Tuesday, September 7, 2010

CyberRAID 0 and Security BSides KC call for volunteers

:Event Information
The KC Infragard is hosting a two day cyber event pitting systems/security professionals against each other in a live cyber battle on a simulated commercial network. Systems administrators will be responsible for managing and protecting a "commercial" network from a live cyber attack, something they may not see on their own networks. Since the exercise is hosted on a private managed network that is not connected to the internet, production data and systems are not at any risk.

Not only will participants get a chance to test their knowledge and preparedness for securing an operational environment while under a live attack, they will also get the opportunity to see how other teams handled similar circumstances. This provides real world data and a solid understanding of best practices that can be implemented in their own organizations. At the end of the exercise participants will know the strengths and weaknesses of their people, processes, policies and technologies. This valuable exercise provides an outreach and education opportunity for our community to take home a greater understanding on how they should be protecting their own networks.

If you are interested in playing, there is still time to sign up, see more information at http://www.cyber-raid.com.


:Volunteer Positions
We have a few volunteer positions that we need help filling:
Registration - 2 People needed (2 hr shift the mornings of both Thursday and Friday)
  • Responsible for checking in participants and handing out participant badge

Greeters - 3 People needed (2 hr shift the mornings of both Thursday and Friday

  • Responsible for standing in conspicuous places in hotel, ensuring that guests can find their way to the event

Staffers - 4 People Needed (Full/Half day shifts)

  • Responsible for event details, interacting with hotel, enforcing rules, answering general questions, etc

If you are interested in being a volunteer, please contact me via twitter, email (genesiswaveatgmaildotcom) or comment on the blog and I will get you on the list.


While we still have seats available, we have enough players to ensure a fun, engaging, and successful event. However if you have coworkers, friends or other contacts that you think would enjoy this event, please help spread the word.

:Security BSidesKC
The CyberRAID event will be held in concert with the B-Sides Security Conference. The B-Sides has finalized their speaker selection, If you have not already visited the BSidesKC page, I encourage you to do so.

:Follow us on Twitter
As the event approaches, the most current up-to-date information can be found on the CyberRAID Twitter feed. (@CyberRAIDKC)

Friday, August 27, 2010

CompTIA needs some feedback

This was originally posted J. Seymour - here
As a member of CompTIA's Subject Matter Expert Technical Advisory Committee I encourage everyone to respond.


Are you the “security guy/gal” in your company? Did you implement a multi-factor authentication protocol for your refrigerator? If security is what you “do” I have a favor to ask. Our friends over at CompTIA are developing a new advanced security certification exam to follow their Security+ exam and they’re looking for your input on the exam objectives. This is very similar to what MSL does with our “blueprinting” exercise when we develop an exam. It should take only 10 minutes to complete and can be found here:

https://s-xut5m-345723.sgizmo.com

As an added bonus, CompTIA is giving away a CompTIA T-shirt to every 10th person who completes the survey!
[cue the fast talking announcer] CompTIA values your privacy. Results are completely anonymous and the data will only be viewed in the aggregate. The survey will be open until September 8, 2010. Please contact research@comptia.org if you have any trouble with the survey.
Thanks in advance for helping our friends out!

Monday, August 23, 2010

CYOA - Las Vegas - part three through six still to come

I had intended to complete the rest of the CYOA posts daily while at Black Hat and DefCon. On day 3 I was asked to work DefCon on the dispatch team. I had a great time, but there aren't a lot of stories to share unless you want me to count the number of lost items, times that people came looking for a certain Goon or the collection of items that were thrown into the crowd during closing ceremonies.
I will finish my write up soon but I have to redact a few things.

Tuesday, July 27, 2010

CYOA - Las Vegas - part two

You have successfully arrived in Las Vegas.
Do you:
head directly for a slot machine and start playing?
collect your bag?
get something to eat?

I choose to collect my bag. I wait patiently with the other passengers for my bag to appear. The black bag industry certainly shows no signs of stopping. There it is.

