Forensics

The Tennessee Technology Center at Shelbyville will be offering a free Computer Forensics class to Law Enforcement and Information Technology Personnel.  The Tennessee Technology Center at Shelbyville is a member of the Tennessee Board of Regents and is an accredited institution of higher learning recognized by the Department of Education and COE.

Course:                        CFO -101  Cyberforensics
Hours:                          40 hours
Dates:                          May 1 - June 30
Seats:                          30
Award:                         Supplemental Certificate from TTC Shelbyville
Cost:                           This Class Only - Free
Course Requirements: 
Review of All PowerPoint’s and Podcasts class notes on each PowerPoint (Minimum of 10 key points made during the powerpoint) must be emailed to the instructor.
Target Audience:
Law Enforcement and Information Technology (two years preferred)
United States Residence Only
Final Exam:  Before End date of Class
This class is instructor guided - this form of learning and allows the student to study on their
own and submit work at their own pace (see deadline for final dates).  All classwork is due by June 30, 2008.    Instructor:    Steve Mallard, CEI, CEH, MCT

Registration Link

Nigerian Scam Foiled

I always get in the weirdest situations. Link

4.2 Million More Credit Cards

http://www.darkreading.com/document.asp?doc_id=148730&f_src=drweekly

Funny thing is some people wonder why we teach CNDA, CEH and Security+….

Link Stolen Data 200 Million Records

Over 200 million records….. stolen or lost….

http://www.privacyrights.org/ar/ChronDataBreaches.htm

Hopefully IT Personnel are training themselves and staff on how to protect their data. 

National Security Agency - CNSS

nsa.jpg

ECCouncil has met the curriculum requirements for the National Security Agency.  Read More.

The Tennessee Technology Center is now an accredited training center for ECCouncil.

Your Business Computer is Not Secure

A small checklist you can go over to see if your business is secure:

•Do you use Windows XP Home Edition?     If yes, you should be using Win XP Pro.  (Open source is great-Linux)Home does not allow for proper file sharing and other features.
Fact-Windows XP is NOT a server
•Is your partition on your harddrive NTFS?  If not, it should be…if you don’t know, right click your ‘c’ drive and go to properties.
•Do you use the computer for personal use?  If yes, you are inviting malware, spyware and viruses to your computer
•Are your employees using the company computer for personal use?  see above
•Do you get all of your patches and updates for Windows and all third party software (i.e., Quicktime, Office..)? If not, you should be.  Don’t be fooled by going to Microsoft’s update site and then not getting updates for all of the other software on your computer.  Hackers often use third party vulnerabilities to get into your comptuer.
•Are you using complex passwords and changing them frequently?  Th3PaZzw0Rd$ should be changed.
•Are you sharing a folder on a drive?  If so, is it limited to specific users?  If you are using Windows XP home, the whole world can get into the folder.
•Are you using a router (with or without wireless)?  If so, did you change the default password and if it has wireless, did you implement WPA?  Most routers are not true firewalls.  Don’t let this be a false sense of protection.
•Are you using a hardware firewall?  Software firewalls are a good secondary defense.  Secondary. You need a hardware firewall if you are in business.
•Are you training your staff not to be social engineered?   Employees give out information to anyone who seems trustworthy.
•Do you backup off site daily? Log off everytime you leave your computer? ……

These are just a few very basic tips.  Have someone look at your network set-up.  Not your cousin Ed who took a class or setup his own wireless network at home.  Call a true professional  and ask for a penatration test and a security evaluation.

Password Protect a Folder in Windows

MyLockBox is a software security program that helps you protect folders on your computer.  This freeware offers a way to simplify the security of a folder on your Windows computer.  With more and more laptops being stolen, and more confidential documents on your computer, this is an excellent way to help protect your documents.

Digital Picture Frames that Steal Your Identity

You can’t make this up.  Evidently, the Chinese have workers who load a trogan virus on digital picture frames.  The trojan which is advanced, can then jump to your computer and steal your identity (limited for now).  Now if manufacturers don’t have quality standards, viruses can get in through hardware.  Several months ago the Chinese were loading viruses on Seagate computers.  Seagate article.

