<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Information Security Philippines</title>
	<atom:link href="http://infosec.box.com.ph/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec.box.com.ph</link>
	<description>InfoSec Matters in One Box</description>
	<pubDate>Mon, 23 Jun 2008 14:11:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>The Past, Present, and Future of Risk Assessments</title>
		<link>http://infosec.box.com.ph/2008-06-23-the-past-present-and-future-of-risk-assessments/</link>
		<comments>http://infosec.box.com.ph/2008-06-23-the-past-present-and-future-of-risk-assessments/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 14:11:41 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[InfoSec Trends]]></category>

		<category><![CDATA[Risk Management]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[Webcasts]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[risk assessment]]></category>

		<category><![CDATA[webinars]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/?p=66</guid>
		<description><![CDATA[
presents
The Past, Present, and Future of Risk Assessments (Webinar)
Live broadcast: June 24, 2008 @ 10 AM (PST); 1 PM (EST); 6 PM (BST)
Duration: 60                                [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img src="http://farm4.static.flickr.com/3035/2603560725_ea69543016_m_d.jpg" alt="Infosec Webcast" width="240" height="47" /></p>
<p style="text-align: center;">presents</p>
<p style="text-align: center;"><strong>The Past, Present, and Future of Risk Assessments</strong> (Webinar)</p>
<p style="text-align: center;"><strong><span style="color: #cc3333;"><span style="font-weight: bold; color: #cc3333;"><span>Live broadcast: </span></span></span></strong><strong><strong><span><span style="font-family: Verdana;">June 24, 2008 @ 10 AM (PST); 1 PM (EST); 6 PM (BST)</span></span></strong></strong><strong><span style="color: #333399;"><span style="font-weight: bold; color: #333399;"><br />
</span></span></strong><span><strong><span style="color: #cc3333;"><span style="font-weight: bold;">Duration: </span></span></strong></span><strong><strong><span style="font-family: Verdana; color: #333399;"><span style="color: #333399; font-family: Verdana;">60                                  minutes</span></span></strong></strong></p>
<p align="left"><span><strong><span style="font-family: Verdana; color: #cc3333; font-size: xx-small;"><span style="font-weight: bold; font-size: 8.5pt;">Moderator:</span></span></strong></span> <strong>John Sterlicchi,</strong> <em><em><span style="font-family: Verdana; color: #000066;"><span style="color: #000066; font-family: Verdana;">Infosecurity</span></span></em></em><span><span style="color: #000066;"> Magazine</span></span><strong><span style="color: #cc3333;"><span style="font-weight: bold; color: #cc3333;"><br />
<span>Panelist: </span></span></span></strong><span><strong>Michael Gregg,</strong> Villanova University</span><strong><span style="color: #cc3333;"><span style="font-weight: bold; color: #cc3333;"><br />
<span>Panelist: </span></span></span></strong><strong><span>Svetlana Hristozova, </span></strong>Marketing Manager, Villanova                                  University Online</p>
<p align="left"><span><strong><span style="font-family: Verdana; color: #cc3333; font-size: xx-small;"><span style="font-weight: bold; font-size: 8.5pt;">Description:</span></span></strong></span><strong><span style="font-weight: bold;"><br />
</span></strong><span><span><span><span><strong>Join noted author and security expert Michael Gregg on June 24th to learn more about how risk assessments are changing to meet evolving security needs.</p>
<p></strong><span>You&#8217;ll travel through time with Mr. Gregg to explore the progression of IS Security problems. For example, in the not too distant past, risk assessments were performed to counter attacks that were designed for glory and fame (Nimda, Code Red and SQL Slammer). These early attacks required massive amounts of time for cleanup and repair and relied on defensive technologies.</p>
<p>In today&#8217;s information age, attack vectors have changed. More recent incidents are financial in nature. Yesterday&#8217;s virus is today&#8217;s custom malware; while denial of service attacks have been<br />
replaced with botnets.</p>
<p>Learn how this evolving threat has forced organizations to view risk assessments differently and develop new techniques. Get the essential solutions every IS and IT professional needs to counter current and future threats.</span></span></span></span></span></p>
<p align="left"><strong>Who should attend: </strong><br />
Any IT or                                  business professional interested in IS Security                                  and assessing risk to an organization.</p>
<p align="left"><strong>This Webinar will:</strong></p>
<ul>
<li>
<div>Teach you more about how risk                                  assessments are changing to meet evolving                                  security needs. You&#8217;ll also discover the latest                                  security solutions to safeguard your company&#8217;s                                  ever-changing needs.</div>
</li>
<li>
<div>Give you insight into the                                  progression of IS Security issues. Plus, you&#8217;ll                                  learn how this evolving threat has forced                                  organizations to view risk assessments                                  differently and develop new techniques.</div>
</li>
<li>
<div>Provide you with the essential                                  solutions every IS and IT professional needs to                                  counter current and future threats.</div>
</li>
</ul>
<p style="text-align: center;"><span><strong><span style="font-family: Verdana; color: #c81c23; font-size: xx-small;"><span style="font-size: 7.5pt;">This webinar is free to                                  attend, but <span style="text-decoration: underline;">space is                                  limited</span></span></span></strong></span></p>
<p style="text-align: center;"><strong><a href="https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;eventid=112309" target="_blank">Register Now</a></strong></p>
<p><em><span style="font-family: Verdana; color: #14214a; font-size: xx-small;"><span style="font-weight: bold; font-size: 8.5pt; color: #14214a; font-family: Verdana;"><strong><span style="font-family: Verdana;"><span style="font-family: Verdana;">CISSPs and SSCPs can receive 1 CPE credit for attending this webinar. You can earn the credit by simply specifying your number on the registration form and correctly answering 3 multiple choice polling questions about the program at the end of the event.</span></span></strong></span></span></em></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2008-06-23-the-past-present-and-future-of-risk-assessments/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Network Vulnerability Assessment Workshop (March 2008)</title>
		<link>http://infosec.box.com.ph/2008-03-04-network-vulnerability-assessment-workshop-march-2008/</link>
		<comments>http://infosec.box.com.ph/2008-03-04-network-vulnerability-assessment-workshop-march-2008/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 05:37:35 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[InfoSec PH]]></category>

