<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS</title>
<link>http://www.professionalsecuritytesters.org</link>
<description>You need more than tools to defeat the adversary!</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2010-09-04T15:30:17-04:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2010-09-04T15:30:17-04:00</sy:updateBase>

<item>
<title>I am in need of good question writers</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1213</link>
<description><![CDATA[<p>Good day to all, <br> <br> I am in dire need of good question writer who can produce some of the  new scenario based questions that have been showing up on the CISSP  exam.  It is the new type that present a large scenario (a paragraph or a  few) and then ask you a few questions related to that scenario. <br> <br> I would also need help from people who are CEH to develop questions for  that certification as well.  Those are the same style as we have in the  quiz engine right now. <br> <br> If you are interested I would like you to contact me at: <br> <strong>Clement [dot]Dupuis[at]Gmail[dot]com </strong><br> <br> As you know me, I prefer quality over quantity.  Even if you can commit  only to writing a few question it is fine.   I prefer a few that really  tests skills and knowledge than a whole bunch of bad ones. <br> <br> Please send me an email and tell me if you are willing to write question  for the CEH or the CISSP Scenario based questions and how much you  would like to be paid per question. <br> <br> Thanks in advance <br> <br> Clement</p>]]></description>
<guid isPermaLink="false">1213@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Quiz</dc:subject>
<dc:date>2010-09-03T22:34:02-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>2nd. OWASP Ibero-American Web-Applications Security conference 2010 (IBWAS 10)</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1212</link>
<description><![CDATA[<p>2nd. OWASP Ibero-American Web-Applications Security conference 2010 (IBWAS&#8217;10)<br> ISCTE &#8211; Lisbon University Institute<br> 25th &#8211; 26th November 2010<br> Lisboa, Portugal<br> <a href="http://www.ibwas.com/">http://www.ibwas.com</a><br> <br> <strong>Call for Papers</strong><br> <br> <strong>Introduction</strong><br> There is a change in the information systems development paradigm. The  emergence of Web 2.0 technologies led to the extensive deployment and  use of web-based applications and web services as a way to developed new  and flexible information systems. Such systems are easy to develop,  deploy and maintain and demonstrate impressive features for users,  resulting in their current wide use.<br> As a result of this paradigm shift, the security requirements have also  changed. These web-based information systems have different security  requirements, when compared to traditional systems. Important security  issues have been found and privacy concerns have also been raised  recently. In addition, the emerging Cloud Computing paradigm promises  even greater flexibility; however corresponding security and privacy  issues still need to be examined. The security environment should  involve not only the surrounding environment but also the application  core.<br> This conference aims to bring together application security experts,  researchers, educators and practitioners from the industry, academia and  international communities such as OWASP, in order to discuss open  problems and new solutions in application security. In the context of  this track academic researchers will be able to combine interesting  results with the experience of practitioners and software engineers.<br> <br> <strong>Conference Topics</strong><br> Suggested topics for papers submission include (but are not limited to):<br> &#8226; Secure application development<br> &#8226; Security of service oriented architectures<br> &#8226; Security of development frameworks<br> &#8226; Threat modelling of web applications<br> &#8226; Cloud computing security<br> &#8226; Web applications vulnerabilities and analysis (code review, pen-test, static analysis etc.)<br> &#8226; Metrics for application security<br> &#8226; Countermeasures for web application vulnerabilities<br> &#8226; Secure coding techniques<br> &#8226; Platform or language security features that help secure web applications<br> &#8226; Secure database usage in web applications<br> &#8226; Access control in web applications<br> &#8226; Web services security<br> &#8226; Browser security<br> &#8226; Privacy in web applications<br> &#8226; Standards, certifications and security evaluation criteria for web applications<br> &#8226; Application security awareness and education<br> &#8226; Security for the mobile web<br> &#8226; Attacks and Vulnerability Exploitation<br> <br> Paper Submission Instructions<br> Authors should submit an original paper in English, carefully checked  for correct grammar and spelling, using the on-line submission procedure  (<a href="http://www.easychair.org/conferences/?conf=ibwas10">http://www.easychair.org/conferences/?conf=ibwas10</a>).  Please check the paper formats so you may be aware of the accepted  paper page limits (12 pages, in accordance to a supplied template: <a href="ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip">ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip</a>).