<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-414</id>
	<title>Nabble - Security - Linux</title>
	<updated>2009-11-24T08:25:54Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Security---Linux-f414.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security---Linux-f414.html" />
	<subtitle type="html"></subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26498545</id>
	<title>Re: Hardening CentOS</title>
	<published>2009-11-24T08:25:54Z</published>
	<updated>2009-11-24T08:25:54Z</updated>
	<author>
		<name>Tony Murphy</name>
	</author>
	<content type="html">Here is a link to a YouTube demo of the 3.1 product that was shot at the RedHat Summit earlier this year. &amp;nbsp;The new product coming out in Dec 2009 will also support Novell SUSE and OpenSUSE and Fedora 11.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://tcs-security-blanket.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tcs-security-blanket.blogspot.com/&lt;/a&gt;&amp;nbsp;is the technical blog for the product and has tons of great content.
&lt;br&gt;&lt;br&gt;Demo
&lt;br&gt;&lt;br&gt;&lt;object width=&quot;640&quot; height=&quot;385&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/F0rJVWUjZK8&amp;hl=en_US&amp;fs=1&amp;color1=0x006699&amp;color2=0x54abd6&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/F0rJVWUjZK8&amp;hl=en_US&amp;fs=1&amp;color1=0x006699&amp;color2=0x54abd6&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;640&quot; height=&quot;385&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br&gt;&lt;quote author=&quot;Tony Murphy&quot;&gt;&lt;br&gt;David, 
&lt;br&gt;Thanks for the mention of Security Blanket. &amp;nbsp;I've written a quick synopsis of the product and provided a link for a free trial here.
&lt;br&gt;&lt;a id=&quot;nabblelink&quot; href=&quot;http://n2.nabble.com/Security-Blanket-by-Trusted-Computer-Systems-Linux-Solaris-Hardening-Lockdown-f3121579.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Security Blanket by Trusted Computer Systems Linux Solaris Hardening Lockdown&lt;/a&gt;&lt;br&gt;&amp;lt;script src=&amp;quot;&lt;a href=&quot;http://n2.nabble.com/embed/f3121579&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://n2.nabble.com/embed/f3121579&lt;/a&gt;&amp;quot;&amp;gt;&amp;lt;/script&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;David A. Kennel wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;A good place to start would be the Center For Internet Security Red Hat 
&lt;br&gt;Enterprise Benchmark and the NSA Secure Configuration Guide. You could 
&lt;br&gt;also check out the Security Blanket tool by Trusted Computing Solutions 
&lt;br&gt;or Bastille.
&lt;br&gt;&lt;br&gt;Link farm:
&lt;br&gt;&lt;a href=&quot;http://www.nsa.gov/snac/downloads_redhat.cfm?MenuID=scg10.3.1.1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.nsa.gov/snac/downloads_redhat.cfm?MenuID=scg10.3.1.1&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.cisecurity.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cisecurity.org/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.trustedcs.com/SecurityBlanket.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.trustedcs.com/SecurityBlanket.html&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://bastille-linux.sourceforge.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bastille-linux.sourceforge.net/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Florin Iliescu wrote:
&lt;br&gt;&amp;gt; Helo,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can anybody help me with some procedures to secure a CentOS server? I am going to use it for receiving files over Internet with SFTP.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thank you,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Florin
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;--
&lt;br&gt;David Kennel
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
&lt;/quote&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Hardening-CentOS-tp18262907p26498545.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26498542</id>
	<title>Re: Linux Hardening</title>
	<published>2009-11-24T08:19:09Z</published>
	<updated>2009-11-24T08:19:09Z</updated>
	<author>
		<name>Tony Murphy</name>
	</author>
	<content type="html">Security Blanket by TCS is an automated lockdown tool for Linux and Solaris. &amp;nbsp;TCS helped create the linux 2.6 kernel and is listed on the NSA webpage for having created the MLS extensions to SELinux.
&lt;br&gt;&lt;br&gt;The product blog is &lt;a href=&quot;http://tcs-security-blanket.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tcs-security-blanket.blogspot.com/&lt;/a&gt;&amp;nbsp;with tons of content, example reports, links to industry recognized lockdown criteria
&lt;br&gt;&lt;br&gt;Security Blanket supports:
&lt;br&gt;RHEL 4 and above
&lt;br&gt;Oracle Ent Linux 4 and above
&lt;br&gt;Fedora 10 and above
&lt;br&gt;SUSE 11 and above
&lt;br&gt;OpenSUSE 11 and above
&lt;br&gt;Solaris 10 x86 and SPARC
&lt;br&gt;&lt;br&gt;It runs on System z, SPARC, 32 bit and 64 bit x86 architectures and PowerPC
&lt;br&gt;&lt;br&gt;Here is a demo of the 3.1 GA version and a newer version from RedHat Summit 2009 and a new product will release Dec 2009
&lt;br&gt;&lt;object width=&quot;640&quot; height=&quot;385&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/F0rJVWUjZK8&amp;hl=en_US&amp;fs=1&amp;color1=0x006699&amp;color2=0x54abd6&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/F0rJVWUjZK8&amp;hl=en_US&amp;fs=1&amp;color1=0x006699&amp;color2=0x54abd6&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;640&quot; height=&quot;385&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;jvicente wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi,
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I was looking for a Linux hardening tool. I found Bastille. The latest = version that I was able to find is 3.09. I cannot seem to get this = version to work on later versions of Linux (RHEL 5, FC 6,7) = distributions.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Is this tool still being supported? Is there a similar tool out there?
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks in advance,
&lt;br&gt;&lt;br&gt;JP
&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Linux-Hardening-tp13159861p26498542.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26452396</id>
	<title>Replicating the Gonzalez Cyber Attacks through Penetration Testing</title>
	<published>2009-11-20T16:07:10Z</published>
	<updated>2009-11-20T16:07:10Z</updated>
	<author>
		<name>Norwich University</name>
	</author>
	<content type="html">--------------------------------------------------------------------------------
&lt;br&gt;YOU'RE INVITED: IT SECURITY ON DEMAND WEBCAST
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;quot;Replicating the Gonzalez Cyber Attacks through Penetration Testing&amp;quot;
&lt;br&gt;Register: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;---------------------------------------------------------------------------------
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Recently, we saw the indictment of cybercrime kingpin Albert Gonzalez, one of the accused masterminds behind high-profile data breaches at Heartland Payment Systems, Hannaford Bros. Supermarkets, 7-Eleven, and TJX. Next week, Core Security Technologies will present a hands-on look at the attacks Gonzalez and his co-conspirators are believed to have used in breaching these organizations.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Leveraging the actual indictment document as a guide, Core Security senior product manager Alex Horan will use CORE IMPACT Pro penetration testing software to demonstrate the techniques by which Gonzales allegedly stole millions of credit card numbers* - showing you how to identify IT exposures in your own environment before cybercriminals do.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;During the webcast, you'll see a step-by-step depiction of an attack similar to that described in the Gonzalez indictment, including the following critical stages:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;the initial web application compromise via SQL Injection
&lt;br&gt;* &amp;nbsp;the use of a well-known backend database command to make the attacks even
&lt;br&gt;* &amp;nbsp;more invasive
&lt;br&gt;* &amp;nbsp;the planting of malware on the backend database server
&lt;br&gt;* &amp;nbsp;the collection and transmission of credit card transactions to the
&lt;br&gt;* &amp;nbsp;attackers
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Through the demonstration, you'll also learn how commercial-grade penetration testing software enables you to see your IT systems as an attacker would -- not only by determining if the kinds of issues that Gonzalez reportedly leveraged are present in your environment, but also by ...
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;assessing how deployed defenses react to specific threats
&lt;br&gt;* &amp;nbsp;revealing what systems and data would be exposed by a breach
&lt;br&gt;* &amp;nbsp;depicting how chains of vulnerabilities open paths to mission-critical
&lt;br&gt;* &amp;nbsp;systems and information
&lt;br&gt;* &amp;nbsp;providing actionable data for immediately mitigating critical exposures
&lt;br&gt;* &amp;nbsp;repeating tests to ensure the effectiveness of remediation efforts
&lt;br&gt;&amp;nbsp;
&lt;br&gt;This webcast is ideal for anyone interested in proactively assessing their security posture against real-world cyber threats.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Replicating-the-Gonzalez-Cyber-Attacks-through-Penetration-Testing-tp26452396p26452396.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26098028</id>
	<title>Smart-Card Open Test Toolkit</title>
	<published>2009-10-28T00:24:30Z</published>
	<updated>2009-10-28T00:24:30Z</updated>
	<author>
		<name>Tommaso Cucinotta-2</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;&lt;br&gt;I would like to announce the availability of SCOTT, an open, modular and
&lt;br&gt;extensible smart-card shell, which can be used for interacting with
&lt;br&gt;smart-card devices, i.e., browsing its contents or also using the
&lt;br&gt;on-board capabilities, as well as for automating such smart-card
&lt;br&gt;operations by means of scripts. The envisioned usage scenario is around
&lt;br&gt;automated smart-card configuration like needed during the development of
&lt;br&gt;smart-card based applications, where one may have to repeatedly perform
&lt;br&gt;a set of operations onto a smart-card, usually for testing purposes. For
&lt;br&gt;example, &amp;quot;formatting&amp;quot; a card and loading some certificates and keys, or
&lt;br&gt;loading some (updated version of a) JavaCard Applet. This is the
&lt;br&gt;motivation for the project name: Smart-Card Open Test Toolkit.
&lt;br&gt;&lt;br&gt;The idea is to have a basic core constituted by a command-line
&lt;br&gt;interactive shell, where external plugins define sets of commands which
&lt;br&gt;can be:
&lt;br&gt;-) commands related to some particular smart-card API, like the &amp;quot;system&amp;quot;
&lt;br&gt;scott-pcsc plug-in, which provides shell commands for listing available
&lt;br&gt;readers, checking status, connecting to the inserted device and sending
&lt;br&gt;generic APDUs;
&lt;br&gt;-) commands corresponding to a set of command APDUs defined by some
&lt;br&gt;specific standard, like the scott-iso7816 plug-in, currently supporting
&lt;br&gt;ISO 7816-4 file management commands
&lt;br&gt;-) commands corresponding to the specific set of APDUs supported by a
&lt;br&gt;particular smart-card device, like the scott-cryptoflex8 plug-in,
&lt;br&gt;currently supporting specific capabilities of the Schlumberger
&lt;br&gt;Cryptoflex 8K device.
&lt;br&gt;&lt;br&gt;Other plugins which may come in the future could be for supporting
&lt;br&gt;loading of JavaCard applets, for supporting specific commands of
&lt;br&gt;particular devices, or for supporting other standard APIs.
&lt;br&gt;&lt;br&gt;The shell has a built-in type-system, by which a plug-in can define its
&lt;br&gt;own set of types. This allows for example to exchange high-level
&lt;br&gt;information with the user in a structured form (the classical example is
&lt;br&gt;when one provides the set of information needed to create a new file, or
&lt;br&gt;when one selects an on-board file and retrieves its &amp;quot;descriptor&amp;quot;).
&lt;br&gt;&lt;br&gt;Also, it has a built-in variables environment, by which one can assign
&lt;br&gt;return types from commands, then supply them to other commands as input,
&lt;br&gt;etc....
&lt;br&gt;&lt;br&gt;The project has been developed by Andrea Angella for his masters thesis
&lt;br&gt;in Computer Engineering here at the Real-Time Systems Laboratory of
&lt;br&gt;Scuola Superiore Sant'Anna, under my supervision, and it has been
&lt;br&gt;released under GPL open-source license. Code is available on gna.org:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;https://gna.org/projects/scott&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://gna.org/projects/scott&lt;/a&gt;&lt;br&gt;&lt;br&gt;Any comment/suggestion is of course encouraged and very welcome. You can
&lt;br&gt;also use the mailing-list we set-up for the project:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;https://mail.gna.org/listinfo/scott-devel/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://mail.gna.org/listinfo/scott-devel/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thanks for your attention.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; Tommaso Cucinotta
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Tommaso Cucinotta, Computer Engineering PhD, Researcher
&lt;br&gt;ReTiS Lab, Scuola Superiore Sant'Anna, Pisa, Italy
&lt;br&gt;Tel +39 050 882 024, Fax +39 050 882 003
&lt;br&gt;&lt;a href=&quot;http://retis.sssup.it/people/tommaso&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://retis.sssup.it/people/tommaso&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Smart-Card-Open-Test-Toolkit-tp26098028p26098028.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25386256</id>
	<title>SecurityTubeCon CFP, Venue: Cyberspace!</title>
	<published>2009-09-09T21:45:34Z</published>
	<updated>2009-09-09T21:45:34Z</updated>
	<author>
		<name>vivek-18</name>
	</author>
	<content type="html">Dear All,
&lt;br&gt;&lt;br&gt;SecurityTube.net is pleased to announce the CFP for SecurityTubeCon, the 
&lt;br&gt;first hacker conference, to be held completely online!
&lt;br&gt;&lt;br&gt;SecurityTubeCon is aimed at democratizing hacker conferences by allowing 
&lt;br&gt;any researcher, regardless of his physical location, to share his work 
&lt;br&gt;with the community. Unlike other Cons we will not *accept / reject* 
&lt;br&gt;speakers. If you have something interesting to share, you WILL be heard. 
&lt;br&gt;The idea behind SecurityTubeCon is not to pass judgments on your work, 
&lt;br&gt;instead, it aims at providing a platform for knowledge exchange.
&lt;br&gt;&lt;br&gt;Once speakers send in their talk abstracts, we will put it online for 
&lt;br&gt;the community members to decide which talks they want to attend. On the 
&lt;br&gt;day of the conference, speakers will broadcast their talks using 
&lt;br&gt;screencasting software and the interested participants will tune in. The 
&lt;br&gt;participants will use IRC / chat rooms to ask questions to the speakers 
&lt;br&gt;during the talks.
&lt;br&gt;&lt;br&gt;What else is unique about SecurityTubeCon?
&lt;br&gt;&lt;br&gt;a. This conference will be held completely online!
&lt;br&gt;b. Location No Barrier - speak / attend SecurityTubeCon from your bedroom :)
&lt;br&gt;c. Language No Barrier - though we would recommend English as the 
&lt;br&gt;preferred language so you can address a global audience, feel free to 
&lt;br&gt;speak in the language you are most comfortable with
&lt;br&gt;d. $0 is the conference registration fees - absolutely free
&lt;br&gt;&lt;br&gt;&lt;br&gt;For the CFP and other details please visit the conference site at 
&lt;br&gt;&lt;a href=&quot;http://www.securitytubecon.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securitytubecon.org&lt;/a&gt;&lt;br&gt;&lt;br&gt;Here is a quick summary of the CFP in an FAQ format:
&lt;br&gt;&lt;br&gt;-----------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;1. When and Where will SecurityTubeCon be held?
&lt;br&gt;&lt;br&gt;Venue: Cyberspace
&lt;br&gt;Dates: 6th, 7th and 8th November, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;2. How will it all work?
&lt;br&gt;&lt;br&gt;a. Interested speakers will send us their talk details
&lt;br&gt;a. We will post the list of speakers and abstracts online
&lt;br&gt;b. Participants will register for talks and will receive webinar invitations
&lt;br&gt;c. Speakers will broadcast their talks using screencasting / web 
&lt;br&gt;conferencing software and invited participants will join in
&lt;br&gt;d. The participants will use IRC / Chat rooms to ask questions to the 
&lt;br&gt;speakers during the talks
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;3. Are there any requirements to become a speaker?
&lt;br&gt;&lt;br&gt;Just two:
&lt;br&gt;&lt;br&gt;1. You should know what you are talking about :)
&lt;br&gt;2. You will need to submit a video recording of your entire talk before 
&lt;br&gt;the deadline. This will ensure that participants have something to watch 
&lt;br&gt;in case there is a last minute technical issue or some other problem. &amp;nbsp;
&lt;br&gt;These videos will be made available absolutely free to everyone a week 
&lt;br&gt;after the conference.
&lt;br&gt;&lt;br&gt;&lt;br&gt;4. Awesome! I want to register as a speaker! How do I apply?
&lt;br&gt;&lt;br&gt;To Become a Speaker at SecurityTubeCon, please follow the following steps:
&lt;br&gt;&lt;br&gt;a. Send an email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25386256&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;submissions@...&lt;/a&gt; containing the 
&lt;br&gt;following information:
&lt;br&gt;&lt;br&gt;I. Talk Title
&lt;br&gt;II. Abstract: Minimum 250 words
&lt;br&gt;III. Language in which talk will be delivered in
&lt;br&gt;IV. Desired Duration: 15 mins / 30 mins / 60 mins?
&lt;br&gt;V. Speaker Names with Email addresses
&lt;br&gt;VI. Speaker Bios: As detailed as possible
&lt;br&gt;&lt;br&gt;b. Once we receive your email, we will post your talk online and send 
&lt;br&gt;you a confirmation
&lt;br&gt;c. You will need to submit the presentation, tools, other relevant 
&lt;br&gt;material and a video of the entire talk by October 20th, 2009. We will 
&lt;br&gt;send you the details on where to upload via email.
&lt;br&gt;d. If the material mentioned in (c) is not received by the deadline, 
&lt;br&gt;your talk will be removed from the website
&lt;br&gt;e. For any additional questions, please contact us at 
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25386256&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;submissions@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;5. How long can a talk be?
&lt;br&gt;&lt;br&gt;15 mins, 30 mins and 60 mins talk slots are available
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;6. What are the Deadlines?
&lt;br&gt;&lt;br&gt;1. Deadline to Submit Abstracts: October 10th, 2009
&lt;br&gt;2. Deadline to submit the full presentation and video: October 20th, 2009
&lt;br&gt;3. Conference Dates: 6th, 7th and 8th November
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;7. What kind of talks will be accepted at SecurityTubeCon?
&lt;br&gt;&lt;br&gt;Very broadly, there will be 4 tracks in SecurityTubeCon:
&lt;br&gt;&lt;br&gt;a. Research Track: Show your bleeding edge research and zero days here
&lt;br&gt;b. Tutorials Track: In-depth Tutorials on security technologies can be 
&lt;br&gt;given here by domain experts
&lt;br&gt;c. Tool Demos: Demonstration of new and cutting edge tools by their 
&lt;br&gt;original authors
&lt;br&gt;d. Security Product Demos: Demos of state of the art security products 
&lt;br&gt;by companies and organizations
&lt;br&gt;&lt;br&gt;Topics can belong to a broad spectrum, here are a couple (neither 
&lt;br&gt;exhaustive nor limited to):
&lt;br&gt;&lt;br&gt;a. Protocol / Application based vulnerability in networks and computers
&lt;br&gt;b. Firewall Evasion techniques
&lt;br&gt;c. Intrusion detection/prevention
&lt;br&gt;d. Data Recovery and Incident Response
&lt;br&gt;e. Mobile Security (cellular technologies)
&lt;br&gt;f. Virus and Worms
&lt;br&gt;g. WLAN and Bluetooth Security
&lt;br&gt;h. Analysis of malicious code
&lt;br&gt;i. Cryptography and Cryptanalysis
&lt;br&gt;j. Computer forensics
&lt;br&gt;k. Cyber Crime &amp; law
&lt;br&gt;.....
&lt;br&gt;&lt;br&gt;&lt;br&gt;8. How can I help?
