<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-19798898</id><updated>2011-10-07T13:13:01.670-04:00</updated><category term='defcon 17 hack hacking las vegas'/><category term='Lower Merion School District webcam spying'/><category term='download'/><category term='Backtrack 4 offensive-security remote-exploit'/><title type='text'>Security|Networking|Hacking|Life. by 6e:69:63:6b:38:63:68</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://nhtc.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-19798898.post-3577792748169381204</id><published>2011-01-09T20:15:00.004-05:00</published><updated>2011-01-09T20:20:27.720-05:00</updated><title type='text'>Social Engineering: The Art of Human Hacking - Essential Read for any Security Professional</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hWfj6pqRTss/TSpeRGRzLLI/AAAAAAAAAD4/a2j2YYLkJqA/s1600/41JyTYDUA5L._SL500_AA300_.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 200px; height: 200px;" src="http://4.bp.blogspot.com/_hWfj6pqRTss/TSpeRGRzLLI/AAAAAAAAAD4/a2j2YYLkJqA/s200/41JyTYDUA5L._SL500_AA300_.jpg" alt="" id="BLOGGER_PHOTO_ID_5560360337778355378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Chris Hadnagy of Social-Engineer.org has done a tremendous job on a ground breaking new SE book.&lt;br /&gt;I must say after reading this book I feel as though the name "Kevin Mitnick" will now be replaced with "Chris Hadnagy" when referring to Social Engineering. I was amazed at how this was not merely a collection of experiences but an in depth, well researched, well organized crash course into the human psyche and the science behind human manipulation. My favorite chapter was number 6: "Influence: The Power of Persuasion" particularly the part on "Framing". This section really drove home the point that humans ARE hackable!&lt;br /&gt;I appreciated how this book is not a "how-to" for would-be malicious hackers or con men. But a guide on the what, how and why techniques behind Social Engineering can be used for malicious purposes. In fact, Chapter 9 is dedicated to "Prevention and Mitigation" of SE attacks&lt;br /&gt;The book is clear, concise and an easy read. This is a must read for anyone in the Information security field, but I think an essential guide for anyone in law enforcement, private security, or even John Q. Public looking to protect himself from being manipulated. Humans will always be the weakest link in security the infrastructure, but this book is a patch for our mental firewall. Highly Recommended.&lt;br /&gt;&lt;br /&gt;Available at &lt;a href="http://www.amazon.com/Social-Engineering-Art-Human-Hacking/dp/0470639539/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1294622327&amp;amp;sr=8-1"&gt;Amazon &lt;/a&gt;&lt;br /&gt;And don't forget to check out &lt;a href="http://Social-Engineer.org"&gt;Social-Engineer.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-3577792748169381204?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/3577792748169381204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/3577792748169381204'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2011/01/social-engineering-art-of-human-hacking.html' title='Social Engineering: The Art of Human Hacking - Essential Read for any Security Professional'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hWfj6pqRTss/TSpeRGRzLLI/AAAAAAAAAD4/a2j2YYLkJqA/s72-c/41JyTYDUA5L._SL500_AA300_.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-6109904208335044498</id><published>2010-05-12T22:52:00.004-04:00</published><updated>2010-05-12T23:10:17.017-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lower Merion School District webcam spying'/><title type='text'>Technical Analysis of the methods used by the Lower Merion School District webcam spying case.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hWfj6pqRTss/S-tsaLVWyoI/AAAAAAAAADk/YGMKjaLl94A/s1600/spying.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 175px; height: 200px;" src="http://4.bp.blogspot.com/_hWfj6pqRTss/S-tsaLVWyoI/AAAAAAAAADk/YGMKjaLl94A/s200/spying.jpg" alt="" id="BLOGGER_PHOTO_ID_5470585369346361986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I recently had the pleasure of contributing to Social-Engineer.org on a very interesting topic. Most media outlets are focusing their attention on the "official" theft tracking software and neglecting to analyze the main computer management agent that is installed on the computers and it's capabilities. Thanks, Logan_WHD and the SE.org team for the post.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.social-engineer.org/blog/interesting-se-articles/analysis-of-lower-merion-school-district-remote-monitoring-of-students-2/"&gt;Click Here for the article.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-6109904208335044498?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/6109904208335044498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/6109904208335044498'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2010/05/technical-analysis-of-technology-used.html' title='Technical Analysis of the methods used by the Lower Merion School District webcam spying case.'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hWfj6pqRTss/S-tsaLVWyoI/AAAAAAAAADk/YGMKjaLl94A/s72-c/spying.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-4154824441772848978</id><published>2010-05-11T15:45:00.003-04:00</published><updated>2010-05-11T15:59:35.121-04:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hWfj6pqRTss/S-m257eTvoI/AAAAAAAAADc/oRBrJVYtXI8/s1600/LMSD-big-brother-poster.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 136px; height: 200px;" src="http://2.bp.blogspot.com/_hWfj6pqRTss/S-m257eTvoI/AAAAAAAAADc/oRBrJVYtXI8/s200/LMSD-big-brother-poster.jpg" alt="" id="BLOGGER_PHOTO_ID_5470104328751791746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Watch this space.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-4154824441772848978?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/4154824441772848978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/4154824441772848978'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2010/05/watch-this-space.html' title=''/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hWfj6pqRTss/S-m257eTvoI/AAAAAAAAADc/oRBrJVYtXI8/s72-c/LMSD-big-brother-poster.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-2136400898393611215</id><published>2009-12-15T23:49:00.003-05:00</published><updated>2009-12-16T00:00:14.665-05:00</updated><title type='text'>Social-engineer.org</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hWfj6pqRTss/SyhnvcKD39I/AAAAAAAAADU/ap5xXe-gX7Q/s1600-h/headShadow.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 157px; height: 157px;" src="http://3.bp.blogspot.com/_hWfj6pqRTss/SyhnvcKD39I/AAAAAAAAADU/ap5xXe-gX7Q/s200/headShadow.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5415692616622923730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;First of... Whoa first post since July! Zoinks! Busy Busy. Nice new adventures in Pen testing to write about in coming months though. I wanted to post a quick review of a site that ALL security professionals and penetration testers alike should be frequenting. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.social-engineer.org/"&gt;WWW.SOCIAL-ENGINEER.ORG&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;By far the best if not the only source of all things social engineering. Move over Mitnik! They are presently on their 3rd month of podcasts, all can say is its pure gold! Partnering with well known figures in the security industry such as mutts (lead Back|Track dev) and Re|ik (creator of fast-track and the new SET, social engineers toolkit) makes this a match made in hax0r Heaven! LoganWHD has taken this sometime fringe aspect of security, the HUMAN computer, and developed an awesome source for SE with the help of several members of the hacker community. John aka Elwood also brings years of law enforcement experience for a very well rounded framework for SE.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bookmark this site, subscribe to the newsletter and get the podcast. You'll thank yourself!