<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Security Kitchen</title>
	<atom:link href="http://blog.remes-it.be/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blog.remes-it.be</link>
	<description></description>
	<lastBuildDate>Mon, 23 Aug 2010 21:40:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>A hommage to my friends</title>
		<link>http://blog.remes-it.be/?p=480</link>
		<comments>http://blog.remes-it.be/?p=480#comments</comments>
		<pubDate>Mon, 23 Aug 2010 21:39:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=480</guid>
		<description><![CDATA[Next month, at Brucon, we mark the 1st birthday of the Eurotrash Information Security Podcast.  One year ago I sat together with Craig Balding, Dale Pearson and Chris-John Riley on the last day at Brucon and we all agreed on one thing : &#8220;There was no real European information security podcast.&#8221; It&#8217;s not that we [...]]]></description>
			<content:encoded><![CDATA[<p>Next month, at Brucon, we mark the 1st birthday of the<a href="http://www.eurotrashsecurity.eu/index.php/Main_Page" target="_blank"> Eurotrash Information Security Podcast</a>.  One year ago I sat together with Craig Balding, Dale Pearson and Chris-John Riley on the last day at Brucon and we all agreed on one thing : &#8220;There was no real European information security podcast.&#8221;</p>
<p>It&#8217;s not that we didn&#8217;t like podcasts from across the pond. Au contraire. There&#8217;s were some pretty good ones back then and more have popped up in the past year but we missed European nuance and it all seemed like everything in infosec came from the U.S. and we were just eating their beans.  Apart from having good fun together we wanted to create a platform that allowed us to put European security people in the spotlight. And have we ? Sandro Gauci, Brian Honan, Justin Clarke, Didier Stevens, Ewout Meij , Portswigger, Aluc and Ivan Ristic are only some of the names that we were honored to have as our guests. It was awesome talking, listening and learning from them.</p>
<p>Today we released our 25th episode, 13 full-length episodes and 12 microcasts. We chose to add the microcast format because sometimes one of us would get in touch with someone awesome and we wouldn&#8217;t all have time to join in the conversation. We felt it was the best way to bring more than 1 episode per month and we haven&#8217;t regretted it. We sincerely hope you didn&#8217;t either <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>With this post I want to share my gratitude for being able to do this with Craig, Dale and Chris. I have enjoyed every single minute of it and without either of them, this podcast wouldn&#8217;t exist.</p>
<p>If I were vain enough to track server logs, I would know how many people are actually downloading what we do but that doesn&#8217;t really matter.  If you happen to listen to our podcast and you are coming to Brucon in September, consider yourself invited to the first <a href="http://www.eurotrashsecurity.eu/index.php/Brucon_meetup" target="_blank">Brucon Podcasters Meetup</a> !</p>
<p>thanks for listening &amp; sorry for the funny accent !</p>
<p><a href="http://blog.remes-it.be/wp-content/uploads/2010/08/VivaLaEurotrash2.mp3">Viva La Eurotrash !</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=480</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://blog.remes-it.be/wp-content/uploads/2010/08/VivaLaEurotrash2.mp3" length="751489" type="audio/mpeg" />
		</item>
		<item>
		<title>It&#8217;s the analyst, silly &#8230;</title>
		<link>http://blog.remes-it.be/?p=476</link>
		<comments>http://blog.remes-it.be/?p=476#comments</comments>
		<pubDate>Thu, 12 Aug 2010 18:32:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=476</guid>
		<description><![CDATA[Jack Daniel posted a link on twitter earlier today that was titled &#8220;it&#8217;s the buying center, silly&#8230;&#8221; which attracted my attention.  Maybe because I had no stinkin&#8217; clue what &#8220;buying centers&#8221; were and wanted to learn something, maybe because I felt an awesome quote coming &#8230; The quote was ripped from James Carville, apparently driven [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.twitter.com/jack_daniel" target="_blank">Jack Daniel</a> posted a link on twitter earlier today that was titled &#8220;<a href="http://blogs.gartner.com/greg_young/2010/08/12/wafs-its-the-buying-center-silly/" target="_blank">it&#8217;s the buying center, silly&#8230;</a>&#8221; which attracted my attention.  Maybe because I had no stinkin&#8217; clue what &#8220;buying centers&#8221; were and wanted to learn something, maybe because I felt an awesome quote coming &#8230; The quote was ripped from James Carville, apparently driven by the fact that Mr. Author himself had spent enough minutes in the same room with James Carville to have a picture taken that fit them both in the same frame. Awesomeness. For those who don&#8217;t know Mr. Carville, Google is your friend.</p>
