<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GRM n00bs</title>
	<atom:link href="http://www.grmn00bs.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.grmn00bs.com</link>
	<description>A blog for noobs by noobs</description>
	<lastBuildDate>Tue, 22 Jun 2010 15:44:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>User Training Video #2: [c]Lick Me!</title>
		<link>http://www.grmn00bs.com/2010/06/21/user-training-video-2-click-me</link>
		<comments>http://www.grmn00bs.com/2010/06/21/user-training-video-2-click-me#comments</comments>
		<pubDate>Mon, 21 Jun 2010 21:24:52 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[User Training Videos]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=152</guid>
		<description><![CDATA[
Here Georgia and Rachel discuss downloaded malware and how to avoid falling victim.  It wouldn&#8217;t be GRM n00bs without some foolery. We&#8217;ve got lapdances, internal threats with broomsticks, and a lot of books from Syngress. 
]]></description>
			<content:encoded><![CDATA[<p><object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/IxXnyeK-4zA&#038;hl=en_US&#038;fs=1&#038;rel=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/IxXnyeK-4zA&#038;hl=en_US&#038;fs=1&#038;rel=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"></embed></object></p>
<p>Here Georgia and Rachel discuss downloaded malware and how to avoid falling victim.  It wouldn&#8217;t be GRM n00bs without some foolery. We&#8217;ve got lapdances, internal threats with broomsticks, and a lot of books from <a href="http://www.syngress.com">Syngress</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/06/21/user-training-video-2-click-me/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Example for Video</title>
		<link>http://www.grmn00bs.com/2010/06/19/example-for-video</link>
		<comments>http://www.grmn00bs.com/2010/06/19/example-for-video#comments</comments>
		<pubDate>Sat, 19 Jun 2010 19:20:44 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=146</guid>
		<description><![CDATA[This is just an example for my newest user training video (coming soon).  All it does is say Hello Georgia anyhow.
grmn00bs.py
MD5 sum: a3e75154e163037c63ff0ffae4d923e9
]]></description>
			<content:encoded><![CDATA[<p>This is just an example for my newest user training video (coming soon).  All it does is say Hello Georgia anyhow.</p>
<p><a href="https://sites.google.com/site/grmn00bsstuff/grmn00bs-python-script/grmn00bs.py?attredirects=0">grmn00bs.py</a></p>
<p>MD5 sum: a3e75154e163037c63ff0ffae4d923e9</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/06/19/example-for-video/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TSA n00bs</title>
		<link>http://www.grmn00bs.com/2010/05/29/tsa-n00bs</link>
		<comments>http://www.grmn00bs.com/2010/05/29/tsa-n00bs#comments</comments>
		<pubDate>Sat, 29 May 2010 22:10:07 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=136</guid>
		<description><![CDATA[	I’m fairly certain I unwittingly committed a serious crime. I went through airport security using someone else’s boarding pass, bearing a name that’s only resemblance to my own completely legitimate and self representative government issued ID was that our last names shared the same first letter.  The TSA agent, you know the one, with ]]></description>
			<content:encoded><![CDATA[<p>	I’m fairly certain I unwittingly committed a serious crime. I went through airport security using someone else’s boarding pass, bearing a name that’s only resemblance to my own completely legitimate and self representative government issued ID was that our last names shared the same first letter.  The TSA agent, you know the one, with the little hologram checking flashlight, looked at my ID, my boarding pass, my ID again, me. I thought he seemed a tad skeptical, taking longer than necessary on a process he must step through about a million times a day. I will admit that passport photograph was taken when I was 16, and I can look a little like a fraud at 7 am after several nights of limited sleep. Rather than being annoyed at the slight holdup, though said lack of sleep had me about at the end of my rope with the usual ubiquitous airport annoyances, I realized this man was only doing his job to protect my safety. I can certainly hang around an extra 30 seconds so I don’t get blown to bits. Then he marked a bunch of esoteric jargon on the boarding pass I was not yet aware was not mine and sent me on through security. Who needs Bruce Schneier’s boarding pass switching trick when you can make it through security with just any old boarding pass that you find lying around the airport?<br />