<br> The guidelines for paper formatting provided at the conference web site  must be strictly used for all submitted papers. The submission format is  the same as the camera-ready format. Please check and carefully follow  the instructions and templates provided.<br> Each paper should clearly indicate the nature of its  technical/scientific contribution, and the problems, domains or  environments to which it is applicable.<br> Papers that are out of the conference scope or contain any form of plagiarism will be rejected without reviews.<br> Remarks about the on-line submission procedure:<br> 1. A "double-blind" paper evaluation method will be used. To facilitate  that, the authors are kindly requested to produce and provide the paper,  WITHOUT any reference to any of the authors. This means that is  necessary to remove the author&#8217;s personal details, the acknowledgements  section and any reference that may disclose the authors identity<br> 2. Papers in ODF, PDF, DOC, DOCX or RTF format are accepted<br> 3. The web submission procedure automatically sends an acknowledgement, by e-mail, to the contact author.<br> <br> <strong>Paper submission types</strong><br> <br> <strong>Regular Paper Submission</strong><br> A regular paper presents a work where the research is completed or  almost finished. It does not necessary means that the acceptance is as a  full paper. It may be accepted as a "full paper" (30 min. oral  presentation), a "short paper" (15 min. oral presentation) or a  "poster".<br> Position Paper Submission<br> A position paper presents an arguable opinion about an issue. The goal  of a position paper is to convince the audience that your opinion is  valid and worth listening to, without the need to present completed  research work and/or validated results. It is, nevertheless, important  to support your argument with evidence to ensure the validity of your  claims. A position paper may be a short report and discussion of ideas,  facts, situations, methods, procedures or results of scientific research  (bibliographic, experimental, theoretical, or other) focused on one of  the conference topic areas. The acceptance of a position paper is  restricted to the categories of "short paper" or "poster", i.e. a  position paper is not a candidate to acceptance as "full paper".<br> <br> <strong>Camera-ready</strong><br> After the reviewing process is completed, the contact author (the author  who submits the paper) of each paper will be notified of the result, by  e-mail. The authors are required to follow the reviews in order to  improve their paper before the camera-ready submission.<br> <br> <strong>Publications</strong><br> All accepted papers will be published in the conference proceedings,  under an ISBN reference. Conference proceedings will be published by  Springer in the Communications in Computer and Information Science  (CCIS) series.<br> <br> Web-site:&#160; <a href="http://www.ibwas.com/">http://www.ibwas.com</a><br> <br> Secretariat:&#160; E-mail: <a href="mailto:secretariat@ibwas.com">secretariat@ibwas.com</a><br> <br> <strong>Important Dates</strong><br> Submission of papers and all other contributions due: 8th October 2010<br> Notification of acceptance: 22nd October 2010<br> Camera-ready version of accepted contributions: 29th October 2010<br> Conference: 25th &#8211; 26th November 2010<br> <br> Conference Chairs<br> Vicente Aguilera D&#237;as, Internet Security Auditors, OWASP Spain, Spain<br> Carlos Serr&#227;o, ISCTE-IUL Instituto Universit&#225;rio de Lisboa, OWASP Portugal, Portugal<br> <br> <strong>Organization Committee</strong><br> Fabio Cerullo, OWASP Global Education Committee, Ireland<br> Dinis Cruz, OWASP Board Member, UK<br> Paulo Coimbra, OWASP Project Manager, UK<br> Miguel Correia, Universidade de Lisboa, Portugal<br> Paulo Sousa, Universidade de Lisboa, Portugal<br> Lucas C. Ferreira, C&#226;mara dos Deputados, Brasil<br> Arturo Busleiman, OWASP Argentina, Argentina<br> Martin Tartarelli, OWASP Argentina, Argentina<br> Paulo Querido, Portugal<br> <strong><br> Conference Program Committee</strong><br> Andr&#233; Z&#250;quete, Universidade De Aveiro, Portugal<br> Candelaria Hern&#225;ndez-Goya, Universidad De La Laguna, Spain<br> Carlos Costa, Universidade De Aveiro, Portugal<br> Carlos Ribeiro, Instituto Superior T&#233;cnico, Portugal<br> Eduardo Neves, OWASP Education Committee, OWASP Brazil, Brazil<br> Francesc Rovirosa i Radu&#224;, Universitat Oberta de Catalunya (UOC), Spain<br> Gonzalo &#193;lvarez Mara&#241;&#243;n, Consejo Superior de Investigaciones Cient&#237;ficas (CSIC), Spain<br> Isaac Agudo, University of Malaga, Spain<br> Jaime Delgado, Universitat Politecnica De Catalunya, Spain<br> Javier Hernando, Universitat Politecnica De Catalunya, Spain<br> Javier Rodr&#237;guez Saeta, Herta Security, Spain<br> Joaquim Castro Ferreira, Universidade de Lisboa, Portugal<br> Joaquim Marques, Instituto Polit&#233;cnico de Castelo Branco, Portugal<br> Jorge D&#225;vila Muro, Universidad Polit&#233;cnica de Madrid (UPM), Spain<br> Jorge E. L&#243;pez de Vergara, Universidad Aut&#243;noma de Madrid, Spain<br> Jos&#233; Carlos Metr&#244;lho, Instituto Polit&#233;cnico de Castelo Branco, Portugal<br> Jos&#233; Luis Oliveira, Universidade De Aveiro, Portugal<br> Kuai Hinojosa, OWASP Global Education Committee, New York University, United States<br> Leonardo Chiariglione, Cedeo, Italy<br> Leonardo Lemes, Unisinos, Brasil<br> Manuel Sequeira, ISCTE-IUL Instituto Universit&#225;rio de Lisboa, Portugal<br> Marco