<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISSP Fix &#187; Security</title>
	<atom:link href="http://cisspfix.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://cisspfix.com</link>
	<description>Here you can find every bit of information in an interactive way. Enjoy while learning, this will bring best out of you.</description>
	<lastBuildDate>Sat, 10 Dec 2011 05:07:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Setup Firewall on Router</title>
		<link>http://cisspfix.com/setup-firewall-on-router.html</link>
		<comments>http://cisspfix.com/setup-firewall-on-router.html#comments</comments>
		<pubDate>Fri, 07 May 2010 05:14:13 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[firewall design]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[router configuration]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=314</guid>
		<description><![CDATA[Firewall is used to protect the network from external attacks by hackers. Firewall prevents direct communication between computers in the network and the external computers, through the Internet. Instead, all communication is done through a proxy server, outside the organization &#8230; <a href="http://cisspfix.com/setup-firewall-on-router.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fsetup-firewall-on-router.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fsetup-firewall-on-router.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Firewall is used to protect the network from external attacks by hackers. Firewall prevents direct communication between computers in the network and the external computers, through the Internet. Instead, all communication is done through a proxy server, outside the organization s network, which decides whether or not it is safe to let a file pass through. The term firewall now denotes a component or set of components that restrict access, protects, and filters the content passing through a protected network from the Internet. Firewalls can protect a network by screening out harmful files or data from within or outside and prevent its clients from accessing prohibited or harmful websites. The use of a firewall on a router is possible. A number of different router brands or designs like the CISCO collection of routers have options on setting up a basic firewall. A router is a device that diverts or routes information along a specified network.</p>
<p>What you will need in the process:</p>
<ul>
<li>Router</li>
<li>Computer</li>
</ul>
<p>Here we goes with the steps:</p>
<p><strong>Step 1</strong></p>
<p>Choose a router best suited for the computer. There are different types of firewalls that suit different kinds of computers and routers that cater to a user’s specific needs.</p>
<p><strong>Step 2</strong></p>
<p>It is a must to understand a basic firewall. Most routers incorporate a pre-configured basic firewall sufficient for most common needs. This basic firewall is generally adequate to protect the network while allowing the clients of the network appropriate access to be productive. Some users have specific needs that require an advanced degree of customized firewall configuration. Because of this, a router sometimes includes a filter set editor that can make a custom firewall set suitable to answering the specific needs of individual users.</p>
<p><strong>Step 3</strong><br />
To further understand a firewall, some firewall terms must be defined. A host is a computer unit on a network. A packet is a unit of communication on the network and is filtered by packet filters. Packet filters allow or deny packets depending on source or destination IP addresses, the TCP ACK bit or TCP, or UDP ports. The port is a number that defines a particular type of service. The filter rule is a filter set comprised of individual filter rules while a filter set is a group of individual filter rules.</p>
<p><strong>Step 4</strong></p>
<p>Set up a basic firewall on your router. Usually, a firewall is activated by accessing the “Connection Profile” option on the “Quick Menus”. Change Connection Profiles into “IP Profile Parameters then “Filter Set”. This basic firewall will allow traffic originating from the Local Area Network (LAN) to move out and prevent traffic from moving in unless requested by the LAN. You may also check your Router User’s Manual for additional details not found here.</p>
<p><strong>Step 5</strong></p>
<p>Configure your basic firewall according your preference. </p>
<p>Below is the example of configuring CISCO ASA as a transparent firewall&#8230;&#8230;. May be this is not related to the topic directly but will help to understand the procedure. </p>
<p><object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/7fs8F_Qet7c&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/7fs8F_Qet7c&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object> </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fsetup-firewall-on-router.html&amp;title=Setup%20Firewall%20on%20Router"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/setup-firewall-on-router.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>EC-Council focusing on the starters &#8211; Security5 this time</title>
		<link>http://cisspfix.com/ec-council-focusing-on-the-starters-security5-this-time.html</link>
