<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Assurance Club</title>
	<atom:link href="http://iaclub.ist.psu.edu/feed/" rel="self" type="application/rss+xml" />
	<link>http://iaclub.ist.psu.edu</link>
	<description>Hands-on Security</description>
	<lastBuildDate>Mon, 16 Nov 2009 23:14:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Faronics Insight Seminar</title>
		<link>http://iaclub.ist.psu.edu/2009/11/15/faronics-insight-seminar/</link>
		<comments>http://iaclub.ist.psu.edu/2009/11/15/faronics-insight-seminar/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 10:33:46 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Upcoming Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=370</guid>
		<description><![CDATA[We’ve all heard about the new software in all of the classrooms in IST. Come out and learn how it works, what it’s capable of doing, and what that means in terms of privacy and legality. We’ll discuss the key logging capabilities of the software (which have now been disabled) and some other potential misuses (such as rogue teacher machines). We’ll end with an open discussion on both Insight and monitoring software in general.]]></description>
			<content:encoded><![CDATA[<p><strong>Faronics Insight Seminar</strong><br />
Monday, November 16th<br />
8:00 PM — 206 IST</p>
<p>We’ve all heard about the new software in all of the classrooms in IST. Come out and learn how it works, what it’s capable of doing, and what that means in terms of privacy and legality. We’ll discuss the key logging capabilities of the software (which have now been disabled) and some other potential misuses (such as rogue teacher machines). We’ll end with an open discussion on both Insight and monitoring software in general.</p>
<p><strong>Slides: </strong><a href="http://iaclub.ist.psu.edu/files/2009-11-16-insight-slides.pptx">2009-11-16-insight-slides.pptx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/11/15/faronics-insight-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>International Capture The Flag (iCTF) Competition</title>
		<link>http://iaclub.ist.psu.edu/2009/10/29/international-capture-the-flag-ictf-competition/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/29/international-capture-the-flag-ictf-competition/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 08:34:34 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Upcoming Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=347</guid>
		<description><![CDATA[The UCSB International Capture The Flag (also known as the iCTF) is a distributed, wide-area security exercise, whose goal is to test the security skills of the participants. The Capture The Flag contest is multi-site, multi-team hacking contest in which a number of teams compete independently against each other.

The goal of each team is to maintain a set of services such that they remain available and uncompromised throughout the contest phase. Each team also has to attempt to compromise other teams’ services...]]></description>
			<content:encoded><![CDATA[The UCSB International Capture The Flag (also known as the iCTF) is a distributed, wide-area security exercise, whose goal is to test the security skills of the participants. The Capture The Flag contest is multi-site, multi-team hacking contest in which a number of teams compete independently against each other.

The goal of each team is to maintain a set of services such that they remain available and uncompromised throughout the contest phase. Each team also has to attempt to compromise other teams’ services...]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/29/international-capture-the-flag-ictf-competition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anatomy of the Hack</title>
		<link>http://iaclub.ist.psu.edu/2009/10/27/anatomy-of-the-hack/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/27/anatomy-of-the-hack/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 07:31:12 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Upcoming Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=325</guid>
		<description><![CDATA[Learn how to think like a hacker! This seminar will cover the 5 phases of an attack: Reconnaissance, Scanning, Gaining Access, Maintaining Access, and Covering Tracks. It is a great way to prepare for the iCTF competition.]]></description>
			<content:encoded><![CDATA[<p><a href="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/aoth.jpg"><img src="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/aoth-682x1024.jpg" alt="Anatomy of the Hack" title="Anatomy of the Hack" width="600" class="aligncenter size-large wp-image-326" /></a></p>
<p>Learn how to think like a hacker!  This seminar will cover the 5 phases of an attack: Reconnaissance, Scanning, Gaining Access, Maintaining Access, and Covering Tracks.  It is a great way to prepare for the iCTF competition.</p>
<p>Slides: <a href="http://iaclub.ist.psu.edu/files/2009-10-29-slides.pptx">Anatomy of the Hack</a><br />
<a href="http://iaclub.ist.psu.edu/ictf">iCTF 2009 Page</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/27/anatomy-of-the-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IST 10th Anniversary Celebration Demonstrations</title>
		<link>http://iaclub.ist.psu.edu/2009/10/21/ist-10th-anniversary-celebration-demonstrations/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/21/ist-10th-anniversary-celebration-demonstrations/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 01:07:53 +0000</pubDate>
		<dc:creator>Brian Reitz</dc:creator>
				<category><![CDATA[Past Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=303</guid>
		<description><![CDATA[
&#160;
The IA Club Executive Board demonstrated seminars from this year in the newly revamped Kimberly-Clark Security Lab, and the Nittany Lion, Dean Foley, and even President Graham Spanier stopped by to watch Saturday at IST&#8217;s 10th year anniversary celebration. On October 10th, 2009 the College of IST celebrated its first 10 years at Penn State. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/lion-hacking.jpg"><img src="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/lion-hacking.jpg" alt="Nittany Lion Hacking" title="Nittany Lion Hacking" width="600" class="alignleft size-full wp-image-317" /></a></p>
<p>&nbsp;</p>
<p>The IA Club Executive Board demonstrated seminars from this year in the newly revamped Kimberly-Clark Security Lab, and the Nittany Lion, Dean Foley, and even President Graham Spanier stopped by to watch Saturday at IST&#8217;s 10th year anniversary celebration. On October 10th, 2009 the College of IST celebrated its first 10 years at Penn State. President Graham Spanier, Dean Hank Foley, and the Nittany Lion all made an appearance, playing host to an audience of nearly 300 people, including individual and corporate donors, alumni, current and former faculty and staff, and graduate and undergraduate students. </p>
<p>After remarks by President Spanier, Dean Foley, and others, attendees explored the IST building and exhibitions of technology demonstrations. The IA Club received plenty of attention hosting one of many technological attractions, explaining the use of dictionary attack against WPA-PSK, showing the speed of WEP cracking, playing back our Bluetooth headset capture, and other seminars.  Even the Nittany Lion stopped by to showcase his hacking skills. Overall, the IA Club got great exposure to a wide audience, and the Dean congratulated us on a job well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/21/ist-10th-anniversary-celebration-demonstrations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe PDF Seminar</title>
		<link>http://iaclub.ist.psu.edu/2009/10/21/adobe-pdf-seminar/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/21/adobe-pdf-seminar/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 22:41:45 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Presentations and Seminars]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=311</guid>
		<description><![CDATA[The goal of this seminar was to raise awareness of increasing use of Adobe PDFs as a vector for other malware.  IA Club members learned a little about the history of PDFs as well as the internal workings of the document format.  We also explored a few PDF based exploits using /JavaScript and the /OpenAction functions.  This seminar gave a very high level overview of buffer overflows and heap sprays and focused more on the practical application of such techniques.  We also looked at some detection and mitigation strategies and best practices when dealing with PDFs.]]></description>
			<content:encoded><![CDATA[<p><strong>PDF Seminar</strong><br />
Wednesday, October 21st<br />
7:30 PM – 208 IST</p>
<p>The goal of this seminar was to raise awareness of increasing use of Adobe PDFs as a vector for other malware.  IA Club members learned a little about the history of PDFs as well as the internal workings of the document format.  We also explored a few PDF based exploits using /JavaScript and the /OpenAction functions.  This seminar gave a very high level overview of buffer overflows and heap sprays and focused more on the practical application of such techniques.  We also looked at some detection and mitigation strategies and best practices when dealing with PDFs.</p>
<p><strong>Links</strong><br />
<a href="http://iaclub.ist.psu.edu/files/PDF_Seminar/2009-10-21-slides.pptx">Adobe PDF Seminar Slides</a><br />
<a href="http://iaclub.ist.psu.edu/files/PDF_Seminar/JBIG2Decode-XViD.avi">JBIG2Decode Video</a><br />
<a href="http://iaclub.ist.psu.edu/files/PDF_Seminar/malware-pdf-XViD.avi">PDFID and PDF-Parser Video</a><br />
<a href="http://iaclub.ist.psu.edu/files/PDF_Seminar/anatomy_of_malicious_pdfs.pdf">Anatomy of Malicious PDFs &#8211; Didier Stevens</a><br />
<a href="http://iaclub.ist.psu.edu/files/PDF_Seminar/pdf_risks.pdf">Hidden Data and Metadata in Adobe PDF Files: Publication Risks and Countermeasures</a><br />
<a href="http://blog.didierstevens.com/">http://blog.didierstevens.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/21/adobe-pdf-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://iaclub.ist.psu.edu/files/PDF_Seminar/JBIG2Decode-XViD.avi" length="2061418" type="video/x-msvideo" />
