Posts in Infosec Education
Page Content
PHPSecInfo v0.2 now available
The newest version of PHPSecInfo, version 0.2, is now available. Here are the major changes:
- Added link to "more info" in output. These lead to pages on the phpsec.org site giving more details on the test and what to do if you have a problem
- Modified CSS to improve readability and avoid license issue with PHP (the old CSS was derived from the output of
phpinfo()) - New test:
PhpSecInfo_Test_Session_Save_Path - Added display of "current" and "recommended" settings in test result output
- Various minor changes and bug fixes; see the CHANGELOG for details
-Download now
-Join the mailing list
What’s New at CERIAS
I haven't posted an update lately of new content on our site, so here's a bit of a make-up post:
CERIAS Reports & Papers
-
17 January 2007, 11:00 pm
-
17 January 2007, 11:00 pm
-
22 January 2007, 11:00 pm
CERIAS Hotlist
-
31 January 2007, 7:09 am
-
29 January 2007, 9:10 am
CERIAS News
-
25 January 2007, 9:32 am
-
8 February 2007, 10:22 am
-
15 February 2007, 2:40 pm
-
19 February 2007, 1:09 pm
CERIAS Security Seminar Podcast
-
17 January 2007, 3:30 pm
-
24 January 2007, 3:30 pm
-
31 January 2007, 3:30 pm
VMworld 2006: Teaching (security) using virtual labs
This talk by Marcus MacNeill (Surgient) discussed the Surgient Virtual Training Lab used by CERT-US to train military personnel in security best practices, etc... I was disappointed because the talk didn't discuss the challenges of teaching security, and the lessons learned by CERT doing so, but instead focused on how the product could be used in a teaching environment. Not surprisingly, the Surgient product resembles both VMware's lab manager and ReAssure. However, the Surgient product doesn't support the sharing of images, and stopping and restarting work, e.g. development work by users (from what I saw -- if it does it wasn't mentioned). They mentioned that they had patented technologies involved, which is disturbing (raise your hand if you like software patents). ReAssure meets (or will soon, thanks to the VIX API) all of the requirements he discussed for teaching, except for student shadowing (seeing what a student is attempting to do). So, I would be very interested in seeing teaching labs using ReAssure as a support infrastructure. There are of course other teaching labs using virtualization that have been developed at other universities and colleges; the challenge is of course to be able to design courses and exercises that are portable and reusable. We can all gain by sharing these, but for that we need a common infrastructure where all these exercises would be valid.
The New Security Seminar Podcast
We've made some significant changes to how people can view our Security Seminar Series:
- We're now offering h.264/mp4 versions of the seminar videos, both as downloadable files and in a spanking-new video podcast. Look us up in iTunes or the Democracy channel guide, and you'll find us. The 320x240 videos are not only higher-quality than what we've previously offered, but are also playable on portable players than support h.264 (we've tested it on 5G iPods)
- We will also look at encoding all of our previous recorded seminars to h.264/mp4 in the next few months. Those that we have on DVD will be easy, but the ones more than a couple years old we only have on VHS, so they will likely take a lot longer.
- In the near future — at latest by summer 2007 — we will stop encoding our videos in RealMedia format. The popularity of Real has faded a lot over the years, and most folks (including us) aren't interested in installing it. This would leave us without a streaming video format, but we're not sure there's a lot of demand for one now. If there is, we will likely go with an embedded Flash video player rather than something like Windows Media.
OSCON 2006: PHP Security BOF
So who's going to OSCON 2006? I am, and if you are too, drop me a line so we can meet up. I'm also going to be "moderating" a PHP Security BOF meet, so if you have some interest in PHP Security or secure web dev in general, come by and participate in the chaos.
If you're planning on going, make sure to check out the official wiki and the OSCamp wiki.




