<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>The Professional Security Testers Warehouse for the CEH V7 GPEN CPTS CREST GCIH GREM OPST</title>
<link>http://www.professionalsecuritytesters.org</link>
<description>You need more than tools to defeat the adversary!</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2012-02-05T07:24:47-05:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2012-02-05T07:24:47-05:00</sy:updateBase>

<item>
<title>Security Kaizen Magazine Issue 4 is released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1370</link>
<description><![CDATA[<div style="text-align: center;"><strong>Security Kaizen Magazine               Yearly issue. <br> An issue that you shouldn't miss</strong><br></div>
<blockquote>In Egypt : 30 % discount Coupon for EC council         Courses inside the Printed Copy.<br><br> <a href="https://spreadsheets9.google.com/viewform?hl=en&#38;formkey=dFhVbGFZUlpZM3BXMHpjWUdkUndqeXc6MQ#gid=0">Printed           Copy Request</a><br> Coming Soon : Arabic Version<br></blockquote>
<div style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><strong>Download the English Edition now</strong><br> </a></div>
<p><br> <a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"></a></p>
<p style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><img src="https://mail.google.com/mail/u/0/?ui=2&#38;ik=0793b57c9a&#38;view=att&#38;th=135349096fe28fa9&#38;attid=0.1&#38;disp=emb&#38;realattid=a364c6ec898db2e0_0.1.1&#38;zw" border="0" alt height="507"></a></p>]]></description>
<guid isPermaLink="false">1370@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2012-02-03T14:58:28-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Modeling Security Pentests - New Issue of WebAppPentesting is  Out!</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1369</link>
<description><![CDATA[<p><strong>Inside Web App Pentesting:</strong></p>
<p>Open Source Web Application Security Testing Tools by Vinodh Velusamy</p>
<p>Author  shows the significance of Open Source Web Application Security Testing  Tools. As he claims &#8222;When you choose and use good tools, you&#8217;ll know it.  Amazingly, you&#8217;ll minimize your time and effort installing them,  running your tests, reporting your results &#8211; everything from start to  finish. <br><br>Most importantly, with a good web vulnerability scanner  you&#8217;ll be able to maximize the number of legitimate vulnerabilities  discovered to help reduce the risks associated with your information  systems. <br>At the end of the day and over the long haul, this will add up to considerable business value you can&#8217;t afford to overlook&#8221;. <br><br><strong>More Articles:</strong></p>
<p>- Modeling Security Penetration Tests with Stringent Time Constraints by Alan Cao <br>- The puzzlepices by Daniel Clemens <br>- WebAppSecurity for Newbies part 2 Herman Stevens <br>- Web Application Common Vulnerabilities &#8211; Part I by Bryan Soliman <br>- CYBER STYLETTO by Mike Brennan and Richard Siennon <br><br><br><strong>SUBSCRIBE NOW AND GET 2 AMAZING E-BOOKS !</strong></p>
<p>1. CISO's Guide to Penetration Testing: A Framework to Plan, Manage,  and Maximize Benefits details the methodologies, framework, and  unwritten conventions penetration tests should cover to provide the most  value to your organization and your customers.<br><br>2. In his new  book "Save the Database, Save the World!" John Ottman captures the  essence of the threats we face to the information that drives business.  Organized crime, underhanded competitors and even foreign governments  are looking to gain any financial, competitive or operational advantage  and these enemies are going directly after the databases and the  applications that access data.</p>
<p>After subscribing contact <strong><a href="mailto:katarzyna.zwierowicz@software.com.pl">katarzyna.zwierowicz@software.com.pl</a></strong> with "WAPT" in the tittle of the message.</p>
<p>You can visit us at: <a href="http://www.pentestmag.com"><strong>http://www.pentestmag.com</strong></a></p>]]></description>
<guid isPermaLink="false">1369@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-25T12:58:26-05:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>ClubHACK Magazine January 2012 Edition</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1368</link>
