<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Strategic Security</title>
	<atom:link href="http://strategicsec.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://strategicsec.com</link>
	<description>An IT Security Consulting Firm</description>
	<lastBuildDate>Tue, 21 May 2013 15:54:54 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>CyberWar 2014: Advanced Pentesting Live Online (Beta)</title>
		<link>http://strategicsec.com/2013/05/21/cyberwar-2014-advanced-pentesting-live-online-beta/</link>
		<comments>http://strategicsec.com/2013/05/21/cyberwar-2014-advanced-pentesting-live-online-beta/#comments</comments>
		<pubDate>Tue, 21 May 2013 15:54:54 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[DLL Injection]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Process Injection]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[WAF]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55582</guid>
		<description><![CDATA[I&#8217;ve been developing the new CyberWar 2014 course for a while and I&#8217;ve decided to run a beta version of the class. This should give you guys a sneak peak    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/05/21/cyberwar-2014-advanced-pentesting-live-online-beta/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ve been developing the new CyberWar 2014 course for a while and I&#8217;ve decided to run a beta version of the class. This should give you guys a sneak peak at next year&#8217;s material and give me some debugging opportunities.</p>
<p>&nbsp;</p>
<h1>Course Description:</h1>
<p>This course picks up where the wildly successful courses &#8220;Advanced Penetration Tester: Pentesting High Security Environments&#8221;, and “CyberWar: Emulating Advanced Persistent Threat” left off. The focus of this class is &#8220;Taking Intrusion Detection System (IDS) evasion, and Anti-virus bypass to the next level.&#8221;</p>
<p>Key Points:</p>
<ul>
<li><span style="text-decoration: underline; color: #ff0000;">Per student request there will be absolutely NO Windows 2000, no Windows XP, Vista, or Server 2003 in the entire course.</span> Only Windows 7, Windows 8, Server 2008, Server 2012 and new flavors of Linux.</li>
</ul>
<ul>
<li>Students attack a network of fully patched, and hardened hosts. Each target computer will be running a Host-Based Intrusion Detection System (HIDS), updated Anti-Virus, and a logging agent that reports to a Security Information and Event Management (SIEM) solution.</li>
</ul>
<ul>
<li>There will also be a Network Intrusion Detection System (NIDS), a web content filtering proxy, and a stateful inspection firewall as well.</li>
</ul>
<ul>
<li>The students will have access to the consoles of all of the security appliances. Students will be able to see in real time the events triggered by the HIDS, NIDS, Proxy, and the logs so the students can learn exactly what attacks and defenses really work in today&#8217;s high security environment.</li>
</ul>
<p>Students that are Network/System Administrators with three or more years experience working in environments such as financial institutions, DoD networks, or similar high security environments will benefit greatly from this course.<br />
It is however primarily designed for Network/Web Application Penetration testers that are looking for the little tips and tricks that will help them better attack high security environments.</p>
<h1 align="center"></h1>
<p>&nbsp;</p>
<h1 style="text-align: left;" align="center">CyberWar 2014 Outline</h1>
<p>&nbsp;</p>
<h3>Day 1: Attacking From the Outside</h3>
<p>&nbsp;</p>
<ul>
<li>Attacking Hardened Web Applications
<ul>
<li>Advanced Methods of identifying SQLI/XSS</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Bypassing Common Web Application Security Mechanisms
<ul>
<li>Client-Side Filtering</li>
<li>Alphanumeric Filtering</li>
<li>Magic Quotes</li>
<li>ASP.NET Request Validate</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Bypassing Common Security Products
<ul>
<li>IDS Signature Evasion</li>
<li>Dealing with Web Application Firewalls</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<p>Day 1’s Mission:</p>
<p>Attack a mock company’s heavily protected external web applications from the outside</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h3>Day 2: Bypassing Anti-Virus &amp; HIPS</h3>
<ul>
<li>Bypassing Popular Anti-Virus
<ul>
<li>AVG</li>
<li>McAfee</li>
<li>Symantec</li>
<li>Windows Defender</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Bypassing Popular HIPS
<ul>
<li>McAfee HIPS</li>
<li>Symantec EndPoint Protection</li>
<li>Forefront</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<p>Day 2’s Mission:</p>
<p>Bypass the most common host-based security products</p>
<p><b> </b></p>
<p><b> </b></p>
<h3>Day 3: DLL/Process Injection, SRP/Applocker Bypass</h3>
<p><b> </b></p>
<ul>
<li>DLL Injection</li>
<li>Process Injection</li>
<li>Bypassing SRP and AppLocker</li>
</ul>
<p>&nbsp;</p>
<p>Day 3’s Mission:</p>
<p>Bypass Group Policy Objects, Software Restriction Policy, and HIPS</p>
<p>&nbsp;</p>
<h3>Day 4: Advanced Host &amp; Network Enumeration</h3>
<p><b> </b></p>
<ul>
<li>Attacking Windows 7 and 8
<ul>
<li>Advanced Post-Exploitation</li>
<li>Data-Mining</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Attacking 2008/2012 Active Directory
<ul>
<li>Advanced Network Enumeration</li>
<li>Data-Mining 2008/2012 Active Directory with security settings enabled</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<p>Day 4’s Mission:</p>
<p>Students will be tasked with gaining access to a highly protected network, finding and stealing critical data and exfiltrating that data without being detected.</p>
<p>&nbsp;</p>
<p>Pressure will added to the training environment by constantly changing the environment and its defensive mechanisms at irregular intervals.</p>
<p>&nbsp;</p>
<h3>Day 5: The Mother Of All CTFs</h3>
<p><b> </b></p>
<p>Get your sleep the night before, eat your Wheaties the morning of because you are about to participate in what will be the toughest CTF around.</p>
<p>&nbsp;</p>
<p><strong>Course Schedule</strong></p>
<p>This is an online course that will run from August 12th &#8211; 16th (Live Online) 10am &#8211; 2pm</p>
<p>&nbsp;</p>
<p><strong>Course Costs (Note: This is a beta class so the cost will go up next time we run it)<br />
</strong></p>
<p><a title="Click here to purchase for $1000" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CyberWar%202014%20Beta&amp;item_number=CyberWar2014Beta&amp;amount=1000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CyberWar%202014%20Beta&amp;item_number=CyberWar2014Beta&amp;amount=1000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">The course cost is $1,000USD &#8211; click here to register for $1,000USD</a></p>
<p>&nbsp;</p>
<p>First 10 applicants can signup for $300 USD &#8211; <a title="Be 1 of the first 10 to signup for $300" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CyberWar%202014%20Beta&amp;item_number=CyberWar2014Beta&amp;amount=300%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CyberWar%202014%20Beta&amp;item_number=CyberWar2014Beta&amp;amount=300%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">click here to see if you can be one of the first 10 signups.</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/05/21/cyberwar-2014-advanced-pentesting-live-online-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Dev Weekend Bootcamp</title>
		<link>http://strategicsec.com/2013/05/20/exploit-dev-weekend-bootcamp/</link>
		<comments>http://strategicsec.com/2013/05/20/exploit-dev-weekend-bootcamp/#comments</comments>
		<pubDate>Mon, 20 May 2013 16:47:57 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[ASLR]]></category>
		<category><![CDATA[DEP Bypass]]></category>
		<category><![CDATA[Heap Spray]]></category>
		<category><![CDATA[SEH Overwrites]]></category>
		<category><![CDATA[Shellcoding]]></category>
		<category><![CDATA[Stack Overflows]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55580</guid>
		<description><![CDATA[All day Saturday/Sunday June 22nd-23rd.  1 full day of Stack/SEH Overwrites (22nd), and 1 full day of Heap Spray/DEP Bypass (23rd). We’ll go from 10am-3pm each day. You’ll get your    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/05/20/exploit-dev-weekend-bootcamp/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>All day Saturday/Sunday June 22<sup>nd</sup>-23rd.  1 full day of Stack/SEH Overwrites (22<sup>nd</sup>), and 1 full day of Heap Spray/DEP Bypass (23rd). We’ll go from 10am-3pm each day. You’ll get your courseware and virtual machines on the 21<sup>st</sup> of June.</p>
<p>The sessions will be recorded each day so students can review the materials at their leisure. Get ready – this workshop is gonna be a ton of material</p>
<p><b>Day 1:</b></p>
<ul>
<li>Stack Overflows</li>
<li>SEH Overwrites</li>
<li>Shellcoding tricks</li>
</ul>
<p><b>Day 2:</b></p>
<ul>
<li>Heap Spray</li>
<li>DEP Bypass</li>
<li>ASLR</li>
</ul>
<p><b>Exploit Development Weekend Bootcamp Cost is $150 – <a title="Click here to purchase for $150" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Dev%20Weekend%20Bootcamp%20June%202013&amp;item_number=EDB-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Dev%20Weekend%20Bootcamp%20June%202013&amp;item_number=EDB-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">click here to purchase for $150</a></b></p>
<p>Or</p>
<p><b>You can have it for $100 if you:</b></p>
<ol>
<li>Post about it on Twitter</li>
<li>Like this page on Facebook</li>
<li>+1 this page on Google+</li>
</ol>
<p>Send me an email with proof that you’ve done this and I’ll reply with the $100 payment link</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/05/20/exploit-dev-weekend-bootcamp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentester Weekend Bootcamp</title>
		<link>http://strategicsec.com/2013/05/20/pentester-weekend-bootcamp/</link>
		<comments>http://strategicsec.com/2013/05/20/pentester-weekend-bootcamp/#comments</comments>
		<pubDate>Mon, 20 May 2013 05:42:43 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[Burp Suite]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Web App]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55545</guid>
