Wednesday, March 27, 2013
chromium_fix.sh added to Kali-Scripts
As the title says, I added a script called chromium_fix.sh to https://github.com/secjohn/kali-scripts. Chrome won't run as root unless you point it to a different home directory. Which is annoying on Kali since you run as root. That change gets blown away every time the package is updated, which is more annoying. So enter this script. It will setup chromium to run as root. Use it every time the package is updated. I decided to use the Debian package using apt-get install chromium instead of downloading the Chrome deb from Google and installing it, which is what I did for BlackTrack. So far it is updated far less often so this annoying feature isn't as bad. If a few people ask for it I'll make a chrome_fix.sh script as well, it is an easy change. Enjoy.
Tuesday, March 26, 2013
Kali Linux and Update script
If you are one of the few people who read this, you may know I have a BackTrack Linux update script here: https://github.com/secjohn/backtrack-shell-scripts. Well Kali Linux is the new version of BackTrack now and with it there are some new and exciting changes.
Gone are the days where you have to do so many steps to keep things updated. Unlike BackTrack, the Kali packages are going to be kept very current, weekly, or even daily if you go with the bleeding edge option. So most of the steps I took in my BackTrack update script are no longer needed. Also, they won't work in Kali anyway. Most of the tools don't have the git or svn info in the directories so updating them that way doesn't work in Kali. Given then I have made a new repo: https://github.com/secjohn/kali-scripts
It is a much shorter and simpler script. It updates the packages on the system, then manually updates Metasploit, Nessus if you have it, puts an SVN version of Fuzzdb in the /user/share/fuzzdb dir and compiles the SVN version of nmap in /opt/nmap-svn.
Those last two items may not be needed, time will tell. Fuzzdb is already on there and I don't know how often it gets updated anymore. The version of nmap on Kali is really close to the SNV version and when I compared the script directories the SVN one only had a few extra scripts in it. So that may not be needed anymore either and I don't overwrite the packaged nmap. If you want to use the SNV nmap call it directly, or just use the scripts in the directory with the installed nmap.
Time will tell how this goes or what other scripts I add. Feedback and additions and ideas are always welcome.
If you haven't switched over to Kali yet, you should. Seriously, it is nice.
Gone are the days where you have to do so many steps to keep things updated. Unlike BackTrack, the Kali packages are going to be kept very current, weekly, or even daily if you go with the bleeding edge option. So most of the steps I took in my BackTrack update script are no longer needed. Also, they won't work in Kali anyway. Most of the tools don't have the git or svn info in the directories so updating them that way doesn't work in Kali. Given then I have made a new repo: https://github.com/secjohn/kali-scripts
It is a much shorter and simpler script. It updates the packages on the system, then manually updates Metasploit, Nessus if you have it, puts an SVN version of Fuzzdb in the /user/share/fuzzdb dir and compiles the SVN version of nmap in /opt/nmap-svn.
Those last two items may not be needed, time will tell. Fuzzdb is already on there and I don't know how often it gets updated anymore. The version of nmap on Kali is really close to the SNV version and when I compared the script directories the SVN one only had a few extra scripts in it. So that may not be needed anymore either and I don't overwrite the packaged nmap. If you want to use the SNV nmap call it directly, or just use the scripts in the directory with the installed nmap.
Time will tell how this goes or what other scripts I add. Feedback and additions and ideas are always welcome.
If you haven't switched over to Kali yet, you should. Seriously, it is nice.
Friday, February 15, 2013
BackTrack Linux Update Script
I use BackTrack Linux a lot. All the time really. And in-between engagements I like to update the tools I use. The normal apt-get update doesn't really update many of the tools I use. And I like to automate things. So I created a simple shell script to do this. I updated it recently and I already have some more tools in mind to update it again. But what I would really like is comments and even code from others who do the same thing to help make it better and more useful for even more people. I find it interesting what other people see as important enough to update.
I used shell on purpose, to keep it simple and accessible to anyone. A shell script is just running the commands you would normally run on the command line. If you can't handle that then maybe BackTrack isn't what you should be running. I kept the script as simple as possible and over did the comments again to keep it accessible and allow for easy re-use of code for people who don't do a lot of shell scripting.
You can find my update script here: https://github.com/secjohn/backtrack-shell-scripts
I would love your commits here, or if you are a github type person make a branch and give me a pull request and get your code in the script. Just don't break anything.
I used shell on purpose, to keep it simple and accessible to anyone. A shell script is just running the commands you would normally run on the command line. If you can't handle that then maybe BackTrack isn't what you should be running. I kept the script as simple as possible and over did the comments again to keep it accessible and allow for easy re-use of code for people who don't do a lot of shell scripting.
You can find my update script here: https://github.com/secjohn/backtrack-shell-scripts
I would love your commits here, or if you are a github type person make a branch and give me a pull request and get your code in the script. Just don't break anything.
Wednesday, October 3, 2012
My DerbyCon Talk
First let me say how great DerbyCon was, the content, the people, the staff, everything about it was ideal. Second let me thank the people who ran it for selecting my talk. I was surprised and very excited that I got to speak.