<description><![CDATA[<p>As seen <a href="http://www.pentestit.com/">http://www.pentestit.com/ </a></p>
<p>Contents of ClubHACK Magazine January 2012:</p>
<ul>
<li>Tech Gyan: <em>One Link Facebook</em><br> Can Facebook accounts be hacked? Is it be possible to access your  account without your permission and without knowing your username and  password? Unfortunately &#8220;YES&#8221; is the answer.</li>
<li>Legal Gyan: <em>Powers of Government under the Information Technology Act, 2000</em><br> Internet Censorship is today&#8216;s hot topic with the passage of statements  by our Honorable Ministers. But the billion dollars question is ?Can  online activities of individuals be censored/monitored in India?</li>
<li>Tool Gyan: <em>SQLMAP &#8211; <a href="http://www.pentestit.com/tag/automated-sql-injection/">Automated Sql Injection</a> Testing Tool</em><br> <a href="http://www.pentestit.com/tag/sql-injection/">Sql injection</a> is one of the most common <a href="http://www.pentestit.com/tag/vulnerability/">vulnerability</a> found in web applications today. Exploiting SQL Injection through  manual approach is somewhat tedious. Using flags like ?or 1=1&#8211;? , ?and  1&#62;2? we can find out if vulnerability is present but exploiting the  vulnerability needs altogether different approach. Tools like Sqlmap,  Havij and Pangolin are helpful in exploiting sql injection.</li>
<li>Matriux Vibhag: <em>Setting up and Getting started with Matriux Krypton</em><br> Wish you a very happy and prosperous new year from team Matriux. 2011  has been a great year for us where we along with CHmag have made it  possible to reach you better. A special thanks to CHmag team for making  it with us. It has been noticed that due to a custom and special  installer MID used in Matriux Krypton, many users are confused on how to  get Matriux setup on their Hard disk or <a href="http://www.pentestit.com/tag/virtualbox/">VirtualBox</a>, so this month we bring you with how to setup and get started with Matriux Krypton, a better way to start 2012.</li>
<li>Mom&#8217;s Guide: <em>Social Networking and its <a href="http://www.pentestit.com/tag/application-security/">Application Security</a></em><br> Social Networks have been an important part of our life, yes, we tweet  for photos we click, every moment of happiness, sadness and the news  around, we update our status if we start a relationship or end one, or  even travel itinerary and hotel check-ins, movie moments, fun with  friends, in fact everything that we do every moment in our life is open  to the world we want to share. Play games with friends and make new  friends.</li>
</ul>
<p>Download ClubHACK Magazine January&#160;2012:</p>
<p>ClubHACK Magazine Issue 24,&#160;January 2012<em>&#160;&#8211; jan2012.pdf</em> &#8211; <a href="http://chmag.in/issue/jan2012.pdf">http://chmag.in/issue/jan2012.pdf</a></p>]]></description>
<guid isPermaLink="false">1368@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Inthenews</dc:subject>
<dc:date>2012-01-19T15:10:14-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>The SPToolkit - The Phishing Toolkit Project</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1367</link>
<description><![CDATA[<p>See the detail below from the Phishing Toolkikt Project.</p>
<p>Get it directly from the project at:&#160; <a href="http://www.sptoolkit.com/download/">http://www.sptoolkit.com/download/</a></p>
<p>Hey, what is this thing?</p>
<p>spt is a simple concept with powerful possibilities. &#160;It is what it&#8217;s name implies: &#160;a simple phishing toolkit.</p>
<p>The basic idea we (the spt project) had was that wouldn&#8217;t it be cool  if there were a simple, effective, easy to use and free (most  importantly!) tool that information security professionals could use to  evaluate and train what we all know is the weakest link in any security  minded organization: &#160;the people. &#160;Since the founders of the spt project  are themselves information security professionals by day (and possibly  either LOL cats or zombies by night), they themselves faced the  frustration of dealing with people within their own organizations that  claimed to know better, but 9 times out of 10 fell for the most absurdly  obvious phishing emails ever seen. &#160;A malware outbreak here, a stolen  password and loss of critical organizational data there and the costs of  dealing with the results of phishing can get to be astronomical pretty  darn quickly!</p>
