<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISSP Fix</title>
	<atom:link href="http://cisspfix.com/feed" rel="self" type="application/rss+xml" />
	<link>http://cisspfix.com</link>
	<description>Here you can find every bit of information in an interactive way. Enjoy while learning, this will bring best out of you.</description>
	<lastBuildDate>Mon, 08 Mar 2010 05:43:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Penetration Testing &#8211; Whole new trend.</title>
		<link>http://cisspfix.com/penetration-testing-whole-new-trend.html</link>
		<comments>http://cisspfix.com/penetration-testing-whole-new-trend.html#comments</comments>
		<pubDate>Mon, 08 Mar 2010 05:33:51 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/penetration-testing-whole-new-trend.html</guid>
		<description><![CDATA[Its not too long when security professionals needed the system to redefine the security checking methods in corporate world. Its very difficult to compete with the whole Black hat army with bare hands. &#8220;Survivial of the fittest&#8221; to make new world security evolves in penetration testing. 
First question flash in our mind is What on [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fpenetration-testing-whole-new-trend.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fpenetration-testing-whole-new-trend.html" height="61" width="51" /></a></div><p>Its not too long when security professionals needed the system to redefine the security checking methods in corporate world. Its very difficult to compete with the whole Black hat army with bare hands. &#8220;Survivial of the fittest&#8221; to make new world security evolves in penetration testing. </p>
<p>First question flash in our mind is What on Earth is this Penetration testing?</p>
<p>It is basically a process of attacking on a system. Lets take an example: </p>
<p>I am security officer of XYZ Inc. I am concerned about the security of the company&#8217;s network but I am not able to find any loop hole or hot spot, which have potential to crash the network and cause loss of million bucks to company. </p>
<p>Now, What I will do is hire a Penetration testing team and instruct them to penetrate or in general term hack in the network of the company. They will apply all possible attacks all possible technologies to hack into the system. Lets assume that they hacked into the system through SQL injection attack. So now I know that the company&#8217;s system is vulnerable to this attack and I will take the appropriate step to prevent this. </p>
<p>May be this is the weird but to protect ourselves from the cyber attackers we have to be one of those. This is the only way we can think in their way and find out their strategy. </p>
<p>I am on it from last 2 weeks very soon I will post about the certification papers for penetration testing. Its&#8217; still in the process of metamorphism. </p>
<p>I am also considering the books on this subject. Lets see how far I can go.<br />
<img src="http://www.secure-bytes.com/images/img_penetration.gif" alt="Its been done to our system" /></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fpenetration-testing-whole-new-trend.html&amp;linkname=Penetration%20Testing%20%26%238211%3B%20Whole%20new%20trend."><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/penetration-testing-whole-new-trend.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CEH gains new chance against CISSP</title>
		<link>http://cisspfix.com/ceh-gains-new-chance-against-cissp.html</link>
		<comments>http://cisspfix.com/ceh-gains-new-chance-against-cissp.html#comments</comments>
		<pubDate>Fri, 05 Mar 2010 10:03:19 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/ceh-gains-new-chance-against-cissp.html</guid>
		<description><![CDATA[
The U.S. Department of Defense (DoD) announces the official approval of the EC-Council Certified Ethical Hacker (CEH) certification program as a new baseline skills requirement for U.S.cyber defenders. Specifically, the new Certified Ethical Hacker program is required for the DoD&#8217;s computer network defenders (CND&#8217;s), a specialized personnel classification within the DoD&#8217;s information assurance workforce.