		<category><![CDATA[InfoSec Reading Materials]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2008-03-04-network-vulnerability-assessment-workshop-march-2008/</guid>
		<description><![CDATA[
presents
Network Vulnerability Assessment Workshop
March 26, 27 and 28 2008
In today&#8217;s world, it is getting more and more important for businesses to be connected and be accessible through the Internet. Businesses now put more stock into the viability of the net in increasing their profit margin and in large extent their public exposure. Thus, more financial [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img src="http://user231791.websitewizard.com/images/posh03_small_copy.jpg" height="47" width="203" /></p>
<p align="center">presents</p>
<p align="center"><strong>Network Vulnerability Assessment Workshop</strong></p>
<p align="center">March 26, 27 and 28 2008</p>
<p>In today&#8217;s world, it is getting more and more important for businesses to be connected and be accessible through the Internet. Businesses now put more stock into the viability of the net in increasing their profit margin and in large extent their public exposure. Thus, more financial value gets imbued into the data that goes around the wires.</p>
<p>That&#8217;s where the value of information security comes into play; assessing one&#8217;s readiness in defending information assets comes as a direct result of proper <strong>Vulnerability Assessment</strong> and to a larger scale of risk management. Getting one&#8217;s feet wet on VA will benefit not only the company&#8217;s security stance but also the individual&#8217;s appreciation of what could possibly lie ahead in terms of threats and risks, realization would also set on the extent of knowledge, time and investment to fully prepare one&#8217;s company in facing the growing challenges of today and tomorrow&#8217;s Internet.</p>
<p><strong>Course Objectives: </strong></p>
<p>At the end of the training, you should be able to:</p>
<ul>
<li>Determine the boundary of analysis and schedule of assessment</li>
<li>Perform threat and impact analysis</li>
<li>Define and verify policies of target assets for VA</li>
<li>Execute active and passive information gathering techniques</li>
<li>Utilize vulnerability scanning tools</li>
<li>Generate technical and managerial VA reports</li>
</ul>
<p><strong>Who Should Attend:</strong></p>
<ul>
<li>Network Managers</li>
<li>System Administrators</li>
<li>IT Managers</li>
<li>IT Auditors</li>
<li>Security Professionals</li>
</ul>
<blockquote>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><strong>Course Outline:</strong></font></font></font></font></font></font></font></font></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"></span><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"> </font></font></font></font></font></font></font></font></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><strong>DAY 1<o:p></o:p></strong></font></font></font></font></font></font></font></font></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"> </font></font></font></font></font></font></font></font></o:p></span></p>
<ul style="margin-top: 0in" type="disc">
<li>
<ul style="margin-top: 0in" type="circle"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Information Security Concepts<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">The Need for Information Security<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Vulnerability Assessment Overview<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">The Security Process<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Information Security Life Cycle<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Threats to Computer and Network Systems <o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">What is Ethical Hacking?<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Types of Ethical Hacking<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Responsibilities of an Ethical Hacker<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Skills Requirements<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Customer Expectations<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Relevant Laws<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
</li>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Introduction<br />
</span></strong></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Foundations<o:p></o:p></span></strong></li>
<p></font></font></font></font></font></font></font></font></ul>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><strong>DAY 2<o:p></o:p></strong></font></font></font></font></font></font></font></font></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"> </font></font></font></font></font></font></font></font></o:p></span></p>
<ul style="margin-top: 0in" type="disc">
<li>
<ul style="margin-top: 0in" type="circle"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Formal Methodologies<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Methodology Overview<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Open Source and Commercial Tools<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">The Live CD Approach<br />
</span><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p> </o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
<ul style="margin-top: 0in" type="circle">
<li>
<ul style="margin-top: 0in" type="square"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Passive Information Gathering<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Active Information Gathering<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Social Engineering<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