		<comments>http://cisspfix.com/ec-council-focusing-on-the-starters-security5-this-time.html#comments</comments>
		<pubDate>Fri, 30 Apr 2010 04:50:12 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[basic certification]]></category>
		<category><![CDATA[EC-Council]]></category>
		<category><![CDATA[fundamental paper]]></category>
		<category><![CDATA[security5]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=300</guid>
		<description><![CDATA[Security5 is an entry level professional certification for individuals interested in learning computer networking and security basics. This certification program insures an individual&#8217;s competency in basic security matters, such as the definitions and the safe implementation of Firewalls, ports, and &#8230; <a href="http://cisspfix.com/ec-council-focusing-on-the-starters-security5-this-time.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fec-council-focusing-on-the-starters-security5-this-time.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fec-council-focusing-on-the-starters-security5-this-time.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Security5 is an entry level professional certification for individuals interested in learning computer networking and security basics. This certification program insures an individual&#8217;s competency in basic security matters, such as the definitions and the safe implementation of Firewalls, ports, and Anti-virus software. The 5 in the Program name indicates the five components of IT Security, as defined by EC-Council:</p>
<ul>
<li>Intrusion Detection System (IDS)</li>
<li>Firewalls</li>
<li>Anti-Virus</li>
<li>Networking</li>
<li>Web Security</li>
</ul>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fec-council-focusing-on-the-starters-security5-this-time.html&amp;title=EC-Council%20focusing%20on%20the%20starters%20%26%238211%3B%20Security5%20this%20time"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/ec-council-focusing-on-the-starters-security5-this-time.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>EC-Council Kinder Garden Exam &#8211; ECSS</title>
		<link>http://cisspfix.com/ec-council-exam-ecss.html</link>
		<comments>http://cisspfix.com/ec-council-exam-ecss.html#comments</comments>
		<pubDate>Wed, 14 Apr 2010 04:27:15 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[EC-Council]]></category>
		<category><![CDATA[ECSS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=269</guid>
		<description><![CDATA[The field of information security has grown and evolved significantly in recent years. As a career choice, there are many ways of gaining entry into the field. It offers many areas for specialization including: securing networks and allied infrastructure, securing &#8230; <a href="http://cisspfix.com/ec-council-exam-ecss.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fec-council-exam-ecss.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fec-council-exam-ecss.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img src="http://www.telkompdc.com/css/images/ec-council/ECSS.jpg" alt="ecss" /></p>
<p>The field of information security has grown and evolved significantly in recent years. As a career choice, there are many ways of gaining entry into the field. It offers many areas for specialization including: securing networks and allied infrastructure, securing applications and databases, security testing, information systems auditing, business continuity planning, and digital forensics science, to name a few.</p>
<p>Information security professionals are the individuals who restrict the unauthorized access of information and resources. The field of information security has grown and evolved significantly in recent years. As a career choice, there are many ways of gaining entry into the field. It offers many areas for specialization including: securing networks and allied infrastructure, securing applications and databases, security testing, information systems auditing, business continuity planning, and digital forensics science, to name a few.</p>
<p>If you are new in the Information security field, then ECSS certification is the best option for you as it covers all the topics that one needs to know to become a valuable Information security professional. ECSS certification is of EC-Council, which is a well known in field of Information Security, Ethical Hacking, Computer Forensics, and Network Security. The ECSS exam will give a holistic overview of the key components of information security and that will help you to get a good job and/or promotions.</p>
<p>If you are new in the Information security field, then ECSS certification is the best option for you as it covers all the topics that one needs to know to become a valuable Information security professional. ECSS certification is of EC-Council, which is a well known in field of Information Security, Ethical Hacking, Computer Forensics, and Network Security. The ECSS exam will give a holistic overview of the key components of information security and that will help you to get a good job and/or promotions. This Certification provides great opportunity to academic Graduates as well as experienced professionals. </p>