Vieira, Universidade de Coimbra, Portugal<br> Mariemma I. Yag&#252;e, University of M&#225;laga, Spain<br> Miguel Correia, Universidade de Lisboa, Portugal<br> Miguel Dias, Microsoft, Portugal<br> Nuno Neves, Universidade de Lisboa, Portugal<br> Osvaldo Santos, Instituto Polit&#233;cnico de Castelo Branco, Portugal<br> Panos Kudumakis, Queen Mary University of London, United Kingdom<br> Paulo Sousa, Universidade de Lisboa, Portugal<br> Rodrigo Roman, University of Malaga, Spain<br> Rui Cruz, Instituto Superior T&#233;cnico, Portugal<br> Rui Marinheiro, ISCTE-IUL Instituto Universit&#225;rio de Lisboa, Portugal<br> S&#233;rgio Lopes, Universidade do Minho, Portugal<br> Tiejun Huang, Pekin University, China<br> V&#237;ctor Villagr&#225;, Universidad Polit&#233;cnica de Madrid (UPM), Spain<br> Vitor Filipe, Universidade de Tr&#225;s-os-Montes e Alto Douro, Portugal<br> Vitor Santos, Microsoft, Portugal<br> Vitor Torres, Universitat Pompeu Fabra, Spain<br> Wagner Elias, OWASP Brazil Chapter Leader, Brazil</p>]]></description>
<guid isPermaLink="false">1212@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2010-09-03T14:32:58-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>New NBISE Cyber Security Certifications will set HIGH BAR for Security Pros</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1211</link>
<description><![CDATA[<p>As seen Published on <em>threatpost</em> (<strong><a href="http://threatpost.com/">http://threatpost.com</a></strong>):</p>
<div class="print-logo" style="text-align: center;"><img class="print-logo" src="http://threatpost.com/sites/default/files/threatpost_logo.jpg" alt></div>
<hr>
<p><strong>New Cyber Security Certifications from <a href="http://www.nbise.org/">NBISE </a>Will Set High Bar for IT Security Pros</strong></p>
<div class="print-submitted">By <em>Paul Roberts</em></div>
<div class="print-created">Created <em>08/05/2010 - 9:53am</em></div>
<p style="text-align: center;"><a href="http://www.nbise.org/"><img title="NBISE" src="images/topics/nbise.jpg" alt="National Board of Information Security Examiners" width="100" height="51"></a></p>
<p>[1]A new non-profit group is developing certifications for information technology security professionals that will set a high bar for IT security practitioners in areas like penetration testing, code auditing and control systems operation.</p>
<p>The <a href="http://www.nbise.org/">National Board of Information Security Examiners (NBISE)</a> [2] is a new, not-for-profit corporation headed by former NERC (North American Electric Reliability Corporation) CSO Mike Assante and overseen by a board of luminaries in the world of information security and critical infrastructure. &#160;The group will be designing certification exams to test the knowledge, practical skill and professionalism of IT security practitioners, with an eye to weeding out the information technology world&#8217;s equivalent of quacks and hucksters.</p>
<p>The new tests are designed to supplant a hodge podge of private and industry certifications for IT security practitioners, including the CISSP and certificate programs run by the SANS Institute and other industry and private groups. NBISE claims that too many of those tests test knowledge, rather than hands-on skills required of practitioners.</p>
<p>&#8220;This is about a higher level of testing,&#8221; said NBISE Director and SANS Institute Director of Research Alan Paller. &#8220;Its about having confidence that the person you hired doesn&#8217;t just know the answer, but can do the job.&#8221;</p>
<p>NBISE Chief Operating Officer Kelly Ziegler likens the  exams to those required by the National Board of Medical Examiners for  aspiring physicians.</p>
<p>Paller said that the group is working with top practitioners in a variety of disciplines to design exams that test practical knowledge, not just book knowledge. Scenario testing &#8211; akin to the now famous &#8220;Capture the Flag&#8221; tournaments at DEFCON and other hacking conferences -- will be an important component of the NBISE exams, he said.</p>
<p>&#8220;If you look at (penetration) testing, you can have multiple choice questions about the correct approach when pen testing, but that&#8217;s very different than having an actual set of systems and having to find a flag, rather than just answer questions about how to find it,&#8221; Paller said.</p>
<p>NBISE plans to release its first exam in the next 30 days. That test will be an adaptation of the UK&#8217;s <a href="http://www.crest-approved.org/">Council of Registered Ethical Security Testers (CREST)</a> [3] exam for penetration testing. The group is working with the UK government&#8217;s CESG &#8211; the British equivalent of the U.S.&#8217;s National Security Agency &#8211; to adapt that exam for use in North America, according to Ziegler.</p>
<p>In other areas, such as the operation of control systems and secure coding, computer forensics and incident response and handling, NBISE is forming national boards of experts to get to work developing exams. The group is also being advised by the National Board of Medical Examiners on ways to devise certification exams that test practical knowledge.</p>