<p>Much to my amazement, the post in question was about WAFs. Yup, Web Application Firewalls.  Here&#8217;s the gist of the post :</p>
<blockquote><p>WAFs are a high value safeguard for custom applications, but are held  back because so many groups are potentially involved in the operation  and buying of applications.  Data center ops, server ops, appdev,  application owners, security, network ops…  Unlike other products like  IPS which have usually two buying centers, there is a wide spread to  which roles are involved in WAF.  There will be some reduction in the  number of buying centers, but as long as custom web applications are  housed and delivered in this complex manner, don’t expect organizations  to change to accommodate the safeguard.</p></blockquote>
<p>Ok, that&#8217;s actually the whole post minus the explanation of the title <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>So apparently &#8216;buying center&#8217; is leet analyst speak for a silo aka a &#8220;cylinder of excellence&#8221;* and Mr. Analyst gives us the reason why adoption is slow or inconsistent : too many silo&#8217;s are involved in buying this tech. Either organisations have to reduce the number of silos or the technology itself needs to cater for less silos. To top it off, he hints &#8220;don&#8217;t expect organizations to change to accomodate the safeguard.&#8221;</p>
<p>I beg to differ from this point of view.  There is a million things wrong in this world, blaming the (assumed) failure of WAFs on a) targeting the wrong silos or b) being an incomprehensible solution, is not gonna solve any of them. (properly designed and implemented) WAF solutions cater for just as much silos as (properly designed and implemented) IPS solutions. The problem is that the silos, even if there&#8217;s only two, are cemented in. They&#8217;re completely separated and years have gone by since someone peeked over the wall to see (with interest) what the other side is doing. Oh wait, we peeked allright, but only to see how hard the other side was failing.</p>
<p>Unless an organization actively starts to break down the silos and creates cross-functional and active involvement in information security, you can look at any technological solution and see it fail before it leaves the styrofoam womb.Obviously, none of these evolutions can be captured in magical squares or quantified in market share estimates. It is however, in my very humble opinion, the focal point of our efforts for years to come.</p>
<p>Thus an armchair analyst has spoken.Unfortunately I don&#8217;t have a picture of me and Jack Daniel &#8230; yet.</p>
<p>P.S. : I have nothing personal against analysts, there&#8217;s some pretty smart dudes out there (no name dropping here <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ). It just irks me that some of them seem to feel they can pontificate whatever they seem appropriate under the flag of being industry-defining.</p>
<p>&#8212;-</p>
<p>* I think Jack Daniel himself came up with the name &#8220;cylinder of excellence&#8221;, I may be attributing incorrectly.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=476</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>list of podcasts</title>
		<link>http://blog.remes-it.be/?p=472</link>
		<comments>http://blog.remes-it.be/?p=472#comments</comments>
		<pubDate>Sun, 25 Jul 2010 14:51:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=472</guid>
		<description><![CDATA[It&#8217;s time to bring my list of favorite podcasts up to date.  Why not share it with you In alphabetical order : Aluc.TV &#8211; Aluc started with a videocast which covers all types of security related topics. Most recently (I think starting in May) he also started to do AlucRadio episodes, which are audio podcasts [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s time to bring my list of favorite podcasts up to date.  Why not share it with you <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>In alphabetical order :</p>
<p><strong>Aluc.TV </strong>&#8211; Aluc started with a videocast which covers all types of security related topics. Most recently (I think starting in May) he also started to do AlucRadio episodes, which are audio podcasts featuring interviews with Security people covering the whole spectrum.</p>
<p><strong>Beyond The Perimeter</strong> &#8212; Recently added. Good infosec content, good interviews and rather short episodes, which I like <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>Disaster Protocol</strong></p>
<p><strong>Eurotrash Security Podcast </strong>&#8211; shameless plug <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>Exotic Liability </strong>&#8211; in most cases NSFW but often good discussions + the guys are awesome.</p>
<p><strong>An Information Security Place Podcast </strong></p>
<p><strong>Infosec Daily Podcast</strong></p>
<p><strong>Network Security Podcast </strong></p>
