<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Northeast Ohio Information Security Forum</title>
	<atom:link href="http://www.neoisf.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.neoisf.org</link>
	<description>Northeast Ohio Information Security Forum</description>
	<lastBuildDate>Sat, 28 Aug 2010 01:38:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.5.1" -->
	<copyright>Copyright &#xA9; Northeast Ohio Information Security Forum 2010 </copyright>
	<managingEditor>board@neoisf.org (Northeast Ohio Information Security Forum)</managingEditor>
	<webMaster>board@neoisf.org (Northeast Ohio Information Security Forum)</webMaster>
	<category>posts</category>
	<ttl>1440</ttl>
	<image>
		<url>http://www.neoisf.org/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Northeast Ohio Information Security Forum</title>
		<link>http://www.neoisf.org</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Northeast Ohio Information Security Forum</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &amp; Culture" />
	<itunes:author>Northeast Ohio Information Security Forum</itunes:author>
	<itunes:owner>
		<itunes:name>Northeast Ohio Information Security Forum</itunes:name>
		<itunes:email>board@neoisf.org</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.neoisf.org/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Register Now! 2010 Information Security Summit October 11-15th</title>
		<link>http://www.neoisf.org/security/register-now-2010-information-security-summit-october-11-15th/</link>
		<comments>http://www.neoisf.org/security/register-now-2010-information-security-summit-october-11-15th/#comments</comments>
		<pubDate>Sat, 28 Aug 2010 01:38:45 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hot Topics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[neoisf]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=290</guid>
		<description><![CDATA[Don&#8217;t get left out, register today for the 2010 Information Security Summit! The 8th Annual Information Security Summit will be held on October 14-15 at Corporate College East, Cleveland Ohio with pre-conference training opportunities held October 11-13. Listed below are just some of the activities and sessions you can experience at this year&#8217;s event: Pre-conference [...]]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t get left out, register today for the 2010 Information Security Summit!</p>
<p>The 8th Annual Information Security Summit will be held on October 14-15 at Corporate College East, Cleveland Ohio with pre-conference training opportunities held October 11-13.  Listed below are just some of the activities and sessions you can experience at this year&#8217;s event:</p>
<p><strong>Pre-conference training classes include:</strong> Social Networks, Malware Analysis, Email Authentication, COBIT(r) Exam Prep, White Collar Forensics &#038; the Investigation Process, Websense Web Security, Linux Security, Ethical Hacking, IT Risk Assessment, Building Effective Security Awareness, Defending Against Social Engineering and Next Generation Firewall Training.</p>
<p><strong>Our Keynotes</strong> include two panel discussions and a general session.  Our panel discussions will cover forensics and privacy.  Our general session will focus on identifying the evil insider and protecting against IP theft.</p>
<p><strong>Our Session topics</strong> include an Introduction to GRC, Privacy &#038; Regulations, Social Networks, Hacking Techniques, E-discovery, Computer Forensics, Security Awareness, Securing the Cloud, Risk Assessment, High Security Locks, Securing VMs, Network Security, Web Application Security, Security Assessment Practices, Honeypots, case studies, and much, much more.</p>
<p>By registering for the conference you will be able to attend our Thursday evening networking reception.  This reception provides you an opportunity to get reacquainted with some old friends and business associates, as well as make new business contacts.</p>
<p>The Information Security Summit is a registered non-profit organization run by volunteers with a mission to bring quality, cost-effective training to Northeast Ohio.  Visit our website at <a href="http://www.informationsecuritysummit.org">www.informationsecuritysummit.org</a> for event details and registration information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/security/register-now-2010-information-security-summit-october-11-15th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 18th NEOISF Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/august-18th-neoisf-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/august-18th-neoisf-meeting-announcement/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 01:28:18 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[hope]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tom]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=287</guid>