<ul style="margin-top: 0in" type="square"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Tools and Online Resources<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Google Hacking<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
</li>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Project Start-Up<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Information Gathering<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Threat and Impact Analysis<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Reconnaissance and Enumeration<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
</li>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Getting Started<o:p></o:p></span></strong></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Vulnerability Assessment</span></strong></li>
<p></font></font></font></font></font></font></font></font></ul>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><strong>DAY 3<o:p></o:p></strong></font></font></font></font></font></font></font></font></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"> </font></font></font></font></font></font></font></font></o:p></span></p>
<ul style="margin-top: 0in" type="disc">
<li>
<ul style="margin-top: 0in" type="circle">
<li>
<ul style="margin-top: 0in" type="square"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Technical Report<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Managerial Report<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
</li>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Vulnerability Scanning<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Report Generation<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Web Application Securit<br />
</span><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p> </o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
<ul style="margin-top: 0in" type="circle"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Summary<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Information Security Policies<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Introduction to Penetration Testing<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font></ul>
</li>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Vulnerability Assessment<o:p></o:p></span></strong></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Synopsis<o:p></o:p></span></strong></li>
<p></font></font></font></font></font></font></font></font></ul>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US"><o:p></o:p></span></p>
<p><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Miscellaneous<o:p></o:p></span></strong></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Reports<o:p></o:p></span></li>
<p></font></font></font></font></font></font></font></font><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"><font face="Arial,sans-serif" size="3"><font size="2"><font face="Arial,sans-serif"><font size="2"><font face="Arial,sans-serif"></p>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Checklists<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Technical Reports<o:p></o:p></span></li>
<li class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 10pt; font-family: 'Arial','sans-serif'" lang="EN-US">Managerial Reports</span></li>
<p></font></font></font></font></font></font></font></font></p></blockquote>
<p>Please bring your laptop.</p>
<p>Trainer&#8217;s Profile:</p>
<p><strong>Ariel Ben T. Senga, CISSP</strong></p>
<p>Ariel is the President and CEO of SeQure Technologies, which he cofounded in 2005. He is also a Certified Information Systems Security Professional. Ariel has intensive experience in various information systems management and development in IT, communications, manufacturing, government, and engineering industries. He has conducted various engagements related to IT internal control reviews, standards compliances, and internal audit reviews.</p>
<p>Currently, he has been managing all of SeQure Technologiesâ€™ security services such as vulnerability assessments, penetration testing, security assessments and audits, policy controls, and network infrastructure deployments.</p>
<p>Ariel has developed training courses in security awareness, network vulnerability assessment and penetration testing. As with course development, Ariel has presented in Universities and Colleges in the Philippines as an information security advocate.</p>
<p><strong>Training Schedule:</strong> March 26, 27 and 28, 2008 (3 Days w/ Lunch + Refreshment Snacks)</p>
<p><strong>Course Fee:</strong> PhP 17,500.00 (Exclusive of 12% VAT)</p>
<p><strong>Includes:</strong> Student Manual, Live CD, and Certificate of Completion</p>
<p><strong>Venue:</strong> CEO Suite, 37th Flr. LKG Tower 6801 Ayala Ave. 1226 Makati City</p>
<p>For more details, please call or text Pamela Chua at +63 922 8742757 or email pam@poshmarketingservices.com.</p>
<p>Cancellation of registration should be made seven working-days before the training date. Otherwise, 50% of the training fee shall be charged. No show during the training shall be charged 100% of the training fee.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2008-03-04-network-vulnerability-assessment-workshop-march-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Malcode Analysis and Response: Proficiency vs. Complexity</title>
		<link>http://infosec.box.com.ph/2008-03-03-malcode-analysis-and-response-proficiency-vs-complexity/</link>
		<comments>http://infosec.box.com.ph/2008-03-03-malcode-analysis-and-response-proficiency-vs-complexity/#comments</comments>
		<pubDate>Mon, 03 Mar 2008 05:34:17 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[InfoSec Developments]]></category>