<p><strong>Packet Pushers </strong>&#8211; recently discovered, good technical coverage of network security topics !</p>
<p><strong>Risky Business</strong> &#8212; Professional Aussie podcast.</p>
<p><strong>Securabit</strong></p>
<p><strong>Security Justice</strong></p>
<p><strong>Social-Engineer Podcast </strong>&#8211; unique podcast covering only social engineering topics</p>
<p><strong>The Southern Fried Security Podcast &#8212; </strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=472</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Reply to &#8220;The Cash Drawer Lock Box and SMB Security&#8221;</title>
		<link>http://blog.remes-it.be/?p=468</link>
		<comments>http://blog.remes-it.be/?p=468#comments</comments>
		<pubDate>Wed, 21 Jul 2010 21:23:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=468</guid>
		<description><![CDATA[I just finished reading &#8220;The Cash Drawer Lock Box and SMB Security&#8220;, a post on Dark Reading by one of the infosec community I hold in very high esteem, Jennifer Jabbusch.  As Dark Reading does not allow commenting without registration, I have to post my thoughts on this article here. In the post, Jennifer posts [...]]]></description>
			<content:encoded><![CDATA[<p>I just finished reading &#8220;<a href="http://www.darkreading.com/blog/archives/2010/07/the_cash_drawer.html">The Cash Drawer Lock Box and SMB Security</a>&#8220;, a post on Dark Reading by one of the infosec community I hold in very high esteem, Jennifer Jabbusch.  As Dark Reading does not allow commenting without registration, I have to post my thoughts on this article here.</p>
<p>In the post, Jennifer posts her view on how security is handled in SMB-land. Much to my amazement, the average SMB is described as a mom-and-pop shop.  Unfortunately, it isn&#8217;t.  As I&#8217;m European, I always try to view a subject from different angles.  The definition of SMB (or SME) is different wherever you live. Allthough Europe is trying to standardize, the concept of SMB is fuzzy. In Germany and SMB would have anything below 250 employees, in Belgium (this is SMB Ground Zero, just to put the record straight) it would have fewer than 100 employees.  Today we are calling anything below 50 small and anything between 50 and 250 medium.  In the US on the other hand small is anything below 100 employees and medium anything below 500.</p>
<p>This is not trivial information. Assuming you are targetting an SMB market, you have to know who is in that market.  Equalizing everything to the mom&amp;pop shop caricature and then saying they don&#8217;t GET security is a little over the top.   It just isn&#8217;t true.</p>
<p>I have worked in several industries. I have worked in companies with fewer than 100 employees who have a revenue that you would proud of in an enterprise.  I have done security jobs in mom&amp;pop (and son&amp;daughther) shops and I&#8217;ve been catering for enterprise and government customers.  I&#8217;ve seen it all.  The closest I&#8217;ve been to the cash drawer lock box was when I was fixing a computer with a stack of bills worth 50k euros next to me, and that was because they forgot to put them in the (unlocked) drawer. However, I disgress, it&#8217;s not about me (or my integrity).</p>
<p>In the SMB market, security isn&#8217;t THAT different and, it might amaze you, but most people do get it.  A lot of those companies are dealing with compliance due to PCI or other regulations, a lot of those companies have to get it. And they do, or they try, but there&#8217;s not a lot of &#8220;security companies&#8221; interested to help. They&#8217;re too small &#8230;</p>
<p>On the other hand, you&#8217;re saying how much different they are from the enterprises. How enterprises do appreciate the risk and have and use the necessary resources and knowledge to do something about it. Every day you&#8217;re proven wrong. The answer to the question why is suited for another post.</p>
<p>Big enterpises keep losing customer records, big enterprises (knowing what they&#8217;re doing and knowing the threats they&#8217;re up against) keep getting pwned and pwned and pwned.Why is that ? Because they don&#8217;t get security.  And they deserve the rap much more than their SMB counterparts.</p>
<p>What the SMB people see is a bunch of vampires knocking at their door touting $1000 a day rates to solve their problems, but unable to tell them what their problems really are.</p>
<p>What they hear is a bunch of fancy product vendors unable to tell them what added value this or that appliance means for their business.</p>
<p>What they feel is fear, uncertainty and doubt being shoved down their throat and we&#8217;re not even courteous enough to allow them to swallow.</p>
<p>There is no need to dumb down security for the SMB so they will get it.  There is a need for us to understand them more than there is the other way around.</p>