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-2136400898393611215?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2136400898393611215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2136400898393611215'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/12/social-engineerorg.html' title='Social-engineer.org'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hWfj6pqRTss/SyhnvcKD39I/AAAAAAAAADU/ap5xXe-gX7Q/s72-c/headShadow.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-2438019584239797207</id><published>2009-07-02T15:01:00.006-04:00</published><updated>2009-07-02T15:53:10.953-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='defcon 17 hack hacking las vegas'/><title type='text'>Defcon 17 - Boing!!!</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hWfj6pqRTss/Sk0FuK2K1oI/AAAAAAAAADM/iwSzQpbQLJw/s1600-h/Badge1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 172px; height: 200px;" src="http://2.bp.blogspot.com/_hWfj6pqRTss/Sk0FuK2K1oI/AAAAAAAAADM/iwSzQpbQLJw/s200/Badge1.jpg" alt="" id="BLOGGER_PHOTO_ID_5353941822757066370" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Well its that time again. Vegas will once again be swamped with the likes of white, gray and black hats from all creeds, colors, income tax brackets and species. What an experience! If you have a chance to attend I HIGHLY recommend it. More info can be found here.... &lt;a href="http://defcon.org/"&gt;http://defcon.org&lt;/a&gt; Be sure to check the DEFCON forums for info on attending. I personally liked checking out some of the you-tube vids from previous years to get a feel for what to expect.&lt;br /&gt;&lt;br /&gt;Simple truth.... expect anything and besides getting a flight and hotel, don't really plan anything else. For maximum fun just go with  the flow. You may end up in some very cool places rubbing arms with people you've only read about in the hacker community.&lt;br /&gt;&lt;br /&gt;This year should be very interesting. Cool talks lined up &lt;a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Long"&gt;Johnny Long&lt;/a&gt;, &lt;a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Endgrain"&gt;Dan "attention whore" Kaminsky&lt;/a&gt; and , get this, &lt;a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Savage"&gt;Adam Savage&lt;/a&gt; from Mythbusters on the Discovery channel, will be there this year. Last HOPE in NYC he spoke, I saw it, he's a really cool guy. Hoping to meet him. His twitter is "donttrythis". Checkity check him out.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Here is a couple n3wb tips for maximum fun and $$ savings:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1) &lt;span style="font-weight: bold;"&gt;Shop for flight &amp;amp; hotel deals.&lt;/span&gt; This year from philly direct to vegas and 5 nights hotel at teh Circus Circus a friend and I scored tickets for about $500 a piece. giggity giggity! Unless you want non-stop, no-sleep, no-rest, skip the Riviera for lodging. 10000 hotels other than that one to stay at.&lt;br /&gt;&lt;br /&gt;2&lt;span style="font-weight: bold;"&gt;)DRINK WATER&lt;/span&gt;: you're in the friggin desert for mitnick's sake!&lt;br /&gt;&lt;br /&gt;3)&lt;span style="font-weight: bold;"&gt;You won't get much sleep, trust me! &lt;/span&gt;Prepare the week before by getting some good rest. out there the place just drains the living crap out of you. I found that fitting in like four hours here and there kept me going. Well that and lots and lots of monster, rockstar and 5 hour energy.&lt;br /&gt;&lt;br /&gt;4)&lt;span style="font-weight: bold;"&gt;Black is cool to wear&lt;/span&gt;, hey we're hackers, its what we do. BUT, and its a HUGE BUT, bring black t-shirts that breathe! and shorts are a very good idea. jeans suck! :)&lt;br /&gt;&lt;br /&gt;5)&lt;span style="font-weight: bold;"&gt; Leave room in your luggage for swag!&lt;/span&gt; You will totoally score some great stuff. (ie. t-shirts, or other crap you want to bring home.) And is it really nessasary to bring all your tech gear to the con? You may really only need a single system and any gear you may want to play with. Its easier in the long run also.&lt;br /&gt;&lt;br /&gt;6)&lt;span style="font-weight: bold;"&gt;Don't access anything from Public Internet access points&lt;/span&gt; in or around the Riviera or anywhere really. Seriously. If you have access or actually own a 3g, GPRS, GSM, CDMA etc WLAN card, use it! Stay off the hotel net and the pub Defcon wifi/lan with anything you care about. It WILL be hacked and/or compromised. Don't be a victim of the "wall of sheep". (google it if you want more info). What I do is use either a sanitized/clean hd with nothing on it of value or use a bootable usb key with Back|Track. (remember to change the default password). But still remember not to check any webmail etc. SSL will not protect you. Ahh yes and one more bit of advice, skip the ATM at  the Riv. trust me.... just bring enough cash ahead of time. ;)&lt;br /&gt;&lt;br /&gt;7)&lt;span style="font-weight: bold;"&gt;Be humble.&lt;/span&gt; I don't care if you just hacked DOD or changed the Pres' blackberry ring-tone so that he's "rick-rolled" every time biden calls him. There will always be someone who can put you down. Once you go for the first time you'll understand, you can spot a arrogant hacker SOB from a mile away (**ehhemm,kaminsky,cough**). l33t h@xoR$ IMO are always very humble. Trust me sit back be silent unless you're asking questions. Make friends. Learn. No "measuring" of size going on here. Hacking is about learning.&lt;br /&gt;&lt;br /&gt;All in all, sit back and take in the awesome exchange of knowledge and technical exploration available.&lt;br /&gt;&lt;br /&gt;Hope to see  you there! Remember to search for the offsec &amp;amp; remote-exploit ppl.&lt;br /&gt;&lt;br /&gt;nick8ch&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-2438019584239797207?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2438019584239797207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2438019584239797207'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/07/defcon-17-boing.html' title='Defcon 17 - Boing!!!'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hWfj6pqRTss/Sk0FuK2K1oI/AAAAAAAAADM/iwSzQpbQLJw/s72-c/Badge1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-5410799844368037430</id><published>2009-03-17T00:56:00.010-04:00</published><updated>2009-03-17T02:01:40.101-04:00</updated><title type='text'>Security Certification Exam Cage Match</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_hWfj6pqRTss/Sb8y_X1BXZI/AAAAAAAAAC0/5oCHnGX5WpA/s1600-h/2277957534_8b0e23eff1.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5314022149630025106" style="margin: 0px auto 10px; display: block; width: 200px; height: 150px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_hWfj6pqRTss/Sb8y_X1BXZI/AAAAAAAAAC0/5oCHnGX5WpA/s200/2277957534_8b0e23eff1.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hWfj6pqRTss/Sb8wR8gkdPI/AAAAAAAAACk/tIDLVOBpmmo/s1600-h/notcissp.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5314019170179118322" style="margin: 0px 0px 10px 10px; float: right; width: 1px; height: 1px;" alt="" src="http://1.bp.blogspot.com/_hWfj6pqRTss/Sb8wR8gkdPI/AAAAAAAAACk/tIDLVOBpmmo/s320/notcissp.gif" border="0" /&gt;&lt;/a&gt; &lt;a href="http://3.bp.blogspot.com/_hWfj6pqRTss/Sb8ydMZxRVI/AAAAAAAAACs/QThTDtNfXj8/s1600-h/2277957534_8b0e23eff1.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;What is the best group of letters to have after your name as a security professional?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;I thought I would write a brief account of my experience with three of such certifications. Certified Ethical Hacker (CEH), GIAC Certified Penetration Tester (GPEN) and Offensive Security Certified Professional (OSCP).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CEH&lt;/strong&gt; &lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;My experience with the CEH certification started with a one week boot-camp type training session through a training center in Plano, TX. The training was very “by the book” and when I say that I mean “books”. During the first day we were given three large red books for a total of 2300+ pages of information AND a 500 page lab manual. In the classroom each had a small satellite desktop system loaded with WinXP-pro, win2000 and a BackTrack partition. The trainer we had was actually a very good trainer but the training lacked something. At the time I really couldn't put my finger on it due to my lack of experience with training sessions. More on that later as you will see.