		<category><![CDATA[InfoSec Trends]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[WWW]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2008-03-03-malcode-analysis-and-response-proficiency-vs-complexity/</guid>
		<description><![CDATA[

presents
Malcode Analysis and Response: Proficiency vs. Complexity
by Matt Allen and Russ McRee
Thursday, March 20, 2008 at 1:00 PM EDT (1700 UTC/GMT)
 The threat landscape changes constantly, driven in part by the &#8220;bot economy&#8221; and changing malcode techniques. In response, incident handler techniques must keep pace. This presentation will cover the use of RAPIER, a security [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><strong><img src="https://www.sans.org/images/webcasts_logo.jpg" height="207" width="273" /><br />
</strong></p>
<p align="center">presents</p>
<p align="center"><strong>Malcode Analysis and Response: Proficiency vs. Complexity</strong></p>
<p align="center">by Matt Allen and Russ McRee</p>
<p align="center">Thursday, March 20, 2008 at 1:00 PM EDT (1700 UTC/GMT)</p>
<p> The threat landscape changes constantly, driven in part by the &#8220;bot economy&#8221; and changing malcode techniques. In response, incident handler techniques must keep pace. This presentation will cover the use of RAPIER, a security tool built to facilitate first response procedures for incident handling. It is designed to acquire commonly requested information and samples during an information security event, incident, or investigation. RAPIER automates the entire process of data collection and delivers the results directly to the hands of a skilled security analyst. From detection and discovery, capture and containment, count on a useful discussion meant to further your incident response practices.</p>
<p>The second part of this webcast will discuss how malicious code authors are persistently introducing new hurdles to complicate reverse engineering. At Norman, we combine observations from our labs with feedback from SandBox customers to identify complexities responsible for wearing down efficient analysis of new threats. The impact of new SandBox capabilities for addressing these complexities will be introduced, followed by a short discussion of top priorities in the SandBox product roadmap.</p>
<p><strong>Matt Allen:</strong> With backgrounds in computer and information sciences as well as business, Matt Allen has worked in a number of different roles at Norman over the past 5 years, varying from incident response to web and software development. Matt is currently working with the SandBox team on various projects ranging from development to marketing.</p>
<p><strong>Russ McRee:</strong> Russ McRee, GCIH, GCFA, CISSP is a security analyst working in the Seattle area. He&#8217;s the author of ISSA Journal&#8217;s monthly column Toolsmith, and has written for Information Security, Linux Pro, SysAdmin and others, including an OWASP whitepaper. Prior speaking engagements include SecureWorld Expo, ISSA Northwest Regional, WSA SIG, RAID 2005, and Linuxfest Northwest. Russ has been a board member of ISSA Puget Sound, and is a member of PACCISO, InfraGard and CCSA. Russ maintains <a href="http://holisticinfosec.org/" target="_blank">holisticinfosec.org</a>.</p>
<p align="left"><a href="https://www.sans.org/webcasts/show.php?webcastid=91808" target="_blank">Register for this free webseminar</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2008-03-03-malcode-analysis-and-response-proficiency-vs-complexity/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security Insights with Dr. Eric Cole</title>
		<link>http://infosec.box.com.ph/2008-03-02-security-insights-with-dr-eric-cole/</link>
		<comments>http://infosec.box.com.ph/2008-03-02-security-insights-with-dr-eric-cole/#comments</comments>
		<pubDate>Sun, 02 Mar 2008 05:30:57 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[WWW]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2008-03-02-security-insights-with-dr-eric-cole/</guid>
		<description><![CDATA[