<enclosure url="http://iaclub.ist.psu.edu/files/PDF_Seminar/malware-pdf-XViD.avi" length="6557650" type="video/x-msvideo" />
		</item>
		<item>
		<title>Guest Lecture: Insider Threat with Christopher King</title>
		<link>http://iaclub.ist.psu.edu/2009/10/07/insider-threat/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/07/insider-threat/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 00:24:09 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Past Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=260</guid>
		<description><![CDATA[Insider Threat is a growing problem for today’s organizations. Often overlooked in favor of technological solutions, the “trusted insider” can commit tremendous damage to an organization. CERT has researched hundreds of cases of actual insiders, from a combination of open source reporting, Secret Service case files, and voluntary contributions from organizations. Using these case files, and statistical, psychological, and technical analysis, CERT was able to develop a model of malicious insiders and why they commit their crimes. This presentation will discuss some of the major cases we have studied, profiles of malicious insiders, and best practices for reducing the risk of insider threat.]]></description>
			<content:encoded><![CDATA[<p><img src="http://iaclub.ist.psu.edu/files/Insider_Threat/insider_threat.jpg" alt="Insider Threat" /><br />
The Information Assurance Club welcomes guest speaker Christopher King for a presentation on <strong>Insider Threat</strong>.</p>
<p>Tuesday, October 13th, 2009<br />
205 IST &mdash; 7:00 PM</p>
<p>Insider Threat is a growing problem for today’s organizations.   Often overlooked in favor of technological solutions, the &#8220;trusted insider&#8221; can commit tremendous damage to an organization.  <a href="http://www.cert.org/">CERT</a> has researched hundreds of cases of actual insiders, from a combination of open source reporting, Secret Service case files, and voluntary contributions from organizations.  Using these case files, and statistical, psychological, and technical analysis, CERT was able to develop a model of malicious insiders and why they commit their crimes.  This presentation will discuss some of the major cases we have studied, profiles of malicious insiders, and best practices for reducing the risk of insider threat.</p>
<p>Afterwards, Christopher will answer questions regarding future careers in government or contractors, and some general advice for &#8220;getting ahead&#8221; in the information security industry.</p>
<p><em>Speaker Biography:</em></p>
<p>Christopher King works for the Threat and Incident Management Team (TAIM) at the Computer Emergency Response Team (CERT), a federally funded research and development organization created by DARPA in 1988 after the first computer worm.  TAIM researches insider threats and incident response solutions for the DoD, DHS, and other organizations.  He is also a graduate student at Carnegie Mellon University, studying Information Security Policy and Management. </p>
<p>Previously, Christopher worked for the Defense Information Systems Agency (DISA) as an Information Assurance Manager, working in Command and Control technologies.  Through his tenure at DISA, he managed multi-million dollar contracts, led a development team on the Net-Enabled Command Capability (NECC), and ensured secure architecture for the NECC program.  Christopher has also worked for DHS Office of Inspector General, and CERT’s Vulnerability Analysis team.</p>
<p>Christopher attended Penn State University and received a degree in Information Sciences and Technology in 2007.</p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/07/insider-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October is National Cybersecurity Awareness Month</title>
		<link>http://iaclub.ist.psu.edu/2009/10/07/national-cybersecurity-awareness-mont/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/07/national-cybersecurity-awareness-mont/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 05:54:13 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=278</guid>
		<description><![CDATA[Cyber attacks and their viral ability to infect networks, devices, and software must be the concern of all Americans. This month, we highlight the responsibility of individuals, businesses, and governments to work together to improve their own cybersecurity and that of our Nation. We all must practice safe computing to avoid attacks. A key measure of our success will be the degree to which all Americans educate themselves about the risks they face and the actions they can take to protect themselves and our Nation’s digital infrastructure.]]></description>
			<content:encoded><![CDATA[<p><img src="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/ncaw.jpg" alt="National Cybersecurity Awareness Month" /></p>
<p>This October has been declared National Cyber Security Awareness Month, a month in which Americans are encouraged to learn more about the national security priority that is the U.S. communications infrastructure.</p>