<p>I understand the wake-up call is long overdue, but I&#8217;m afraid you are ringing the wrong bell.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=468</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>lessons from CVE-2010-2568</title>
		<link>http://blog.remes-it.be/?p=465</link>
		<comments>http://blog.remes-it.be/?p=465#comments</comments>
		<pubDate>Wed, 21 Jul 2010 11:01:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=465</guid>
		<description><![CDATA[CVE-2010-2568 (aka the LNK vulnerability) was another 0-day to add to the list for 2010. But more than that, it showed some ugly truths about how we, as an industry, look at security and how we, as an industry, look at people who work with products and solutions to support their business. Every 0-day provides [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2568" target="_blank">CVE-2010-2568</a> (aka the LNK vulnerability) was another 0-day to add to the list for 2010. But more than that, it showed some ugly truths about how we, as an industry, look at security and how we, as an industry, look at people who work with products and solutions to support their business. Every 0-day provides a 360° view of the whole playing field. More than interesting.</p>
<ol>
<li>SCADA vendors, Siemens in this case, don&#8217;t care about the security of their customers in the slightest. Their database password is compromised since 2008 and still, in an advisory on the virus (abusing the LNK flaw) that targets exactly that password, they do nothing less than tell their customers to not change that password.  It is a complete trainwreck.</li>
<li>Product vendors, Microsoft in this case, fail to provide their customers with adequate solutions but choose to provide quick fixes that are completely unusable since they wreck the complete user experience.  Releasing it as a &#8216;fix-it&#8217; solution to make it &#8216;easier&#8217; for people to implement just exponentially increases the fail.</li>
<li>Independent people succeed in providing work-arounds for the flaw using standard product functionality (namely the <a href="http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/" target="_blank">SRP fix provided by Didier Stevens</a>). We can only be thankful to be active in a community with engaged people that choose not to sit back and be force-fed the crap &#8216;innovative&#8217; and &#8216;thought-leading&#8217; cooperations provide us but actually go out to do what needs to be done.</li>
</ol>
<p>The question remains why Microsoft can&#8217;t come up with the stuff Didier came up with.  It uses standard functionality of the OS, it can be implemented in small and large environments in an easy and controlled manner and it doesn&#8217;t break the user experience. What is so difficult about that ? Today, it&#8217;s 2010 FFS, security administrators have evolved from registry editing and most do understand how your OS works. Stop treating them like babies and provide them the solutions they need to protect them from the evil posed by your fuck-ups.</p>
<p>To end, Didier deserves a word of thanks for the work he did on the SRP fix for this one.  It looks like something easy but he took the time, did the research, he did the testing and he chose to share with the community.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=465</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>&#8220;Le mieux est l&#8217;ennemi du bien&#8221; or OSSTMM v3, will it ever be &#8230; free ?</title>
		<link>http://blog.remes-it.be/?p=458</link>
		<comments>http://blog.remes-it.be/?p=458#comments</comments>
		<pubDate>Mon, 28 Jun 2010 21:11:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=458</guid>
		<description><![CDATA[I blogged about this more than a year ago, and we interviewed Pete Herzog of ISECOM about a month ago on the Eurotrash podcast. Where the hell is OSSTMM v3? If it&#8217;s good enough to sell €3000 trainings, it&#8217;s good enough for me. I loved OSSTMM when it was v2. It was open, it was [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.remes-it.be/?p=94">I blogged about this more than a year ago</a>, and we interviewed Pete Herzog of ISECOM about a month ago on the <a href="http://www.eurotrashsecurity.eu" target="_blank">Eurotrash podcast</a>. Where the hell is OSSTMM v3?</p>
<blockquote><p>If it&#8217;s good enough to sell €3000 trainings, it&#8217;s good enough for me.</p></blockquote>
<p>I loved OSSTMM when it was v2. It was open, it was verifiable and it was the shit if it came to testing methodologies. One of it&#8217;s key &#8220;selling&#8221; was that you no longer had to hide behind a proprietary standard (in most cases, companies saying that, were saying they had no methodology at all!). You could reference the OSSTMM and your customer could download the standard, see what he would be getting and if it fitted his needs. Moreover he could verify whether your work lived up to the standard you promised him.</p>
<p>Life was good.</p>
