Does anyone want to talk about general security topics?

Reel

Diamond Member
Jul 14, 2001
4,484
0
76
All I see so far are antivirus/spyware type questions. Anybody else hoping to discuss real security issues?

To get the ball rolling, we could talk about something from Bruce Schneier's newsletter: penetration testing. article and article

I did pen testing for a bit at my old job and the mentality was that we had to find a way in or we weren't doing our job. There were some times when we would just brute force passwords and get lucky and find a complex password. I just felt that the mentality of penetration testing rarely fixed problems since most of them were organizational and procedural problems to begin with. For example, hospitals never had secure passwords because doctors would say "I'm too busy saving lives to have to remember and spend the time typing a complex password".
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
I agree that manual pen-testing is a waste of $$. It's a nice income stream for the "consulting" companies.

IMHO, automated pen testing (aka: input fuzzing, etc) is a useful tool to run against applications before they're put into production use. Shopping carts, etc... Good tool to make sure the applications are decently coded. Particularly valuable for internally developed applications, where the quality/quantity of code review may not match that of a vendor product.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: Reel
All I see so far are antivirus/spyware type questions. Anybody else hoping to discuss real security issues?

To get the ball rolling, we could talk about something from Bruce Schneier's newsletter: penetration testing. article and article

I did pen testing for a bit at my old job and the mentality was that we had to find a way in or we weren't doing our job. There were some times when we would just brute force passwords and get lucky and find a complex password. I just felt that the mentality of penetration testing rarely fixed problems since most of them were organizational and procedural problems to begin with. For example, hospitals never had secure passwords because doctors would say "I'm too busy saving lives to have to remember and spend the time typing a complex password".

http://www.rearguardsecurity.com/ episode 2 talks about the password thing specifically.

Organizational and procedural problems are real, and cause plenty of security vulnerabilities. They are definitely something that should be fixed, and sometimes it takes a penetration to do it.

BTW, I posted a non spyware/antivirus thread.
 

ScottFern

Diamond Member
Oct 23, 2002
3,629
2
76
I have a general security question. I have started my career as a junior admin (if you want to call it that) and I am in charge of 70 WinXP workstations and 9 Win2003 Servers. However, looking ahead I was thinking about trying to get into security field as a specialization. But, what are the best certifications (yes I know the dreaded useless cert) and type of jobs that lead to bigger and better security roles. At my current employer its a smaller company with 9 people in the IT department total and no one is the security specialist per se.

Security+ ? -> CCNA -> CISSP?
 

Reel

Diamond Member
Jul 14, 2001
4,484
0
76
Originally posted by: ScottFern
I have a general security question. I have started my career as a junior admin (if you want to call it that) and I am in charge of 70 WinXP workstations and 9 Win2003 Servers. However, looking ahead I was thinking about trying to get into security field as a specialization. But, what are the best certifications (yes I know the dreaded useless cert) and type of jobs that lead to bigger and better security roles. At my current employer its a smaller company with 9 people in the IT department total and no one is the security specialist per se.

Security+ ? -> CCNA -> CISSP?

CCNA is more for Cisco networking devices than general security. CISSP pays lots of money to try to position themselves as the top security certification and for some purposes it is required that a CISSP be involved in a project (thinking DoD here). Regardless, the best certs are the ones you can get your company to pay for. If you can write up a business case about how it will benefit your company, you may be able to get them to pay for them. Also, bring up your interest to your supervisor and tell them that you'd like to absorb that role as part of your career growth. The more you learn about security hands on, the more you will learn and the easier any security cert exams would be.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
CISSP is for management. Look at Sans.

The best thing I think someone can do is to play with and learn about this stuff constantly. Setup a lab. Break it. Rebuild it.

Most of all, have fun.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |