<?xml version="1.0"?>
<!-- name="generator" content="blosxom/2.0" -->
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN" "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">
  <channel>
    <title>extern blog SensePost;   </title>
    <link>http://www.sensepost.com/blog</link>
    <description>doing the web 2.0 thing...</description>
    <language>en</language>

  <item>
    <title>Hacking By Numbers Online - your thoughts?</title>
    <pubDate>Wed, 7 Jan 2009 08:42:00 </pubDate>
    <link>http://www.sensepost.com/blog/2794.html</link>
    <description>
&lt;p&gt;We often get asked by students of our Hacking By Numbers courses if the course environments or at least the VMWare images are available after the training is over. As a result we've started to experiment with a model for offering our courses in an online environment. The idea would be to maintain the full numbers of labs and technical work, maintain the high standard of trainers and materials, but make the training available via the internet to people at various diverse locations. The approach we've been testing appears to show some promise, so we're hoping to ask some of you for your input and opinions.&lt;/p&gt;
&lt;p&gt;The model we have in mind works like this:&lt;/p&gt;
&lt;p&gt;1. Our slide decks have been ported to a Flash format with voice-overs blended in. This allows the students to browse through the materials, pause the presentation and move forward and backward as they please. The voice-over is by an experienced trainer and is presented in the same anecdotal style we use in our regular courses. There's also a transcript of the speaker's presentation that ensures students understand the trainer and allows them to copy and reuse text from the dialog.&lt;/p&gt;
&lt;p&gt;2. The Flash slides are accompanied by the same lab sheets and accompanying answer sheets that are used in our regular training.&lt;/p&gt;
&lt;p&gt;3. In order to complete the labs students connect to a Microsoft Terminal Server over the Internet. Each student has their own desktop that's pre-installed and configured with everything they'll need, including an SSH session to the Linux box that's needed for some of the labs. In this way the student walks right into a clean pre-configured environment with a full Windows and Linux toolset. All the targets, along with the classroom infrastructure like web and DNS servers, are available on virtual networks attached to the Terminal Server.&lt;/p&gt;
&lt;p&gt;4. The course is broken up into a series of 'modules', where a module corresponds to a number of slides from the deck, followed by a lab exercise from the lab sheets. The students can work their way through the slides in the module then tackle the corresponding labs by logging onto the Terminal Server.&lt;/p&gt;
&lt;p&gt;5. Although students work their way through the materials and labs on their own time, they are expected to complete each module within a certain amount of time. At the start and end of each module there is a trainer briefing that occurs via Skype. Students are given an overview of the materials and labs to follow and are given the opportunity to ask questions and make comments.&lt;/p&gt;
&lt;p&gt;6. There is also an interim Skype briefing at fixed times at the start and end of each day. Finally, students have the opportunity to submit questions via email during the course of the day that will be dealt with by the trainer at the next briefing.  In this manner we envisage a two-day classroom being spread over a five-day or even a seven-day period.&lt;/p&gt;
&lt;p&gt;So that's the basic approach. We've started by porting our Cadet Edition in this fashion because it had the least labs and (as a beginners course) seemed to make the most sense. There's a brief course summary at the end of this message. But before we take the course live, we're planning to take it for a few test runs and hopefully get some input and feedback from you. Basically, there are three questions we want to ask:&lt;/p&gt;
&lt;p&gt;1. Have you done online training before?
If you've done online courses, what are your observations? Did it work for you? What did you and didn't you like?&lt;/p&gt;
&lt;p&gt;2. Do you think our online approach is a workable learning tool?
Do you think our approach can work and would you be interested to attend a course presented in this manner?&lt;/p&gt;
&lt;p&gt;3. What would you be prepared to pay for such a course?