<p>Paller said the new emphasis on certification is a response to <a href="http://threatpost.com/en_us/blogs/new-cybersecurity-czar-faces-tough-road-060209">an aching skills gap in the IT security space</a> [4]. That gap has been underscored by a series of studies and reports that have pointed to the need to develop IT security expertise within the public and private sectors. Most recently, in June, the Center for Strategic and International Studies issued a report warning of a &#8220;human capital crisis&#8221; in cyber security.</p>
<p>Paller said that the profusion of different certifications has allowed legions of poorly trained IT professionals to falsely claim expertise in cyber security. Often, their lack of training only becomes evident once they&#8217;ve been hired. &#160;</p>
<p>NBISE will also provide more focused instruction than initiatives like the U.S. Departments of Defense&#8217;s Directive 8570 (DOD 8570), which provides training and certification guidance for government employees who work in Information Assurance, but give employees a menu of different certifications to choose from in fulfilling the directive, say NBISE organizers.</p>
<p>The NBISE exams, once instituted, will serve as a threshold exam for work in areas like government and financial services, separating those with technical knowledge of a subject from those with both knowledge and hands on experience to perform a job. <strong>Paller said that the exams, once adopted, could take business away from certification organizations like The SANS Institute, but that those organizations might merely shift to fulfill a role similar to that of medical schools today: teaching students a body of material and hands on skills necessary to pass the NBISE certification exam.</strong></p>
<p>&#160;</p>
<hr>
<div class="print-source_url"><strong>Source URL:</strong> <a href="http://threatpost.com/en_us/blogs/new-certification-group-aims-set-high-bar-it-security-pros-080510">http://threatpost.com/en_us/blogs/new-certification-group-aims-set-high-bar-it-security-pros-080510</a></div>
<p><strong>Links:</strong><br>[1] <a href="http://threatpost.com/en_us/blogs/new-certification-group-aims-set-high-bar-it-security-pros-080510">http://threatpost.com/en_us/blogs/new-certification-group-aims-set-high-bar-it-security-pros-080510</a><br> [2] <a href="http://www.nbise.org/">http://www.nbise.org/</a><br> [3] <a href="http://www.crest-approved.org/">http://www.crest-approved.org/</a><br> [4] <a href="http://threatpost.com/en_us/blogs/new-cybersecurity-czar-faces-tough-road-060209">http://threatpost.com/en_us/blogs/new-cybersecurity-czar-faces-tough-road-060209</a><br> [5] <a href="http://www.twitter.com/home?status=New">http://www.twitter.com/home?status=New Certifications Will Set High Bar for IT Security Pros http://threatpost.com/en_us/c4B</a></p>]]></description>
<guid isPermaLink="false">1211@http://www.professionalsecuritytesters.org</guid>
<dc:subject>NBISE</dc:subject>
<dc:date>2010-09-02T10:20:22-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Insecure Magazine issue 27 has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1210</link>
<description><![CDATA[<p>(IN)SECURE Magazine is a freely available digital security magazine discussing some of the hottest information security topics.</p>
<p><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-27.pdf"></a></p>
<p style="text-align: center;"><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-27.pdf"><img style="vertical-align: middle;" src="http://www.net-security.org/images/insecure/issues/issue27.jpg" alt></a></p>
<p class="style3" align="center"><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-27.pdf">DOWNLOAD ISSUE 27 HERE</a><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-27.pdf"> </a>(September 2010)</p>
<p><br>Issue 27 has just been released. Download it from:<br><strong><a href="http://www.insecuremag.com/">http://www.insecuremag.com</a></strong><br><br>The covered topics include:<br><br>- Review: BlockMaster SafeStick secure USB flash drive<br>- The devil is in the details: Securing the enterprise against the cloud<br>- Cybercrime may be on the rise, but authentication evolves to defeat it<br>- Learning from bruteforcers<br>- PCI DSS v1.3: Vital to the emerging demand for virtualization and cloud security<br>- Security testing - the key to software quality<br>- A brief history of security and the mobile enterprise<br>- Payment card security: Risk and control assessments<br>- Security as a process: Does your security team fuzz?<br>- Book review: Designing Network Security, 2nd Edition<br>- Intelligent security: Countering sophisticated fraud<br>____________________________________________________<br><br>(IN)SECURE Magazine is supporting the following industry events:<br><br>SOURCE Barcelona 2010 <br>Barcelona, Spain, 21-22 September 2010.<br>Use discount code SOURCEHN10 to get 15% off your ticket price.<br><a href="http://www.sourceconference.com/">http://www.sourceconference.com</a><br><br>Brucon 2010<br>Brussels, Belgium. 24-25 September 2010.<br><a href="http://www.brucon.org/">http://www.brucon.org</a><br><br>InfoSecurity Russia 2010<br>Moscow, Russia. 17-19 November 2010.<br><a href="http://www.infosecurityrussia.ru/">http://www.infosecurityrussia.ru</a><br><br>RSA Conference Europe 2010<br>London, United Kingdom. 12-14 October 2010.<br><a href="http://bit.ly/rsa2010eu">http://bit.ly/rsa2010eu</a><br><br>__________________________________________________<br><br>Visit the (IN)SECURE Magazine web site at:<br><a href="http://www.insecuremag.com/">http://www.insecuremag.com</a><br><br>Subscribe to our RSS feed at:<br><a href="http://feeds2.feedburner.com/insecuremagazine">http://feeds2.feedburner.com/insecuremagazine</a><br><br>Daily security news RSS feed:<br><a href="http://feeds2.feedburner.com/HelpNetSecurity">http://feeds2.feedburner.com/HelpNetSecurity</a><br><br>Help Net Security on Twitter:<br><a href="http://twitter.com/helpnetsecurity">http://twitter.com/helpnetsecurity</a><br><br>Contact:<br><br>- For information on contributing to (IN)SECURE Magazine, please contact Chief Editor Mirko Zorz at editor( at )insecuremag.com<br>- For marketing inquiries do contact Marketing Director Berislav Kucan at marketing( at )insecuremag.com</p>]]></description>