		<description><![CDATA[Ok everyone &#8211; LET&#8217;S DO THIS!!!!!!!!!!! All day Saturday/Sunday June 8th and 9th.  1 full day of Network Pentesting (8th), and 1 full day of Web App Pentesting (9th). We’ll    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/05/20/pentester-weekend-bootcamp/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Ok everyone &#8211; LET&#8217;S DO THIS!!!!!!!!!!!</p>
<p>All day Saturday/Sunday June 8th and 9th.  1 full day of Network Pentesting (8<sup>th</sup>), and 1 full day of Web App Pentesting (9<sup>th</sup>). We’ll go from 10am-3pm each day. You’ll get your courseware and network access on the 7<sup>th</sup> of June and maintain access to the lab network until the 30<sup>th</sup> of June.</p>
<p>The webinars will be recorded each day, and the network will be fluid (targets changing each day in some cases several times a day). Get ready – this workshop is gonna be full on pentesting covering both Network and Web App Pentesting all in one shot!</p>
<p><b>Day 1:</b></p>
<ul>
<li>External Network Scanning</li>
<li>Internal Network Scanning</li>
<li>Exploitation (Service and Client-Side)</li>
<li>Post-Exploitation</li>
<li>Getting REALLY comfortable with Metasploit (lots of tips and tricks)</li>
</ul>
<p>&nbsp;</p>
<p><b>Day 2:</b></p>
<ul>
<li>SQL Injection</li>
<li>Cross Site Scripting</li>
<li>File Handling Vulnerabilities</li>
<li>Getting REALLY comfortable with Burp Suite (lots of tips and tricks)</li>
</ul>
<p><b>Pentester Weekend Bootcamp Cost is $150 – <a title="Click here to purchase for $150" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesters%20Weekend%20Bootcamp%20June%202013&amp;item_number=PWB-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesters%20Weekend%20Bootcamp%20June%202013&amp;item_number=PWB-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">click here to purchase for $150</a></b></p>
<p>Or</p>
<p><b>You can have it for $100 if you:</b></p>
<ol>
<li>Post about it on Twitter</li>
<li>Like this page on Facebook</li>
<li>+1 this page on Google+</li>
</ol>
<p>Send me an email with proof that you’ve done this and I’ll reply with the $100 payment link</p>
<p>Hope to see you in class.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/05/20/pentester-weekend-bootcamp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CyberWar</title>
		<link>http://strategicsec.com/services/training-services/online/cyberwar/</link>
		<comments>http://strategicsec.com/services/training-services/online/cyberwar/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:22:59 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55535</guid>
		<description><![CDATA[Coming Soon]]></description>
				<content:encoded><![CDATA[<p>Coming Soon</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/cyberwar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Development</title>
		<link>http://strategicsec.com/services/training-services/online/exploit-development/</link>
		<comments>http://strategicsec.com/services/training-services/online/exploit-development/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:17:34 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55533</guid>
		<description><![CDATA[This workshop is for newbies to the world of exploit development. It takes participants from “n00b” to “31337? – ok just kidding not quite “31337”, but it will help you    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/exploit-development/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>This workshop is for newbies to the world of exploit development. It takes participants from “n00b” to “31337? – ok just kidding not quite “31337”, but it will help you get comfortable with the subject because you are given the time to actually absorb the material.</p>
<p>Each Saturday from noon to 4pm EST Joe McCray will host a webinar.</p>
<p>Here are some of the topics to look forward to:</p>
<p>Course Outline:</p>
<p><strong>Week 1</strong> – Stack Overflows</p>
<p><strong>Week 2</strong> – Structured Exception Handlers</p>
<p><strong>Week 3</strong> – Heap Spray</p>
<p><strong>Week 4</strong> – Shellcoding Tricks</p>
<p>Each week Joe will host the 4 hour webinar where he will walk through the previous week’s homework exercises, cover the material for the current week, take questions from the students, and provide homework for the upcoming week. The homework that is handed out each week is designed so students can work on and reinforce each week’s lesson.</p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100                       <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%201&amp;item_number=ED-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%201&amp;item_number=ED-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500                       <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%202&amp;item_number=ED-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%202&amp;item_number=ED-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500                            <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%203&amp;item_number=ED-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Level%203&amp;item_number=ED-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/exploit-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powershell</title>
		<link>http://strategicsec.com/services/training-services/online/powershell/</link>
		<comments>http://strategicsec.com/services/training-services/online/powershell/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:15:34 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55531</guid>
		<description><![CDATA[Here’s the low down. If you are hacking modern versions of Windows (Windows 7, Windows 8, Server 2008, Server 2012) – you need Powershell. What will we be doing you    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/powershell/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Here’s the low down. If you are hacking modern versions of Windows (Windows 7, Windows 8, Server 2008, Server 2012) – you need Powershell.</p>
<p>What will we be doing you ask – check this out:</p>
<p>Fundamenatls:</p>
<p>- Cmdlets</p>
<p>- Variables</p>
<p>- WMI Objects</p>
<p>- Interacting With Active Directory</p>
<p>Hacking with Powershell:</p>
<p>- Traditional Hacking</p>
<p>- Ping Sweeping</p>
<p>- Port Scanning</p>
<p>- Enumerating Hosts/Networks</p>
<p>- Download &amp; Execute</p>
<p>- Parsing Nmap</p>
<p>- Parsing Nessus</p>
<p>- Powersploit</p>
<p>- Nishang</p>
<p>…and of course integrating with Metasploit</p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100                <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%201&amp;item_number=PFP-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%201&amp;item_number=PFP-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500                <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%202&amp;item_number=PFP-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%202&amp;item_number=PFP-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500                     <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%203&amp;item_number=PFP-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20Level%203&amp;item_number=PFP-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/powershell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Python</title>
		<link>http://strategicsec.com/services/training-services/online/python/</link>
		<comments>http://strategicsec.com/services/training-services/online/python/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:13:44 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55529</guid>
		<description><![CDATA[This class is for security professionals that have VERY LITTLE PROGRAMMING EXPERIENCE. Week 1: Programming Concepts, Parsing Files, Logs, and PCAPs Python Basics Text File Parsing Log Parsing PCAP Parsing Week    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/python/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>This class is for security professionals that have VERY LITTLE PROGRAMMING EXPERIENCE.</p>
<p><strong>Week 1:</strong> Programming Concepts, Parsing Files, Logs, and PCAPs</p>
<p>Python Basics</p>
<p>Text File Parsing</p>
<p>Log Parsing</p>
<p>PCAP Parsing</p>
<p><strong>Week 2:</strong> Password Cracking, Netcat, Port-Scanning, and simple fuzzing</p>
<p>Password Cracking</p>
<p>Netcat-like Functionality</p>
<p>Port-Scanning</p>
<p>Fuzzing</p>
<p><strong>Week 3:</strong> Web Application Vulnerability Testing</p>
<p>Vulnerable Service Identification</p>
<p>SQL Injection</p>
<p>XSS</p>
<p>RFI/LFI</p>
<p><strong>Week 4:</strong> Writing Your Own Security Tools</p>
<p>Click Here To Signup</p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100           <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%201&amp;item_number=PFSP-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%201&amp;item_number=PFSP-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500           <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%202&amp;item_number=PFSP-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%202&amp;item_number=PFSP-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500                <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%203&amp;item_number=PFSP-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20Level%203&amp;item_number=PFSP-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/python/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IDS Signature Writing</title>
		<link>http://strategicsec.com/services/training-services/online/ids-signature-writing/</link>
		<comments>http://strategicsec.com/services/training-services/online/ids-signature-writing/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:11:53 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55527</guid>
		<description><![CDATA[Coming Soon]]></description>
				<content:encoded><![CDATA[<p>Coming Soon</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/ids-signature-writing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Analysis</title>
		<link>http://strategicsec.com/services/training-services/online/malware-analysis/</link>
		<comments>http://strategicsec.com/services/training-services/online/malware-analysis/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:09:41 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55525</guid>