		<description><![CDATA[Our next meeting is this WEDNESDAY August 18, 2010. Pizza and networking start at 6:00 PM. Talks start at 6:30 PM. Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio. Click here for a Google Map! Open to everyone and free as always! Here are the list of talks and [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is this WEDNESDAY August 18, 2010. Pizza and networking start at 6:00 PM. Talks start at 6:30 PM. Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio. <a href="http://maps.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;time=&#038;date=&#038;ttype=&#038;q=6150+Oak+Tree+Blvd,+independence+oh&#038;sll=41.396614,-81.661634&#038;sspn=0.002704,0.004131&#038;ie=UTF8&#038;ll=41.39694,-81.660937&#038;spn=0.002704,0.004131&#038;t=h&#038;z=18&#038;om=1">Click here for a Google Map!</a> Open to everyone and free as always! Here are the list of talks and agenda items for this months meeting:</p>
<p><strong>Overview of The Next HOPE Conference &#8211; Jody McCluggage</strong><br />
The HOPE (Hackers on Planet Earth) conference is a biennial conference held in New York City and sponsored by 2600.  A high level overview will be given of the events, presentations, and politics at the most recent conference.</p>
<p><strong>Return of the Social Zombies &#8211; Tom Eston</strong><br />
Tom Eston, the only survivor of the zombie apocalypse that took place at Shmoocon this year, examines the risks of social networks and discusses techniques and tools that can be used to exploit these issues. This presentation begins by discussing new twists on existing privacy concerns that are caused by the trust mass that is social networks. This privacy confusion is used to exploit members and their companies during penetration tests.  The presentation then discusses social network botnets and bot programs. Both the delivery of malware through social networks and the use of these social networks as command and control channels will be examined. Tom then explores the use of browser-based bots and their delivery through custom social network applications and shows new social network applications can be used for malware delivery.  Finally, the information available through the social network APIs is explored using third-party applications designed for penetration testing. This allows for complete coverage of the targets and their information.</p>
<p><strong>Speaker Bios:</strong></p>
<p><strong>Jody McCluggage</strong> (CISSP, CCNA, CEH, MCTS, CHP, Network+) – Director of Operations and Compliance at a local government agency.</p>
<p><strong>Tom Eston</strong> is a Senior Security Consultant for SecureState.  Tom has previously served in many security roles for large enterprises including leading a penetration testing team for a Fortune 500 financial institution. Tom is actively involved in the security community and focuses his research on the security of social media. He is the founder of SocialMediaSecurity.com which is an open source community dedicated to exposing the insecurities of social media.  Tom is also a security blogger, co-host of the Security Justice and Social Media Security podcasts and is a frequent speaker at security user groups and national security conferences including Defcon, Shmoocon, OWASP AppSec and Notacon. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/august-18th-neoisf-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 21st NEOISF Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/july-21st-neoisf-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/july-21st-neoisf-meeting-announcement/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 02:03:48 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[neoisf]]></category>
		<category><![CDATA[reverseengineering]]></category>
		<category><![CDATA[tyler]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=280</guid>
		<description><![CDATA[Our next meeting is this WEDNESDAY July 21, 2010. Pizza and networking start at 6:00 PM. Talks start at 6:30 PM. Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio. Click here for a Google Map! Open to everyone and free as always! Here are the list of talks and [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is this WEDNESDAY July 21, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  <a href="http://maps.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;time=&#038;date=&#038;ttype=&#038;q=6150+Oak+Tree+Blvd,+independence+oh&#038;sll=41.396614,-81.661634&#038;sspn=0.002704,0.004131&#038;ie=UTF8&#038;ll=41.39694,-81.660937&#038;spn=0.002704,0.004131&#038;t=h&#038;z=18&#038;om=1">Click here for a Google Map!</a> Open to everyone and free as always!  Here are the list of talks and agenda items for this months meeting</p>
<p><strong>Cradle to Grave Part 2 &#8211; FBI Special Agent Ryan MacFarlane</strong><br />
This is the continuation of last months talk in which Ryan will walk us through a forensic analysis and incident response of compromised systems using SIFT 2.0.  Last month Dave Kennedy showed a demonstration of systems being exploited with Metasploit Express.</p>
<p><strong>Overview of the REcon Security Conference &#8211; Tyler Hudak</strong><br />
Tyler gives a review of the <a href="http://recon.cx/2010/speakers.html">REcon Security Conference</a> that he recently attended.  REcon is a conference focused on reverse engineering and is held in Montreal Canada.</p>
<p><strong>Speaker Bios</strong></p>
<p><strong>FBI Special Agent Ryan MacFarlane</strong>, Cleveland Office, has spent the last six years investigating numerous criminal intrusions.  With over 8 years of Internet security experience, previous work experience includes positions at IBM, i2 Technologies, Georgia Tech, and as a co-founder of an Internet security start-up in 2004.</p>
