• 03 May 2010

    Commercial WEP and WPA key recovery tools

    Ever find yourself needing a wireless network analyzer that's easy to use and doesn't cost an arm and a leg? Well, CommView for WiFi is a great option...It's a product I've talked about for years in both Hacking For Dummies and Hacking Wireless Networks For Dummies. A neat thing about CommView for WiFi are its relatively new WEP and WPA key recovery add-ons. Referred to as WEPKR and WPAKR, they're ...

    Continue Reading...
  • 30 Apr 2010

    Security strategies that lead to success

    Here's a new webcast I recorded where I talk about how to use visibility, control, and simplicity to your advantage to take the pain out of IT and security management:Strategies for Securing your Enterprise for SuccessBe sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, videos, Twitter updates, and more....

    Continue Reading...
  • 29 Apr 2010

    IT security roundtable starting soon

    Join me if you can in just over an hour for AppSec's Five Burning Questions: Q2 2010 IT Security Auditor Roundtable. I and others from companies such as Ernst & Young, KMPG, and Protiviti will discuss database audit challenges and share tips and best practices you can implement to ensure database compliance and security.I hope to "see" you there!...

    Continue Reading...
  • 27 Apr 2010

    How to become a better presenter

    There are a lot of unknowns in IT but one thing's for sure: if you're going to be successful in your job and move up the career ladder you have to sharpen your presentation skills. Here's a new piece I wrote that'll help you get started down the right path:Eight tips every IT pro can use towards becoming a better presenter...

    Continue Reading...
  • 26 Apr 2010

    The ultimate SQL Server faux pas, other oversights & solutions

    Here's a new piece I wrote where I talk about one of the root causes of SQL Server security issues:The ultimate SQL Server security faux pas: Overlooked systems...along with some additional oversights:Common oversights with SQL Server audits...and, to top things off, some things you can do to lock down your database environment (SQL Server or not)Meet compliance requirements with improved database security practices...

    Continue Reading...
  • 26 Apr 2010

    Cracking Windows 7 passwords + a bit on BitLocker

    Here's the latest on Windows 7 passwords along with how they can be cracked and some tools for doing so:Cracking passwords in Windows 7I wrote a whitepaper on BitLocker in Windows 7 not long ago and here are some additional thoughts/tips in case you're considering it:Using BitLocker in Windows 7 For additional reading, Paul Thurrott's SuperSite for Windows is a great resource on Windows 7 and more....

    Continue Reading...
  • 26 Apr 2010

    The key to failure

    Bill Cosby said it best: "I don't know the key to success, but the key to failure is trying to please everybody." Be it your current job, your career, information security, IT, whatever - you cannot forget this sage advice....

    Continue Reading...
  • 23 Apr 2010

    Re-post of my update on CSRF

    I was just informed by my editor at SearchSoftwareQuality.com that they're going to take my Ask the Expert response regarding CSRF (referred to in this post) offline until they've had a chance to review it. In the interest of not letting this fizzle out without people knowing what happened as well as maintaining my stance on the topic and further clarifying what I meant, here's the original question along with ...

    Continue Reading...
  • 22 Apr 2010

    Great information security quote

    Socrates said it best: "The more you know, the more you realize you know nothing." How true this is in the context of information security.Funny how we start out knowing everything in our teens, think we know everything in our 20s, and, in our 30s and beyond, come to the realization that things are much more complex than we originally thought.Common sense - and humility - are the key ingredients ...

    Continue Reading...
  • 19 Apr 2010

    Have you seen Win7’s Windows XP Mode?

    It's a great way for setting up a virtual testing environment. Here's a recent piece I wrote about it:Using Windows XP Mode for security testing in Windows 7I'm really digging Windows 7....even if you just upgrade your own machine, Windows 7 has lots of things that will help you work more efficiently....

    Continue Reading...