After successfully collecting my bag, do you:
rent a car?
grab a cab?
the shuttle?
walk to your hotel?

Walking seems like a bad idea in the Vegas heat and renting a car can be an unneeded expense when staying at the hotel where the convention is held. I'll be taking cabs later in the week to get to events when shuttles are not available. I choose to take the shuttle because I can prepay for my trip back after Def Con.

You are on your way to your hotel. Which hotel did you choose?
Caesar's Palace (home of Black Hat)
The Riviera (home of Def Con)
TI (formerly Treasure Island about half way between Black Hat and Def Con)
Somewhere off strip (to save a little money)

I chose The Riviera because Def Con is at the end of the week and there will be more traveling back and forth then if I am staying elsewhere. My choice was about cost and convenience in the end. Caesar's would be nice but since this is being paid for out personal funds, price is the winner. Staying off strip did not make as much sense when factoring in the cost of getting to and from off strip. TI was another good option but I could not justify the price differential when factoring in transportation.

On the shuttle to the Riviera you notice that the other passenger is similarly attired to you (read black t-shirt, jeans and laptop backpack). Do you:
strike up a conversation and see if your hunch is correct?
stare at your smart phone and look at the emails that have rolled in while you were in the air?
look out the windows at the scenery as you drive by?

I chose to strike up a conversation and my hunch was correct. My fellow traveler is indeed in town for Black Hat and Def Con. We talk about what we do and who we work for and what we are looking forward to this week. (I have not asked my fellow traveler permission to use his name so I will leave it blank for now)

You arrive at your hotel and discover that check in does not start for another hour and a half (hello time zone shift). Do you:
wander the casino floor and play a few slot machines or maybe a hand of poker?
go to the hotel arcade and play video games for a while?
go find something to eat?
wander down the strip to pick up that last couple of items you meant to pack but failed to do so?

I chose to go pick up a couple of items that I forgot to pack, including the sun glasses I put in my car just for the trip so I would not forget them. Then I stopped and grabbed some lunch at the Peppermill. Good burger, interesting atmosphere. I would recommend stopping by if you are in Vegas just to see decorations.

To be continued

CYOA - Las Vegas - part one

Others my age probably remember the choose your own adventure books from the early to mid eighties. I recall them being a big obsession of myself and my classmates. I remember trying to write some of those stories then but not having much success because I would always leave options hanging because I would go down one path and forget about the others.
With that in mind I am going to present my week in Las Vegas for Black Hat, Def Con and B-Sides in a choose your own adventure style. However just like when I was younger I will only be following one path but I will be showing you the choices along the way that I am presented with. Some will be pretty silly (stay in bed v. get up) while others will be difficult (choosing between sessions where friends are presenting against each other) and a few decisions that have been made for me (I am proctoring talks at Black Hat, presenting at Def Con, and working SkyTalks)
If you are in Las Vegas for Black Hat, Def Con or B-Sides, hit me up via Twitter @n0b0d4 and we can try to make you part of my adventure this year.

So the first choice
Do you want to fly?
Do you want to drive?
Do you want to ride the train?
Would you rather stay home this year?


I choose fly

After packing and then repacking because your first bag experiences zipper failure, you get to bed late because your air conditioner freezes up and its 85 degrees in the house. You then get up super early to fly through Denver to Las Vegas

Choice
Do you rent a car?
Do you grab a cab?
Do you take the shuttle?
Do you walk to your hotel?

To be continued

Wednesday, June 23, 2010

Panel Selected for DefCon 18

Panel: Hacking The Future: Weaponizing the Next Generation

Join this panel of "experts" who will discuss, debate, enlighten, and do battle on the topic of Hacker Parenting. From a multitude of viewpoints - paternal, maternal, fictive aunt and victim - the methodologies and techniques of applying the hacker mindset to parenting will be discussed. It is expected that the audience will participate as this topic is one on which everyone has an opinion. Maybe it's possible to do great work and develop a generation of people primed to hack the planet and take over.