<p><strong>Tyler Hudak</strong> is an Incident Handler for General Electric, specializing in malware analysis and reverse engineering.  Prior to joining GE, Tyler  worked for a number of corporations performing intrusion detection, incident response, forensics and, of course, malware analysis.  He has presented at a number of local and national conferences, is on the board of the Northeast Ohio Information Security Forum and maintains a blog at <a href="http://secshoggoth.blogspot.com">http://secshoggoth.blogspot.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/july-21st-neoisf-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 16th NEOISF Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/june-16th-neoisf-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/june-16th-neoisf-meeting-announcement/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 02:36:44 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[neoisf]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=275</guid>
		<description><![CDATA[Our next meeting is this WEDNESDAY June 16, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  Click here for a Google Map! Open to everyone and free as always!  Here are the list of talks and [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is <strong>this WEDNESDAY June 16, 2010</strong>.  Pizza  and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location:  Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road,  Independence, Ohio.  <a href="http://maps.google.com/maps?f=q&amp;hl=en&amp;geocode=&amp;time=&amp;date=&amp;ttype=&amp;q=6150+Oak+Tree+Blvd,+independence+oh&amp;sll=41.396614,-81.661634&amp;sspn=0.002704,0.004131&amp;ie=UTF8&amp;ll=41.39694,-81.660937&amp;spn=0.002704,0.004131&amp;t=h&amp;z=18&amp;om=1">Click  here for a Google Map!</a> Open to everyone and free as always!  Here  are the list of talks and agenda items for this months meeting:</p>
<p><strong>Whose Afraid of the Big Bad Wolf: Embracing Audit as a Service</strong><br />
Let&#8217;s see if you have a picture in your head of auditors. Do see you them, sitting there in the darkness, with a maniacal look on their faces. They pour over your documentation and configuration files just hoping to find the red meat. If there is anything juicy they will find it and feed off it at your expense. Is this the image you have of auditors? Perhaps you were burned during an audit, or just didn&#8217;t have a very good experience at the auditor&#8217;s hands. With a bit of explanation, your next audit doesn&#8217;t have to be so stressful and adversarial. Maybe, just maybe, you can walk away with some value to help improve what you do that you hadn&#8217;t thought of before.</p>
<p>Starting from the beginning, we will walk through why IT auditors exist and what role they play in the organizations risk management process. Since we all can relate to risk, maybe we can find the common ground and start to derive value from what auditors provide. Given the right amount of attention and care, organizations can ultimately benefit from IT and Audit working together. Plus you will sleep better at night knowing the bogeyman is just a myth.</p>
<p><strong>Speaker Bio</strong><br />
<strong>Jeff Kirsch</strong> is an IT auditor by day and ghostnomad, an infosec geek alter ego, every chance he can get. Always trying to learn new things drives him to find better ways to help others learn about technology. His passion for technology also drives him to help those in technology understand auditors and the audit process.</p>
<p><strong>Part 1: Metasploit Express &#8211; Dave Kennedy</strong><br />
Metasploit Express was newly released by Rapid7 and is a web-based exploitation suite built on top of the Metasploit Framework. During this presentation we will be discussing how this tool can be incorporated into your daily use within vulnerability management and penetration testing within your organization and how this tool can revolutionize how you currently perform your own testing. Metasploit Express is now one of my favorite toolset&#8217;s to utilize and after this talk, it may be yours too.</p>
<p><strong>Part 2: Cradle to Grave -</strong> <strong>FBI Special Agent</strong> <strong>Ryan MacFarlane</strong><br />
Following an attack run from Metasploit Express through incident response and forensic analysis using SIFT 2.0.</p>
<p><strong>Speaker Bios</strong><br />
<strong>Dave Kennedy</strong> is a security expert that has over ten years of experience in the Information Security arena. He has presented at several large conferences including BlackHat, DefCon, ShmooCon, Information Security Summit, InfoSecWorld, and other well known speaking engagements. David is the author of the Social-Engineer Toolkit, a well known and established attack framework for Social-Engineering. David has published a number of exploits, whitepapers, and contributed to the widely popular Back|Track security distribution and the Metasploit Framework. Currently, David is a director of security for an international Fortune 1000 company located in North Canton, Ohio.</p>