		<description><![CDATA[The goal of this class is to provide a methodical hands-on approach to malware analysis by covering both behavioral and code analysis aspects of the analytical process. Week 1: Basic Forensics    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/malware-analysis/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The goal of this class is to provide a methodical hands-on approach to malware analysis by covering both behavioral and code analysis aspects of the analytical process.</p>
<p><strong>Week 1:</strong> Basic Forensics</p>
<p>Analyzing a hard drive image</p>
<p>Recovering deleted files</p>
<p>Decrypting encrypted files</p>
<p><strong>Week 2:</strong> Bypassing Anti-Virus</p>
<p>Using Hex Editors to bypass AV</p>
<p>Using packers to bypass AV</p>
<p>Using debuggers/disassemblers to bypass AV</p>
<p><strong>Week 3:</strong> Network/Browser Forensics</p>
<p>Advanced pcap analysis</p>
<p>De-obfuscating malicious javascript</p>
<p><strong>Week 4:</strong> Memory Analysis</p>
<p>Memory analysis</p>
<p>Malicious pdf file analysis</p>
<p>DLL injection</p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100            <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%201&amp;item_number=MA-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%201&amp;item_number=MA-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500            <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%202&amp;item_number=MA-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%202&amp;item_number=MA-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500                 <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%203&amp;item_number=MA-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Level%203&amp;item_number=MA-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web App Pentester Night School</title>
		<link>http://strategicsec.com/services/training-services/online/web-app-pentester-night-school/</link>
		<comments>http://strategicsec.com/services/training-services/online/web-app-pentester-night-school/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:03:46 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55523</guid>
		<description><![CDATA[So what exactly do I mean by “Hands-on” – this video is a good example of the kinds of things you’ll be learning. Course Outline Week 1: Simple ASP/ MSSQL Web    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/web-app-pentester-night-school/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>So what exactly do I mean by “Hands-on” – this video is a good example of the kinds of things you’ll be learning.</p>
<p>Course Outline</p>
<p><strong>Week 1:</strong> Simple ASP/ MSSQL Web App</p>
<p><strong>Week 2:</strong> PHP/MySQL Web App</p>
<p><strong>Week 3:</strong> JSP/Oracle Web App</p>
<p><strong>Week 4:</strong> Tricky Stuff</p>
<p>Specifics I’ll Be Covering</p>
<p>SQL Injection</p>
<p>Cross-Site Scripting</p>
<p>Web Shells</p>
<p>Filter Evasion</p>
<p>SQL Injection to a command-shell</p>
<p>XSS to a command-shell</p>
<p>WAF Bypass</p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100          <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500          <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500               <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20Level%201&amp;item_number=WAPNS-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/web-app-pentester-night-school/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Pentester Night School</title>
		<link>http://strategicsec.com/services/training-services/online/network-pentester-night-school/</link>
		<comments>http://strategicsec.com/services/training-services/online/network-pentester-night-school/#comments</comments>
		<pubDate>Fri, 17 May 2013 06:01:22 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55521</guid>
		<description><![CDATA[The primary focus of the class is ‘goal oriented pentesting’, or emulating Advanced Persistent Threat so there will be a lot of focus on Bypassing Anti-Virus, and POST EXPLOITATION (with    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/network-pentester-night-school/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The primary focus of the class is ‘goal oriented pentesting’, or emulating Advanced Persistent Threat so there will be a lot of focus on Bypassing Anti-Virus, and POST EXPLOITATION (with and without Metasploit).</p>
<p>The network environment is going to be highly fluid, really volatile. Each day the network topology will be changing slightly.</p>
<p>Class Outline</p>
<p><strong>Week 1:</strong> Scanning &amp; Exploitation</p>
<p>Dealing with Load Balancers, IPS, and WAF</p>
<p>Web Attacks</p>
<p>Client-Side Exploitation</p>
<p><strong>Week 2:</strong> BypassingAV</p>
<p>File Splitting</p>
<p>Packing</p>
<p>Encoding</p>
<p>Shellcode Injection</p>
<p><strong>Week 3:</strong> Post Exploitation</p>
<p>Getting Files On/Off System</p>
<p>Download and Execute</p>
<p>Creating Listeners/Backdoor Services</p>
<p>Different Kinds of Reverse Shells</p>
<p>Automating Tasks</p>
<p>Privilege Escalation</p>
<p>Lateral Movement</p>
<p>Pass The Hash</p>
<p>Host Enumeration</p>
<p>Host Data Mining</p>
<p>Active Directory Enumeration</p>
<p><strong>Week 4:</strong> Your Pentest</p>
<p><strong>Level 1.</strong> Courseware, Labs, forums, videos $100          <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%201&amp;item_number=PNS-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%201&amp;item_number=PNS-Level1&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 2:</strong> Live Online (Nights or Weekends) $500         <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%202&amp;item_number=PNS-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%202&amp;item_number=PNS-Level2&amp;amount=500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p><strong>Level 3:</strong> Live Online (5-Day weekdays) $1500              <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%203&amp;item_number=PNS-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20Level%203&amp;item_number=PNS-Level3&amp;amount=1500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/network-pentester-night-school/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powershell For Pentesters</title>
		<link>http://strategicsec.com/2013/05/09/powershell-for-pentesters/</link>
		<comments>http://strategicsec.com/2013/05/09/powershell-for-pentesters/#comments</comments>
		<pubDate>Thu, 09 May 2013 19:53:11 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[Metasploi]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[Nishang]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[Powersploit]]></category>
		<category><![CDATA[WMI Objects]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55499</guid>
		<description><![CDATA[Everyone knows my love for Python, but I&#8217;ve got to be honest and let you know that Powershell is a close second to my beloved Python. Here&#8217;s the low down.    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/05/09/powershell-for-pentesters/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Everyone knows my love for Python, but I&#8217;ve got to be honest and let you know that Powershell is a close second to my beloved Python.</p>
<p>Here&#8217;s the low down. If you are hacking modern versions of Windows (Windows 7, Windows 8, Server 2008, Server 2012) &#8211; you need Powershell.</p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20June%202013&amp;item_number=PFP-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Powershell%20For%20Pentesters%20June%202013&amp;item_number=PFP-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">The class cost is $100 &#8211; click here to purchase</a></p>
<p>What will we be doing you ask &#8211; check this out:</p>
<p><strong>Fundamenatls:</strong><br />
- Cmdlets<br />
- Variables<br />
- WMI Objects<br />
- Interacting With Active Directory</p>
<p><strong>Hacking with Powershell:</strong><br />
- Traditional Hacking<br />
- Ping Sweeping<br />
- Port Scanning<br />
- Enumerating Hosts/Networks<br />
- Download &amp; Execute<br />
- Parsing Nmap<br />
- Parsing Nessus<br />
- Powersploit<br />
- Nishang</p>
<p>&#8230;..and of course integrating with Metasploit</p>
<p>This class will run for the entire month of June on Tues/Thurs from 7pm – 9pm EST<br />
The classes will be recorded so students can still view the lessons if they miss an individual class.</p>
<p>Or, you can bundle with the Python class that is already running right now for $150</p>
<p><a title="Click Here To Signup For $150USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=%20Python%20For%20Security%20Professionals%20and%20Powershell%20For%20Pentesters%20May%20and%20June%202013&amp;item_number=%20PFSP-MAY-PFP-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=%20Python%20For%20Security%20Professionals%20and%20Powershell%20For%20Pentesters%20May%20and%20June%202013&amp;item_number=%20PFSP-MAY-PFP-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the Python and Powershell bundle for $150</a></p>
<p>If you&#8217;ve already purchased the Python For Security Professionals class &#8211; send me an email and I&#8217;ll give you the Powershell for the additional $50.</p>
<p>If you&#8217;ve already purchased the Python For Security Professionals &amp; Python For Tool Security Development package &#8211; send me an email and I&#8217;ll give you the Powershell for <span style="text-decoration: underline;"><span style="color: #ff0000; text-decoration: underline;">FREE</span></span>.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/05/09/powershell-for-pentesters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking in Paradise Giveaway 2013</title>
		<link>http://strategicsec.com/2013/05/06/hacking-in-paradise-giveaway-2013/</link>
		<comments>http://strategicsec.com/2013/05/06/hacking-in-paradise-giveaway-2013/#comments</comments>
		<pubDate>Tue, 07 May 2013 03:46:39 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55494</guid>
		<description><![CDATA[Strategic Security is giving away four free seats (1 seat per month from April – July) to Hacking In Paradise – The Bahamas 2013. This is a full package deal    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/05/06/hacking-in-paradise-giveaway-2013/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Strategic Security is giving away four free seats (1 seat per month from April – July) to Hacking In Paradise – The Bahamas 2013.</p>
