<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Infosec Events &#187; Security Workshops</title>
	<atom:link href="http://infosecevents.net/category/workshops/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Mon, 06 Feb 2012 21:35:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Information Security Events For January</title>
		<link>http://infosecevents.net/2012/01/16/information-security-events-for-january-2/</link>
		<comments>http://infosecevents.net/2012/01/16/information-security-events-for-january-2/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 16:04:48 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[CCC]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1974</guid>
		<description><![CDATA[Here are information security events in North America this month: &#160; DoD Cybercrime Conference 2012: January 20 to January 27 in Atlanta &#160; &#160; &#160; ShmooCon USA : January 27 to Januaryin Washington, DC &#160; &#160; &#160; And here are the information security events in the other parts of the world: BSides Vienna: January 21 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://www.dodcybercrime.com/12CC/register.asp"><img class="alignleft size-full wp-image-1975" title="CyberCrime Conference 2012" src="http://infosecevents.net/wp-content/uploads/2012/01/CyberCrime-Conference-2012.jpg" alt="" width="300" height="84" /></a></p>
<p>&nbsp;</p>
<p><a href="http://www.dodcybercrime.com/12CC/">DoD Cybercrime Conference 2012</a>: January 20 to January 27 in Atlanta</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://www.shmoocon.org/registration"><img class="alignleft size-full wp-image-1976" title="Shmoocon 2012" src="http://infosecevents.net/wp-content/uploads/2012/01/Shmoocon-2012.jpg" alt="" width="300" height="85" /></a></p>
<p>&nbsp;</p>
<p><a href="http://www.shmoocon.org/">ShmooCon USA</a> : January 27 to Januaryin Washington, DC</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="http://bsidesvienna2012.eventbrite.com/"><img class="alignleft size-full wp-image-1977" title="BSides logo 02" src="http://infosecevents.net/wp-content/uploads/2012/01/BSides-logo-02.jpg" alt="" width="150" height="95" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/48231836/BSidesVienna2012">BSides Vienna</a>: January 21 in Vienna</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="javascript:void(window.open('https://www.regonline.com/ecrimegermany2012','','resizable=yes,location=yes,menubar=yes,scrollbars=yes,status=yes,toolbar=yes,fullscreen=no,dependent=no'))"><img class="alignleft size-medium wp-image-1978" title="eCrime Germany" src="http://infosecevents.net/wp-content/uploads/2012/01/eCrime-Germany-300x113.jpg" alt="" width="300" height="113" /></a></p>
<p>&nbsp;</p>
<p><a href="http://www.e-crimecongress.org/germany/">eCrime Germany</a>: January 31 in Frankfurt</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1974&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/01/16/information-security-events-for-january-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 49 In Review</title>
		<link>http://infosecevents.net/2011/12/14/week-49-in-review-2/</link>
		<comments>http://infosecevents.net/2011/12/14/week-49-in-review-2/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 17:10:26 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[ClubHack]]></category>
		<category><![CDATA[Malcon]]></category>
		<category><![CDATA[PacSec]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1949</guid>
		<description><![CDATA[Events Related PacSec 2011 Presented Material &#8211; pacsec.jp English/Japanese versions of PacSec 2011 Tokyo event last month. @OWASP Tokyo Webservices: Attack, defenses, and hardening &#8211; twitter.com Archives for ClubHack 2011 Videos &#8211; clubhack.tv MalCon 2011 YouTube Channel &#8211; youtube.com Resources Opensecuritytraining.info Welcome Message &#8211; opensecuritytraining.info New open source, creative commons powered teaching portal on computer [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="http://pacsec.jp/psj11archive.html">PacSec 2011 Presented Material</a> &#8211; pacsec.jp<br />
English/Japanese versions of PacSec 2011 Tokyo event last month.</li>
<li><a href="http://twitter.com/#!/OwaspTokyo/statuses/145695411787669504">@OWASP Tokyo Webservices: Attack, defenses, and hardening</a> &#8211; twitter.com</li>
<li><a href="http://www.clubhack.tv/event/2011/">Archives for ClubHack 2011 Videos</a> &#8211; clubhack.tv</li>
<li><a href="http://www.youtube.com/user/malconlive?feature=watch">MalCon 2011 YouTube Channel</a> &#8211; youtube.com</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li><a href="http://www.opensecuritytraining.info/Welcome.html">Opensecuritytraining.info Welcome Message</a> &#8211; opensecuritytraining.info<br />
New open source, creative commons powered teaching portal on computer security.</li>
<li><a href="http://www.reddit.com/r/netsec/comments/n19en/free_commercial_security_products/">Free Commercial Security Products?</a> &#8211; reddit.com<br />
I just found out that ArcSight Logger is free for personal/home use (within some reasonable log size limits), and I&#8217;m wondering what other commercial enterprise security products are also free for personal use. I don&#8217;t mean trial/eval licenses that limit the user to 15 or 30 days, I&#8217;m looking for full blown, feature-full enterprise software that is free for personal use within reasonable limits.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://gse-compliance.blogspot.com/2011/12/router-audit-tool-rat.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+CrackedInsecureAndGenerallyBroken+%28Cracked%2C+inSecure+and+Generally+Broken%29">Router Audit Tool (RAT)</a> &#8211; gse-compliance.blogspot.com<br />
The Router Audit Tool or RAT was designed to help audit the configurations of Cisco routers quickly and efficiently. RAT tests Cisco router configurations against a baseline. After performing the baseline test, it not only provides a list of the potential security vulnerabilities discovered but also a list of commands to be applied to the router in order to correct the potential security problems discovered.</li>
<li><a href="http://www.oxid.it/downloads/ca_setup.exe">UPDATE: Cain &amp; Abel v4.9.43!</a> &#8211; www.oxid.it/downloads/ca_setup.exe<br />
Cain &amp; Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of  passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols.</li>
<li><a href="http://sourceforge.net/projects/ettercap/files/ettercap/0.7.4-Lazarus/">UPDATE: Ettercap 0.7.4!</a> &#8211;  sourceforge.net/projects/ettercap/files/ettercap/0.7.4-Lazarus/<br />
Ettercap is a multipurpose sniffer/interceptor/logger for switched LAN. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. It is a suite for man-in-the-middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.</li>
<li><a href="http://blog.taddong.com/2011/12/cookie-decoder-f5-big-ip.html">Cookie Decoder: F5 BIG-IP</a> &#8211; blog.taddong.com<br />
I still remember with excitement the first time I found my first F5 BIG-IP load balancer persistent cookie, disclosing the network details of the internal hosts: IP address and TCP port. Although it was a few years ago during a pen-test, still today is very common to find them on lots of target environments.</li>
<li><a href="http://www.manvswebapp.com/announcing-sql-invader">Announcing SQL Invader</a> &#8211; manvswebapp.com<br />
Today, we announced SQL Invader, a new free GUI-based tool that enables testers to easily and quickly exploit a SQL Injection vulnerability, get a proof of concept with database visibility and export results into a csv file. In just a few clicks, users will be able to view the list of records, tables and user accounts on the back-end database.</li>
<li><a href="http://www.vulnerabilitydatabase.com/2011/12/csrf-scanner-v1-0-released/">CSRF Scanner v1.0 Released</a> &#8211; vulnerabilitydatabse.com<br />
CSRFScan is a tool designed to find CSRF security flaws on forms. The tool uses a static analysis of pages to determine if the form is protected or not. It is written in Python and published under GPL v3. This tool analyse only forms present in an authenticated session, so it needs authenticated cookies to perform the analysis.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li>VLAN Hacking How To<br />
In Virtual LAN or VLAN is a group of hosts communicate with each other, even thoughthey are in different physical location. Virtual LAN provides location independence to the users, able to save the bandwidth, manage the device, cost effective for the organization are some of the facilities provided by the Virtual LAN.</li>
<ul>
<li><a href="http://resources.infosecinstitute.com/vlan-hacking/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">VLAN Hacking</a> - resources.infosecinstitute.com</li>
<li><a href="http://www.reddit.com/r/netsec/comments/n4v0z/vlan_hacking_tutorial/">Reddit Thread on VLAN Hacking</a> - reddit.com</li>
</ul>
</ul>
<ul>
<li><a href="http://dvlabs.tippingpoint.com/blog/2011/12/05/shellcode-detection-python?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+dvlabsblog+%28TippingPoint+DVLabs+Blog%29">Shellcode Detection Using Python</a> &#8211; dvlabs.tippingpoint.com<br />
DVLabs has been collecting a large number of documents and files that are flagged as malicious and we&#8217;re trying to decrease the number that we have to do a full manual analysis on. One of the methods we&#8217;re using to aid in this is shellcode detection.</li>