	I though there might be a snafu in the whole thing once I realized the flight I was waiting for was not my own and examined the boarding pass realizing Mr. W____/S____ was not in fact me. The problem I anticipated was the lack of said marks on my boarding pass. However, this was not the case, and I boarded my correct flight without incident.<br />
How did I end up with someone else’s boarding pass? By what strange luck did I happen to have my own boarding pass waiting in the bottom of my backpack to save the day, no doubt saving me from a lot of awkward questions, possible detainment, and at the very least missing my flight by having to go back out through security to get the whole mess sorted out. As it happens, I took advantage of the online check-in and boarding pass printing option the evening before the flight. I decided to check my bag (mainly because I didn’t feel like lugging around my mammoth cissp book in not one but two airports). So I had to wait in line at the kiosks anyhow. I did not instruct the kiosk to print out another copy of my boarding pass, however before taking off towards security I noticed a boarding pass in the kiosk. Not one to leave personal information lying around, I grabbed the pass, assuming the kiosk was living up to their generally unreliable reputation. Now that I had two copies of my boarding pass, why wouldn’t I opt to use the thick, newly printer one rather than the day old, wrinkly one cluttered with weather and restaraunt information? I should have inspected the boarding pass for accuracy; I humbly admit this. I’m sure kiosks spit out the wrong boarding passes on occasion and even more often dazed and overwhelmed individuals leave their boarding passes behind. In my defense it was quite early, I suffer from severe flight anxiety that only massive doses of Xanax can assuage, and I did after all have another boarding pass on hand that I had carefully inspected for accuracy.<br />
I did not attempt to board the other individual’s flight, but I did feel somewhat concerned for my safety. I won’t go into the specifics of ideas that came to mind for how black hats and terrorists might leverage this lack of constant vigilance on the part of TSA employees. I have enough trouble flying with fears of mechanical failure and turbulence. So please Washington Dulles International Airport and any other airports with this problem, step it up. Our safety is on the line. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/05/29/tsa-n00bs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Software Engineering Gone Wild</title>
		<link>http://www.grmn00bs.com/2010/05/07/software-engineering-gone-wild</link>
		<comments>http://www.grmn00bs.com/2010/05/07/software-engineering-gone-wild#comments</comments>
		<pubDate>Sat, 08 May 2010 00:20:21 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=133</guid>
		<description><![CDATA[I am not a software engineer.  Studying large software products while getting my master&#8217;s degree pretty much convinced me that God, in fact, does play dice with the universe.  It also gave me plenty to work through with my therapist.  However, at some point after embarking on my quest to become the ]]></description>
			<content:encoded><![CDATA[<p>I am not a software engineer.  Studying large software products while getting my master&#8217;s degree pretty much convinced me that God, in fact, does play dice with the universe.  It also gave me plenty to work through with my therapist.  However, at some point after embarking on my quest to become the world&#8217;s greatest information security professional, it occurred to me that I used to be not so bad at coding.  That was before group projects in graduate school caused me to develop psychosomatic symptoms and forced me to forgo so much as coding in Alice.  On the other hand, I was able to present a very thorough risk analysis of why I was ready to be released from the loony bin.</p>
<p>	Then I got a bit distracted from the storyline and went off on a side quest to learn a new scripting language with one of my partners in crime.  The loot I was after was the extended capability to write security tools, resulting in a dramatic increase in career opportunities.  Daring to risk forgoing “planning the planning” on the grounds that this was such a small project, we were such a small team, and all the other excuses in the software engineering failure case studies, I dove right into drafting out a needs list.  I got really into it for a while, going off on random tangents, secure in the fact that I could clean it up into the correct format before sharing it.  The fact that said needs list was not due sometime early last week no doubt aided the creative process in this case.  </p>