<p>For more information, visit the following link. <a href="http://www.eccouncil.org/certification/ec-council_certified_security_specialist.aspx">http://www.eccouncil.org/certification/ec-council_certified_security_specialist.aspx</a> </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fec-council-exam-ecss.html&amp;title=EC-Council%20Kinder%20Garden%20Exam%20%26%238211%3B%20ECSS"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/ec-council-exam-ecss.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Hacking tools used in penetration testing. Part 8 &#8211; Ettercap</title>
		<link>http://cisspfix.com/hacking-tools-penetration-testing-ettercap.html</link>
		<comments>http://cisspfix.com/hacking-tools-penetration-testing-ettercap.html#comments</comments>
		<pubDate>Tue, 13 Apr 2010 04:55:55 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[network sniffing]]></category>
		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=265</guid>
		<description><![CDATA[Ettercap is a Unix and Windows tool for computer network protocol analysis and security auditing. It is capable of intercepting traffic on a network segment, capturing passwords, and conducting active eavesdropping against a number of common protocols. It is a &#8230; <a href="http://cisspfix.com/hacking-tools-penetration-testing-ettercap.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fhacking-tools-penetration-testing-ettercap.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fhacking-tools-penetration-testing-ettercap.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img src="http://images.ientrymail.com/securitypronews/ettercap_4.gif" alt="ettercap" /></p>
<p>Ettercap is a Unix and Windows tool for computer network protocol analysis and security auditing. It is capable of intercepting traffic on a network segment, capturing passwords, and conducting active eavesdropping against a number of common protocols. It is a free open source software. Ettercap supports active and passive dissection of many protocols (including ciphered ones) and provides many features for network and host analysis. </p>
<p>Ettercap can be downloaded from the following link:  <a href="http://ettercap.sourceforge.net/download.php">http://ettercap.sourceforge.net/download.php</a></p>
<p><object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/hmXJXCiMoCU&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/hmXJXCiMoCU&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object> </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fhacking-tools-penetration-testing-ettercap.html&amp;title=Hacking%20tools%20used%20in%20penetration%20testing.%20Part%208%20%26%238211%3B%20Ettercap"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/hacking-tools-penetration-testing-ettercap.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Famous Hacking Tools used in Penetration testing. &#8211; Netcat</title>
		<link>http://cisspfix.com/famous-hacking-tools-used-in-penetration-testing-netcat.html</link>
		<comments>http://cisspfix.com/famous-hacking-tools-used-in-penetration-testing-netcat.html#comments</comments>
		<pubDate>Mon, 22 Mar 2010 06:35:56 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Netcat]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://cisspfix.com/famous-hacking-tools-used-in-penetration-testing-netcat.html</guid>
		<description><![CDATA[I was wondering from last couple of months with the tools and techniques used to perform penetration testing. So I thought my fellow readers also might be wondering with this tiedious task too. Finally I have decided to post about &#8230; <a href="http://cisspfix.com/famous-hacking-tools-used-in-penetration-testing-netcat.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Ffamous-hacking-tools-used-in-penetration-testing-netcat.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Ffamous-hacking-tools-used-in-penetration-testing-netcat.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I was wondering from last couple of months with the tools and techniques used to perform penetration testing. So I thought my fellow readers also might be wondering with this tiedious task too. Finally I have decided to post about most helpful and comprehensive tools used in this process. </p>
<p>Starting with the Netcat. Please comment on this idea. Is it helpful? or need to do something else. New more things to come, just wait and watch. </p>
<p>NetCat: </p>
<p>Netcat is a networking utility tool, which is used to read and write data across network connections, using the TCP/IP protocol.<br />
It is a reliable &#8220;back-end&#8221; tool that can be used directly or easily driven by other programs and scripts. It is also very efficient in  network debugging and exploration. </p>
<p>Features of Netcat, which drive me to keep it at first place are as follows:</p>
<ol>
<li>outbound or inbound connections, TCP or UDP, to or from any ports</li>
<li>Full DNS forward/reverse checking, with appropriate warnings</li>
<li>Ability to use any local source port</li>
<li>Ability to use any locally-configured network source address</li>
<li>Built-in port-scanning capabilities, with randomization</li>
<li>Built-in loose source-routing capability</li>
<li>Hex dump of transmitted and received data</li>
<li>Optional telnet-options responder</li>