<p>I first saw Pete talking about v3 back in 2007, at FOSDEM, one of the biggest Open Source developers gatherings in the world. Promises were big and the emphasis was on quality. ISECOM wanted to deliver the best standard, nothing more, nothing less. After his talk at FOSDEM, I subscribed to the OSSTMM reviewers group and I did review a few chapters.  What I saw was awesome, it didn&#8217;t look like there was much more work left.</p>
<p>I was wrong, or wasn&#8217;t I ?</p>
<p>Eventually, since activity on the list went to near-zero I let it slip.  I expected much smarter people than me contributing to the standard and was anxiously waiting for it to be released. Fast forward to 2009.  Still no OSSTMM v3 and I <a href="http://blog.remes-it.be/?p=94">blogged</a> . Pete responded in a comment on that same post, you can read it for yourself.  OSSTMM v3 was going to be a game changer, completely different from v2, hence it was taking that long.</p>
<p>Another year (+ a few months) has passed. and still no OSSTMM v3.</p>
<p>And thus comes the question.  ISECOM is <a href="http://www.isecom.org/schedule.shtml" target="_self">training</a> OPSA and OPST based on OSSTMM v3, at about 2900 euro&#8217;s per student. You can become Silver, Gold or Platinum Partner for $99, $299 or $999 respectively and have access to the (draft) OSSTMM v3. The question is not when OSSTMM v3 will be there, since ISECOM thinks it&#8217;s good enough to base training on it (Pete has also stated that v2 is crap compared to v3 on the Eurotrash episode), the question is when it will live up to the OS in it&#8217;s name. When will it be open source again?</p>
<p>I can perfectly understand that mouths need to be fed and bills need to be payed. I can live with that. There&#8217;s 3 solutions I see in the immediate future :</p>
<ol>
<li>Release OSSTMMv3 to the public, as it is supposed to be. If it&#8217;s good enough to sell €3000 trainings, it&#8217;s good enough for me.</li>
<li>Provide a deadline for OSSTMMv3 and gather a team (Gold,Silver,Platinum or volunteer, you choose) that can meet that deadline. Then release OSSTMMv3 to the public, as it is supposed to be.</li>
<li>drop the OS and call it STMMv1</li>
</ol>
<p>Without a doubt, I got the greatest respect for Pete and his team. Some of the greatest minds in the European security scene are (according to the website) working with Pete to do nothing but great stuff.  It is, however, time to stop sending mixed messages and let the community know where it&#8217;s at.</p>
<p>When, if ever, will we see the new (Open Source) Security Testing Methodology Manual ?</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=458</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>What if I train my people and they leave ?</title>
		<link>http://blog.remes-it.be/?p=452</link>
		<comments>http://blog.remes-it.be/?p=452#comments</comments>
		<pubDate>Mon, 17 May 2010 21:54:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=452</guid>
		<description><![CDATA[I&#8217;d like to dedicate this to all the children I have some food in my bag for you Not the edible food the food you eat no Perhaps some food for thought Since knowledge is infinite It has infinitely fell on me so um &#8230; Erykah Badu, Appletree The obvious answer to the question in [...]]]></description>
			<content:encoded><![CDATA[<blockquote>
<p style="text-align: center;">I&#8217;d like to dedicate this to all the children<br />
I have some food in my bag for you<br />
Not the edible food the food you eat no<br />
Perhaps some food for thought<br />
Since knowledge is infinite<br />
It has infinitely fell on me so um &#8230;</p>
</blockquote>
<p style="text-align: right;"><em>Erykah Badu, Appletree</em></p>
<p style="text-align: left;">The obvious answer to the question in the title is : &#8220;What if you don&#8217;t, and they stay.&#8221;</p>
<p style="text-align: left;">In information security keeping your skills up to date is key and finding the necessary budget to do so becomes more and more difficult.  The funny thing with training starts when you actually do have a budget <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  What to choose ? Not an easy task.</p>
<p style="text-align: left;">You can choose to chase one of the blanket certs. CISSP, CISA, CISM, &#8230; you name it. They look awesome on your CV and the pins you receive are cool for S&amp;M games, let alone the awesome looking paper cert you get to frame and hang on your wall.  Eternal sources of infinite ego boost.  But I disgress.</p>
<p style="text-align: left;">Technical certs.  Cisco, Microsoft, Juniper, [insert vendor here], &#8230; Sure, if you like yourself some letter soup.</p>
<p style="text-align: left;">Then, there&#8217;s the rest.  SANS offers awesome training, but your budget will probably not suffice.  While I&#8217;ve heard nothing than positive feedback. If you&#8217;re living in Europe (like me) there&#8217;s not a lot of opportunity to get to the classroom based trainings (one or two events per year) and If you have a real job and a family (like me) computer-based training, mentored training, remote learning isn&#8217;t a good choice either.</p>