Here's some benchmark pricing for you to consider
- A CEH course starts at $ 695.00 (normal pricing seems to be $ 895)
- A SANS @Home hacking course starts at $3,275.00
- The Offensive Security Offsec 101 starts at $ 550.00 (and goes up to about $ 700, without 'options')
- Our Cadet course retails at Black Hat from $ 2,200.00, with fully configured laptops provided
Our total training content amounts to about 2 days. Given this, what do you think would be a fair price to pay for this course?&lt;/p&gt;
&lt;p&gt;Finally, we're planning to hold a free online 'beta' of the course early in 2009. If you'd like to take part, please let us know by contact 'training@sensepost.com'&lt;/p&gt;
</description>
  </item>
  <item>
    <title>&quot;Hooker&quot; approach to break-in!</title>
    <pubDate>Wed, 7 Jan 2009 08:06:00 </pubDate>
    <link>http://www.sensepost.com/blog/2799.html</link>
    <description>
&lt;p&gt;Interesting post on cost/benefit analysis of  hacker and hooker attacks&lt;a href=&quot;http://rdist.root.org/2008/07/21/hacker-or-hooker/&quot; target=&quot;_blank&quot;&gt;.... &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;behrang&lt;/p&gt;
</description>
  </item>
  <item>
    <title>Headhunter: Employers Hate World Of Warcraft Players </title>
    <pubDate>Mon, 5 Jan 2009 16:07:00 </pubDate>
    <link>http://www.sensepost.com/blog/2742.html</link>
    <description>
&lt;p&gt;This is an old post, regurgitated because it yielded some spirited discussion.&lt;/p&gt;
&lt;p&gt;Apparantly headhunters are being told to avoid World of Warcraft players:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.alleyinsider.com/2008/12/headhunter-employers-hate-world-of-warcraft-players&quot; target=&quot;_blank&quot;&gt;http://www.alleyinsider.com/2008/12/headhunter-employers-hate-world-of-warcraft-players&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It's an interesting twist, because a little while back i also recall hearing an itconversations interview on in-game leadership skills..&lt;/p&gt;
&lt;p&gt;My own views on this are mixed.. i find the amount of time spent on gaming to be staggering (at least with gamers ive spoken to)  but ive also heard some pretty hard core hax0rs talking about gaming.. hmm....&lt;/p&gt;
</description>
  </item>
  <item>
    <title>Dont look now, but it seems they broke the Interwebs again..</title>
    <pubDate>Mon, 29 Dec 2008 21:00:00 </pubDate>
    <link>http://www.sensepost.com/blog/2720.html</link>
    <description>
&lt;p&gt;Those pesky hackers!&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://phreedom.org/&quot; target=&quot;_blank&quot;&gt;Alex Sotirov&lt;/a&gt; (of &lt;a href=&quot;http://phreedom.org/research/heap-feng-shui/&quot; target=&quot;_blank&quot;&gt;heap feng shui&lt;/a&gt; fame, famous for breaking everything from &lt;a href=&quot;http://video.google.com/videoplay?docid=-7185841369679533904&quot; target=&quot;_blank&quot;&gt;Vista&lt;/a&gt;, to &lt;a href=&quot;http://phreedom.org/research/bypassing-browser-memory-protections/&quot; target=&quot;_blank&quot;&gt;web browsers&lt;/a&gt;, to &lt;a href=&quot;http://phreedom.org/research/blackbox-reversing-of-xss-filters/&quot; target=&quot;_blank&quot;&gt;facebook&lt;/a&gt;) and Jacob Applebaum (of &lt;a href=&quot;http://citp.princeton.edu/memory/&quot; target=&quot;_self&quot;&gt;cold-boot attack&lt;/a&gt; fame, and more importantly of &quot;&lt;a href=&quot;http://www.appelbaum.net/knuthismyhomeboy.jpg&quot; target=&quot;_blank&quot;&gt;knuth is my homeboy&lt;/a&gt;&quot; fame) will be talking in a few hours at the 25c3 conference in Germany and by all accounts its going to be an &quot;Internet Breaker&quot;.&lt;/p&gt;