<li>Featured tunneling mode which allows also special tunneling such as UDP to TCP, with the possibility of specifying all network parameters</li>
</ol>
<p>It looks something like this in Linux.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/1/13/Netcat.png" alt="Netcat looks like this." /></p>
<p>and something like this in Windows:</p>
<p><img src="http://www.hackanonymous.com/images/nc_cmd.jpg" alt="Netcat" /></p>
<p>This is a GNU project and can be downloaded <a href="http://netcat.sourceforge.net/download.php">from here</a></p>
<p>More to come. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Ffamous-hacking-tools-used-in-penetration-testing-netcat.html&amp;title=Famous%20Hacking%20Tools%20used%20in%20Penetration%20testing.%20%26%238211%3B%20Netcat"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/famous-hacking-tools-used-in-penetration-testing-netcat.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Cryptographic Attack..out open</title>
		<link>http://cisspfix.com/cryptographic-attack-out-open.html</link>
		<comments>http://cisspfix.com/cryptographic-attack-out-open.html#comments</comments>
		<pubDate>Thu, 11 Mar 2010 02:52:26 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Study notes]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=14</guid>
		<description><![CDATA[Cryptographic attacks are methods of evading the security of a cryptographic system by finding weaknesses in such areas as the code, cipher, cryptographic protocol or key management scheme in the cryptographic algorithm. The following are the cryptographic attacks usually performed &#8230; <a href="http://cisspfix.com/cryptographic-attack-out-open.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fcryptographic-attack-out-open.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fcryptographic-attack-out-open.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Cryptographic attacks are methods of evading the security of a cryptographic system by finding weaknesses in such areas as the code, cipher, cryptographic protocol or key management scheme in the cryptographic algorithm. The following are the cryptographic attacks usually performed by an attacker: Known plaintext attack: In a known plaintext attack, an attacker should have both the plaintext and&#8230;copy of it with the encrypted data. This is used to find patterns in the cryptographic output that might uncover a vulnerability or reveal a cryptographic key.Chosen ciphertext attack: In this type of attack, an attacker can choose the ciphertext to be decrypted and can then analyze the plaintext output of the event. The early versions of RSA used in SSL were actually vulnerable to this attack.  </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fcryptographic-attack-out-open.html&amp;title=Cryptographic%20Attack..out%20open"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/cryptographic-attack-out-open.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Be Air cautious&#8211;Wireless network security</title>
		<link>http://cisspfix.com/be-air-cautious-wireless-network-security.html</link>
		<comments>http://cisspfix.com/be-air-cautious-wireless-network-security.html#comments</comments>
		<pubDate>Fri, 23 Oct 2009 03:49:37 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Wifi]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[wireless security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/be-air-cautious-wireless-network-security.html</guid>
		<description><![CDATA[Wireless networks today are the real needs of the business and technology world as it provides the interconnection between computers without any wires. The bottleneck of location and wires ,costs are all eliminated by the wireless technology. The wireless network &#8230; <a href="http://cisspfix.com/be-air-cautious-wireless-network-security.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fbe-air-cautious-wireless-network-security.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fbe-air-cautious-wireless-network-security.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Wireless networks today are the real needs of the business  and technology world as it provides the interconnection between computers without any wires. The bottleneck of location and wires ,costs are all eliminated by the wireless technology. The wireless network setup concept is very much similar to that of a wired network where instead of the wires only wirelessly connections are made through wave spectrum.</p>
<p>It is a fairly simple setup. The Internet connection comes in from your provider and is connected to a wireless access point or router which broadcasts the signal. You connect wireless antenna network cards to your computers to receive that signal and talk back to the wireless access point and you are in business. </p>
<p><strong>What are the Security issues ?</strong></p>
<p>The risks to users of wireless technology have increased as the service has become more popular. There were relatively few dangers when wireless technology was first introduced. Crackers had not yet had time to latch on to the new technology and wireless was not commonly found in the work place. However, there are a great number of security risks associated with the current wireless protocols and encryption methods, and in the carelessness and ignorance that exists at the user and corporate IT level.Cracking methods have become much more sophisticated and innovative with wireles networks. </p>