<p style="text-align: left;">So in essence, you&#8217;re looking for local training by awesome trainers that can really push you to and over your limit and preferably close to where you live so you can maximize your budget.  It&#8217;s a damn shame spending cash on transport just to get you to the training &#8230;</p>
<p style="text-align: left;">One tip : Don&#8217;t settle for the second-hand knowledge transfer by your local reseller that sees their training center as a marketing tool rather than a center of excellence.</p>
<p style="text-align: left;">I hear you coming already &#8230; You won&#8217;t be able to spend the training budget you got without getting good value for your money.  Not true !!  Look at conferences !!</p>
<p style="text-align: left;">Europe has already had the Blackhat briefings a few weeks ago, lots of other conferences are yet to come.  One of those is Brucon, a conference that is near and dear to my heart (don&#8217;t ask me to utter that sentence in real life without rofling please !!).</p>
<p style="text-align: left;">Two days before Brucon, on September 22nd and 23rd there are awesome trainings planned that have a reasonable price and are taught by people who really know their stuff.  Examples ?</p>
<p style="text-align: left;">Sandro Gauci is teaching a crash course in pentesting and securing VoIP.</p>
<p style="text-align: left;">Joe McCray is teaching his Advanced Penetration Testing course. The sequel to his well-received training last year.</p>
<p style="text-align: left;">Sharon Conheady is coming back for an awesome Social Engineering course.</p>
<p style="text-align: left;">Paul Asadoorian is teaching Advanced Vulnerability Scanning using Nessus</p>
<p style="text-align: left;">and last, but not least</p>
<p style="text-align: left;">Justin Searle is coming to Brussels to introduce you in the wonderworld that is Assessing and Exploiting Web Applications with Samurai-WTF.</p>
<p style="text-align: left;">From the <a href="http://2010.brucon.org/index.php/Training" target="_blank">website</a> :</p>
<blockquote>
<p style="text-align: left;">The price for the 2 day courses is 895 € early bird (+ VAT) per  attendee. After 1st of July this will become 995 €.</p>
</blockquote>
<p style="text-align: left;">A vendor cert will set you back three times that amount and will only confirm what you already know. You&#8217;ll spend close to 5 or 6 times that amount to achieve a blanket cert. Why not make both your boss and yourself happy by being economic with the money provided and get real training, by real experts, at Brucon ?</p>
<p style="text-align: left;">
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=452</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>challenge for free beer @ brucon</title>
		<link>http://blog.remes-it.be/?p=445</link>
		<comments>http://blog.remes-it.be/?p=445#comments</comments>
		<pubDate>Sat, 15 May 2010 10:04:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=445</guid>
		<description><![CDATA[Update 0&#215;01 There&#8217;s actually 2 ways to find the solution.  I currently have answers using only one way (you lazy bastids). I will limit the number of winners to 3 (three).  At least one winner needs to provide both possible solutions. &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; Update 0&#215;02 Ok, I have too hard a time to choose winners.  Khurt, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Update 0&#215;01<br />
</strong></p>
<p>There&#8217;s actually 2 ways to find the solution.  I currently have answers using only one way (you lazy bastids). I will limit the number of winners to 3 (three).  At least one winner needs to provide both possible solutions.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p><strong>Update 0&#215;02</strong></p>
<p>Ok, I have too hard a time to choose winners.  Khurt, test@india, Kasperle, Mirko, courts and Chris please ping me on<br />
wim 0&#215;40 eurotrashsecurity 0&#215;20 eu . For the others, watch <a href="http://www.thehexfactor.org" target="_blank">http://www.thehexfactor.org</a> for the 2009 challenges (walk throughs are being released weekly as of last week) &#8230; I might release another few little beer challenges in a few weeks. Thanks for playing !</p>
<p>this is a first test to see what I can come up with to get you guys over to<a href="http://www.brucon.org"> Brucon</a>.</p>
<p>First (non-Belgian) who tells me in which Belgian city this picture was taken, gets a free beer at Brucon.</p>
<p>Submissions are only accepted by commenting on this post.</p>
<p>Please provide a detailed description of how you found the solution.</p>