<li><a href="http://www.fishnetsecurity.com/blogs/?p=250">Path of Least Resistance </a>- fishnetsecurity.com<br />
I (Tim Medin) do a good number of internal penetration tests, and I have found one particular series of techniques that tend to be very quick and efficient at gaining Domain Administrator-level access. Of course, the viability of this depends on the environment and the configurations, and since this technique depends on default configurations, it is usually very effective because defaults aren’t usually changed.</li>
<li><a href="http://carnal0wnage.attackresearch.com/2011/12/aggressive-mode-vpn-ike-scan-psk-crack.html">Aggressive Mode VPN &#8212; IKE-Scan, PSK Crack, and Cain</a> &#8211; carnal0wnage.attackresearch.com<br />
In IKE Aggressive mode the authentication hash based on a preshared key (PSK) is transmitted as response to the initial packet of a vpn client that wants to establish an IPSec Tunnel (Hash_R). This hash is not encrypted. It&#8217;s possible to capture these packets using a sniffer, for example tcpdump and start dictionary or brute force attack against this hash to recover the PSK.</li>
<li><a href="http://resources.infosecinstitute.com/firefox-and-sqlite-forensics/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">Understanding Firefox and SQLite Tables For Computer Forensics</a> &#8211; resources.infosecinstitute.com<br />
I was showing off a trick to export Firefox SQLite tables to a spread sheet, and while she is a forensics person, she had never ever heard of this trick. It is neat enough to know when working off an image to pull the entire history of a Firefox user by using the SQLite table manager Firefox plugin. You can also find this plugin for Chrome that makes things just as easy. This article though will focus on SQLite and Firefox.</li>
<li><a href="http://carnal0wnage.attackresearch.com/2011/12/sqlmap-searching-databases-for-specific.html">SQLMap &#8212; Searching Databases for Specific Columns/Data &amp; Extracting from Specific Columns</a> &#8211; carnal0wnage.attackresearch.com<br />
So assuming we have some sort of SQL Injection in the application (Blind in this case) and we&#8217;ve previously dumped all the available databases (&#8211;dbs), we now want to search for columns with &#8216;password&#8217; in them.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li>Microsoft Updates<br />
With the release of the security bulletins for December 2011, this bulletin summary replaces the bulletin advance notification originally issued December 8, 2011. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance Notification.</li>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-dec">Microsoft Security Bulletin Summary for 2011</a> &#8211; technet.microsoft.com</li>
<li><a href="http://threatpost.com/en_us/blogs/microsoft-unveils-new-windows-defender-offline-tool-120911">Microsoft Unveils new Windows Defender Offline Tool</a> &#8211; threatpost.com</li>
</ul>
</ul>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li>Adobe, Acrobat Attacks<br />
Malicious hackers are targeting a previously unknown security hole in Adobe Reader and Acrobat to compromise Microsoft Windows machines, Adobe warned today.</li>
<ul>
<li><a href="http://krebsonsecurity.com/2011/12/attackers-hit-new-adobe-reader-acrobat-flaw/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Attackers Hit New Adobe Reader, Acrobat Flaw</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.darkreading.com/insider-threat/167801100/security/application-security/232300055/new-zero-day-adobe-attack-under-way.html">New Zero-Day Adobe Attack Under Way</a> &#8211; darkreading.com</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=12166&amp;rss">Newest Adobe Flash 11.1.102.55 And Zero Day Update</a> &#8211; isc.sans.edu</li>
</ul>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>The Carrier IQ Controversy<br />
Security researchers who have investigated the inner workings of the Carrier IQ software and its capabilities say that the application has some powerful, and potentially worrisome capabilities, but that as it&#8217;s currently deployed by carriers it doesn&#8217;t have the ability to record SMS messages, phone calls or keystrokes.</li>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/researchers-say-carrier-iq-not-logging-texts-or-emails-has-some-worrisome-capabilities-120511">Researchers Say Carrier IQ Not Logging Texts or Emails, But Has Some Worrisome Capabilities</a> - threatpost.com</li>
<li><a href="http://www.bgr.com/2011/12/06/how-to-find-out-if-carrier-iq-is-installed-on-your-phone-in-one-tap/">How to find out if Carrier IQ is installe din your phone with one tap</a> &#8211; bgr.com</li>
</ul>
<li><a href="http://www.shredderchallenge.com/">All Your Shreds Belong To Us</a> &#8211; shredderchallenge.com<br />
Today&#8217;s troops often confiscate the remnants of destroyed documents in war zones, but reconstructing them is a daunting task. DARPA&#8217;s Shredder Challenge called upon computer scientists, puzzle enthusiasts and anyone else who likes solving complex problems to compete for up to $50,000 by piecing together a series of shredded documents.</li>
<li><a href="http://www.h-online.com/security/news/item/Google-researchers-propose-way-out-of-the-SSL-dilemma-1389182.html">Google Researchers Propose Way Out Of The SSL Dilemma</a> &#8211; h-online.com<br />
In a paper entitled Certificate Authority Transparency and Auditability, Google researchers Adam Langley and Ben Laurie have proposed new measures for improving the trustworthiness of the public key infrastructure (PKI) underpinning HTTPS. The researchers&#8217; idea is based on a public list of all certificates ever issued by certificate authorities.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1949&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/12/14/week-49-in-review-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Events For October</title>
		<link>http://infosecevents.net/2011/10/01/information-security-events-for-october-2/</link>
		<comments>http://infosecevents.net/2011/10/01/information-security-events-for-october-2/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 18:29:46 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[e-Crime]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1849</guid>
		<description><![CDATA[Here are information security events in North America this month: BSides PDX: October 7 in Portland SANS Baltimore: October 9 to October 15 in Baltimore SANS NCIC: October 11 to October 15 in Washington, D.C. SecTor: October 17 to October 20 in Toronto BSides Montana: October 21 to October 22 in Jefferson City SANS Chicago: [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://bsidesportland.eventbrite.com/"><img class="alignleft size-full wp-image-1853" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/10/Bsides-logo1.jpg" alt="Bsides logo" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/40113672/BsidesPDX">BSides PDX</a>: October 7 in Portland</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23913"><img class="alignleft size-full wp-image-1859" title="SANS Baltimore" src="http://infosecevents.net/wp-content/uploads/2011/10/SANS-Baltimore.jpg" alt="SANS Baltimore" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/baltimore-2011/">SANS Baltimore</a>: October 9 to October 15 in Baltimore</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=25719"><img title="SANS NCIC" src="http://infosecevents.net/wp-content/uploads/2011/10/SANS-NCIC.jpg" alt="SANS NCIC" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/ncic-2011/">SANS NCIC</a>: October 11 to October 15 in Washington, D.C.</p>
<p><a href="http://www.sector.ca/register.htm"><img class="alignleft size-full wp-image-1850" title="SecTor logo" src="http://infosecevents.net/wp-content/uploads/2011/10/SecTor-logo.jpg" alt="SecTor logo" width="180" height="142" /></a></p>
<p><a href="http://www.sector.ca/">SecTor</a>: October 17 to October 20 in Toronto</p>
<p><a href="https://www.eventbrite.com/register?orderid=52650087830&amp;ebtv=F&amp;eid=1396283321&amp;client_token=noqueue"><img class="alignleft size-full wp-image-1851" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/10/Bsides-logo.jpg" alt="Bsides logo" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/35094907/BSidesMo">BSides Montana</a>: October 21 to October 22 in Jefferson City</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=24233"><img class="alignleft size-full wp-image-1860" title="SANS Chicago" src="http://infosecevents.net/wp-content/uploads/2011/10/SANS-Chicago.jpg" alt="SANS Chicago" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/chicago-2011/special.php">SANS Chicago</a>: October 23 to October 28 Chicago</p>
<p>&nbsp;</p>
<p><a href="http://infosecevents.net/wp-content/uploads/2011/10/Bsides-logo2.jpg"><img class="alignleft size-full wp-image-1854" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/10/Bsides-logo2.jpg" alt="Bsides logo" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/26298468/BSidesKC">BSides KC</a>: October 26 in Johnson County</p>
<p>&nbsp;</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=24358"><img class="alignleft size-full wp-image-1858" title="SANS Gulf Region" src="http://infosecevents.net/wp-content/uploads/2011/10/SANS-Gulf-Region.jpg" alt="SANS Gulf Region" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/gulf-region-2011/">SANS Gulf Region</a>: October 8 to October 22 in Dubai</p>
