Showing posts with label General InfoSec. Show all posts
Showing posts with label General InfoSec. Show all posts

Sunday, May 5, 2013

Logstalgia: The Next Step In The Network Security?

Ever since the release of Hackers and Johnny Mnemonic, I've longed for a stylish way to represent computer networks. I've always dreamed of having a visual interface that displays network data in a practical manner.  In a sense, I wanted someone to blur the lines between video games and network information.


Has that time finally come?

Logstalgia creates a beautiful visual representation of web traffic.  Logstalgia creates a real-time "pong" like representation of traffic being sent or received by a web server.  The beauty of this plugin is its simplicity.  Even though it's an Apache plugin, it can support multiple log formats. The Google Code website also recommends running Logstalgia on a workstation rather than a web server itself.  It appears that Logstalgia could create a considerable amount overhead in regards to computer resources.





This open source application provides a high level overview of real time web traffic.  Although incredible, I don't believe that this application is 100% practical.  I wouldn't place this application in any type of network operating center.  I believe the bright flashes and colors could become very distracting.  And although the GUI could provide an easily digestible representation to a layman, this visual representation wouldn't yield enough information to someone like an administrator.  With that being said, I would still install it on my web server if I were running one.

Thursday, April 18, 2013

Tuesday, March 5, 2013

How To Install Gnome Classic on Ubuntu 12.10


I love Ubuntu.  I hate the new Unity desktop design.  It's awful.   I understand that it is important for operating systems to keep up with current trends, but I feel that the Unity desktop is awkward and clunky.  Every single time I install Ubuntu I need to re-install the classic GNOME desktop.  This tutorial shows a user how to install GNOME classic.

1.  Log into Ubuntu.  It may be necessary to first update Ubuntu.  You can do this by running
sudo apt-get update or using by using the Update Manager GUI.

BARF!

2.  In the console issue the following command sudo apt-get install gnome-session-fallback

Take that! Crappy GUI...
4. Let Ubuntu run it's magic.  Once completed log out. At the login screen click the little foot icon and then select GNOME Classic. 



5.  Log into the normal Ubuntu desktop.

Sweet Success!


Wednesday, February 20, 2013

Tips on Passing the CISSP Examination

If I had to summarize the Certified Information System Security Professional exam in one word, I would use the word "challenging".  The CISSP can be described as the most coveted certification in the computer security industry.  Prior to taking the exam, I researched what many people had to say about it.  After hearing many contrasting stories, I decided to share my thoughts, incites and opinions on CISSP examination. 

What materials did you use?


Official (ISC)2 Guide to the CISSP -

The Official Guide to the CISSP was my primary source when it came to study materials.  I recommend this book on the sole fact that if officially covers every question on the exam.  This book is very comprehensive but also very dry.  If I had to study for this test over again, I would first check out the Shon Harris All-In One Exam Guide.  I heard the reading in the All-In One Exam Guide is a little more light.


CCCure.org
CCCure.org is an online quiz engine tailored for tests like the CISSP and the Certified Ethical Hacker.  Although the website layout appears to be a bit dated, the quiz engine works like a charm.  The CCCure.org quiz engine has a database full of questions and provides statistics on how well you did in certain areas.  I found this to be the most beneficial!  There is a free limited version of the quiz engine, but I highly recommend the paid version.


What strategies did you use to study?

Study, Study, Study - 

This goes without saying.  Unfortunately there are no short-cuts when it comes to studying.  As long as you have good study material, you should set aside at least one hour a night for 3-5 months.  Schedule yourself an ample amount of time before the exam.  It is important to not study too feverishly or else you will burn yourself out on the abundant amount of facts you will be trying to memorize.  It is also important to take a night off once in a while to drink a beer (if in fact that is what you are into).

Utilize What You Are Studying -
It is very beneficial if you have IT job that allows you to apply your new found knowledge.  Try and apply what you studied to your daily job routine.  For example, if you are studying access control, what access control mechanisms interact with on a daily basis.  Can these access controls be improved or refined? 

What are some good tactics when taking the test?


Use the Process of Elimination -
And use it well! I felt that many of the questions on the CISSP exam were very vague.  I felt that throughout the 80% of the exam I used the process of elimination.

Be Comfortable with the 10 Domains - 
I feel that if you can categorize an uncertain question into one of the 10 domains, you may have better incite when choosing an uncertain answer.  Just for reference, the 10 domains to know are:
  • Access Control
  • Telecommunications
  • Information Security Governance and Risk Managment
  • Software Development Security
  • Cryptography
  • Security Architecture and Design
  • Operation Security
  • Business Continuity and Disaster Recovery Planning
  • Legal, Regulations, Investigations and Compliance
For a more verbose list, click here.

Flag the Questions you Feel Doubtful On -
Now that the CISSP is computerized, it is quick and easy to flag a question for review.  I unfortunately flagged the first 100 questions or so.  Don't do this. It didn't help me.  Only flag the questions you feel very uncertain about.  But by all means, if you have extra time at the end of your exam, skim and review every question possible.

Time Management - 
When taking the exam, you have 6 hours to answer 250 questions.  After the first 100 questions you feel a little brain dead.  Find a way to pace yourself.  Don't spend too much time on one single question.  Flag it and move on, you may have a better grasp on the answer the second time through. 

Pre-Exam Preperations - 
Make sure that you get a solid 7-8 hours of rest the night before.  If possible try to warm your brain up with some practice questions before you start the test.  I didn't but it might help you.  Eat food with fiber and complex carbohydrates.  I prefer oatmeal.  Also, many people say that you shouldn't use cafiene do to the crash, but I dont listen to that because...

I LOVE COFFEE!!!


Conclusion 

The test is challenging, but not impossible by any means.  Many poeple never feel prepared enough going into the exam, but then again I don't think you are supposed to.  The test is very broad and sometimes theoretical.  If you spend a hearty amount of time studying and take some interest in what you are learning, most likely you will be fine.