5.16.2007

Linux Command Directory

This website is a great resource for insight on Linux Commands. It comes from the book Linux in a Nutshell by O'Reilly.

Chalmer

Been a long time...

It has been quite a while since my last post. My time was fully committed to the task of searching for a new job. Which I found...

I am now working for a consulting firm in Maryland, doing information assurance/information security work.

This will enable me the opportunity to really focus my studies on InfoSec and hopefully pass some of that info on to you, my astute readers.

Chalmer

3.11.2007

There is an interesting post on one of the many Google Blogs on how to search specific sites for data. In researching information security topics, it is often frustrating to use the default search box on certain websites. Many websites don't have decent indexing of their data and thus don't/can't offer effective search tools. Google has a way to overcome some of these limitations...

For example:

site:www.example.com sample
Would search the site www.example.com for the term "sample". Similarly,
site:insecure.org hacker
Will search the website insecure.org for the term "hacker".

Happy searching...

Chalmer

Only one main interface to the Internet???

Very interesting article about a potential plot to disrupt Britain's Internet access...One item that jumps out at me:

Raids by Metropolitan Police detectives found computer files indicating that terrorist suspects had targeted a high-security Internet "hub" in London that handles most of the Internet information that passes in and out of Britain, including London's businesses and stock exchange, the Sunday Times said.
The first question that comes to mind...is "Why does Britain have only one main hub to handle the majority of their Internet traffic?

This flies against the security principle of redundant systems.

Chalmer

2.17.2007

Korean Hackers??? and how our hands are tied...

Josh Rogin at Federal Computer Week has another interesting article on recent attacks traced back to South Korean servers AND a good discussion on what elements of current United States Policies may be limiting our ability to respond to cyber attacks.

This question is becoming more critical all the time. Cyber attacks are increasing in number and in sophistication everyday. It is only a matter of time before someone initiates an attack that will catch us off-guard, much the way 9/11 caught us off-guard.

Air Force General Ronald Keys, Commander of Air Combat Command had several interesting points:

The recent UltraDNS attacks raised several questions for DOD policy makers, Keys said. “How do you react to that attack? How do you trace it back? What are the legalities included? What do you do when you do find them? It’s a huge challenge,” he said.
The enemy is no stranger to cyber attacks:
“We’re already at war in Cyberspace, have been for many years,” said Keys. Terrorists use the Internet extensively, through remotely detonated bombs, GPS, Internet financial transactions, navigation jamming, blogs, bulletin boards, and chat rooms.
This statement is the most intriguing - mostly because it is true:
Cyberspace is the only warfighting domain in which the U.S. has peer competitors, Keys said.
Chalmer

Chinese Hackers...

There is a great article in Federal Computer Week on Chinese hackers and their all-out attacks against the Department of Defense. One key point from the article, to ponder:

A recent Chinese military white paper states that China plans to be able to win an “informationized war” by the middle of this century.
Their innovation is also of interest...
China is also using more traditional hacking methods, such as Trojan horse viruses and worms, but in innovative ways.

For example, a hacker will plant a virus as a distraction and then come in “slow and low” to hide in a system while the monitors are distracted. Hackers will also use coordinated, multipronged attacks, the official added.
The field of information warfare may not be as "front-page picture-worthy" as bombed out husks of military equipment but it is just as real. The bad guys are out there!

Chalmer

2.15.2007

Improving your memory

I have a real fondness for foreign language...by which I mean honest-to-goodness languages from foreign countries and languages that are just plain foreign, like programming languages.

For many astute readers, dealing with a topic such as information security can be like dealing with a foreign language...there are many new terms to remember and new definitions tied to terms you thought you already knew.

Trying to remember these or any other facts, can be difficult. Mindtools offers some tips on how to remember things. If you find that you can't remember material you've read, can't remember people's names, or can't remember computer geek terminology, try some of the tips they offer.

Chalmer

2.11.2007

Know your target and what is beyond


There is an interesting story about a man who was mistaken for a large rodent and shot! Apparently, John Cheesman was snorkeling when someone saw him and mistook him for a large rodent, the Nutria. The guy, William Roderick, allegedly shot Cheesman in the head. Mr. Cheesman is apparently doing well and had the bullet fragments removed. Mr. Roderick is being charged with assault, being a felon in possession of a firearm, possession of methamphetamine and marijuana.

The take home message for the Astute Reader?

"Know your target and what is beyond" - This is a critical concept to understand, in all aspects of life, not just firearm safety. If you don't have a clear plan, when you enter into a venture, you are often doomed to failure...

This includes:

  • information security
  • personal goals
  • shopping trips
  • school and work assignments
  • career plans
  • finances
  • raising kids
If you don't have a good plan, then spend the time to make one...Franklin Covey's Mission Statement Builder might be a good place to start.

Chalmer

2.08.2007

Hacked in 39 seconds...

Just a quick point of reference regarding how prevalent probes and scans are on the Internet.

When you connect to the Internet, your computer is almost immediately being scanned by the bad guys. The researchers in this article found that their test computers were assaulted 2,244 times in 24 hours, or an average of every 39 seconds.

What does the astute reader do to keep themselves safe? Keep your defenses up - anti-virus, firewalls, etc.

Chalmer

Google