<guid isPermaLink="false">1210@http://www.professionalsecuritytesters.org</guid>
<dc:subject>InsecureMagazine</dc:subject>
<dc:date>2010-09-01T20:25:19-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>nullcon GOA Dwitiya (2.0) The Jugaad (hacking) Conference</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1209</link>
<description><![CDATA[<p><strong>NOTE FROM CLEMENT:</strong></p>
<p>GOA is a magical place with amazing beaches in the North.&#160; You have miles and miles of beaches to yourself.&#160; Not to mention that GOA is a hub for tourism and it is very inexpensive.&#160;&#160; A great place at great price,&#160; do entend your stay a bit to visit the area.&#160; February is one of the best month of the year to visit as well.</p>
<p><strong>nullcon Dwitiya (2.0)<br> The Jugaad(hacking) Conference</strong><br> <br> nullcon is an initiative by null - The open security community.<br> <br> Website:&#160; <strong><a href="http://nullcon.net/">http://nullcon.net</a></strong><br> <br> <strong>Calling all Jugaadus(hackers)</strong><br> It's the time of the year when we welcome research done by the community as paper submissions for nullcon.&#160; So, sip your coffee, dust your debuggers, fire your tools, challenge your grey cells and shoot us an email.<br> <br> <strong>Tracks:</strong><br> ---------------<br> - Bakkar: &#160; &#160; &#160; &#160; 1 Hr Talks<br> - Tez: &#160; &#160; &#160; &#160; &#160; &#160; &#160;5-30 min Talks<br> - Karyashala: &#160;&#160; 2-4 Hrs Workshop<br> - Desi Jugaad&#160;&#160;&#160; (Local Hack): 1 Hr<br> <br> <strong>Submition Topics:</strong><br> ------------------------------<br> 1. One of the topics of interest to us is "Desi Jugaad"(Local Hack) and has a separate track of it's own. Submissions can be any kind of local hacks that you have worked on (hints: electronic/mechanical meters, automobile hacking,&#160; Hardware, mobile phones, lock-picking, bypassing procedures and processes, etc, Be creative &#160;:-D)<br> <br> 2. The topics pertaining to security and Hacking in the following domains(but not limited to)<br> - Hardware (ex: RFID, Magnetic Strips, Card Readers, Mobile Devices, Electronic Devices)<br> - Tools (open source)<br> - Programming/Software Development<br> - Networks<br> - Information Warfare<br> - Botnets, Malware<br> - Web<br> - New attack vectors<br> - Mobile, VOIP and Telecom<br> - VM<br> - Cloud<br> - Critical Infrastructure<br> - Satellite<br> - Wireless<br> - Forensics<br> - Cyber Laws<br> <br> <strong>Submission Format:</strong><br> ------------------------------<br> Email the cfp to: cfp(_at_)<a href="http://nullcon.net/">nullcon.net</a><br> Subject should be: CFP Dwitiya <br> Email Body:<br> - Name<br> - Handle<br> - Track &#38; Time required<br> - Paper Title<br> - Country of residence<br> - Organization<br> - Contact no.<br> - Have you presented/submitted this talk at any other conference(s)?<br> - Why do you think your paper is different/innovative?<br> - Brief Profile ( &#60;= 500 Words)<br> - Paper Abstract ( &#60;= 3000 Words)<br> <br> NOTE: The Abstract should clearly mention the techniques and hacks in<br> detail and merely mentioning that it works will not help in<br> understanding the research to it's full extent.<br> <br> <br> <strong>Important Dates:</strong><br> ------------------------------<br> CFP End Date: &#160; &#160; &#160; &#160; 30th November 2010<br> Speakers List Online: 10th December 2010<br> Conference Dates: &#160; &#160; 25th - 26th February 2011<br> <br> <br> <strong>Venue:</strong><br> ----------------<br> Goa, India<br> (Exact Venue TBD)<br> <br> <br> <strong>Speaker Benefits:</strong><br> ------------------------------</p>
<div id=":xg">--<br> For Tracks "Bakkar", "Desi Jugaad" and "Karyashala"<br> 1. Free Accommodation for 3 nights<br> 2. Travel (One way or Return depending on the Sponsorships :-) )<br> 3. Free access to the conference.<br> 4. Invitation to Mehfil-E-Mausiqi (null party)<br> <br> For Track "Tez"<br> 1. Free access to the conference.<br> 2. Invitation to Mehfil-E-Mausiqi (null party)<br> <br> * Only one speaker will be eligible for the benfits in case there are two or more speakers for a talk.</div>]]></description>
<guid isPermaLink="false">1209@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2010-09-01T09:57:29-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>September issue of Hakin9 magazine: Mobile Malware – the new cyber threat</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1208</link>
<description><![CDATA[<p><br><br></p>
<table style="padding: 10px;" border="0" cellspacing="0" cellpadding="0" width="598" bgcolor="#ffffff">

<tr>
<td><img src="http://www.payrankings.com/12all/admin/images/wydawnictwo/hakin9_EN/2010_04_30/logo.jpg" border="0" alt="Hakin9" width="598"></td>
</tr>
<tr>
<td>