The Certified [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fceh-gains-new-chance-against-cissp.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fceh-gains-new-chance-against-cissp.html" height="61" width="51" /></a></div><p><img src="http://www.dnsarrow.co.uk/dns_CMS/uploadedImages/DNS/Training_Services/Security/CEH_fastgrow..gif" alt="EC-Council CEH" /><br />
The U.S. Department of Defense (DoD) announces the official approval of the EC-Council Certified Ethical Hacker (CEH) certification program as a new baseline skills requirement for U.S.cyber defenders. Specifically, the new Certified Ethical Hacker program is required for the DoD&#8217;s computer network defenders (CND&#8217;s), a specialized personnel classification within the DoD&#8217;s information assurance workforce.</p>
<p>The Certified Ethical Hacker requirement falls under the auspices of DoD Directive 8570 Information Assurance Workforce Improvement Program. The current version (incorporating Change 2) was signed by Assistant Secretary of Defense, John G. Grimes and was officially instated on February 25, 2010. Directive 8570 provides clear guidance to information assurance training, certification and workforce management across all components of the DoD. </p>
<p>The CND groups protect, monitor, analyze, detect, and respond to unauthorized activity within DoD information systems and computer networks. </p>
<p>With this directive, military service, contractors, and foreign employees across all job descriptions must show 100-percent compliance with the new Certified Ethical Hacker training requirement by 2011. This shows the DoD&#8217;s focus on better training and preparation of the U.S. military workforce in this area.</p>
<p>The Certified Ethical Hacker qualification tests the certification holder&#8217;s knowledge in the mindset, tools and techniques of a hacker, fortifying it&#8217;s certification tag line: &#8220;To beat a hacker, you must think like one.&#8221; </p>
<p>&#8220;It is one of the most technically advanced certifications on the directive for CND professionals. In fact, it is the only certification approved across four out of the five categories to prepare the CND teams. While other policy-based programs add value, CEH prepares the U.S. CNDs to combat hackers in real time, defending U.S. interests globally.&#8221;</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fceh-gains-new-chance-against-cissp.html&amp;linkname=CEH%20gains%20new%20chance%20against%20CISSP"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/ceh-gains-new-chance-against-cissp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP &#8211; DoD excellence</title>
		<link>http://cisspfix.com/cissp-dod-excellence.html</link>
		<comments>http://cisspfix.com/cissp-dod-excellence.html#comments</comments>
		<pubDate>Thu, 04 Mar 2010 06:23:55 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://cisspfix.com/cissp-dod-excellence.html</guid>
		<description><![CDATA[CISSP is added the Department of Defense Directive 8750. 
In August of 2004, the U.S. Department of Defense recognized Directive 8570.1, which involves that every full- and part-time military service member, defense contractor, civilian and foreign employee with privileged access to a DoD system, regardless of job series or work-related area of expertise, to get [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fcissp-dod-excellence.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fcissp-dod-excellence.html" height="61" width="51" /></a></div><p>CISSP is added the Department of Defense Directive 8750. </p>
<p>In August of 2004, the U.S. Department of Defense recognized Directive 8570.1, which involves that every full- and part-time military service member, defense contractor, civilian and foreign employee with privileged access to a DoD system, regardless of job series or work-related area of expertise, to get a viable certification record that has been recognized by the American National Standards Institute (ANSI) by January 1, 2010 in order to maintain his or her job.</p>
<p>Government agencies know that their best line of defense for securing and protecting their vital information and information systems is a well-trained and aware user. That&#8217;s why DoD Directive 8570.1 was put into place. This enterprise-wide consent requires that any personnel conducting Information Assurance (IA) functions be trained and certified in a commercial certification on the concepts, principles, and applications to enhance protection of the Department of Defense&#8217;s (DoD) information, information systems, and networks.</p>
<p>Department of Defense Directive 8570 (DoD 8570) provides guidance and procedures for the training, certification, and management of all government employees who conduct Information Assurance functions in assigned duty positions. These individuals are required to carry an approved certification for their particular job classification. GIAC certifications are among those required for Technical, Management, CND, and IASAE classifications. </p>
<p>In the next post I will discuss about the levels and posts associated with the CISSP cert exam. </p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fcissp-dod-excellence.html&amp;linkname=CISSP%20%26%238211%3B%20DoD%20excellence"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/cissp-dod-excellence.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IEEE 802.1X authentication</title>