&lt;br&gt;&lt;br&gt;a. Please forward this CFP link / email to your friends in the security 
&lt;br&gt;/ hacking community
&lt;br&gt;b. Send this CFP to any mailing lists related to security
&lt;br&gt;c. Post a link to the conference website on forums, discussion groups 
&lt;br&gt;you frequent
&lt;br&gt;d. Particpate either as a Speaker or as an Attendee :)
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;9. I have a question? Need more info?
&lt;br&gt;&lt;br&gt;Write to us at &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25386256&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;info@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;Hoping that all of you will attend and participate!
&lt;br&gt;&lt;br&gt;Cheers!
&lt;br&gt;&lt;br&gt;Vivek Ramachandran
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securitytube.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securitytube.net&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SecurityTubeCon-CFP%2C-Venue%3A-Cyberspace%21-tp25386256p25386256.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24187504</id>
	<title>CHASE - 2009 Lahore Pakistan | Call for Papers</title>
	<published>2009-06-24T00:16:31Z</published>
	<updated>2009-06-24T00:16:31Z</updated>
	<author>
		<name>Muhammad Farooq-i-Azam-2</name>
	</author>
	<content type="html">&lt;br&gt;-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;- ----------------------------------------------------------
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C &amp;nbsp;H &amp;nbsp;A &amp;nbsp;S &amp;nbsp;E &amp;nbsp;- &amp;nbsp;2 &amp;nbsp;0 &amp;nbsp;0 &amp;nbsp;9 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Lahore
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; November 06-10 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.chase.org.pk/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.chase.org.pk/&lt;/a&gt;&lt;br&gt;&lt;br&gt;- ----------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;Registration fee for the first day is only Rs. 700/- which
&lt;br&gt;includes lunch, teas and conference material.
&lt;br&gt;&lt;br&gt;A training tool kit of open source software comprising of
&lt;br&gt;a 500 pages book and 9 CDs would be provided FREE OF COST
&lt;br&gt;to the participants of the event.
&lt;br&gt;&lt;br&gt;Limited travel funds are available for speakers coming
&lt;br&gt;outside of Pakistan.
&lt;br&gt;&lt;br&gt;Completely FREE boarding and lodging for all the 
&lt;br&gt;international participants of the event. 
&lt;br&gt;&lt;br&gt;&lt;br&gt;- ----------------------------------------------------------
&lt;br&gt;&lt;br&gt;CHASE is a unique information and network security event 
&lt;br&gt;of its kind being organized in Pakistan since 2006. 
&lt;br&gt;&lt;br&gt;&lt;br&gt;In addition to presentations and talks, CHASE-2009 will 
&lt;br&gt;include gaming competition and four tracks of trainings. 
&lt;br&gt;&lt;br&gt;&lt;br&gt;Limited travel funds are vailable for speakers coming
&lt;br&gt;outside of Pakistan. For details, please visit the website 
&lt;br&gt;at: 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.chase.org.pk/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.chase.org.pk/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;[** CALL FOR PAPERS **] 
&lt;br&gt;&lt;br&gt;If you are a hacker or a computer and internet security 
&lt;br&gt;professional and have something to talk about, then you have 
&lt;br&gt;an opportunity to do so at CHASE 2009. Please download and 
&lt;br&gt;fill out submission form and send your presentation as early 
&lt;br&gt;as possible to: 
&lt;br&gt;&lt;br&gt;cfp AT chase DOT org DOT pk 
&lt;br&gt;&lt;br&gt;Last date for filing submissions is Friday September 04, 2009. 
&lt;br&gt;&lt;br&gt;Limited travel funds are available for international speakers.
&lt;br&gt;&lt;br&gt;All those individuals who would like to present are urged to 
&lt;br&gt;at least send their abstracts as early as possible to the 
&lt;br&gt;mail above. To see guidelines for submission, please visit 
&lt;br&gt;the following page:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.chase.org.pk/en/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.chase.org.pk/en/index.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;[** TRAININGS **]
&lt;br&gt;&lt;br&gt;This event would offer trainings in four tracks. To see 
&lt;br&gt;details of the training and to get registered, please visit
&lt;br&gt;the link below:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.chase.org.pk/en/training.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.chase.org.pk/en/training.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;There is special discount for early registration.
&lt;br&gt;&lt;br&gt;&lt;br&gt;[** Call For Participation **]
&lt;br&gt;&lt;br&gt;Those who just want to participate may please register as 
&lt;br&gt;early as possible. Just visit the website or send an email 
&lt;br&gt;to: 
&lt;br&gt;&lt;br&gt;register AT chase DOT org DOT pk.
&lt;br&gt;&lt;br&gt;Completely FREE boarding and lodging is available for 
&lt;br&gt;participants coming outside of Pakistan.
&lt;br&gt;&lt;br&gt;A FREE training kit for Open Source Software comprising of 
&lt;br&gt;a 500 pages book and 9 CDs will be provided FREE OF COST to 
&lt;br&gt;the participants of the event.
&lt;br&gt;&lt;br&gt;The event comprises of five days. First day is for talks and 
&lt;br&gt;remaining four days are trainings. You need to register 
&lt;br&gt;separately for talks and trainings. To see details and to 
&lt;br&gt;see how you can register, please visit:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://chase.org.pk/en/register.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://chase.org.pk/en/register.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Hoping to see you all at CHASE-2009 Lahore.
&lt;br&gt;&lt;br&gt;&lt;br&gt;- - --
&lt;br&gt;CHASE Team
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24187504&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;chase@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Tel: +92 300 452 4903
&lt;br&gt;&lt;br&gt;Friday June 05, 2009.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (GNU/Linux)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkopKbwACgkQaVLjC8ViUeIIeACfdlbzYotS/ebEJyUifnxEccVp
&lt;br&gt;pgYAn2DpWCFcnViU9MAqFpapnYQJf2WN
&lt;br&gt;=fOh8
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Muhammad Farooq-i-Azam
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24187504&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lists@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.chase.org.pk/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.chase.org.pk/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CHASE---2009-Lahore-Pakistan-%7C-Call-for-Papers-tp24187504p24187504.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24151096</id>
	<title>Re: Hardening CentOS</title>
	<published>2009-06-22T09:45:43Z</published>
	<updated>2009-06-22T09:45:43Z</updated>
	<author>
		<name>Tony Murphy</name>
	</author>
	<content type="html">David, 
&lt;br&gt;Thanks for the mention of Security Blanket. &amp;nbsp;I've written a quick synopsis of the product and provided a link for a free trial here.
&lt;br&gt;&lt;a id=&quot;nabblelink&quot; href=&quot;http://n2.nabble.com/Security-Blanket-by-Trusted-Computer-Systems-Linux-Solaris-Hardening-Lockdown-f3121579.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Security Blanket by Trusted Computer Systems Linux Solaris Hardening Lockdown&lt;/a&gt;&lt;br&gt;&amp;lt;script src=&amp;quot;&lt;a href=&quot;http://n2.nabble.com/embed/f3121579&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://n2.nabble.com/embed/f3121579&lt;/a&gt;&amp;quot;&amp;gt;&amp;lt;/script&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;David A. Kennel wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;A good place to start would be the Center For Internet Security Red Hat 
&lt;br&gt;Enterprise Benchmark and the NSA Secure Configuration Guide. You could 
&lt;br&gt;also check out the Security Blanket tool by Trusted Computing Solutions 
&lt;br&gt;or Bastille.
&lt;br&gt;&lt;br&gt;Link farm:
&lt;br&gt;&lt;a href=&quot;http://www.nsa.gov/snac/downloads_redhat.cfm?MenuID=scg10.3.1.1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.nsa.gov/snac/downloads_redhat.cfm?MenuID=scg10.3.1.1&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.cisecurity.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cisecurity.org/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.trustedcs.com/SecurityBlanket.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.trustedcs.com/SecurityBlanket.html&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://bastille-linux.sourceforge.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bastille-linux.sourceforge.net/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Florin Iliescu wrote:
&lt;br&gt;&amp;gt; Helo,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can anybody help me with some procedures to secure a CentOS server? I am going to use it for receiving files over Internet with SFTP.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thank you,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Florin
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;--
&lt;br&gt;David Kennel
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Hardening-CentOS-tp18262907p24151096.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23710604</id>
	<title>RE: curuncula dbr rootkit detection tool</title>
	<published>2009-05-25T09:44:32Z</published>
	<updated>2009-05-25T09:44:32Z</updated>
	<author>
		<name>Jeremi Gosney</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;you appear to be running a release candidate kernel instead of a stable
&lt;br&gt;kernel. as you can see, this source relies on the kernel headers. try
&lt;br&gt;compiling it with a stable kernel. if you are using an unstable version
&lt;br&gt;of gcc, this could attribute to this as well. it's really hard to debug
&lt;br&gt;things if you aren't running stable software.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;cheers.
&lt;br&gt;&lt;br&gt;&lt;br&gt;- -----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23710604&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23710604&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of Forums
&lt;br&gt;Sent: Friday, May 22, 2009 3:54 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23710604&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;
&lt;br&gt;Subject: Re: curuncula dbr rootkit detection tool
&lt;br&gt;&lt;br&gt;&lt;br&gt;Can't seem to compile this on my system.
&lt;br&gt;&lt;br&gt;(skimmer:~/Xploits/curuncula)% make
&lt;br&gt;make -C /lib/modules/`uname -r`/build M=`pwd` modules
&lt;br&gt;make[1]: Entering directory `/boot/src/linux-2.6.28-tuxonice-r8'
&lt;br&gt;&amp;nbsp; CC [M] &amp;nbsp;/home/circut/Xploits/curuncula/curuncula_26.o
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:42:1: warning: &amp;quot;rdmsr&amp;quot;
&lt;br&gt;redefined In file included from
&lt;br&gt;/boot/src/linux-2.6.28-tuxonice-r8/arch/x86/include/asm/processor.h:20,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/prefetch.h:14,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/list.h:6,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/module.h:9,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from /home/circut/Xploits/curuncula/curuncula_26.c:33:
&lt;br&gt;/boot/src/linux-2.6.28-tuxonice-r8/arch/x86/include/asm/msr.h:134:1:
&lt;br&gt;warning: this is the location of the previous definition
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c: Assembler messages:
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:232: Error: suffix or
&lt;br&gt;operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:235: Error: suffix or
&lt;br&gt;operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:238: Error: suffix or
&lt;br&gt;operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:241: Error: suffix or
&lt;br&gt;operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:244: Error: suffix or
&lt;br&gt;operands invalid for `mov'
&lt;br&gt;make[2]: *** [/home/circut/Xploits/curuncula/curuncula_26.o] Error 1
&lt;br&gt;make[1]: *** [_module_/home/circut/Xploits/curuncula] Error 2
&lt;br&gt;make[1]: Leaving directory `/boot/src/linux-2.6.28-tuxonice-r8'
&lt;br&gt;make: *** [curuncula_26] Error 2
&lt;br&gt;(skimmer:~/Xploits/curuncula)% uname -a
&lt;br&gt;Linux skimmer 2.6.28-tuxonice-r8 #2 SMP Mon May 4 15:54:00 CDT 2009
&lt;br&gt;x86_64 Intel(R) Core(TM)2 Duo CPU T7100 @ 1.80GHz GenuineIntel GNU/Linux
&lt;br&gt;&lt;br&gt;- -Erik
&lt;br&gt;&lt;br&gt;On Fri, 24 Apr 2009 00:13:59 +0200
&lt;br&gt;Giuseppe Cocomazzi &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23710604&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sbudella@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; I've released a little program named Curuncula.
&lt;br&gt;&amp;gt; Curuncula is a tool shipped as a loadable kernel module that aims to 
&lt;br&gt;&amp;gt; detect rootkits based on the Intel debugging support facilities.
&lt;br&gt;&amp;gt; Rootkits that set the GD access flag are also detected. It makes use 
&lt;br&gt;&amp;gt; of the &amp;quot;last branch recording&amp;quot; mechanism provided by the Intel 
&lt;br&gt;&amp;gt; architecture. Support both the 2.4 and 2.6 Linux kernels.
&lt;br&gt;&amp;gt; Complete source code can be found here:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I hope you find it useful.
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Giuseppe Cocomazzi
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; every day above ground is a good one.
&lt;/div&gt;&lt;br&gt;&lt;br&gt;- -- 
&lt;br&gt;Forums &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23710604&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;forums@...&lt;/a&gt;&amp;gt;
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (MingW32)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkoayvAACgkQIBHDN8vm6zuyxACfbQ3xaZ8AwxBtpYGOt8ksdtW3
&lt;br&gt;GzYAoIUBS8gmjrsRdoyKXtnNtX6XHXR/
&lt;br&gt;=hktL
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/curuncula-dbr-rootkit-detection-tool-tp23221284p23710604.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23709580</id>
	<title>Re: curuncula dbr rootkit detection tool</title>
	<published>2009-05-22T03:53:42Z</published>
	<updated>2009-05-22T03:53:42Z</updated>
	<author>
		<name>Erik Lat</name>
	</author>
	<content type="html">&lt;br&gt;Can't seem to compile this on my system.
&lt;br&gt;&lt;br&gt;(skimmer:~/Xploits/curuncula)% make
&lt;br&gt;make -C /lib/modules/`uname -r`/build M=`pwd` modules
&lt;br&gt;make[1]: Entering directory `/boot/src/linux-2.6.28-tuxonice-r8'
&lt;br&gt;&amp;nbsp; CC [M] &amp;nbsp;/home/circut/Xploits/curuncula/curuncula_26.o
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:42:1: warning: &amp;quot;rdmsr&amp;quot; redefined
&lt;br&gt;In file included from /boot/src/linux-2.6.28-tuxonice-r8/arch/x86/include/asm/processor.h:20,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/prefetch.h:14,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/list.h:6,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from include/linux/module.h:9,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;from /home/circut/Xploits/curuncula/curuncula_26.c:33:
&lt;br&gt;/boot/src/linux-2.6.28-tuxonice-r8/arch/x86/include/asm/msr.h:134:1: warning: this is the location of the previous definition
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c: Assembler messages:
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:232: Error: suffix or operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:235: Error: suffix or operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:238: Error: suffix or operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:241: Error: suffix or operands invalid for `mov'
&lt;br&gt;/home/circut/Xploits/curuncula/curuncula_26.c:244: Error: suffix or operands invalid for `mov'
&lt;br&gt;make[2]: *** [/home/circut/Xploits/curuncula/curuncula_26.o] Error 1
&lt;br&gt;make[1]: *** [_module_/home/circut/Xploits/curuncula] Error 2
&lt;br&gt;make[1]: Leaving directory `/boot/src/linux-2.6.28-tuxonice-r8'
&lt;br&gt;make: *** [curuncula_26] Error 2
&lt;br&gt;(skimmer:~/Xploits/curuncula)% uname -a
&lt;br&gt;Linux skimmer 2.6.28-tuxonice-r8 #2 SMP Mon May 4 15:54:00 CDT 2009 x86_64 Intel(R) Core(TM)2 Duo CPU T7100 @ 1.80GHz GenuineIntel GNU/Linux
&lt;br&gt;&lt;br&gt;-Erik
&lt;br&gt;&lt;br&gt;On Fri, 24 Apr 2009 00:13:59 +0200
&lt;br&gt;Giuseppe Cocomazzi &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23709580&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sbudella@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; I've released a little program named Curuncula.
&lt;br&gt;&amp;gt; Curuncula is a tool shipped as a loadable kernel module that aims to
&lt;br&gt;&amp;gt; detect rootkits based on the Intel debugging support facilities.
&lt;br&gt;&amp;gt; Rootkits that set the GD access flag are also detected. It makes use of
&lt;br&gt;&amp;gt; the &amp;quot;last branch recording&amp;quot; mechanism provided by the Intel
&lt;br&gt;&amp;gt; architecture. Support both the 2.4 and 2.6 Linux kernels.
&lt;br&gt;&amp;gt; Complete source code can be found here:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I hope you find it useful.
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Giuseppe Cocomazzi
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; every day above ground is a good one.
&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Forums &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23709580&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;forums@...&lt;/a&gt;&amp;gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/curuncula-dbr-rootkit-detection-tool-tp23221284p23709580.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23418075</id>
	<title>EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/5) Tokyo CFP deadline: June 1 2009</title>
	<published>2009-05-06T15:28:45Z</published>
	<updated>2009-05-06T15:28:45Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">EUSecWest 2009 Speakers
&lt;br&gt;&lt;br&gt;Efficient UAK Recovery attacks against DECT 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Ralf-Philipp Weinmann, &amp;nbsp;University of Luxembourg
&lt;br&gt;A year in the life of an Adobe Flash security researcher 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Peleus &amp;nbsp;Uhley, Adobe
&lt;br&gt;Pwning your grandmother's iPhone 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Charley Miller, Independent Security Evaluators
&lt;br&gt;Post exploitation techniques on OSX and Iphone and other TBA matters.
&lt;br&gt;&amp;nbsp; 	- Vincent Iozzo,Zynamics
&lt;br&gt;STOP!! Objective-C Run-TIME.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - nemo
&lt;br&gt;Exploiting Delphi/Pascal 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Ilja Van Sprundel, IOActive
&lt;br&gt;PCI bus based operating system attack and protections 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Christophe &amp;nbsp;Devine &amp; Guillaume Vissian, Thales
&lt;br&gt;Thoughts about Trusted Computing 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Joanna Rutkowska, Invisible Things Lab
&lt;br&gt;Nice NIC you got there... does it come with an SSH daemon? 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Arrigo Trulzi
&lt;br&gt;Evolving Microsoft Exploit Mitigations 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Tim Burrell &amp; Peter Beck, &amp;nbsp;Microsoft
&lt;br&gt;Malware Case Study: the ZeuS evolution 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Vicente Diaz, S21Sec
&lt;br&gt;Writing better XSS payloads 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Alex Kouzemtchenko, SIFT
&lt;br&gt;Exploiting Firefox Extensions 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -Roberto Suggi Liverani &amp; Nick Freeman, &amp;nbsp;Security-Assessment.com
&lt;br&gt;Stored Value Gift Cards, Magstripes Revisited 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Adrian Pastor, &amp;nbsp;Gnucitizen, Corsaire
&lt;br&gt;Advanced SQL Injection to operating system control 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Bernardo Damele Assumpcao Guimaraes, Portcullis
&lt;br&gt;Cloning Mifare Classic 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Nicolas Courtois, University of London
&lt;br&gt;Rootkits on Windows Mobile/Embedded 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Petr Matousek, Coseinc
&lt;br&gt;&lt;br&gt;&lt;br&gt;PacSec 2009 &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;World Security Pros To Converge on Japan
&lt;br&gt;&lt;br&gt;TOKYO, Japan -- To address the increasing importance of information &amp;nbsp;
&lt;br&gt;security in Japan, the best known figures in the international &amp;nbsp;
&lt;br&gt;security industry will get together with leading Japanese researchers &amp;nbsp;
&lt;br&gt;to share best practices and technology. The most significant new &amp;nbsp;
&lt;br&gt;discoveries about computer network hack attacks will be presented at &amp;nbsp;
&lt;br&gt;the seventh annual PacSec conference to be discussed.