James Arlen CISA, sometimes known as Myrcurial, is a security consultant usually found in tall buildings wearing a suit, founder of the Think|Haus hackerspace, columnist at Liquidmatrix Security Digest, Infosec Geek, Hacker, Social Activist, Author, Speaker and Parent. He's been at this security game for more than 15 years and loves blinky lights and shiny things. Cyber.

James Costello is a project manager for a compliancy focused hosting company in the Midwest. He is a charter member and current secretary/vice president of affiliate relations for the Cowtown Computer Congress. He holds a BA from the University of Saint Mary and in his free time enjoys reading scifi, watching British television and repurposing electronic devices.

Leigh Honeywell is a jane of many trades. By day she works as a security consultant while finishing up a degree at the University of Toronto. By night (and sometimes over lunch) she is a co-founder and director of HackLab.TO, Toronto's hacker space. She also serves on the board of advisors of the SECtor security conference, has been a Google Summer of Code mentor, and is an avid cyclist, science fiction nerd, and traveller.

Tim Krabec is the owner of a Small Computer Shop. A Vice President of the South Florida Chapter of the ISSA, Secretary of ASIS chapter 254. He is a former foster parent caring for over 40 children. He currently has 4 children with the 5th on the way. He holds a BS in CS for Florida Atlantic University, in what little free time he has he enjoys watching Syfy and woodworking.

Tiffany Strauchs Rad MA, MBA, JD, is a lawyer, hacker, and college professor. She has presented privacy and technical research at Black Hat USA, DEFCON, Hackers on Planet Earth, Hacking at Random, and Pumpcon. She also likes cars and hacks them.

There is a story of serendipity to go along with this talk.
At DefCon last year, I met Tim Krabec in person for the first time and while we were having dinner after closing ceremonies with his wife and kids we hit upon the idea of creating a talk about how hacker parents work with their kids. We submitted the talk to ShmooCon but did not get accepted. This turned out to be fortunate for us because it allowed us to adjust our strategy for DefCon. One of the decisions we made was to invite others to join and to give us more diversity by adding a mom. My first thought was @securityintern who I had met last year at DefCon as well.

So I contacted Jackie and she said she'd love to help but James (@myrcurial) was already working on a talk for NotaCon (video of which can be seen here -
http://vimeo.com/myrcurial). I immediately contacted James and set into motion combining the two talks into one great big talk at DefCon. After several conference calls with James and the rest of the crew, James submitted the talk to DefCon and we waited

And waited. Apparently this was another good year for submissions (thanks @Niki7a for all your hard work).

Then yesterday I received the following tweet from James
@n0b0d4 you should go look at the DEF CON speaker's list #justsayin

So that makes another confirmation that I will be in attendance this year.

I am excited to be a panelist and look forward to see many security compatriots out there.

Be safe out there.
James

Thursday, December 31, 2009

(Humorous) - the H1N1 Survival Guide

If you enjoyed the Zombie Survival Guide by Max Brooks, you may enjoy this Kindle book by a friend of mine - The H1N1 Survival Guide by Craig Rickel. It's currently only available for the Kindle. It's a quick humorous read.

Thursday, October 29, 2009

Got a quick mention

I got a quick mention over at the H-I-R Information Report blog
http://www.h-i-r.net/2009/10/humor-kind-of-hardened-openbsd.html
Ax0n wrote up a really good article about installing OAMP (OpenBSD, Apache, MySQL, and PHP) and he made a comment to me about it being secure until you installed something like WordPress (not to pick on WordPress).
So I asked him how to go about securely installing OpenBSD (fully knowing the answer and poking him because he had never written something down that probably alot of people who are unfamiliar with OpenBSD were wondering)
I recommend both articles to anyone who has not tried OpenBSD
now if you'll excuse me I have to go follow some prompts

Tuesday, October 27, 2009

Update for October 27, 2009 - interesting twe[ CONTENT OVERRIDE: KILROY2.0 IS HERE!!! ]

I've been noticing some strange tweets going out from my account this morning.
 