		<link>http://cisspfix.com/ieee-802-1x-authentication-2.html</link>
		<comments>http://cisspfix.com/ieee-802-1x-authentication-2.html#comments</comments>
		<pubDate>Sun, 21 Feb 2010 17:46:57 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://cisspfix.com/ieee-802-1x-authentication-2.html</guid>
		<description><![CDATA[The IEEE 802.1X standard defines a method of authenticating and authorizing users to connect to an IEEE 802 LAN. It blocks users from accessing the network on the failure of authentication. IEEE 802.1X supports the Extensible Authentication Protocol-Transport Level Security (EAP-TLS) and Protected EAP-Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAP v2) protocols. In the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fieee-802-1x-authentication-2.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fieee-802-1x-authentication-2.html" height="61" width="51" /></a></div><p>The IEEE 802.1X standard defines a method of authenticating and authorizing users to connect to an IEEE 802 LAN. It blocks users from accessing the network on the failure of authentication. IEEE 802.1X supports the Extensible Authentication Protocol-Transport Level Security (EAP-TLS) and Protected EAP-Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAP v2) protocols. In the IEEE802.1X authentication system, an access point receives a connection request from a wireless client and forwards the request to the RADIUS server. The RADIUS server then uses the Active Directory database to determine whether the client should be granted access to the network.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fieee-802-1x-authentication-2.html&amp;linkname=IEEE%20802.1X%20authentication"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/ieee-802-1x-authentication-2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firewall design implementation (Access Router)&#8211; Part 1</title>
		<link>http://cisspfix.com/firewall-design-implementation-access-router-part-1.html</link>
		<comments>http://cisspfix.com/firewall-design-implementation-access-router-part-1.html#comments</comments>
		<pubDate>Tue, 16 Feb 2010 06:26:28 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=191</guid>
		<description><![CDATA[The access router is the common name of the exterior router present in the screened host firewall architecture. It is attached to the perimeter network and the internet. Access router is used to protect both the perimeter network and the internal network from the Internet. It allows anything that is outbound from the perimeter network. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Ffirewall-design-implementation-access-router-part-1.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Ffirewall-design-implementation-access-router-part-1.html" height="61" width="51" /></a></div><p>The access router is the common name of the exterior router present in the screened host firewall architecture. It is attached to the perimeter network and the internet. Access router is used to protect both the perimeter network and the internal network from the Internet. It allows anything that is outbound from the perimeter network. Access router seldom do packet filtering. The rules for packet filtering, which is used to protect internal machines are always same on both the interior router and the exterior router.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Ffirewall-design-implementation-access-router-part-1.html&amp;linkname=Firewall%20design%20implementation%20%28Access%20Router%29%26%238211%3B%20Part%201"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/firewall-design-implementation-access-router-part-1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is the land attack?</title>
		<link>http://cisspfix.com/what-is-the-land-attack.html</link>
		<comments>http://cisspfix.com/what-is-the-land-attack.html#comments</comments>
		<pubDate>Sat, 13 Feb 2010 03:05:27 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=184</guid>
		<description><![CDATA[In the land attack, the attacker sends the spoofed TCP SYN packet in which the IP address of the target is filled in both source and destination fields. Now, on receiving the spoofed packet the target system becomes confused and goes into the frozen state. Now-a-days the antivirus can easily detect such attacks.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-the-land-attack.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-the-land-attack.html" height="61" width="51" /></a></div><p>In the land attack, the attacker sends the spoofed TCP SYN packet in which the IP address of the target is filled in both source and destination fields. Now, on receiving the spoofed packet the target system becomes confused and goes into the frozen state. Now-a-days the antivirus can easily detect such attacks.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-the-land-attack.html&amp;linkname=What%20is%20the%20land%20attack%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-the-land-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a teardrop attack?</title>
		<link>http://cisspfix.com/what-is-a-teardrop-attack.html</link>
		<comments>http://cisspfix.com/what-is-a-teardrop-attack.html#comments</comments>
		<pubDate>Fri, 12 Feb 2010 03:04:24 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=182</guid>