&lt;p&gt;There is a fair bit of speculation on the nature of the bug (though most people some confident that its routing protocol related) and &lt;a href=&quot;http://www.breakingpointsystems.com/community/blog/Attacking-Critical-Internet-Infrastructure&quot; target=&quot;_blank&quot;&gt;HD Moore has blogged&lt;/a&gt; that the pair have sought legal advice pre-publishing.&lt;/p&gt;
&lt;p&gt;If i had to, i would take a guess at BGP too, mainly because the talk is labeled &quot;&lt;a href=&quot;http://events.ccc.de/congress/2008/Fahrplan/events/3023.en.html&quot; target=&quot;_blank&quot;&gt;Making the theoretical possible&lt;/a&gt;&quot; which was a tagline used by the l0pht back when they were talking about shutting down the internet with BGP related attacks.&lt;/p&gt;
&lt;p&gt;The only problem i have with all this, is that it reveals confusion over how we measure &quot;the year&quot; when we award &lt;a href=&quot;http://pwnie-awards.org&quot; target=&quot;_blank&quot;&gt;pwnies&lt;/a&gt;.. if the talk happens on the last day (just about) of 2008.. Does it count for pwnies 09??&lt;/p&gt;
&lt;p&gt;/mh&lt;/p&gt;
</description>
  </item>
  <item>
    <title>We going to sue and make Squillions.....</title>
    <pubDate>Mon, 29 Dec 2008 08:02:00 </pubDate>
    <link>http://www.sensepost.com/blog/2714.html</link>
    <description>
&lt;p&gt;or maybe not...
The twitters informed me that &lt;a href=&quot;http://twitter.com/singe&quot; target=&quot;_blank&quot;&gt;Singe&lt;/a&gt; uncovered a case of &lt;a href=&quot;https://singe.za.net/blog/archives/963-Brand-Plagiarism.html&quot; target=&quot;_blank&quot;&gt;brand plagiarism&lt;/a&gt;!!!1!
-snip-
&lt;a href=&quot;/blogstatic/2008/12/singe.png&quot;&gt;&lt;div class=&quot;blog_image&quot;&gt;&lt;img class=&quot;aligncenter size-full wp-image-2715&quot; title=&quot;singe&quot; src=&quot;/blogstatic/2008/12/singe.png&quot; alt=&quot;&quot; width=&quot;500&quot; height=&quot;173&quot; /&gt;&lt;/div&gt;&lt;/a&gt;
-snip-&lt;/p&gt;
&lt;p&gt;So lets review..
&lt;ol&gt;
	&lt;li&gt;the logo looks shockingly the same&lt;/li&gt;
	&lt;li&gt;they no doubt, behind closed doors refer to themselves as SP too&lt;/li&gt;
	&lt;li&gt;just based on their staff numbers, they probably have 16 good looking people there too!&lt;/li&gt;
&lt;/ol&gt;
i had the lawyers lined up but decided to dig more info. on them first..&lt;/p&gt;
&lt;p&gt;We opened doors in 2000, and i was hoping to find proof of these copycats having started like 2 weeks after us.. hmmm..&lt;/p&gt;
&lt;p&gt;According to &lt;a href=&quot;http://en.wikipedia.org/wiki/Schering-Plough&quot; target=&quot;_blank&quot;&gt;wikipedia&lt;/a&gt;: &quot;Schering-Plough Corporation (NYSE: SGP) is a pharmaceutical company founded in 1851&quot; + has &quot;Revenue 	US$ 12.69 billion (2008)&quot;&lt;/p&gt;
&lt;p&gt;Archive.org shows the logo in use &lt;a href=&quot;http://web.archive.org/web/20000301051659/http://www.schering-plough.com/index.html&quot; target=&quot;_blank&quot;&gt;at least back in 2000&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Bah! looks like we will have to make our money some other way!&lt;/p&gt;
&lt;p&gt;/mh&lt;/p&gt;
</description>
  </item>
  </channel>
</rss>