<p><a href="http://infosecevents.net/wp-content/uploads/2011/10/e-crime-turkey-logo.jpg"><img class="alignleft size-full wp-image-1862" title="e crime turkey logo" src="http://infosecevents.net/wp-content/uploads/2011/10/e-crime-turkey-logo.jpg" alt="e crime turkey logo" width="230" height="85" /></a></p>
<p><a href="http://www.e-crimecongress.org/turkey/en/">e-Crime Turkey</a>: October 12 in Istanbul</p>
<p><a href="https://conference.hitb.org/hitbsecconf2011kul/register/"><img class="alignleft size-full wp-image-1852" title="HITB logo" src="http://infosecevents.net/wp-content/uploads/2011/10/HITB-logo.jpg" alt="HITB logo" width="230" height="69" /></a></p>
<p><a href="http://conference.hitb.org/hitbsecconf2011kul/">HITBSecConf 2011 Malaysia</a>: October 10 to October 14 in Kuala Lumpur</p>
<p><a href="http://www.sans.org/singapore-sos-2011/reg-options.php"><img class="alignleft size-full wp-image-1856" title="SANS Singapore" src="http://infosecevents.net/wp-content/uploads/2011/10/SANS-Singapore.jpg" alt="SANS Singapore" width="180" height="78" /></a></p>
<p style="text-align: left;"><a href="http://www.sans.org/singapore-sos-2011/">SANS Singapore SOS</a>: October 10 to October 18 in Singapore</p>
<p style="text-align: left;"><a href="http://www.regonline.co.uk/ecrimemidyearmeeting"><img class="alignleft size-full wp-image-1861" title="e crime logo" src="http://infosecevents.net/wp-content/uploads/2011/10/e-crime-logo.jpg" alt="e crime logo" width="230" height="88" /></a></p>
<p style="text-align: left;"><a href="http://www.e-crimecongress.org/forum/">e-Crime Mid-Year Meeting</a>: October 20 in London</p>
<p><a href="http://www.securitybsides.com/w/page/28106141/BSidesNewDelhi"><img class="alignleft size-full wp-image-1855" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/10/Bsides-logo3.jpg" alt="Bsides logo" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/28106141/BSidesNewDelhi">BSides New Delhi</a>: October 22 to October 23 in new Delhi</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1849&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/10/01/information-security-events-for-october-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Events For September</title>
		<link>http://infosecevents.net/2011/09/01/information-security-events-for-september-2/</link>
		<comments>http://infosecevents.net/2011/09/01/information-security-events-for-september-2/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 23:28:43 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[RAID]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1817</guid>
		<description><![CDATA[Here are information security events in North America this month: SANS Las Vegas: Septemer 17 to September 26 in Las Vegas RAID 2011: September 20 to September 21 in Menlo Park AppSEC USA 2011: September 20 to September 24 in Minneapolis DerbyCon: September 30 to October 3 in Louisville &#160; And here are the information [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=10313"><img class="alignleft size-full wp-image-1821" title="SANS Las Vegas" src="http://infosecevents.net/wp-content/uploads/2011/09/SANS-Las-Vegas.jpg" alt="SANS Las Vegas" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/network-security-2011/">SANS Las Vegas</a>: Septemer 17 to September 26 in Las Vegas</p>
<p><a href="http://www.regonline.com/Register/Checkin.aspx?EventID=964470"><img class="alignleft size-full wp-image-1818" title="Raid 2011" src="http://infosecevents.net/wp-content/uploads/2011/09/Raid-2011.jpg" alt="Raid 2011" width="200" height="94" /></a></p>
<p><a href="http://raid2011.org/">RAID 2011</a>: September 20 to September 21 in Menlo Park</p>
<p><a href="http://www.appsecusa.org/attend.html"><img class="alignleft size-full wp-image-1819" title="AppSec-USA.gif" src="http://infosecevents.net/wp-content/uploads/2011/09/AppSec-USA.gif.jpg" alt="AppSec-USA.gif" width="230" height="36" /></a></p>
<p><a href="http://www.appsecusa.org/">AppSEC USA 2011</a>: September 20 to September 24 in Minneapolis</p>
<p><a href="http://www.derbycon.com/registration/"><img class="alignleft size-full wp-image-1820" title="DerbyCon logo" src="http://infosecevents.net/wp-content/uploads/2011/09/DerbyCon-logo.jpg" alt="DerbyCon logo" width="280" height="107" /></a></p>
<p><a href="http://www.derbycon.com/">DerbyCon</a>: September 30 to October 3 in Louisville</p>
<p>&nbsp;</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=24799"><img class="alignleft size-full wp-image-1822" title="SANS Delhi" src="http://infosecevents.net/wp-content/uploads/2011/09/SANS-Delhi.jpg" alt="SANS Delhi" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/delhi-2011/location.php">SANS Delhi</a>: September 12 to September 17 in Delhi</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23203"><img class="alignleft size-full wp-image-1823" title="SANS London" src="http://infosecevents.net/wp-content/uploads/2011/09/SANS-London.jpg" alt="SANS London" width="200" height="87" /></a></p>
<p><a href="http://www.sans.org/eu-forensic-incident-resp-summit-2011/">SANS Incident Response Summit</a>: September 21 to September 27 in London</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1817&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/09/01/information-security-events-for-september-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 31 In Review</title>
		<link>http://infosecevents.net/2011/08/08/week-31-in-review/</link>
		<comments>http://infosecevents.net/2011/08/08/week-31-in-review/#comments</comments>
		<pubDate>Mon, 08 Aug 2011 18:12:48 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[DEFCON]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1795</guid>
		<description><![CDATA[Events Related Notes from BlackHat 2011 Below are more than a dozen updates and resource portals for the recently concluded BlackHat conference. Tavis Ormandy&#8217;s Sophail Presentation &#8211; anti-virus-rants.blogspot.com BlackHat 2011 Presentation &#8211; sensepost.com Black Hat USA 2011 &#8211; f-secure.com BH2011: Hacking Google Chome OS &#8211; nakedsecurity.sophos.com BlackHat 2011: Macs in the age of the APT [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li>Notes from BlackHat 2011<br />
Below are more than a dozen updates and resource portals for the recently concluded BlackHat conference.</li>
<ul>
<li><a href="http://anti-virus-rants.blogspot.com/2011/08/tavis-ormandys-sophail-presentation.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Anti-virusRants+(anti-virus+rants)">Tavis Ormandy&#8217;s Sophail Presentation</a> &#8211; anti-virus-rants.blogspot.com</li>
<li><a href="http://www.sensepost.com/blog/5964.html">BlackHat 2011 Presentation</a> &#8211; sensepost.com</li>
<li><a href="http://www.f-secure.com/weblog/archives/00002209.html">Black Hat USA 2011</a> &#8211; f-secure.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/08/04/bh-2011-hacking-google-chromeos/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+NakedSecurityChesterWisniewski+(Sophos+Naked+Security+%C2%BB+Chester+Wisniewski)">BH2011: Hacking Google Chome OS</a> &#8211; nakedsecurity.sophos.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/08/03/black-hat-2011-macs-in-the-age-of-the-apt/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+NakedSecurityChesterWisniewski+(Sophos+Naked+Security+%C2%BB+Chester+Wisniewski)">BlackHat 2011: Macs in the age of the APT</a> &#8211; nakedsecurity.sophos.com</li>
<li><a href="http://www.digitalbond.com/2011/08/04/beresford-black-hat-part-i-details/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+digitalbond/oLPM+(Digital+Bond)">Beresford @ Black Hat Part 1: Details</a> &#8211; digitalbond.com</li>
<li><a href="http://www.digitalbond.com/2011/08/04/beresford-black-hat-part-ii-gurus-politics-and-ics-response/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+digitalbond/oLPM+(Digital+Bond)">Beresford @ Black Hat Part 2: Guru&#8217;s, Politics, and ICS Response</a> &#8211; digitalbond.com</li>
<li><a href="http://www.slideshare.net/dakami/black-ops-of-tcpip-2011-black-hat-usa-2011">Dan Kaminsky on Black Ops of TCP/IP</a> &#8211; slideshare.net</li>
<li><a href="http://www.accuvant.com/capability/accuvant-labs/security-research/featured-presentation">Battery Firmware Hacking , Dr. Charlie Miller </a>- accuvant.com</li>
<li><a href="http://blog.securestate.com/post/2011/08/01/Done28099t-Drop-the-SOAP-Real-World-Web-Service-Testing-for-Web-Hackers-at-Black-Hat-USA.aspx">Don&#8217;t Drop the Soap Real World Web Service Testing</a> &#8211; blog.securestate.com</li>
<li><a href="http://blog.security4all.be/2011/08/how-to-follow-blackhat-defcon-bsideslv.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Security4all+(Security4all)">How To Follow Blackhat/Defcon/BsidesLV Without Being There</a> - blog.security4all.be</li>
<li><a href="http://news.cnet.com/8301-27080_3-20088947-245/attacking-home-automation-networks-over-power-lines/?part=rss&amp;tag=feed&amp;subj=News-Security">Attacking Home Automation Networks Over Power Lines</a> &#8211; news.cnet.com</li>