		<description><![CDATA[In a teardrop attack, a series of data packets are sent to the target computer with overlapping offset field values. As a result, the target computer is unable to reassemble these packets and is forced to crash, hang, or reboot.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-teardrop-attack.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-teardrop-attack.html" height="61" width="51" /></a></div><p>In a teardrop attack, a series of data packets are sent to the target computer with overlapping offset field values. As a result, the target computer is unable to reassemble these packets and is forced to crash, hang, or reboot.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-teardrop-attack.html&amp;linkname=What%20is%20a%20teardrop%20attack%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-a-teardrop-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a ping of death attack?</title>
		<link>http://cisspfix.com/what-is-a-ping-of-death-attack.html</link>
		<comments>http://cisspfix.com/what-is-a-ping-of-death-attack.html#comments</comments>
		<pubDate>Thu, 11 Feb 2010 03:03:42 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=180</guid>
		<description><![CDATA[In a ping of death attack, the attacker sends an ICMP packet larger than 65,536 bytes. Since the operating system does not know how to handle a packet larger than 65,536 bytes, it either freezes or crashes at the time of reassembling the packet. However, nowadays the operating systems discard such packets, so the ping [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-ping-of-death-attack.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-ping-of-death-attack.html" height="61" width="51" /></a></div><p>In a ping of death attack, the attacker sends an ICMP packet larger than 65,536 bytes. Since the operating system does not know how to handle a packet larger than 65,536 bytes, it either freezes or crashes at the time of reassembling the packet. However, nowadays the operating systems discard such packets, so the ping of death attack is not applicable under these circumstances.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-ping-of-death-attack.html&amp;linkname=What%20is%20a%20ping%20of%20death%20attack%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-a-ping-of-death-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a fraggle DoS attack?</title>
		<link>http://cisspfix.com/what-is-a-fraggle-dos-attack.html</link>
		<comments>http://cisspfix.com/what-is-a-fraggle-dos-attack.html#comments</comments>
		<pubDate>Wed, 10 Feb 2010 03:03:01 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=178</guid>
		<description><![CDATA[In a fraggle DoS attack, an attacker sends a large amount of UDP echo request traffic to the IP broadcast addresses. These UDP requests have a spoofed source address of the intended victim. If the routing device delivering traffic to those broadcast addresses delivers the IP broadcast to all the hosts, most of the IP [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-fraggle-dos-attack.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-fraggle-dos-attack.html" height="61" width="51" /></a></div><p>In a fraggle DoS attack, an attacker sends a large amount of UDP echo request traffic to the IP broadcast addresses. These UDP requests have a spoofed source address of the intended victim. If the routing device delivering traffic to those broadcast addresses delivers the IP broadcast to all the hosts, most of the IP addresses send an ECHO reply message. However, on a multi-access broadcast network, hundreds of computers might reply to each packet when the target network is overwhelmed by all the messages sent simultaneously. Due to this, the network becomes unable to provide services to all the messages and crashes.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-fraggle-dos-attack.html&amp;linkname=What%20is%20a%20fraggle%20DoS%20attack%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-a-fraggle-dos-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a smurf DoS attack?</title>
		<link>http://cisspfix.com/what-is-a-smurf-dos-attack.html</link>
		<comments>http://cisspfix.com/what-is-a-smurf-dos-attack.html#comments</comments>
		<pubDate>Tue, 09 Feb 2010 03:02:17 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=176</guid>
		<description><![CDATA[In a smurf DoS attack, an attacker sends a large amount of ICMP echo request traffic to the IP broadcast addresses. These ICMP requests have a spoofed source address of the intended victim. If the routing device delivering traffic to those broadcast addresses delivers the IP broadcast to all the hosts, most of the IP [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-smurf-dos-attack.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-smurf-dos-attack.html" height="61" width="51" /></a></div><p>In a smurf DoS attack, an attacker sends a large amount of ICMP echo request traffic to the IP broadcast addresses. These ICMP requests have a spoofed source address of the intended victim. If the routing device delivering traffic to those broadcast addresses delivers the IP broadcast to all the hosts, most of the IP addresses send an ECHO reply message. However, on a multi-access broadcast network, hundreds of computers might reply to each packet when the target network is overwhelmed by all the messages sent simultaneously. Due to this, the network becomes unable to provide services to all the messages and crashes.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-a-smurf-dos-attack.html&amp;linkname=What%20is%20a%20smurf%20DoS%20attack%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-a-smurf-dos-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Online Certificate Status Protocol (OCSP)?</title>