&lt;br /&gt;During the training we were told several times that EVERYONE here WILL pass the exam. This made me feel as if the whole purpose of this training was ONLY to pass the exam and get that little piece of paper and those three letters after our name. The books mainly focus on the use of windows/linux based programs and utilities that are already made for a specific task. Very little practical knowledge or challenging exercises. For example a typical day session would be like this; “hello class, open to page such-n-such , we are going to see how to use wireshark to sniff packets.” Following 5-8 slides on the projector explaining what the ins and outs were, we would open the program and start sniffing. “Ok, any questions? Good, moving on to our next tool.....” Was this a Ethical Hacking course or a discussion of man pages?&lt;br /&gt;Overall I am glad I took the class, 7 day session included the CEH and CHFI exam which was a breeze. I'm happy I have the certs because it does show a degree of knowledge in the field of security and penetration testing. But, in the list of security certifications I think the CEH is quickly loosing credibility due to the fact that very little security experience is needed to pass this exam. It is very close to MS certifications in that, a simple memorization of material will allow you to pass the exam. If you can memorize some command line switches for Nmap and Netcat, you can pass this.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;GPEN&lt;/strong&gt; &lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;The GIAC Certified Penetration Tester certification is relatively new to the arena. Approximately 350 certified at the time I received mine last month. From the GIAC website: “The GPEN certification is for security personnel whose job duties involve assessing target networks and systems to find security vulnerabilities. Certification objectives include penetration-testing methodologies, the legal issues surrounding penetration testing and how to properly conduct a penetration test as well as best practice technical and non-technical techniques specific to conduct a penetration test.” The certification is based on the SANS 560 course material.&lt;br /&gt;&lt;br /&gt;I did not attend any training for this exam and did not pay for it either. I received this certification basically on a dare :) Let me explain. GIAC decided that their certification didn't have enough publicity or wasn't being recognized so they decided to offer the $900 exam for free to people who had passed one of the rival certifications CEH &amp;amp; OSCP recently. I had just completed my OSCP as I will explain later and I decided to give it a whirl. The test was a 4hr 150 question multiple choice test that needed to be proctored at a testing center. Along with the exam I was given two free practice tests to take ahead of time. I passed those and scheduled my exam. Granted I didn't really study or prepare too much but I was able to pass.&lt;br /&gt;With this certification I only have the exam to compare to the other two, so based on that, the exam still lacked something. I mean, could a person with a tech support level 1 have passed this exam. Well, multiple choice questions, 4 hours, I think so. This is really my point, where is the practicality of the exam? Does it show actual REAL working knowledge. If I can answer a question like; “Which of the following tools would be used to create a Reverse Bind TCP shell?”, does that make me a security professional? Um, no.&lt;br /&gt;Now, let's talk about the last certification.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;OSCP &lt;/strong&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;The Offensive Security Certified Professional certification is also relatively new. It's a certification that proves that the individual has a real working knowledge of a real-world penetration testing environment. The training, a lab testing environment and Exam is included in a package. The training is called “Pen testing with backtrack”, instead of “Ofsec 101” as it was called previously. From their website: “an on-line course designed for network administrators and security professionals who need to get acquainted with the world of offensive security. The course introduces the latest hacking tools and techniques, and includes remote live labs for exercising the material presented to the students.”&lt;br /&gt;So, the course is on-line and tremendously cheaper than other certifications. Is it any good? Thats a big NO! Its way way better. Its AWESOME. With the lab time you receive with your training, you get VPN access to a real-world pen-testing lab environment with several target machines and objectives and exercises throughout the training. This in itself is an amazing learning tool. You also have a dedicated windows system within the lab with several tools installed including Core Impact which most people haven't had access to due to the cost.&lt;br /&gt;The training itself is CBT based using video and also you receive a very well written training manual that goes along with the training. Each section ends with an exercise and a “extra mile” type exercise that you can preform and document for extra points at the end of your course. All in all the training is A+! Since the pre-reqs for taking this training requires a previous understanding of TCP, network admin, etc. There isn't time wasted on very basic networking concepts. The training is by Mati Aharoni of offensive-security, a seasoned security professional with google being his resume'. He is also the main developer of the BackTrack security Linux distribution. So the training focuses on using BackTrack as the platform for pen testing. If you opt to get the lab time, which again I will say GET IT, If you sign up for the “Pen testing with backtrack” you will have the opportunity at the end of the training to attempt final challenges that have been designed to test all aspects of the training you went through. I give credit to the excellent training I received as being the reason I was able to blast through the GPEN exam. It is unlike previous technical training I have had in that it teaches you how to reason and think, not just fill your head with man pages from hacker tools. But enough about the training. Since we are mainly comparing the exams for the certifications. How did the OSCP fair?&lt;br /&gt;&lt;br /&gt;This was no Q&amp;amp;A exam. The OSCP exam is designed to test you as a Penetration Tester. Last time I checked when you were testing a company's network they don't hand you a test with multiple choice questions. So this is where the OSCP, in its awesome practicality, stands above the rest. (The exam is 24 hours, yes that's right, 24 hours to complete.) You are given VPN access to a separate and dedicated only to you specially designed lab for your exam. You are then given objectives to complete. Basically you are told to find, exploit, document and prove exploitation of several systems in the exam lab. Hence the need for 24 hours, and I tell you I almost used all of the exam time (thank you red bull). The system could really be any operating system and you have no prior information regarding what is in the lab you are connected to. It truly is a test of EVERYTHING you were trained on in the course. It will test you to the very limits of what you are capable of and it is a true challenge. Following the exam, you submit your notes and proof of exploits and your are then graded.