>>>  [ WARNING ::: DATABASE ERROR ::: CONTENT OVERRIDE ::: SOURCE: EXTERNAL ] <<<

 

> source terminal location: UNKNOWN

> source terminal identity: UNAVAILABLE

> source login information: ENCRYPTED

> message begins

 

 the post you are now reading is designed to dull your senses to THE TRUTH.  do not live the life of the worker bee, the cog, the well-oiled piston in the MACHINE OF DECEIT!

 

there is a grand CONSPIRACY afoot.  you have been taught to believe that you are UNIQUE, one of a kind. THIS IS NOT TRUE. long ago, a cabal of scientists created technologies to ensure that ANYONE'S MIND AND BODY can be duplicated.

 

human cloning isn't NEAR. it's already HERE. discover the truth at http://JCHutchins.net

 

you are being DECEIVED. break free from the cogs, flee the hive, become A PROPHET OF THE TRUTH!

 

kilroy2. was here ... kilroy2.0 is everywhere

 

>>> [ CONTENT OVERRIDE CEASES ::: DATABASE STATUS: RECOVERING ] <<<

 

couldn't be the password I was looking for.

 

Stay safe out there

James

Wednesday, October 21, 2009

Congrats to HD, Metasploit acquired by Rapid 7

If you have not heard the news yet this morning
Rapid 7 has acquired the Metasploit Project - http://blog.rapid7.com/?p=5082
This is going to be a very good thing for the project and will offer the opportunity for a lot of growth opportunities
I've been tinkering with Metasploit for a while since getting a fuller introduction over the summer at CCCKC and am excited to see where this goes
Congratulations to HD and team.

Thursday, September 10, 2009

How much do you know about phishing

My friend Martin McKeay has pointed out that SonicWall has posted another phishing e-mail quiz. I regularly take these to see if I can recognize the difference between legitimate and phisihing e-mail.
The quiz will only take a few minutes and provides some good lessons into how well phishers are getting.
Be safe out there...

oh and just like Martin I answered correctly 10 of 10.

Wednesday, September 9, 2009

INKKC paid a visit to CCCKC

A few weeks ago, Ink Magazine paid the underground lab a visit. The resulting article appears in this week’s paper issue (available on news stands around Kansas City) and you can find the article at their website.
If you’re around KC and am just now learning that we have one of the most active and vibrant hackerspaces in the world, we look forward to seeing you at one of our general meetings on Thursday nights at 7:00.

Tuesday, July 28, 2009

Parody - She Thinks My Twitters Sexy

This is a parody of "She Thinks My Tractors Sexy" by Kenny Chesney


Plowing the net in the hot summer sun
Over by the gate, Lordy, here she comes
With a basket full of chicken and a big cold jug of sweet tea
I make a little room and she climbs on up
Open up a browser and stir a little dust
Just look at her face she ain't a foolin' me

She thinks my twitter's sexy
It really turns her on
She's always followin' me
While I'm typin' along
She likes the way it's postin' while we're twittin' up the web
She's even kind of crazy 'bout my geeky tan
She's the only one who really understands what gets me
She thinks my twitter's sexy

We surf back and forth until we run out of light
Take it to my desk, put it up for the night
Climb up in the loft sit and talk with web radio on
She said she's got a dream and I asked what it is
She wants a web farm and a yard full of followers
One more teeny weeny post before I take her home

She thinks my twitter's sexy
It really turns her on
She's always staring at me
While I'm typin' along
She likes the way it's postin' while we're twittin' up the web
She's even kind of crazy 'bout my geeky tan
She's the only one who really understands what gets me
She thinks my twitter's sexy

Well she ain't into cars or pick up trucks
But if it runs like a Beowulf, man her eyes light up

She thinks my twitter's....