<p><strong>What are the different types of wireless security threats?</strong></p>
<p><strong>Denial of service attack</strong></p>
<p>A Denial-of-Service attack (DoS) occurs when an attacker continually bombards a targeted AP (Access Point) or network with bogus requests, premature successful connection messages, failure messages, and/or other commands. These cause legitimate users to not be able to get on the network and may even cause the network to crash. These attacks rely on the abuse of protocols such as the Extensible Authentication Protocol (EAP).</p>
<p> . The usual reason for performing a DoS attack is to observe the recovery of the wireless network, during which all of the initial handshake codes are re-transmitted by all devices, providing an opportunity for the malicious attacker to record these codes and use various &#8220;cracking&#8221; tools to analyze security weaknesses and exploit them to gain unauthorized access to the system. This works best on weakly encrypted systems such as WEP, where there are a number of tools available which can launch a dictionary style attack of &#8220;possibly accepted&#8221; security keys based on the &#8220;model&#8221; security key captured during the network recovery.</p>
<p><strong>Network Injection attack</strong></p>
<p>In a network injection attack, a cracker can make use of access points that are exposed to non-filtered network traffic, specifically broadcasting network traffic such as “Spanning Tree”, OSPF, RIP, and HSRP. The cracker injects bogus networking re-configuration commands that affect routers, switches, and intelligent hubs. A whole network can be brought down in this manner and require rebooting or even reprogramming of all intelligent networking devices.</p>
<p><strong>What to do to detect the intrusion?</strong></p>
<p>A number of times all the prevention schemes fail to provide you the wireless fulproof security. Wireless intrusion detection systems give you the way to deal in the lost conditions. Wireless IDSs can be purchased through a vendor or developed in-house. There are currently only a handful of vendors who offer a wireless IDS solution &#8211; but the products are effective and have an extensive feature set.</p>
<p>Popular wireless IDS solutions include Airdefense RogueWatch and Airdefense Guard , and Internet Security Systems Realsecure Server sensor and wireless scanner products . A homegrown wireless IDS  can be developed with the use of the Linux operating system, for example, and some freely available software. Open source solutions include Snort-Wireless  and WIDZ , among others. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fbe-air-cautious-wireless-network-security.html&amp;title=Be%20Air%20cautious%26%238211%3BWireless%20network%20security"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/be-air-cautious-wireless-network-security.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>What is WHOIS?</title>
		<link>http://cisspfix.com/what-is-whois.html</link>
		<comments>http://cisspfix.com/what-is-whois.html#comments</comments>
		<pubDate>Wed, 21 Oct 2009 04:48:44 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[database query]]></category>
		<category><![CDATA[IP lookup]]></category>
		<category><![CDATA[port 43]]></category>
		<category><![CDATA[whois]]></category>

		<guid isPermaLink="false">http://cisspfix.com/what-is-whois.html</guid>
		<description><![CDATA[WHOIS is a famous protocol chiefly used for database query to determine the information of Internet resources like domain name, IP address, or any autonomous address. WHOIS lookup is basically performed with command user interface. Many web-based tools are available &#8230; <a href="http://cisspfix.com/what-is-whois.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-whois.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-whois.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>WHOIS is a famous protocol chiefly used for database query to determine the information of Internet resources like domain name, IP address, or any autonomous address. WHOIS lookup is basically performed with command user interface. Many web-based tools are available to perform WHOIS query. This service is usually communicated using the Transmission Control Protocol (TCP). Server listens to the request on the port number 43. The WHOIS system is originally developed for the system administrator to acquire contact information for different IP address or domain name administrators. Now a days WHOIS lookup query evolved into various different important aspects, including:</p>
<ul>
<li>It helps in determining the registration status of domain names. </li>
<li>WHOIS also helps in law enforcement by various authorities in investigations for enforcing national and international laws.Specialized non-governmental bodies may be involved in this work of law enforement using this database query service.</li>
<li>WHOIS lookup also help businesses, organizations and users in fighting fraud, complying with relevant laws and safeguarding the interests of the public properties.</li>
