Many people tout how great open source and freeware wireless tools are for finding and exploiting wireless network vulnerabilities - myself included. However, if you're performing a wireless assessment, you don't want to overlook the value the commercial tools have to offer.The commercial tool I've been using for a while - since before I co-authored Hacking Wireless Networks For Dummies - is AirMagnet's WiFi Analyzer (formerly their "Laptop" product). It's ...
Continue Reading...Here's another security career question from someone who is about to graduate with an IT bachelor's degree and is planning to work in the information security field:"...What is the best certificates you can recommend on information security to go through these days? How about going through Cisco Networking certificates such as CCIE. Is it better than CISSP? Actually I'm confused about either Cisco or CISSP. Should I be employed first ...
Continue Reading...This is something I'm going to start doing more of on my blog...That is, posting questions regarding security careers that people email to me along with my responses back to them. I think this is something that many of you might benefit from.Here's a recent one from a software engineer with three years experience:"...I work creating Web sites. I want to be an expert in information security for Web-based systems. ...
Continue Reading......it's been out for a few weeks and wow, it looks really neat. Great way to demonstrate the vulnerabilities associated with Wi-Fi in the enterprise. I've actually been wondering when someone would come up with a tool like this.http://metasploit.com/dev/trac/wiki/KarmetasploitKarmetasploit acts as a wireless access point serving up legitimate-looking services such as SMTP, DNS, etc. It can be used to capture email passwords, retrieve info from Web form fields, exploit Web ...
Continue Reading..."Everyone starts from scratch, but not everyone keeps on scratching!" - Anonymous...
Continue Reading...Want to see what the real scoop is on the person you're hiring but don't want to spend any $$$ on running a background check? I know, it's only like $5 but I'm just being realistic because I know some people would not spend that kind of money willy-nilly. Or, are you not getting a good feeling about your boss and are wondering about his or her past? Well, here's ...
Continue Reading...I'm running a day behind! Here's a recent podcast I recorded with my bud David Nielson at SearchWindowsSecurity.com regarding the DNS flaw:DNS flaw threatens Windows shopsI'm still waiting on about 5 others articles to be published. Will you know as soon as they are. For all my information security resources, be sure to check out www.principlelogic.com/resources.html....
Continue Reading...I've been harping on this subject for a while. Why don't more managers let their employees telecommute? After all, it helps morale, can boost productivity, and even impresses those who buy in to the religion of "global warming".Then I came across this article citing evidence that apparently more in management are telecommuting themselves...The email I received this in had the headline "Joining the telecommute revolution". Everybody, quick! Jump on the ...
Continue Reading...I'm writing an article series that includes some information about PCI DSS. In my research, I noticed something interesting - almost comical - about Requirement 12.7:Screen potential employees to minimize the risk of attacks from internal sources. For those employees such as store cashiers who only have access to one card number at a time when facilitating a transaction, this requirement is a recommendation only.So, "access to one card number ...
Continue Reading...I was thinking some more about the knowledge=power equation. To have knowledge we have to have information, right? But information is also a weakness in the context of the work we do, agreed?So, does weakness=power? I don't know for sure...Having trouble wrapping my head around this. I never really did all that well in Algebra anyway. ;)...now back to work....
Continue Reading...