		<link>http://cisspfix.com/what-is-online-certificate-status-protocol-ocsp.html</link>
		<comments>http://cisspfix.com/what-is-online-certificate-status-protocol-ocsp.html#comments</comments>
		<pubDate>Mon, 08 Feb 2010 03:00:19 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=172</guid>
		<description><![CDATA[Online Certificate Status Protocol (OCSP) is used for obtaining the revocation status of an X.509 digital certificate. It is used to verify the status of a certificate. It was created as an alternative to certificate revocation lists (CRL). It provides more timely information about the revocation status of a certificate. It also eliminates the need [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-online-certificate-status-protocol-ocsp.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-online-certificate-status-protocol-ocsp.html" height="61" width="51" /></a></div><p>Online Certificate Status Protocol (OCSP) is used for obtaining the revocation status of an X.509 digital certificate. It is used to verify the status of a certificate. It was created as an alternative to certificate revocation lists (CRL). It provides more timely information about the revocation status of a certificate. It also eliminates the need for clients to retrieve the CRLs themselves. Therefore, it generates to less network traffic and provides better bandwidth management. It is described in RFC 2560 and is on the Internet standards track.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-online-certificate-status-protocol-ocsp.html&amp;linkname=What%20is%20Online%20Certificate%20Status%20Protocol%20%28OCSP%29%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-online-certificate-status-protocol-ocsp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Certificate Enrollment Protocol (CEP)?</title>
		<link>http://cisspfix.com/what-is-certificate-enrollment-protocol-cep.html</link>
		<comments>http://cisspfix.com/what-is-certificate-enrollment-protocol-cep.html#comments</comments>
		<pubDate>Sat, 06 Feb 2010 02:59:25 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=170</guid>
		<description><![CDATA[Certificate Enrollment Protocol (CEP) allows Cisco devices to acquire and utilize digital certificates from Certification Authorities (CAs). This protocol is primarily used for deployment of IPSec VPNs while using digital certificate authentication with Cisco devices.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-enrollment-protocol-cep.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-enrollment-protocol-cep.html" height="61" width="51" /></a></div><p>Certificate Enrollment Protocol (CEP) allows Cisco devices to acquire and utilize digital certificates from Certification Authorities (CAs). This protocol is primarily used for deployment of IPSec VPNs while using digital certificate authentication with Cisco devices.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-enrollment-protocol-cep.html&amp;linkname=What%20is%20Certificate%20Enrollment%20Protocol%20%28CEP%29%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-certificate-enrollment-protocol-cep.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Certificate Management Protocol (CMP)?</title>
		<link>http://cisspfix.com/what-is-certificate-management-protocol-cmp.html</link>
		<comments>http://cisspfix.com/what-is-certificate-management-protocol-cmp.html#comments</comments>
		<pubDate>Fri, 05 Feb 2010 02:58:05 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/what-is-certificate-management-protocol-cmp.html</guid>
		<description><![CDATA[Certificate Management Protocol (CMP) provides functionalities for advanced management associated with the use of digital certificates such as certificate issuance, exchange, revocation, invalidation, etc. This protocol is able to operate over any protocol.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-management-protocol-cmp.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-management-protocol-cmp.html" height="61" width="51" /></a></div><p>Certificate Management Protocol (CMP) provides functionalities for advanced management associated with the use of digital certificates such as certificate issuance, exchange, revocation, invalidation, etc. This protocol is able to operate over any protocol.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fwhat-is-certificate-management-protocol-cmp.html&amp;linkname=What%20is%20Certificate%20Management%20Protocol%20%28CMP%29%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-certificate-management-protocol-cmp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISC-2 lacks in Penetration Testing.</title>
		<link>http://cisspfix.com/isc-2-lacks-in-penetration-testing.html</link>
		<comments>http://cisspfix.com/isc-2-lacks-in-penetration-testing.html#comments</comments>
		<pubDate>Thu, 04 Feb 2010 04:31:17 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisspfix.com/isc-2-lacks-in-penetration-testing.html</guid>
		<description><![CDATA[I looked the blooming IT market after lifeless recession, and feel the warm of standing at the higher grounds. ISC-2 got my nerves when I passed CISSP, but I don&#8217;t know what happened to them. I mean can&#8217;t they see the hot cake of today&#8217;s scenario. Yes, guys I am talking about PENETRATION TESTING. 
