<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MorningStar Security &#187; security</title>
	<atom:link href="http://www.morningstarsecurity.com/blog/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.morningstarsecurity.com</link>
	<description>Keeping you secure</description>
	<lastBuildDate>Wed, 28 Apr 2010 06:50:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Speaking at Indian Security Education &amp; Awareness</title>
		<link>http://www.morningstarsecurity.com/blog/speaking-at-indian-security-education-awareness</link>
		<comments>http://www.morningstarsecurity.com/blog/speaking-at-indian-security-education-awareness#comments</comments>
		<pubDate>Thu, 11 Feb 2010 12:38:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[IIT]]></category>
		<category><![CDATA[lecture]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[workshop]]></category>

		<guid isPermaLink="false">http://www.morningstarsecurity.com/?p=625</guid>
		<description><![CDATA[Tomorrow I leave for India to conduct a workshop at IIT Guwahati, a prestigious Indian university. I was invited by Vivek Ramachandran of Security Tube fame to lecture and provide a workshop on information security for ISEA (Indian Security Education &#038; Awareness) which is a project organised by the Department of Information Technology of the [...]]]></description>
			<content:encoded><![CDATA[<p>Tomorrow I leave for India to conduct a <a href="http://www.iitg.ernet.in/cse/ISEA/tech.html">workshop at IIT Guwahati</a>, a prestigious Indian university. I was invited by <a href="http://www.vivekramachandran.com">Vivek Ramachandran</a> of <a href="http://www.securitytube.net">Security Tube</a> fame to lecture and provide a workshop on information security for <a href="http://www.isea.gov.in/isea/index.jsp">ISEA </a>(Indian Security Education &#038; Awareness) which is a project organised by the Department of Information Technology of the Government of India.</p>
<p>The purpose of ISEA is to improve understanding of IT security so my first thought was that the OWASP Top 10 Risks is perfect for this so I&#8217;m going to explain the new 2010 release candidate list.</p>
<p>Here&#8217;s my talk abstract:<br />
<code>Introduction to web hacking. Information on how to detect, prevent and exploit the top ten most<br />
common web vulnerabilities as specified by OWASP (Open Web Application Security Project). Practical<br />
attack scenarios and demonstrations will be given for each of the classes of vulnerability. The 2010<br />
OWASP Top 10 vulnerability classes are injection, cross site scripting (XSS), broken authentication<br />
and session management, insecure direct object references, cross site request forgery (CSRF),<br />
security misconfiguration, failure to restrict url access, unvalidated redirects and forwards,<br />
insecure cryptographic storage, insufficient transport layer protection. Examples will be given in<br />
PHP because it is the most common web language.<br />
</code></p>
<p>Interestingly enough, IIT is the Indian university joked about in the Dilbert cartoons, here&#8217;s a sample:</p>
<p><img alt="" src="http://www.biocrawler.com/w/images/a/ae/Dilbert_IIT2.gif" title="Dilbert Asok IIT" class="alignnone" width="600" height="205" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.morningstarsecurity.com/blog/speaking-at-indian-security-education-awareness/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Christchurch Information Security Group (CISG) Inaugural Meeting</title>
		<link>http://www.morningstarsecurity.com/blog/christchurch-information-security-group-cisg-inaugural-meeting</link>
		<comments>http://www.morningstarsecurity.com/blog/christchurch-information-security-group-cisg-inaugural-meeting#comments</comments>
		<pubDate>Tue, 26 Jan 2010 03:57:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Christchurch]]></category>
		<category><![CDATA[group]]></category>
		<category><![CDATA[Information Security Interest Group]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[innovation incubator]]></category>
		<category><![CDATA[ISIG]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.morningstarsecurity.com/?p=607</guid>
		<description><![CDATA[Update: CISG has been absorbed into the Information Security Interest Group (ISIG). All meeting details are the same except for the name which is now, ISIG Christchurch Chapter. I&#8217;m setting up the Christchurch Information Security Group (CISG) ISIG Christchurch Chapter to help organise the local Information Security community. It&#8217;s a casual meeting for information security [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Update: </strong>CISG has been absorbed into the Information Security Interest Group (ISIG). All meeting details are the same except for the name which is now, ISIG Christchurch Chapter.</p>
<p>I&#8217;m setting up the <del datetime="2010-01-27T05:54:10+00:00">Christchurch Information Security Group (CISG)</del> ISIG Christchurch Chapter to help organise the local Information Security community. It&#8217;s a casual meeting for information security enthusiasts to network and collaborate on projects. Business, academic and amateur people are welcome. </p>
<p><strong>When: </strong>6.45pm, the last Thursday of the month, beginning Thursday 28th of January.</p>
<p><strong>Where: </strong>Upstairs in the couch area at the Canterbury Innovation Incubator, 200 Armagh St.<br />
The doors to the Canterbury Innovation Incubator will be locked. Press the doorbell inside the open roller doors or TXT 0272 646 959 for entry.</p>
<p>Questions and comments are welcome <img src='http://www.morningstarsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.morningstarsecurity.com/blog/christchurch-information-security-group-cisg-inaugural-meeting/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;New Zealand Web Reconnaisansse with WhatWeb&#8217; at Kiwicon III</title>
		<link>http://www.morningstarsecurity.com/blog/kiwicon-iii</link>
		<comments>http://www.morningstarsecurity.com/blog/kiwicon-iii#comments</comments>
		<pubDate>Tue, 01 Dec 2009 14:02:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[basedomainname]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[bing-ip2hosts]]></category>
		<category><![CDATA[gggooglescan]]></category>
		<category><![CDATA[kiwicon]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaker]]></category>
		<category><![CDATA[whatweb]]></category>