<p><a href="http://blog.remes-it.be/wp-content/uploads/2010/05/pot.jpg"><img class="aligncenter size-full wp-image-444" title="pot" src="http://blog.remes-it.be/wp-content/uploads/2010/05/pot.jpg" alt="" width="1600" height="1458" /></a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=445</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>tools with tools can only fool fools</title>
		<link>http://blog.remes-it.be/?p=441</link>
		<comments>http://blog.remes-it.be/?p=441#comments</comments>
		<pubDate>Tue, 11 May 2010 20:02:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=441</guid>
		<description><![CDATA[If you&#8217;ve been involved with pentesting, chances are you played around with tools to automate the process in one way or another. Core Impact, Metasploit and CANVAS are the first to come to mind.  As with any industry, the tools we work with evolve and evolution generally means they get better.  Few will argue that [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve been involved with pentesting, chances are you played around with tools to automate the process in one way or another. Core Impact, Metasploit and CANVAS are the first to come to mind.  As with any industry, the tools we work with evolve and evolution generally means they get better.  Few will argue that better tools improve the ability of companies to detect vulnerabilities, make the risk posed by those vulnerabilities tangible by actually exploiting them and kicking the people responsible for the assets right where it hurts.  They enable companies to employ people that might not be considered pentesters to verify vulnerabilities that would otherwise end up marked green, orange and red on a chart, ideally accompanied by their respective temporal CVSS score.  Which one is better?</p>
<p>Do these improving tools make pentesters redundant ? Far from it.  As hardcore as they portray themselves, there are very few (dare I say none?) that do not use one or another tool, framework or whatever you want to call it. If you are doing pentesting for a living, economy is key.  You just don&#8217;t want to be spending time writing code for the vuln you just detected. Why exactly would you want to reinvent the wheel? There&#8217;s much better things you can do with your time.</p>
<p>If a pentester feels redundant with ever-improving tools flooding the market, my bet that the subject involved is a tool himself and his lazy ass deserves a cruel beating. If you forgot to improve yourself because you were thinking your 1337 apps wouldn&#8217;t be replaced by a industrialized solution, haha on you !</p>
<p>Mr.<a href="http://www.twitter.com/jack_daniel" target="_blank"> Jack Daniel</a> said it well : &#8220;Any pentester that feels redundant because of Metasploit Express already was.&#8221;</p>
<p><em>Tools</em> with tools will always be able to fool fools. Companies providing pentesting services will have to step up their game, mediocrity shall no longer be the standard, because the customer can now do that part of it themselves.</p>
<p>Anybody serious about the infosec industry should welcome that. Evolution is happening. And I, for one, think that is a very good thing.</p>
<p>(part of this blogpost was inspired by<a href="http://www.twitter.com/indi303" target="_blank"> indi303</a>, <a href="http://www.twitter.com/chrisjohnriley" target="_blank">chrisjohnriley</a>, <a href="http://www.twitter.com/danielkennedy74" target="_blank">danielkennedy74</a> and <a href="http://www.twitter.com/dasfiregod" target="_blank">dasfiregod</a> on twitter.)</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=441</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>closed</title>
		<link>http://blog.remes-it.be/?p=429</link>
		<comments>http://blog.remes-it.be/?p=429#comments</comments>
		<pubDate>Mon, 25 Jan 2010 22:13:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.remes-it.be/?p=429</guid>
		<description><![CDATA[Hi, I&#8217;ve been unable to blog for a while now and for various reasons I am closing this place until further notice. Yes, I&#8217;ll be back but don&#8217;t ask me when   I got my hands full with some speaking engagements, the Eurotrash podcast, prepping some other exciting stuff, my day job and family &#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>I&#8217;ve been unable to blog for a while now and for various reasons I am closing this place until further notice.</p>
<p>Yes, I&#8217;ll be back but don&#8217;t ask me when <img src='http://blog.remes-it.be/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   I got my hands full with some speaking engagements, <a href="http://www.eurotrashsecurity.eu" target="_blank">the Eurotrash podcast</a>, prepping some other exciting stuff, my day job and family &#8230; I&#8217;ll be busy enough.</p>
<p>I hope to catch you all at a later point this year !</p>
<p>Take care &amp; stay secure !</p>
<p>Wim</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.remes-it.be/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.remes-it.be/?feed=rss2&amp;p=429</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