<p>Enter spt. &#160;spt was made from scratch, like a baby (or maybe a  zombie) with the goal of giving over-worked and under-staffed  information security professionals a simple tool (more like a framework,  as we hope to add more features over time) that could be used to  identify and train those weakest links. &#160;spt is a fully self-contained  phishing email toolkit that can be installed, configured and phishing in  less than 15 minutes. &#160;Its design is modular and open-ended allowing  for future expansion and&#160;additional&#160;features via easy to snap-in modules  that are simply uploaded in the administration dashboard. &#160;Why not try  out spt today and see who your weakest link is?</p>
<p>Why do we care about phishing?</p>
<p>Simple answer: &#160;phishing has become one of the easiest ways to remotely separate people from that which is important to them.</p>
<p>These articles give some good insights into why phishing is on the  rise and why you, as an information security professional, should be  worried about it.</p>
<ul>
<li><a href="http://www.symantec.com/connect/blogs/phish-tastes-better-spam">Phish Tastes Better Than Spam</a></li>
<li><a href="http://www.rsa.com/phishing_reports.aspx">RSA Online Fraud Reports</a> (click to download the various reports for each month)</li>
<li><a href="http://www.scmagazineus.com/crooks-opt-for-spear-phishing-despite-higher-upfront-cost/article/206586/">Crooks opt for spear phishing despite higher upfront cost</a></li>
<li><a href="http://labs.m86security.com/2011/03/phishing-scam-in-an-html-attachment/">M86 Labs: &#160;Phishing Scam in an HTML Attachment</a></li>
<li><a href="http://blog.imperva.com/2010/07/gnarley-new-phishing-kit.html">Imperva finds master hacker who dupes thousands into phishing army</a></li>
<li><a href="http://www.scmagazineus.com/travel-education-sectors-most-vulnerable-to-phishing/article/203589/">Travel, education sectors most vulnerable to phishing</a></li>
</ul>
<p>Some quotes to drive the point home perhaps.</p>
<p><em>&#160;-&#160;Travel, education sectors most vulnerable to phishing</em></p>
<blockquote>
<p>Researchers sent simulated phishing messages to employees  at more than 3,500 small and midsize enterprises (SMEs) and found that  recipients at nearly 500 companies, or 15 percent, clicked on a link  contained in the message.</p>
</blockquote>
<p><em>&#160;-&#160;Imperva finds master hacker who dupes thousands into phishing army</em></p>
<blockquote>
<p>A recently released, next-generation phishing toolkit  promises to automate the tedious task of tricking people into visiting  websites designed to steal their financial information. Even better, the  toolkit is free. The only hitch: the creators added a backdoor,  allowing them to also amass all of the data captured by their phishing  toolkit, no matter who uses it.</p>
</blockquote>
<p><em>&#160;-&#160;Phish Tastes Better Than Spam</em></p>
<blockquote>
<p>A major source of survival for spammers is consumer  spending. With the recession eroding world economies, consumer spending  has taken a major hit. Spammers, who thrived on luring consumers to  spend money, have definitely been dealt a severe blow. After all, who is  going to be lured by spammed products during tough financial  circumstances? What logically follows in the worldview of a spammer is  the money in your bank account rather than that in your purse. Or, in  other words, spammers will shift to baiting consumers with phishing  emails to try and steal banking credentials when they know their spam  campaigns aren&#8217;t working.</p>
</blockquote>
<p>The problem is big, and getting bigger. &#160;Protect your network, your organization and your people&#8230;from your people</p>
<p>Get it directly from the project at:&#160; <a href="http://www.sptoolkit.com/download/">http://www.sptoolkit.com/download/</a></p>]]></description>
<guid isPermaLink="false">1367@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Social</dc:subject>
<dc:date>2012-01-19T14:37:55-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>SOPA and PIPA -- What`s in it for you</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1366</link>
<description><![CDATA[<p>As seen on one of my hosting company mailing list:</p>