<div style="margin-left: 52px; margin-right: 52px;"><br> <strong>September issue of  Hakin9 magazine:<br> Mobile Malware &#8211; the new cyber threat </strong><br> </div>
</td>
</tr>
<tr>
<td align="center">
<p align="left"><a href="http://hakin9.org/magazine/1464-mobile-malware-the-new-cyber-threat"><img src="http://mytalkoot.com/12all/images/wydawnictwo/hakin9_EN/2010_08_03/hakin9_08_2010.png" border="0" alt hspace="5" vspace="5" align="right"></a><strong>
<div>New issue of Hakin9 magazine already available!<br> <br> Inside:</div>
</strong></p>
<div>
<ul>
<li> Mobile Malware &#8211; the new cyber threat</li>
<li> Botnet: The Six Laws And Immerging Command &#38; Control Vectors</li>
<li>Hacking Trust Relationships &#8211; Part 2</li>
<li> Web Malware &#8211; Part 2</li>
<li> Defeating Layer-2 &#8211; A ttacks in VoIP</li>
<li>Armoring Malware: Hiding Data within Data</li>
<li>Is Anti-virus Dead? The answer is YES. Here&#8217;s why&#8230;</li>
<br><br>
</ul>
</div>
<p align="left"> <a href="http://hakin9.org/magazine/1464-mobile-malware-the-new-cyber-threat">Download your copy NOW -- Click HERE</a></p>
<hr>
<p align="left"><strong>Mobile Malware &#8211; the new cyber threat</strong><br> <em>Julian Evans</em><br> Mobile phone malware first appeared in June  2004 and it was called Cabir. The mobile-phone features at most risk are  text messaging (using social engineering), contacts list, video and  buffer overflows. GSM, GPS, Bluetooth, MMS and SMS will indeed be some  of the attack vector to expect this year and beyond.</p>
<hr>
<p align="left"> <strong>Botnet: The Six Laws And Immerging Command &#38; Control Vectors</strong><br> <em>Richard C. Batka</em><br> New BotNet communication vectors are  emerging. The industry is not prepared. For the next 20 years, BotNets  will be what viruses were for the last 20.</p>
<hr>
<p align="left"> <strong>Hacking Trust Relationships &#8211; Part 2</strong><br> <em>Thomas Wilhelm</em><br> This is the second article in a series of  six that covers the topic of hacking trust relationships. This article  focuses specifically on Vulnerability Identification against a target  system, in order to identify and exploit potential trust relationships.</p>
<hr>
<p align="left"> <strong>Web Malware &#8211; Part 2</strong> <br> <em>Rajdeep Chakraborty</em><br> In the previous section of the article Web  Malwares (Part 1) we discussed various statistics that showed us the  increase of Web Malware activity in recent years and why the focus of  Malware authors has changed from creating havoc in the infrastructure to  infecting the endpoints for various other henious purpose, we have seen it all. Once we are aware of these  facts and figures, in the next section we will look into the technical  Details of Web Malwares (Part 2).</p>
<hr>
<p align="left"> <strong>Defeating Layer-2 &#8211; A ttacks in VoIP</strong> <br> <em>Abhijeet Hatekar</em><br> ARP Poisoning and other Layer 2 attacks are  present since many decades now and one may think that they are absolute.  However, we still see them quite often on the network. The biggest  advantage is easy access to sensitive information like passwords, credit  card details, phone conversations etc.</p>
<hr>
<p align="left"> <strong>Armoring Malware: Hiding Data within Data</strong> <br> <em>Israel Torres</em><br> We are receiving malware daily via hundreds  of facets that the Internet enables with various services; most common  are via e-mail and web surfing. At any one time you can be sitting idly  on the &#8216;net when you are presented with something that could be  malicious either overtly or covertly. We&#8217;ll play through the scenario of  where you&#8217;ve discovered a binary on your network and unsure of it&#8217;s  purpose... and then reveal how it was done.</p>
<hr>
<p align="left"> <strong>Is Anti-virus Dead? The answer is YES. Here&#8217;s why&#8230;</strong> <br> <em>Gary Miliefsky</em><br> There have been billions of dollars in  damages caused by exploiters on the Internet. These exploiters are  intelligent cyber terrorists, criminals and hackers who have a plethora  of tools available in their war chest &#8211; ranging from spyware, rootkits,  trojans, viruses, worms, zombies and botnets to various other blended  threats. From old viruses to these new botnets, we can categorize them  all as malware.</p>
<hr>
<p align="left"> <strong>Hakin9 magazine is also available in German. <br> <a href="http://hakin9.org/de">Download here</a></strong></p>
<hr>
<p align="left"> <strong>Contacts Us</strong> </p>
<table border="0" width="97%">

<tr>
<td>
<p align="left"> <a href="mailto:editors@hakin9.org">editors@hakin9.org</a> <br> Editor-in-Chief<br> Karolina Lesi&#324;ska<br> <a href="mailto:karolina.lesinska@hakin9.org">karolina.lesinska@hakin9.org</a></p>
</td>
</tr>

</table>
</td>
</tr>

</table>]]></description>
<guid isPermaLink="false">1208@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2010-08-31T09:18:46-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>New website announcement - www.itsecdb.com</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1207</link>