<p>What I ended up with had a little note in the margin of the fifth page, “If I had turned this in for software engineering class, I would have been expelled.”  It’s true what I came up with was no needs list.  Aside from flying in the faces of prescriptive grammarians and often bordering on incoherence, many of the notes shouldn’t have been addressed until the features list or even detailed design.  There was even a small block of pseudo code mixed in with the idea for this article.  Additionally there were details I wanted to remember to look up about the language and possible security issues that needed to be addressed. </p>
<p>I will admit at some point I may have played it up a bit.  I got the idea into my head that after I became the world&#8217;s greatest information security professional I could publish my random software notes in the style of the Journals of Kurt Cobain.  All the n00bs will buy it, and art house geek will finally become chic.  Regardless, I felt like I had gotten more vision for a software project in one hour of free association than I had from any of those long team meetings back in graduate school trying to churn out an acceptable risk list by 1am yesterday. </p>
<p>What exactly am I suggesting here?  That we expend valuable company resources sending the software team out to the woods with a pen and paper to take acid every time a new project begins?  Even the most dedicated software engineers might protest having yet another phase added to the software engineering life cycle.  I had to do a project in graduate school breaking down the steps of software development in every methodology from rapid prototyping to waterfall.  I know what I’m complaining about.  Or maybe I’m yet another two-guys-in-a-basement type who thinks we should just chuck the whole software engineering methodology and turn the whole business into some sort of improvised performance art.  I’m not really advocating any of that. Rather I&#8217;m suggesting that taking some time to think about the problem with no goal in mind other than seeing where your thoughts take you might be worth its weight in time spent watching Youtube at work.  </p>
<p>Take my advice or don’t.  I don’t care.  I’m not a software engineer.  I’m an information security professional.  I&#8217;m in business because software engineers don&#8217;t write down ideas for potential security vulnerabilities.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/05/07/software-engineering-gone-wild/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Podcast Episode 10: Stop the Music-CCDC qualifier experiences</title>
		<link>http://www.grmn00bs.com/2010/02/17/podcast-episode-10-stop-the-music-ccdc-qualifier-experiences</link>
		<comments>http://www.grmn00bs.com/2010/02/17/podcast-episode-10-stop-the-music-ccdc-qualifier-experiences#comments</comments>
		<pubDate>Wed, 17 Feb 2010 06:03:09 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=128</guid>
		<description><![CDATA[Here I interview Rachel and another member of the JMU cyber defense team about their experiences with the new qualifier setup for the Mid Atlantic CCDC.  For more info on the qualifier check out this post.
Georgia Regina Mundi
]]></description>
			<content:encoded><![CDATA[
<p>Here I interview Rachel and another member of the JMU cyber defense team about their experiences with the new qualifier setup for the Mid Atlantic CCDC.  For more info on the qualifier check out this <a href="http://www.grmn00bs.com/2010/01/04/cyber-defense-red-white-and-blue">post</a>.</p>
<p>Georgia Regina Mundi</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/02/17/podcast-episode-10-stop-the-music-ccdc-qualifier-experiences/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.grmn00bs.com/episodes/ep10.mp3" length="22617549" type="audio/mpeg" />
		</item>
		<item>
		<title>Nexus One: A New Grail for the Littlest Hack Station? (X-Post with Security Musings).</title>
		<link>http://www.grmn00bs.com/2010/01/25/nexus-one-a-new-grail-for-the-littlest-hack-station</link>
		<comments>http://www.grmn00bs.com/2010/01/25/nexus-one-a-new-grail-for-the-littlest-hack-station#comments</comments>
		<pubDate>Mon, 25 Jan 2010 18:57:13 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Security Musings X-Posts]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=124</guid>