<p>Greetings <a href="http://www.site5.com/">Site5 Customers</a>!<br> <br> The U.S. Congress is currently considering two bills -- one in the House  of Representatives called SOPA (Stop Online Piracy Act) and another in  the Senate called PIPA (Protect IP Act). These bills both attempt to use  similar methods to further criminalize and police intellectual property  infringement. Although protecting intellectual property is important,  these bills would use heavy-handed tactics that would censor and  splinter the Internet.<br> <br> SOPA and PIPA would grant the U.S. government the ability to block  almost any website on the Internet if the site is perceived to be an  "infringing site." Search engines would be required to remove the site  from their search listings, payment processors and advertisement  networks would be forbidden from doing business with the site, and ISPs  could be forced to block access to the site for Americans. The bill  provides little detail about what would constitute an infringing site,  which makes the potential for abuse far greater. We have already seen  how these kind of systems can be abused. In 2010, ICE (Immigration and  Customs Enforcement) mistakenly seized a domain name belonging to a  music blog and labeled it as a "rogue site" &#8212; the domain name was not  returned until a year later (source: <a href="http://nyti.ms/uF73mZ">http://nyti.ms/uF73mZ</a>). If you would like to see a video explanation of how the bill works and its dangers, please go here: <a href="http://vimeo.com/31100268">http://vimeo.com/31100268</a><br> <br> Site5 has publicly declared our opposition to both bills, and we  encourage you to do the same. Contact your representatives in Congress  to let your opposition to these bills be known! To locate the contact  information for your representatives, visit one of the following  websites:<br> <br> <a href="http://www.contactingthecongress.org/">http://www.contactingthecongress.org</a><br> <a href="http://www.grassroutes.us/sopa">http://www.grassroutes.us/sopa</a><br> <br> If you're located outside the United States, you can let your voice be heard as well by sending your thoughts via this website:<br> <br> <a href="http://americancensorship.org/">http://americancensorship.org</a><br> <br> Another way to get involved in the fight against SOPA and PIPA is to  join in on the blackouts. Many well-known websites such as Wikipedia,  Google, and Reddit are demonstrating their opposition, and you can too.  Site5 has sponsored a WordPress plugin for participating in blackouts,  and it features an easy setup and configuration options within the  WordPress admin area:<br> <br> <a href="http://wordpress.org/extend/plugins/sopa-blackout-plugin/">http://wordpress.org/extend/plugins/sopa-blackout-plugin/</a><br> <br> We feel very strongly that the future of the Internet is at stake, and we urge everyone to get involved!<br> <br> Thanks,</p>
<p>The Site5 Management Team</p>]]></description>
<guid isPermaLink="false">1366@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Inthenews</dc:subject>
<dc:date>2012-01-19T14:23:08-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>OWASP Long Island Meeting - A hands-on demo of the top web application risks</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1365</link>
<description><![CDATA[<p>OWASP Meeting - A hands-on demo of the top web application risks - Thursday, February 16, 2011</p>
<p>Adelphi University, Garden City, New York</p>
<p>You are invited to the OWASP Long Island chapter meeting. &#160;In a continuation of the previous meeting; we have once again organized a lab to demonstrate and discuss various OWASP top 10 vulnerabilities. &#160;Please register by using the link below...</p>
<p><strong>When</strong>: Thursday, February 16, 2011; 7:00pm - 9:30pm</p>