<p><strong>FBI Special Agent</strong> <strong>Ryan MacFarlane</strong>, Cleveland Office, has spent the last six years investigating numerous criminal intrusions.  With over 8 years of Internet security experience, previous work experience includes positions at IBM, i2 Technologies, Georgia Tech, and as a co-founder of an Internet security start-up in 2004.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/june-16th-neoisf-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Audio from the May NEOISF Meeting with Rafal Los</title>
		<link>http://www.neoisf.org/past-presentations/audio-from-the-may-neoisf-meeting-with-rafal-los/</link>
		<comments>http://www.neoisf.org/past-presentations/audio-from-the-may-neoisf-meeting-with-rafal-los/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 04:22:24 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Audio]]></category>
		<category><![CDATA[Past Presentations]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[neoisf]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[rafallos]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=266</guid>
		<description><![CDATA[We just posted the audio from Rafal Los&#8217; talk: Into the Rabbit Hole: Execution Flow-Based Web Application Testing.  The slide deck will be posted soon!  You can download the audio as a podcast below:]]></description>
			<content:encoded><![CDATA[<p>We just posted the audio from Rafal Los&#8217; talk: <strong>Into the Rabbit Hole: Execution Flow-Based Web Application Testing</strong>.  The slide deck will be posted soon!  You can download the audio as a podcast below<strong>: </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/past-presentations/audio-from-the-may-neoisf-meeting-with-rafal-los/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/securityjustice/NEOISF_May2010_RafalLos.mp3" length="59464024" type="audio/mpeg" />
		<itunes:duration>61:56</itunes:duration>
		<itunes:subtitle>We just posted the audio from Rafal Los' talk: Into the Rabbit Hole: Execution Flow-Based Web Application Testing.  The slide deck will be posted soon!  ...</itunes:subtitle>
		<itunes:summary>We just posted the audio from Rafal Los' talk: Into the Rabbit Hole: Execution Flow-Based Web Application Testing.  The slide deck will be posted soon!  You can download the audio as a podcast below: </itunes:summary>
		<itunes:keywords>Audio, Past Presentations</itunes:keywords>
		<itunes:author>board@neoisf.org</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
		<!-- non-podPress enclosures: -->
	</item>
		<item>
		<title>May 19th NEOISF Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/may-19th-neoisf-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/may-19th-neoisf-meeting-announcement/#comments</comments>
		<pubDate>Tue, 18 May 2010 16:06:26 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[certifications]]></category>
		<category><![CDATA[rafallos]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=260</guid>
		<description><![CDATA[Our next meeting is this WEDNESDAY May 19, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  Click here for a Google Map! Open to everyone and free as always!  Here are the list of talks and [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is <strong>this WEDNESDAY May 19, 2010</strong>.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  <a href="http://maps.google.com/maps?f=q&amp;hl=en&amp;geocode=&amp;time=&amp;date=&amp;ttype=&amp;q=6150+Oak+Tree+Blvd,+independence+oh&amp;sll=41.396614,-81.661634&amp;sspn=0.002704,0.004131&amp;ie=UTF8&amp;ll=41.39694,-81.660937&amp;spn=0.002704,0.004131&amp;t=h&amp;z=18&amp;om=1">Click here for a Google Map!</a> Open to everyone and free as always!  Here are the list of talks and agenda items for this months meeting:</p>
<p><strong>Into the Rabbit Hole: Execution Flow-Based Web Application Testing</strong><br />
Since the caveman first fashioned a spear humans have been using tools to make them more efficient and effective. Unfortunately, today&#8217;s analysts often misunderstand the role tools play in testing web applications. While tools can be quite good at mapping a web application&#8217;s attack surface there is still much human analysis that must be done to find the elusive defects that lie just below the surface. That human analysis is daunting and irregular &#8230; until now. The answer is an execution-flow-based approach to application security testing. By first understanding application logic and execution flow it is possible to completely map a web application&#8217;s attack surface, and therefore fully test the application. Along the way, we will cover the principles of data-flow analysis, application process mapping and building execution-flow diagrams (EFDs), which together form a complete picture of the web application and allow an analyst to uncover potentially critical defects.</p>
<p><strong>Speaker Bio</strong><br />
Senior Security Specialist and Web Application Security evangelist with Hewlett-Packard&#8217;s Application Security Center (ASC), <strong>Rafal Los</strong> has more than thirteen years of experience in network and system design, security policy and process design, risk analysis, penetration testing, and consulting. For the past eight years, he has focused on information security and risk management, leading security architecture teams, and managing successful enterprise security programs for General Electric and other Fortune 100 companies, as well as SMB enterprises. Previously, Rafal spent three years in-house with GE Consumer Finance, leading its web application security programs.</p>