<li><a href="http://download.cnet.com/8301-2007_4-20087850-12/when-hacking-chrome-its-all-about-your-data/?part=rss&amp;tag=feed&amp;subj=News-Security">When Hacking Chrome it&#8217;s All About Your Data</a> &#8211; download.cnet.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20087589-245/microsoft-offers-$250000-for-security-defense-research/?part=rss&amp;tag=feed&amp;subj=News-Security">Microsoft Offers $250,000 for security defense research</a> &#8211; news.cnet.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20087201-245/researchers-warn-of-scada-equipment-discoverable-via-google/?part=rss&amp;tag=feed&amp;subj=News-Security">Researchers Warn of SCADA equipment discoverable via Google </a>- news.cnet.com</li>
<li><a href="http://www.darkreading.com/security/news/231300289/at-black-hat-mobile-devices-under-the-microscope.html">At BlackHat Mobile Devices Under The Microscope</a> &#8211; darkreading.com</li>
<li><a href="http://intrepidusgroup.com/insight/2011/08/apple-mdm-talk/">Strengths And Weaknesses of Apple&#8217;s MDM Systems</a> &#8211; intrepidusgroup.com</li>
</ul>
<li>BlackHat 2011 Highlight: DIY Hacking UAV<br />
Yesterday at Black Hat, two security researchers demonstrated how a radio-controlled model airplane outfitted with a computer and 4G connectivity could be used to create a nearly undetectable aerial hacking device that could perpetrate aerial attacks on targets otherwise unreachable by land.</li>
<ul>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/vulnerabilities/231300240/wardriving-evolves-into-warflying.html?itc=edit_stub">Wardriving Evolves Into Warflying</a> - darkreading.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/08/blackhat-drone/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">DIY Spy Drone Sniffs WiFi, Intercepts Phone Calls</a> - wired.com</li>
</ul>
<li>BlackHat 2011 Highlight: The Problem With Square Card Readers<br />
Security researchers at the Black Hat Briefings demonstrated a method for turning purloined credit card information into cash, this time using Square, a free credit card reader that promises to turn anyone with a mobile device into a merchant capable of accepting credit card payments.</li>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/black-hat-square-mobile-card-reader-provides-straight-line-illicit-cash-080411">Researcher: Square Card Reader Provides Avenue To Illicit Cash?</a> - threatpost.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20088441-245/researchers-find-avenues-for-fraud-in-square/?part=rss&amp;tag=feed&amp;subj=News-Security">Researchers Find Avenues For Fraud In Square</a> - news.cnet.com</li>
</ul>
<li>BlackHat 2011 Highlight: The Shocking Siemens Vulnerability<br />
A researcher&#8230;has discovered a number of vulnerabilities in programmable logic controllers (PLCs) from Siemens that are used to automate mechanical devices in utilities, power plants, and other industrial control environments and which could be remotely controlled to cause damage if connected to the Internet.</li>
<ul>
<li><a href="http://news.cnet.com/8301-27080_3-20087833-245/researcher-demos-attacks-on-siemens-industrial-control-systems/?part=rss&amp;tag=feed&amp;subj=News-Security">Researcher demos attack on Siemens industrial control system</a> - news.cnet.com</li>
<li><a href="http://www.digitalbond.com/2011/08/01/making-sense-of-siemens-vulnerability-conflationconfusion/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+digitalbond/oLPM+(Digital+Bond)">Making Sense of Siemens&#8217; Vulnerability Conflation/Confusion</a> - digitalbond.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/08/siemens-hardcoded-password/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">Hard Coded Passwords And Other Security Holes Found In Siemens Control Systems</a> - wired.com</li>
</ul>
<li>DefCon 19<br />
Notes and news about DefCon 19</li>
<ul>
<li><a href="http://vulnfactory.org/research/defcon-remote.pdf">Dan Rosenug Remote Kernel Exploitation Slides from DefCon 19</a> - vulnfactory.org</li>
<li><a href="http://www.cnn.com/2011/TECH/web/08/05/def.con.hackers/index.html?hpt=hp_abar">DefCon: The Event That Scares Hackers</a> &#8211; cnn.com</li>
<li><a href="http://blog.security4all.be/2011/08/how-to-follow-blackhat-defcon-bsideslv.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Security4all+(Security4all)">How To Follow Blackhat/Defcon/BsidesLV Without Being There</a> - blog.security4all.be</li>
<li><a href="http://download.cnet.com/8301-2007_4-20089152-12/10-year-old-hacker-finds-zero-day-flaw-in-games/?part=rss&amp;tag=feed&amp;subj=News-Security">10 year old hacker finds zero day exploit in games</a> &#8211; download.cnet.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20089123-245/android-could-allow-mobile-ad-or-phishing-pop-ups/?part=rss&amp;tag=feed&amp;subj=News-Security">Android could allow mobile ad or phishing pop ups </a>- news.cnet.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/08/hacking-home-automation/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">Hacking Home Automation Systems Through Your Power Lines</a> &#8211; wired.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20086690-245/defcon-kids-joins-adult-hacker-conferences/?part=rss&amp;tag=feed&amp;subj=News-Security">DefCon Kids Join Adult Hacker Conferences</a> &#8211; news.cnet.com</li>
<li><a href="http://it.toolbox.com/blogs/securitymonkey/defcon-19-presentations-pdf-downloads-47788?rss=1">DefCon 19 presentations (PDF)</a> &#8211; it.toolbox.com</li>
</ul>
<li><a href="http://blog.security4all.be/2011/08/how-to-follow-blackhat-defcon-bsideslv.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Security4all+(Security4all)">How To Follow Blackhat/Defcon/BsidesLV Without Being There</a> - blog.security4all.be<br />
Well, I&#8217;m one of the poor souls who couldn&#8217;t make it to the Blackhat/Defcon / SecurityBsides fun. There are some ways to follow the events in Vegas (real time). The first tool is to use twitter and follow the hashtags #defcon, #blackhat and #bsideslv. If you have a twitter account, I would recommend installing tweetdeck and setting up 3 search columns.</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li><a href="http://diniscruz.blogspot.com/2011/08/owasp-o2-platform-history-so-far-sep.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+DinisCruzBlog+(Dinis+Cruz+blog)">OWASP O2 Platform the History So Far</a>- diniscruz.blogspot.com
<div>For the past couple years I have been using this personal blog to document O2 Platform&#8217;s history. Here are the most important blog posts, ordered chronologically and with some additional comments (made in August 2011).</div>
</li>
<li><a href="http://nakedsecurity.sophos.com/2011/08/05/tavis-ormandy-and-sophos/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+NakedSecurityGrahamCluley+(Sophos+Naked+Security+%C2%BB+Graham+Cluley)">Tavis Ormandy and Sophos</a> &#8211; nakedsecurity.sophos.com<br />
As a security company keeping our customers safe is our primary responsibility, therefore we investigate all vulnerability reports and implement the best course of action in order to protect our customers. Recently, researcher Tavis Ormandy contacted us about an examination he was doing of Sophos&#8217;s anti-virus product &#8211; not in terms of possible vulnerabilities &#8211; but instead looking at how various components of it were implemented.</li>
<li><a href="http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html">The Scanning Legion: Web Application Scanners Accuracy Assessment &amp; Feature Comparison Commercial &amp; Open Source Scanners</a> &#8211; sectooladdict.blogspot.com<br />
I&#8217;ve always been curious about it… from the first moment I executed a commercial scanner, almost seven years ago, to the day I started performing this research. Although manual penetration testing has always been the main focus of the test, most of us use automated tools to easily detect &#8220;low hanging fruit&#8221; exposures, increase the coverage when testing large scale applications in limited timeframes and even to double check locations that were manually tested. The questions always pops up, in every penetration test in which these tools are used.</li>
<li><a href="http://dvws.secureideas.net/downloads/index.html">Damn Vulnerable Web Services</a> &#8211; dvws.secureideas.net/downloads/index.html<br />
In this presentation Tom, Josh and Kevin will discuss the new security issues with web services and release an updated web service testing methodology that will be integrated into the OWASP testing guide, new Metasploit modules and exploits for attacking web services and a open source vulnerable web service for the Samurai-WTF (Web Testing Framework).</li>
<li><a href="http://blogs.cisco.com/security/cisco-2q11-global-threat-report/#utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=cisco-2q11-global-threat-report">Cisco 2Q11 Global Threat Report</a> &#8211; blogs.cisco.com<br />
Data breaches dominated security news during the first half of 2011 and companies across all industry sectors were equally impacted. Many of these breaches resulted from advanced persistent threats; others resulted from SQL injection and other brute force intrusions. In all cases, customer data and corporate intellectual property were at risk.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish 2.03b!</a> - code.google.com/p/skipfish/downloads/list<br />
Skipfish is a fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://www.oxid.it/downloads/ca_setup.exe">UPDATE: Cain and Abel v4.9.41!</a> &#8211; oxit.it/downloads/ca_setup.exe<br />