		<description><![CDATA[It&#8217;s all over the news;  Google finally has an Android to call its own.  The media is throwing around terms such as iPhone killer, but that doesn&#8217;t seem altogether likely to me.  Perhaps it will level out to a PC vs. Mac sort of scenario.  This actually sounds plausible as in ]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s all over the news;  <a href="http://www.cnn.com/2010/TECH/01/05/google.nexus.announcement/index.html">Google finally has an Android to call its own</a>.  The media is throwing around terms such as iPhone killer, but that doesn&#8217;t seem altogether likely to me.  Perhaps it will level out to a PC vs. Mac sort of scenario.  This actually sounds plausible as in my research I came across news of a project working on  <a href="http://reviews.cnet.com/8301-19512_7-10186107-233.html">porting Mac OSX 7 to the iPhone</a>, and the great big thing with Android back when I got mine was running <a href=" http://www.androidfanatic.com">Debian on the G1.</a></p>
<p><strong><span id="more-124"></span></strong>Specs-wise, the Nexus One looks to be the clear winner for the next littlest hack station.  The Nexus One sports a 1 GHz Qualcomm processor with 512mb of RAM.  I don&#8217;t know about you, but I still have servers with those sorts of specs running my day-to-day functions.  The Android G1, which has done a fine job as littlest hack station, has a 528 MHz processor with 192mb of RAM.  The thing I don&#8217;t like about the iPhone is the technical specifications page.  They give me information about fingerprint-resistant, oleophobic (Microsoft Word doesn&#8217;t even think that is a word) stuff, but not a word about the processor speed or RAM.  Other websites high on the Google hits quoted 600 MHz processor with 512 MB RAM for the current model 3GS.  This only matters in the short term though.   Smartphones are the new computers (way more than orange is the new pink), and everybody knows when you buy the cutting edge computer it becomes obsolete on the drive home from the store.  A year from now, there will be a new iPhone and, if it makes it, a Nexus One Point One.</p>
<p>While there have been things worth jailbreaking that have not been jailbroken (the GPU of the PS3 comes to mind), odds are good that if people with the know-how are interested in jailbreaking the Nexus one, they will.  The iPhone was first announced in January 2007, and by August 2007 the first, albeit complicated, <a href="http://iphonejtag.blogspot.com/2007/08/full-hardware-unlock-of-iphone-done.html">unlock had been completed</a> with the first <a href="http://www.cultofmac.com/first-jailbreak-for-iphone-3gs-released-windows-only/12564">jailbreaking application</a> for 3GS appearing less than two months after the phone was announced.  As for Android phones, a <a href="http://www.thetechherald.com/article.php/200846/2417/Android-moves-swiftly-to-kill-G1-jailbreak">fix</a> for a flaw that allowed users to run instructions as root in the Android operating system on the G1 was released in November of 2008, while the G1 was first released towards the end of October 2008.  Work on hacking the G1 has continued with rooting applications, downgraders, custom firmware, full Debian installs, and other cool stuff.  However, there seems to have been little interest in the community in working on later Android models.</p>
<p>The problem with keeping the secrets of these Smartphone operating systems hidden from curious hackers forever is they are Unix based, or in the case of iPhone OS, Mac OS based which is in turn Unix based, and hackers built Unix. While manufacturers may not be down with hackers using the full capacity of their devices, it&#8217;s just a fact of life. With enough community interest and talented minds, it seems inevitable that the full power of the Nexus One will be available to us in the near future.</p>
<p>With more hype behind Android, it is likely there will be at least some converts from the kingdom of iPhone to the Republic of Android.  One thing the Android Market has going for it is freedom for developers.  There has been much woe from all sides pertaining to Apple&#8217;s requirement that all apps including updated versions of existing apps go through the lengthy approval process.  While it is a deft argument that this process actually helps to protect users from security breaches by reviewing apps for potential malware, iPhone could also be dubbed a security killer.  What happens when a popular application is found to have a major security flaw in the code?  The developers cooperate with researchers and fix the problem, but then the updated version sits in the approval queue while malicious attackers exploit the vulnerability.   Many developers including, some security conscious types, will no doubt see the appeal of Android&#8217;s open market resulting in more apps for Nexus One.</p>