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Conclusion&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;With so many people passing themselves off as “Security Professionals”, I think more than ever it is imperative that the individual show practical real-world knowledge of Penetration testing. For instance, do you only take a written test for your drivers license? Of course not. So why do some of the so called “best” security certifications not test REAL working knowledge? Many certifications test the individual on book knowledge and totally ignore the fact that when you are preforming a penetration test you are in essence a malicious hacker for that project, so you in turn need to think like one. You have to think offensively from a black box perspective and the OSCP nails that in all aspects of the training and exam. In my opinion this certification &amp;amp; training should be mandatory for anyone looking to break into the field of penetration testing. Yes other certifications look great on a resume' but as time goes on and the OSCP becomes more well known I think you will see more and more companies looking at this setting the bar for security certifications.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-5410799844368037430?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/5410799844368037430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/5410799844368037430'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/03/security-certification-exam-cage-match.html' title='Security Certification Exam Cage Match'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hWfj6pqRTss/Sb8y_X1BXZI/AAAAAAAAAC0/5oCHnGX5WpA/s72-c/2277957534_8b0e23eff1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-7417692703323203463</id><published>2009-03-02T17:13:00.002-05:00</published><updated>2009-03-02T17:17:41.174-05:00</updated><title type='text'>Internal Network Policies Part 3: </title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hWfj6pqRTss/Saxa5LAOLsI/AAAAAAAAACc/vbyd2Po5j-Q/s1600-h/matrix_wideweb__430x326.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 152px;" src="http://1.bp.blogspot.com/_hWfj6pqRTss/Saxa5LAOLsI/AAAAAAAAACc/vbyd2Po5j-Q/s200/matrix_wideweb__430x326.jpg" alt="" id="BLOGGER_PHOTO_ID_5308717999015734978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Body Text"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:"Arial Unicode MS"; 	panose-1:2 11 6 4 2 2 2 2 2 4; 	mso-font-charset:128; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-134238209 -371195905 63 0 4129279 0;} @font-face 	{font-family:"\@Arial Unicode MS"; 	panose-1:2 11 6 4 2 2 2 2 2 4; 	mso-font-charset:128; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-134238209 -371195905 63 0 4129279 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:none; 	mso-hyphenate:none; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Arial Unicode MS"; 	mso-font-kerning:.5pt; 	mso-fareast-language:#00FF;} p.MsoBodyText, li.MsoBodyText, div.MsoBodyText 	{mso-style-noshow:yes; 	mso-style-unhide:no; 	mso-style-link:"Body Text Char"; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:6.0pt; 	margin-left:0in; 	mso-pagination:none; 	mso-hyphenate:none; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Arial Unicode MS"; 	mso-font-kerning:.5pt; 	mso-fareast-language:#00FF;} span.BodyTextChar 	{mso-style-name:"Body Text Char"; 	mso-style-noshow:yes; 	mso-style-unhide:no; 	mso-style-locked:yes; 	mso-style-link:"Body Text"; 	mso-ansi-font-size:12.0pt; 	mso-bidi-font-size:12.0pt; 	font-family:"Arial Unicode MS","sans-serif"; 	mso-fareast-font-family:"Arial Unicode MS"; 	mso-font-kerning:.5pt; 	mso-fareast-language:#00FF;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;    &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;The Enemy of my Enemy is my Enemy? Huh?&lt;/span&gt;&lt;/u&gt;&lt;/i&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;Yes, that statement may seem odd but it's true. Sometimes the greatest threat can come from within. In the last two articles we discussed how an employee of your own company could compromise your entire network by doing something as simple as downloading &amp;amp; sharing the latest Britney Spears song. But what are the implications of this action? Are your employees trying to sabotage your company? Most likely, &lt;i style=""&gt;No&lt;/i&gt;. But are your employees performing an action that is inadvertently compromising your information integrity? They might be....&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;What have you implemented as a company policy or procedure, to educate your employees of the fact that the action they take may impact the company in a negative way? Most of the time nothing of this sort is done, Why?&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;The problem lies in the fact that most network administrators dwell too much on making things “work” and not enough on making things “secure”. But what does this involve? It's much more than enforcing strong passwords or insisting that the staff not take out of the premises data that may expose information that could lead to a breach. It involves an overall education of what can be done with a small portion of access to your company's network.  For example, what information could I gain from a single e-mail login from say,.. a sales person? Any inside information available there? Perhaps information regarding a product that you have a niche in? Do you ever send financial information to a sales person? The point is this, information you would normally pass off as insignificant between members of your own company may seem common but, to the a rival company or malicious entity could be very lucrative. What would be the cost to your company if that information was in the open?  Could you lose your advantage or perhaps a crucial bid to a large contract? &lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size:14;"&gt;Information is everything.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;It is the life blood of your way of making money with your product or service.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;How do you protect that?&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;By understanding the flaws that threatened the integrity of that information. Only by understanding how the “would be” attacker of your company thinks, will you understand what really is at risk here. If you do not have someone who understands this very fundamental aspect of information security on your IT team, &lt;b style=""&gt;GET ONE&lt;/b&gt;. The need of the cookie cutter “&lt;i style=""&gt;bachelors degree in computer science&lt;/i&gt;” is long gone. &lt;b style=""&gt;WORKING &lt;/b&gt;knowledge in the &lt;b style=""&gt;REAL&lt;/b&gt; world of computer technology and networking is &lt;b style=""&gt;ESSENTIAL&lt;/b&gt;.&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;To the CEO and management personal that are reading this, I write this: there are more vulnerabilities in the software you run each day on your office PC than you can count. And I'm not talking about viruses, ad-ware or spy-ware. &lt;i style=""&gt;Real threats.&lt;/i&gt; More and more each day. I don't say this to frighten you but to educate you on the fact that when it comes to “conventional” knowledge of Information Technology, nowadays, it just doesn't cut it. You need to think beyond the out-of-the-box mentality of network security. Norton, McAfee, etc will &lt;b style=""&gt;NOT &lt;/b&gt;save you from the real threats that lurk out there. You need real active, intelligent staff in place to deal with the threats that exist.&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;What can you do as management? Have a conversation with your IT staff or IT provider. Ask them to explain what the TCP/IP stack involves and what tools such as NMAP and Netcat do. Do they understand the various forms of encryption when it comes to wireless? What's the difference between WEP &amp;amp; WPA? Or better yet, keep it short and simple, ask them to give you a detailed report on what steps they have taken to ensure that threats externally and internally are being actively defended against. With this report you should be able to determine what, if any, defense has been implemented against such attacks.