presents
Security Insights with Dr. Eric Cole
Wednesday, March 19, 2008 at 1:00 PM EDT (1700 UTC/GMT)
Most people think that encryption protects attackers from accessing sensitive information, but it is important to remember that encryption stops anyone from reading information. Therefore if it is not properly deployed, encryption can actually decrease security if it blinds critical security [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><strong><img src="https://www.sans.org/images/webcasts_logo.jpg" height="207" width="273" /><br />
</strong></p>
<p align="center">presents</p>
<p align="center"><strong>Security Insights with Dr. Eric Cole</strong></p>
<p align="center">Wednesday, March 19, 2008 at 1:00 PM EDT (1700 UTC/GMT)</p>
<p>Most people think that encryption protects attackers from accessing sensitive information, but it is important to remember that encryption stops anyone from reading information. Therefore if it is not properly deployed, encryption can actually decrease security if it blinds critical security components from analyzing traffic. In addition, many companies are deploying full disk encryption but if it is not configured correctly, it might be providing a false sense of security.</p>
<p>Based on first-hand experience, this talk will look at areas where encryption should be used and how to avoid common mistakes. Dr. Cole will also identify areas where encryption should not be deployed. Overall, this talk will provide expert knowledge of the landscape of encryption, proper uses and common pitfalls.</p>
<p>Dr. Eric Cole is an industry recognized security expert, with over 15 year&#8217;s hands-on experience. Dr. Cole currently performs leading edge security consulting and works in research and development to advance the state of the art in information systems security. Dr. Cole has experience in information technology, with a focus on perimeter defense, secure network design, vulnerability discovery, penetration testing, and intrusion detection systems. Dr. Cole has a Masters in Computer Science from NYIT, and Ph.D. from Pace University with a concentration in Information Security. Dr. Cole is the author of several books to include Hackers Beware, Hiding in Plain Site, Network Security Bible and Insider Threat. He is also the inventor of over 20 patents and is a researcher, writer, and speaker. Eric is also a senior scientist with Lockheed Martin Information Technology (LMIT) and Lockheed Martin (LM) fellow. Dr. Cole is actively involved with The SANS Technology Institute (STI) and SANS actively working with students, teaching, maintaining and developing courseware.</p>
<p><a href="https://www.sans.org/webcasts/show.php?webcastid=91788" target="_blank">Register now for this free webcast! </a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2008-03-02-security-insights-with-dr-eric-cole/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What Works: PaulDotCom&#8217;s Penetration Testing Dojo: Core IMPACT Style</title>
		<link>http://infosec.box.com.ph/2008-03-01-what-works-pauldotcoms-penetration-testing-dojo-core-impact-style/</link>
		<comments>http://infosec.box.com.ph/2008-03-01-what-works-pauldotcoms-penetration-testing-dojo-core-impact-style/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 01:06:26 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[Security Tools]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2008-03-01-what-works-pauldotcoms-penetration-testing-dojo-core-impact-style/</guid>
		<description><![CDATA[

presents
What Works: PaulDotCom&#8217;s Penetration Testing Dojo: Core IMPACT Style
by Alan Paller and Paul Asadoorian
Tuesday, March 18 at 1:00 PM EDT (1700 UTC/GMT)
When beginning a security process at a consortium of non-profits, senior network security engineer, Paul Asadoorian of Pauldotcom began looking for a penetration testing tool that did network, web application and social engineering tests. [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><strong><img src="https://www.sans.org/images/webcasts_logo.jpg" height="207" width="273" /><br />
</strong></p>
<p align="center">presents</p>
<p align="center"><strong>What Works: PaulDotCom&#8217;s Penetration Testing Dojo: Core IMPACT Style</strong></p>
<p align="center">by Alan Paller and Paul Asadoorian</p>
<p align="center">Tuesday, March 18 at 1:00 PM EDT (1700 UTC/GMT)</p>
<p align="left">When beginning a security process at a consortium of non-profits, senior network security engineer, Paul Asadoorian of Pauldotcom began looking for a penetration testing tool that did network, web application and social engineering tests. The tool he purchased is low on manpower use, mostly self-maintaining and reliably proves the existence of network vulnerabilities. Please attend this webcast to find out why Paul selected CORE IMPACT and learn how it can help you safely perform network, web application and end-user penetration testing.</p>
<p align="left">About the Speakers:</p>
<p align="left"><strong>Alan Paller:</strong></p>
<p align="left">Alan is the Director of Research for the SANS Institute, responsible for overseeing all research projects ranging from the SANS Step-by-Step guides to the SANS digests to the Top Twenty Internet Security Threats. He the founder of the CIO Institute, and earned his degrees in Computer Science and Engineering from Cornell and MIT. Alan is the author of the EIS Book: Information Systems for Top Managers and How to Give the Best Presentation of Your Life. In 2001 the President named Alan as one of the original members of the National Infrastructure Advisory Council. The Federal CIO Council chose him as its 2005 Azimuth Award winner recognizing his vision and outstanding service to federal information technology.In 2007, CIO Decisions, eWeek , and Baseline magazines jointly selected Alan as one of the 100 most influential people in the Information technology field.</p>
<p><strong>Paul Asadoorian:</strong></p>
<p align="left">Paul Asadoorian GCIA, GCIH, Founder &amp; Chief Executive Officer Paul Asadoorian has over 5 years experience working in the information security field. His work experience covers both major corporations and academic institutions. He currently holds two GIAC (Global Information Assurance Certification) certifications in intrusion detection (GCIA, GIAC Certified Intrusion Analyst) and incident response (GCIH, GIAC Certified Incident Handler). Paul also sits on the GCIA advisory board, has spent one year as a GCIA authorized grader, and continues to stay involved in the SANS (SysAdmin, Audit, Network, Security) Institute. His research has appeared in the book Network Intrusion Detection, 3rd edition, and also in the SANS Reading Room web site. Paul has presented for numerous organizations and conferences, including MIT Security Camp, and ISACA (Information Systems Audit and Control Association). Paul graduated from Bryant College with a bachelor of science in Computer Information Systems.</p>
<p align="left">Sign-up to <a href="https://www.sans.org/webcasts/show.php?webcastid=91541" target="_blank">attend the free webcast</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2008-03-01-what-works-pauldotcoms-penetration-testing-dojo-core-impact-style/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Proactive Strategies for Securing Your Applications</title>
		<link>http://infosec.box.com.ph/2007-06-10-proactive-strategies-for-securing-your-applications/</link>
		<comments>http://infosec.box.com.ph/2007-06-10-proactive-strategies-for-securing-your-applications/#comments</comments>
		<pubDate>Sun, 10 Jun 2007 06:32:25 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[InfoSec Reading Materials]]></category>