<p>There&#8217;s no doubt that the Android G1 is an enjoyable little hack station. &#8220;Is she texting, or is she reading all your web traffic?&#8221; is a worthwhile question if you are connected to a public access point.   More information on becoming Starbucks Wi-Fi is <a href="http://www.grmn00bs.com/2009/06/13/guest-tutorial-rooted-g1-access-point">here</a>.  (Disclaimer: Only with permission, never for evil, proof of concept, etc. etc. etc.)  With additional interest and hours from the community to integrate the hardware with available tools, the sky is the limit.   So, is the Nexus One an &#8220;iPhone killer?&#8221;  Probably not.  However, it is in a good position to have a solid foothold in the smartphone market and be a fun tool for hackers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/01/25/nexus-one-a-new-grail-for-the-littlest-hack-station/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backtrack 4: The big cheese (X-posted with Security Musings)</title>
		<link>http://www.grmn00bs.com/2010/01/25/backtrack-4-the-big-cheese</link>
		<comments>http://www.grmn00bs.com/2010/01/25/backtrack-4-the-big-cheese#comments</comments>
		<pubDate>Mon, 25 Jan 2010 18:15:39 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Security Musings X-Posts]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=122</guid>
		<description><![CDATA[It&#8217;s the news the penetration testers have all been long awaiting; Backtrack 4 final is here and now.  Though many people, myself included, have been using various pre-release, beta release, and pre-final release flavors for almost a year now ever since first standing in line to hand over my usb stick to a group ]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s the news the penetration testers have all been long awaiting; <a href="http://www.backtrack-linux.org/">Backtrack 4</a> final is here and now.  Though many people, myself included, have been using various pre-release, beta release, and pre-final release flavors for almost a year now ever since first standing in line to hand over my usb stick to a group of elite hackers at <a href="http://www.shmoocon.org/">Shmoocon</a> 5, now there is no excuse.     The final release is just in time for Hack or Halo at Shmoocon 6, saving me the trouble of making sure to update every tool I might possibly need before the big event.</p>
<p>So why does Backtrack rock in general?  It&#8217;s basically most of the tools you will need for your pentest all rolled into one and set up nicely.  I say most because it doesn&#8217;t have your commercial tools such as Nessus built in for obvious reasons, though it is possible to integrate your licensed Nessus into your Backtrack install.  Ever been setting up Dradis for your first big pentesting gig at a new company on a recently imaged box?  You&#8217;ve got your ruby prerequisites (rubydev, opensslruby, etc.), various gardening tools, SQLite, diamonds, garnets, and opals.  At some point in the process of getting it all integrated, even your technically savvy individual may find himself ruing the day he decided it was a good idea to wait until the night before to build the pentest box.  In Backtrack it goes like this:<br />
root@bt4: cd /pentest/misc/dradis/server<br />
root@bt4: ruby ./script/server<br />
Done.</p>
<p>So why upgrade to Backtrack 4?  First off, there&#8217;s the obvious perk of having the newest versions of all your favorite tools and some you&#8217;ve had on your list to check out for a while now.  It also includes some new tools that have been developed in the interim since Backtrack 3 came out way back in summer of 2008, saving you the trouble of those pesky installs and svn checkouts.  A great new tool that&#8217;s making its Backtrack debut on the final release of Backtrack 4 is re1ik&#8217;s <a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_%28SET%29">social engineering toolkit (SET)</a>.  Additionally, Backtrack 4 is Ubuntu based rather than Slackware based.  While Backtrack 3 was great, your Ubuntu-based system has its perks as far as driver integration goes.  As more and more people move from just the Live-CD Backtrack approach to using Backtrack as the base operating system on their pentesting boxes, this can only be a step in the right direction.  Speaking of installation, Backtrack 4 final has an installation script that looks a lot like the GUI-based point-and-click installation wizards seen in system such as Ubuntu, resulting in a more hands-off approach than <a href="http://www.grmn00bs.com/2009/06/14/the-littlest-hack-station-part-2-persistent-changes-and-drivers-bt3-eee">persistent changes in Backtrack 3</a>.</p>
<p>The only drawback with Backtrack 4 as is that I can think of would be trying to write up your reports in Backtrack.   Let&#8217;s not get into any holy war between writing in vi or nano, and just suffice to say it&#8217;s not easy.  Backtrack 4 does come with Emacs, and some included tools such as <a href="http://www.paterva.com/web4/index.php/maltego">Maltego</a> make some pretty graphs.  Plus, you can install OpenOffice on Backtrack, so it&#8217;s not that big of a drawback after all.<br />