&lt;br&gt;&lt;br&gt;The PacSec meeting provides an opportunity for foreign specialists to &amp;nbsp;
&lt;br&gt;be exposed to Japanese innovation and markets and collaborate on &amp;nbsp;
&lt;br&gt;practical solutions to computer security issues. In an informal &amp;nbsp;
&lt;br&gt;setting with a mixture of material bilingually translated in both &amp;nbsp;
&lt;br&gt;English and Japanese the eminent technologists can socialize and &amp;nbsp;
&lt;br&gt;attend training sessions.
&lt;br&gt;&lt;br&gt;Announcing the opportunity to submit papers for the PacSec 2009 &amp;nbsp;
&lt;br&gt;network security training conference. The conference will be held &amp;nbsp;
&lt;br&gt;November 4/5th in Tokyo. The conference focuses on emerging &amp;nbsp;
&lt;br&gt;information security tutorials - it is a bridge between the &amp;nbsp;
&lt;br&gt;international and Japanese information security technology communities..
&lt;br&gt;&lt;br&gt;Please make your paper proposal submissions before June 1st, 2009. &amp;nbsp;
&lt;br&gt;Slides for the papers must be submitted for translation by October 1, &amp;nbsp;
&lt;br&gt;2009 (Which, oh so rarely, happens we are going to start asking for &amp;nbsp;
&lt;br&gt;them earlier :-P --dr).
&lt;br&gt;&lt;br&gt;A some invited papers have been confirmed, but a limited number of &amp;nbsp;
&lt;br&gt;speaking slots are still available. The conference is responsible for &amp;nbsp;
&lt;br&gt;travel and accomodations for the speakers. If you have a proposal for &amp;nbsp;
&lt;br&gt;a tutorial session then please email a synopsis of the material and &amp;nbsp;
&lt;br&gt;your biography, papers and, speaking background to &amp;nbsp;. Tutorials are &amp;nbsp;
&lt;br&gt;one hour in length, but with simultaneous translation should be &amp;nbsp;
&lt;br&gt;approximately 45 minutes in English, or Japanese. Only slides will be &amp;nbsp;
&lt;br&gt;needed for the October paper deadline, full text does not have to be &amp;nbsp;
&lt;br&gt;submitted.
&lt;br&gt;&lt;br&gt;The PacSec conference consists of tutorials on technical details about &amp;nbsp;
&lt;br&gt;current issues, innovative techniques and best practices in the &amp;nbsp;
&lt;br&gt;information security realm. The audiences are a multi-national mix of &amp;nbsp;
&lt;br&gt;professionals involved on a daily basis with security work: security &amp;nbsp;
&lt;br&gt;product vendors, programmers, security officers, and network &amp;nbsp;
&lt;br&gt;administrators. We give preference to technical details and education &amp;nbsp;
&lt;br&gt;for a technical audience.
&lt;br&gt;&lt;br&gt;The conference itself is a single track series of presentations in a &amp;nbsp;
&lt;br&gt;lecture theater environment. The presentations offer speakers the &amp;nbsp;
&lt;br&gt;opportunity to showcase on-going research and collaborate with peers &amp;nbsp;
&lt;br&gt;while educating and highlighting advancements in security products and &amp;nbsp;
&lt;br&gt;techniques. The focus is on innovation, tutorials, and education &amp;nbsp;
&lt;br&gt;instead of product pitches. Some commercial content is tolerated, but &amp;nbsp;
&lt;br&gt;it needs to be backed up by a technical presenter - either giving a &amp;nbsp;
&lt;br&gt;valuable tutorial and best practices instruction or detailing &amp;nbsp;
&lt;br&gt;significant new technology in the products.
&lt;br&gt;&lt;br&gt;Paper proposals should consist of the following information:
&lt;br&gt;&lt;br&gt;1) Presenter, and geographical location (country of origin/passport) &amp;nbsp;
&lt;br&gt;and contact info (e-mail, postal address, phone, fax).
&lt;br&gt;2) Employer and/or affiliations.
&lt;br&gt;3) Brief biography, list of publications and papers.
&lt;br&gt;4) Any significant presentation and educational experience/background.
&lt;br&gt;5) Topic synopsis, Proposed paper title, and a one paragraph &amp;nbsp;
&lt;br&gt;description.
&lt;br&gt;6) Reason why this material is innovative or significant or an &amp;nbsp;
&lt;br&gt;important tutorial.
&lt;br&gt;7. Optionally, any samples of prepared material or outlines ready.
&lt;br&gt;8. Will you have full text available or only slides?
&lt;br&gt;9. Language of preference for submission.
&lt;br&gt;10. Please list any other publications or conferences where this &amp;nbsp;
&lt;br&gt;material has been or will be published/submitted.
&lt;br&gt;&lt;br&gt;Please include the plain text version of this information in your &amp;nbsp;
&lt;br&gt;email as well as any file, pdf, sxw, ppt, or html attachments.
&lt;br&gt;&lt;br&gt;Please forward the above information to &amp;nbsp;to be considered for &amp;nbsp;
&lt;br&gt;placement on the speaker roster.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. May 27/28 2009  &lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;Tokyo, Japan November 4/5 2009 &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;Vancouver, Canada March 22-26 2010 &amp;nbsp;&lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/EUSecWest-2009-%28May27-28%29-London-Agenda-and-PacSec-2009-%28Nov-4-5%29-Tokyo-CFP-deadline%3A-June-1-2009-tp23418075p23418075.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23221284</id>
	<title>curuncula dbr rootkit detection tool</title>
	<published>2009-04-23T15:13:59Z</published>
	<updated>2009-04-23T15:13:59Z</updated>
	<author>
		<name>Giuseppe Cocomazzi</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;I've released a little program named Curuncula.
&lt;br&gt;Curuncula is a tool shipped as a loadable kernel module that aims to
&lt;br&gt;detect rootkits based on the Intel debugging support facilities.
&lt;br&gt;Rootkits that set the GD access flag are also detected. It makes use of
&lt;br&gt;the &amp;quot;last branch recording&amp;quot; mechanism provided by the Intel
&lt;br&gt;architecture. Support both the 2.4 and 2.6 Linux kernels.
&lt;br&gt;Complete source code can be found here:
&lt;br&gt;&lt;a href=&quot;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://packetstormsecurity.org/UNIX/audit/curuncula.tgz&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope you find it useful.
&lt;br&gt;Regards,
&lt;br&gt;Giuseppe Cocomazzi
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;every day above ground is a good one.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/curuncula-dbr-rootkit-detection-tool-tp23221284p23221284.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22854505</id>
	<title>RE: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-04-01T17:18:36Z</published>
	<updated>2009-04-01T17:18:36Z</updated>
	<author>
		<name>Joe_Wulf</name>
	</author>
	<content type="html">Michael,
&lt;br&gt;&lt;br&gt;Lynis looks like it has a good future and potential.
&lt;br&gt;&lt;br&gt;I've noticed that several bugs have been reported against the your recently
&lt;br&gt;published edition.
&lt;br&gt;I'm curious if you've a production 'schedule' of any sort?
&lt;br&gt;Are you doing all the work on this, or do you have some assistance?
&lt;br&gt;Will you be releasing a new version with bug-corrections anytime soon?
&lt;br&gt;Would you have something like Bugzilla where bugs can be submitted and tracked
&lt;br&gt;(or considered it)?
&lt;br&gt;&lt;br&gt;I look forward to trying it out and would be willing to give feedback on what I
&lt;br&gt;find. &amp;nbsp;Other than
&lt;br&gt;the public mailing list where other bugs have been reported recently, do you have
&lt;br&gt;another method
&lt;br&gt;you prefer for bug reports?
&lt;br&gt;&lt;br&gt;Good luck with your Linux security audit tool!
&lt;br&gt;&lt;br&gt;&lt;br&gt;R,
&lt;br&gt;-Joe Wulf, CISSP, VCP, USN(RET)
&lt;br&gt;&amp;nbsp;Senior IA Engineer
&lt;br&gt;&amp;nbsp;ProSync Technology Group, LLC
&lt;br&gt;&amp;nbsp;www.prosync.com
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22854505&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22854505&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of M. Boelen
&lt;br&gt;Sent: Friday, March 27, 2009 13:55
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22854505&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;
&lt;br&gt;Subject: [tool] Unix auditing, Lynis 1.2.5
&lt;br&gt;&lt;br&gt;A new version of Lynis is available, which includes currently over 200 tests to
&lt;br&gt;assist auditors and security administrators to audit their Unix machines. The
&lt;br&gt;tool can be executed without a required installation and displays the outcome of
&lt;br&gt;the tests on the screen. Extended information can be found in the log file,
&lt;br&gt;including all the results of tests.
&lt;br&gt;&lt;br&gt;After many releases I want to ask to try this new version and give me input about
&lt;br&gt;what you like to see when checking Unix systems for their security strenghts and
&lt;br&gt;weaknesses.
&lt;br&gt;&lt;br&gt;More information and a download link can be found on the project page:
&lt;br&gt;&lt;a href=&quot;http://www.rootkit.nl/projects/lynis.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl/projects/lynis.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Michael Boelen
&lt;br&gt;--
&lt;br&gt;Original author of Rootkit Hunter and Lynis - &lt;a href=&quot;http://www.rootkit.nl&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22854505.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22838159</id>
	<title>EUSecWest 2009 CFP (May 27/28, Deadline April 7 2009)</title>
	<published>2009-04-01T14:31:57Z</published>
	<updated>2009-04-01T14:31:57Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Call For Papers
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; The EUSecWest 2009 CFP is now open.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Deadline is April 7th, 2009.
&lt;br&gt;&lt;br&gt;EUSecWest CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; LONDON, U.K. -- The third annual EUSecWest applied
&lt;br&gt;&amp;nbsp; &amp;nbsp; technical security conference - where the eminent figures
&lt;br&gt;&amp;nbsp; &amp;nbsp; in the international security industry will get together
&lt;br&gt;&amp;nbsp; &amp;nbsp; share best practices and technology - will be held in
&lt;br&gt;&amp;nbsp; &amp;nbsp; downtown London at the Sound Club in Leicester Square
&lt;br&gt;&amp;nbsp; &amp;nbsp; on May 27/28, 2009. The most significant new discoveries
&lt;br&gt;&amp;nbsp; &amp;nbsp; about computer network hack attacks and defenses,
&lt;br&gt;&amp;nbsp; &amp;nbsp; commercial security solutions, and pragmatic real world
&lt;br&gt;&amp;nbsp; &amp;nbsp; security experience will be presented in a series of
&lt;br&gt;&amp;nbsp; &amp;nbsp; informative tutorials.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; The EUSecWest meeting provides international researchers
&lt;br&gt;&amp;nbsp; &amp;nbsp; a relaxed, comfortable environment to learn from
&lt;br&gt;&amp;nbsp; &amp;nbsp; informative tutorials on key developments in security
&lt;br&gt;&amp;nbsp; &amp;nbsp; technology, and collaborate and socialize with their peers
&lt;br&gt;&amp;nbsp; &amp;nbsp; in one of the world's most most important technology
&lt;br&gt;&amp;nbsp; &amp;nbsp; hubs and scenic cities. The timing of the conference
&lt;br&gt;&amp;nbsp; &amp;nbsp; allows international travelers to travel to Berlin for
&lt;br&gt;&amp;nbsp; &amp;nbsp; FX's Ph-Neutral on the weekend, and Rennes the 
&lt;br&gt;&amp;nbsp; &amp;nbsp; following week for SSTIC.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; We would like to announce the opportunity to submit
&lt;br&gt;&amp;nbsp; &amp;nbsp; papers, and/or lightning talk proposals for selection by
&lt;br&gt;&amp;nbsp; &amp;nbsp; the EUSecWest technical review committee. This year we
&lt;br&gt;&amp;nbsp; &amp;nbsp; will be doing one hour talks, and some shorter talk
&lt;br&gt;&amp;nbsp; &amp;nbsp; sessions.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Please make your paper proposal submissions before
&lt;br&gt;&amp;nbsp; &amp;nbsp; April 7th, 2009.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Some invited papers have been confirmed, but a limited
&lt;br&gt;&amp;nbsp; &amp;nbsp; number of speaking slots are still available. The
&lt;br&gt;&amp;nbsp; &amp;nbsp; conference is responsible for travel and accommodations for
&lt;br&gt;&amp;nbsp; &amp;nbsp; the speaker (one speaker airfare and one room). If you 
&lt;br&gt;&amp;nbsp; &amp;nbsp; have a proposal for a tutorial session then please email 
&lt;br&gt;&amp;nbsp; &amp;nbsp; a synopsis of the material and your biography, papers 
&lt;br&gt;&amp;nbsp; &amp;nbsp; and, speaking background to secwest09 [at] eusecwest.com . 
&lt;br&gt;&amp;nbsp; &amp;nbsp; Only slides will be needed for the paper deadline, full text 
&lt;br&gt;&amp;nbsp; &amp;nbsp; does not have to be submitted - but will be accepted if 
&lt;br&gt;&amp;nbsp; &amp;nbsp; available. 
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; The EUSecWest 2009 conference consists of tutorials on
&lt;br&gt;&amp;nbsp; &amp;nbsp; technical details about current issues, innovative
&lt;br&gt;&amp;nbsp; &amp;nbsp; techniques and best practices in the information security
&lt;br&gt;&amp;nbsp; &amp;nbsp; realm. The audiences are a multi-national mix of
&lt;br&gt;&amp;nbsp; &amp;nbsp; professionals involved on a daily basis with security
&lt;br&gt;&amp;nbsp; &amp;nbsp; work: security product vendors, programmers, security
&lt;br&gt;&amp;nbsp; &amp;nbsp; officers, and network administrators. We give preference
&lt;br&gt;&amp;nbsp; &amp;nbsp; to technical details and new education for a technical
&lt;br&gt;&amp;nbsp; &amp;nbsp; audience.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; The conference itself is a single track series of
&lt;br&gt;&amp;nbsp; &amp;nbsp; presentations in a lecture theater environment. The
&lt;br&gt;&amp;nbsp; &amp;nbsp; presentations offer speakers the opportunity to showcase
&lt;br&gt;&amp;nbsp; &amp;nbsp; on-going research and collaborate with peers while
&lt;br&gt;&amp;nbsp; &amp;nbsp; educating and highlighting advancements in security
&lt;br&gt;&amp;nbsp; &amp;nbsp; products and techniques. The focus is on innovation,
&lt;br&gt;&amp;nbsp; &amp;nbsp; tutorials, and education instead of product pitches. Some
&lt;br&gt;&amp;nbsp; &amp;nbsp; commercial content is tolerated, but it needs to be backed
&lt;br&gt;&amp;nbsp; &amp;nbsp; up by a technical presenter - either giving a valuable
&lt;br&gt;&amp;nbsp; &amp;nbsp; tutorial and best practices instruction or detailing
&lt;br&gt;&amp;nbsp; &amp;nbsp; significant new technology in the products.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Paper proposals should consist of the following
&lt;br&gt;&amp;nbsp; &amp;nbsp; information:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;1. Presenter, and geographical location (country of
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; origin/passport) and contact info (e-mail, postal
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; address, phone, fax).
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;2. Employer and/or affiliations.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;3. Brief biography, list of publications and papers.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;4. Any significant presentation and educational
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; experience/background.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;5. Topic synopsis, Proposed paper title, and a one
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; paragraph description.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;6. Reason why this material is innovative or significant
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; or an important tutorial.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;7. Optionally, any samples of prepared material or
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; outlines ready.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;8. Will you have full text available or only slides?
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;9. Language of preference for submission.
&lt;br&gt;&amp;nbsp; &amp;nbsp; 10. Please list any other publications or conferences
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; where this material has been or will be
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; published/submitted.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Please include the plain text version of this information
&lt;br&gt;&amp;nbsp; &amp;nbsp; in your email as well as any file, pdf, sxw, ppt, or html
&lt;br&gt;&amp;nbsp; &amp;nbsp; attachments.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Please forward the above information to secwest09 [at]
&lt;br&gt;&amp;nbsp; &amp;nbsp; eusecwest.com to be considered for placement on the
&lt;br&gt;&amp;nbsp; &amp;nbsp; speaker roster, or have your lightning talk scheduled. If
&lt;br&gt;&amp;nbsp; &amp;nbsp; you contact anyone else at our organization please ensure
&lt;br&gt;&amp;nbsp; &amp;nbsp; you also cc the submission address with your proposal or
&lt;br&gt;&amp;nbsp; &amp;nbsp; it may be omitted from the review process.
&lt;br&gt;&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. May 27/28 2009  &lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/EUSecWest-2009-CFP-%28May-27-28%2C-Deadline-April-7-2009%29-tp22838159p22838159.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22788202</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-30T05:13:30Z</published>
	<updated>2009-03-30T05:13:30Z</updated>
	<author>
		<name>security-56</name>
	</author>
	<content type="html">hi,
&lt;br&gt;&lt;br&gt;very fine!!
&lt;br&gt;&lt;br&gt;here are some errors on debian (5.0) lenny:
&lt;br&gt;&lt;br&gt;- Locate database... &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[ NOT FOUND ]
&lt;br&gt;Aufruf: locate [-d path | --database=path] [-e | -E | --[non-]existing]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; [-i | --ignore-case] [-w | --wholename] [-b | --basename]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; [--limit=N | -l N] [-S | --statistics] [-0 | --null] [-c | --count]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; [-P | -H | --nofollow] [-L | --follow] [-m | --mmap ] [ -s | --stdio ]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; [-A | --all] [-p | --print] [-r | --regex ] [--regextype=TYPE]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; [--max-database-age D] [--version] [--help]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Muster...
&lt;br&gt;&lt;br&gt;locate-database was present!
&lt;br&gt;&lt;br&gt;########################################
&lt;br&gt;&lt;br&gt;- Checking Exim status... &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [ NOT FOUND ]
&lt;br&gt;&lt;br&gt;but running exim4 
&lt;br&gt;debian source-package self-compiled but std. installation path not changed:
&lt;br&gt;/usr/sbin/exim4
&lt;br&gt;/etc/exim4
&lt;br&gt;&lt;br&gt;########################################
&lt;br&gt;&lt;br&gt;[+] Scheduled tasks
&lt;br&gt;------------------------------------
&lt;br&gt;find: &amp;quot;/var/spool/crontabls&amp;quot;: Datei oder Verzeichnis nicht gefunden
&lt;br&gt;&lt;br&gt;########################################
&lt;br&gt;&lt;br&gt;&lt;br&gt;thats it!!
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;chris
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;---------- &amp;nbsp;Ursprüngliche Nachricht &amp;nbsp;----------
&lt;br&gt;&lt;br&gt;Von: &amp;nbsp; &amp;nbsp; &amp;quot;M. Boelen&amp;quot; &amp;lt;&amp;quot;M. Boelen&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788202&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt;&amp;gt;&amp;gt;
&lt;br&gt;An: &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788202&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788202&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Betreff: [tool] Unix auditing, Lynis 1.2.5
&lt;br&gt;&lt;br&gt;Am Freitag, 27. März 2009 schrieb M. Boelen:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; A new version of Lynis is available, which includes currently over 200
&lt;br&gt;&amp;gt; tests to assist auditors and security administrators to audit their Unix
&lt;br&gt;&amp;gt; machines. The tool can be executed without a required installation and
&lt;br&gt;&amp;gt; displays the outcome of the tests on the screen. Extended information
&lt;br&gt;&amp;gt; can be found in the log file, including all the results of tests.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; After many releases I want to ask to try this new version and give me
&lt;br&gt;&amp;gt; input about what you like to see when checking Unix systems for their
&lt;br&gt;&amp;gt; security strenghts and weaknesses.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; More information and a download link can be found on the project page:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.rootkit.nl/projects/lynis.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl/projects/lynis.html&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Michael Boelen
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Original author of Rootkit Hunter and Lynis - &lt;a href=&quot;http://www.rootkit.nl&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl&lt;/a&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;-------------------------------------------------------
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22788202.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22788021</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-30T01:33:56Z</published>
	<updated>2009-03-30T01:33:56Z</updated>
	<author>
		<name>Quentin Chung@Programmer</name>
	</author>
	<content type="html">from fune2fs man page: 
&lt;br&gt;-o [^]mount-option[,...] 