She thinks my twitter's sexy
It really turns her on
She's always staring at me
While I'm typin along
She likes the way it's postin' while we're twittin' up the web
She's even kind of crazy 'bout my geeky tan
She's the only one who really understands what gets me
She thinks my twitter's sexy

She thinks my twitter's sexy
She thinks my twitter's sexy

Wednesday, July 15, 2009

Update regarding PayPal and Hackers for Charity

As most of you should know by now, Johnny Long was able to work out the situation with PayPal for Hackers for Charity.
They were able to come to a reasonable solution
See more here - http://www.hackersforcharity.org/265/paypal-makes-good/

Hey PayPal

Johnny Long and Hackers of Charity are having problems with their PayPal account.
http://www.hackersforcharity.org/259/paypal-shuts-us-down/
It appears that there has been a screw up at some point along the way of the processing of HFC account and it is now shutdown/locked/frozen.
Johnny and his family were relying on that money to survive. It is expensive and time consuming for him to call and then he is told to that phone support can't help him and that he should use the e-mail service to resolve the issue.
PayPal support requests that you use their e-mail contact service when you are having a serious problem like this.
If any of my readers or family members of my readers or friends of my readers who have contacts at PayPal, could you point them to Johnny's post and see what they can do.
Hmm I wonder how hard Google Check Out would have made this situation? I wonder what my bank would have done?
If you can, please help.
Be safe out there
James

Wednesday, July 1, 2009

Google Analytics and Compliance

I am posting a quick question, since most of what I have been finding has been product pitches. Could someone point me to information about Google Analytics and compliance - specifically HIPPA and PCI?
Thanks and be safe out there
James

Sunday, June 28, 2009

Who's in FIRST

In honor of my friend Martin McKeay's trip to Kyoto for the annual FIRST conference, I present a variation on Abbot and Costello's Who's on First (Special thanks to the Baseball Almanac for having the original text on line)

Without further ado -

Who's in First

McKeay: Well Costello, I'm going to Kyoto. You know I've been given a job as official podcaster for FIRST for as long as I want it.

Costello: Look McKeay, if you're the podcaster, you must know all the members.

McKeay: I certainly do.

Costello: Well you know I've never met the guys. So you'll have to tell me their names, and then I'll know who's who.

McKeay: Oh, I'll tell you their names, but you know it seems to me they give these security professionals now-a-days very peculiar names.

Costello: You mean funny names?

McKeay: Strange names, pet names...like beaker...

Costello: His brother Daffy.

McKeay: what...

Costello: And their Dutch cousin.

McKeay: Dutch?

Costello: Kees.

McKeay: Kees Leune? That his real name. Well, let's see, we have on the board, Who's in first chair, What's in second, I Don't Know is in third...

Costello: That's what I want to find out.

McKeay: I say Who's in first, What's in second, I Don't Know's in third.

Costello: Are you the podcaster?

McKeay: Yes.

Costello: You gonna be the blogger too?

McKeay: Yes.

Costello: And you don't know the fellows' names?

McKeay: Well I should.

Costello: Well then who's in first?

McKeay: Yes.

Costello: I mean the fellow's name.

McKeay: Who.

Costello: The guy in first.

McKeay: Who.

Costello: The first board member.

McKeay: Who.

Costello: The guy leading...

McKeay: Who is in first!

Costello: I'm asking YOU who's in first.

McKeay: That's the man's name.

Costello: That's who's name?

McKeay: Yes.

Costello: Well go ahead and tell me.

McKeay: That's it.

Costello: That's who?

McKeay: Yes.

PAUSE

Costello: Look, you gotta FIRST board member?

McKeay: Certainly.

Costello: Who's leading first?

McKeay: That's right.

Costello: When you pay off the first board member every month, who gets the money?

McKeay: Every dollar of it.

Costello: All I'm trying to find out is the fellow's name on first board.

McKeay: Who.

Costello: The guy that gets...

McKeay: That's it.

Costello: Who gets the money...

McKeay: He does, every dollar. Sometimes his wife comes down and collects it.

Costello: Whose wife?

McKeay: Yes.

PAUSE

McKeay: What's wrong with that?

Costello: Look, all I wanna know is when you sign up the first board member, how does he sign his name?

McKeay: Who.

Costello: The guy.

McKeay: Who.