<blockquote><p>Americans are constantly adopting new and innovative technologies. This exposure has dramatically increased our thirst for computers, smartphones, and other digital solutions at work and at home. Our Nation&#8217;s growing dependence on cyber and information-related technologies, coupled with an increasing threat of malicious cyber attacks and loss of privacy, has given rise to the need for greater security of our digital networks and infrastructures. In the Information Age, the very technologies that empower us to create and build also empower those who would disrupt and destroy. During National Cybersecurity Awareness Month, we rededicate ourselves to promoting cybersecurity initiatives that ensure the confidentiality of sensitive information, the integrity of e-commerce, and the resilience of digital infrastructures.</p>
<p>Cyber attacks and their viral ability to infect networks, devices, and software must be the concern of all Americans. This month, we highlight the responsibility of individuals, businesses, and governments to work together to improve their own cybersecurity and that of our Nation. We all must practice safe computing to avoid attacks. A key measure of our success will be the degree to which all Americans educate themselves about the risks they face and the actions they can take to protect themselves and our Nation&#8217;s digital infrastructure.</p>
<p>Source: <a href="http://www.whitehouse.gov/the_press_office/Presidential-Proclamation-National-Cybersecurity-Awareness-Month/">White House Press Release</a>
</p></blockquote>
<p>In honor of National Cybersecurity Awareness Month, the Information Assurance Club would like to highlight two cyber related reports.</p>
<p>First, Websense has released their &#8220;<a href="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/WebsenseReport9-09.pdf">State of Internet Security, Q1-Q2 2009</a>&#8221; report.  This report outlines and reemphasizes many of the things we already know.  <strong>Today&#8217;s threats are leading to the Web</strong>, whether as the vector of the attack or simply the route in which stolen, confidential data is transmitted.  Further underscoring the growth of the Web as the primary threat vector, during the first half of 2009 Websense Security Labs discovered:</p>
<ul>
<li>233% growth in the number of malicious sites in the last six months and a 671% growth during the last year.</li>
<li>77% of Web sites with malicious code are legitimate sites that have been compromised.</li>
<li>95% of comments to blogs, chat rooms and message boards are spam or malicious.</li>
<li>57% of data-stealing attacks are conducted over the Web.</li>
<li>85.6% of all unwanted emails in circulation contained links to spam sites and/or malicious Web sites.</li>
</ul>
<p>A video summary of the report can be found below (along with <a href="http://www.youtube.com/watch?v=p1bTr5ImpUE">Part 2</a>):</p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/BNu1TXNYArI&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/BNu1TXNYArI&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="425" height="344"></embed></object></p>
<p>Second, the American Bar Association published a paper, &#8220;<a href="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/ABA-Cyber-Study-0609.pdf">National Security Threats in Cyberspace</a>.&#8221;   In June of this year, more than two dozen experts with diverse backgrounds &#8211; physicists; telecommunications executives; Silicon Valley entrepreneurs; federal law enforcement, military, homeland security and intelligence officials; congressional staffers; and civil liberties advocates &#8211; discussed their thoughts on the tenets of cyber policy as they relate to national security.  The participants were asked to consider in particular: (1) what national security threats are posed by actors in cyberspace, (2) how the United States is currently addressing threats in cyberspace, (3) potential legal and doctrinal issues in cyberspace, (4) the organizational framework needed for a coherent cyber strategy, (5) the future of cyberspace and (6) metrics for success.</p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/07/national-cybersecurity-awareness-mont/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux Seminar with Women in IST</title>
		<link>http://iaclub.ist.psu.edu/2009/10/01/linux-seminar-with-women-in-ist/</link>
		<comments>http://iaclub.ist.psu.edu/2009/10/01/linux-seminar-with-women-in-ist/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 15:39:25 +0000</pubDate>
		<dc:creator>Brian Reitz</dc:creator>
				<category><![CDATA[Presentations and Seminars]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=246</guid>
		<description><![CDATA[This presentation covered some of the basics of Linux, its history, its business uses, and a hands-on portion encouraging attendees to try out Ubuntu 9.04 for themselves. This event was held in conjunction with the student club Women in IST (WIST) as part of their Successful Women in IT series, and members of both clubs got to interact and learn more about each club over ice cream after the seminar. Thirty Ubuntu 9.04 Live CDs were distributed to encourage members to try Linux on their own computers at home without permanently changing anything. Members also got a look at the powerful command line under the hood of Linux through SSH by using Penn State’s Linux cluster.]]></description>