&lt;br&gt;Set or clear the indicated default mount options in the filesystem. Default mount options can be overridden by mount options specified either in /etc/fstab(5) or on the command line arguments to mount(8). Older kernels may not support this feature; in particular, kernels which predate 2.4.20 will almost certainly ignore the default mount options field in the superblock. 
&lt;br&gt;More than one mount option can be cleared or set by separating 
&lt;br&gt;features with commas. Mount options prefixed with a caret character ('^') will be cleared in the filesystem's superblock; mount options without a prefix character or prefixed with a plus character ('+') will be added to the filesystem. 
&lt;br&gt;The following mount options can be set or cleared using 
&lt;br&gt;tune2fs: 
&lt;br&gt;&lt;br&gt;see also &lt;a href=&quot;http://magazine.redhat.com/2007/06/07/tips-from-an-rhce-new-default-mount-options-in-red-hat-enterprise-linux-5/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://magazine.redhat.com/2007/06/07/tips-from-an-rhce-new-default-mount-options-in-red-hat-enterprise-linux-5/&lt;/a&gt;&lt;br&gt;Tips from an RHCE: New default mount options in Red Hat Enterprise Linux 5
&lt;br&gt;&lt;br&gt;Best Regards, Quentin
&lt;br&gt;BBA, CISSP #322276, MHKIM, PMHKLA, RHCE, BCCPP, BCWAA, LPIC-1
&lt;br&gt;candidate of PMP, C|EH, C|HFI, ECSA, CIA
&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: &amp;quot;Zhang Huangbin&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788021&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;zhbmaillistonly@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;quot;Quentin Chung@Programmer&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788021&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;quentin.chung@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &amp;quot;M. Boelen&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788021&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt;&amp;gt;; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22788021&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Monday, March 30, 2009 4:13 PM
&lt;br&gt;Subject: Re: [tool] Unix auditing, Lynis 1.2.5
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Quentin Chung@Programmer wrote:
&lt;br&gt;&amp;gt;&amp;gt; are you sure there has no &amp;quot;acl&amp;quot; option ?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Absolutely.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On my laptop (RHEL 5.3, x86_64):
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; # cat /etc/fstab &amp;nbsp;|grep '/ '
&lt;br&gt;&amp;gt; LABEL=/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ext3 &amp;nbsp; &amp;nbsp;defaults &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 1
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; # e2label /dev/sda3
&lt;br&gt;&amp;gt; /
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; # tune2fs -l /dev/sda3 |grep acl
&lt;br&gt;&amp;gt; Default mount options: &amp;nbsp; &amp;nbsp;user_xattr acl
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Best regards.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Zhang Huangbin
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; - Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;gt; &amp;nbsp;&lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22788021.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22787876</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-30T01:13:01Z</published>
	<updated>2009-03-30T01:13:01Z</updated>
	<author>
		<name>Zhang Huangbin</name>
	</author>
	<content type="html">Quentin Chung@Programmer wrote:
&lt;br&gt;&amp;gt; are you sure there has no &amp;quot;acl&amp;quot; option ?
&lt;br&gt;&lt;br&gt;Absolutely.
&lt;br&gt;&lt;br&gt;On my laptop (RHEL 5.3, x86_64):
&lt;br&gt;----
&lt;br&gt;# cat /etc/fstab &amp;nbsp;|grep '/ '
&lt;br&gt;LABEL=/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ext3 &amp;nbsp; &amp;nbsp;defaults &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 1
&lt;br&gt;&lt;br&gt;# e2label /dev/sda3
&lt;br&gt;/
&lt;br&gt;&lt;br&gt;# tune2fs -l /dev/sda3 |grep acl
&lt;br&gt;Default mount options: &amp;nbsp; &amp;nbsp;user_xattr acl
&lt;br&gt;----
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Best regards.
&lt;br&gt;&lt;br&gt;Zhang Huangbin
&lt;br&gt;&lt;br&gt;- Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22787876.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22787710</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-29T19:49:36Z</published>
	<updated>2009-03-29T19:49:36Z</updated>
	<author>
		<name>Quentin Chung@Programmer</name>
	</author>
	<content type="html">quoted from man mount
&lt;br&gt;&lt;br&gt;Mount options for ext2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The &amp;nbsp;'ext2' &amp;nbsp;file &amp;nbsp;system &amp;nbsp;is &amp;nbsp;the standard Linux file system. &amp;nbsp;Since Linux 2.5.46, for most mount options the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;default is determined by the filesystem superblock. Set them with tune2fs(8).
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;acl / noacl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Support POSIX Access Control Lists (or not).
&lt;br&gt;&lt;br&gt;are you sure there has no &amp;quot;acl&amp;quot; option ?
&lt;br&gt;&lt;br&gt;Best Regards, Quentin
&lt;br&gt;BBA, CISSP #322276, MHKIM, PMHKLA, RHCE, BCCPP, BCWAA, LPIC-1
&lt;br&gt;candidate of PMP, C|EH, C|HFI, ECSA, CIA
&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: &amp;quot;Zhang Huangbin&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22787710&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;zhbmaillistonly@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;quot;M. Boelen&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22787710&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22787710&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Saturday, March 28, 2009 5:49 PM
&lt;br&gt;Subject: Re: [tool] Unix auditing, Lynis 1.2.5
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; M. Boelen wrote:
&lt;br&gt;&amp;gt;&amp;gt; A new version of Lynis is available
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; filesystem ACL support detect is incorrect on CentOS/RHEL 5.x.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; It doesn't include 'acl' option in /etc/fstab, but you can check it like 
&lt;br&gt;&amp;gt; below:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; # mount | grep '/ '
&lt;br&gt;&amp;gt; /dev/hda1 on / type ext3 (rw)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; # tune2fs -l /dev/hda1 | grep -i acl
&lt;br&gt;&amp;gt; Default mount options: &amp;nbsp; &amp;nbsp;user_xattr acl
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Best regards.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Zhang Huangbin
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; - Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;gt; &amp;nbsp;&lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22787710.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22775671</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-28T03:30:41Z</published>
	<updated>2009-03-28T03:30:41Z</updated>
	<author>
		<name>Zhang Huangbin</name>
	</author>
	<content type="html">M. Boelen wrote:
&lt;br&gt;&amp;gt; A new version of Lynis is available, which includes currently over 200
&lt;br&gt;&lt;br&gt;Another error on RHEL/CentOS 5.x platform:
&lt;br&gt;&lt;br&gt;----
&lt;br&gt;&amp;nbsp; - Checking PAM modules &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[ FOUND ]
&lt;br&gt;passwd: bad argument --all: unknown option
&lt;br&gt;----
&lt;br&gt;&lt;br&gt;In passwd(1), doesn't metion '--all'.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Best regards.
&lt;br&gt;&lt;br&gt;Zhang Huangbin
&lt;br&gt;&lt;br&gt;- Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22775671.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22775412</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-28T02:49:19Z</published>
	<updated>2009-03-28T02:49:19Z</updated>
	<author>
		<name>Zhang Huangbin</name>
	</author>
	<content type="html">M. Boelen wrote:
&lt;br&gt;&amp;gt; A new version of Lynis is available
&lt;br&gt;&lt;br&gt;filesystem ACL support detect is incorrect on CentOS/RHEL 5.x.
&lt;br&gt;&lt;br&gt;It doesn't include 'acl' option in /etc/fstab, but you can check it like 
&lt;br&gt;below:
&lt;br&gt;&lt;br&gt;----
&lt;br&gt;# mount | grep '/ '
&lt;br&gt;/dev/hda1 on / type ext3 (rw)
&lt;br&gt;&lt;br&gt;# tune2fs -l /dev/hda1 | grep -i acl
&lt;br&gt;Default mount options: &amp;nbsp; &amp;nbsp;user_xattr acl
&lt;br&gt;----
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Best regards.
&lt;br&gt;&lt;br&gt;Zhang Huangbin
&lt;br&gt;&lt;br&gt;- Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22775412.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22775596</id>
	<title>Re: [tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-28T02:42:57Z</published>
	<updated>2009-03-28T02:42:57Z</updated>
	<author>
		<name>Zhang Huangbin</name>
	</author>
	<content type="html">M. Boelen wrote:
&lt;br&gt;&amp;gt; A new version of Lynis is available, which includes currently over 200
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;Great work. :)
&lt;br&gt;&lt;br&gt;But i found it doesn't include the openldap configuration directory 
&lt;br&gt;(/etc/openldap) for RHEL/CentOS.
&lt;br&gt;Patch attached:
&lt;br&gt;&lt;br&gt;--- include/tests_ldap.orig &amp;nbsp; &amp;nbsp; 2009-03-28 17:40:45.000000000 +0800
&lt;br&gt;+++ include/tests_ldap &amp;nbsp;2009-03-28 17:41:00.000000000 +0800
&lt;br&gt;@@ -22,7 +22,7 @@
&lt;br&gt;&amp;nbsp;#
&lt;br&gt;&amp;nbsp;#################################################################################
&lt;br&gt;&amp;nbsp;#
&lt;br&gt;- &amp;nbsp; &amp;nbsp;SLAPD_CONF_LOCS=&amp;quot;/usr/local/etc/openldap /etc/ldap&amp;quot;
&lt;br&gt;+ &amp;nbsp; &amp;nbsp;SLAPD_CONF_LOCS=&amp;quot;/usr/local/etc/openldap /etc/ldap /etc/openldap&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;SLAPD_CONF_LOCATION=&amp;quot;&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;SLAPD_RUNNING=0
&lt;br&gt;&amp;nbsp;#
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Best regards.
&lt;br&gt;&lt;br&gt;Zhang Huangbin
&lt;br&gt;&lt;br&gt;- Open Source Mail Server Solution for RHEL/CentOS 5.x:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://code.google.com/p/iredmail/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/iredmail/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22775596.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22754307</id>
	<title>[tool] Unix auditing, Lynis 1.2.5</title>
	<published>2009-03-27T10:55:11Z</published>
	<updated>2009-03-27T10:55:11Z</updated>
	<author>
		<name>M. Boelen</name>
	</author>
	<content type="html">&lt;br&gt;A new version of Lynis is available, which includes currently over 200
&lt;br&gt;tests to assist auditors and security administrators to audit their Unix
&lt;br&gt;machines. The tool can be executed without a required installation and
&lt;br&gt;displays the outcome of the tests on the screen. Extended information
&lt;br&gt;can be found in the log file, including all the results of tests.
&lt;br&gt;&lt;br&gt;After many releases I want to ask to try this new version and give me
&lt;br&gt;input about what you like to see when checking Unix systems for their
&lt;br&gt;security strenghts and weaknesses.
&lt;br&gt;&lt;br&gt;More information and a download link can be found on the project page:
&lt;br&gt;&lt;a href=&quot;http://www.rootkit.nl/projects/lynis.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl/projects/lynis.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Michael Boelen
&lt;br&gt;--
&lt;br&gt;Original author of Rootkit Hunter and Lynis - &lt;a href=&quot;http://www.rootkit.nl&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rootkit.nl&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-tool--Unix-auditing%2C-Lynis-1.2.5-tp22754307p22754307.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22031096</id>
	<title>CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)</title>
	<published>2009-02-15T18:50:55Z</published>
	<updated>2009-02-15T18:50:55Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Final Speaker Lineup for CanSecWest 2009 (March 18-20):
&lt;br&gt;===============================================
&lt;br&gt;&lt;br&gt;The Smart-Phones Nightmare - Sergio 'shadown' Alvarez
&lt;br&gt;&lt;br&gt;Getting into the SMRAM: SMM Reloaded - Loíc Duflot
&lt;br&gt;&lt;br&gt;Network design for effective HTTP traffic filtering - Jeff &amp;quot;rfp&amp;quot; &amp;nbsp;
&lt;br&gt;Forristal, Zscaler
&lt;br&gt;&lt;br&gt;Ninja Scanning - Fyodor, Insecure.org
&lt;br&gt;&lt;br&gt;On Approaches and Tools for Automated Vulnerability Analysis - Tanmay &amp;nbsp;
&lt;br&gt;Ganacharya &amp; Nikola Livic &amp; Abhishek Singh &amp; Swapnil Bhalode &amp; Scott &amp;nbsp;
&lt;br&gt;Lambert, Microsoft
&lt;br&gt;&lt;br&gt;Kicking It Old School: No DNS Packets Were Harmed In The Making Of &amp;nbsp;
&lt;br&gt;This Presentation - Dan Kaminski, IOActive
&lt;br&gt;&lt;br&gt;Binary Clone Wars: Software Whitelisting for Malware Prevention and &amp;nbsp;
&lt;br&gt;Coordinated Incident Response. - Shane Macaulay, Sean Comeau, and &amp;nbsp;
&lt;br&gt;Derek Callaway, Security Objectives
&lt;br&gt;&lt;br&gt;.NET Rootkits - Erez Metula
&lt;br&gt;&lt;br&gt;The Evolution of Microsoft's Exploit Mitigations - Matt Miller and Tim &amp;nbsp;
&lt;br&gt;Burrell, Microsoft
&lt;br&gt;&lt;br&gt;An overview of the state of videogame console security. - Victor Muñoz
&lt;br&gt;&lt;br&gt;A Look at a Modern Mobile Security Model: Google's Android - Jon &amp;nbsp;
&lt;br&gt;Oberheide
&lt;br&gt;&lt;br&gt;Bug classes we have found in *BSD, OS X and Solaris kernels - Christer &amp;nbsp;
&lt;br&gt;Oberg and Neil Kettle, Convergent Network Solutions
&lt;br&gt;&lt;br&gt;Multiplatform Iphone/Android Shellcode, and other smart phone &amp;nbsp;
&lt;br&gt;insecurities - Alfredo Ortega and Nico Economou, Core
&lt;br&gt;&lt;br&gt;Platform-independent static binary code analysis using a meta-assembly &amp;nbsp;
&lt;br&gt;language - Sebastian Porst &amp; Thomas &amp;quot;halvar&amp;quot; Dullien, zynamics
&lt;br&gt;&lt;br&gt;Persistent BIOS Infection - Anibal Sacco &amp; Alfredo Ortega, Core
&lt;br&gt;&lt;br&gt;Decompiling Dalvik and other JavaFX - Marc Schoenefeld
&lt;br&gt;&lt;br&gt;Automated Real-time and Post Mortem Security Crash Analysis and &amp;nbsp;
&lt;br&gt;Categorization - Jason Shirk &amp; Dave Weinstein, Microsoft
&lt;br&gt;&lt;br&gt;SSL, The Sequel: MD5 collisions and EV certificates - Alexander &amp;nbsp;
&lt;br&gt;Sotirov &amp; Mike Zusman
&lt;br&gt;&lt;br&gt;Exploiting Unicode-enabled software - Chris Weber
&lt;br&gt;&lt;br&gt;Chinese Infosec &amp; Malware Overview - Wei &amp;quot;icbm&amp;quot; Zhao, 365menshen
&lt;br&gt;&lt;br&gt;Hacking Macs for Fun and Profit - Dino Dai Zovi &amp; Charlie Miller
&lt;br&gt;&lt;br&gt;...and a variety of lightning talks...
&lt;br&gt;&lt;br&gt;&lt;br&gt;Security Masters Dojo courses (March 14-17):
&lt;br&gt;====================================
&lt;br&gt;&lt;br&gt;Metasploit: Asymmetric Warfare - H D Moore, BreakingPoint Systems
&lt;br&gt;&lt;br&gt;Advanced Honeypots - Thorsten Holz
&lt;br&gt;&lt;br&gt;IPv6 Network Security - Nico Fishbach &amp; Guillaume Valadon, COLT &amp; CNRS
&lt;br&gt;&lt;br&gt;Ultimate Web Hacking (One Day Edition) - Mike Andrews, Foundstone
&lt;br&gt;&lt;br&gt;TCP/IP Network Security In Depth - Andrea Barisani, inverse path
&lt;br&gt;&lt;br&gt;Effective Fuzzing using the Peach Fuzzing Platform - Michael &amp;nbsp;
&lt;br&gt;Eddington, Leviathan Security
&lt;br&gt;&lt;br&gt;Secure Java Programming and Auditing - Marc Schoenefeld
&lt;br&gt;&lt;br&gt;Practical 802.11 WiFi (In)Security - Cédric Blancher, EADS
&lt;br&gt;&lt;br&gt;Q/SSE Qualified/ Software Security Expert Certification Bootcamp - &amp;nbsp;
&lt;br&gt;Security University
&lt;br&gt;&lt;br&gt;Q/SA Qualified Security Analyst Penetration Tester - Security University
&lt;br&gt;&lt;br&gt;Advanced Linux Hardening - Andrea Barisani &amp; Jay Beale, inverse path &amp; &amp;nbsp;
&lt;br&gt;Intelguardians
&lt;br&gt;&lt;br&gt;Physical Security and Lock Technology - Deviant Ollam
&lt;br&gt;&lt;br&gt;The Exploit Laboratory - Advanced Edition - Saumil Shah, Net-Square
&lt;br&gt;&lt;br&gt;Mastering the Network with Scapy - Phillipe Biondi, EADS
&lt;br&gt;&lt;br&gt;&lt;br&gt;Pwn2Own Contests:
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;There will be TWO Pwn2Own contests this year.
&lt;br&gt;Generous cash prize(s) for exploits will be sponsored by Tipping Point,
&lt;br&gt;and &amp;nbsp;a Sony VAIO P fresh from Japan and a new loaded Apple Macbook
&lt;br&gt;will be amongst the prizes.
&lt;br&gt;&lt;br&gt;The targets this year will be mobile smart-phones, and browsers.
&lt;br&gt;&lt;br&gt;Mobile targets:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; iPhone
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Android
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Symbian
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RIM/BlackBerry
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Windows Mobile
&lt;br&gt;&lt;br&gt;Browser Targets:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IE8
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FF3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Safari
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Opera
&lt;br&gt;&lt;br&gt;The contest will like in previous years feature a progressively &amp;nbsp;
&lt;br&gt;expanding attack surface over the three day duration of the 
&lt;br&gt;conference. Final prizes and rules will be announced shortly.
&lt;br&gt;&lt;br&gt;Post-Conference Whistler Expedition:
&lt;br&gt;=============================
&lt;br&gt;&lt;br&gt;We have secured some rooms at good rates at the Westin in Whistler 
&lt;br&gt;and reserved a cluster of four, 3-5 bedroom, cabins for the weekend 
&lt;br&gt;after the conference. Contact &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22031096&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dr@...&lt;/a&gt; if you wish to be included 
&lt;br&gt;in the planning, final accommodation rates will be announced shortly.