<p>This is a full package deal offer – so you’ll get airfare, lodging, and the training if you win.</p>
<p>To enter and be considered for one of the seats you’ll have to perform several activities.<br />
You can do as many activities as you want everyday – good luck.</p>
<p>After you complete your tasks, send an email to joe(at)strategicsec(dot)com with publicly viewable links to the completed activities.</p>
<p>Here are the entry activities:</p>
<p>- Tweet about this giveaway (3 points)<br />
- Follow @j0emccray on twitter (1 point)<br />
- Follow @strategicsec on twitter (1 point)<br />
- Friend j0emccray on facebook [facebook.com/j0emccray] (1 point)<br />
- Add gplus.to/j0emccray to one of your circles on Google+ (1 point)<br />
- Like this page on facebook (1 point)<br />
- +1 Hacking in Paradise page on Google+ (1 point)<br />
- Blog about this class (3 points)<br />
- Google+ post about this class (3 points)<br />
- Follow @ITSecPros on twitter (5 points)<br />
- +1 IT Security Professionals page on Google+ (1 point)</p>
<p><a class="rafl" id="rc-2b3ea72" href="http://www.rafflecopter.com/rafl/display/2b3ea72/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.rafflecopter.com/rafl/display/2b3ea72/']);" rel="nofollow">a Rafflecopter giveaway</a><br />
<script type="text/javascript" src="//d12vno17mo87cx.cloudfront.net/embed/rafl/cptr.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/05/06/hacking-in-paradise-giveaway-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About us</title>
		<link>http://strategicsec.com/about-us-2/</link>
		<comments>http://strategicsec.com/about-us-2/#comments</comments>
		<pubDate>Mon, 06 May 2013 12:44:38 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55473</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[<div class="su-tabs su-tabs-style-1">
<div class="su-tabs-nav"><span>Tab 0</span><span>Tab 1</span><span>Tab 2</span><span>Tab 3</span><span>Tab 4</span><span>Tab 5</span></div>
<div class="su-tabs-panes">
<div class="su-tabs-pane">
<p>Strategic Security is an Information Technology (IT) Security consulting firm that provides in-depth technical security assessments of your networks or web applications, regulatory compliance gap analysis (ex: PCI, HIPAA, ISO 27000, etc), guidance on integrating security into your software development life cycle, building an enterprise security program, and much more.</p>
<p>Although these services are offered by most security consulting firms, implementing and maintaining an effective information security management practices involves more than just security testing and compliance. Today’s organizations must first identify how they use information to meet their strategic business goals and then determine the best ways to protect their information assets throughout the information security life cycle.</p>
<p>Strategic Security’s highly skilled practitioners employ tremendous skill in the areas of penetration testing and compliance auditing, but the real skill – the real value Strategic Security brings to the table is the ability to understand our client’s business vision, mission, goals and strategic business objectives. By assessing our client’s enterprise security posture, we can effectively ensure that critical security areas are aligned with organizational business objectives taking into account associated business risks and reducing operating expenses. We welcome you to browse the website. Please read the <a title="case studies" href="http://strategicsec.com/strategic-security-difference-2/case-studies/"  target="_self">case studies</a>, <a title="testimonials" href="http://strategicsec.com/strategic-security-difference-2/testimonials/"  target="_self">testimonials</a>, and feel free to <a title="contact us" href="http://strategicsec.com/about-us/contact-us/" >contact us</a> for more information including references, work samples. More importantly, if your organization is interested in learning more about  how Strategic Security can help achieve your business goals while ensuring that your company’s security is aligned with them, <a title="contact us" href="http://strategicsec.com/about-us/contact-us/" >contact us</a> today.</p>
<p>&nbsp;</p>
<p><span style="color: #000000;"><strong>Please see also:</strong></span></p>
<ul>
<li><a href="http://strategicsec.com/about-us/company-overview/" >Company Overview</a></li>
<li><a href="http://strategicsec.com/about-us/about-the-founder/" >About The Founder</a></li>
<li><a href="http://strategicsec.com/about-us/our-values/" >Our Values</a></li>
<li><a href="http://strategicsec.com/about-us/client-service/" >Client Service</a></li>
<li><a href="http://strategicsec.com/about-us/contact-us/" >Contact Us</a></li>
</ul>
</div>
<div class="su-tabs-pane">
<p><span style="color: #000000;">We like to say &#8220;A problem is one week, and impossible is two.&#8221;</span></p>
<p><span style="color: #000000;">There is no substitute for experience and just flat out knowing an industry inside and out. Organizations need to track the competitive landscape, regulatory changes, and advances in technology to compete and thrive in their respective sectors.</span><br />
<span style="color: #000000;"> Our consultants draw upon years of experience as well as deep industry knowledge to ensure our clients&#8217; security and more importantly their success.</span></p>
</div>
<div class="su-tabs-pane">
<p><span style="color: #000000;">Joe McCray is an Air Force Veteran and has been in security for over 10 years. Joe has been involved in over 150 very high level pentesting assessments and has some major hacking accomplishments that he can share with his clients and students.</span></p>
<p><span style="color: #000000;">His extensive experience and deep knowledge, mixed with his comedic style has lead Joe to be one of the most highly sought after speaking experts in the industry. Joe often makes speaking appearances and gives seminars at major events in the security community such as Black Hat, DefCon, BruCon, Hacker Halted and more.</span></p>
</div>
<div class="su-tabs-pane"></div>
<div class="su-tabs-pane">
<p><span style="color: #000000;">We are consultants, not insultants! We aren&#8217;t copy/paste consultants. We aren&#8217;t spreadsheet ninjas. There is no bait and switch here (Some consulting organizations send a “selling team” (senior consultants or partners who are good at sales presentations and deal-closing) and may do not adequately reveal who will actually be doing the bulk of the work, who may be less experienced associates).</span></p>
<p><span style="color: #000000;">We&#8217;re not here to tell you stuff you already know, or give you a huge report full of meaningless information.</span></p>
</div>
<div class="su-tabs-pane">
<form id="wpc_b9241548c9a3cb179458efc9b00d5e87_form" class="form-horizontal wp_crm_contact_form wp_crm_contact_form_example_form">
<ul class="wp_crm_contact_form">
<li class="wp_crm_b9241548c9a3cb179458efc9b00d5e87_first">
              <input type="hidden" name="action" value="process_crm_message" /><br />
        <input type="text" name="wp_crm_nonce" value="b9241548c9a3cb179458efc9b00d5e87" /><br />
        <input type="text" name="email" /><br />
        <input type="text" name="name" /><br />
        <input type="text" name="url" /><br />
        <input type="text" name="comment" /><br />
        <input type="hidden" name="wp_crm[success_message]" value="Your message has been sent. Thank you." />
                  </li>
<li class="wp_crm_form_element wp_crm_required_field wp_crm_display_name_container">
<div class="control-group wp_crm_display_name_div">
        <label class="control-label wp_crm_input_label">Display Name</label></p>
<div class="controls wp_crm_input_wrapper">
                                  <input  TABINDEX=1  wp_crm_slug="display_name" random_hash="21901" name="wp_crm[user_data][display_name][21901][value]"  class="input-large wp_crm_display_name_field wp_crm_display_name_field regular-text wp_crm_required_field" type="text" value="" /><br />
                                            <span class="help-inline wp_crm_error_messages"></span>
        </div>
</p></div>
</li>
<li class="wp_crm_form_element wp_crm_required_field wp_crm_user_email_container">
<div class="control-group wp_crm_user_email_div">
        <label class="control-label wp_crm_input_label">User Email</label></p>
<div class="controls wp_crm_input_wrapper">
                                  <input  TABINDEX=2  wp_crm_slug="user_email" random_hash="95821" name="wp_crm[user_data][user_email][95821][value]"  class="input-large wp_crm_user_email_field wp_crm_user_email_field regular-text wp_crm_required_field email_validated" type="text" value="" /><br />
                                            <span class="help-inline wp_crm_error_messages"></span>
        </div>
</p></div>
</li>
<li class="wp_crm_form_element  wp_crm_company_container">
<div class="control-group wp_crm_company_div">
        <label class="control-label wp_crm_input_label">Company</label></p>
<div class="controls wp_crm_input_wrapper">
                                  <input  TABINDEX=3  wp_crm_slug="company" random_hash="31471" name="wp_crm[user_data][company][31471][value]"  class="input-large wp_crm_company_field wp_crm_company_field regular-text" type="text" value="" /><br />
                                            <span class="help-inline wp_crm_error_messages"></span>
        </div>
</p></div>
</li>
<li class="wp_crm_form_element  wp_crm_phone_number_container">
<div class="control-group wp_crm_phone_number_div">
        <label class="control-label wp_crm_input_label">Phone Number</label></p>
<div class="controls wp_crm_input_wrapper">
                                  <input  TABINDEX=4  wp_crm_slug="phone_number" random_hash="86542" name="wp_crm[user_data][phone_number][86542][value]"  class="input-large wp_crm_phone_number_field wp_crm_phone_number_field regular-text" type="text" value="" /><br />
                                            <span class="help-inline wp_crm_error_messages"></span>
        </div>
</p></div>
</li>
<li class="wp_crm_form_element wp_crm_message_field ">
<div class="control-group">