Cain &amp; Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of  passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols.</li>
<li><a href="http://www.ollydbg.de/odbg201b.zip">UPDATE: OllyDbg 2.01 Alpha 4!</a> &#8211; ollydbg.de/odbg201b.zip<br />
OllyDbg is a 32-bit assembler level analysing debugger for Microsoft® Windows®. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable.</li>
<li><a href="http://www.secmaniac.com/download/">UPDATE: The Social Engineer Toolkit v2.0!</a> &#8211; secmaniac.com/download<br />
The Social Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing. It’s main purpose is to augment and simulate social-engineering attacks and allow the tester to effectively test how a targeted attack may succeed.</li>
<li><a href="http://cat.contextis.co.uk/cat/CAT_Version_1.msi">UPDATE: Context App Tool v1!</a> &#8211; cat.contextis.co.uk/cat/CAT_Version_1.msi<br />
Context App Tool or CAT is designed to facilitate manual web application penetration testing for more complex, demanding application testing tasks. It removes some of the more repetitive elements of the testing process, allowing the tester to focus on individual applications, thus enabling them to conduct a much more thorough test.</li>
<li><a href="http://sourceforge.net/projects/agnitiotool/files/">UPDATE: Agnitio v2.0</a>! &#8211; sourceforge.net/projects/agnitiotool/files/<br />
Agnitio is a tool to help developers and security professionals conduct manual security code reviews in a consistent and repeatable way. It aims to replace the adhoc nature of manualsecurity code review documentation, create an audit trail and reporting.</li>
<li><a href="http://download.cnet.com/https-everywhere/3000-11745_4-75211397.html">HTTPS Everywhere opens to all</a> &#8211; download.cnet.com<br />
The security add-on for Firefox called HTTPS Everywhere (download) that forces HTTPS encryption on numerous popular Web sites has graduated to its first stable release, about a year after it was released into public beta.</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2011/08/01/metasploit-40-released?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+metasploit/blog+(Metasploit+Blog)">Metasploit Framework 4.0 Released! </a>- community.rapid7.com<br />
It&#8217;s been a long road to 4.0. The first 3.0 release was almost 5 years ago and the first release under the Rapid7 banner was almost 2 years ago. Since then, Metasploit has really spread its wings. When 3.0 was released, it was under a EULA-like license with specific restrictions against using it in commercial products.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://zeroknock.blogspot.com/2011/08/framebusting-dual-protection-core.html">Framebusting-the dual protection core</a> &#8211; zeroknock.blogspot.com<br />
Since the outcome of ClickJacking attacks, framebusting has become the unavoidable part of web application security. Considering the real world scenario, it has been noticed that still the appropriate protections have not been placed in the plethora of websites.</li>
<li><a href="http://zeroknock.blogspot.com/2011/08/sql-injection-php-escaping-and-like.html">SQL Injection (Primer 1) PHP Escaping And Light Operators </a>- zeroknock.blogspot.com<br />
This post talks about exploiting the SQL queries with LIKE operator in use. However, this situation and target can be specific in nature but one can use the concept that is discussed below to go after exploiting the SQL injection.</li>
<li><a href="http://diniscruz.blogspot.com/2011/08/injecting-o2-into-net-process-in-this.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+DinisCruzBlog+(Dinis+Cruz+blog)">Injecting O2 into an .NET Process, in this case IBM Rational AppScan standard</a> &#8211; diniscruz.blogspot.com<br />
Of course that this is just the beginning! Now that we have the full O2 scripting capabilities inside the AppScan .NET process, there is A LOT that can be done (namely the integration with .NET Static Analysis data).</li>
<li><a href="http://pentestmonkey.net/cheat-sheet/john-the-ripper-hash-formats?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+pentestmonkey+(pentestmonkey.net+RSS+Feed)">John The Ripper Hash Formats </a>- pentestmonkey.net<br />
John the Ripper is a favourite password cracking tool of many pentesters.  There is plenty of documentation about its command line options. I’ve encountered the following problems using John the Ripper.  These are not problems with the tool itself, but inherent problems with pentesting and password cracking in general.</li>
<li><a href="http://mnin.blogspot.com/2011/06/examining-stuxnets-footprint-in-memory.html">Stuxnet Footprint In Memory With Volatility 2.0</a> &#8211; mnin.blogspot.com<br />
In this blog post, we&#8217;ll examine Stuxnet&#8217;s footprint in memory using Volatility 2.0. A talk was given at Open Memory Forensics Workshop on this topic (see the online Prezi) and the details will be shared here for anyone who missed it.</li>
</ul>
<p><strong>Vulnerabilities<br />
</strong></p>
<ul>
<li>Tim Thumb<br />
A zero-day in a very commonly used WordPress library hit quite a few news sites. The flaw is in an image utility called TimThumb which is used in a LOT of premium themes for generating on the fly thumbnails.</li>
<ul>
<li><a href="http://www.darknet.org.uk/2011/08/zero-day-vulnerability-in-timthumb-image-utility-threatens-many-wordpress-sites/">Zero Day Vulnerability In Tim Thumb Image Utility Threatens Many WordPress Sites</a> - darknet.org.uk</li>
<li><a href="http://r00tsec.blogspot.com/2011/08/timthumbphp-security-vulnerability.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+r00tsecblog+(Computer+Security+Blog)">Timthumb.php Security Vulnerability</a> - r00tsec.blogspot.com</li>
<li><a href="http://markmaunder.com/2011/zero-day-vulnerability-in-many-wordpress-themes/">Zero Day vulnerability in many WordPress themes</a> &#8211; markmaunder.com</li>
</ul>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>Shady RAT Revealed!<br />
Computer security company McAfee has said that it has discovered a massive global cyber spying operation targeting several US government departments, the UN and other governments across the world for five years or more.</li>
<ul>
<li><a href="http://security.cbronline.com/news/mcafee-uncovers-massive-global-cyber-snoop-030811">McAfee Uncovers Massive Global Cyber Snoop</a> &#8211; security.cbronline.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20087268-245/global-cyber-espionage-operation-uncovered/?part=rss&amp;tag=feed&amp;subj=News-Security">Global cyber espionage operation uncovered </a>- news.cnet.com</li>
<li><a href="http://www.computerworld.com/s/article/9218910/_Shady_RAT_hacking_claims_overblown_say_security_firms?source=rss_security&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+computerworld/s/feed/topic/82+(Computerworld+Cybercrime+and+Hacking+News)">Shady RAT hacking claims overblown says security firm</a> &#8211; computerworld.com</li>
</ul>
<li><a href="http://news.cnet.com/8301-27080_3-20087265-245/android-users-twice-as-likely-to-see-malware-than-six-months-ago/?part=rss&amp;tag=feed&amp;subj=News-Security">Android Users Twice As Likely To See Malware Than Six Months Ago</a> &#8211; news.cnet.com<br />
If you&#8217;ve got an Android you are 2.5 times more likely to encounter malware on the device today than six months ago, while mobile users have a 30 percent likelihood of clicking on a malicious link, according to a report released today from mobile security firm Lookout.</li>
<li><a href="http://www.acunetix.com/blog/news/anonymous-hack-us-department-of-defence-analysis/">Anonymous Hacks US Department of Defense: Analysis of the Attack</a> &#8211; acunetix.com<br />
On the 12th of July 2011, Booz Allen Hamilton the largest U.S. military defence contractor admitted that they had just suffered a very serious security breach, at the hands of hacktivist group AntiSec. Operation Anti-Security (AntiSec) is a hacking operation, carried out by two of the biggest names in the black-hat world – Anonymous, and LulzSec.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1795&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/08/08/week-31-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Events For August</title>
		<link>http://infosecevents.net/2011/08/01/information-security-events-for-august-2/</link>
		<comments>http://infosecevents.net/2011/08/01/information-security-events-for-august-2/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 15:50:49 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1777</guid>
		<description><![CDATA[Here are information security events in North America this month: BSides Las Vegas: August 3 to August 5 in Las Vegas DefCon 19: August 4 to August 8 in Las Vegas SANS Boston: August 6 to August 15 in Boston BSides Los Angeles: August 18 to August 20 in Los Angeles SANS Security Architecture: August [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://www.securitybsides.com/w/page/37015560/BSidesLV%202011"><img class="alignleft size-full wp-image-1779" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/08/Bsides-logo.jpg" alt="" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/37015560/BSidesLV%202011">BSides Las Vegas</a>: August 3 to August 5 in Las Vegas</p>
<p><a href="http://www.defcon.org/html/defcon-19/dc-19-index.html"><img class="alignleft size-full wp-image-1781" title="Defcon19 logo" src="http://infosecevents.net/wp-content/uploads/2011/08/Defcon19-logo.jpg" alt="" width="230" height="74" /></a></p>