&lt;br&gt;&lt;br&gt;Conference Hotel Block:
&lt;br&gt;===================
&lt;br&gt;&lt;br&gt;The room rates at the Sheraton Wall Center hotel where the conference
&lt;br&gt;is being held have been reduced from $183 to $169, and still includes
&lt;br&gt;a waived $15/day free internet access in the rate.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Tenth Anniversary Gala Event:
&lt;br&gt;========================
&lt;br&gt;&lt;br&gt;Since this is our tenth anniversary for the conference, we will 
&lt;br&gt;be having a party on Thursday night. Venue TBD. We're pretty 
&lt;br&gt;sure there will be a cake. No word yet on whether there will 
&lt;br&gt;be dancers inside it. ;-)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Day-Care Facilities will be available:
&lt;br&gt;=============================
&lt;br&gt;&lt;br&gt;As a nod to the shifting demographic of early gen. security
&lt;br&gt;researchers we will be trying a new experiment this year 
&lt;br&gt;and we will be providing day-care facilities for those 
&lt;br&gt;traveling with kids. We will try to arrange some group
&lt;br&gt;discounts with our provider once we know how many 
&lt;br&gt;kids and what ages and times will have to be 
&lt;br&gt;accommodated. If you are interested in this service
&lt;br&gt;please send a note to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22031096&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yuriko@...&lt;/a&gt; and let 
&lt;br&gt;her know ages and times.
&lt;br&gt;&lt;br&gt;We will try to get them started on exploit writing 
&lt;br&gt;courses for pre-schoolers :-). Does this mean 
&lt;br&gt;we are all grown up now?
&lt;br&gt;&lt;br&gt;&lt;br&gt;It promises to be another fun conference again this 
&lt;br&gt;year. See you all there.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Vancouver, Canada  March 16-20 2009  &lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CanSecWest-2009-Speakers-and-Dojo-courses-%28Mar-14-20%29-tp22031096p22031096.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22031256</id>
	<title>DEFCON 17 CFP now open</title>
	<published>2009-02-15T14:45:20Z</published>
	<updated>2009-02-15T14:45:20Z</updated>
	<author>
		<name>The Dark Tangent</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;xxxxxxxxxxxxxxxxxx xxx xx x xx &amp;nbsp; &amp;nbsp; DEF CON 17, Las Vegas 2009
&lt;br&gt;xxxxxxxXXXXxxxxxxxxxxxxx xx x x &amp;nbsp; &amp;nbsp;July 31st - August 2nd
&lt;br&gt;xxxxxxXXXXXXxxxxx x x x &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The Rivera Hotel and Casino
&lt;br&gt;xxxxxXXXXXXXXxxxxx xx x x &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Las Vegas, Nevada, USA
&lt;br&gt;xxxxXXXXXXXXXXxxx x xxxxxxxx x &amp;nbsp; &amp;nbsp; &lt;a href=&quot;https://www.defcon.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.defcon.org/&lt;/a&gt;&lt;br&gt;xxxXXXXXXXXXXXXxxxxxxxxxx x
&lt;br&gt;xxXXXXXXXXXXXXXXxxxxxx xx x &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxXXXXXXXXXXXXxxxxxxxx &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxxXXXXXXXXXXxxxxxxxx x x xx &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxxxXXXXXXXXxxxxxxx xxx xx x &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxxxxXXXXXXxxxxxxx x x x &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxxxxxXXXXxxxxxxxxxxx xx x x &amp;nbsp; &amp;nbsp; &amp;nbsp;Call for Papers Call for Papers
&lt;br&gt;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx x &amp;nbsp; Call for Papers Call for Papers
&lt;br&gt;&lt;br&gt;Dark monks of techno-fu, it is that time of the year again! The DEFCON CFP
&lt;br&gt;is now open!
&lt;br&gt;&lt;br&gt;What: DEFCON 17 Call For Papers
&lt;br&gt;When: The Call for Papers will close on May 15, 2009
&lt;br&gt;How: Complete the Call for Papers Form and send to talks at defcon dot org
&lt;br&gt;&lt;br&gt;Papers and presentations are now being accepted for DEFCON 17, the
&lt;br&gt;conference your mother and ISC(2) warned you about. DEFCON will take place
&lt;br&gt;at the Riviera in Las Vegas, NV, USA, July 31 - August 2, 2009.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;https://www.defcon.org/html/defcon-17/dc-17-cfp.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.defcon.org/html/defcon-17/dc-17-cfp.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: PGP Desktop 9.9.1 (Build 287)
&lt;br&gt;Charset: us-ascii
&lt;br&gt;&lt;br&gt;wsBVAwUBSZibKA6+AoIwjTCUAQK86Qf/RnSG6c8k0iy/NPrO1JDmLUr7qJzjsVwd
&lt;br&gt;yPwHUAjIR+Kp7gwi5me/DFhPu7TRPitHlV6VmZpQGrWTwRLPXimpM7fFpJQKX+Ea
&lt;br&gt;YSk1CLsktenSKo57nXPIs0MjVIFivmkVPuQzRCMwA/sORBCp1xuNITqsD9w7azAA
&lt;br&gt;CcsZXNRDZ8UnNNr2Vyr+LFXE/06ETMWyskKxEs9z3WOigqgb+zNG0ylqmS1SBhQN
&lt;br&gt;klZVdPFTmgfsDjmhvYvfjJTrOpxOwlLLjV8hqwR4CpbOgm0RWsbH42CAmJ0mJ9qt
&lt;br&gt;+JlPTVWEQEgwQIDjbkRuBPkn+CKxz+45c7aa1PPN/JxAHa/k6V5Cxw==
&lt;br&gt;=IBnB
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/DEFCON-17-CFP-now-open-tp22031256p22031256.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21701182</id>
	<title>Training &amp; jobs</title>
	<published>2009-01-27T23:34:24Z</published>
	<updated>2009-01-27T23:34:24Z</updated>
	<author>
		<name>KiranUS</name>
	</author>
	<content type="html">“Join us to make future”
&lt;br&gt;FOR OPT/F-1 STUDENTS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FREE TRAINING 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FOOD ACCOMODATION 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; H1B PROCESSING 
&lt;br&gt;FOR L1/ L2/ H1/ H4/ EAD/ GC 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EXCELLENT OPPRTUNITIES 
&lt;br&gt;&amp;nbsp;	TRAINING 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PLACEMENT 
&lt;br&gt;Highly Competitive offers for New H1b Transfers
&lt;br&gt;&lt;br&gt;About Us:
&lt;br&gt;V2 technology inc is serving NJ since 2005, for us our employees are 
&lt;br&gt;of utmost importance. Our highly skilled and dedicated instructors 
&lt;br&gt;train you explicitly in market-related technologies for today and 
&lt;br&gt;tomorrow. We will work with you in developing marketing strategies 
&lt;br&gt;and finding the assignments of your choice.
&lt;br&gt;We not only help you get a job but we build your long lasting 
&lt;br&gt;careers!!! 
&lt;br&gt;What are we Looking for:
&lt;br&gt;&amp;nbsp; &amp;nbsp;Excellent communication skills. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Valid F1/ OPT/ CPT/ H1/ H4/ L1 or valid work status &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp;(EAD, GC). 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Bachelors’ degree in CS/ IT or previous IT experience. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Preferably (not mandatory) Master's Degree in Computers/ 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Electronics or previous IT experience. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Willing to relocate anywhere in USA.
&lt;br&gt;&lt;br&gt;What’s The Deal: 
&lt;br&gt;&amp;nbsp; &amp;nbsp;H1-B sponsorship to F1/ OPT/ H4/ L1/ L2/ E3/ EAD 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Transfer of H1 &amp; L1 visas. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Green Card sponsorship through PERM 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Job focused professional training in 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Java/ J2EE 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; .NET 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Documentum 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Share point 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Oracle 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Data Modeling 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Relocation assistance- airfare, hotel accommodation, car rental 
&lt;br&gt;&amp;nbsp; &amp;nbsp;etc 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Guarantee lowest bench period. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Employee referral program. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Effective Resume writing help, Marketing and Placement. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Technical mock interviews. Preparation of In Person Interviews 
&lt;br&gt;&lt;br&gt;100% Guaranteed placement 
&lt;br&gt;Get in Touch:
&lt;br&gt;write mail at jobs@v2techinc.com
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Training---jobs-tp21701182p21701182.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21587789</id>
	<title>CfP DIMVA 2009</title>
	<published>2009-01-21T01:30:06Z</published>
	<updated>2009-01-21T01:30:06Z</updated>
	<author>
		<name>Sebastian Schmerl</name>
	</author>
	<content type="html">&amp;nbsp; (We apologize if you receive multiple copies of this message.)
&lt;br&gt;----------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FIRST
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;DIMVA 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sixth International Conference on
&lt;br&gt;&amp;nbsp; &amp;nbsp; Detection of Intrusions and Malware &amp; Vulnerability Assessment
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Organized by GI SIG SIDAR
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;In Cooperation with
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; IEEE Computer Society Task Force on Information Assurance
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Milan, Italy
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; June / July, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.dimva.org/dimva2009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dimva.org/dimva2009&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;info@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;----------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;The annual &amp;nbsp;DIMVA conference serves &amp;nbsp;as a premier forum &amp;nbsp;for advancing
&lt;br&gt;the state &amp;nbsp;of the art &amp;nbsp;in intrusion detection, malware &amp;nbsp;detection, and
&lt;br&gt;vulnerability &amp;nbsp; assessment. &amp;nbsp; &amp;nbsp;Each &amp;nbsp; year &amp;nbsp; DIMVA &amp;nbsp; brings &amp;nbsp; together
&lt;br&gt;international &amp;nbsp;experts &amp;nbsp;from &amp;nbsp;academia, &amp;nbsp;industry &amp;nbsp;and &amp;nbsp;government &amp;nbsp;to
&lt;br&gt;present and discuss novel research &amp;nbsp;in these areas. DIMVA is organized
&lt;br&gt;by &amp;nbsp;the special &amp;nbsp;interest &amp;nbsp;group Security &amp;nbsp;- &amp;nbsp;Intrusion Detection &amp;nbsp;and
&lt;br&gt;Response &amp;nbsp;(SIDAR) &amp;nbsp;of &amp;nbsp;the &amp;nbsp; German &amp;nbsp;Informatics &amp;nbsp;Society &amp;nbsp;(GI). &amp;nbsp; The
&lt;br&gt;conference &amp;nbsp;proceedings are &amp;nbsp;planned to &amp;nbsp;appear in &amp;nbsp;Springer's Lecture
&lt;br&gt;Notes in Computer Science (LNCS) series.
&lt;br&gt;&lt;br&gt;DIMVA solicits &amp;nbsp;submission of high-quality, &amp;nbsp;original scientific work.
&lt;br&gt;This year we invite two types of paper submissions:
&lt;br&gt;&lt;br&gt;* Full &amp;nbsp;papers, presenting &amp;nbsp;novel and &amp;nbsp;mature research &amp;nbsp;results. &amp;nbsp;Full
&lt;br&gt;&amp;nbsp; papers &amp;nbsp;are &amp;nbsp; limited &amp;nbsp;to &amp;nbsp;20 &amp;nbsp;pages, &amp;nbsp;prepared &amp;nbsp; according &amp;nbsp;to &amp;nbsp;the
&lt;br&gt;&amp;nbsp; instructions provided &amp;nbsp;below. They will &amp;nbsp;be reviewed by &amp;nbsp;the program
&lt;br&gt;&amp;nbsp; committee, and &amp;nbsp;papers accepted &amp;nbsp;for presentation at &amp;nbsp;the conference
&lt;br&gt;&amp;nbsp; will be included in the proceedings.
&lt;br&gt;&lt;br&gt;* Short &amp;nbsp;papers &amp;nbsp;(extended &amp;nbsp; abstracts), &amp;nbsp;presenting &amp;nbsp;original, &amp;nbsp;still
&lt;br&gt;&amp;nbsp; ongoing work &amp;nbsp;that has not yet &amp;nbsp;reached the maturity &amp;nbsp;required for a
&lt;br&gt;&amp;nbsp; full paper. Short papers are limited to 10 pages, prepared according
&lt;br&gt;&amp;nbsp; to the &amp;nbsp;instructions provided below. &amp;nbsp;They will also be &amp;nbsp;reviewed by
&lt;br&gt;&amp;nbsp; the program &amp;nbsp;committee, and papers accepted for &amp;nbsp;presentation at the
&lt;br&gt;&amp;nbsp; conference will be included &amp;nbsp;in the proceedings (containing Extended
&lt;br&gt;&amp;nbsp; Abstract in the title).
&lt;br&gt;&lt;br&gt;DIMVA's scope includes, but is not restricted to the following areas:
&lt;br&gt;&lt;br&gt;* Intrusion Detection
&lt;br&gt;&amp;nbsp; + Approaches
&lt;br&gt;&amp;nbsp; + Insider detection
&lt;br&gt;&amp;nbsp; + Applications to business level fraud
&lt;br&gt;&amp;nbsp; + Implementations
&lt;br&gt;&amp;nbsp; + Prevention and response
&lt;br&gt;&amp;nbsp; + Result correlation and cooperation
&lt;br&gt;&amp;nbsp; + Evaluation
&lt;br&gt;&amp;nbsp; + Potentials and limitations
&lt;br&gt;&amp;nbsp; + Operational experiences
&lt;br&gt;&amp;nbsp; + Legal and social aspects
&lt;br&gt;&lt;br&gt;* Malware Detection
&lt;br&gt;&amp;nbsp; + Techniques
&lt;br&gt;&amp;nbsp; + Acquisition of specimen
&lt;br&gt;&amp;nbsp; + Detection and analysis
&lt;br&gt;&amp;nbsp; + Automated behavior model generation
&lt;br&gt;&amp;nbsp; + Early warning
&lt;br&gt;&amp;nbsp; + Prevention and containment
&lt;br&gt;&amp;nbsp; + Trends and upcoming risks
&lt;br&gt;&amp;nbsp; + Forensics and recovery
&lt;br&gt;&amp;nbsp; + Economic aspects
&lt;br&gt;&lt;br&gt;* Vulnerability Assessment
&lt;br&gt;&lt;br&gt;&amp;nbsp; + Vulnerabilities
&lt;br&gt;&amp;nbsp; + Vulnerability detection and analysis
&lt;br&gt;&amp;nbsp; + Vulnerability prevention
&lt;br&gt;&amp;nbsp; + Classification and evaluation
&lt;br&gt;&amp;nbsp; + Situational awareness
&lt;br&gt;&lt;br&gt;DIMVA 2009 particularly encourages papers that discuss applications of
&lt;br&gt;intrusion &amp;nbsp;detection methods &amp;nbsp;for &amp;nbsp;fraud detection &amp;nbsp;in business &amp;nbsp;level
&lt;br&gt;processes and composite Web Services.
&lt;br&gt;&lt;br&gt;Organizing Committee
&lt;br&gt;&lt;br&gt;General Chair: Danilo M. Bruschi,
&lt;br&gt;&amp;nbsp;Università degli Studi di Milano, Italy (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;info@...&lt;/a&gt;)
&lt;br&gt;Program Chair: Ulrich Flegel,
&lt;br&gt;&amp;nbsp;SAP Research CEC Karlsruhe, Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pc-chair@...&lt;/a&gt;)
&lt;br&gt;Rump Session Chair: Sven Dietrich,
&lt;br&gt;&amp;nbsp;Stevens Institute of Technology, U.S.A. (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rump-chair@...&lt;/a&gt;)
&lt;br&gt;Sponsorship Chair: Thorsten Holz,
&lt;br&gt;&amp;nbsp;University of Mannheim, Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sponsor-chair@...&lt;/a&gt;)
&lt;br&gt;Publicity Chair: Sebastian Schmerl
&lt;br&gt;&amp;nbsp;University of Technology Cottbus, Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;publicity-chair@...&lt;/a&gt;)
&lt;br&gt;&lt;br&gt;Program Committee
&lt;br&gt;&lt;br&gt;Thomas Biege (Novell, Germany)
&lt;br&gt;Gunter Bitz (SAP AG, Germany)
&lt;br&gt;Herbert Bos (Vrije Universiteit Amsterdam, Netherlands)
&lt;br&gt;Roland Büschkes (RWE AG, Germany)
&lt;br&gt;Marc Dacier (Symantec Research, France)
&lt;br&gt;Hervé Debar (France Télécom, France)
&lt;br&gt;Sven Dietrich	(Stevens Institute of Technology, U.S.A.)
&lt;br&gt;Thomas Dullien (Zynamics, Germany)
&lt;br&gt;Thorsten Holz (University of Mannheim, Germany)
&lt;br&gt;Engin Kirda (Eurecom, France)
&lt;br&gt;Christian Kreibich (ICSI, U.S.A.)
&lt;br&gt;Christopher	Kruegel (UC Santa Barbara, U.S.A)
&lt;br&gt;Klaus Julisch (IBM Zurich Research Laboratory, Switzerland)
&lt;br&gt;Pavel Laskov (Fraunhofer FIRST and University of Tuebingen, Germany)
&lt;br&gt;Wenke Lee (Georgia Institute of Technology, U.S.A.)
&lt;br&gt;Javier Lopez (University of Malaga, Spain)
&lt;br&gt;John McHugh (University of North Carolina and Dalhousie University, Canada)
&lt;br&gt;Michael Meier (Technical University of Dortmund, Germany)
&lt;br&gt;George Mohay (Queensland University of Technology, Australia)
&lt;br&gt;Martin Rehák (Czech Technical University, Czech)
&lt;br&gt;Konrad Rieck (Technical University of Berlin, Germany)
&lt;br&gt;Robin Sommer (ICSI/LBNL, U.S.A.)
&lt;br&gt;Salvatore Stolfo (Columbia University, U.S.A)
&lt;br&gt;Peter Szor (Symantec, U.S.A.)
&lt;br&gt;&lt;br&gt;Important Dates
&lt;br&gt;&lt;br&gt;&amp;nbsp;Deadline for paper submission: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; February 6, 2009
&lt;br&gt;&amp;nbsp;Notification of acceptance or rejection: March &amp;nbsp; 30, 2009
&lt;br&gt;&amp;nbsp;Final paper camera ready copy: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; April &amp;nbsp; 10, 2009
&lt;br&gt;&amp;nbsp;Conference dates: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; June/July, 2009
&lt;br&gt;&lt;br&gt;Paper Submission
&lt;br&gt;&lt;br&gt;&amp;nbsp;All papers &amp;nbsp;must be &amp;nbsp;submitted electronically in &amp;nbsp;PDF format &amp;nbsp;via the
&lt;br&gt;&amp;nbsp;conference Web &amp;nbsp;site. Submissions must be formatted &amp;nbsp;according to the
&lt;br&gt;&amp;nbsp;instructions provided by Springer Verlag.