<description><![CDATA[Hi all,<br><br>As some of you may already know, I am the owner of <a href="http://www.cvedetails.com/">http://www.cvedetails.com</a>  (I hope you already know about it) and I recently decided to add list of related OVAL definitions to CVE details page.<br><br>So I created a new web site, <a href="http://www.itsecdb.com/">http://www.itsecdb.com</a>  , which collects OVAL (Open Vulnerability and Assessment Language) definitions from<br>several sources and allows users to view full details (not only comments) of OVAL definitions.<br><br>Using this site you will be able to :<br>- View exactly what you must do to verify a vulnerability, patch or compliance check.<br>- Browse OVAL definitions related to files, rpms, registry keys, patches etc.<br>- View OVAL definitions from several sources like Mitre, Redhat, Suse, NIST etc.<br>- It's fully integrated with <a href="http://www.cvedetails.com/">www.cvedetails.com</a> so you will be able to view/browse OVAL definitions related to products or CVE entries. <br><br>Samples :<br> - OVAL definition sample :<br><a href="http://www.itsecdb.com/oval/definition/oval/org.mitre.oval/def/6253/">http://www.itsecdb.com/oval/definition/oval/org.mitre.oval/def/6253/</a><br> - CVE details with list of related OVAL definitions :<br><a href="http://www.cvedetails.com/cve/CVE-2007-0994/">http://www.cvedetails.com/cve/CVE-2007-0994/</a><br> - Browse objects (files, rpms, patches etc) :<br><a href="http://www.itsecdb.com/oval/oval-objects-index.php">http://www.itsecdb.com/oval/oval-objects-index.php</a><br> - Links to OVAL definitions related to a product :<br><a href="http://www.cvedetails.com/product/3264/Mozilla-Firefox.html?vendor_id=452">http://www.cvedetails.com/product/3264/Mozilla-Firefox.html?vendor_id=452</a><br><br>Regards<br>Serkan &#214;zkan<br>]]></description>
<guid isPermaLink="false">1207@http://www.professionalsecuritytesters.org</guid>
<dc:subject>VulnDB</dc:subject>
<dc:date>2010-08-29T22:02:45-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>FREE Cisco CCNP TSHOOT Webcast</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1206</link>
<description><![CDATA[<p class="MsoNormal"><strong>FREE</strong><strong> Cisco CCNP TSHOOT Webcast August 31st, 2010 with expert trainer and best-selling Cisco Press author Kevin Wallace, see more info about Kevin and register now at:</strong></p>
<p class="MsoNormal"><strong> <a href="http://promo.pearsonitcertification.com/pages/start/plp-webcast-home/index.html?Campaign_Id=262&#38;Activity_Id=212">hhttp://promo.pearsonitcertification.com/pages/start/plp-webcast-home/index.html?Campaign_Id=262&#38;Activity_Id=212</a></strong></p>
<p class="MsoNormal"><strong>Kevin Wallace</strong>, expert trainer and best-selling author of the CCNP TSHOOT 642-832 Official Certification Guide and Network Troubleshooting Video Mentor, takes you on a tour of a troubleshooting scenario that is typical of what you might see on the CCNP TSHOOT exam. Kevin walks you through an HSRP trouble ticket. You will review the theory of HSRP followed by a live troubleshooting demonstration and concluding with a Q&#38;A session.</p>
<p class="MsoNormal">Join us for this Free Pearson IT Certification / Cisco Press Webcast to gain unique insight into what you can expect on the CCNP TSHOOT exam!&#160; <a href="http://promo.pearsonitcertification.com/pages/start/plp-webcast-home/index.html?Campaign_Id=262&#38;Activity_Id=212">Register Now</a>. Hope you can attend!</p>
<p class="MsoNormal">~Jamie</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal" style="text-align: left;"><a href="mailto:jamie.adams@pearson.com">Jamie Adams</a>, Senior Publicist</p>
<p class="MsoNormal" style="text-align: left;">Representing technical brands of Pearson in <strong>networking technologies</strong> (IP Com, network security, storage), and <strong><strong>all certifications</strong></strong> including <strong><strong>Cisco&#174;, Microsoft and CompTIA. </strong></strong></p>
<p class="MsoNormal" style="text-align: left;">Office: 317-428-3012</p>
<p class="MsoNormal" style="text-align: left;">Twitter: <a href="http://www.twitter.com/ciscopress">@ciscopress</a>, <a href="http://www.twitter.com/pearsonitcert">@pearsonitcert</a>, and <a href="http://www.twitter.com/jamieadams76">@jamieadams76</a></p>
<p class="MsoNormal" style="text-align: left;">Facebook: <a href="http://www.facebook.com/ciscopress">facebook.com/ciscopress</a> and other Pearson brands at <a href="http://www.informit.com/socialconnect">informit.com/socialconnect</a>.</p>
<p style="text-align: left;">LinkedIn: <a href="http://www.linkedin.com/in/msjamieadams">www.linkedin.com/in/msjamieadams</a>.</p>]]></description>
<guid isPermaLink="false">1206@http://www.professionalsecuritytesters.org</guid>
<dc:subject>CISCO</dc:subject>
<dc:date>2010-08-29T09:29:36-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>A new advanced security certification from CompTIA -- Fill the survey</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1205</link>
<description><![CDATA[<p>A New Advanced Security Certification is on the way!</p>
<p>To Security Professionals &#8211; Important Request:</p>
<p>In case you did not know, I am a Founding Member of the <a href="http://www.fastlaneus.com/course/fl-secplusbc">CompTIA Security+</a> Cornerstone Committee.&#160; I am writing this blog to ask if you would  complete an important survey because of your expertise in information  security. CompTIA is developing a new advanced security certification  exam to follow <a href="http://www.fastlaneus.com/course/fl-secplusbc">CompTIA Security+</a> (or equivalent experience) and we are seeking your input on the exam  objectives. We hope you&#8217;ll appreciate how important your input is to the  development of this certification, and ultimately to those who follow  you in their security careers.&#160; Personally, I am excited by the  cutting-edge objective set of the intended certification:&#160; It is  up-to-date and pragmatic.&#160; It includes (speak of the devil) objectives  related to:</p>
