Posts

Sguil Status

Image
One of you wrote recently to ask about the status of the open source Network Security Monitoring suite called Sguil . You noticed the last release of Sguil (0.6.1) occurred in February 2006. I can assure you Sguil is not dead. In fact, just last week I wrote an article for a new BSD magazine about installing the sensor and server components of Sguil 0.7.0 (from CVS on FreeBSD 7.0. To keep up with development read the sguil-devel mailing list and visit #snort-gui on irc.freenode.net. I expect to see Sguil 0.7.0 released before 13 February 2008 to avoid hitting the two year mark.

Last Book Reviews of 2007 Posted

Amazon.com just published my five star review of Ajax Security by Billy Hoffman and Bryan Sullivan. From the review : Ajax Security was the last book I read and reviewed in 2007. However, it was the best book I read all year. The book is absolutely compelling and every security professional and Web developer should read it. It's really as simple as that. I am not a Web developer. I was not very familiar with Ajax (beyond its buzzword status and a vague notion of functionality) when I started reading Ajax Security. I attended the authors' Black Hat 2007 talk and was thoroughly impressed and disturbed by the security implications they presented. I expected Ajax Security to be a good book, but one can never be sure if talented hackers and presenters can transfer their skills to the written word. Ajax Security gets the job done. Ajax Security is my Best Book Bejtlich Read in 2007 award winner. Amazon.com will soon publish my four star review of Geekonomics by David Rice. Fro...

Best Book Bejtlich Read in 2007

Image
Last year I posted my first year-end ranking of books I had read and reviewed in 2006, titled Favorite Books I Read and Reviewed in 2006 . I decided to continue the tradition this year by posting my 2007 rankings, and awarding Best Book Bejtlich Read in 2007 (B3R07). 2007 was not my most productive year in terms of reading and reviewing books . I read 17 in 2000, 42 in 2001, 24 in 2002, 33 in 2003, 33 in 2004, 26 in 2005, and 52 in 2006. This year I read and reviewed 25 books, several during the last week. My ratings can be summarized as follows: 5 stars: 9 books 4 stars: 11 books 3 stars: 4 books 2 stars: 1 book 1 star: 0 books The competition for the B3R07 award was intense. Keep in mind these are all five star books. 9. Designing BSD Rootkits: An Introduction to Kernel Hacking by Joseph Kong (No Starch). If you understand C and want to learn how to manipulate the FreeBSD kernel, Designing BSD Rootkits is for you. 8. Hacking Exposed VoIP: Voice Over IP Security Secrets ...

Long Live Emerging Threats

If you haven't noticed, availability of Bleeding Threats has been lousy recently. If you read Matt Jonkman's recent post you'll notice the arrival of Emerging Threats . I am currently getting my copy of the Bleeding ruleset there; I am no longer using Bleeding Threats.

Snort Report 11 Posted

Image
My 11th Snort Report on Snort Limitations has been posted. From the start of the article: In the first Snort Report I mentioned a few things value-added resellers should keep in mind when deploying Snort: 1. Snort is not a "badness-ometer." 2. Snort is not "lightweight." 3. Snort is not just a "packet grepper." In this edition of the Snort Report, I expand beyond those ideas, preparing you to use Snort by explaining how to think properly about its use. Instead of demonstrating technical capabilities, we'll consider what you can do with a network inspection and control system like Snort. The editors titled this piece "Snort Limitations" -- I didn't.

Predictions for 2008

Image
For the last five years I've resisted the urge to write year-end predictions (thanks Anton ). However, I'm seeing indications of the following, so maybe this is more about highlighting trends than taking wild guesses. Here are my five predictions for 2008. Expect greater government involvement in assessing the security of private sector networks. I base this item on what's happening in the UK following their latest data breach. The article Data watchdog seeks dawn-raid powers states the following: The Information Commissioner’s Office (ICO), which polices the security of the nation’s data, is to be given the power to raid Government departments suspected of breaching protection laws. The move, announced today by Gordon Brown, comes in response to the loss by HM Revenue & Customs (HMRC) of personal details of some 25 million Britons. The Prime Minister said the ICO would be given extra powers to carry out “spot checks” of government departments. However, it is unclea...

Two Book Reviews Posted

Image
Amazon.com just published my five star review of Absolute FreeBSD, 2nd Ed by Michael Lucas. From the review : Almost five years ago I reviewed Absolute BSD, Michael Lucas' first book on FreeBSD. I gave that book five stars, back when several other BSD books provided competition. On the eve of 2008, I am happy to say that Michael Lucas is probably the best system administration author I've read. I am amazed that he can communicate top-notch content with a sense of humor, while not offending the reader or sounding stupid. When was the last time you could physically feel yourself getting smarter while reading a book? If you are a beginning to average FreeBSD user, Absolute FreeBSD 2nd Ed (AF2E) will deliver that sensation in spades. Even more advanced users will find plenty to enjoy. Amazon.com also just published my five star review of Linux Firewalls by Mike Rash. From the review : Disclaimer: I wrote the foreword for this book, so obviously I am biased. However, I am not ...