• 03 Nov 2009

    Good dictionary to use for password cracking

    Here's a pretty comprehensive password dictionary I recently came across that you may want to use in your security testing...there may be "friendlier" download link but I haven't searched for it.If time is a factor, this dictionary may be too big for its own good given the time it'd take to run through everything but at least you know you're using a good dictionary. After all, your dictionary-based password cracking ...

    Continue Reading...
  • 30 Oct 2009

    1 day left for 50% discount on current audio programs

    Final call for the 50% discount on my current Security On Wheels audio programs. Just enter OCT09 as the discount code when checking out!...

    Continue Reading...
  • 30 Oct 2009

    You’d think Twitter would have the means to fix this

    Seems like I get it more often than not these days...Ahh, the growing pains of an Internet startup....

    Continue Reading...
  • 29 Oct 2009

    Disaster recovery is dead?? Not hardly!

    In this recent SearchCIO.com bit, the executive director of the Disaster Recovery Institute International says that disaster recovery is dead. He goes on to say that "disaster recovery (DR) and business continuity have become synonymous" and (here's the kicker) "We don't do recovery anymore, because what everybody wants is continuous operations...We have auto failover now. We have redundancy in data. We do have more continuity. And that is because recovery ...

    Continue Reading...
  • 21 Oct 2009

    Metasploit as we knew it going bye bye?

    The day I never thought I'd see has come. Once HD Moore announced "Metasploit is hiring" I knew something was going on. Metasploit has been acquired by Rapid7...huh!? Too bad Qualys - maker of my favorite OS/network vulnerability scanner - missed this opportunity!According to the Rapid7 acquisition FAQ Metasploit will remain open source but with a commercial twist. I hope it only gets better...fingers crossed.Hey at least Capitalism prevailed...it's dying ...

    Continue Reading...
  • 16 Oct 2009

    Email business continuity – this is funny…and ironic

    As I reported a couple of days ago, my email security provider stopped working. Maybe they took a hiatus...a sabbatical...an extended vacation - and didn't tell me. Seriously, I did end up calling them a few times trying to work things out. I got what seemed to be a knowledgeable tech rep trying to help me. The problem was he never could. He said he'd call me back two different ...

    Continue Reading...
  • 14 Oct 2009

    The fastest vendor acquisition I’ve seen

    This has to be the fastest security startup/acquisition I've ever seen. I'm pretty sure the company - which is here in my neck of the woods - was less than a year old.You know how I feel about SaaS and "the cloud" but kudos to Paul Judge, Chris Tilton, and those guys for growing and turning this thing around so quickly. Capitalism at its finest!!...

    Continue Reading...
  • 14 Oct 2009

    Cloud computing & customer no-service – match made in heaven?

    I never thought I could be so productive. This week I've had less pressure to deliver. I've been able to turn "things" off. All while I'm attending a conference when I usually get even more behind. Well you see, my email isn't working. My email security "application service provider", I mean "managed service", dang it, actually my "cloud computing" provider delivering "software as a service" has apparently decided to take ...

    Continue Reading...
  • 13 Oct 2009

    In case you’re trying to email me…

    ...my lovely email security provider has chosen to work part-time apparently. If you need to reach me, email my full name (1 word) at gmail dot com....

    Continue Reading...
  • 13 Oct 2009

    Latest version of LANguard worth considering

    Have you seen the new - OK, it's not that new any more - version of LANguard (formerly LANguard Network Security Scanner)? It's certainly a tool worth checking out if you do vulnerability scanning.I've been using LANguard for years for share finding and authenticated scanning and it does both very well. The biggest change in the latest version is the user interface. I've never been a big fan and I'm ...

    Continue Reading...