		<guid isPermaLink="false">http://www.morningstarsecurity.com/?p=468</guid>
		<description><![CDATA[I was a speaker at the annual, New Zealand IT security conference, Kiwicon, in Wellington this year. I spoke on &#8220;New Zealand Web Reconnaisansse with WhatWeb&#8221;. Kiwicon is fast growing a reputation as a conference of the highest international standard. Talk abstract: Ever wanted to web scan all of New Zealand but didn&#8217;t have the [...]]]></description>
			<content:encoded><![CDATA[<p>I was a speaker at the annual, New Zealand IT security conference, Kiwicon, in Wellington this year. I spoke on &#8220;New Zealand Web Reconnaisansse with WhatWeb&#8221;. Kiwicon is fast growing a reputation as a conference of the highest international standard.</p>
<blockquote><p><strong>Talk abstract: </strong>Ever wanted to web scan all of New Zealand but didn&#8217;t have the right tools? Me too, so I developed WhatWeb, a next generation website identification scanner. With stealth-mode turned all the way up to 11 it&#8217;s less intrusive than the Google crawler and eminently suitable for large scale internet scanning. Look foward to juicier web statistics than at NetCraft.com and a guided tour to the unindexed websites hidden among NZ&#8217;s 6 million allocated IPs. The web space is littered with voip phones, web cameras, printers, routers and bizzare devices to amaze and astound you. WhatWeb will be officially released at Kiwicon 2009.</p></blockquote>
<p>Tools published at the Kiwicon conference:</p>
<ul>
<li><strong>Whatweb</strong> &#8211; next generation webscanner. <a href="/research/whatweb/">Whatweb homepage</a></li>
<li><strong>bing-ip2hosts</strong> &#8211; Enumerate hostnames from Bing.com for an IP address.<br />
Bing.com is Microsoft’s search engine which has an IP: search parameter. <a href="/research/">Homepage</a></li>
<li><strong>gggooglescan</strong> &#8211; Enumerate hostnames and URLs from Google.<br />
Features: antibot avoidance, search within a country, custom search appliance <a href="/research/">Homepage</a></li>
<li><strong>basedomainname</strong> &#8211; Extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname from fully qualified domain names. <a href="/research/">Homepage</a></li>
</ul>
<p>Link to Kiwicon III presentations : <a href="https://kiwicon.org/presentations/#urbanadventurer">https://kiwicon.org/presentations/#urbanadventurer</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.morningstarsecurity.com/blog/kiwicon-iii/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guest speaker at the NZITF (New Zealand Internet Task Force)</title>
		<link>http://www.morningstarsecurity.com/blog/guest-speaker-at-the-nzitf-new-zealand-internet-task-force</link>
		<comments>http://www.morningstarsecurity.com/blog/guest-speaker-at-the-nzitf-new-zealand-internet-task-force#comments</comments>
		<pubDate>Tue, 01 Dec 2009 13:50:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[NZITF]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[webwatcher]]></category>
		<category><![CDATA[whatweb]]></category>

		<guid isPermaLink="false">http://www.morningstarsecurity.com/?p=455</guid>
		<description><![CDATA[I was a guest speaker at the NZITF (New Zealand Internet Task Force) meeting on Friday, November 27th. I spoke on the topic of WebWatcher and next generation web scanning. I wish to thank Paul McKitrick for inviting me to speak. The talk was well received, I enjoyed presenting and met some interesting people.]]></description>
			<content:encoded><![CDATA[<p>I was a guest speaker at the NZITF (New Zealand Internet Task Force) meeting on Friday, November 27th. I spoke on the topic of WebWatcher and next generation web scanning. I wish to thank Paul McKitrick for inviting me to speak. The talk was well received, I enjoyed presenting and met some interesting people.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.morningstarsecurity.com/blog/guest-speaker-at-the-nzitf-new-zealand-internet-task-force/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
