Browsing Monthly Archive March 2011

How to Learn the IT Skills of a Security Professional

In the comments to an earlier article, Ideal Skill Set For the Penetration Testing, a reader, Nicole, asked, “Does anyone have any suggestions on where

March 31, 2011 General Security, Hacking, Other

CISA Domain 4 Information Systems Operations, Maintenance and Support

For 2011, ISACA has updated the domains reducing them from 6 to 5.  Domain 4 now includes Disaster Recovery from the old Domain 6.  This

CISSP Domain – Application Development Security

Application development security requires an awareness of how different environments demand different security. For example, the security for running a mainframe application that is not

March 30, 2011 CISSP, IT Certifications

Finding Security Vulnerabilities in PHP Using Grep

Description: Using grep to find common web application vulnerabilities within your applications. Introduction It is a common misconception that companies need to purchase complicated and

March 29, 2011 Application Security

CISA Domain 3 Information Systems Acquisition, Development and Implementation

It’s interesting to notice how ISACA is aligning itself with the International Organization of Standards ISO/IEC 27002.  The title for Domain 3 is Information Systems

Joanna Rutkowska Reveals Her Process for Security Research

In our ongoing series of interviews, Joanna Rutkowska answered a few questions and pulled back the curtain a bit on the methods, tools and motivation

March 25, 2011 Exploit Development

CISSP Domain – Legal, Regulations, Investigations and Compliance

There are several topics we need to look at when we discuss the Legal domain of CISSP.  First you need some background and a couple

March 25, 2011 CISSP, IT Certifications

CISSP – Steganography, An Introduction Using S-Tools

An Introduction to S-Tools Steganography (as we discussed in our coverage of the CISSP Cryptography Domain) is the hiding of information within a picture, say

March 24, 2011 CISSP, IT Certifications

iPhone Security: 10 Tips and Settings

The iPhone is one of the most popular mobile devices on the market with an array of downloadable apps for users to do any number

CISA Domain 2 – Governance and Management of IT

CISA – Domain 2 – Governance and Management of IT ISACA has revamped the CISA material and this domain now contains the Business Continuity section from

iPhone Security: iPhone Forensics

In this video, we will review the wealth of forensic data stored on an iPhone 3Gs using Paraben’s Device Seizure software. The iPhone is one

March 23, 2011 Forensics

CISA – Domain Mapping for 2011 Exam

Several of you have been asking for a mapping of the new CISA 5 domains to the previous year’s six domains.  The new mapping is

HD Moore Reveals His Process for Security Research

In our ongoing series of interviews, we got HD Moore to answer a few questions and pull back the curtain a bit on the methods,

March 22, 2011 Interviews, SCADA

OWASP Top 10 Tools and Tactics

Description: A tool for each of the OWASP Top 10 to aid in discovering and remediating each of the Top Ten Introduction If you’ve spent

March 21, 2011 Application Security

Standards for Penetration Testing

The cost and quality of penetration tests vary wildly between different vendors. As a response to those differences, a group of security professionals have been

March 18, 2011 Hacking

CISSP Domain – Business Continuity and Disaster Recovery

You only have to turn on the TV and watch some of the footage of the destruction caused by the tsunami in Japan to realize

March 17, 2011 CISSP, IT Certifications

CISA Domain 1 – The Process of Auditing Information Systems

First, Get a copy of the CISA Review Manual and a copy of the Q&A CD Second, Read one Domain then answer all the questions

The CISA Domains – An Overview

ISACA’s 2011 CISA Exam material has been revised from six domains to five domains.  Prior to 2011 Domain 6 was Business Continuity and Disaster Recovery.  That

Charlie Miller Reveals His Process for Security Research

As the first in an ongoing series of interviews, we got recent Pwn2Own winner Charlie Miller to answer a few questions and pull back the

March 14, 2011 Exploit Development

CISSP Domain – Cryptography and Security

There are books upon books about cryptography and this article will not attempt to regurgitate all of the historical background about the subject. However, there

March 14, 2011 CISSP, IT Certifications
Back to Top Copyright © 2012 - InfoSec Institute