ...

    Continue Reading...
  • 12 May 2009

    Do two wrongs make a right?

    I came across this bit recently on whether or not it's considered illegal hacking if security vendors and researchers become Internet crime fighters.Maybe it's just me but I think this is risky behavior. Want to hack something? Then setup your own systems to hack...or find a willing participant or paying client, get their permission in writing, and do it the right way....

    Continue Reading...
  • 10 Mar 2009

    Using AirMagnet WiFi Analyzer for security assessments

    While I'm on a roll testing out the latest security tools (can you tell I'm finally getting caught up on things?!) I wanted to write the follow-up to this previous post I promised regarding AirMagnet's wireless network analyzer (now dubbed WiFi Analyzer).I've been using WiFi Analyzer for years...it now supports 802.11n for those of you on the "bleeding edge" and it even has some automated security checks for "n". As ...

    Continue Reading...
  • 10 Mar 2009

    Gem of a Web application security book

    It's three years old but Andres Andreu has put together a gem of a book on Web security testing:It covers Web apps, some commercial scanners, and practically every open source tool available for Web security testing. It also has some of the best coverage I've seen on testing Web services.Andres must've had a lot of time on his hands when he wrote it...I know firsthand how much effort it takes ...

    Continue Reading...
  • 19 Feb 2009

    My latest security content

    Here's my latest stuff. First off, here are two articles I wrote for SearchEnterpriseDesktop.com:Sysinternals tools: A must-have for every Windows security toolbox...an article I wrote for SearchSoftwareQuality.com:Web application security gaps not fixed in 2008...and an article I wrote for SearchEnterpriseLinux.com:Five common Linux security vulnerabilities you may be overlookingIn the meantime, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 18 Feb 2009

    An upcoming seminar you may want to attend

    If you're in or around South Carolina, I'll be leading a seminar on ethical hacking for the South Carolina chapter of ISACA in Columbia on March 19th. It's going to be a fun and enlightening get together.Here's a link to the page if you want more info. Maybe I'll see you there!...

    Continue Reading...