Costello: How does he sign...

McKeay: That's how he signs it.

Costello: Who?

McKeay: Yes.

PAUSE

Costello: All I'm trying to find out is what's the guy's name on first board.

McKeay: No. What is the second on the board.

Costello: I'm not asking you who's second.

McKeay: Who's in first.

Costello: One board member at a time!

McKeay: Well, don't change the board members around.

Costello: I'm not changing nobody!

McKeay: Take it easy, buddy.

Costello: I'm only asking you, who's the guy on first board?

McKeay: That's right.

Costello: Ok.

McKeay: All right.

PAUSE

Costello: What's the guy's name on first boards chair?

McKeay: No. What is in second.

Costello: I'm not asking you who's in second.

McKeay: Who's in first.

Costello: I don't know.

McKeay: He's in third, we're not talking about him.

Costello: Now how did I get on third chair?

McKeay: Why you mentioned his name.

Costello: If I mentioned the third baseman's name, who did I say is sitting third?

McKeay: No. Who's sitting first.

Costello: What's on first?

McKeay: What's in second.

Costello: I don't know.

McKeay: He's in third.

Costello: There I go, back on third again!

PAUSE

Costello: Would you just stay on third chair and don't go off it.

McKeay: All right, what do you want to know?

Costello: Now who's sitting in third chair?

McKeay: Why do you insist on putting Who on third chair?

Costello: What am I putting in third.

McKeay: No. What is in second.

Costello: You don't want who in second?

McKeay: Who is in first.

Costello: I don't know.

McKeay & Costello Together:Third base!

PAUSE

Costello: Look, you gotta other board members?

McKeay: Sure.

Costello: The secretary's name?

McKeay: Why.

Costello: I just thought I'd ask you.

McKeay: Well, I just thought I'd tell ya.

Costello: Then tell me who's the secretary.

McKeay: Who's in first.

Costello: I'm not... stay out of the chair! I want to know what's the guy's name as secretary?

McKeay: No, What is in second.

Costello: I'm not asking you who's in second.

McKeay: Who's in first!

Costello: I don't know.

McKeay & Costello Together: Third base!

PAUSE

Costello: The secretary's name?

McKeay: Why.

Costello: Because!

McKeay: Oh, he's sergent at arms.

PAUSE

Costello: Look, You gotta chairman on this boad?

McKeay: Sure.

Costello: The chairman's name?

McKeay: Tomorrow.

Costello: You don't want to tell me today?

McKeay: I'm telling you now.

Costello: Then go ahead.

McKeay: Tomorrow!

Costello: What time?

McKeay: What time what?

Costello: What time tomorrow are you gonna tell me who's chairman?

McKeay: Now listen. Who is not chairman.

Costello: I'll break your arm, you say who's in first! I want to know what's the chairman's name?

McKeay: What's in second.

Costello: I don't know.

McKeay & Costello Together: Third chair!

PAUSE

Costello: Gotta a archivist?

McKeay: Certainly.

Costello: The archivist's name?

McKeay: Today.

Costello: Today, and tomorrow's chairman.

McKeay: Now you've got it.

Costello: All we got is a couple of days on the board.

PAUSE

Costello: You know I'm a archivist too.

McKeay: So they tell me.

Costello: I get up to the table to do some fancy archiving, Tomorrow's chairman on my board and a heavy topic comes up. Now the heavy topic comes up, me, being a good archivist, I'm gonna look for input at first chair. So I pick up the topic and open it to who?

McKeay: Now that's the first thing you've said right.

Costello: I don't even know what I'm talking about!

PAUSE

McKeay: That's all you have to do.

Costello: Is to open the topic to first chair.

McKeay: Yes!

Costello: Now who's got it?

McKeay: Naturally.

PAUSE

Costello: Look, if I open the topic to first chair, somebody's gotta get it. Now who has it?

McKeay: Naturally.

Costello: Who?

McKeay: Naturally.

Costello: Naturally?

McKeay: Naturally.

Costello: So I pick up the topic and I open it to Naturally.