After [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fisc-2-lacks-in-penetration-testing.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fisc-2-lacks-in-penetration-testing.html" height="61" width="51" /></a></div><p>I looked the blooming IT market after lifeless recession, and feel the warm of standing at the higher grounds. ISC-2 got my nerves when I passed CISSP, but I don&#8217;t know what happened to them. I mean can&#8217;t they see the hot cake of today&#8217;s scenario. Yes, guys I am talking about PENETRATION TESTING. </p>
<p>After being disheartened by ISC-2, I look forward to another vendors. As expected I found two renowned vendors providing certification for Penetration testing&#8211; EC-Council and GIAC.</p>
<p>For EC-Council, You must pass there old famous CEH (312-50) and Security analyst (ECSA-412-79) to become Penetration tester.</p>
<p>For GIAC, You can pass single open book test GPEN to become certified Penetration Testor. </p>
<p>Lets see what else I can find in this new dimension of security. </p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fisc-2-lacks-in-penetration-testing.html&amp;linkname=ISC-2%20lacks%20in%20Penetration%20Testing."><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/isc-2-lacks-in-penetration-testing.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Hot Certifications&#8211; SCNS</title>
		<link>http://cisspfix.com/new-hot-certifications-scns.html</link>
		<comments>http://cisspfix.com/new-hot-certifications-scns.html#comments</comments>
		<pubDate>Tue, 02 Feb 2010 04:14:17 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[SCNS]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=165</guid>
		<description><![CDATA[ I found this paper really helpful, its objectives covered broad domain. 
The Security Certified Network Specialist (SC0-451) certification is designed to examine the knowledge of networking and security skills required by a network security professional. This validation is done basically on the following technologies: Network Defense Fundamentals, Advanced TCP/IP, Routers and Access Control Lists, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fnew-hot-certifications-scns.html"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fnew-hot-certifications-scns.html" height="61" width="51" /></a></div><p> I found this paper really helpful, its objectives covered broad domain. </p>
<p>The Security Certified Network Specialist (SC0-451) certification is designed to examine the knowledge of networking and security skills required by a network security professional. This validation is done basically on the following technologies: Network Defense Fundamentals, Advanced TCP/IP, Routers and Access Control Lists, Designing Firewalls, Configuring Firewalls, Configuring Virtual Private Networks, Designing an Intrusion Detection System, Configuring an Intrusion Detection System and Securing Wireless Networks.</p>
<p>There are no specific prerequisites for this certification but any kind of Security+ certification or its equivalent work experience is recommended.</p>
<p>It provides a track for the following certifications:</p>
<ol>
<li>Security Certified Network Professional (SCNP)</li>
<li>Security Certified Network Architect (SCNA)</li>
<li>Certified Information Systems Security Professional (CISSP)
   </li>
<li>Certified Information Security Manager(CISM)</li>
<li>Certified Wireless Security Professional(CWSP)</li>
<li>Certified Ethical Hacker(CEH)</li>
<li>Cisco Certified Security Professional (CCSP)</li>
</ol>
<p>You will be required to attempt 60 questions in 90 minutes. You need to score 75% to pass the exam.</p>
<p>Having such certification shows the eligibility graph of a candidate in today&#8217;s IT industry. People with security certifications receive consistently more appointments from today&#8217;s industries and get higher base salary, bonuses, and raises as compared with other, less specialized IT positions</p>
<p>You can get more information at <a href="http://www.securitycertified.net/Certifications/SCNS.aspx">Vendor Site</a></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fcisspfix.com%2Fnew-hot-certifications-scns.html&amp;linkname=New%20Hot%20Certifications%26%238211%3B%20SCNS"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/new-hot-certifications-scns.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