		<category><![CDATA[Risk Management]]></category>

		<category><![CDATA[Security Tools]]></category>

		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2007-06-10-proactive-strategies-for-securing-your-applications/</guid>
		<description><![CDATA[
The threat vectors that target today’s software applications are constantly evolving. While commercial software security features are improving, vulnerabilities still exist.
Customized and proprietary software – those that power much of today’s business operations – are even more vulnerable, as hackers increasingly target applications that range from e-commerce platforms to legacy accounting systems.

As the number of [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img src="http://farm2.static.flickr.com/1166/538209854_f7ff7f4561_o_d.gif" title="Neophasis" alt="Neophasis" align="absmiddle" height="23" width="194" /></p>
<p>The threat vectors that target today’s software applications are constantly evolving. While commercial software security features are improving, vulnerabilities still exist.</p>
<p>Customized and proprietary software – those that power much of today’s business operations – are even more vulnerable, as hackers increasingly target applications that range from e-commerce platforms to legacy accounting systems.</p>
<p align="center"><img src="http://farm2.static.flickr.com/1236/538217350_4ecd214800_d.jpg" title="Probability and Severity" alt="Probability and Severity" align="absmiddle" /></p>
<p>As the number of companies deploying proprietary software on or near public networks continues to spike, concerns about application security are more acute than ever.</p>
<p align="center"><img src="http://farm2.static.flickr.com/1368/538335293_6772b3fae9_o_d.jpg" title="Secured SDLC" alt="Secured SDLC" align="absmiddle" height="293" width="324" /></p>
<p align="center">What steps can you take to protect your company?</p>
<p>An effective, proactive defense against today’s attacks and tomorrow’s threats requires the right combination of technology and expertise.</p>
<p align="center"> <img src="http://farm2.static.flickr.com/1338/538217210_335dfba15b_o_d.jpg" title="Degree of Security Assurance and Review Time" alt="Degree of Security Assurance and Review Time" align="absmiddle" height="507" width="462" /></p>
<p>Making sure you have the right team in place, typically a blend of internal and external experts, is the first step. Methodically identifying and addressing your company’s vulnerabilities, and establishing a plan for ongoing defensive measures is the next.</p>
<p>This FREE whitepaper from Neophasis will help you better understand the threats your company is facing, and the immediate steps you can take to confidently secure your applications.</p>
<p>Download <a href="http://www.emediausa.com/FM/GetFile.aspx?id=4231" target="_blank">Neophasis&#8217; Proactive Strategies for Securing Your Applications FREE Whitepaper</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2007-06-10-proactive-strategies-for-securing-your-applications/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Anatomy of a Breach Webcast</title>
		<link>http://infosec.box.com.ph/2007-06-09-anatomy-of-a-breach-webcast/</link>
		<comments>http://infosec.box.com.ph/2007-06-09-anatomy-of-a-breach-webcast/#comments</comments>
		<pubDate>Fri, 08 Jun 2007 22:18:41 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[InfoSec Developments]]></category>