All in all, Backtrack 4 is the bomb, and if you haven&#8217;t jumped on the bandwagon, my advice is to get to it.</p>
<p>Georgia</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/01/25/backtrack-4-the-big-cheese/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Defense Red, White, and Blue?</title>
		<link>http://www.grmn00bs.com/2010/01/04/cyber-defense-red-white-and-blue</link>
		<comments>http://www.grmn00bs.com/2010/01/04/cyber-defense-red-white-and-blue#comments</comments>
		<pubDate>Mon, 04 Jan 2010 07:00:08 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=112</guid>
		<description><![CDATA[This will come out all wrong if I don&#8217;t begin with &#8220;I love Cyber Defense.&#8221; There it is; I said it. My one true love is not David Foster Wallace after all but an obscure excuse to get assassinated by a bunch of professionals on a Saturday morning. I blame this notion of the collegiate ]]></description>
			<content:encoded><![CDATA[<p>This will come out all wrong if I don&#8217;t begin with &#8220;I love Cyber Defense.&#8221; There it is; I said it. My one true love is not David Foster Wallace after all but an obscure excuse to get assassinated by a bunch of professionals on a Saturday morning. I blame this notion of the collegiate Cyber Defense Competition for single-handedly launching my career, getting me into famous-people parties at conferences, and the fact that it is debatable whether I am 22 or 24. If I was the director of the Viteman foundation for the advancement of education, I would invest a good deal of my doubloons to see that there will always be a Red Team at the Mid-Atlantic qualifier. However, being as I am instead just another recent college graduate who thinks maybe just maybe she can make it in security, I can&#8217;t do much more than whine about it. It being Rachel waking me up before my alarm on a Thursday in a panic to tell me that the world we have come to depend on has ceased to exist. No one who has ever been Cyber Defense captain would dare refute her. That&#8217;s not to say that anything can prepare a team for cyber defense, but back when I was captain I used to chant, &#8220;It isn&#8217;t qualifier if the Red Team doesn&#8217;t have root before you start.&#8221; Everyone knows a captain&#8217;s word is law. So what then is a qualifier-esque scenario in which the student teams connect to the competition VPN from home, spend 3 hours hardening 3-4 systems with some services, and then are scored by Core Impact and some other penetration testing tools not to include a Red Team?</p>
<p>The rationale for this decision includes allowing more teams and smaller teams with smaller budgets to compete and saving money for everyone involved. I am all for saving JMU money so they can budget more for my filet mignon, though filet mignon is part of the JMU Cyber Defense Team tradition in Lancaster, PA at qualifier while we are all a little too nervous to enjoy it properly. In the spirit of all fairness, I believe everyone, read everyone, should have a chance to compete in Cyber Defense. I&#8217;m not even precluding non-security-type majors. Cyber Defense can be a good way to know if you want to do this for your whole life. I suppose by nature you have to be in college to compete, but I&#8217;m looking forward to competition going international with a top showing from the Uganda Christian University where beneficiaries of Hackers for Charity will be further honing their skills. The press release also notes that this system has been used by other regions such as the Midwest. &#8220;Why does it matter what the Midwest is doing?&#8221; I ask flippantly before realizing that the winner of past two national competitions Baker College hails from the Midwest region. Fair enough. They are no doubt doing something right out there, but I seriously doubt having an offsite qualifier without a Red Team has much to do with it. </p>