      <label class="control-label wp_crm_input_label">&nbsp;</label></p>
<div class="controls wp_crm_input_wrapper">
                 <textarea wp_crm_slug="message_field"   TABINDEX=5  random_hash="79483" name="wp_crm[user_data][message_field][79483][value]" class="input-large wp_crm_message_field_field wp_crm_message_field_field"></textarea>
                      </div>
</p></div>
</li>
<li class="wp_crm_form_response">
<div class="wp_crm_response_text" style="display:none;"></li>
<li class="wp_crm_submit_row">
<div class="control-group">
<div class="controls wp_crm_input_wrapper">
          <input class="btn-primary c9b5dd5a1c71c4d7f608037e0bed884d" type="submit" value="Submit" />
        </div>
</p></div>
<p>      <input type="hidden" name="form_slug" value="419662a1cc9f51e9ea6237fe49d239af" /><br />
      <input type="hidden" name="associated_object" value="55473" />
    </li>
</ul></form>
<style type="text/css">.wp_crm_b9241548c9a3cb179458efc9b00d5e87_first {display:none;}</style>
<p>  <script type="text/javascript">
    jQuery(document).ready(function() {</p>
<p>      if(typeof wp_crm_developer_log != 'function') {
        function wp_crm_developer_log() {}
      }</p>
<p>      if(typeof _gaq != 'object') {
        var _gaq = false;
      }</p>
<p>      if(_gaq) {
        _gaq.push(['_trackEvent', "Contact Form", "Viewed", "Shortcode Form 1"]);
      }</p>
<p>      var this_form = jQuery("#wpc_b9241548c9a3cb179458efc9b00d5e87_form");
      var submit_button = jQuery("input[type=submit]", this_form);
      var form_response_field = jQuery(".wp_crm_form_response div", this_form);</p>
<p>      var this_form_data = {};
      var validation_error = false;</p>
<p>      jQuery(this_form).change(function(event) {</p>
<p>        if(this_form_data.start_form == undefined) {
          this_form_data.start_form = event.timeStamp;
        }</p>
<p>        if(_gaq &#038;& this_form_data.interaction_logged !== undefined) {
          _gaq.push(['_trackEvent', "Contact Form", "Interacted With", "Shortcode Form 1"]);
          this_form_data.interaction_logged = true;
        }</p>
<p>      });</p>
<p>      jQuery(this_form).submit(function(event) {
        event.preventDefault();
        submit_this_form();
      });</p>
<p>      jQuery(submit_button).click(function(event) {
        event.preventDefault();
        submit_this_form();
      });</p>
<p>          jQuery(".wp_crm_user_email_field", this_form).change(function() {
        validation_error = true;
        submit_this_form('system_validate', this);
      });</p>
<p>      function submit_this_form(crm_action, trigger_object) {
        var validation_error = false;
        var form = this_form;</p>
<p>        wp_crm_developer_log('submit_this_form() initiated.');</p>
<p>        if(typeof wp_crm_save_user_form == 'function') {
          /* passed form object into wp_crm_save_user_form() is not usable */
          if(!wp_crm_save_user_form(jQuery(form))) {
            return false;
          }
        } else {
          wp_crm_developer_log('wp_crm_save_user_form() function does not exist.');
        }</p>
<p>        jQuery("*", form).removeClass(form).removeClass("wp_crm_input_error");
        jQuery(".control-group", form).removeClass(form).removeClass("error");</p>
<p>        jQuery("span.wp_crm_error_messages", form).removeClass(form).text("");</p>
<p>        if(validation_error) {
          jQuery(submit_button).removeAttr("disabled");
          return false;
        }</p>
<p>        params = jQuery(this_form).serialize();</p>
<p>        if(crm_action != 'system_validate') {
          jQuery(submit_button).attr("disabled", "disabled");</p>
<p>          jQuery(form_response_field).show();
          jQuery(form_response_field).removeClass('success');
          jQuery(form_response_field).removeClass('failure');
          jQuery(form_response_field).text("Processing...");
        }</p>
<p>        if(crm_action) {
          params = params + "&#038;crm_action=" + crm_action;
        }</p>
<p>        jQuery(submit_button).attr("disabled", "disabled");</p>
<p>        jQuery.ajax({
          url: "http://strategicsec.com/wp-admin/admin-ajax.php",
          dataType: "json",
          data: params,
          cache: false,
          success: function(result) {</p>
<p>            /* Enable submit button in case it was disabled during validation */
            jQuery(submit_button).removeAttr("disabled");</p>
<p>            /* Get conflicting fields */
            if(result.bad_fields !== undefined) {</p>
<p>              jQuery.each(result.bad_fields, function(field) {</p>
<p>                /* If check started by a specific object, we only update it */
                if(jQuery(trigger_object).hasClass("regular-text") &#038;& jQuery(trigger_object).attr("wp_crm_slug") != field) {
                  return;
                }</p>
<p>                jQuery("div.wp_crm_"+field+"_div input.regular-text:first, div.wp_crm_"+field+"_div select", form).addClass("wp_crm_input_error");
                jQuery("div.wp_crm_"+field+"_div.control-group", form).addClass("error");
                jQuery("div.wp_crm_"+field+"_div span.wp_crm_error_messages", form).text(result.bad_fields[field]);
              });
            }</p>
<p>            /* If doing only a validation, stop here */
            if(crm_action == 'system_validate') {
              if(result.validation_passed == true) {
                validation_error = true;
              } else {
                validation_error = false;
              }
              return;
            }</p>
<p>            if(result.success == "true") {</p>
<p>              if(_gaq) {
                _gaq.push(['_trackEvent', "Contact Form: Shortcode Form 1", "Submitted", "Total Time", (+new Date) - this_form_data.start_time]);
              }</p>
<p>              jQuery(form_response_field).addClass("success");
              jQuery(submit_button).removeAttr("disabled");</p>
<p>            } else {</p>
<p>              if(_gaq) {
                _gaq.push(['_trackEvent', "Contact Form: Shortcode Form 1", "Submission Failure", result.message]);
                this_form_data.interaction_logged = true;
              }</p>
<p>              jQuery(form_response_field).addClass("failure");
              jQuery(submit_button).removeAttr("disabled");
            }</p>
<p>            jQuery(form_response_field).text(result.message);</p>
<p>        },
        error: function(result) {</p>
<p>          jQuery(form_response_field).show();
          jQuery(form_response_field).addClass("failure");
          jQuery(form_response_field).text("A server error occurred while trying to process the form.");</p>
<p>          jQuery(form_response_field).addClass("failure");
          jQuery(submit_button).removeAttr("disabled");</p>
<p>          if(_gaq) {
            _gaq.push(['_trackEvent', "Contact Form: Shortcode Form 1", "Submission Failure", "Server error."]);
            this_form_data.interaction_logged = true;
          }</p>
<p>        }
      });</p>
<p>     }</p>
<p>    });
  </script>
  </div>
</div>
<div class="su-spacer"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Contact Us</title>
		<link>http://strategicsec.com/about-us/contact-us/</link>
		<comments>http://strategicsec.com/about-us/contact-us/#comments</comments>
		<pubDate>Thu, 02 May 2013 06:43:11 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55463</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[<div class="wpcf7" id="wpcf7-f55486-p55463-o1">
<form action="/feed/#wpcf7-f55486-p55463-o1" method="post" class="wpcf7-form" novalidate="novalidate">
<div style="display: none;">
<input type="hidden" name="_wpcf7" value="55486" /><br />
<input type="hidden" name="_wpcf7_version" value="3.4" /><br />
<input type="hidden" name="_wpcf7_unit_tag" value="wpcf7-f55486-p55463-o1" /><br />
<input type="hidden" name="_wpnonce" value="286576d06b" />
</div>
<p>Display Name (required)<br />
    <span class="wpcf7-form-control-wrap display-name"><input type="text" name="display-name" value="" size="40" class="wpcf7-form-control wpcf7-text wpcf7-validates-as-required" aria-required="true" /></span> </p>
<p>User Email (required)<br />
    <span class="wpcf7-form-control-wrap user-email"><input type="email" name="user-email" value="" size="40" class="wpcf7-form-control wpcf7-text wpcf7-email wpcf7-validates-as-required wpcf7-validates-as-email" aria-required="true" /></span> </p>
<p>Company<br />
    <span class="wpcf7-form-control-wrap company"><input type="text" name="company" value="" size="40" class="wpcf7-form-control wpcf7-text" /></span> </p>
<p>Phone Number<br />
    <span class="wpcf7-form-control-wrap phone"><input type="text" name="phone" value="" size="40" class="wpcf7-form-control wpcf7-text" /></span> </p>
<p>Your Message<br />
    <span class="wpcf7-form-control-wrap your-message"><textarea name="your-message" cols="40" rows="10" class="wpcf7-form-control wpcf7-textarea"></textarea></span> </p>
<p><input type="submit" value="Send" class="wpcf7-form-control wpcf7-submit" /></p>
<div class="wpcf7-response-output wpcf7-display-none"></div>
</form>
</div>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/contact-us/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Client Service</title>
		<link>http://strategicsec.com/about-us/client-service/</link>
		<comments>http://strategicsec.com/about-us/client-service/#comments</comments>
		<pubDate>Thu, 02 May 2013 06:42:38 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55461</guid>
		<description><![CDATA[We are consultants, not insultants! We aren&#8217;t copy/paste consultants. We aren&#8217;t spreadsheet ninjas. There is no bait and switch here (Some consulting organizations send a “selling team” (senior consultants or    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/about-us/client-service/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>We are consultants, not insultants! We aren&#8217;t copy/paste consultants. We aren&#8217;t spreadsheet ninjas. There is no bait and switch here (Some consulting organizations send a “selling team” (senior consultants or partners who are good at sales presentations and deal-closing) and may do not adequately reveal who will actually be doing the bulk of the work, who may be less experienced associates).</p>