		<category><![CDATA[InfoSec Reading Materials]]></category>

		<category><![CDATA[InfoSec Trends]]></category>

		<category><![CDATA[Seminars]]></category>

		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[WWW]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2007-06-09-anatomy-of-a-breach-webcast/</guid>
		<description><![CDATA[ 
Anatomy of a Breach Webcast
June 13 , 2007- 12 p.m. EDT
You harbor vast amounts of confidential information ranging from credit cards to health information to corporate plans. That proprietary data is today’s “new money” and someone is willing to pay for it. Unfortunately, the miscreants who want it may know more about technology—and your IT [...]]]></description>
			<content:encoded><![CDATA[<p align="center"> <img src="http://farm2.static.flickr.com/1269/538256455_573ca2bb10_d.jpg" title="Anatomy of a Breach Webcast" alt="Anatomy of a Breach Webcast" align="absmiddle" /></p>
<p align="center">Anatomy of a Breach Webcast</p>
<p align="center">June 13 , 2007- 12 p.m. EDT</p>
<p>You harbor vast amounts of confidential information ranging from credit cards to health information to corporate plans. That proprietary data is today’s “new money” and someone is willing to pay for it. Unfortunately, the miscreants who want it may know more about technology—and your IT environment—than your own staff. The stakes are enormous: for your customers, your company, and you.</p>
<blockquote><p>In this webcast, we examine the fundamental shift of IT risk to the insider threat and the inability of legacy protection mechanisms to stop it. We itemize and quantify the impact from containment to notification. Most importantly, we discuss eradication of the breach risk. New, targeted, caustic threats require new responses that strictly secure your critical information assets, while proving it with 100 percent surety.</p></blockquote>
<p><strong>Who Should Watch:</strong><br />
Executives responsible for audits, compliance and mitigating data breach risks and security professionals responsible for protecting critical assets on their networks<br />
<strong>About the speakers:</strong><br />
<em>William Malik</em><br />
Consultant, Identity and Information Security<br />
Malik Consulting</p>
<p>Bill Malik has been well-known in information security since the early 1990s when he was a founding member of Gartner&#8217;s Information Security Strategies service. He began his IT career in Boston as an applications programmer with the John Hancock Insurance Company following undergraduate work at MIT. He joined IBM&#8217;s MVS team and worked in development, testing, business planning, and strategic planning for a dozen years. He moved to Gartner in 1990 and held a series of roles as an analyst and manager through 2002. As CTO of Waveset, a start-up in identity management, he helped the firm grow through its acquisition by Sun, where Bill became Director of Marketing for Security. In 2004 Bill established his independent consulting firm, where he helps clients develop their identity management and information security programs.</p>
<p><em>Robert Ciampa</em><br />
Vice President, Marketing and Business Strategy<br />
Trusted Network Technologies</p>
<p>Rob Ciampa has more than 20 years of experience in IT risk management, networking and security. Rob has worked with companies around the world designing and implementing secure infrastructures. An early OS engineer for HP and a former switch and router designer for 3Com, he co-founded one of world’s largest network and security integration firms. Rob then went on to Access360, where he was instrumental in its acquisition by IBM, where he subsequently ran IBM’s worldwide channel for security and identity management. In additional to television commentary on IT and computer security issues, Rob is frequently a featured speaker at major IT venues and events internationally. He has a B.S. in computer science and an M.S. in computer engineering from the University of Massachusetts, as well as an M.B.A. from Boston University. He holds two patents in information technology management. His blog is www.knowidentity.com.</p>
<p>Join the <a href="http://www.trustednetworktech.com/breach.asp" title="Anatomy of a Breach Webcast" target="_blank">Anatomy of a Breach Webcast</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2007-06-09-anatomy-of-a-breach-webcast/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RSA Data Integrity Strategy Kit for the Financial Industry</title>
		<link>http://infosec.box.com.ph/2007-06-08-rsa-data-integrity-strategy-kit-for-the-financial-industry/</link>
		<comments>http://infosec.box.com.ph/2007-06-08-rsa-data-integrity-strategy-kit-for-the-financial-industry/#comments</comments>
		<pubDate>Thu, 07 Jun 2007 22:15:36 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Free Stuff]]></category>

		<category><![CDATA[InfoSec Reading Materials]]></category>

		<category><![CDATA[InfoSec Trends]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2007-06-08-rsa-data-integrity-strategy-kit-for-the-financial-industry/</guid>
		<description><![CDATA[
Get a complimentary copy of the Data Integrity Strategy Kit for the Financial Industry from RSA, featuring a new Burton Group report with actionable information on preventing unauthorized or inappropriate changes to business information.
Data Integrity Strategy Kit for the Financial Industry At a Glance:
Burton Group Report
Security and Risk Management Strategies: Information Integrity, March 2007
Podcast
&#8220;Real-World Strategies [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img src="http://farm2.static.flickr.com/1355/538160359_93941ed519_o_d.jpg" title="RSA Data Integrity Strategy Kit for the Financial Industry" alt="RSA Data Integrity Strategy Kit for the Financial Industry" align="absmiddle" height="160" width="330" /></p>
<p>Get a complimentary copy of the Data Integrity Strategy Kit for the Financial Industry from RSA, featuring a new Burton Group report with actionable information on preventing unauthorized or inappropriate changes to business information.</p>
<p><em>Data Integrity Strategy Kit for the Financial Industry At a Glance:</em></p>
<p><strong>Burton Group Report</strong><br />
Security and Risk Management Strategies: Information Integrity, March 2007</p>
<p><strong>Podcast</strong><br />
&#8220;Real-World Strategies for Protecting your Data&#8221; with Jon Oltsik of Enterprise Strategy Group</p>
<p><strong>Data Sheet: File Security Manager</strong><br />
Centrally managed, transparent compromise prevention for critical files</p>
<p><strong>Data Sheet: Database Security Manager</strong><br />
Transparent, policy-driven data protection optimized for heterogeneous database environments<br />
Limited time offer. Download now! <a href="http://www.sans.org/info/8461" onclick="return top.js.OpenExtLink(window,event,this)" target="_blank">http://www.sans.org/info/8461</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2007-06-08-rsa-data-integrity-strategy-kit-for-the-financial-industry/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yahoo! Messenger ActiveX Flaw Exploits Released!</title>
		<link>http://infosec.box.com.ph/2007-06-07-yahoo-messenger-activex-flaw-exploits-released/</link>
		<comments>http://infosec.box.com.ph/2007-06-07-yahoo-messenger-activex-flaw-exploits-released/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 23:51:04 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[InfoSec Reading Materials]]></category>