<p><a href="http://www.defcon.org/html/defcon-19/dc-19-index.html">DefCon 19</a>: August 4 to August 8 in Las Vegas</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23418"><img class="alignleft size-full wp-image-1782" title="Sans Boston logo" src="http://infosecevents.net/wp-content/uploads/2011/08/Sans-Boston-logo.jpg" alt="" width="150" height="65" /></a></p>
<p><a href="http://www.sans.org/boston-2011/?utm_source=offsite&amp;utm_medium=EventListing&amp;utm_content=20110323_TE_3232011_Boston11_Lanyrd&amp;utm_campaign=SANS_Boston_2011&amp;ref=73424">SANS Boston</a>: August 6 to August 15 in Boston</p>
<p><a href="http://www.securitybsides.com/BSidesLosAngeles"><img class="alignleft size-full wp-image-1780" title="Bsides logo" src="http://infosecevents.net/wp-content/uploads/2011/08/Bsides-logo1.jpg" alt="" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/BSidesLosAngeles">BSides Los Angeles</a>: August 18 to August 20 in Los Angeles</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=25098"><img class="alignleft size-full wp-image-1785" title="SANS Washington" src="http://infosecevents.net/wp-content/uploads/2011/08/SANS-Washington.jpg" alt="" width="150" height="65" /></a></p>
<p><a href="http://www.sans.org/baking-security-applications-networks-2011/">SANS Security Architecture</a>: August 29 to August 30 in Washington, DC</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23908"><img class="alignleft size-full wp-image-1784" title="SANS Virginia Beach" src="http://infosecevents.net/wp-content/uploads/2011/08/SANS-Virginia-Beach.jpg" alt="" width="150" height="65" /></a></p>
<p><a href="https://www.sans.org/virginia-beach-2011/?utm_source=offsite&amp;utm_medium=EventListing&amp;utm_content=20110323_TE_3232011_VB11_Solut&amp;utm_campaign=SANS_Virginia_Beach_2011_&amp;ref=73639">SANS Virginia Beach</a>: August 22 to September 2 in Virginia Beach.</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="http://events.ccc.de/2011/07/18/hurry-up-if-you-dont-have-a-camp-ticket-yet/"><img class="alignleft size-full wp-image-1778" title="Chaos Communication Camp" src="http://infosecevents.net/wp-content/uploads/2011/08/Chaos-Communication-Camp.jpg" alt="Chaos Communication Camp" width="230" height="59" /></a></p>
<p><a href="http://events.ccc.de/">Chaos Communication Camp 2011</a>: August 10 to August 14 in Finowfurt, Berlin, Germany</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1777&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/08/01/information-security-events-for-august-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Events For July</title>
		<link>http://infosecevents.net/2011/07/01/information-security-events-for-july-2/</link>
		<comments>http://infosecevents.net/2011/07/01/information-security-events-for-july-2/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 18:58:38 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[RECON]]></category>
		<category><![CDATA[SANSFIRE]]></category>
		<category><![CDATA[SOUPS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1743</guid>
		<description><![CDATA[Here are information security events in North America this month: ReCon 2011: July 8 to July 11 in Montreal SANSFIRE 2011: July 15 to July 25 in Washinton, DC SOUPS 2011: July 20 to July 23 in Pittsburgh TRISC 2011: July 24 to July 27 in Austin PETS 2011: July 27 to July 30 in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://recon.cx/2011/conference.html"><img class="alignleft size-full wp-image-1749" title="Recon logo" src="http://infosecevents.net/wp-content/uploads/2011/07/Recon-logo.jpg" alt="Recon logo" width="150" height="242" /></a></p>
<p><a href="http://recon.cx/">ReCon 2011</a>: July 8 to July 11 in Montreal</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=10343"><img class="alignleft size-full wp-image-1747" title="Sansfire" src="http://infosecevents.net/wp-content/uploads/2011/07/Sansfire.jpg" alt="Sansfire" width="200" height="87" /></a></p>
<p><a href="http://www.sans.org/sansfire-2011/">SANSFIRE 2011</a>: July 15 to July 25 in Washinton, DC</p>
<p><a href="http://cups.cs.cmu.edu/soups/2011/register.html"><img class="alignleft size-full wp-image-1748" title="Soups logo" src="http://infosecevents.net/wp-content/uploads/2011/07/Soups-logo.jpg" alt="Soups logo" width="129" height="146" /></a></p>
<p><a href="http://cups.cs.cmu.edu/soups/2011/">SOUPS 2011</a>: July 20 to July 23 in Pittsburgh</p>
<p><a href="http://www.cvent.com/events/trisc-2011-conference-training/event-summary-cc5fbd31d60443aa82d30d0abef39d0d.aspx"><img class="alignleft size-full wp-image-1746" title="TRISC logo" src="http://infosecevents.net/wp-content/uploads/2011/07/TRISC-logo.jpg" alt="TRISC logo" width="180" height="157" /></a></p>
<p><a href="http://trisc.org/">TRISC 2011</a>: July 24 to July 27 in Austin</p>
<p><a href="http://petsymposium.org/2011/registration.php"><img class="alignleft size-medium wp-image-1745" title="PETS logo" src="http://infosecevents.net/wp-content/uploads/2011/07/PETS-logo-300x30.jpg" alt="PETS logo" width="300" height="30" /></a></p>
<p><a href="http://petsymposium.org/2011/">PETS 2011</a>: July 27 to July 30 in Waterloo</p>
<p><a href="http://www.blackhat.com/html/bh-us-11/registration/bh-us-11-registration.html"><img class="alignleft size-full wp-image-1744" title="Black Hat masthead" src="http://infosecevents.net/wp-content/uploads/2011/07/Black-Hat-masthead.jpg" alt="Black Hat masthead" width="300" height="131" /></a></p>
<p><a href="http://www.blackhat.com/html/bh-us-11/bh-us-11-home.html">Black Hat Las Vegas</a>: July 30 to August 5 in Las Vegas</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23963"><img class="alignleft size-full wp-image-1750" title="Sans Canberra" src="http://infosecevents.net/wp-content/uploads/2011/07/Sans-Canberra.jpg" alt="Sans Canberra" width="210" height="90" /></a></p>
<p><a href="http://www.sans.org/canberra-2011/">SANS Canberra</a>: July 1 to July 9 in Canberra</p>
<p><a href="http://www.syscan.org/index.php/cn"><img class="alignleft size-medium wp-image-1751" title="SyScan" src="http://infosecevents.net/wp-content/uploads/2011/07/SyScan-300x114.jpg" alt="SyScan" width="300" height="114" /></a></p>
<p><a href="http://www.syscan.org/index.php/cn">SyScan China 2011</a>: July 21 to 22 in Shanghai</p>
<p><a href="https://sans-japan.jp/register/en/session.aspx"><img class="alignleft size-full wp-image-1752" title="Sans Tokyo" src="http://infosecevents.net/wp-content/uploads/2011/07/Sans-Tokyo.jpg" alt="Sans Tokyo" width="200" height="87" /></a></p>
<p><a href="http://www.sans.org/tokyo-summer-2011/">SANS Tokyo Summer 2011</a>: July 25 to July 30 in Tokyo</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1743&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/07/01/information-security-events-for-july-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Events For June</title>
		<link>http://infosecevents.net/2011/06/02/information-security-events-for-june/</link>
		<comments>http://infosecevents.net/2011/06/02/information-security-events-for-june/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 07:26:29 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[SummerCon]]></category>
		<category><![CDATA[ToorCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1686</guid>
		<description><![CDATA[Here are information security events in North America this month: BSides Detroit: June 3 to June 5 Detroit Techno Security &#38; Digital Investigations Conference: June 5 to June 8 in Myrtle Beach SANS What Works In Forensics and Incident Response Summit 2011: June 7 to June 15 in Austin SummerCon: June 10 to June 13 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://www.securitybsides.com/w/page/34031395/BSidesDetroitConversations"><img class="alignleft size-full wp-image-1688" title="Bsides Detroit logo" src="http://infosecevents.net/wp-content/uploads/2011/06/Bsides-Detroit-logo.jpg" alt="Bsides Detroit logo" width="150" height="106" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/33949981/BSidesDetroit">BSides Detroit</a>: June 3 to June 5 Detroit</p>
<p><a href="http://www.thetrainingco.com/html/Security%20Conference%202011.html"><img class="alignleft size-full wp-image-1689" title="Techno Security logo" src="http://infosecevents.net/wp-content/uploads/2011/06/Techno-Security-logo.jpg" alt="Techno Security logo" width="250" height="86" /></a></p>
<p><a href="http://www.thetrainingco.com/html/Security%20Conference%202011.html">Techno Security &amp; Digital Investigations Conference</a>: June 5 to June 8 in Myrtle Beach</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23213"><img class="alignleft size-medium wp-image-1690" title="Sans Forensics" src="http://infosecevents.net/wp-content/uploads/2011/06/Sans-Forensics-300x68.jpg" alt="Sans Forensics" width="300" height="68" /></a></p>
<p><a href="http://www.sans.org/forensics-incident-response-summit-2011/">SANS What Works In Forensics and Incident Response Summit 2011</a>: June 7 to June 15 in Austin</p>
<p><a href="http://www.summercon.org/conference.html"><img class="alignleft size-medium wp-image-1691" title="Summercon logo" src="http://infosecevents.net/wp-content/uploads/2011/06/Summercon-logo-300x71.jpg" alt="Summercon logo" width="300" height="71" /></a></p>
<p><a href="http://www.summercon.org/">SummerCon</a>: June 10 to June 13 in New York</p>