Deborah Gage’s article; “Trojan Horse probing defenses– New virus is smart, aggressive and blocks antivirus protection at will“, published in the San Fransisco Chronicle, Friday, Feb. 15th. 2008. Business Section.

Now that is scary!

Take a Break from Technology

With cellphones, mobile devices, online gaming, computers, the internet and blogs; take a break, log off and enjoy the great outdoors, go to the local recreation center, go see your family, read a book (no ebooks), take a nap and take a break.  We’ve created a fast paced society. Slow down and enjoy it.  In fact I’m logging off right now…

Analytical Thinking- Think People! Think!

Analytical Thinking follows the scientific approach to problem solving.

Analytical Thinking. Competency Definition: Use a methodical step-by-step approach to break down complex problems or processes into their constituents parts.

As a teacher of information technology, I often leave my students hanging… it’s for their own good.  I use the phrase there are 20 of you in here and there is 120+ lbs of gray matter, help each other.  I’ve had students come back to me and say, “You left me hanging and I had to figure it out on my own! Thanks a lot!”    Now think about that, the instructors at our institution guide the student and help them to a point and then we analyze their ability to analytically think.  Most people see a problem today and totally freak out when all they have to do is stop and break the complex problem down into smaller steps.  Besides, they can “Google it”.

PC Magazine Excellent Article on Security

http://www.pcmag.com/article2/0,2704,2210515,00.asp

Everyone should read this….thanks to David for finding this…

Free - Video Lectures and e-Books

http://www.learnerstv.com/

You can’t beat free. 

Teaching Students How to Hack – Ethically

 - Steve Mallard, MCT, CEI, CEH

Ethically.  When you use the word hack and the word ethically in the same paragraph, it almost is a contradiction of terms.  ECCouncil offers the CEH (Certified Ethical Hacker) certification with several other certifications.  As a teacher, I recently obtained my CEI (Instructor’s Certification).  I now have to look at the students I will be teaching network defense techniques which in essence is the understanding of ‘how-to’ hack.  If we (the older generation of IT Managers) don’t teach the younger generation about the techniques used, the internet will become even more dangerous to use.

The Technology Center in Shelbyille is the only academia institution to be a CompTIA Learning Alliance member recognized in the state of Tennessee.  As Mike Miller and I teach Security+, we teach a lot of defense measures used in protecting your network.  To make our students (interns) more competitive with ‘boot camps’ (who turn out IT ‘wannabees’) we teach CompTIA, Microsoft and now ECCouncil 30 hours a week for two years.  The average student goes to work for average to above average IT wages because of this. Now think about that.   You’re talking about 2100+ hours with the instructor.  Lectures and Labs continuously.  There is no other alternative to learning IT in this fashion.  The introduction of security is emphasized throughout the entire course. 

The role of Security Analyst or the understanding of security now has to be taught at all levels of Information Technology.  If the IT technician is a hardware/software tech, this individual is at the base and core of protecting the network.  These individuals are responsible for protecting your network at the workstation level.  Students memorizing a TestKing or other testing software without the hands on are not truly IT Professionals unless they have the experience with what they are studying.

Several years ago, many blogs said that ECCouncil was a scam.  Now they are one of the most sought after certifications in the IT Industry.  Searches across employment sites show the popularity of this certification for those individuals saying that it is a certification that is easy to obtain, I challenge you to take the four hour exam.  It is one of the hardest and most concise exams I have ever taken.  The material alone will not allow you to pass the exam.  You need hands-on in this area.  ECCouncil now promotes Hacker Halted events globally and host webinars for the public.

As we setup our labs, we will be training students in essence, how to hack.  This becomes a dangerous ‘gray’ area.  We show students what software and hardware they can use to hack a network.  The goal is to show them how to protect their employer or client against such software.  Without these tools, students today will not know how to truly protect their networks.  How many universities, retail stores or government sites have to be hacked before people really wake up to on-line insecurity?

Our job now as teachers is to keep the students from becoming Black Hats…

Spyware that Steals from your Bank Account?

Now how did I miss this?  They estimated in December 2007 over $200,000 was stolen from bank accounts because of the Prg Trojan.  It is estimated that over one million dollars could be stolen…

Secure Works Magazine Article

Do you ever wonder how we will keep up with technology?