&lt;br&gt;&lt;br&gt;&amp;nbsp;Submitted &amp;nbsp;papers &amp;nbsp;must be &amp;nbsp;in &amp;nbsp;English &amp;nbsp;and &amp;nbsp;must not &amp;nbsp;substantially
&lt;br&gt;&amp;nbsp;overlap &amp;nbsp; work &amp;nbsp;that &amp;nbsp; has &amp;nbsp;been &amp;nbsp; published &amp;nbsp;before, &amp;nbsp; or &amp;nbsp; that &amp;nbsp;is
&lt;br&gt;&amp;nbsp;simultaneously &amp;nbsp;in &amp;nbsp;submission to &amp;nbsp;a &amp;nbsp;journal &amp;nbsp;or &amp;nbsp;a conference &amp;nbsp;with
&lt;br&gt;&amp;nbsp;proceedings. &amp;nbsp; Simultaneous &amp;nbsp;submission, &amp;nbsp;submission &amp;nbsp; of &amp;nbsp;previously
&lt;br&gt;&amp;nbsp;published work, and plagiarism &amp;nbsp;constitute dishonesty or fraud. DIMVA
&lt;br&gt;&amp;nbsp;prohibits &amp;nbsp;these practices &amp;nbsp;and may &amp;nbsp;take appropriate &amp;nbsp;action against
&lt;br&gt;&amp;nbsp;authors who have committed them.
&lt;br&gt;&lt;br&gt;&amp;nbsp;For accepted papers, it is required &amp;nbsp;that at least one of the authors
&lt;br&gt;&amp;nbsp;attends the conference to &amp;nbsp;present the paper. Presentations must also
&lt;br&gt;&amp;nbsp;be held in English.
&lt;br&gt;&lt;br&gt;&amp;nbsp;Details about the electronic submission procedure will be provided on
&lt;br&gt;&amp;nbsp;the conference Web site by end of January 2009. &amp;nbsp;Authors of &amp;nbsp;accepted
&lt;br&gt;&amp;nbsp;papers must follow the &amp;nbsp;Springer LNCS guidelines for the &amp;nbsp;preparation
&lt;br&gt;&amp;nbsp;of camera-ready copies. Details of the &amp;nbsp;process will be &amp;nbsp;provided &amp;nbsp;to
&lt;br&gt;&amp;nbsp;the authors in time.
&lt;br&gt;&lt;br&gt;Rump session
&lt;br&gt;&lt;br&gt;&amp;nbsp;As in previous &amp;nbsp;years, DIMVA 2009 will hold a &amp;nbsp;Rump Session: a series
&lt;br&gt;&amp;nbsp;of short &amp;nbsp;and entertaining talks &amp;nbsp;where attendees can &amp;nbsp;present recent
&lt;br&gt;&amp;nbsp;research results, &amp;nbsp;work in progress, &amp;nbsp;or other topics of &amp;nbsp;interest to
&lt;br&gt;&amp;nbsp;the community. &amp;nbsp;Please contact &amp;nbsp;the Rump Session Chair for submission
&lt;br&gt;&amp;nbsp;questions.
&lt;br&gt;&lt;br&gt;Sponsorship Opportunities
&lt;br&gt;&lt;br&gt;&amp;nbsp;We solicit &amp;nbsp;interested organizations to &amp;nbsp;serve as sponsors &amp;nbsp;for DIMVA
&lt;br&gt;&amp;nbsp;2009; please contact the &amp;nbsp;sponsorship chair for information regarding
&lt;br&gt;&amp;nbsp;corporate sponsorship.
&lt;br&gt;&lt;br&gt;Steering Committee
&lt;br&gt;&lt;br&gt;&amp;nbsp;Chairs:
&lt;br&gt;&amp;nbsp;* Ulrich Flegel, SAP Research CEC Karlsruhe
&lt;br&gt;&amp;nbsp;* Michael Meier, Technical University of Dortmund
&lt;br&gt;&lt;br&gt;Members:
&lt;br&gt;&amp;nbsp;* Roland Büschkes, RWE
&lt;br&gt;&amp;nbsp;* Hervé Debar, France Telecom R&amp;D
&lt;br&gt;&amp;nbsp;* Bernhard Hämmerli, Acris GmbH, HSLU
&lt;br&gt;&amp;nbsp;* Marc Heuse, Baseline Security Consulting
&lt;br&gt;&amp;nbsp;* Klaus Julisch, IBM Zurich Research Lab
&lt;br&gt;&amp;nbsp;* Christopher Kruegel, UC Santa Barbara
&lt;br&gt;&amp;nbsp;* Pavel Laskov, Fraunhofer FIRST and University of Tuebingen
&lt;br&gt;&amp;nbsp;* Robin Sommer, ICSI/LBNL
&lt;br&gt;&amp;nbsp;* Diego Zamboni, IBM Zurich Research Lab
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;_____________________________________________________________________
&lt;br&gt;Sebastian Schmerl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tel: +49 (0) 355 69 20 29
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21587789&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sbs@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fax: +49 (0) 355 69 21 27
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BTU Cottbus
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Computer Networks and Communication System
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; P.O.Box 10 13 44, 03013 Cottbus, Germany
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www-rnks.informatik.tu-cottbus.de&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www-rnks.informatik.tu-cottbus.de&lt;/a&gt;&lt;br&gt;_____________________________________________________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (9K) &lt;a href=&quot;http://old.nabble.com/attachment/21587789/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CfP-DIMVA-2009-tp21587789p21587789.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21297339</id>
	<title>CfP DIMVA 2009</title>
	<published>2009-01-05T01:21:39Z</published>
	<updated>2009-01-05T01:21:39Z</updated>
	<author>
		<name>Sebastian Schmerl</name>
	</author>
	<content type="html">&amp;nbsp; (We apologize if you receive multiple copies of this message.)
&lt;br&gt;----------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PRELIMINARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;DIMVA 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sixth International Conference on
&lt;br&gt;&amp;nbsp; &amp;nbsp; Detection of Intrusions and Malware &amp; Vulnerability Assessment
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Organized by GI SIG SIDAR
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;In Cooperation with
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; IEEE Computer Society Task Force on Information Assurance
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Milan, Italy
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; June / July, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.dimva.org/dimva2009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dimva.org/dimva2009&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mailto:info{at}dimva.org
&lt;br&gt;&lt;br&gt;----------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;The annual &amp;nbsp;DIMVA conference serves &amp;nbsp;as a premier forum &amp;nbsp;for advancing
&lt;br&gt;the state &amp;nbsp;of the art &amp;nbsp;in intrusion detection, malware &amp;nbsp;detection, and
&lt;br&gt;vulnerability &amp;nbsp; assessment. &amp;nbsp; &amp;nbsp;Each &amp;nbsp; year &amp;nbsp; DIMVA &amp;nbsp; brings &amp;nbsp; together
&lt;br&gt;international &amp;nbsp;experts &amp;nbsp;from &amp;nbsp;academia, &amp;nbsp;industry &amp;nbsp;and &amp;nbsp;government &amp;nbsp;to
&lt;br&gt;present and discuss novel research &amp;nbsp;in these areas. DIMVA is organized
&lt;br&gt;by &amp;nbsp;the special &amp;nbsp;interest &amp;nbsp;group Security &amp;nbsp;- &amp;nbsp;Intrusion Detection &amp;nbsp;and
&lt;br&gt;Response &amp;nbsp;(SIDAR) &amp;nbsp;of &amp;nbsp;the &amp;nbsp; German &amp;nbsp;Informatics &amp;nbsp;Society &amp;nbsp;(GI). &amp;nbsp; The
&lt;br&gt;conference &amp;nbsp;proceedings are &amp;nbsp;planned to &amp;nbsp;appear in &amp;nbsp;Springer's Lecture
&lt;br&gt;Notes in Computer Science (LNCS) series.
&lt;br&gt;&lt;br&gt;DIMVA solicits &amp;nbsp;submission of high-quality, &amp;nbsp;original scientific work.
&lt;br&gt;This year we invite two types of paper submissions:
&lt;br&gt;&lt;br&gt;* Full &amp;nbsp;papers, presenting &amp;nbsp;novel and &amp;nbsp;mature research &amp;nbsp;results. &amp;nbsp;Full
&lt;br&gt;&amp;nbsp; papers &amp;nbsp;are &amp;nbsp; limited &amp;nbsp;to &amp;nbsp;20 &amp;nbsp;pages, &amp;nbsp;prepared &amp;nbsp; according &amp;nbsp;to &amp;nbsp;the
&lt;br&gt;&amp;nbsp; instructions provided &amp;nbsp;below. They will &amp;nbsp;be reviewed by &amp;nbsp;the program
&lt;br&gt;&amp;nbsp; committee, and &amp;nbsp;papers accepted &amp;nbsp;for presentation at &amp;nbsp;the conference
&lt;br&gt;&amp;nbsp; will be included in the proceedings.
&lt;br&gt;&lt;br&gt;* Short &amp;nbsp;papers &amp;nbsp;(extended &amp;nbsp; abstracts), &amp;nbsp;presenting &amp;nbsp;original, &amp;nbsp;still
&lt;br&gt;&amp;nbsp; ongoing work &amp;nbsp;that has not yet &amp;nbsp;reached the maturity &amp;nbsp;required for a
&lt;br&gt;&amp;nbsp; full paper. Short papers are limited to 10 pages, prepared according
&lt;br&gt;&amp;nbsp; to the &amp;nbsp;instructions provided below. &amp;nbsp;They will also be &amp;nbsp;reviewed by
&lt;br&gt;&amp;nbsp; the program &amp;nbsp;committee, and papers accepted for &amp;nbsp;presentation at the
&lt;br&gt;&amp;nbsp; conference will be included &amp;nbsp;in the proceedings (containing Extended
&lt;br&gt;&amp;nbsp; Abstract in the title).
&lt;br&gt;&lt;br&gt;DIMVA's scope includes, but is not restricted to the following areas:
&lt;br&gt;&lt;br&gt;* Intrusion Detection
&lt;br&gt;&amp;nbsp; + Approaches
&lt;br&gt;&amp;nbsp; + Insider detection
&lt;br&gt;&amp;nbsp; + Applications to business level fraud
&lt;br&gt;&amp;nbsp; + Implementations
&lt;br&gt;&amp;nbsp; + Prevention and response
&lt;br&gt;&amp;nbsp; + Result correlation and cooperation
&lt;br&gt;&amp;nbsp; + Evaluation
&lt;br&gt;&amp;nbsp; + Potentials and limitations
&lt;br&gt;&amp;nbsp; + Operational experiences
&lt;br&gt;&amp;nbsp; + Legal and social aspects
&lt;br&gt;&lt;br&gt;* Malware Detection
&lt;br&gt;&amp;nbsp; + Techniques
&lt;br&gt;&amp;nbsp; + Acquisition of specimen
&lt;br&gt;&amp;nbsp; + Detection and analysis
&lt;br&gt;&amp;nbsp; + Automated behavior model generation
&lt;br&gt;&amp;nbsp; + Early warning
&lt;br&gt;&amp;nbsp; + Prevention and containment
&lt;br&gt;&amp;nbsp; + Trends and upcoming risks
&lt;br&gt;&amp;nbsp; + Forensics and recovery
&lt;br&gt;&amp;nbsp; + Economic aspects
&lt;br&gt;&lt;br&gt;* Vulnerability Assessment
&lt;br&gt;&lt;br&gt;&amp;nbsp; + Vulnerabilities
&lt;br&gt;&amp;nbsp; + Vulnerability detection and analysis
&lt;br&gt;&amp;nbsp; + Vulnerability prevention
&lt;br&gt;&amp;nbsp; + Classification and evaluation
&lt;br&gt;&amp;nbsp; + Situational awareness
&lt;br&gt;&lt;br&gt;DIMVA 2009 particularly encourages papers that discuss applications of
&lt;br&gt;intrusion &amp;nbsp;detection methods &amp;nbsp;for &amp;nbsp;fraud detection &amp;nbsp;in business &amp;nbsp;level
&lt;br&gt;processes and composite Web Services.
&lt;br&gt;&lt;br&gt;Organizing Committee
&lt;br&gt;&lt;br&gt;&amp;nbsp;General Chair: &amp;nbsp; &amp;nbsp; &amp;nbsp;Danilo M. Bruschi, Università degli Studi di
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Milano, Italy (info{at}dimva.org)
&lt;br&gt;&amp;nbsp;Program Chair: &amp;nbsp; &amp;nbsp; &amp;nbsp;Ulrich Flegel, SAP Research CEC Karlsruhe,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Germany (pc-chair{at}dimva.org)
&lt;br&gt;&amp;nbsp;Rump Session Chair: Sven Dietrich, Stevens Institute of Technology,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;U.S.A. (rump-chair{at}dimva.org)
&lt;br&gt;&amp;nbsp;Sponsorship Chair: &amp;nbsp;Thorsten Holz, University of Mannheim, Germany
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(sponsor-chair{at}dimva.org)
&lt;br&gt;&amp;nbsp;Publicity Chair: &amp;nbsp; &amp;nbsp;Sebastian Schmerl, Brandenburg University of
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Technology Cottbus (publicity-chair{at}dimva.org)
&lt;br&gt;&lt;br&gt;Program Committee
&lt;br&gt;&lt;br&gt;To be determined for final Call for Papers.
&lt;br&gt;&lt;br&gt;Important Dates
&lt;br&gt;&lt;br&gt;&amp;nbsp;Deadline for paper submission: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; February 6, 2009
&lt;br&gt;&amp;nbsp;Notification of acceptance or rejection: March &amp;nbsp; 30, 2009
&lt;br&gt;&amp;nbsp;Final paper camera ready copy: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; April &amp;nbsp; 10, 2009
&lt;br&gt;&amp;nbsp;Conference dates: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; June/July, 2009
&lt;br&gt;&lt;br&gt;Paper Submission
&lt;br&gt;&lt;br&gt;&amp;nbsp;All papers &amp;nbsp;must be &amp;nbsp;submitted electronically in &amp;nbsp;PDF format &amp;nbsp;via the
&lt;br&gt;&amp;nbsp;conference Web &amp;nbsp;site. Submissions must be formatted &amp;nbsp;according to the
&lt;br&gt;&amp;nbsp;instructions provided by Springer Verlag.
&lt;br&gt;&lt;br&gt;&amp;nbsp;Submitted &amp;nbsp;papers &amp;nbsp;must be &amp;nbsp;in &amp;nbsp;English &amp;nbsp;and &amp;nbsp;must not &amp;nbsp;substantially
&lt;br&gt;&amp;nbsp;overlap &amp;nbsp; work &amp;nbsp;that &amp;nbsp; has &amp;nbsp;been &amp;nbsp; published &amp;nbsp;before, &amp;nbsp; or &amp;nbsp; that &amp;nbsp;is
&lt;br&gt;&amp;nbsp;simultaneously &amp;nbsp;in &amp;nbsp;submission to &amp;nbsp;a &amp;nbsp;journal &amp;nbsp;or &amp;nbsp;a conference &amp;nbsp;with
&lt;br&gt;&amp;nbsp;proceedings. &amp;nbsp; Simultaneous &amp;nbsp;submission, &amp;nbsp;submission &amp;nbsp; of &amp;nbsp;previously
&lt;br&gt;&amp;nbsp;published work, and plagiarism &amp;nbsp;constitute dishonesty or fraud. DIMVA
&lt;br&gt;&amp;nbsp;prohibits &amp;nbsp;these practices &amp;nbsp;and may &amp;nbsp;take appropriate &amp;nbsp;action against
&lt;br&gt;&amp;nbsp;authors who have committed them.
&lt;br&gt;&lt;br&gt;&amp;nbsp;For accepted papers, it is required &amp;nbsp;that at least one of the authors
&lt;br&gt;&amp;nbsp;attends the conference to &amp;nbsp;present the paper. Presentations must also
&lt;br&gt;&amp;nbsp;be held in English.
&lt;br&gt;&lt;br&gt;&amp;nbsp;Details about the electronic submission procedure will be provided on
&lt;br&gt;&amp;nbsp;the conference Web site by &amp;nbsp;mid of January 2009. &amp;nbsp;Authors of accepted
&lt;br&gt;&amp;nbsp;papers &amp;nbsp;must follow the &amp;nbsp;Springer guidelines &amp;nbsp;for the &amp;nbsp;preparation of
&lt;br&gt;&amp;nbsp;camera-ready copies. &amp;nbsp;Details of the &amp;nbsp;process will be provided to the
&lt;br&gt;&amp;nbsp;authors in time.
&lt;br&gt;&lt;br&gt;Rump session
&lt;br&gt;&lt;br&gt;&amp;nbsp;As in previous &amp;nbsp;years, DIMVA 2009 will hold a &amp;nbsp;Rump Session: a series
&lt;br&gt;&amp;nbsp;of short &amp;nbsp;and entertaining talks &amp;nbsp;where attendees can &amp;nbsp;present recent
&lt;br&gt;&amp;nbsp;research results, &amp;nbsp;work in progress, &amp;nbsp;or other topics of &amp;nbsp;interest to
&lt;br&gt;&amp;nbsp;the community. &amp;nbsp;Please contact &amp;nbsp;the Rump Session Chair for submission
&lt;br&gt;&amp;nbsp;questions.
&lt;br&gt;&lt;br&gt;Sponsorship Opportunities
&lt;br&gt;&lt;br&gt;&amp;nbsp;We solicit &amp;nbsp;interested organizations to &amp;nbsp;serve as sponsors &amp;nbsp;for DIMVA
&lt;br&gt;&amp;nbsp;2009; please contact the &amp;nbsp;sponsorship chair for information regarding
&lt;br&gt;&amp;nbsp;corporate sponsorship.
&lt;br&gt;&lt;br&gt;Steering Committee
&lt;br&gt;&lt;br&gt;&amp;nbsp;Chairs:
&lt;br&gt;&amp;nbsp;* Ulrich Flegel, SAP Research CEC Karlsruhe
&lt;br&gt;&amp;nbsp;* Michael Meier, Technical University of Dortmund
&lt;br&gt;&lt;br&gt;&amp;nbsp;Members:
&lt;br&gt;&amp;nbsp;* Roland Büschkes, RWE
&lt;br&gt;&amp;nbsp;* Hervé Debar, France Telecom R&amp;D
&lt;br&gt;&amp;nbsp;* Bernhard Hämmerli, Acris GmbH, HSLU
&lt;br&gt;&amp;nbsp;* Marc Heuse, Baseline Security Consulting
&lt;br&gt;&amp;nbsp;* Klaus Julisch, IBM Zurich Research Lab
&lt;br&gt;&amp;nbsp;* Christopher Kruegel, UC Santa Barbara
&lt;br&gt;&amp;nbsp;* Pavel Laskov, Fraunhofer FIRST and University of Tuebingen
&lt;br&gt;&amp;nbsp;* Robin Sommer, ICSI/LBNL
&lt;br&gt;&amp;nbsp;* Diego Zamboni, IBM Zurich Research Lab
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;_____________________________________________________________________
&lt;br&gt;Sebastian Schmerl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tel: +49 (0) 355 69 20 29
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21297339&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sbs@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fax: +49 (0) 355 69 21 27
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BTU Cottbus
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Computer Networks and Communication System
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; P.O.Box 10 13 44, 03013 Cottbus, Germany
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www-rnks.informatik.tu-cottbus.de&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www-rnks.informatik.tu-cottbus.de&lt;/a&gt;&lt;br&gt;_____________________________________________________________________
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (9K) &lt;a href=&quot;http://old.nabble.com/attachment/21297339/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CfP-DIMVA-2009-tp21297339p21297339.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20686262</id>
	<title>CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008)</title>
	<published>2008-11-24T21:16:57Z</published>
	<updated>2008-11-24T21:16:57Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Call For Papers
&lt;br&gt;&lt;br&gt;    The CanSecWest 2009 CFP is now open.