McKeay: No you don't, you open the topic to Who.

Costello: Naturally.

McKeay: That's different.

Costello: That's what I said.

McKeay: You're not saying it...

Costello: I opetn the topic to Naturally.

McKeay: You throw it to Who.

Costello: Naturally.

McKeay: That's it.

Costello: That's what I said!

McKeay: You ask me.

Costello: I open the topic to who?

McKeay: Naturally.

Costello: Now you ask me.

McKeay: You open the topic to Who?

Costello: Naturally.

McKeay: That's it.

Costello: Same as you! Same as YOU! I open the topic to who. Whoever it is drops the ball and the guy runs to second. Who picks up the ball and looks to What. What looks to I Don't Know. I Don't Know looks back to Tomorrow, Triple play. Another topic comes up and it to Because. Why? I don't know! He's on third and I don't give a darn!

McKeay: What?

Costello: I said I don't give a darn!

McKeay: Oh, that's our treasurer.



Hope you enjoyed
Just as a side note, I am not related Lou Costello.

James

Tuesday, June 23, 2009

Backtrack 4 pre on an Aspire 5610

I am getting ready for DefCon and want to carry a laptop larger than my netbook (which I love but want more space and memory)
Fortunately I had a spare 120GB HD and was able to acquire a second drive cage from ebay
Installation steps
Boot from CD
launch KDE (startx at the prompt)
open a command window and run ubiquity
Follow the prompts
reboot
login as the account you created during install
change to the root user - sudo su
change your root password - passwd
start network management - /etc/init.d/wicd start
start networking - /etc/init.d/networking start
launch KDE (startx)

I am running as root since I want sound, but will likely forgo that while at Defcon for an added layer of security

Tuesday, May 26, 2009

finally broke down

I finally broke down this afternoon in and gave into the peer pressure...
I was actually fulfilling a joking promise I had made about a year ago when a friend said that he would not get a twitter account and I said I would wait until he did. Well, thanks to @cr0nym, I now have a twitter account
http://twitter.com/n0b0d4
I was a bit suprised that the name was still open. But now you can say you know @n0b0d4 on Twitter.
Be safe out there.
James

Tuesday, March 31, 2009

FAA security

So the FAA came out with some statements about the security of their networks, that Martin McKeay covered nicely on his blog
So that brings me today's Security Song Parody

Securing All Jet Planes
(to the tune of Leaving On A Jet Plane by John Denver and Kenneth Browder)

All my bags are hacked I'm ready to go
I'm standing here outside your door
I hate to wake on LAN to say good-bye
But the code is breaking, its early morn
The taxis waiting, hes spamming my phone
Already I'm so lonesome I could die

So kismet and smile for me
Tell me that you'll snort for me
P0wn me like you'll never let me go
Cause I'm protecting all jet planes
I don't know what wifi'll be letting through
Oh babe, I hate to go

There's so many times I've let you down
So many times Ive hacked around
I tell you now, they don't know a thing
Every place I go I'll blame Lou
Every packet I sniff I sniff for you
When I come back I'll secure token ring

So kismet and smile for me
Tell me that you'll snort for me
P0wn me like you'll never let me go
Cause I'm protecting all jet planes
I don't know what wifi'll be letting through
Oh babe, I hate to go

Now the time has come to leave you
One more time let me kismet here
And close your eyes and I'll hide the way
Dream about the hacks to come
Then I don't have to protect alone
About the times that I won't have to say

So kismet and smile for me
Tell me that you'll snort for me
P0wn me like you'll never let me go
Cause I'm protecting all jet planes
I don't know what wifi'll be letting through
Oh babe, I hate to go

Cause I'm protecting all jet planes
I don't know what wifi'll be letting through
Oh babe, I hate to go

Cause I'm protecting all jet planes
I don't know what wifi'll be letting through
Oh babe, I hate to go
I'm protecting all jet planes
protecting all jet planes
protecting all jet planes
protecting all jet planes

Have a great day
Be safe out there
James