</ul>
<p>I was surfing for the same topic and finally I found something very relevent to this topic. So I thought all my readers should also read this. <a href="http://www.ucertify.com/article/what-are-whois-queries.html">Article on Footprinting on uCertify.com</a>. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fwhat-is-whois.html&amp;title=What%20is%20WHOIS%3F"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/what-is-whois.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Get your hand into MD5..</title>
		<link>http://cisspfix.com/get-your-hand-into-md5.html</link>
		<comments>http://cisspfix.com/get-your-hand-into-md5.html#comments</comments>
		<pubDate>Tue, 13 Oct 2009 04:01:33 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[algorithm]]></category>
		<category><![CDATA[checksum]]></category>
		<category><![CDATA[decryption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[MD5]]></category>

		<guid isPermaLink="false">http://cisspfix.com/get-your-hand-into-md5.html</guid>
		<description><![CDATA[What is MD5? MD5 is an algorithm, which is used to check the integrity of the data through the construction of a 128-bit message digest from the input data, which may be a message of any length and is claimed &#8230; <a href="http://cisspfix.com/get-your-hand-into-md5.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fget-your-hand-into-md5.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fget-your-hand-into-md5.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>What is MD5?</strong></p>
<p>MD5 is an algorithm, which is used to check the integrity of the data through the construction of a 128-bit message digest from the input data, which may be a message of any length and is claimed to be as only one of its kind to that specific data. MD5 algorithm was developed by Professor Ronald L. Rivest. This algorithm is originally created to use with digital signature applications, which requires that large files must be compressed by a secure method before being encrypted with a secret key, under a public key cryptosystem. MD5 is currently a standard, Internet Engineering Task Force (IETF) Request for Comments (RFC) 1321. It has been revealed that MD5 is not crash resistant; therefore MD5 algorithm is not suitable for the applications like SSL certificates or digital signatures that rely on this property. An MD5 hash is typically expressed as a 32 digit hexadecimal number. MD5 digests have been extensively used in the software industries to give assurance that the file, which is transferred has arrived unchanged. For example, file servers often provide a pre-computed MD5 checksum for the files, so that a user can compare the checksum of the downloaded file to it. Unix-based operating systems include MD5 sum utilities in their distribution packages, whereas Windows users use third-party applications. MD5 algorithm processes a variable-length message into a fixed-length output of 128 bits. The input message is broken up into pieces of 512-bit blocks; the message is padded so that its length is divisible by 512. The padding works as follows: first a single bit, 1, is appended to the end of the message. This is followed by as many zeros as are required to bring the length of the message up to 64 bits fewer than a multiple of 512. The remaining bits are filled up with a 64-bit integer representing the length of the original message, in bits. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fget-your-hand-into-md5.html&amp;title=Get%20your%20hand%20into%20MD5.."><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/get-your-hand-into-md5.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Things you want to know about CISSP.</title>
		<link>http://cisspfix.com/things-you-want-to-know-about-cissp.html</link>
		<comments>http://cisspfix.com/things-you-want-to-know-about-cissp.html#comments</comments>
		<pubDate>Thu, 01 Oct 2009 03:14:04 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cpe]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[exam]]></category>
		<category><![CDATA[ISC2]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/things-you-want-to-know-about-cissp.html</guid>
		<description><![CDATA[Is CISSP certification is easy? This is pretty controversial topic, some people think that it is easy but most of the people find it real hard. You should have experience of at least 3 years in IT security before you &#8230; <a href="http://cisspfix.com/things-you-want-to-know-about-cissp.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fthings-you-want-to-know-about-cissp.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fthings-you-want-to-know-about-cissp.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Is CISSP certification is easy?</strong></p>
<p>This is pretty controversial topic, some people think that it is easy but most of the people find it real hard. You should have experience of at least 3 years in IT security before you apply for the exam. You are required to come up with an extremely wide area of IT security such as physical security, very few people will have any experience in. And you will be expected to do enough reading and studying to get through CISSP certification exam: 250 questions to be answered in 6 hours. Hard to keep upwith much fun.</p>