		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security Breach]]></category>

		<category><![CDATA[Security Bulletin]]></category>

		<category><![CDATA[Software Updates]]></category>

		<category><![CDATA[Vulnerability]]></category>

		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2007-06-07-yahoo-messenger-activex-flaw-exploits-released/</guid>
		<description><![CDATA[
Two zero-day exploits for remote code execution flaws in Yahoo! Messenger&#8217;s Webcam application have been released.
One of the flaws is a boundary error in the Yahoo! Webcam Upload ActiveX control; the other is in the Yahoo! Webcam Viewer ActiveX control.
Yahoo! expects to have a fix for the flaws available soon.  The flaws have been confirmed [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img src="http://farm2.static.flickr.com/1279/538077028_f1494ba66c_o_d.gif" title="Yahoo! Messenger" alt="Yahoo! Messenger" align="absmiddle" height="33" width="275" /></p>
<p>Two zero-day exploits for remote code execution flaws in Yahoo! Messenger&#8217;s Webcam application have been released.</p>
<p>One of the flaws is a boundary error in the Yahoo! Webcam Upload ActiveX control; the other is in the Yahoo! Webcam Viewer ActiveX control.</p>
<p>Yahoo! expects to have a fix for the flaws available soon.  The flaws have been confirmed in Yahoo! Messenger version 8.1.0.249 and may exist in other versions as well.</p>
<p>{Update: As of Friday, June 8, 2007, Yahoo! has already prompted yahoo messenger users to download and install a security upgrade to patch the security issue}</p>
<p>More info here on the <a href="http://messenger.yahoo.com/security_update.php?id=060707" title="Yahoo! ActiveX Flaw" target="_blank">Yahoo! ActiveX Flaw</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2007-06-07-yahoo-messenger-activex-flaw-exploits-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Dreamhost&#8217;s Systems Hacked Yet Again</title>
		<link>http://infosec.box.com.ph/2007-06-06-dreamhosts-systems-hacked-yet-again/</link>
		<comments>http://infosec.box.com.ph/2007-06-06-dreamhosts-systems-hacked-yet-again/#comments</comments>
		<pubDate>Tue, 05 Jun 2007 22:25:31 +0000</pubDate>
		<dc:creator>InfoSec PH</dc:creator>
		
		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security Breach]]></category>

		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://infosec.box.com.ph/2007-06-06-dreamhosts-systems-hacked-yet-again/</guid>
		<description><![CDATA[ 
Attackers broke into the computer systems of web host company DreamHost and installed malware on hundreds of websites, including the official site of the Mercury music awards.
DreamHost said the intruder or intruders exploited a flaw in its web control panel software.
DreamHost has notified affected customers of the breach via email.
The attackers attempted to access the [...]]]></description>
			<content:encoded><![CDATA[<p align="center"> <img src="http://farm2.static.flickr.com/1427/538067682_348e48d715_o_d.png" align="absmiddle" height="33" width="156" /></p>
<p>Attackers broke into the computer systems of web host company DreamHost and installed malware on hundreds of websites, including the official site of the Mercury music awards.</p>
<p>DreamHost said the intruder or intruders exploited a flaw in its web control panel software.</p>
<p>DreamHost has notified affected customers of the breach via email.</p>
<p>The attackers attempted to access the company&#8217;s central database and billing data, but no billing or credit card data were compromised in the intrusion.</p>
<p>DreamHost is responsible for more than 500,000 domains.  The intrusion affected approximately 3,500 FTP accounts; users were urged to change their FTP account passwords as soon as possible.</p>
<p>Read <a href="http://www.dreamhoststatus.com/2007/06/06/security-breach" title="Dreamhost Breach Statement" target="_blank">Dreamhost&#8217;s official statement on the breach</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosec.box.com.ph/2007-06-06-dreamhosts-systems-hacked-yet-again/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