<p>We&#8217;re not here to tell you stuff you already know, or give you a huge report full of meaningless information.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/client-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Our Values</title>
		<link>http://strategicsec.com/about-us/our-values/</link>
		<comments>http://strategicsec.com/about-us/our-values/#comments</comments>
		<pubDate>Thu, 02 May 2013 06:41:57 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55459</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/our-values/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About The Founder</title>
		<link>http://strategicsec.com/about-us/about-the-founder/</link>
		<comments>http://strategicsec.com/about-us/about-the-founder/#comments</comments>
		<pubDate>Thu, 02 May 2013 06:41:08 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55457</guid>
		<description><![CDATA[Joe McCray is an Air Force Veteran and has been in security for over 10 years. Joe has been involved in over 150 very high level pentesting assessments and has    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/about-us/about-the-founder/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Joe McCray is an Air Force Veteran and has been in security for over 10 years. Joe has been involved in over 150 very high level pentesting assessments and has some major hacking accomplishments that he can share with his clients and students.</p>
<p>His extensive experience and deep knowledge, mixed with his comedic style has lead Joe to be one of the most highly sought after speaking experts in the industry. Joe often makes speaking appearances and gives seminars at major events in the security community such as Black Hat, DefCon, BruCon, Hacker Halted and more.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/about-the-founder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Company Overview</title>
		<link>http://strategicsec.com/about-us/company-overview/</link>
		<comments>http://strategicsec.com/about-us/company-overview/#comments</comments>
		<pubDate>Thu, 02 May 2013 06:39:30 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55454</guid>
		<description><![CDATA[We like to say &#8220;A problem is one week, and impossible is two.&#8221; There is no substitute for experience and just flat out knowing an industry inside and out. Organizations    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/about-us/company-overview/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>We like to say &#8220;A problem is one week, and impossible is two.&#8221;</p>
<p>There is no substitute for experience and just flat out knowing an industry inside and out. Organizations need to track the competitive landscape, regulatory changes, and advances in technology to compete and thrive in their respective sectors.<br />
Our consultants draw upon years of experience as well as deep industry knowledge to ensure our clients&#8217; security and more importantly their success.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/company-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So You Wanna Be A Pentester &#8211; Free Webinar To Show You How</title>
		<link>http://strategicsec.com/2013/04/10/so-you-wanna-be-a-pentester-free-webinar-to-show-you-how/</link>
		<comments>http://strategicsec.com/2013/04/10/so-you-wanna-be-a-pentester-free-webinar-to-show-you-how/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 23:18:48 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Webinars]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[degree]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[pentester]]></category>
		<category><![CDATA[salary]]></category>
		<category><![CDATA[security clearance]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55407</guid>
		<description><![CDATA[I’ll be hosting a FREE webinar on the subject of becoming a penetration tester. Title:    So You Wanna Be A Pentester Date:    Thursday, May 23, 2013 Time:    2:00 PM &#8211;    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/04/10/so-you-wanna-be-a-pentester-free-webinar-to-show-you-how/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I’ll be hosting a <a href="https://www4.gotomeeting.com/register/422400863" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www4.gotomeeting.com/register/422400863']);">FREE webinar</a> on the subject of becoming a penetration tester.</p>
<p>Title:    <a title="Click Here To Signup" href="https://www4.gotomeeting.com/register/422400863" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www4.gotomeeting.com/register/422400863']);">So You Wanna Be A Pentester</a><br />
Date:    Thursday, May 23, 2013<br />
Time:    2:00 PM &#8211; 3:00 PM EDT</p>
<p>&nbsp;</p>
<p>I’ll be covering things like:</p>
<ul>
<li>Some of the various types of penetration testing jobs</li>
<li>Education/Certification/Experience/Skill requirements
<ul>
<li>Should I have a degree – if so what type?</li>
<li>Should I have certifications – if so which ones?</li>
<li>Should I have work experience – if so what type?</li>
<li>What skills should I have prior to applying?</li>
<li>Do I need to be a good programmer?</li>
<li>Where can I get these skills if I’m not currently working in the field?</li>
<li>Security clearance requirements</li>
<li>What are good key words to use when searching IT job sites for pentesting jobs?</li>
<li>What to expect during the interview process</li>
<li>I’m not in the US, where can I find pentester work abroad?</li>
<li>How much money can I expect to make as a pentester?</li>
<li>The good the bad and the ugly…what the work is actually like day-in and day-out</li>
</ul>
</li>
</ul>
<p>I’m hoping that newbies that want to get into the field will find this <a href="https://www4.gotomeeting.com/register/422400863" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www4.gotomeeting.com/register/422400863']);">webinar</a> helpful.</p>
<p><b>Space is limited.</b><br />
<a href="https://www4.gotomeeting.com/register/422400863" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www4.gotomeeting.com/register/422400863']);">Reserve your Webinar seat</a> now at:<br />
<a href="https://www4.gotomeeting.com/register/422400863" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www4.gotomeeting.com/register/422400863']);">https://www4.gotomeeting.com/register/422400863</a></p>
<p>After registering you will receive a confirmation email containing information about joining the Webinar.</p>
<p>System Requirements</p>
<p>PC-based attendees<br />
Required: Windows® 7, Vista, XP or 2003 Server</p>
<p>Mac®-based attendees<br />
Required: Mac OS® X 10.6 or newer</p>
<p>Mobile attendees<br />
Required: iPhone®, iPad®, Android™ phone or Android tablet</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/04/10/so-you-wanna-be-a-pentester-free-webinar-to-show-you-how/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Python For IT Security Workshops Online Training Package</title>
		<link>http://strategicsec.com/2013/04/09/python-for-it-security-workshops-online-training-package/</link>
		<comments>http://strategicsec.com/2013/04/09/python-for-it-security-workshops-online-training-package/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 01:35:39 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[log parsing]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[port scanning]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[scapy]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[web application]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55389</guid>
		<description><![CDATA[You can take your choice of the 2 workshops: Python For Security Professionals (Online) – Level 1  for $100 Or Python For Security Tool Development (Online) – Level 2 for    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/04/09/python-for-it-security-workshops-online-training-package/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>You can take your choice of the 2 workshops:</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Python For Security Professionals (Online) – Level 1  for $100</a></p>
<p>Or</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Python For Security Tool Development (Online) – Level 2 for $100</a></p>
<p>Or</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number= PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number=PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Both workshops for $150</a></p>
<p>&nbsp;</p>
<p><strong>Short Descriptions:</strong></p>
<p>&nbsp;</p>
<p><strong>Python For Security Professionals (Online) – Level 1</strong></p>
<p>This is a beginner’s functional programming course focused on programming concepts that can be used to accomplish common security tasks such as log parsing, password cracking, port scanning, vulnerability testing, web application security testing, malware analysis, and exploit development. There won’t be a bunch of math, no CD collection databases, and no useless programming mumbo jumbo.</p>
<p>Each Week the students will learn a few basic programming concepts, and then use some sample code (skeleton scripts) to perform security tasks. The students will keep the skeleton scripts so that when they get back to work they’ll have something that they can use a crib sheet to  build scripts that can do other security tasks.</p>
<p>This class will run for the entire month of May on Mon/Wed from 7pm – 9pm EST.</p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8http://" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','']);">Click Here To Signup</a></p>
<p>&nbsp;</p>
<p><strong>Python For Security Tool Development (Online) – Level 2</strong></p>
<p>This class takes what you learned in Python For Security Professionals to the next level. It’s designed for people that want to modify existing security tools, and/or create their own. We will focus exclusively solving problems IT Security Professionals often face. We’ll analyze several popular security tools, and modify them to work in situations they weren’t designed for.</p>
<p>Finally you’ll be required to develop a sophisticated analysis tool, and a sophisticated attack tool as part of the class. You’ll get to choose what the primary functions of your tools are, and you’ll be encouraged to release your tool as an open source project or modify your tool so that it becomes an integral component a class project that will be released as an open source project on github.</p>