<p><strong>Get certified, sit back and enjoy.</strong></p>
<p>The answer is big NO. After you pass the exam you are expected to earn CPE credits in order to keep your certification active. If you don&#8217;t then you are required to resit the exam after 3 years to keep the certification. Getting CPEs is fairly straightforward: if you publish papers, attend seminars, do some presentations, and basically remain active in the IT security arena then you should have no problem here. But it takes a little work: this isn&#8217;t a get-it and forget-it sort of certification.</p>
<p><strong>You will get more money/better job/more recognition.</strong></p>
<p>In actual fact, you probably won&#8217;t. I have found that many employers and even employment agencies have no idea what a CISSP is. They tend to think in terms of the product-certifications; you know, the Cisco CCNA and Checkpoint CCSE sort of thing. They have no idea that you need 3 years of experience to get a CISSP, and they have no idea that it is an ongoing professional-level certification like a CPA (Chartered Accountant). Ergo, you probably won&#8217;t get a better job or more money from waving your CISSP certificate around.</p>
<p>So, why would you want a CISSP? Its not easy to get, it takes maintenance, and may not gain you much. Why would you want to go through all that hassle? Here&#8217;s some good reasons:</p>
<ol>
<li>To expand your knowledge in security concepts and practices.</li>
<li>To show a dedication to the security discipline.</li>
<li>To meet a growing demand for security professionals, and to work in a thriving field.</li>
<li>To join a professional organisation and to link up with like-minded individuals. </li>
</ol>
<p>If you&#8217;re genuinely interested in IT security (cryptography, practices, ethics, etc), and you feel you need a driver to learn more then the CISSP is for you. Book the exam, then start learning as much as possible. On the other hand, if you just want a better job/more money then get an MCSE or CCNA </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fthings-you-want-to-know-about-cissp.html&amp;title=Things%20you%20want%20to%20know%20about%20CISSP."><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/things-you-want-to-know-about-cissp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP..What you want to know.</title>
		<link>http://cisspfix.com/cissp-what-you-want-to-know.html</link>
		<comments>http://cisspfix.com/cissp-what-you-want-to-know.html#comments</comments>
		<pubDate>Wed, 09 Sep 2009 03:06:26 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[administrator]]></category>
		<category><![CDATA[ANSI ISO]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[ISC2]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=43</guid>
		<description><![CDATA[Certified Information Systems Security Professional (CISSP) is an independent information security certification governed by the not-for-profit International Information Systems Security Certification Consortium, commonly known as (ISC)2. In June, 2004, the CISSP was the first information security credential accredited by ANSI &#8230; <a href="http://cisspfix.com/cissp-what-you-want-to-know.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fcissp-what-you-want-to-know.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fcissp-what-you-want-to-know.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Certified Information Systems Security Professional (CISSP) is an independent information security certification governed by the not-for-profit International Information Systems Security Certification Consortium, commonly known as (ISC)2. In June, 2004, the CISSP was the first information security credential accredited by ANSI ISO/IEC Standard 17024:2003 accreditation, and, as such, has led industry acceptance of this global standard and its stringent requirements.It is formally approved by the U.S. Department of Defense (DoD) in both their Information Assurance Technical (IAT) and Managerial (IAM) categories. The CISSP has been adopted as a baseline for the U.S. National Security Agency&#8217;s ISSEP program. (ISC)2 promotes the CISSP certification as the &#8220;international gold standard&#8221; against which other security certifications are measured.</p>
<p>IT professionals with security expertise are often in high demand, and the CISSP is one metric by which that expertise can be demonstrated. A 2006 Certification Magazine salary survey also ranked the CISSP credential highly at $94,070 per year, and ranked CISSP concentration certifications as the top best paid credentials in IT, with CISSP-ISSAPs averaging at $114,210 per year and CISSP-ISSMP at $111,280 per year. These numbers correlate with compensation advantages enjoyed by IT security professionals in general, as well as with advantages accruing to the seniority and management roles that intersect with the concentration certificates. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fcissp-what-you-want-to-know.html&amp;title=CISSP..What%20you%20want%20to%20know."><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/cissp-what-you-want-to-know.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