&lt;br&gt;&lt;br&gt;    Deadline is December 8th, 2008.
&lt;br&gt;&lt;br&gt;CanSecWest CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;    VANCOUVER, Canada -- The tenth annual CanSecWest applied
&lt;br&gt;    technical security conference - where the eminent figures
&lt;br&gt;    in the international security industry will get together
&lt;br&gt;    share best practices and technology - will be held in
&lt;br&gt;    downtown Vancouver at the the Sheraton Wall Centre on
&lt;br&gt;    March 18-20, 2009. The most significant new discoveries
&lt;br&gt;    about computer network hack attacks and defenses,
&lt;br&gt;    commercial security solutions, and pragmatic real world
&lt;br&gt;    security experience will be presented in a series of
&lt;br&gt;    informative tutorials.
&lt;br&gt;&lt;br&gt;    The CanSecWest meeting provides international researchers
&lt;br&gt;    a relaxed, comfortable environment to learn from
&lt;br&gt;    informative tutorials on key developments in security
&lt;br&gt;    technology, and collaborate and socialize with their peers
&lt;br&gt;    in one of the world's most scenic cities - a short drive
&lt;br&gt;    away from one of North America's top skiing areas.
&lt;br&gt;&lt;br&gt;    The CanSecWest conference will also feature the
&lt;br&gt;    availability of the Security Masters Dojo expert network
&lt;br&gt;    security sensei instructors, and their advanced, and
&lt;br&gt;    intermediate, hands-on training courses - featuring small
&lt;br&gt;    class sizes and practical application excercises to
&lt;br&gt;    maximize information transfer.
&lt;br&gt;&lt;br&gt;    We would like to announce the opportunity to submit
&lt;br&gt;    papers, and/or lightning talk proposals for selection by
&lt;br&gt;    the CanSecWest technical review committee. This year we
&lt;br&gt;    will be doing one hour talks, and some shorter talk
&lt;br&gt;    sessions.
&lt;br&gt;&lt;br&gt;    Please make your paper proposal submissions before
&lt;br&gt;    December 8th, 2008.
&lt;br&gt;&lt;br&gt;    Some invited papers have been confirmed, but a limited
&lt;br&gt;    number of speaking slots are still available. The
&lt;br&gt;    conference is responsible for travel and accomodations for
&lt;br&gt;    the speakers. If you have a proposal for a tutorial
&lt;br&gt;    session then please email a synopsis of the material and
&lt;br&gt;    your biography, papers and, speaking background to
&lt;br&gt;    secwest09 [at] cansecwest.com . Only slides will be needed
&lt;br&gt;    for the March paper deadline, full text does not have to
&lt;br&gt;    be submitted - but will be accepted if available. This
&lt;br&gt;    year we will be opening up the presentation guidelines to
&lt;br&gt;    include talks not in English (particularly Chinese) which
&lt;br&gt;    we will offer to translate for the speaker if they are not
&lt;br&gt;    a native English speaker.
&lt;br&gt;&lt;br&gt;    The CanSecWest 2009 conference consists of tutorials on
&lt;br&gt;    technical details about current issues, innovative
&lt;br&gt;    techniques and best practices in the information security
&lt;br&gt;    realm. The audiences are a multi-national mix of
&lt;br&gt;    professionals involved on a daily basis with security
&lt;br&gt;    work: security product vendors, programmers, security
&lt;br&gt;    officers, and network administrators. We give preference
&lt;br&gt;    to technical details and new education for a technical
&lt;br&gt;    audience.
&lt;br&gt;&lt;br&gt;    The conference itself is a single track series of
&lt;br&gt;    presentations in a lecture theater environment. The
&lt;br&gt;    presentations offer speakers the opportunity to showcase
&lt;br&gt;    on-going research and collaborate with peers while
&lt;br&gt;    educating and highlighting advancements in security
&lt;br&gt;    products and techniques. The focus is on innovation,
&lt;br&gt;    tutorials, and education instead of product pitches. Some
&lt;br&gt;    commercial content is tolerated, but it needs to be backed
&lt;br&gt;    up by a technical presenter - either giving a valuable
&lt;br&gt;    tutorial and best practices instruction or detailing
&lt;br&gt;    significant new technology in the products.
&lt;br&gt;&lt;br&gt;    Paper proposals should consist of the following
&lt;br&gt;    information:
&lt;br&gt;     1. Presenter, and geographical location (country of
&lt;br&gt;        origin/passport) and contact info (e-mail, postal
&lt;br&gt;        address, phone, fax).
&lt;br&gt;     2. Employer and/or affiliations.
&lt;br&gt;     3. Brief biography, list of publications and papers.
&lt;br&gt;     4. Any significant presentation and educational
&lt;br&gt;        experience/background.
&lt;br&gt;     5. Topic synopsis, Proposed paper title, and a one
&lt;br&gt;        paragraph description.
&lt;br&gt;     6. Reason why this material is innovative or significant
&lt;br&gt;        or an important tutorial.
&lt;br&gt;     7. Optionally, any samples of prepared material or
&lt;br&gt;        outlines ready.
&lt;br&gt;     8. Will you have full text available or only slides?
&lt;br&gt;     9. Language of preference for submission.
&lt;br&gt;    10. Please list any other publications or conferences
&lt;br&gt;        where this material has been or will be
&lt;br&gt;        published/submitted.
&lt;br&gt;&lt;br&gt;    Please include the plain text version of this information
&lt;br&gt;    in your email as well as any file, pdf, sxw, ppt, or html
&lt;br&gt;    attachments.
&lt;br&gt;&lt;br&gt;    Please forward the above information to secwest09 [at]
&lt;br&gt;    cansecwest.com to be considered for placement on the
&lt;br&gt;    speaker roster, or have your lightning talk scheduled. If
&lt;br&gt;    you contact anyone else at our organization please ensure
&lt;br&gt;    you also cc the submission address with your proposal or
&lt;br&gt;    it may be ommitted from the review process.
&lt;br&gt;&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Vancouver, Canada  March 16-20 2009  &lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CanSecWest-2009-CFP-%28March-18-20-2009%2C-Deadline-December-8-2008%29-tp20686262p20686262.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20075413</id>
	<title>ANNOUNCE: New iptables(8) firewall script release, many new features</title>
	<published>2008-10-19T07:33:42Z</published>
	<updated>2008-10-19T07:33:42Z</updated>
	<author>
		<name>TJ Easter</name>
	</author>
	<content type="html">Note to Mods: &amp;nbsp;If this is considered SPAM, please drop it in the
&lt;br&gt;bit-bucket. &amp;nbsp;This appeared to me to be acceptable according to the FAQ
&lt;br&gt;for the list.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Hello all!
&lt;br&gt;&lt;br&gt;A week or so ago I added several new features to my firewall script
&lt;br&gt;that I had been considering. &amp;nbsp;This brings me to release 1.8.2.
&lt;br&gt;The script is for Linux-systems only, using the netfilter/iptables
&lt;br&gt;tools to create a secure firewall for almost any situation. &amp;nbsp;This
&lt;br&gt;newest release
&lt;br&gt;brings many new levels of flexibility and customization. &amp;nbsp;The initial
&lt;br&gt;purpose of this firewall script was to be able to create a secure
&lt;br&gt;ruleset from the very beginning; and then allowing easy addition of
&lt;br&gt;rules to manage services in an obvious way. &amp;nbsp;I believe that by
&lt;br&gt;naming a file something like /etc/firewall/tcp.ssh, and adding one
&lt;br&gt;subnet/host per line, I make it fairly straight-forward to build a
&lt;br&gt;secure
&lt;br&gt;ruleset, even with minimal experience.
&lt;br&gt;&lt;br&gt;A quick rundown on features are as follows:
&lt;br&gt;- All services configurable via flat text files, such as tcp.ssh, one
&lt;br&gt;subnet/host per line
&lt;br&gt;- Ability to add &amp;quot;deny&amp;quot; entries from service files by prefixing
&lt;br&gt;subnet/host with a !
&lt;br&gt;- Ability to let non-root users to manage rules, setup information is
&lt;br&gt;in the README
&lt;br&gt;- Stateful firewall, allows outbound-connection-related packets (ICMP
&lt;br&gt;host-unreach, time-exceeded, TCP RST, etc) back in automatically
&lt;br&gt;- A secure, &amp;quot;deny all except what's explicitly allowed&amp;quot; default configuration
&lt;br&gt;- Ability to allow/deny any packets from a subnet/host (use of this is
&lt;br&gt;discouraged)
&lt;br&gt;- Simple masquerading configuration by adding subnet/hosts to &amp;quot;masquerade&amp;quot; file
&lt;br&gt;- Ability to set up TCP and UDP port-forwarding, details in the README
&lt;br&gt;- Configuration variables such as $FWCONF, where the service files are
&lt;br&gt;located, can be set in /etc/sysconfig/network
&lt;br&gt;- A &amp;quot;status&amp;quot; and &amp;quot;running&amp;quot; parameter that shows the firewall status
&lt;br&gt;and running ruleset, respectively
&lt;br&gt;- Rate-limits control the amount of outbound replies to minimize
&lt;br&gt;damage in a DoS or reflective DoS
&lt;br&gt;- Rate-limits control the number of entries that get logged per second
&lt;br&gt;to mitigate overloading the syslog system
&lt;br&gt;- All files/scripts are distro-agnostic
&lt;br&gt;- Use of $FWCONF/rc.local.{nat,rules} to allow advanced users the
&lt;br&gt;ability to write their own rules,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;or manipulate the automatically generated rules.
&lt;br&gt;&lt;br&gt;For complete details, see the README file available at:
&lt;br&gt;&lt;a href=&quot;http://tje.ssllink.net/firewall/README&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tje.ssllink.net/firewall/README&lt;/a&gt;&lt;br&gt;&lt;br&gt;Release 1.8.2 can be found here:
&lt;br&gt;&lt;a href=&quot;http://tje.ssllink.net/firewall-1.8.2.tar.gz&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tje.ssllink.net/firewall-1.8.2.tar.gz&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;66d04d274cfb06a6b7968a1c10d3d3ff
&lt;br&gt;&lt;br&gt;As always, I welcome all comments, questions, complaints, flames, cash
&lt;br&gt;donations, etc. &amp;nbsp;Please CC me on
&lt;br&gt;all replies as I have not been on the focus-linux list for some time
&lt;br&gt;now. &amp;nbsp;Thanks!
&lt;br&gt;&lt;br&gt;-tje-
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;TJ Easter
&lt;br&gt;-- 
&lt;br&gt;&amp;quot;Being a humanist means trying to behave decently without expectation
&lt;br&gt;of rewards or punishment after you are dead.&amp;quot; &amp;nbsp;-- Kurt Vonnegut, 1922
&lt;br&gt;- 2007
&lt;br&gt;&lt;a href=&quot;http://keyserver1.pgp.com/vkd/DownloadKey.event?keyid=0x5EB6E92FE2340DEF&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://keyserver1.pgp.com/vkd/DownloadKey.event?keyid=0x5EB6E92FE2340DEF&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/ANNOUNCE%3A-New-iptables%288%29-firewall-script-release%2C-many-new-features-tp20075413p20075413.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19383812</id>
	<title>Re: Pandora FMS 1.2 released</title>
	<published>2008-09-08T17:26:35Z</published>
	<updated>2008-09-08T17:26:35Z</updated>
	<author>
		<name>villa_rep</name>
	</author>
	<content type="html">Pandora FMS (Flexible Monitoring System) is a monitoring application to watch systems, applications or process, that allows to know the status of any element of your systems, watch for your hardware, your software, your multilayer system and of course your Operating System.
&lt;br&gt;&lt;br&gt;Development of stable version 2.0 of Pandora FMS is over. After a long period of testing, Pandora FMS team has finished development for this version that introduces great features from previous version.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Some changes from last version are.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * WMI Remote Monitoring Server (Windows) and Plugin Server (UNIX).
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Prediction Server.
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Export Server.
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Network Map.
&lt;br&gt;&amp;nbsp; &amp;nbsp; * New Visual Console in AJAX for interactive map creation.
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Agent remote configuration from the Console.
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Coumpound alerts.
&lt;br&gt;&lt;br&gt;You can download Pandora FMS v2.0 or migrate tool from &lt;a href=&quot;http://www.pandorafms.com/index.php?sec=pandora&amp;sec2=download&amp;lang=en&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.pandorafms.com/index.php?sec=pandora&amp;sec2=download&amp;lang=en&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;pandorainfo wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Pandora FMS (Free Monitoring
&lt;br&gt;System) is a monitoring application to watch systems and applications, that allows to know the status of any element of your systems, watch for your hardware, your software, your multilayer system and of course your Operating System.
&lt;br&gt;&lt;br&gt;Development of stable version 1.2 of Pandora FMS is over. After a
&lt;br&gt;long period of testing, Pandora FMS team has finished development for
&lt;br&gt;this version that introduces great features from previous version.
&lt;br&gt;&lt;br&gt;Pandora FMS is a Free Software project. Pandora FMS monitor systems,
&lt;br&gt;network elements and applications in any operating systems. It's
&lt;br&gt;published under GPL license.
&lt;br&gt;&lt;br&gt;Some changes from last version are.
&lt;br&gt;&lt;br&gt;-Network monitoring without need to install agents.
&lt;br&gt;-SNMP console to receive traps
&lt;br&gt;-Better alerts.
&lt;br&gt;-Better user visualization
&lt;br&gt;-Internal messages between teams and operators.
&lt;br&gt;-Better usability.
&lt;br&gt;-Pandora FMS also includes a new Windows Agent, with graphical
&lt;br&gt;installer, that allows to monitor easily Windows hosts.
&lt;br&gt;-Individual module interval for each module.
&lt;br&gt;-On-demand agent polling (for network modules).
&lt;br&gt;-Other minor features.
&lt;br&gt;&lt;br&gt;You can download Pandora FMS v1.2 from &lt;a href=&quot;http://pandora.sourceforge.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pandora.sourceforge.net&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pandora-FMS-1.2-released-tp7824584p19383812.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19169558</id>
	<title>PacSec 2008 CFP  (Deadline Sept. 1, Conference Nov. 12/13) and BA-Con 2008 Speakers (Sept. 30/  Oct. 1)</title>
	<published>2008-08-26T13:09:28Z</published>
	<updated>2008-08-26T13:09:28Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Spanish url: &lt;a href=&quot;http://ba-con.com.ar/speakers.html?language=es&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ba-con.com.ar/speakers.html?language=es&lt;/a&gt;&lt;br&gt;&lt;br&gt;Speaker list and Dojos for BA-Con, September 30, October 1st.
&lt;br&gt;(all presentations in both Spanish and English)
&lt;br&gt;&lt;br&gt;  Presentations:
&lt;br&gt;&lt;br&gt;  WPA/WPA2: how long is it gonna make it - Cédric Blancher &amp; Simon Maréchal, 
&lt;br&gt;EADS &amp; SGDN
&lt;br&gt;  Security Concerns of Firmware Updates (SPI System BIOS and Embedded  
&lt;br&gt;Controller) - Sun Bing
&lt;br&gt;  A Practical Approach to Mitigate and Remove Malware - Ching Tim Meng
&lt;br&gt;  Advances in Attacking Interpreted Languages: Javascript - Justin  
&lt;br&gt;Ferguson
&lt;br&gt;  Understanding eVoting in post Everest, TTBR world - Harri Hursti
&lt;br&gt;  SecViz 007 - Raffael Marty, Splunk
&lt;br&gt;  Pass-the-hash Toolkit for Windows - Hernan Ochoa, Core
&lt;br&gt;  Linux 2.6 kernel rootkits - Daniel Palacio, Immunity
&lt;br&gt;  Reverse Engineering Dynamic Languages, a Focus on Python - Aaron  
&lt;br&gt;Portnoy &amp; Ali Rizvi-Santiago, TippingPoint
&lt;br&gt;  All the Crap Aircrafts Receive and Send - Hendrik Scholz
&lt;br&gt;  Teflon: anti-stick for the browsers attack surface - Saumil Shah,  
&lt;br&gt;Net-Square
&lt;br&gt;  Hacking PXE without reboot (using the BIOS network stack for other 
&lt;br&gt;purposes) - Julien Vanegue, CESAR
&lt;br&gt;  LeakedOut: the Social Networks You Get Caught In - Jose Orlicki, Core
&lt;br&gt;&lt;br&gt;Dojos (September 28/29):
&lt;br&gt;  Reverse Code Engineering - Edgar Barbosa, COSEINC
&lt;br&gt;  Practical 802.11 Wi-Fi (In)Security - Cédric Blancher, EADS
&lt;br&gt;  Effective Fuzzing using the Peach Fuzzing Platform (2 days) -  Michael 
&lt;br&gt;Eddington, Leviathan
&lt;br&gt;  Assembler for Exploits - Gerardo Richarte, Core
&lt;br&gt;  The Exploit Lab - Saumil Shah, Net-Square
&lt;br&gt;&lt;br&gt;We would like to especially thank the gracious sponsorship of Core, 
&lt;br&gt;Microsoft, and Symantec/SecurityFocus, without whom this event 
&lt;br&gt;would not be possible and/or would be a lot more expensive for attendees.
&lt;br&gt;We also suggest that conference attendees stay a couple of days
&lt;br&gt;longer and go to ekoparty right after this event.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;--8&amp;lt;--kyx--8&amp;lt;--
&lt;br&gt;&lt;br&gt;English url: &lt;a href=&quot;http://pacsec.jp/speakers.html?language=en&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp/speakers.html?language=en&lt;/a&gt;&lt;br&gt;Japanese url: &lt;a href=&quot;http://pacsec.jp/speakers.html?language=ja&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp/speakers.html?language=ja&lt;/a&gt;&lt;br&gt;(the following should be up soon...)
&lt;br&gt;Spanish url: &lt;a href=&quot;http://pacsec.jp/speakers.html?language=es&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp/speakers.html?language=es&lt;/a&gt;&lt;br&gt;Chinese url: &lt;a href=&quot;http://pacsec.jp/speakers.html?language=cn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp/speakers.html?language=cn&lt;/a&gt;&lt;br&gt;&lt;br&gt;PacSec 2008 CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;World Security Pros To Converge on Japan
&lt;br&gt;&lt;br&gt;    TOKYO, Japan -- To address the increasing importance of information
&lt;br&gt;    security in Japan, the best known figures in the international
&lt;br&gt;    security industry will get together with leading Japanese
&lt;br&gt;    researchers to share best practices and technology. The most 
&lt;br&gt;    significant new discoveries about computer network hack attacks 
&lt;br&gt;    and defenses will be presented at the sixth annual PacSec conference.
&lt;br&gt;&lt;br&gt;    The PacSec meeting provides an opportunity for foreign specialists  
&lt;br&gt;    to be exposed to Japanese innovation and markets and collaborate 
&lt;br&gt;    on practical solutions to computer security issues. In an informal
&lt;br&gt;    setting with a mixture of material bilingually translated in both
&lt;br&gt;    English and Japanese the eminent technologists can socialize and
&lt;br&gt;    attend training sessions.