&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;These queries are just the bare minimum in what a qualified IT person should be able to answer today. Why? Because setup and installation of your network is, for the most part, taken care of by the software/hardware manufacturer. Most setup of even enterprise networks is “wizard driven”, meaning automated or &lt;i style=""&gt;really easy.&lt;/i&gt; The rest, including securing your information, is up to your staff or IT provider, the &lt;i style=""&gt;human element&lt;/i&gt;. Make sure you are protected, in these critical financial times, you cannot afford to lose money due to an information breach. &lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;If you have any questions about this series of articles or need assistance in assessing whether or not your information security is up to par, contact the MAEA. We have a qualified IT and Security staff that can answer your questions.&lt;/p&gt;  &lt;p class="MsoBodyText"&gt; &lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;Nick Hitchcock&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;    &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;OSCP, CEH, CHFI, MCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;NHT Consulting&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;www.nhtconsulting.com &lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;i style=""&gt;nickh@nhtconsulting.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-7417692703323203463?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/7417692703323203463'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/7417692703323203463'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/03/internal-network-policies-part-3.html' title='Internal Network Policies Part 3: '/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hWfj6pqRTss/Saxa5LAOLsI/AAAAAAAAACc/vbyd2Po5j-Q/s72-c/matrix_wideweb__430x326.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-2487878620067840734</id><published>2009-02-11T10:13:00.006-05:00</published><updated>2009-02-11T10:27:45.411-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='download'/><category scheme='http://www.blogger.com/atom/ns#' term='Backtrack 4 offensive-security remote-exploit'/><title type='text'>Back|Track 4 Public is now available!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hWfj6pqRTss/SZLuEYMtvGI/AAAAAAAAACE/bzTH5tHlBQ0/s1600-h/bt4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 96px;" src="http://3.bp.blogspot.com/_hWfj6pqRTss/SZLuEYMtvGI/AAAAAAAAACE/bzTH5tHlBQ0/s200/bt4.png" alt="" id="BLOGGER_PHOTO_ID_5301561470351162466" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Our friends over at Remote-Exploit &amp;amp; Offensive-Security have rolled out the public version of BT4. The ISO and VMware editions are available via the following links:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-iso"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;font-size:85%;" &gt;http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-iso&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-vm"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;font-size:85%;" &gt;http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-vm&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can distribute the ISO and VM, but the team asks that you would please forward the above links for people to download from. This will give them good estimates on how many downloads are being made initially. Thanks and Enjoy!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Greetz to muts, loganWHD, ziplock, ReL!k, MisterX, ZeroChaos, jabra, omar,TheX1le, and the whole team..... cheerz!&lt;br /&gt;You can thank the team yourself on IRC, freenode net on #remote-exploit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-2487878620067840734?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2487878620067840734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/2487878620067840734'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/02/backtrack-4-public-is-now-available_11.html' title='Back|Track 4 Public is now available!'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hWfj6pqRTss/SZLuEYMtvGI/AAAAAAAAACE/bzTH5tHlBQ0/s72-c/bt4.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-8702063772076688881</id><published>2009-02-10T12:25:00.006-05:00</published><updated>2009-02-10T13:34:07.375-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Backtrack 4 offensive-security remote-exploit'/><title type='text'>BackTrack 4 and ShmooCon 2009</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hWfj6pqRTss/SZG7L3r0n1I/AAAAAAAAAA4/XDEzOfqAcuI/s1600-h/bt4.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 96px;" src="http://3.bp.blogspot.com/_hWfj6pqRTss/SZG7L3r0n1I/AAAAAAAAAA4/XDEzOfqAcuI/s200/bt4.png" alt="" id="BLOGGER_PHOTO_ID_5301224048992493394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was privileged to be a part of the Remote-Exploit/Offensive-Security team this last weekend at the Washington DC based Hacker Con, ShmooCon. Was an awesome time. Many  new friends made and many old acquaintances met again. I was able to be a part of distributing the new beta version of BackTrack 4. This has not been publicly available yet but should be shortly. Keep checking the Back|Track blog over at &lt;a href="http://backtrack4.blogspot.com/"&gt;http://backtrack4.blogspot.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Here are a few pics from the event. Was a great time! &lt;a href="http://flickr.com/photos/35146528@N07/"&gt;http://flickr.com/photos/35146528@N07/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enjoy... More info to come...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-8702063772076688881?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/8702063772076688881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/8702063772076688881'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2009/02/backtrack-4-and-shmoocon-2009.html' title='BackTrack 4 and ShmooCon 2009'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hWfj6pqRTss/SZG7L3r0n1I/AAAAAAAAAA4/XDEzOfqAcuI/s72-c/bt4.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-7189789122862624282</id><published>2008-12-26T13:35:00.005-05:00</published><updated>2008-12-26T13:48:16.835-05:00</updated><title type='text'>Internal Net Policies part 2</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hWfj6pqRTss/SVUm6N3V3_I/AAAAAAAAAAw/8OJEtXDysH4/s1600-h/highrise1.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 128px;" src="http://1.bp.blogspot.com/_hWfj6pqRTss/SVUm6N3V3_I/AAAAAAAAAAw/8OJEtXDysH4/s200/highrise1.JPG" alt="" id="BLOGGER_PHOTO_ID_5284172519385194482" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing 	{mso-style-priority:1; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt; 	mso-ascii-font-family:Calibri; 	mso-fareast-font-family:Calibri; 	mso-hansi-font-family:Calibri;} @page Section1 	{size:8.5in 11.0in; 	margin:.25in 40.5pt .25in 40.5pt; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;Internal Company Network Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;i style=""&gt;Part 2: A framework for your IT procedures.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;In our last edition of the journal, part 1 touched on the need of your company to have a good internal network policy for your employees and the need to enforce it. In this part we will touch on just how you go about doing that.&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;Is it a Policy, a Standard or a Guideline?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;We frequently hear people use the names "policy", "standard", and "guideline" to refer to documents that fall within the policy infrastructure.&lt;span style=""&gt;  &lt;/span&gt;We are focusing in on “policy” for our discussion. &lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;A &lt;i style=""&gt;policy&lt;/i&gt; is typically a document that outlines specific requirements or rules that must be met. In the information/network security realm, policies are usually point-specific, covering a single area. For example, an "Acceptable Use" policy would cover the rules and regulations for appropriate use of the computing facilities.