<p><a href="http://www.securitybsides.com/w/page/36747375/BSidesCT"><img class="alignleft size-full wp-image-1692" title="Bsides" src="http://infosecevents.net/wp-content/uploads/2011/06/Bsides.jpg" alt="Bsides" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/36747375/BSidesCT">BSides Connecticut</a>: June 11 to June 12 in Meriden</p>
<p><a href="http://seattle.toorcon.org/2011/registration.php"><img class="alignleft size-full wp-image-1693" title="Toorcon Seattle" src="http://infosecevents.net/wp-content/uploads/2011/06/Toorcon-Seattle.jpg" alt="Toorcon Seattle" width="241" height="96" /></a></p>
<p><a href="http://seattle.toorcon.org/2011/about.php">ToorCon Seattle 2011</a>: June 18 to June 20 in Seattle</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="http://www.athcon.org/register/"><img class="alignleft size-full wp-image-1694" title="AthCon logo" src="http://infosecevents.net/wp-content/uploads/2011/06/AthCon-logo.jpg" alt="AthCon logo" width="221" height="83" /></a></p>
<p><a href="http://www.athcon.org/register/">AthCon 2011</a>: June 2 to June 3 in Athens</p>
<p><a href="https://www.owasp.org/index.php/AppSecEU2011#tab=Registration"><img class="alignleft size-medium wp-image-1695" title="OWASP AppSec Europe" src="http://infosecevents.net/wp-content/uploads/2011/06/OWASP-AppSec-Europe-300x72.jpg" alt="OWASP AppSec Europe" width="300" height="72" /></a></p>
<p><a href="https://www.owasp.org/index.php/AppSecEU2011#tab=Welcome">AppSec Europe 2011</a>: June 6 to June 9 in Dublin</p>
<p><a href="https://www.euromoneysecure.com/orders/MISTIEurope/default.asp?abc=123&amp;LS=ciso&amp;ProductID=13248&amp;page=71"><img class="alignleft size-medium wp-image-1697" title="CISO logo" src="http://infosecevents.net/wp-content/uploads/2011/06/CISO-logo-300x38.jpg" alt="CISO logo" width="300" height="38" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/35302219/BSidesStJohns">8th Annual CISO Summit and Roundtable</a>: June 8 to June 10 in Rome</p>
<p><a href="http://www.regonline.co.uk/Register/Checkin.aspx?EventID=956472"><img class="alignleft size-medium wp-image-1699" title="eCrime london" src="http://infosecevents.net/wp-content/uploads/2011/06/eCrime-london-300x111.jpg" alt="eCrime london" width="300" height="111" /></a></p>
<p><a href="http://www.e-crimecongress.org/cloud/">e Crime Cloud Security Forum</a>: June 8 in London</p>
<p><a href="http://www.securitybsides.com/w/page/35302219/BSidesStJohns"><img class="alignleft size-full wp-image-1698" title="BSides St John logo" src="http://infosecevents.net/wp-content/uploads/2011/06/BSides-St-John-logo1.jpg" alt="BSides St John logo" width="160" height="97" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/35302219/BSidesStJohns">BSides St. John&#8217;s</a>: June 10 in Newfoundland</p>
<p><a href="https://reg.first.org/conference/2011/"><img class="alignleft size-full wp-image-1700" title="First logo" src="http://infosecevents.net/wp-content/uploads/2011/06/First-logo.jpg" alt="First logo" width="241" height="145" /></a></p>
<p><a href="http://conference.first.org/">FIRST</a>: June 12 to June 17 in Vienna</p>
<p><a href="http://www.hackinparis.com/products_hip"><img class="alignleft size-medium wp-image-1702" title="Hack In Paris" src="http://infosecevents.net/wp-content/uploads/2011/06/Hack-In-Paris-300x38.jpg" alt="Hack In Paris" width="300" height="38" /></a></p>
<p><a href="http://www.hackinparis.com/">Hack in Paris</a>: June 14 to June 17 in Paris</p>
<p><a href="http://www.nuitduhack.com/location-nuit-du-hack"><img class="alignleft size-medium wp-image-1701" title="Nuit du Hack" src="http://infosecevents.net/wp-content/uploads/2011/06/Nuit-du-Hack-300x143.jpg" alt="Nuit du Hack" width="300" height="143" /></a></p>
<p><a href="http://www.nuitduhack.com/">Nuit du Hack:</a> June 18 to June 19 in Paris</p>
<p><a href="http://2011.ninjacon.net/register"><img class="alignleft size-medium wp-image-1703" title="NinjaCon" src="http://infosecevents.net/wp-content/uploads/2011/06/NinjaCon-300x147.jpg" alt="NinjaCon" width="300" height="147" /></a></p>
<p><a href="http://2011.ninjacon.net/">NinjaCon/BSides Vienna</a>: June 18 in Vienna</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23958"><img class="alignleft size-medium wp-image-1704" title="SANS Malaysia" src="http://infosecevents.net/wp-content/uploads/2011/06/SANS-Malaysia-300x57.jpg" alt="SANS Malaysia" width="300" height="57" /></a></p>
<p><a href="http://www.sans.org/malaysia-2011/">SANS Malaysia</a>: June 27 to July 2 in Cyberjaya Selangor</p>
<p><a href="http://www.i-society.eu/Registration.html"><img class="alignleft size-full wp-image-1705" title="i-Society Logo" src="http://infosecevents.net/wp-content/uploads/2011/06/i-Society-Logo.jpg" alt="i-Society Logo" width="245" height="106" /></a></p>
<p><a href="http://www.i-society.eu/">i-Society 2011</a>: June 27 to June 29 in London</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1686&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/06/02/information-security-events-for-june/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>San Diego Security Community</title>
		<link>http://infosecevents.net/2011/05/13/san-diego-security-community/</link>
		<comments>http://infosecevents.net/2011/05/13/san-diego-security-community/#comments</comments>
		<pubDate>Fri, 13 May 2011 19:11:12 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Local Meetings]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[CyberSecurity Symposium]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1651</guid>
		<description><![CDATA[Each week, we’ll highlight a major city in the US and cover the places and events you can go to in that area to get your security information fix. This post is part of the information security communities. Not quite as hyper as L.A. and a little too laid back compared to bustling San Fran, [...]]]></description>
			<content:encoded><![CDATA[<p><em>Each week, we’ll highlight a major city in the US and cover the  places and events you can go to in that area to get your security  information fix. This post is part of the information security  communities.</em></p>
<p>Not quite as hyper as L.A. and a little too laid back compared to bustling San Fran, but San Diego has its own charms. No surprise then that there&#8217;s a significant presence of <strong>local professional groups</strong>.</p>
<ul>
<li><a href="https://www.owasp.org/index.php/SanDiego">OWASP San Diego Local Chapter</a> &#8211; Are pretty active and concluded a meeting just last month. For news on their doings, join the <a href="http://lists.owasp.org/mailman/listinfo/owasp-sandiego">mailing list</a>.</li>
<li><a href="http://www.sdissa.org/">SD ISSA Local Chapter</a> &#8211; Just concluded a training event last week and a membership meeting wend down on the 11th These guys are very active and can be reached via <a href="http://www.twitter.com/CyberWarriors">Twitter</a>. The chapter is also open to <a href="http://www.issa.org/Join/Join-Online.html">new members</a>.</li>
<li><a href="http://www.isaca-sd.org/">ISACA San Diego Chapter</a> &#8211; These guys meet once a month and the 19th has already been booked. Get n touch by opening the link.</li>
<li><a href="https://www.sdinfragard.net/">Infragard San Diego Chapter</a> &#8211; They&#8217;ve got a meet on the 20th. For contacts and extra details, just open the link.</li>
<li><a href="http://www.aitp.org/organization/chapters/chapters.jsp#California">AITP San Diego</a> &#8211; <a href="http://www.nuaitp.net/">National University</a>, <a href="http://www.sdaitp.org/">San Diego State</a>, and <a href="http://www.aitp.org/organization/chapters/chapterhome.jsp?chapter=1039">U of San Diego</a> all have student groups who are quite active. Open the links for the whole scoop on their doings.</li>
</ul>
<p>Since there are lots of groups, there are definitely lots of <strong>local meetings </strong>too.</p>
<ul>
<li><a href="http://san2600.org/">San Diego 2600</a> &#8211; It&#8217;s at Regent&#8217;s Pizza, 4150 Regent&#8217;s Part Row #170. If you&#8217;re itching to, then don&#8217;t miss it. San Diego 2600 get together every first Friday of the month.</li>
</ul>
<p>Woah! check out these <strong>hackerspaces</strong>.</p>
<ul>
<li><a href="http://www.neucleon.org/?q=node/1">Nucleon</a> &#8211; Haven&#8217;t done anything significant in a while. But they at least have an extensive back log.</li>
<li><a href="http://hackerspaces.org/wiki/San_Diego_Hacker_News_Meetup">San Diego Hacker News Meetup</a> &#8211; Quite the shadowy bunch. They do have a physical address though.</li>
<li><a href="http://hackerspaces.org/wiki/HackerspaceSD">HackerspaceSD</a> &#8211; Another group who keep a really low profile. Try the link for interesting stuff.</li>
</ul>
<p>There wouldn&#8217;t be much of a scene without<strong> security events</strong>.</p>
<ul>
<li><a href="http://www.sans.org/security-west-2011/">SANS Security West San Diego</a> &#8211; It actually just finished yesterday, but just so you know it happened.</li>
<li><a href="http://sandiego.toorcon.org/">ToorCon San Diego</a> &#8211; Already wrapped last year but there&#8217;s another come October, so stay tuned on this front.</li>
<li><a href="http://securingourecity.org/spring2011-cybersecurity-symposium">CyberSecurity Symposium</a> &#8211; Happens on May 17. An all day event at the Doubletree Hotel.</li>