My talk was in the small room and against some stiff competition at the 4PM Sat slot and several Chicago land people I know went to Ben0xA's talk instead, which I totally understand. His talk rocked. But the room was almost totally full anyway and I think only one person walked out on me which is rather good for a Con, so it worked out fine I think.
I was pretty nervous in the beginning and talking a bit faster than I needed to, something I even say at some point. I was afraid I would run out of time. Once I noticed how fast I was going I loosened up a bit and remembered to tell the audience to ask questions which I meant to do in the beginning but forgot. So they did, and their questions were great! Several questions reminded me to talk about something that I planed to talk about but forgot like how to say no to people who you have to make sure keep liking you if you want to keep your job. Seriously the questions improved the talk and I love how smart everyone is at Cons like this.
At the end I got a lot of positive feedback and people wanting to continue the conversation which we did at the hotel bar and it was great. For my first talk at a large Con I'm putting this down as a success.
I posted the slides at the securityhangout forum http://forum.securityhangout.org/index.php, the direct link to the post is http://forum.securityhangout.org/index.php.
The video can be seen here: http://www.irongeek.com/i.php?page=videos/derbycon2/4-2-7-john-woods-so-you-got-yourself-an-infosec-manager-job-now-what
All the video's are here: http://www.irongeek.com/i.php?page=videos/derbycon2/mainlist, I recommend checking out tons of them.
Let me know what you think of the talk and slides. I'm always looking to learn and to improve.
My talk was in the small room and against some stiff competition at the 4PM Sat slot and several Chicago land people I know went to Ben0xA's talk instead, which I totally understand. His talk rocked. But the room was almost totally full anyway and I think only one person walked out on me which is rather good for a Con, so it worked out fine I think.
I was pretty nervous in the beginning and talking a bit faster than I needed to, something I even say at some point. I was afraid I would run out of time. Once I noticed how fast I was going I loosened up a bit and remembered to tell the audience to ask questions which I meant to do in the beginning but forgot. So they did, and their questions were great! Several questions reminded me to talk about something that I planed to talk about but forgot like how to say no to people who you have to make sure keep liking you if you want to keep your job. Seriously the questions improved the talk and I love how smart everyone is at Cons like this.
At the end I got a lot of positive feedback and people wanting to continue the conversation which we did at the hotel bar and it was great. For my first talk at a large Con I'm putting this down as a success.
I posted the slides at the securityhangout forum http://forum.securityhangout.org/index.php, the direct link to the post is http://forum.securityhangout.org/index.php.
The video can be seen here: http://www.irongeek.com/i.php?page=videos/derbycon2/4-2-7-john-woods-so-you-got-yourself-an-infosec-manager-job-now-what
All the video's are here: http://www.irongeek.com/i.php?page=videos/derbycon2/mainlist, I recommend checking out tons of them.
Let me know what you think of the talk and slides. I'm always looking to learn and to improve.
Tuesday, October 2, 2012
DerbyCon 2.0
I must say, DerbyCon was great this year. I missed it last year and had high expectations going into it based on what I heard and it was even better than I expected!
First off, checking in took about 30 seconds, seriously. Also I could always get into any talk I wanted to get in and even find a seat. The hotel seemed to like us and people hung out and drank and talked in the lobby all night and it was a ton of fun and very relaxed.
BurbonCon was great, it was like ChiSec, BurbSec, and BurbSec-West all came together in one place. Really the only bad thing was I couldn't see everything I wanted to and the stable talks weren't recorded. I wish I knew they weren't being recorded earlier on I would have gone to more of those, there were some really good ones I missed.
This was also my first time speaking at what I would consider a major conference. I'll blog about my talk separate and not bore you about the content here. But I think it went pretty well. The audience got into it after about 10 minutes when I finally loosened up, I was pretty nervous in the beginning. I got a lot of great questions that moved the talk along and proved how smart everyone in the audience was. And I got some great feedback afterwords which made me feel pretty good. Ryan Reynolds came up to me and told me how much he liked it and he gave one of my favorite talks this year at DEF CON, that really made my day.
All in all it was great. Now I'm hitting http://www.irongeek.com/i.php?page=videos/derbycon2/mainlist to watch some talks I missed. Starting with Ben0xA's talk which was at the same time as mine, I heard it was good and really funny.
First off, checking in took about 30 seconds, seriously. Also I could always get into any talk I wanted to get in and even find a seat. The hotel seemed to like us and people hung out and drank and talked in the lobby all night and it was a ton of fun and very relaxed.
BurbonCon was great, it was like ChiSec, BurbSec, and BurbSec-West all came together in one place. Really the only bad thing was I couldn't see everything I wanted to and the stable talks weren't recorded. I wish I knew they weren't being recorded earlier on I would have gone to more of those, there were some really good ones I missed.
This was also my first time speaking at what I would consider a major conference. I'll blog about my talk separate and not bore you about the content here. But I think it went pretty well. The audience got into it after about 10 minutes when I finally loosened up, I was pretty nervous in the beginning. I got a lot of great questions that moved the talk along and proved how smart everyone in the audience was. And I got some great feedback afterwords which made me feel pretty good. Ryan Reynolds came up to me and told me how much he liked it and he gave one of my favorite talks this year at DEF CON, that really made my day.