<p>As previously stated I think everyone on the face of the planet should have a chance to participate in the Collegiate Cyber Defense Competition; however, I suppose I don&#8217;t see competing in this setup quite the same thing as actually competing. You can never be ready for regionals. Every year White Wolf has managed to throw some righteous challenges our way. Even as a Red Team member it will be an opportunity to get some experience with cutting edge technologies that are coming to the forefront of information security. Having been through the Collegiate Cyber Defense Competition and even having taken gold at the qualifier, I still knew I was in for trouble that no amount of preparation could absolve the moment I saw the final team packet the morning of the regional competition. I remember Tim Rosenberg of White Wolf Security commented, &#8220;Think you have enough USBs?&#8221; upon seeing ten around my neck. The answer: &#8220;no, not even close.&#8221;  It&#8217;s just a given that the real winner is always the Red Team. The most a Blue Team can hope for is not to cry and vomit, learn more than you will learn in any classroom, and maybe, just maybe, knock out and keep out a few Red Team exploits along the way. My question is how can teams that have never done this before ever hope to have a good experience at Cyber Defense regionals? Without getting their feet wet in the one day qualifier where the Red Team is in before it even begins, how will they know how to hit the ground running and come home from regionals proud? I once heard it from a friend who did Cyber Defense before there was a qualifier that, &#8220;one team decided to walk out in the middle of the competition.&#8221; In my personal opinion a team that goes through only the form of qualifying round suggested above will not get the most out their experience. </p>
<p>Cyber Defense has already tried to make it extra difficult with no internet, purposefully bogged down network, etc. (Pronounced etcetera for the win). I just think maybe the newly instated rules for the qualifier might be taking it to a whole new extreme. An additional information release stated that again machines will have no access to the internet, and no tools may be uploaded to the systems. Though not specifically stated, this probably means no patches as well, especially considering past waltzes around the legality of patches. But let&#8217;s face it, why not just run &#8220;Core Impact and other penetration testing tools,&#8221; against the systems and do your best to fix what it finds in the time allotted, that is if your school is rich enough to have a Core Impact license. I&#8217;m sure we all know how much that costs, which kind of goes full circle back to the idea that this setup will allow programs with smaller budgets to compete. Compete, sure, but at a disadvantage to say the least.</p>
<p>One might could say that the bulk of my argument is stemmed from the fact that I want yet another excuse to see how my old team is doing these days, hang with all the famous people I&#8217;ve met through Cyber Defense, and hack some stuff. While all that would be grand, and you&#8217;d better believe Scott plus Georgia equals social engineering trouble, my real concern is that some students won&#8217;t get the opportunity to be coerced into crying and vomiting by the Red Team. The Red Team is what makes this article so tragically unfinished. The Red Team is what makes Cyber Defense, Cyber Defense. Here&#8217;s a joke: a Blue Team captain just recently 21 walks into a hotel bar. Not long after that a small group of Red Team and White Team members also enter the bar. Later that year she&#8217;s at arguably the biggest hacker show of the year and walking through the press room she hears, &#8220;Hey, I know you!&#8221; from a very important table. A small crowd of people around her all looks on in disbelief, &#8220;Who are you and what have you done that&#8217;s so awesome that famous person knows you?&#8221; The punch line is she&#8217;s arguably 22 by morning, but that&#8217;s another story with a video evidence to prove it.</p>
<p>What&#8217;s really getting me down here is that a whole set of teams are not going to get to meet real live hackers with spouses and children and sometimes stable jobs and even mortgages. I suppose it&#8217;s in that instant that a computer hacker ceases to be this esoteric Zarathustra on the mountaintop, the geeky equivalent to Don Mafioso, and turns into exactly what I&#8217;ve wanted to be my whole life. It&#8217;s kind of like some really important type telling you, you really can be a rock star except instead of saving rock and roll you are going to save, well, everything.</p>
<p>Georgia </p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2010/01/04/cyber-defense-red-white-and-blue/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Ch-ch-chaaaange &#8211; Upgrades</title>
		<link>http://www.grmn00bs.com/2009/12/20/ch-ch-chaaaange-upgrades</link>
		<comments>http://www.grmn00bs.com/2009/12/20/ch-ch-chaaaange-upgrades#comments</comments>
		<pubDate>Mon, 21 Dec 2009 01:11:39 +0000</pubDate>
		<dc:creator>SneakySimian</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=110</guid>
		<description><![CDATA[Please excuse the dust on the site. We&#8217;re currently trying to get a new theme up along with some other new things. Poor planning on my part I&#8217;m afraid.
