Informational

TwitterFacebook
Get flash to fully experience Pearltrees
This free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework. http://www.offensive-security.com/metasploit-unleashed/Main_Page

Metasploit Unleashed - Mastering the Framework

December 24, 2011 The latest version of Infosec Island is now available. There are more content options and more ways to connect and interact with your peers. https://www.infosecisland.com/

Infosec Island

Broadband and information technology are powerful factors in small businesses reaching new markets and increasing productivity and efficiency. 1. https://www.infosecisland.com/blogview/13823-FCCs-Ten-Key-Cybersecurity-Tips-for-Businesses.html

FCC's Ten Key Cybersecurity Tips for Businesses

Information Security Policies and Procedures Part 1

Note: This is part of an ongoing series on documentation development. https://www.infosecisland.com/blogview/12304-Information-Security-Policies-and-Procedures-Part-1.html
https://www.infosecisland.com/blogview/13452-Information-Security-Policies-and-Procedures-Part-2.html This is part of an ongoing series on documentation development. Please be sure to read the previous posts in this series: Part 1

Information Security Policies and Procedures Part 2

https://www.infosecisland.com/blogview/13453-Information-Security-Policies-and-Procedures-Part-3.html

Information Security Policies and Procedures Part 3

This is part of an ongoing series on documentation development.

Information Security Policies and Procedures Part 4

This is part of an ongoing series on documentation development. Please be sure to read the previous posts in this series: Part 1 Part 2 Part 3 The formatting and structure of documentation may not seem like the most enthralling topic, and in many (most) ways it is not. https://www.infosecisland.com/blogview/13454-Information-Security-Policies-and-Procedures-Part-4.html
https://www.infosecisland.com/blogview/13455-Information-Security-Policies-and-Procedures-Part-5.html This is part of an ongoing series on documentation development.

Information Security Policies and Procedures Part 5

It is interesting how many people believe that their wireless is secure because they are using WPA. Well we did a test recently and were able to basically password guess our way with a dictionary attack using either a straight dictionary or a rainbow table. The cool thing is I bought an ALFA USB antenna and could sit down at the corner coffee place and still see my wireless access point.

Hacking the WPA Airwaves

https://www.infosecisland.com/blogview/13748-Hacking-the-WPA-Airwaves.html
http://www.infosecisland.com/blogview/20571-CISSP-Reloaded-Domain-Three-Telecoms-and-Network-Security.html This is the 3rd part on my CISSP Reloaded where I am revisiting the 10 CISSP domains I studied for many years ago to see what has changed and how much of it I have retained as well as adding in my own personal thoughts, experiences and rambles into the mix. ( Part One ) ( Part Two )

CISSP Reloaded Domain Three: Telecoms and Network Security

Malware

If you have a big network with multiple Access Switches connecting to the core switches or routers then tracing a device like a PC or a laptop for troubleshooting or security purposes is one of those tasks that you often end up doing. This is not a difficult task but can certainly be time consuming.

HowTo: Find switchport of a MAC Address on Cisco Catalyst Switch | ItsyourIP.com

NIST.gov - Computer Security Division - Computer Security Resource Center

[Mar. 23, 2012] -- NIST announces the second public draft of NIST Interagency Report (NISTIR) 7622, Notional Supply Chain Risk Management Practices for Federal Information Systems.

CC Blog: Recommendations to vendors for communicating product security information

Hi, this is Chad Dougherty of the Vulnerability Analysis team. One of the important roles that our team plays is coordinating vulnerability information among a broad range of vendors.
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).

National Vulnerability Database Home

Common Vulnerability Scoring System Version 2 Calculator

National Vulnerability Database CVSS Scoring