<p><strong>Where: </strong><br>IT conference room in the lower level of Hagedorn Hall of Enterprise (Building HHE on Map upper right)<br>Adelphi University, Garden City, NY 11549-1000. <br><a href="http://maps.google.com/maps?hl=en&#38;sugexp=kjrmc&#38;cp=8&#38;gs_id=v&#38;xhr=t&#38;qe=QWRlbHBoaSA&#38;qesig=JiDWqoZNuHjzxH4mu6hKFg&#38;pkc=AFgZ2tkIdEHC3xl3TdCwzVHV-FzgNlMu6AZnN1IK_YD8inckTi6GpPNW_NXm1BSV3gh-c-dec9v32CZ8YRCkAnZnP8Jja8WVtw&#38;gs_upl=&#38;bav=on.2,or.r_gc.r_pw.,cf.osb&#38;biw=1302&#38;bih=938&#38;um=1&#38;ie=UTF-8&#38;cid=0,0,9404387279279361491&#38;fb=1&#38;hq=adelphi+university&#38;hnear=0x89c286e540a98237:0x6a5b71f23a74346c,Old+Westbury,+NY&#38;gl=us&#38;daddr=1+South+Avenue,+Garden+City,+NY+11530-0701&#38;geocode=0,40.721203,-73.652149&#38;ei=xHScTsqnMefm0QGXhpiaBA&#38;sa=X&#38;oi=local_result&#38;ct=directions-to&#38;resnum=1&#38;ved=0CFYQngIwAA">Google map</a>. &#160;<a href="http://www.adelphi.edu/visitors/campus.php">Campus Map</a> <br>Once at the building, enter the building from the North and go down the stairs, knock on the door to be let in.   <br><strong><br>How Much: </strong>Free.&#160; Pizza and beverages will be provided.&#160; This event is supported 100% by OWASP Long Island volunteers.&#160;&#160;  RSVP required:&#160; &#160; &#160;   <br><strong><br>Registration Details:&#160;</strong> <br>This chapter meeting has been&#160;organized&#160;to be a lab; as a result, space is limited in the room to a maximum of&#160;18&#160;people.</p>
<p><strong>Who Are We:</strong>&#160;&#160;We are volunteers of&#160;<a href="http://www.owasp.org/index.php/Main_Page">OWASP</a>, a worldwide charitable organization focused on improving the security of application software.&#160; Everyone is free to participate in&#160;OWASP&#160;and all of our materials are available under a free and open software license.</p>
<p><strong>Meeting Agenda:</strong> Dr. Kees Leune - Lab utilizing some of the OWASP 10 vulnerabilities with BackTrack 5. &#160;</p>
<p><strong>Topics:</strong> Overview of BackTrack Overview of some tools on BackTrack (nmap, JohnTheRipper,MetaSploit) Overview of the lab challenge (covers multiple owasp top 10 vulns)</p>
<p><strong>Bring your own laptop:</strong> Laptops are needed if you wish to participate in the lab exercise. &#160;Each participant will be provided a copy of Backtrack 5 R1, laptops should be capable of booting off a DVD. &#160;Cables, power strips, etc ...&#160;will be provided;&#160;but make sure you have your own power adapter.</p>
<p><strong>About the Speaker:</strong><br>Dr. Kees Leune is an Information Security Officer, Strategist, Professor, Mentor, Adviser, Consultant, Speaker and occasional open source developer. <br>He blogs at&#160;<a href="http://www.leune.org/">http://www.leune.org</a>&#160;and can be found on Twitter as @leune. <br>Kees has extensive experience in information security and holds several professional certifications, including the CISSP, GCIH, GCFA, CISM, and CISA.       <br><br>To view past meetings, go to&#160;<a href="https://www.owasp.org/index.php/Long_Island">https://www.owasp.org/index.php/Long_Island</a>&#160;or click&#160;<a href="https://www.owasp.org/index.php/Long_Island">here</a>.      <br><br>To subscribe to the the chapter mailing list, go to&#160;<a href="https://lists.owasp.org/mailman/listinfo/owasp-longisland">https://lists.owasp.org/mailman/listinfo/owasp-longisland</a>&#160;or click&#160;<a href="https://lists.owasp.org/mailman/listinfo/owasp-longisland">here</a>.&#160; <br><br>Your email address will be used for OWASP related notifications only. &#160;We will not share it with any third party.&#160; <br><br>You can cancel your subscription anytime you want.</p>
<p>_______________________________________________<br>Owasp-LongIsland mailing list<br><a href="mailto:Owasp-LongIsland@lists.owasp.org">Owasp-LongIsland@lists.owasp.org</a><a href="https://lists.owasp.org/mailman/listinfo/owasp-longisland"><br>https://lists.owasp.org/mailman/listinfo/owasp-longisland</a> <br><br>Helen Gao, CISSP <br>Chapter leader of OWASP</p>]]></description>
<guid isPermaLink="false">1365@http://www.professionalsecuritytesters.org</guid>
<dc:subject>OWASP</dc:subject>
<dc:date>2012-01-18T10:41:46-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>LACSEC 2012, May 6-11, 2012, Quito, Ecuador</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1364</link>