<p><strong>A Survey of Security Certifications:  Which Regex Should You Match?</strong><br />
The IT industry has long been a maze of myriad technology certifications, and the security industry is no different.  CISSP, CISA, CEH, GCIH, OSCP&#8230;you&#8217;ve seen the letters, and probably even have a few on your business card.  In this presentation, Chris will breakdown popular security certifications, categorizing them by both educational and resume-building value.</p>
<p><strong>Speaker Bio</strong><br />
<strong>Chris Clymer</strong> is a senior security consultant for a Fortune 500 financial services institution, a co-host of the Security Justice podcast, and currently sits on the NEOISF board.  He&#8217;s been working hard on his cert regex in recent years, current patterns matched include: CISSP, CISA, GPEN, and GWAPT.</p>
<p>This months meeting is sponsored by <a href="http://hp.com">HP</a>.  Come early, at 6:00 PM, for pizza, pop, water and social networking with your peers.﻿  We hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/may-19th-neoisf-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS (SEC503) Intusion Detection In-Depth in Cleveland June 24th</title>
		<link>http://www.neoisf.org/sans/sans-sec503-intusion-detection-in-depth-in-cleveland-june-24th/</link>
		<comments>http://www.neoisf.org/sans/sans-sec503-intusion-detection-in-depth-in-cleveland-june-24th/#comments</comments>
		<pubDate>Thu, 06 May 2010 01:30:53 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[NIDS]]></category>
		<category><![CDATA[SEC503]]></category>
		<category><![CDATA[SNORT]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/sans/sans-sec503-intusion-detection-in-depth-in-cleveland-june-24th/</guid>
		<description><![CDATA[Starting June 24th,  SANS will be running Intrusion Detection In-Depth in Cleveland, OH.  This course will be taught by SANS Mentor and NEOISF member Steve Jaworski.   Steve will show you practical hands-on intrusion detection and traffic analysis, network traces and analysis tips. The emphasis of this course is on increasing students&#8217; understanding of the workings [...]]]></description>
			<content:encoded><![CDATA[<p>Starting June 24th,  SANS will be running Intrusion Detection In-Depth in Cleveland, OH.  This course will be taught by SANS Mentor and NEOISF member Steve Jaworski.   Steve will show you practical hands-on intrusion detection and traffic analysis, network traces and analysis tips.</p>
<p>The emphasis of this course is on increasing students&#8217; understanding of the workings of TCP/IP, methods of network traffic analysis, and one specific network intrusion detection system (NIDS) &#8211; Snort. This is not a comparison or demonstration of multiple NIDSs. Instead, the knowledge provided here allows students to better understand the qualities that go into a sound NIDS and the whys behind them, and thus, to be better equipped to make a wise selection for their site&#8217;s particular needs.</p>
<p>For complete event details visit <a href="http://www.sans.org/info/58593">http://www.sans.org/info/58593</a>.</p>
<p>When: June 24 &#8211; August 26, 2010 (Class meets once a week from 6:30-8:30PM on Thursdays)<br />
Course: Security 503: Intrusion Detection In-Depth<br />
Mentor: Steve Jaworski<br />
CPEs: 36<br />
GIAC Certification: GIAC Certified Intrusion Analyst (GCIA). This course prepares meets the requirement of the DoD 8570 IAT Level III. <a href="http://www.sans.org/8570/">http://www.sans.org/8570/</a><br />
Tuition: Save $400 when you register by May 27 at http://www.sans.org/info/58593<br />
For group discounts please contact mentor@sans.org.</p>
<p><a href="http://www.sans.org/info/57693"><strong>What is the SANS Mentor Program</strong></a><br />
The SANS Mentor Program offers you local, live training over the course of ten weeks.  This format allows students to understand, apply and digest the material each week and return with any questions at the next class session.  Mentor classes are small classes averaging less than 12 students which gives students the opportunity to directly interact with each other and the Mentor in a hands-on environment.</p>
<p>With local training from SANS Mentor  you save on travel expenses, time away from work, family and save on average 25% on the tuition<br />
cost.  If you have a limited training budget this SANS Mentor class will get you the knowledge you need at savings you can use.  If this sounds like the kind of local, live training you can use please register today at <a href="http://www.sans.org/info/58593">http://www.sans.org/info/58593</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/sans/sans-sec503-intusion-detection-in-depth-in-cleveland-june-24th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rafal Los from HP Speaking at the May 19th Meeting</title>
		<link>http://www.neoisf.org/meeting-announcements/rafal-los-from-hp-speaking-at-the-may-19th-meeting/</link>