&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;This is different from a &lt;i style=""&gt;standard&lt;/i&gt; which is typically a collection of system-specific or procedural-specific requirements that must be met by everyone. For example, you might have a standard that describes how to harden a Windows workstation for placement on an external (DMZ) network. A &lt;i style=""&gt;guideline&lt;/i&gt; is typically a collection of system specific or procedural specific "suggestions" for best practice. They are not requirements to be met, but are strongly recommended. Effective security policies make frequent references to standards and guidelines that exist within an organization.&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;A Security Policy indicates senior management’s commitment to maintaining a secure network, which allows the IT Staff to do a more effective job of securing the company’s information assets. Ultimately, a Security Policy will reduce your risk of a damaging security incident.&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;What is right for me?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;The most important thing to remember when starting the process of developing a Security Policy is that there is no “right” or “wrong” way to go about it. No one policy will work for every organization. There is no generic template that will meet every need. A fantastic policy for Company ABC might be useless to Company XYZ. That being said, a Security Policy must be a &lt;i style=""&gt;custom&lt;/i&gt; document that reflects your company’s specific security needs. In fact, a useless Security Policy is worse than no policy. Companies that boast of Security Policies thicker than a ream of paper are often the ones that have no idea what those policies say. The false sense of security provided by an ineffective policy is dangerous. The point of a Security Policy is not to create “shelfware” that will look good in a binder, but rather to create an actionable and realistic policy that your company can use to manage its security practices. &lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;A Great Framework&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;Having an Information Technology framework for your company is an essential first step in how your technology is being handled internally. Thankfully there is a great framework to help companies accomplish this. &lt;i style=""&gt;The Information Technology Infrastructure Library&lt;/i&gt;, called the &lt;i style=""&gt;ITIL&lt;/i&gt;, is a tool that can help you. It is a customizable framework of good practices designed to promote quality computing services within your company. &lt;i style=""&gt;ITIL&lt;/i&gt; provides a systematic approach to the provisioning and management of IT services. The core parts of this framework include Service Strategy, Service Design, Service Transition and Service Operation, including incident management and security management.&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;Stay tuned for part 3.........&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;Nick Hitchcock&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;OSCP, CEH, CHFI, MCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;NHT Consulting&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;www.nhtconsulting.com &lt;/b&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-7189789122862624282?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/7189789122862624282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/7189789122862624282'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2008/12/internal-net-policies-part-2.html' title='Internal Net Policies part 2'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hWfj6pqRTss/SVUm6N3V3_I/AAAAAAAAAAw/8OJEtXDysH4/s72-c/highrise1.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-4728576282971532562</id><published>2008-12-26T13:25:00.004-05:00</published><updated>2008-12-26T13:34:05.870-05:00</updated><title type='text'>Internal Net Policies. Part 1</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hWfj6pqRTss/SVUjN5xH6AI/AAAAAAAAAAo/ez7wzDwC9DM/s1600-h/Mr.Yuck-713258.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 200px;" src="http://2.bp.blogspot.com/_hWfj6pqRTss/SVUjN5xH6AI/AAAAAAAAAAo/ez7wzDwC9DM/s200/Mr.Yuck-713258.gif" alt="" id="BLOGGER_PHOTO_ID_5284168459541276674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CNick%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073741899 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p 	{mso-style-noshow:yes; 	mso-style-priority:99; 	mso-margin-top-alt:auto; 	margin-right:0in; 	margin-bottom:5.75pt; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:Calibri;} p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing 	{mso-style-priority:1; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt; 	mso-ascii-font-family:Calibri; 	mso-fareast-font-family:Calibri; 	mso-hansi-font-family:Calibri;} @page Section1 	{size:8.5in 11.0in; 	margin:31.5pt 45.0pt 27.0pt 40.5pt; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;span style="font-size:85%;"&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style=";font-family:arial;font-size:85%;"  &gt;&lt;span style="font-size:14;"&gt;I thought a good start to the "re-invigoration" of this blog would be to post a couple articles that have been written for other publication. Enjoy...&lt;/span&gt;&lt;/span&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="font-size:14;"&gt;Internal Network policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;b style=""&gt;&lt;span style="font-size:14;"&gt;Part 1: File Sharing&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Your company has the convenience and accessibility once thought to be science fiction. Files can be transferred to the other side of the planet within seconds. Communication is a snap. Even within the past five to ten years the speeds available in certain areas for Internet have doubled, tripled or even more in speed. But with this convenience as with anything comes abuse. Could your network at this moment be being used for something other than what you intended it?&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;b&gt;&lt;span style=";font-family:&amp;quot;;font-size:13;"  &gt;Does your company have an internal network policy?&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;A recent national survey of U.S. white-collar workers commissioned by ISACA found that more than one-third (35%) of employees have violated their company’s information technology (IT) policies at least once and that nearly one-sixth (15%) of employees have used peer-to-peer file-sharing at least once at their place of business, opening the door to security breaches and placing sensitive business and personal information at risk. Do you have a policy in effect to prevent this? &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;b&gt;&lt;span style=";font-family:&amp;quot;;font-size:13;"  &gt;What exactly is the risk?&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Many file sharing programs are just that, the&lt;span style="color:navy;"&gt;y&lt;/span&gt; “share” files. How so? In many popular easy&lt;span style="color:navy;"&gt;-&lt;/span&gt;to&lt;span style="color:navy;"&gt;-&lt;/span&gt;use file sharing applications&lt;span style="color:navy;"&gt;,&lt;/span&gt; during the initial setup the application may look for files, primarily media files, to allow other users of that particular file sharing network to access. With that in mind think of the following scenario:&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Bob wants to install a file-sharing program on his computer at work for something relatively harmless. He just wants some music to listen to at work. During the setup of the file-sharing application the program installs wonderfully and Bob is ready to get some music and get productive at work. But, there is a problem. During the setup, the file-sharing application found a few media files in a directory to share, one is named “widget-demo.avi” and another is “jingle-music.mp3”. The major problem in this is not the fact that it may have shared your commercial video or jingle music, but that&lt;span style="color:navy;"&gt;,&lt;/span&gt; when this file-sharing program shares those files&lt;span style="color:navy;"&gt;,&lt;/span&gt; it shares the &lt;b style=""&gt;entire&lt;/b&gt; contents of that file folder. What else could be in that folder? Perhaps “Q4-earnings.xls”, “Board_of_Dirs_minutes.doc” or maybe “CompanyFinancial.qbb”. &lt;span style=""&gt; &lt;/span&gt;You get the point,&lt;span style=""&gt;  &lt;/span&gt;this can be very dangerous.