Micheal
]]></description>
			<content:encoded><![CDATA[<p>Please excuse the dust on the site. We&#8217;re currently trying to get a new theme up along with some other new things. Poor planning on my part I&#8217;m afraid.</p>
<p>Micheal</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2009/12/20/ch-ch-chaaaange-upgrades/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Podcast Episode 9: When They Were n00bs with Rob Fuller(mubix)</title>
		<link>http://www.grmn00bs.com/2009/12/16/podcast-episode-9-when-they-were-n00bs-with-rob-fullermubix</link>
		<comments>http://www.grmn00bs.com/2009/12/16/podcast-episode-9-when-they-were-n00bs-with-rob-fullermubix#comments</comments>
		<pubDate>Wed, 16 Dec 2009 16:20:52 +0000</pubDate>
		<dc:creator>Georgia</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.grmn00bs.com/?p=98</guid>
		<description><![CDATA[In this episode Georgia and Micheal interview Rob Fuller of Room 362 about how he made it in security and advice for breaking into security yourself.
Shownotes: 
hak5  is one of the original security shows.  Rob has been featured on several segments.
Twit Netcast Network with Leo Laporte is another show that&#8217;s been around for ]]></description>
			<content:encoded><![CDATA[
<p>In this episode Georgia and Micheal interview Rob Fuller of <a href="http://www.room362.com">Room 362</a> about how he made it in security and advice for breaking into security yourself.</p>
<p>Shownotes: </p>
<p><a href="http://www.hak5.org/">hak5</a>  is one of the original security shows.  Rob has been featured on several segments.<br />
<a href="http://twit.tv/">Twit Netcast Network with Leo Laporte</a> is another show that&#8217;s been around for a while.<br />
<a href="http://www.securitytube.net/">Security Tube</a> is the Youtube of security videos.  This is where I&#8217;m at when I should be working.  You might even find some GRM n00bs stuff rattling around there.<br />
<a href="http://www.theacademypro.com/">The Academy Pro</a> is another excellent place to go for security training.<br />
<a href="http://www.milw0rm.com">milw0rm</a> has lots of exploits.  It&#8217;s a good place to check out some old papers to brush up on security history.<br />
<a href="http://neworder.box.sk/">NewOrder</a> is another resource to get abreast of lessons learned in the past.<br />
<a href="http://www.digininja.org/jasager/">Jasager</a> is the &#8220;Yes Man&#8221; Rob talks about in the show.<br />
<a href="http://astore.amazon.com/carnal0wnage-20/">Chris Gates&#8217;s book list</a> has some good ideas for security reading.<br />
<a href="http://www.syngress.com/">Syngress</a> is a publisher of security texts.  They have all my money.<br />
Donate to <a href=" http://www.hackersforcharity.org/">Johnny Long</a>.</p>
<p>Whoa what a new podcast?  I thought you guys had retired into the abyss!  No, we are still here.  Look out for an avalanche of GRMyness in the new year such as podcasts with the sound fixed, more basic tutorials, and maybe even some videos.</p>
<p>Georgia &#8220;Not Watching Final Fantasy Trailers at Work&#8221; Nabaat</p>
]]></content:encoded>
			<wfw:commentRss>http://www.grmn00bs.com/2009/12/16/podcast-episode-9-when-they-were-n00bs-with-rob-fullermubix/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://media.grmn00bs.com/episodes/ep9.mp3" length="242" type="audio/mpeg" />
		</item>
	</channel>
</rss>