<description><![CDATA[<div id=":23k">*****************************************<br> &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; <strong>CALL FOR PRESENTATIONS</strong><br> *****************************************<br> &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; <strong>&#160;LACSEC 2012</strong><br> &#160; &#160; &#160; 7th Network Security Event for Latin America and the Caribbean<br> &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;May 6-11, 2012, Quito, Ecuador<br> &#160; &#160; <strong>&#160; &#160; &#160; &#160; <a href="http://lacnic.net/en/eventos/lacnicxvii/">http://lacnic.net/en/eventos/lacnicxvii/</a></strong><br> <br> <br> LACNIC (<a href="http://www.lacnic.net/">http://www.lacnic.net</a>) is the international organization based in (Uruguay) that is responsible for administrating IP address space, Reverse Resolution, Autonomous System Numbers and other resources for the region of Latin America and the Caribbean on behalf of the Internet<br> community.<br> <br> The 7th Network Security Event for Latin America and the Caribbean will be held in Quito, Ecuador, within the framework of LACNIC's seventeenth annual meeting (LACNIC XVII). This is a public call for presentations for that event.<br> <br> The topics of interest include, but are not limited to, the following:<br> <br> * Honeypots, network monitoring and situational awareness tools in general.<br> * Fighting spam, particularly spam from origin (SPF, DKIM and related technologies. Email reputation)<br> * Fighting phishing and pharming<br> * Fighting malware<br> * Internet protocol security<br> * IPv6 security<br> * DNSsec<br> * Security of network infrastructure services (DNS, NTP, etc.)<br> * Web security<br> * DoS/DDoS response and mitigation, botnets<br> * Authentication and access control<br> * Security in the cloud<br> * Protection of critical infrastructure<br> * Security in mobile systems<br> * Computer security incident response teams (CSIRTs): creation, management, experiences<br> * Security in corporate environments, compliance and auditing, return on security investments<br> * Security management (procedures, operational logs, records, etc.)<br> * Risk management in Information Security<br> * Computer forensics<br> * Protection of privacy<br> * Legal aspects relating to computer security<br> <br> <br> Guidelines for Presenting Proposals<br> <br> Proposals for the 7th Network Security Event for Latin America and the Caribbean (LACSEC 2012) must be presented taking into account the<br> following considerations:<br> <br> * The proposal may consist of a paper, or (alternatively) an Extended Abstract plus a draft version of the slides to be used for the presentation.<br> * Proposals may be presented in English, Portuguese or Spanish.<br> * Proposals must be submitted in Portable Document Format (PDF) <br> * Submissions must be created directly using a word processing system (scanned articles will not be accepted)<br> * Presentations may not be longer than 30 minutes.<br> <br> <br> Submitting a Proposal<br> <br> Those interested in presenting at LACSEC 2012 must send the following information to &#60;<a href="mailto:comite_seguridad@lacnic.net">comite_seguridad@lacnic.net</a>&#62; within the deadlines set<br> forth below:<br> <br> * Full title of the presentation<br> * A paper or, alternatively, an Extended abstract and a draft of the slides to eb used for the presentation. The paper should not be longer than 10 pages. The extended abstract should not contain more than one thousand (1000) words. The Evaluation Committee may, at its sole discretion, request additional or&#160; omplementary information.<br> * Full name, email address and organization with which the author (or authors) of the submission is affiliated<br> <br> For more information, please don't hesitate to contact the Evaluation Committee at &#60;<a href="mailto:comite_seguridad@lacnic.net">comite_seguridad@lacnic.net</a>&#62;.<br> <br> <br> Proposal Evaluation<br> <br> The Evaluation Committee that has been created for this purpose will evaluate proposals based on the following basic criteria:<br> <br> * Originality<br> * Technical quality<br> * Relevance<br> * Presentation<br> * Applicability<br> <br> <br> Speaker's Privileges<br> <br> LACNIC will cover the registration fee for those authors whose presentations are accepted. Speaker travel and accommodation expenses, however, will not be covered.<br> <br> Presenters who require financial assistance to attend the event may apply for the LACNIC Financial Assistance Program. Please read the corresponding instructions &#60;<a href="http://lacnic.net/en/eventos/lacnicxvii/">http://lacnic.net/en/eventos/lacnicxvii/</a>&#62;.&#160; In no case does applying for the sponsorship program guarantee that financial assistance will be granted. For more information please contact LACNIC staff at &#60;<a href="mailto:becas@lacnic.net">becas@lacnic.net</a>&#62;.