			<content:encoded><![CDATA[<p><img src="http://iaclub.ist.psu.edu/files/Linux_Seminar/linux1.jpg" alt="Linux Seminar" width="290" /><img src="http://iaclub.ist.psu.edu/files/Linux_Seminar/linux2.jpg" alt="Linux Seminar" width="290" /><br />
<img src="http://iaclub.ist.psu.edu/files/Linux_Seminar/linux3.jpg" alt="Brian Reitz" width="290" /><img src="http://iaclub.ist.psu.edu/files/Linux_Seminar/linux4.jpg" alt="Ice Cream Social" width="290" /></p>
<p>This presentation covered some of the basics of Linux, its history, its business uses, and a hands-on portion encouraging attendees to try out Ubuntu 9.04 for themselves. This event was held in conjunction with the student club Women in IST (WIST) as part of their Successful Women in IT series, and members of both clubs got to interact and learn more about each club over ice cream after the seminar. Thirty Ubuntu 9.04 Live CDs were distributed to encourage members to try Linux on their own computers at home without permanently changing anything. Members also got a look at the powerful command line under the hood of Linux through SSH by using Penn State&#8217;s Linux cluster.</p>
<p>Slides: <a href="http://iaclub.ist.psu.edu/wp-content/uploads/2009/10/linux.pptx">Linux Seminar Slides</a></p>
<p>More information:<br />
Ubuntu Linux: <a href="http://www.ubuntu.com/">http://www.ubuntu.com/</a><br />
Penn State Linux Cluster: <a href="http://clc.its.psu.edu/Labs/Linux/cluster_connection.aspx">CLC Linux &#8211; Documentation</a><br />
Command line cheat sheet: <a href="http://files.fosswire.com/2007/08/fwunixref.pdf">http://files.fosswire.com/2007/08/fwunixref.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/10/01/linux-seminar-with-women-in-ist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Security with Firefox</title>
		<link>http://iaclub.ist.psu.edu/2009/09/17/web-security-with-firefox/</link>
		<comments>http://iaclub.ist.psu.edu/2009/09/17/web-security-with-firefox/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 23:30:29 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Presentations and Seminars]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=230</guid>
		<description><![CDATA[This presentation covered some of the basics of web security using Firefox. It was meant to serve as an introduction to SQL Injections, Cross Site Scripting (XSS), as well as form data manipulation. We have chosen Firefox because it has some powerful addons that make security testing as easy as point and click.]]></description>
			<content:encoded><![CDATA[<p>This presentation covered some of the basics of web security using Firefox.  It was meant to serve as an introduction to SQL Injections, Cross Site Scripting (XSS), as well as form data manipulation.  We have chosen Firefox because it has some powerful addons that make security testing as easy as point and click.</p>
<p>Firefox:<br />
<a href="http://www.getfirefox.com">http://www.getfirefox.com</a></p>
<p>Addons:<br />
<a href="https://addons.mozilla.org/en-US/firefox/addon/7597">SQL Inject Me (https://addons.mozilla.org/en-US/firefox/addon/7597)</a><br />
<a href="https://addons.mozilla.org/en-US/firefox/addon/7598">XSS Me (https://addons.mozilla.org/en-US/firefox/addon/7598)</a><br />
<a href="https://addons.mozilla.org/en-US/firefox/addon/966">Tamper Data (https://addons.mozilla.org/en-US/firefox/addon/966)</a></p>
<p>Playground:<br />
<a href="http://www.codecrypt.com/websecurity">http://www.codecrypt.com/websecurity</a></p>
<p>Slides:<br />
<a href="http://iaclub.ist.psu.edu/files/2009-09-17-slides.pptx">http://iaclub.ist.psu.edu/files/2009-09-17-slides.pptx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/09/17/web-security-with-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security Panel</title>
		<link>http://iaclub.ist.psu.edu/2009/09/11/cyber-security-panel/</link>
		<comments>http://iaclub.ist.psu.edu/2009/09/11/cyber-security-panel/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 23:00:55 +0000</pubDate>
		<dc:creator>tjnary</dc:creator>
				<category><![CDATA[Past Events]]></category>

		<guid isPermaLink="false">http://iaclub.ist.psu.edu/?p=188</guid>
		<description><![CDATA[Join Booz Allen Hamilton, a leading strategy and technology consulting firm, as we discuss the future of DoD in cyberspace during an interactive panel discussion for Penn State students and faculty. Our panel of Cyber specialists—comprised of Penn State Alumni and a Happy Valley native—will also address audience questions, drawing on important client work and their own expertise.]]></description>
			<content:encoded><![CDATA[<p><a href="http://iaclub.ist.psu.edu/files/CyberPanelFlyer.pdf" title="Click for Full PDF Version"><img src="http://iaclub.ist.psu.edu/files/CyberPanelFlyer.jpg" width="100%" height="100%" alt="Click for Full PDF Version" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://iaclub.ist.psu.edu/2009/09/11/cyber-security-panel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