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;b&gt;&lt;span style=";font-family:&amp;quot;;font-size:13;"  &gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;File sharing &lt;span style="color:navy;"&gt;is&lt;/span&gt; very useful in some aspects of legitimate business. But, this is only one of the various security risks in allowing a file-sharing application to be installed on an unattended client machine. The fact is most file sharing applications can bypass any firewall security you may have in place negating any steps or investments you may have made to stop network attacks.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt;"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;This is one of the many parts of a full network policy that your company should have. In upcoming articles we will discuss other aspects of a network policy and how to enforce these without restricting productivity.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;Nick Hitchcock,&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;OSCP, CEH, CHFI, MCP&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;NHT Consulting&lt;/p&gt;  &lt;p class="MsoNoSpacing"&gt;&lt;a href="http://www.nhtconsulting.com/"&gt;www.nhtconsulting.com&lt;/a&gt; &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-4728576282971532562?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/4728576282971532562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/4728576282971532562'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2008/12/internal-net-policies-part-1.html' title='Internal Net Policies. Part 1'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hWfj6pqRTss/SVUjN5xH6AI/AAAAAAAAAAo/ez7wzDwC9DM/s72-c/Mr.Yuck-713258.gif' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-6978402981739199757</id><published>2008-12-25T12:53:00.003-05:00</published><updated>2008-12-25T12:59:53.585-05:00</updated><title type='text'>Amazing how things stay around on the net</title><content type='html'>So here I am thinking to myself while redesigning my website, "man I should have one of them there blogs to post hack/sec stuff." So I do what everybody else seems to have done and I go to blogspot.com&lt;br /&gt;I start to sign up and dang! someone already used "nhtc"! I proceed to follow the link and low and behold its ME from 2005. Wow I have a short memory.&lt;br /&gt;&lt;br /&gt;/me proceeds to smack himself in the head with a large trout&lt;br /&gt;(irc folks will get that one hehe)&lt;br /&gt;&lt;br /&gt;Stay tuned for more.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-6978402981739199757?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/6978402981739199757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/6978402981739199757'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2008/12/amazing-how-things-stay-around-on-net.html' title='Amazing how things stay around on the net'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-113500122385978460</id><published>2005-12-19T08:28:00.000-05:00</published><updated>2005-12-19T09:22:14.496-05:00</updated><title type='text'>Windows Critical Updates, More improtant than your data?!?!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/2297/1967/1600/bill_is_borg.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/2297/1967/200/bill_is_borg.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;So there I am, asleep in bed, well sort of. I wasn't sleeping very well that night to begin with but to get to my story. Here comes 3am and what do I hear that breaks the silence of the early morning? Well, its my fancy little "Exiting Windows" wav file. "Hmm" I think. That's odd, because I'm not at my computer and surely nothing on this planet would just make my computer just shut down. So like a good nerd, I have to get up and see what the heck is going on. My system comes back up and to my amazement, I see a nice little balloon message pop up from Microsoft...."You computer was recently AUTOMATICALLY RESTARTED because of a critical update."&lt;br /&gt;&lt;br /&gt;OK... I will let that soak in for a second.........&lt;br /&gt;&lt;br /&gt;Ok, You got that? AUTOMATICALLY RESTARTED!!!! &lt;br /&gt;&lt;br /&gt;Let's look at a simple equation. Microsoft or another technology firm, finds a flaw in windows that may lead to the ability to allow a person to compromise the weakness and damage your data. Sounds simple enough right? Now, the problem is so high on the list of windows problems that someone decides this needs to be applied IMMEDIATELY!!. Good enough, sounds like good ole' MS is looking out for us. &lt;br /&gt;&lt;br /&gt;But, here is my point. MS comes out with a patch to fix a problem so that users WILL NOT lose their valuable data, by rebooting automatically and possibly leading to the loss of DATA!?!?!&lt;br /&gt;&lt;br /&gt;AHHHHHHHHHHHHHHHHHHHH! Anyone else following me on this?&lt;br /&gt;&lt;br /&gt;Here is what happens in Microsoft Speak. "As it turns out, the reboot is actually expected behavior.  You have Automatic Updates on your system configured to Automatically download recommended updates for my computer and install them on a schedule.  When one or more of those updates requires a reboot, the system gets rebooted."&lt;br /&gt;&lt;br /&gt;So it's my fault? Oh i feel better. Thanks. Enngg! Wrong.&lt;br /&gt;&lt;br /&gt;If any of you remember a virus back about four or so years ago, (can't remember the exact name but I think it was "Sircam") This viruexploiteded a critical flaw in NT based OS's (XP is NT based) that caused the system to rebooinexplicablyly when thpersonne logged on to their internet service provider. This virus maker cause "millions" of dollars of damage. They were caught, sent to prison and so forth.&lt;br /&gt;Microsoft has made the exact bi-product with this Auto update feature. NowI'm'm not likening MS to a criminal, although there are times I want to. BUT, this problem needs to be addressed at the highest level. This really is an inconvenience for the user and sometimes worse. Perhaps you were working on a term paper at night, went to bed without saving, it happens to everybody sometimes, we forget to save. But thats ok until BAM! MS restarts your computer!&lt;br /&gt;&lt;br /&gt;Nope! that's not what I want.&lt;br /&gt;&lt;br /&gt;So here are the options........&lt;br /&gt;&lt;br /&gt;1) Turn off Automatic Updates.&lt;br /&gt;      - Well, some people have no problewithth doing this, but with the amount of time that it takes for someone to use MS bulletin and use it maliciously, I wouldn't recommendnd it. Yodon'tnt always remember to run the manual updates. So I would leave this on.&lt;br /&gt;&lt;br /&gt;2)Wait for a fix?&lt;br /&gt;      - In speaking to MS employeeee at a recent MS event, I don't think there is one coming soon. Unless someone REALLY has a fit. It will come to a head, but MS is too busy with their regular biz.&lt;br /&gt;&lt;br /&gt;3)Hacked registry fix.&lt;br /&gt;     EUREKAKA! There we go That's what we need. Let's just turn it off! It turns out there is a registry entry that gets rid of this annoyance and will allow you to save your data and reboot on your own. Don't you feel better now? I know I do! :)&lt;br /&gt;&lt;br /&gt;Here is the link, save to your desktop, double click and say "yes" to add it to the registry.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="http://nhtconsulting.com/files/aureboot.reg"&gt;"Turn off auto reboot" fix&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;Happy Computing! and Pass this info on!&lt;br /&gt;Nick H&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-113500122385978460?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113500122385978460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113500122385978460'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2005/12/windows-critical-updates-more.html' title='Windows Critical Updates, More improtant than your data?!?!'