<br> <br> <br> IMPORTANT DATES<br> <br> * Deadline for proposal submission: February 15th, 2012<br> * Notification of acceptance: February 27th, 2012<br> * Deadline for submitting the final version the presentation: May 6th, 2012<br> <br> 7th Network Security Event for Latin America and the Caribbean (LACSEC 2012)<br> <br> Chair<br> &#160;Fernando Gont (SI6 Networks/UTN-FRH, Argentina)<br> <br> Evaluation Committee<br> &#160;Iv&#225;n Arce (Argentina)<br> &#160;Lorena Ferreyro (Consultora Independiente, Argentina)<br> &#160;Javier Liendo (Cisco, Mexico)<br> &#160;Carlos Martinez Cagnazzo (LACNIC, Uruguay)<br> &#160;Reinaldo Mayol (Universidad Pontificia Bolivariana, Colombia)<br> &#160;Domingo Montanaro (iSight Partners, Brazil)<br> &#160;Jose Miguel Parrella Romero (Debian developer, Ecuador)<br> &#160;Patricia Prandini (ADACSI, Argentina)<br> &#160;Javier Romero (JaCkSecurity, Peru)<br> &#160;Arturo Servin (LACNIC, Uruguay)<br> &#160;Liliana V. Solha (CAIS/RNP, Brazil)<br> &#160;Leonardo Vidal (ISOC Capitulo Uruguay, Uruguay)<br> <br> - --<br> Fernando Gont<br> SI6 Networks<br> e-mail: <a href="mailto:fgont@si6networks.com">fgont@si6networks.com</a><br></div>]]></description>
<guid isPermaLink="false">1364@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2012-01-16T12:43:47-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>New Issue of PenTest Extra Magazine is available</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1363</link>
<description><![CDATA[<table style="font-size: 12px;" border="0" cellpadding="10px">

<tr>
<td style="font-size: 12px;">New Issue of PenTest Extra Magazine is available! <a href="http://pentestmag.com/pentest-extra-012012/"><img style="margin-left: 10px;" src="http://mytalkoot.com/12all/images/zdalnymailing/pt/20120116pt.gif" alt width="343" height="493" align="right"></a> Download the Free Sample Issue to check the content and read Free article, just click <a href="http://pentestmag.com/pentest-extra-012012/">here</a>. <br><br> Read free article "XSS &#38; CSRF: Practical exploitation of  post-authentication vulnerabilities in web applications" by Marsel  Nizamutdinov The goal of this article is to demonstrate the real danger of  post-authenticated vulnerabilities. The author will not explain the  basics of web   application attacks in this article, as that has already been done many  times before by others. He will focus on a practical way to exploit   post-authentication XSS's and CSRF, which remain a highly underestimated  attack vector in the security scene.<br><br> Inside:  
<ul>
<li><strong>XSS &#38; CSRF: Practical exploitation of post-authentication vulnerabilities in web applications</strong> <em>by Marsel Nizamutdinov</em> </li>
<li><strong>Discovering Modern CSRF Patch Failures</strong> <em>by Tyler Borland</em></li>
<li><strong>Business Logic Vulnerabilities via CSRF</strong> <em>by Eugene Dokukin</em></li>
<li><strong>XSS Using Shell of the future</strong> <em>by Sow Ching Shiong</em></li>
<li><strong>Cross-Site Request Forgery</strong> <em>by Jamie</em></li>
<li><strong>Security Resolutions for 2012</strong> <em>by Rishi Narang</em></li>
<li><strong>Interview with Peter N. M. Hansteen</strong> <em>by PenTest Team</em></li>
</ul>
</td>
</tr>
<tr>
<td align="center"><a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52169&#38;l=-http--pentestmag.com/wp-login.php--Q-action--E-register--Q-a_aid--E-krzysztofmarczyk--A-a_bid--E-163efff7"><img src="http://mytalkoot.com/12all/images/zdalnymailing/subbut.png" alt width="272" height="68"></a> 
<hr>
</td>
</tr>
<tr>
<td>Get For Free "The Book of PF" by Peter N. M. Hansteen! <img style="margin-left: 10px;" src="http://mytalkoot.com/12all/images/zdalnymailing/pt/pf2.png" alt width="343" height="453" align="right"> <strong>Buy annual subscription of PenTest and receive:</strong> 
<ul>
<li><strong>Free Ebook</strong> <em>"The Book of PF: A No-Nonsense Guide to the OpenBSD Firewall"</em> <strong>worth $30.00</strong> Today's system administrators face increasing challenges in the quest  for network quality, and The Book of PF can help by demystifying the   tools of modern *BSD network defense. But, perhaps more importantly,  because we know you like to tinker, The Book of PF tackles a broad range    of topics that will stimulate your mind and pad your resume, including  how to: 
<ul>