<p>This class will run for the entire month of June on Mon/Wed from 7pm – 9pm EST.</p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click Here To Signup</a></p>
<p>&nbsp;</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number= PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number=PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Want to take both for $150 – Click Here</a></p>
<p>&nbsp;</p>
<p><strong>Course Syllabus:</strong></p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Python For Security Professionals (Online) – Level 1</a></p>
<p>This class will run for the entire month of May on Mon/Wed from 7pm – 9pm EST.</p>
<p>This class is for security professionals that have <span style="color: #ff0000;">VERY LITTLE PROGRAMMING EXPERIENCE</span>.</p>
<p>Week 1:     Programming Concepts, Parsing Files, Logs, and PCAPs</p>
<ul>
<li>    Python Basics</li>
<li>    Text File Parsing</li>
<li>    Log Parsing</li>
<li>    PCAP Parsing</li>
</ul>
<p>Week 2:    Password Cracking, Netcat, Port-Scanning, and simple fuzzing</p>
<ul>
<li>    Password Cracking</li>
<li>    Netcat-like Functionality</li>
<li>    Port-Scanning</li>
<li>    Fuzzing</li>
</ul>
<p>&nbsp;</p>
<p>Week 3:    Web Application Vulnerability Testing</p>
<ul>
<li>    Vulnerable Service Identification</li>
<li>    SQL Injection</li>
<li>    XSS</li>
<li>    RFI/LFI</li>
</ul>
<p>Week 4:    Writing Your Own Security Tools</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20May%202013&amp;item_number=PFSP-MAY-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click Here To Signup</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Python For Security Tool Development (Online) – Level 2</a></p>
<p>The depth of the material will be heavily dependent upon the skill-level of the attendees. I’ll do my best to make sure that I help everyone and sufficiently challenge each student based on their ability/knowledge.</p>
<p>The primary goal of this class will be for the students to really get in there and work on something really useful for the IT Security community.</p>
<p>&nbsp;</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Tool%20Development%20June%202013&amp;item_number=PFSTD-JUN-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click Here To Signup</a></p>
<p>&nbsp;</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name= Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number= PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals%20and%20Python%20For%20Security%20Tool%20Development%20May%20and%20June%202013&amp;item_number=PFSP-MAY-PFSTD-JUN-2013&amp;amount=150%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Want to take both for $150 – Click Here</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/04/09/python-for-it-security-workshops-online-training-package/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking in Paradise 2013 Giveaway</title>
		<link>http://strategicsec.com/2013/03/26/hacking-in-paradise-2013-giveaway/</link>
		<comments>http://strategicsec.com/2013/03/26/hacking-in-paradise-2013-giveaway/#comments</comments>
		<pubDate>Tue, 26 Mar 2013 04:00:41 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Hacking In Paradise]]></category>
		<category><![CDATA[metasploit]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55380</guid>
		<description><![CDATA[Strategic Security is giving away four free seats (1 seat per month from April &#8211; July) to Hacking In Paradise &#8211; The Bahamas 2013. This is a full package deal    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/03/26/hacking-in-paradise-2013-giveaway/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Strategic Security is giving away four free seats (1 seat per month from April &#8211; July) to Hacking In Paradise &#8211; The Bahamas 2013. This is a full package deal offer &#8211; so you&#8217;ll get airfare, lodging, and the training if you win.</p>
<p>To enter and be considered for one of the seats you&#8217;ll have to perform several activities.<br />
You can do as many activities as you want everyday – good luck.</p>
<p>After you complete your tasks, send an email to joe(at)strategicsec(dot)com with<br />
publicly viewable links to the completed activities.</p>
<p>Here are the entry activities:</p>
<p>- Tweet about this giveaway (3 points)<br />
- Follow @j0emccray on twitter (1 point)<br />
- Follow @strategicsec on twitter (1 point)<br />
- Friend j0emccray on facebook [facebook.com/j0emccray] (1 point)<br />
- Add gplus.to/j0emccray to one of your circles on Google+ (1 point)<br />
- Like this page on facebook (1 point)<br />
- +1 Hacking in Paradise page on Google+ (1 point)<br />
- Blog about this class (3 points)<br />
- Google+ post about this class (3 points)<br />
- Follow @ITSecPros on twitter (5 points)<br />
- +1 IT Security Professionals page on Google+ (1 point)</p>
<p>&nbsp;<br />
<a class="rafl" id="rc-2b3ea71" href="http://www.rafflecopter.com/rafl/display/2b3ea71/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.rafflecopter.com/rafl/display/2b3ea71/']);" rel="nofollow">Hacking In Paradise Giveaway</a><br />
<script type="text/javascript" src="//d12vno17mo87cx.cloudfront.net/embed/rafl/cptr.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/03/26/hacking-in-paradise-2013-giveaway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Site: IT Security Professionals</title>
		<link>http://strategicsec.com/2013/03/16/new-site-it-security-professionals/</link>
		<comments>http://strategicsec.com/2013/03/16/new-site-it-security-professionals/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 04:01:56 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55366</guid>
		<description><![CDATA[For the past few months the rookies and I have been working on the new website IT Security Professionals. &#160; What’s this place all about? Simple – it’s a social    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/03/16/new-site-it-security-professionals/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>For the past few months the rookies and I have been working on the new website <a href="http://it-security-professionals.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://it-security-professionals.com/']);">IT Security Professionals</a>.</p>
<p>&nbsp;</p>
<p><b>What’s this place all about?</b></p>
<p>Simple – it’s a social networking and resource website for IT Security Professionals. Think – LinkedIn, Facebook, Monster.com, and Wikipedia all wrapped up in one website just for IT Security People.</p>
<p>&nbsp;</p>
<p><b>What separates this website from anywhere else on the web?</b></p>
<p>The key differentiators for this website are:</p>
<ol>
<li>Spam-Free</li>
<li>Vendor-Free</li>
<li>Content and Discussion driven</li>
</ol>
<p>&nbsp;</p>
<p>There were several goals that this site needed to accomplish, and I&#8217;m really hoping that we are moving in the right direction so we can achieve them. Here is the rundown:</p>
<p>R00kie group goals:</p>
<ul>
<li>Provide us with a project management solution so we could task r00kies with projects and track the status of those projects.</li>
</ul>
<ul>
<li>Provide us with the ability for r00kies to collaborate on documents</li>
<li>Provide us with a mechanism to allow r00kies to show what their contributions to the r00kie program have been</li>
</ul>
<p>&nbsp;</p>
<p>IT Security Community Goals</p>
<ul>
<li>Provide us with a mechanism to give back to the IT Security Community</li>
<li>Provide the IT Security Community with a vehicle to learn and keep up with the industry</li>
</ul>
<p>&nbsp;</p>
<p><strong>Check out the site, and let us know what you think</strong></p>
<p>I really hope that you check out the <a href="http://it-security-professionals.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://it-security-professionals.com/']);">website</a> and let us know what you think. I know it will take some time, but I really think that we&#8217;re going to provide something of value to the community with this project.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><a href="http://it-security-professionals.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://it-security-professionals.com/']);">http://it-security-professionals.com/</a></p>
<p>&nbsp;</p>
<p>Joe</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/03/16/new-site-it-security-professionals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web App Pentester Night School (Tues/Thurs) April 2013</title>
		<link>http://strategicsec.com/2013/03/15/web-app-pentester-night-school-tuesthurs-april-2013/</link>
		<comments>http://strategicsec.com/2013/03/15/web-app-pentester-night-school-tuesthurs-april-2013/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 03:20:23 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[WAF Bypass]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55361</guid>
		<description><![CDATA[Hands-on Web Application Security So what exactly do I mean by “Hands-on” – this video is a good example of the kinds of things you’ll be learning. &#160; Course Outline    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/03/15/web-app-pentester-night-school-tuesthurs-april-2013/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><strong>Hands-on Web Application Security</strong></p>
<p>So what exactly do I mean by “Hands-on” – <a href="https://www.youtube.com/watch?v=qBVThFwdYTc" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.youtube.com/watch?v=qBVThFwdYTc']);">this video is a good example of the kinds of things you’ll be learning.</a></p>
<p>&nbsp;</p>
<p><strong>Course Outline</strong></p>
<p>Week 1: Simple ASP/ MSSQL Web App (2 and 4 April)</p>
<p>Week 2: PHP/MySQL Web App (9 and 11 April)</p>
<p>Week 3: JSP/Oracle Web App (16 and 18 April)</p>
<p>Week 4: Tricky Stuff (23 and 25 April)</p>
<p>&nbsp;</p>
<p><strong>Specifics I’ll Be Covering</strong></p>
<ul>
<li>         SQL Injection</li>
<li>         Cross-Site Scripting</li>
<li>         Web Shells</li>
<li>         Filter Evasion</li>
<li>         SQL Injection to a command-shell</li>
<li>         XSS to a command-shell</li>
<li>         WAF Bypass</li>
</ul>
<p><strong> </strong></p>
<p><strong>Class Schedule</strong></p>