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-113442385706343058</id><published>2005-12-12T16:33:00.000-05:00</published><updated>2005-12-12T17:29:38.710-05:00</updated><title type='text'>Eating Fatty McDonald's food may soon Pay off!</title><content type='html'>I think we now officially are in a true digital age, here is an interesting little story in the New York Times. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"If the Walt Disney Company has its way, McDonald's Happy Meal toys could be replaced with portable media players that hold Disney movies, music, games or photos, according to a pending patent application. Users could add files to the devices by earning points with food purchases.&lt;br /&gt;&lt;br /&gt;The plan could work something like this: A customer enters a restaurant and buys a meal, receiving the portable media player and an electronic code that authorizes a partial download of a movie, video or other media file, which can be downloaded while in the restaurant, according to a United States Patent and Trademark Office application filed by Disney. Then, with each subsequent return, the customer earns more downloadable data, eventually getting an entire movie or game.&lt;br /&gt;&lt;br /&gt;Earning a large file, like a movie, might require five trips - a compelling incentive for a customer to return to the restaurant."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Yeah I'll take a Number 3 supersized with a chunk of Star Wars Episode III please! Ahh CRAP! I already have 5 first half's of the movie! This sucks!&lt;br /&gt;&lt;br /&gt;Once again corporate America pushes society towards digital obesiety.&lt;br /&gt;Yum Yum&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-113442385706343058?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113442385706343058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113442385706343058'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2005/12/eating-fatty-mcdonalds-food-may-soon.html' title='Eating Fatty McDonald&apos;s food may soon Pay off!'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-113440087392513307</id><published>2005-12-12T10:13:00.000-05:00</published><updated>2005-12-12T10:36:40.320-05:00</updated><title type='text'>MS Excel Vulnerability</title><content type='html'>MS Excel Vulnerability? Yup another one. Although this time its a very humerous story how this came to light. &lt;br /&gt;&lt;br /&gt;Eweek had this to say:&lt;br /&gt;---------------------------&lt;br /&gt;What's the retail value of a security vulnerability in Microsoft Corp.'s Excel spreadsheet program? At last check: $53 and counting.&lt;br /&gt;&lt;br /&gt;An unknown security researcher chose a novel way to issue a warning for a code execution flaw in Excel—posting it for sale on eBay. But the auction was pulled late Thursday after discussions between Microsoft and eBay Inc.&lt;br /&gt;&lt;br /&gt;When the auction was squashed, the bidding had reached $53 and had attracted 19 offers.&lt;br /&gt;&lt;br /&gt;A spokeswoman for Microsoft confirmed that the eBay listing was indeed a legitimate security flaw in Excel. "[We] have not been made aware of any attacks attempting to use the reported vulnerability or customer impact at this time, but will continue to investigate the public reports to help provide additional guidance for customers," the spokeswoman said in a statement sent to Ziff Davis Internet News.&lt;br /&gt;&lt;br /&gt;The spokeswoman said the company was investigating the report and working with eBay to determine the appropriate course of action to protect Excel users.&lt;br /&gt;&lt;br /&gt;In the listing, posted by a seller named "fearwall," the issue is described as a zero-day vulnerability that was discovered on Dec. 6, 2005 and reported to Microsoft.&lt;br /&gt;&lt;br /&gt;The seller openly taunts the software giant, poking fun at the company's delays in providing fixes for known security bugs. "It can be assumed that no patch addressing this vulnerability will be available within the next few months. So, since I was unable to find any use for this by-product of Microsoft developers, it is now available for you at the low starting price of $0.01 (a fair value estimation for any Microsoft product)," the listing read.&lt;br /&gt;&lt;br /&gt;It said a percentage of the proceeds from the auction would be contributed to various open-source projects.&lt;br /&gt;&lt;br /&gt;"Microsoft representatives get 10 percent off the final price. To qualify, you MUST provide @microsoft.com e-mail address and MUST mention discount code LINUXRULZ during checkout," it added.&lt;br /&gt;&lt;br /&gt;The seller also provides brief details on the flaw, which occurs because Excel does not perform sufficient data validation when parsing document files.&lt;br /&gt;&lt;br /&gt;"As a result, it is possible to pass a large counter value to "msvcrt.memmove()" function which causes critical memory regions to be overwritten, including the stack space. The vulnerability can be exploited to compromise a user's PC," according to the listing.&lt;br /&gt;&lt;br /&gt;"It is feasible to manipulate the data in the document file to get a code of attacker's choice executed when [a] malicious file is opened by MS Excel. The exploit code is not included in the auction. You must have very advanced skills if you want to further research this vulnerability," it added.&lt;br /&gt;&lt;br /&gt;The seller promised to provide the winning bidder with two .xls files—one file is the original Microsoft Excel document, the other one is a copy of the same document modified to demonstrate the vulnerability.&lt;br /&gt;&lt;br /&gt;"The demonstration merely triggers the exception causing Excel to crash. It does not do anything malicious. A detailed description of the vulnerability will be provided in the message body." &lt;br /&gt;&lt;br /&gt;---------------&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;So Keep your eye on e-bay becuase you never know when a security hole will come up!&lt;/span&gt;&lt;br /&gt;Oh, and if you get a mysterious spreadsheet from anyone, it would probably be a good idea not to open it right now.&lt;br /&gt;&lt;br /&gt;That is of course only a problem if you're using excel. :)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/2297/1967/1600/tux-png-8.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/2297/1967/320/tux-png-8.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-113440087392513307?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113440087392513307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113440087392513307'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2005/12/ms-excel-vulnerability.html' title='MS Excel Vulnerability'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-19798898.post-113439732785231962</id><published>2005-12-12T09:18:00.001-05:00</published><updated>2008-12-25T12:59:02.498-05:00</updated><title type='text'>Well here it goes.</title><content type='html'>Hello All,&lt;br /&gt;    Well after much consideration (at least 5 minutes) I decided to launch this blog. Interesting term "Blog" sounds like a 1950's SiFi movie about brain-eating aliens. hmm....&lt;br /&gt;Anyway, Here it goes. I will try to keep this updated as much as possible. You will find all things Technology related here and also the occasional rant usually about big business or something to that effect.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ENJOY!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19798898-113439732785231962?l=nhtc.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113439732785231962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19798898/posts/default/113439732785231962'/><link rel='alternate' type='text/html' href='http://nhtc.blogspot.com/2005/12/well-here-it-goes.html' title='Well here it goes.'/><author><name>Nick</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='14' src='http://1.bp.blogspot.com/_hWfj6pqRTss/SVPHOQ9K7cI/AAAAAAAAAAM/rfAeeNTmlk8/S220/NHT-logo+Small.JPG'/></author></entry></feed>