<li>Create rule sets for all kinds of network traffic, whether it is  crossing a simple home LAN, hiding behind NAT, traversing DMZs, or   spanning bridges</li>
<li>Use PF to create a wireless access point, and lock it down tight with authpf and special access restrictions</li>
<li>Maximize availability by using redirection rules for load balancing and CARP for failover</li>
<li>Use tables for proactive defense against would-be attackers and spammers</li>
<li>Set up queues and traffic shaping with ALTQ, so your network stays responsive</li>
<li>Master your logs with monitoring and visualization, because you can never be too paranoid</li>
</ul>
</li>
</ul>
If you buy PenTest annual subscription, you will receive 48 Issues of PeneTest per year and get:  
<ul>
<li>PenTest (release date: 1st of each month) &#8211; 50 pages of content dedicated to penetration tests, few regular columns written by   specialists</li>
<li>PenTest Extra (release date: 15th of each month) &#8211; 50 pages of  strictly topical content dedicated each time to different hot topic</li>
<li>Mobile Pentesting (release date: 7th of each month) &#8211; 40 pages of content dedicated to latest mobile topics</li>
<li>Web App Pentesting (release date: 22nd of each month) &#8211; 40 pages of content dedicated to web application topics</li>
</ul>
Buy annual subscription and contact us at krzysztof.marczyk@software.com.pl. We will take care of everything for you!</td>
</tr>
<tr>
<td align="center"><a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52169&#38;l=-http--pentestmag.com/wp-login.php--Q-action--E-register--Q-a_aid--E-krzysztofmarczyk--A-a_bid--E-163efff7"><img src="http://mytalkoot.com/12all/images/zdalnymailing/subbut.png" alt width="304" height="76"></a></td>
</tr>

</table>
<p><br> <strong>Contact PenTest team!</strong><br> Please spread the word about PenTest magazine!<br><br> Enjoy reading!<br> Krzysztof Marczyk &#38; PenTest team<br> <a href="mailto:krzysztof-marczyk@software.com.pl">mailto:olga.glowala@software.com.pl</a><br> <a href="http://mytalkoot.com/12all/lt.php?c=1953&#38;m=1324&#38;nl=141&#38;s=5905ac794f5c2ecaaa3527b5171afb07&#38;lid=52170&#38;l=-http--pentestmag.com/">PenTest Magazine</a></p>]]></description>
<guid isPermaLink="false">1363@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-16T11:26:04-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Sniffing an SSL Handshake using Wireshark -- Crypto Song</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1362</link>
<description><![CDATA[<p>My good friend Larry Greenblatt who is an instructor extraordinaire and a men of many talents has created a great song about SSL sniffing using Wireshark.&#160; Listen to it on UTube.&#160; See his note below:</p>
<p>I created a music video about Crypto using Wireshark to sniff a SSL  handshake with Google.&#160; I got some good comments from some Sharkfest  presenters and it looks like I am going to present this at Sharkfest  2012 in June!<br><br> <a href="http://www.youtube.com/watch?v=1dHsj1ZxDto">http://www.youtube.com/watch?v=1dHsj1ZxDto</a></p>]]></description>
<guid isPermaLink="false">1362@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Cryptography</dc:subject>
<dc:date>2012-01-15T13:02:16-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>OWASP Long Island Chapter</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1361</link>
<description><![CDATA[<p class="p1">The Open Web Application Security Project (OWASP) is a  501c3 not-for-profit worldwide charitable organization focused on  improving the security of application software. Our mission is to make  application security <a href="https://www.owasp.org/index.php/Category:OWASP_Video">visible,</a> so that <a href="https://www.owasp.org/index.php/Industry:Citations">people and organizations can make informed decisions</a> about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.</p>
<p class="p1">All Long Island chapter meetings are free. Please water our calendar for up coming events.</p>
<p class="p1">For more info contact:&#160; Helen Gao&#160; (helen.gao@wasp.org)</p>
<p class="p1"><strong><a href="https://www.owasp.org/index.php/Long_Island">https://www.owasp.org/index.php/Long_Island</a></strong></p>]]></description>
<guid isPermaLink="false">1361@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2012-01-14T11:41:34-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

</channel>
</rss>