		<comments>http://www.neoisf.org/meeting-announcements/rafal-los-from-hp-speaking-at-the-may-19th-meeting/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 20:05:52 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[neoisf]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[rafallos]]></category>
		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=256</guid>
		<description><![CDATA[We are excited to announce that Rafal Los from HP will be speaking at the May 19th meeting.  He will be giving his talk from the Source Boston conference &#8220;Into the Rabbit Hole: Execution Flow-Based Web Application Testing&#8221;.  Here is the talk abstract and his bio: Since the caveman first fashioned a spear humans have [...]]]></description>
			<content:encoded><![CDATA[<p>We are excited to announce that Rafal Los from HP will be speaking at the May 19th meeting.  He will be giving his talk from the Source Boston conference <strong>&#8220;Into the Rabbit Hole: Execution Flow-Based Web Application Testing&#8221;</strong>.  Here is the talk abstract and his bio:</p>
<p>Since the caveman first fashioned a spear humans have been using tools to make them more efficient and effective. Unfortunately, today&#8217;s analysts often misunderstand the role tools play in testing web applications. While tools can be quite good at mapping a web application&#8217;s attack surface there is still much human analysis that must be done to find the elusive defects that lie just below the surface. That human analysis is daunting and irregular &#8230; until now. The answer is an execution-flow-based approach to application security testing. By first understanding application logic and execution flow it is possible to completely map a web application&#8217;s attack surface, and therefore fully test the application. Along the way, we will cover the principles of data-flow analysis, application process mapping and building execution-flow diagrams (EFDs), which together form a complete picture of the web application and allow an analyst to uncover potentially critical defects.</p>
<p><strong>Speaker Bio:</strong><br />
Senior Security Specialist and Web Application Security evangelist with Hewlett-Packard&#8217;s Application Security Center (ASC), Rafal Los has more than thirteen years of experience in network and system design, security policy and process design, risk analysis, penetration testing, and consulting. For the past eight years, he has focused on information security and risk management, leading security architecture teams, and managing successful enterprise security programs for General Electric and other Fortune 100 companies, as well as SMB enterprises. Previously, Rafal spent three years in-house with GE Consumer Finance, leading its web application security programs.</p>
<p>Stay tuned for the full agenda announcement in the next few days!  We hope to see you May 19th!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/rafal-los-from-hp-speaking-at-the-may-19th-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/april-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/april-meeting-announcement/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 17:56:24 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[arcsight]]></category>
		<category><![CDATA[neoisf]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[siem]]></category>
		<category><![CDATA[spiderlabs]]></category>
		<category><![CDATA[trustwave]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=250</guid>
		<description><![CDATA[Our next meeting is WEDNESDAY April 21, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  Click here for a Google Map! Open to everyone and free as always!  Here are the list of talks and agenda [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is <strong>WEDNESDAY April 21, 2010</strong>.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  <a href="http://tinyurl.com/neoisfmtg">Click here for a Google Map!</a> Open to everyone and free as always!  Here are the list of talks and agenda items for this months meeting:</p>
<p><strong>Oracle, Interrupted: Stealing Sessions and Credentials</strong><br />
In a world of free, ever-present encryption libraries, many penetration testers still find a lot of great stuff on the wire. Database traffic is a common favorite, and with good reason: when the data includes PAN, Track, and CVV, it makes you stop and wonder why this stuff isn’t encrypted by default. However, despite this weakness, we still need someone to issue queries before we see the data. Or maybe not… after all, it’s just plaintext.</p>
<p>Recapping his recent Black Hat Europe presentation with Wendel G. Henrique, Steve Ocepek will be taking a look at the world&#8217;s most popular relational database: Oracle. Through a combination of downgrade attacks and session take-over exploits, this talk introduces a unique approach to database account hijacking. Using a new tool, thicknet, Steve will demonstrate just how deadly injection attacks can be to database security.</p>