<li><a href="http://www.barcampsd.org/">BarCamp San Diego</a> &#8211; A long running series that just concluded its first 2011 outing on January. Check the link for updates and registration for future meets.</li>
<li><a href="http://securitydaysandiego.ucsd.edu/">Security Day San Diego</a> &#8211; A campus event at UCSD that happens at least once a year. The last installment was on November 2010, so expect its follow up on the same date this 2011.</li>
</ul>
<p>There might be a few groups and events we missed. If so, feel free to chime in at the comments.</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1651&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/05/13/san-diego-security-community/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Security Events For May</title>
		<link>http://infosecevents.net/2011/05/01/information-security-events-for-may/</link>
		<comments>http://infosecevents.net/2011/05/01/information-security-events-for-may/#comments</comments>
		<pubDate>Sun, 01 May 2011 16:29:48 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[IEEE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Secure360]]></category>
		<category><![CDATA[SEIC]]></category>
		<category><![CDATA[TakeDownCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1620</guid>
		<description><![CDATA[Here are the information security events in North America this month: SANS Security West 2011: May 3 to May 13 in San Diego Bsides ROC: May 7 to May 8 in New York Secure 360: May 10 to May 12 in Saint Paul TakeDownCon: May 14 to May 20 in Dallas SANS Cyber Guardian: May [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are the information security events in North America this month:</strong></p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=13813"><img class="alignleft size-full wp-image-1621" title="SANS logo" src="http://infosecevents.net/wp-content/uploads/2011/05/SANS-logo.jpg" alt="SANS logo" width="90" height="59" /></a></p>
<p><a href="http://www.sans.org/security-west-2011/">SANS Security West 2011</a>: May 3 to May 13 in San Diego</p>
<p><a href="http://www.securitybsides.com/w/page/29035710/BSidesROC"><img class="alignleft size-full wp-image-1622" title="Bsides" src="http://infosecevents.net/wp-content/uploads/2011/05/Bsides.jpg" alt="Bsides" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/BSidesROC">Bsides ROC</a>: May 7 to May 8 in New York</p>
<p><a href="http://secure360.org/pages/2011-attendee-registration-now-open"><img class="alignleft size-full wp-image-1623" title="Secure 360 logo" src="http://infosecevents.net/wp-content/uploads/2011/05/Secure-360-logo.jpg" alt="Secure 360 logo" width="259" height="38" /></a></p>
<p><a href="http://www.secure360.org/">Secure 360</a>: May 10 to May 12 in Saint Paul</p>
<p><a href="http://www.takedowncon.com/?page_id=23"><img class="alignleft size-full wp-image-1624" title="TakeDownCon logo" src="http://infosecevents.net/wp-content/uploads/2011/05/TakeDownCon-logo.jpg" alt="TakeDownCon logo" width="325" height="44" /></a></p>
<p><a href="http://www.takedowncon.com/">TakeDownCon</a>: May 14 to May 20 in Dallas</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23398"><img class="alignleft size-full wp-image-1625" title="SANS Cyber Guardian 2011" src="http://infosecevents.net/wp-content/uploads/2011/05/SANS-Cyber-Guardian-2011.jpg" alt="SANS Cyber Guardian 2011" width="228" height="44" /></a></p>
<p><a href="http://www.sans.org/cyber-guardian-2011/">SANS Cyber Guardian</a>: May 15 to May 23 in Baltimore</p>
<p><a href="http://www.ceicconference.com/#tab=1"><img class="alignleft size-full wp-image-1626" title="CEIC logo" src="http://infosecevents.net/wp-content/uploads/2011/05/CEIC-logo.jpg" alt="CEIC logo" width="240" height="57" /></a></p>
<p><a href="http://www.ceicconference.com/">CEIC 2011</a>: May 15 to May 19 in Orlando</p>
<p><a href="http://www.regonline.com/Register/Checkin.aspx?EventID=938482"><img class="alignleft size-full wp-image-1627" title="IEEE Symposium logo" src="http://infosecevents.net/wp-content/uploads/2011/05/IEEE-Symposium-logo.jpg" alt="IEEE Symposium logo" width="304" height="53" /></a></p>
<p><a href="http://www.ieee-security.org/TC/SP2011">IEEE Symposium On Security And Privacy</a>: May 22 to May 26</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="http://caro2011.org/registration.php"><img class="alignleft size-full wp-image-1629" title="CARO logo" src="http://infosecevents.net/wp-content/uploads/2011/05/CARO-logo.jpg" alt="CARO logo" width="244" height="133" /></a></p>
<p><a href="http://caro2011.org/">CARO 2011</a>: May 5 to May 6 in Prague</p>
<p><a href="http://infosecurity.questexevents.net/register"><img class="alignleft size-full wp-image-1630" title="InfoSec con logo" src="http://infosecevents.net/wp-content/uploads/2011/05/InfoSec-con-logo.jpg" alt="InfoSec con logo" width="273" height="55" /></a></p>
<p><a href="http://infosecurity.questexevents.net/home">InfoSecurity Conference</a>: May 5 in Singapore</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23813"><img class="alignleft size-full wp-image-1632" title="SANS secure amsterdam" src="http://infosecevents.net/wp-content/uploads/2011/05/SANS-secure-amsterdam1.jpg" alt="SANS secure amsterdam" width="200" height="44" /></a></p>
<p><a href="http://www.sans.org/secure-amsterdam-2011/">SANS Secure Europe 2011</a>: May 9 to May 21 in Amsterdam</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=23953"><img class="alignleft size-full wp-image-1633" title="SANS logo" src="http://infosecevents.net/wp-content/uploads/2011/05/SANS-logo1.jpg" alt="SANS logo" width="90" height="59" /></a></p>
<p><a href="http://www.sans.org/brisbane-2011/">SANS Brisbane</a>: May 9 to May 14 in Brisbane</p>
<p><strong><a href="http://eicar.org/conference/registration_form.htm"><img class="alignleft size-full wp-image-1634" title="Eicar" src="http://infosecevents.net/wp-content/uploads/2011/05/Eicar.jpg" alt="Eicar" width="183" height="70" /></a></strong></p>
<p><a href="http://http://eicar.org/conference">20th EICAR Annual Conference</a>: May 9 to May 10 in Krems</p>
<p><a href="http://infosecurity.questexevents.net/register"><img title="InfoSec con logo" src="../wp-content/uploads/2011/05/InfoSec-con-logo.jpg" alt="InfoSec con logo" width="282" height="55" /></a></p>
<p><a href="http://infosecurity.questexevents.net/home">InfoSecurity Conference</a>: May 12 in Kuala Lumpur</p>
<p><a href="http://www.e-crimecongress.org/middleeast/website.asp?page=register"><img class="alignleft size-full wp-image-1636" title="ecrime middle east logo" src="http://infosecevents.net/wp-content/uploads/2011/05/ecrime-middle-east-logo.jpg" alt="ecrime middle east logo" width="250" height="93" /></a></p>
<p><a href="http://www.e-crimecongress.org/middleeast/">e-Crime Mid-Year Middle East Meeting</a>: May 12 in Abu Dhabi</p>
<p><a href="http://conference.auscert.org.au/conf2011/registration.html"><img class="alignleft size-full wp-image-1637" title="AusCERT logo" src="http://infosecevents.net/wp-content/uploads/2011/05/AusCERT-logo.jpg" alt="http://conference.auscert.org.au/conf2011/registration.html" width="286" height="85" /></a></p>
<p><a href="http://conference.auscert.org.au/conf2011/">AusCERT 2011</a>: May 15 to May 20 in Benowa</p>
<p><a href="http://www.securitybsides.com/w/page/38697948/BSides-Australia"><img class="alignleft size-full wp-image-1638" title="Bsides" src="http://infosecevents.net/wp-content/uploads/2011/05/Bsides1.jpg" alt="BSides" width="76" height="50" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/38697948/BSides-Australia">BSides Australia</a>: May 15 in Queensland</p>
<p><a href="http://www.smi-online.co.uk/store/basket_add.asp?mt=13&amp;mst=1&amp;ref=3526"><img class="alignleft size-full wp-image-1640" title="Cyber Defence logo" src="http://infosecevents.net/wp-content/uploads/2011/05/Cyber-Defence-logo1.jpg" alt="Cyber Defence logo" width="300" height="49" /></a><a href="http://www.smi-online.co.uk/store/basket_add.asp?mt=13&amp;mst=1&amp;ref=3526"><br />
</a></p>
<p><a href="http://www.smi-online.co.uk/events/overview.asp?is=1&amp;ref=3526">Cyber Defence</a>: May 16 to May 17 in Istanbul</p>
<p><a href="http://www.ysts.org/index-eng.html#"><img class="alignleft size-full wp-image-1641" title="You Shot" src="http://infosecevents.net/wp-content/uploads/2011/05/You-Shot.jpg" alt="You Shot" width="133" height="134" /></a></p>
<p><a href="http://www.ysts.org/">You Sh0t the Sheriff V</a>: May 16 in Sao Paulo</p>
<p><a href="http://rejestracja.confidence.org.pl/"><img class="alignleft size-full wp-image-1642" title="Confidence 211" src="http://infosecevents.net/wp-content/uploads/2011/05/Confidence-211.jpg" alt="Confidence 211" width="254" height="53" /></a></p>
<p><a href="http://2011.confidence.org.pl/">Confidence 2011</a>: May 24 to May 25 in Krakow</p>
<p><a href="http://ph-neutral.darklab.org/"></a><a href="http://ph-neutral.darklab.org/cgi-bin/submit.pl"><img class="alignleft size-full wp-image-1643" title="PH Neutral" src="http://infosecevents.net/wp-content/uploads/2011/05/PH-Neutral.jpg" alt="PH Neutral" width="275" height="85" /></a></p>
<p><a href="http://ph-neutral.darklab.org/">PH Neutral 0x7db</a>: May 27 to May 29 in Berlin<strong> </strong></p>
<p><strong><br />
</strong></p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1620&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/05/01/information-security-events-for-may/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