&lt;br&gt;&lt;br&gt;    Announcing the opportunity to submit papers for the PacSec 2008
&lt;br&gt;    network security training conference. The conference will be held
&lt;br&gt;    November 12/13th in Tokyo at the Aoyama Diamond Hall above
&lt;br&gt;    Omotesando station. The conference focuses on emerging
&lt;br&gt;    information security tutorials - it is a bridge between the
&lt;br&gt;    international and Japanese information security technology
&lt;br&gt;    communities..
&lt;br&gt;&lt;br&gt;    Please make your paper proposal submissions before September 1st,
&lt;br&gt;    2008. Slides for the papers must be submitted for translation by
&lt;br&gt;    October 1, 2008.
&lt;br&gt;&lt;br&gt;    A some invited papers have been confirmed, but a limited number of
&lt;br&gt;    speaking slots are still available. The conference is responsible
&lt;br&gt;    for travel and accomodations for the speakers. If you have a 
&lt;br&gt;    proposal for a tutorial session then please email a synopsis of 
&lt;br&gt;    the material and your biography, papers and, speaking background 
&lt;br&gt;    to secwest08 [at] pacsec.jp . Tutorials are one hour in length, but 
&lt;br&gt;    with simultaneous translation should be approximately 45 minutes 
&lt;br&gt;    in English, or Japanese. Only slides will be needed for the October 
&lt;br&gt;    paper deadline, full text does not have to be submitted.
&lt;br&gt;&lt;br&gt;    The PacSec conference consists of tutorials on technical details
&lt;br&gt;    about current issues, innovative techniques and best practices in the
&lt;br&gt;    information security realm. The audiences are a multi-national mix
&lt;br&gt;    of professionals involved on a daily basis with security work: security
&lt;br&gt;    product vendors, programmers, security officers, and network
&lt;br&gt;    administrators. We give preference to technical details and
&lt;br&gt;    education for a technical audience.
&lt;br&gt;&lt;br&gt;    The conference itself is a single track series of presentations in a
&lt;br&gt;    lecture theater environment. The presentations offer speakers the
&lt;br&gt;    opportunity to showcase on-going research and collaborate with peers
&lt;br&gt;    while educating and highlighting advancements in security products
&lt;br&gt;    and techniques. The focus is on innovation, tutorials, and education
&lt;br&gt;    instead of product pitches. Some commercial content is tolerated,
&lt;br&gt;    but it needs to be backed up by a technical presenter - either giving 
&lt;br&gt;    a valuable tutorial and best practices instruction or detailing
&lt;br&gt;    significant new technology in the products.
&lt;br&gt;&lt;br&gt;    Paper proposals should consist of the following information:
&lt;br&gt;     1. Presenter, and geographical location (country of
&lt;br&gt;        origin/passport) and contact info (e-mail, postal address,
&lt;br&gt;        phone, fax).
&lt;br&gt;     2. Employer and/or affiliations.
&lt;br&gt;     3. Brief biography, list of publications and papers.
&lt;br&gt;     4. Any significant presentation and educational
&lt;br&gt;        experience/background.
&lt;br&gt;     5. Topic synopsis, Proposed paper title, and a one paragraph
&lt;br&gt;        description.
&lt;br&gt;     6. Reason why this material is innovative or significant or an
&lt;br&gt;        important tutorial.
&lt;br&gt;     7. Optionally, any samples of prepared material or outlines
&lt;br&gt;        ready.
&lt;br&gt;     8. Will you have full text available or only slides?
&lt;br&gt;     9. Please list any other publications or conferences where
&lt;br&gt;        this material has been or will be published/submitted.
&lt;br&gt;     10. Do you have any special demo or network requirements
&lt;br&gt;        for your presentation?
&lt;br&gt;&lt;br&gt;    Please include the plain text version of this information in
&lt;br&gt;    your email as well as any file, pdf, sxw, ppt, or html
&lt;br&gt;    attachments.
&lt;br&gt;&lt;br&gt;    Please forward the above information to secwest08 [at]
&lt;br&gt;    pacsec.jp to be considered for placement on the speaker
&lt;br&gt;    roster, or have your lightning talk scheduled. The deadline
&lt;br&gt;    is soon for this one: September 1st 2008.
&lt;br&gt;&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;P.S. We have also set the dates for CanSecWest 2010 for Mar. 22-26.
&lt;br&gt;With the Olympics in the neighborhood a month before we have to
&lt;br&gt;plan way ahead.
&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Buenos Aires, Argentina   Sept. 30 / Oct. 1 - 2008    &lt;a href=&quot;http://ba-con.com.ar&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ba-con.com.ar&lt;/a&gt;&lt;br&gt;Tokyo, Japan  November 12/13 2008  &lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;Vancouver, Canada  March 16-20 2009  &lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PacSec-2008-CFP--%28Deadline-Sept.-1%2C-Conference-Nov.-12-13%29-and-BA-Con-2008-Speakers-%28Sept.-30---Oct.-1%29-tp19169558p19169558.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18966757</id>
	<title>Re: problems cloning a hard drive with dcfldd</title>
	<published>2008-08-13T01:25:32Z</published>
	<updated>2008-08-13T01:25:32Z</updated>
	<author>
		<name>Kosala Atapattu-2</name>
	</author>
	<content type="html">Hi Don,
&lt;br&gt;&lt;br&gt;I think it's bit too late for this reply. But you can find whether DD
&lt;br&gt;is failing or DD is failing due to NC failure if you look at the
&lt;br&gt;PIPESTATUS envar from bash.
&lt;br&gt;&lt;br&gt;Kosala
&lt;br&gt;&lt;br&gt;On Wed, Aug 6, 2008 at 11:14 PM, &amp;nbsp;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18966757&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DON.RAIKES@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am a newbie to this whole digital forensics world, and am having a problem cloning a hard drive.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Setup:
&lt;br&gt;&amp;gt; laptop with 40gb harddrive with 2 partitions. The laptop had/has windows xp on it, but it won't boot any longer.
&lt;br&gt;&amp;gt; desktop system running fedora 9 as my forensics lab machine.
&lt;br&gt;&amp;gt; fedora livecd containing dcfldd and some other &amp;nbsp;tools.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Situation:
&lt;br&gt;&amp;gt; I boot the laptop using the livecd and login no problem.
&lt;br&gt;&amp;gt; I can see the hard drive as /dev/sda.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Both systems are connected to my local network.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I want to make a clone of the laptop harddrive so that I can use it to learn some of the forensic tools available like sleuthkit mac-robber etc.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Steps:
&lt;br&gt;&amp;gt; on desktop: start netcat in listening mode port 1234
&lt;br&gt;&amp;gt; on laptop run:
&lt;br&gt;&amp;gt; dcfldd if=/dev/sda1 conv=noerror,sync hash=md5 hashlog=md5.log | nc desktopsystem 1234 -w 3
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; All seems to be going just fine the netcat connection is made and dcfldd is displaying its progress.
&lt;br&gt;&amp;gt; However, at block 98513, I get an error from dcfldd saying:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; error:/dev/sda1 input output error
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; and the whole process stops.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I tried:
&lt;br&gt;&amp;gt; $ dcfldd if=/dev/sda1 of=/dev/null conv=noerror,sync
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; and it processed the entire 34gb without an error.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any suggestions would be appreciated for how to get this drive cloned.
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Kosala
&lt;br&gt;--------------------------------------------
&lt;br&gt;Disclaimer: Views expressed in this mail are my personal views and
&lt;br&gt;they would not reflect views of the employer.
&lt;br&gt;--------------------------------------------
&lt;br&gt;blog.kosala.net
&lt;br&gt;www.linux.lk/~kosala/
&lt;br&gt;www.kosala.net
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/root-shell-auditing-tp18706731p18966757.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18947180</id>
	<title>RE: problems cloning a hard drive with dcfldd</title>
	<published>2008-08-11T14:47:12Z</published>
	<updated>2008-08-11T14:47:12Z</updated>
	<author>
		<name>fd lists</name>
	</author>
	<content type="html">Don,
&lt;br&gt;&lt;br&gt;I think you've found the issue - you were acquiring the first partition,
&lt;br&gt;and _not_ the physical device. &amp;nbsp;Remove the partition from your command
&lt;br&gt;and you should be golden, no need to pull the drive. &amp;nbsp;
&lt;br&gt;&lt;br&gt;Cheers!
&lt;br&gt;&lt;br&gt;farmerdude
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.forensicbootcd.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.forensicbootcd.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.onlineforensictraining.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.onlineforensictraining.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On Mon, 2008-08-11 at 12:11 -0700, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18947180&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DON.RAIKES@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Farmerdude,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Here are the results of the commands you suggested:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; blkid:
&lt;br&gt;&amp;gt; /dev/sda1: UUID=&amp;quot;D08405CF8405B94C&amp;quot; TYPE=&amp;quot;ntfs&amp;quot; 
&lt;br&gt;&amp;gt; /dev/sda2: UUID=&amp;quot;423B-2BDF&amp;quot; TYPE=&amp;quot;vfat&amp;quot; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; fdisk:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Disk /dev/sda: 40.0 GB, 40007761920 bytes
&lt;br&gt;&amp;gt; 255 heads, 63 sectors/track, 4864 cylinders
&lt;br&gt;&amp;gt; Units = cylinders of 16065 * 512 = 8225280 bytes
&lt;br&gt;&amp;gt; Disk identifier: 0x4b36bdea
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;Device Boot &amp;nbsp; &amp;nbsp; &amp;nbsp;Start &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; End &amp;nbsp; &amp;nbsp; &amp;nbsp;Blocks &amp;nbsp; Id &amp;nbsp;System
&lt;br&gt;&amp;gt; /dev/sda1 &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 463 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4863 &amp;nbsp; &amp;nbsp;35351032+ &amp;nbsp; 7 &amp;nbsp;HPFS/NTFS
&lt;br&gt;&amp;gt; /dev/sda2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 462 &amp;nbsp; &amp;nbsp; 3710983+ &amp;nbsp; b &amp;nbsp;W95 FAT32
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Partition table entries are not in disk order
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; While I don't have a usb or firewire drive I can use to clone to directly, I do have an external harddrive enclosure for a laptop drive, so I will be pulling the &amp;nbsp;drive from the laptop and connecting it to my forensics workstation using the enclosure.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I will try cloning the entire drive instead of just the ntfs partition also.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks for the tips.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: farmerdude [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18947180&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;subscribe@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Friday, August 08, 2008 6:40 PM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18947180&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DON.RAIKES@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Cc: focus-linux
&lt;br&gt;&amp;gt; Subject: Re: problems cloning a hard drive with dcfldd
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Don,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Can you provide the output of these commands issued from the laptop
&lt;br&gt;&amp;gt; system;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; fdisk -l
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; blkid /dev/sda*
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Instead of blowing across the network, are you able to attach a firewire
&lt;br&gt;&amp;gt; or USB hard drive to the laptop and blow your acquisition file via one
&lt;br&gt;&amp;gt; of those ports locally? &amp;nbsp;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Also, based on your dcfldd command, you know that you are acquiring only
&lt;br&gt;&amp;gt; the first partition on the physical device, /dev/sda, yes? &amp;nbsp; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; If you want the physical device, remove the number from your command.
&lt;br&gt;&amp;gt; If you want only the partition continue on with your command then!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Cheers!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; farmerdude
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.forensicbootcd.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.forensicbootcd.com&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.onlineforensictraining.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.onlineforensictraining.com&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/root-shell-auditing-tp18706731p18947180.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18947129</id>
	<title>RE: problems cloning a hard drive with dcfldd</title>
	<published>2008-08-11T12:11:11Z</published>
	<updated>2008-08-11T12:11:11Z</updated>
	<author>
		<name>Don Raikes</name>
	</author>
	<content type="html">Farmerdude,
&lt;br&gt;&lt;br&gt;Here are the results of the commands you suggested:
&lt;br&gt;&lt;br&gt;blkid:
&lt;br&gt;/dev/sda1: UUID=&amp;quot;D08405CF8405B94C&amp;quot; TYPE=&amp;quot;ntfs&amp;quot; 
&lt;br&gt;/dev/sda2: UUID=&amp;quot;423B-2BDF&amp;quot; TYPE=&amp;quot;vfat&amp;quot; 
&lt;br&gt;&lt;br&gt;fdisk:
&lt;br&gt;&lt;br&gt;&lt;br&gt;Disk /dev/sda: 40.0 GB, 40007761920 bytes
&lt;br&gt;255 heads, 63 sectors/track, 4864 cylinders
&lt;br&gt;Units = cylinders of 16065 * 512 = 8225280 bytes
&lt;br&gt;Disk identifier: 0x4b36bdea
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Device Boot &amp;nbsp; &amp;nbsp; &amp;nbsp;Start &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; End &amp;nbsp; &amp;nbsp; &amp;nbsp;Blocks &amp;nbsp; Id &amp;nbsp;System
&lt;br&gt;/dev/sda1 &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 463 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4863 &amp;nbsp; &amp;nbsp;35351032+ &amp;nbsp; 7 &amp;nbsp;HPFS/NTFS
&lt;br&gt;/dev/sda2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 462 &amp;nbsp; &amp;nbsp; 3710983+ &amp;nbsp; b &amp;nbsp;W95 FAT32
&lt;br&gt;&lt;br&gt;Partition table entries are not in disk order
&lt;br&gt;&lt;br&gt;While I don't have a usb or firewire drive I can use to clone to directly, I do have an external harddrive enclosure for a laptop drive, so I will be pulling the &amp;nbsp;drive from the laptop and connecting it to my forensics workstation using the enclosure.
&lt;br&gt;&lt;br&gt;I will try cloning the entire drive instead of just the ntfs partition also.
&lt;br&gt;&lt;br&gt;Thanks for the tips.
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: farmerdude [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18947129&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;subscribe@...&lt;/a&gt;]
&lt;br&gt;Sent: Friday, August 08, 2008 6:40 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18947129&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DON.RAIKES@...&lt;/a&gt;
&lt;br&gt;Cc: focus-linux
&lt;br&gt;Subject: Re: problems cloning a hard drive with dcfldd
&lt;br&gt;&lt;br&gt;&lt;br&gt;Don,
&lt;br&gt;&lt;br&gt;Can you provide the output of these commands issued from the laptop
&lt;br&gt;system;
&lt;br&gt;&lt;br&gt;fdisk -l
&lt;br&gt;&lt;br&gt;&lt;br&gt;blkid /dev/sda*
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Instead of blowing across the network, are you able to attach a firewire
&lt;br&gt;or USB hard drive to the laptop and blow your acquisition file via one
&lt;br&gt;of those ports locally? &amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Also, based on your dcfldd command, you know that you are acquiring only
&lt;br&gt;the first partition on the physical device, /dev/sda, yes? &amp;nbsp; 
&lt;br&gt;&lt;br&gt;If you want the physical device, remove the number from your command.
&lt;br&gt;If you want only the partition continue on with your command then!
&lt;br&gt;&lt;br&gt;Cheers!
&lt;br&gt;&lt;br&gt;farmerdude
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.forensicbootcd.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.forensicbootcd.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.onlineforensictraining.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.onlineforensictraining.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/root-shell-auditing-tp18706731p18947129.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18929874</id>
	<title>Re: problems cloning a hard drive with dcfldd</title>
	<published>2008-08-08T18:40:28Z</published>
	<updated>2008-08-08T18:40:28Z</updated>
	<author>
		<name>fd lists</name>
	</author>
	<content type="html">Don,
&lt;br&gt;&lt;br&gt;Can you provide the output of these commands issued from the laptop
&lt;br&gt;system;
&lt;br&gt;&lt;br&gt;fdisk -l
&lt;br&gt;&lt;br&gt;&lt;br&gt;blkid /dev/sda*
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Instead of blowing across the network, are you able to attach a firewire
&lt;br&gt;or USB hard drive to the laptop and blow your acquisition file via one
&lt;br&gt;of those ports locally? &amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Also, based on your dcfldd command, you know that you are acquiring only
&lt;br&gt;the first partition on the physical device, /dev/sda, yes? &amp;nbsp; 
&lt;br&gt;&lt;br&gt;If you want the physical device, remove the number from your command.
&lt;br&gt;If you want only the partition continue on with your command then!
&lt;br&gt;&lt;br&gt;Cheers!
&lt;br&gt;&lt;br&gt;farmerdude
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.forensicbootcd.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.forensicbootcd.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.onlineforensictraining.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.onlineforensictraining.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/root-shell-auditing-tp18706731p18929874.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18896032</id>
	<title>Re: problems cloning a hard drive with dcfldd</title>
	<published>2008-08-07T23:21:57Z</published>
	<updated>2008-08-07T23:21:57Z</updated>
	<author>
		<name>Andreas Ferrari</name>
	</author>
	<content type="html">Dave Hull schrieb:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Wed, Aug 6, 2008 at 3:14 PM, &amp;nbsp;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18896032&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DON.RAIKES@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; I am a newbie to this whole digital forensics world, and am having a problem cloning a hard drive.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Setup:
&lt;br&gt;&amp;gt;&amp;gt; laptop with 40gb harddrive with 2 partitions. The laptop had/has windows xp on it, but it won't boot any longer.
&lt;br&gt;&amp;gt;&amp;gt; desktop system running fedora 9 as my forensics lab machine.
&lt;br&gt;&amp;gt;&amp;gt; fedora livecd containing dcfldd and some other &amp;nbsp;tools.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Situation:
&lt;br&gt;&amp;gt;&amp;gt; I boot the laptop using the livecd and login no problem.
&lt;br&gt;&amp;gt;&amp;gt; I can see the hard drive as /dev/sda.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; You might try pulling the drive out of the laptop and connecting it to
&lt;br&gt;&amp;gt; your PC directly using a USB external drive adapter. Mount the drive
&lt;br&gt;&amp;gt; on your forensics lab machine read-only and try acquiring the image
&lt;br&gt;&amp;gt; with dcfldd. You could also acquire the entire drive, rather than
&lt;br&gt;&amp;gt; individual partitions and then carve out the partitions from that
&lt;br&gt;&amp;gt; image, again using dcfldd. The Sleuthkit command mmls will display the
&lt;br&gt;&amp;gt; partition table information it finds in the image and you can feed
&lt;br&gt;&amp;gt; that information into dcfldd to carve out the partitions.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; dcfldd if=/dev/sda1 conv=noerror,sync hash=md5 hashlog=md5.log | nc desktopsystem 1234 -w 3
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Looks good to me. Have you tried specifying a blocksize via bs=?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; All seems to be going just fine the netcat connection is made and dcfldd is displaying its progress.
&lt;br&gt;&amp;gt;&amp;gt; However, at block 98513, I get an error from dcfldd saying:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; error:/dev/sda1 input output error
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; and the whole process stops.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;/div&gt;If there is an error an the disk dd will fail, if you really dont need 
&lt;br&gt;the forensic features
&lt;br&gt;of dcfldd you can also use ddrescue.
&lt;br&gt;ddrescue is different than dd, a dd fails when there is a read error on 
&lt;br&gt;the disk, ddrescue will
&lt;br&gt;continue (have a look at the man).
&lt;br&gt;God luck
&lt;br&gt;&amp;gt; I have seen similar problems when trying to acquire using Helix and
&lt;br&gt;&amp;gt; USB mounted drives on laptops. I generally have better luck attaching
&lt;br&gt;&amp;gt; and mounting the drives in my forensic workstation.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Good luck.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/root-shell-auditing-tp18706731p18896032.html" />
</entry>

</feed>