<ul>
<li>Security and Social Media</li>
<li>Virtualized Desktops (VDI)</li>
<li>Insider Threat</li>
<li>802.1x</li>
<li>Fuzzing</li>
<li>And a plethora of deep, technical, scary stuff!</li>
</ul>
<p>To begin this approximately ten-minute survey, please go here:&#160; <a href="https://s-xut5m-345723.sgizmo.com/">https://s-xut5m-345723.sgizmo.com</a><br> In appreciation for your time and participation, CompTIA is giving away a  CompTIA T-shirt to every 10th person who completes the survey.</p>
<p>CompTIA values your privacy. Results are completely anonymous and the  data will only be viewed in the aggregate. Please complete by September  8, 2010.<br> Thank you very much for your participation.</p>
<p>Please contact research_at_comptia.org if you experience any technical difficulties with the survey.</p>
<p>Go ahead:&#160; support the community and get a free T-Shirt!</p>
<p>Barry Kaufman, CISSP, CEH, MCSE, ITILv3</p>]]></description>
<guid isPermaLink="false">1205@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Security+</dc:subject>
<dc:date>2010-08-27T22:09:15-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>Air Force Lt. Gen. says: The enemy is banging away at our applications</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1204</link>
<description><![CDATA[<p>by  Chuck Paone<br> 66th Air Base Group Public Affairs<br> <br>8/17/2010&#160;-&#160;<strong>HANSCOM AIR FORCE BASE, Mass. (AFNS)</strong>&#160;--&#160;It's  critical to find the right balance between the security and utility of  an information technology network, the Air Force's chief information  officer said here Aug. 13.<br> <br> Speaking at a Hanscom Representatives Association luncheon, Lt. Gen.  William T. Lord described that balancing act as one of "yin and yang," a  term from ancient Chinese philosophy that describes the interdependence  of seemingly contrary forces. <br> <br> Security without utility is of little value; and utility without security is far too dangerous, General Lord said. <br> <br> In harmony, however, the two provide an optimal operating environment, he said.<br> <br> "We have to be able to put new devices -- shiny new objects, as we're  sometimes accused of using -- on a network that doesn't care what the  end-user device is," the general said. <br> <br> The key is to build a network that is flexible and resilient enough to handle whatever it's being used for. <br> <br> It's also important to protect not only the network, but also the work  being done on the Internet, he said, calling for efforts to broaden  security concepts. <br> <br> While network defense used to be focused almost exclusively on building and enhancing firewalls, he said more needs to be done. <br> <br> "The enemy vector used to be banging away at our firewalls; they're not  any longer," General Lord said. "The enemy is banging away at our  applications." <br> <br> "We have over 19,000 (information technology) applications in the Air  Force," he said, noting that Electronic Systems Center's IT Center of  Excellence at Maxwell Air Force Base-Gunter Annex, Ala., examined about  200 of them. "All of them had over 50 vulnerabilities."<br> <br> General Lord&#160;encouraged industry vendors to bring their proposed  solutions for detecting and protecting against such vulnerabilities to  ESC officials, noting that the center is where solutions can effectively  be put into Air Force systems. <br> <br> Industry officials should continue to "bring us your shiny new objects,"  he said. "But when you do, make sure you also tell us how we can  integrate them onto an old infrastructure." <br> <br> And if that's not possible, he said, tell Air Force officials how to  upgrade the old infrastructure without having to lose capability during a  transition. <br> <br> "We need the network to be ready for today's modern applications, but  frankly one can't slow up for the other," he said. "When they do lane  expansion out on I-95 here, they're still doing it with two rush hours a  day. We need to do the same thing."<br> <br> General Lord also implored industry officials&#160;to focus on what the Air Force return on its IT investment will be. <br> <br> "Here's that bright, shiny object and here's what you get out of it, or  here's what you can give up with it -- manpower, legacy applications  that we have to maintain, etc.," he said.<br> <br> Determining what that return is can help solve a lot of problems,  including the risk of running behind a rapidly evolving technology  curve, he said, stressing that we need to avoid buying "yesterday's  technology tomorrow." <br> <br> "There are probably acquisition things that need to be fixed," he said.  "There are process things that need to be fixed. There are resource  management things we need to fix.<br> <br> "But I think when you bring the return on investment with new combat  capability, that can be the catalyst that begins to help us fix things,"  he said.</p>]]></description>
<guid isPermaLink="false">1204@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2010-08-23T08:14:05-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

</channel>
</rss>