All in all it was great. Now I'm hitting http://www.irongeek.com/i.php?page=videos/derbycon2/mainlist to watch some talks I missed. Starting with Ben0xA's talk which was at the same time as mine, I heard it was good and really funny.
Tuesday, September 11, 2012
Securityhangout.org is Born!
I just launched securityhangout.org as a website for IT security folks to hang out, ask questions of their peers, get answers, learn, etc. The main hangout is at forum.securityhangout.org. Right now it is pretty empty, but I really hope people will register and start posting. If I get enough active members I can expand it to include more than just a board to post info. I have a lot of ideas and if the community there grows I'll be asking them for ideas too. But for now I'm going to see if there is a desire for such a place and if it gets traction before putting a lot of effort into it. Here are some of the rules that I hope will get you interested:
1. Be respectful, this isn't a place for flame wars
2. No sales pitches, even in PM's, this is a place for peers to be able to talk
3. No spam or spam like posts
I will be approving membership and monitoring posts and banning people who post spam or are trying to sell a product or themselves instead of contribute. So let's see how this goes. Sign up today and get the cool names before they are gone!
1. Be respectful, this isn't a place for flame wars
2. No sales pitches, even in PM's, this is a place for peers to be able to talk
3. No spam or spam like posts
I will be approving membership and monitoring posts and banning people who post spam or are trying to sell a product or themselves instead of contribute. So let's see how this goes. Sign up today and get the cool names before they are gone!
Saturday, August 25, 2012
Help fix the CISSP
I got my CISSP in 2001. Times were different back then. I wanted a non-vendor security certificate because that was what I was doing and that seemed to be the only game in town. The only other security certs I knew of were vendor ones, firewalls, etc, which I had already. There were no books or study guides you could buy at the book store. There was one book you could buy directly from the author, which I did, but it was unreadable garbage and totally worthless. Getting a CISSP without taking any training seemed daunting. So what I did was searched the Internet and found HTML formats of some presentations that looked to be some basic training. I read those and made my own study guide based on the information that was totally new to me. Stupid Orange Book levels and physical security terms that I have never had a use for to this day. But whatever. The economy sucked in 2001 (by standards up until that point anyway) and I had two weeks of unpaid vacation I had to take. So I took them before the test and studied every day. I was really trying hard to pass this test, one I heard was very hard to pass especially without taking the training.
So I took the test and I was done in about an hour and I felt like I just wasted those two weeks. It seemed very easy to me. I couldn't believe it. Yes there were some Orange Book and CCTV questions, but I really only needed to study for that for a few days. I really over did it. But whatever, I passed (so I found out weeks later) and life is good.
Now over the past decade or so since then here is what I have noticed:
If you do have one, then vote for new leadership! Go here: http://www.novainfosecportal.com/2012/08/23/unofficial-isc2-board-petition-central/ and sign the petition for those four fine people who are looking to fix these problems and when the time comes vote for them, and only them. And every time you get those elections emails from the ISC2, don't ignore them. Look for reformers and vote them in. It make take some time but let's get enough reformers on the board to get this cert and all certs by ISC2 fixed!
So I took the test and I was done in about an hour and I felt like I just wasted those two weeks. It seemed very easy to me. I couldn't believe it. Yes there were some Orange Book and CCTV questions, but I really only needed to study for that for a few days. I really over did it. But whatever, I passed (so I found out weeks later) and life is good.
Now over the past decade or so since then here is what I have noticed:
- The worst security professionals I've ever met had a CISSP
- Most of the really bad security professionals I've met had their CISSP
- I've met a lot of CISSP's that had no real world security experience and were using the cert to try to break into the industry, some have never even worked in IT
- A large number of really good security professionals don't have their CISSP
- I personally know a lot of people who have taken the test, and I have yet to every meet anyone who hasn't passed it, I'm not sure anyone fails it
It turns out I'm not the only one that has noticed those five things. This has lead a to a large number of leaders in the security community to call out the CISSP as worthless, or worse. It doesn't give any assurance that the holder of the cert is competent or experienced. Heck, it doesn't even do the job of establishing a common language in our community. What this means is the cert is getting less valuable, which is bad for everyone that has it. And I think bad for the industry, I think a generic cert like the CISSP could ad a lot of value if done right. I know others disagree, but I'm an optimist.
What this means for you:
If you don't have a CISSP, don't get one until this is fixed! Seriously, stop using it to try to get a job. If you have a job, look elsewhere to advance your career, you won't learn anything worthwhile getting a CISSP as it is today.
If you do have one, then vote for new leadership! Go here: http://www.novainfosecportal.com/2012/08/23/unofficial-isc2-board-petition-central/ and sign the petition for those four fine people who are looking to fix these problems and when the time comes vote for them, and only them. And every time you get those elections emails from the ISC2, don't ignore them. Look for reformers and vote them in. It make take some time but let's get enough reformers on the board to get this cert and all certs by ISC2 fixed!
Subscribe to:
Posts (Atom)