<p><strong>Speaker Bio:</strong> Steve Ocepek serves as the Director of Security Research for Trustwave&#8217;s SpiderLabs division &#8211; the advanced security team focused on penetration testing, incident response, and application security. Steve has been working in the Information Security field for over ten years. As a founder of Wholepoint Corporation, he and his team created one of the first Network Access Control (NAC) systems in 2001, and has been granted four patents in this area to date. After being acquired by Mirage Networks in 2004, Steve continued his research, discovering new, effective ways to profile network devices in real-time. During this process, Steve had the opportunity to fill a number of roles, from research and development to security consulting. At Trustwave, Steve continues to innovate and is frequently referred to in cases where network technologies are concerned. Steve is a CISSP, frequently speaks at security venues, both corporate and academic. Recent venues include Black Hat USA 2009, Black Hat Europe 2010, and Northwestern University.</p>
<p><strong>SIEM&#8217;s and Auto-blocking Attacks</strong><br />
SIEM&#8217;s are often used in the capacity for intelligence and information gathering within organizations. Often times, the large amount of information used is wasted and not utilized in an efficient manner. At my organization, the SIEM can be used in a much larger capacity when performing responses to actual threats and attacks in an automated fashion. Let&#8217;s take a plunge into ArcSight where we can actively block predefined attacks and utilize the SIEM in a responsive measure across an international company.</p>
<p><strong>Speaker Bio: </strong>Josh Kelley is an Enterprise Security Analyst for a Fortune 1000 company where his primarily responsibilities are web application security, incident response, vulnerability management, and ensuring that the organization is protected against attack. Much of this is understanding the latest attack vectors and establishing a defense against a large international target.  Josh has recently been working on exploit development and vulnerability research. Josh currently holds the SANS&#8217; GSEC and GCIH certifications and is undergoing the Offensive-Security Certified Professional certification.</p>
<p>Come early, at 6:00 PM, for pizza, pop, water and social networking with your peers.﻿  We hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/april-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2010 Meeting Announcement</title>
		<link>http://www.neoisf.org/meeting-announcements/march-2010-meeting-announcement/</link>
		<comments>http://www.neoisf.org/meeting-announcements/march-2010-meeting-announcement/#comments</comments>
		<pubDate>Sun, 14 Mar 2010 01:17:41 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Meeting Announcements]]></category>
		<category><![CDATA[energizer]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[matt]]></category>
		<category><![CDATA[neoisf]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tyler]]></category>
		<category><![CDATA[usb]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[wpa]]></category>

		<guid isPermaLink="false">http://www.neoisf.org/?p=246</guid>
		<description><![CDATA[Our next meeting is WEDNESDAY March 17, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  Click here for a Google Map! Open to everyone and free as always!  Here are the list of talks and agenda [...]]]></description>
			<content:encoded><![CDATA[<p>Our next meeting is WEDNESDAY March 17, 2010.  Pizza and networking start at 6:00 PM.  Talks start at 6:30 PM.  Location: Park Center Plaza #1, 6100 Oak Tree Blvd, off Rockside Road, Independence, Ohio.  <a href="http://tinyurl.com/neoisfmtg">Click here for a Google Map!</a> Open to everyone and free as always!  Here are the list of talks and agenda items for this months meeting:</p>
<p><strong>Attacking WPA-Enterprise Wireless Networks, Matt Neely</strong><br />
This presentation covers different attacks that can be leveraged against wireless networks using Enterprise (802.1x) authentication. Attendees will learn about and see demonstrations of these attacks, many of which can be used to reveal the credentials used to join the wireless network. The presentation concludes with recommendations on how to defend against these attacks.</p>
<p>Matt Neely (CISSP, CTGA, GCIH and GCWN) is the Profiling Team Manager at SecureState, a Cleveland Ohio based security consulting company. At SecureState, Matt and his team perform traditional penetration tests, physical penetration tests, web application security reviews and wireless security assessments. His research interests include the convergence of physical and logical security, cryptography and all things wireless. Matt is also a host on the Security Justice podcast.<br />
<strong><br />
Analysis of the Energizer Charger Malware, Tyler Hudak</strong><br />
Energizer and the US-CERT recently released an advisory that the software for the Energizer USB battery charger contained a backdoor.  Tyler will perform a technical analysis of the backdoor and discuss why this malware is more than just an accidental infection of software.</p>
<p>Come early, at 6:00 PM, for pizza, pop, water and social networking with your peers.﻿  We hope to see you there</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neoisf.org/meeting-announcements/march-2010-meeting-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