<p>Tuesday and Thursday evenings from 7pm EST to 9:00pm EST via webinar.</p>
<p>&nbsp;</p>
<p><strong>Network Access</strong></p>
<p>Students will have 24/7 network access from 1 March 2013 to 31 March 2013.</p>
<p>&nbsp;</p>
<p><strong>Class Cost</strong></p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20April%202013&amp;item_number=WAPNS-APR-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School%20April%202013&amp;item_number=WAPNS-APR-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">This class has a cost $100 USD. Click HERE to signup.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/03/15/web-app-pentester-night-school-tuesthurs-april-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Dev On The Weekends &#8211; April 2013</title>
		<link>http://strategicsec.com/2013/03/15/exploit-dev-on-the-weekends-april-2013/</link>
		<comments>http://strategicsec.com/2013/03/15/exploit-dev-on-the-weekends-april-2013/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 03:14:33 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[Heap Spray]]></category>
		<category><![CDATA[ROP Exploits]]></category>
		<category><![CDATA[SEH Overwrites]]></category>
		<category><![CDATA[Stack Overflows]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55358</guid>
		<description><![CDATA[This workshop is for newbies to the world of exploit development. It takes participants from “n00b” to “31337″ – ok just kidding not quite “31337”, but it will help you    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/03/15/exploit-dev-on-the-weekends-april-2013/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>This workshop is for newbies to the world of exploit development. It takes participants from “n00b” to “31337″ – ok just kidding not quite “31337”, but it will help you get comfortable with the subject because you are given the time to actually absorb the material.</p>
<p>Each Saturday in the month of April (6<sup>th</sup>, 13<sup>th</sup>, 20<sup>th</sup>and 27<sup>th</sup>) from noon to 4pm EST Joe McCray will host a webinar.</p>
<p>Here are some of the topics to look forward to:</p>
<p>Course Outline:</p>
<ul>
<li>April 6<sup>th</sup>– Stack Overflows</li>
<li>April 13<sup>th</sup> – Abusing Structured Exception Handlers on Windows</li>
<li>April 20<sup>th</sup> – Heap Spray</li>
<li>April 27<sup>th</sup> – ROP Exploits</li>
</ul>
<p>Each week Joe will host the 4 hour webinar where he will walk through the previous week’s homework exercises, cover the material for the current week, take questions from the students, and provide homework for the upcoming week. The homework that is handed out each week is designed so students can work on and reinforce each week’s lesson.</p>
<p><a title="Workshop Cost is $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Workshop&amp;item_number=EDWS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Workshop&amp;item_number=EDWS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);" target="_blank">The cost for this workshop is $100USD – click HERE to register.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/03/15/exploit-dev-on-the-weekends-april-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentester Night School (Mon/Wed) April 2013</title>
		<link>http://strategicsec.com/2013/03/15/pentester-night-school-monwed-april-2013/</link>
		<comments>http://strategicsec.com/2013/03/15/pentester-night-school-monwed-april-2013/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 03:05:40 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55356</guid>
		<description><![CDATA[The primary focus of the class is ‘goal oriented pentesting’, or emulating Advanced Persistent Threat so there will be a lot of focus on Bypassing Anti-Virus, and POST EXPLOITATION (with    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/03/15/pentester-night-school-monwed-april-2013/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The primary focus of the class is ‘goal oriented pentesting’, or emulating Advanced Persistent Threat so there will be a lot of focus on Bypassing Anti-Virus, and POST EXPLOITATION (with and without Metasploit).</p>
<p>The network environment is going to be highly fluid, really volatile. Each day the network topology will be changing slightly.</p>
<p>&nbsp;</p>
<p><strong>Class Outline</strong></p>
<p>Week 1:  Scanning &amp; Exploitation                                                   (1-7 April)</p>
<ul>
<li>Dealing with Load Balancers, IPS, and WAF</li>
<li>Web Attacks</li>
<li>Client-Side Exploitation</li>
</ul>
<p>Week 2:  BypassingAV                                                                   (8-14 April)</p>
<ul>
<li>File Splitting</li>
<li>Packing</li>
<li>Encoding</li>
<li>Shellcode Injection</li>
</ul>
<p>Week 3: Post Exploitation                                                            (15-21 April)</p>
<ul>
<li>Getting Files On/Off System</li>
<li>Download and Execute</li>
<li>Creating Listeners/Backdoor Services</li>
<li>Different Kinds of Reverse Shells</li>
<li>Automating Tasks</li>
<li>Privilege Escalation</li>
<li>Lateral Movement</li>
<li>Pass The Hash</li>
<li>Host Enumeration</li>
<li>Host Data Mining</li>
<li>Active Directory Enumeration</li>
</ul>
<p>Week 4: Your Pentest                                                                    (22-31 April)</p>
<p>&nbsp;</p>
<p><strong>Class Schedule</strong></p>
<p>Monday and Wednesday evenings from 7pm EST to 9:00pm EST via webinar.</p>
<p>&nbsp;</p>
<p><strong>Network Access</strong></p>
<p>Students will have 24/7 network access from 1 April 2013 to 31 April 2013.</p>
<p>&nbsp;</p>
<p><strong>Class Cost</strong></p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20April%202013&amp;item_number=PNS-APR-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School%20April%202013&amp;item_number=PNS-APR-2013&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">This class has a cost $100 USD. Click HERE to signup.</a></p>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/03/15/pentester-night-school-monwed-april-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Bookings</title>
		<link>http://strategicsec.com/events/my-bookings/</link>
		<comments>http://strategicsec.com/events/my-bookings/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 17:07:01 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/events/my-bookings/</guid>
		<description><![CDATA[CONTENTS]]></description>
				<content:encoded><![CDATA[<p>CONTENTS</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/events/my-bookings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Categories</title>
		<link>http://strategicsec.com/events/categories/</link>
		<comments>http://strategicsec.com/events/categories/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 17:07:00 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/events/categories/</guid>
		<description><![CDATA[CONTENTS]]></description>
				<content:encoded><![CDATA[<p>CONTENTS</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/events/categories/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Locations</title>
		<link>http://strategicsec.com/events/locations/</link>
		<comments>http://strategicsec.com/events/locations/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 17:06:59 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/events/locations/</guid>
		<description><![CDATA[CONTENTS]]></description>
				<content:encoded><![CDATA[<p>CONTENTS</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/events/locations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Events</title>
		<link>http://strategicsec.com/events/</link>
		<comments>http://strategicsec.com/events/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 17:06:57 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/events/</guid>
		<description><![CDATA[CONTENTS]]></description>
				<content:encoded><![CDATA[<p>CONTENTS</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/events/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Order Received</title>
		<link>http://strategicsec.com/checkout/order-received/</link>
		<comments>http://strategicsec.com/checkout/order-received/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:56 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/checkout/order-received/</guid>
		<description><![CDATA[[woocommerce_thankyou]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_thankyou]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/checkout/order-received/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Checkout &#8594; Pay</title>
		<link>http://strategicsec.com/checkout/pay/</link>
		<comments>http://strategicsec.com/checkout/pay/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:55 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/checkout/pay/</guid>
		<description><![CDATA[[woocommerce_pay]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_pay]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/checkout/pay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Change Password</title>
		<link>http://strategicsec.com/my-account/change-password/</link>
		<comments>http://strategicsec.com/my-account/change-password/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:54 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/my-account/change-password/</guid>
		<description><![CDATA[[woocommerce_change_password]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_change_password]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/my-account/change-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>View Order</title>
		<link>http://strategicsec.com/my-account/view-order/</link>
		<comments>http://strategicsec.com/my-account/view-order/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:53 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/my-account/view-order/</guid>
		<description><![CDATA[[woocommerce_view_order]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_view_order]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/my-account/view-order/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Edit My Address</title>
		<link>http://strategicsec.com/my-account/edit-address/</link>
		<comments>http://strategicsec.com/my-account/edit-address/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:52 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/my-account/edit-address/</guid>
		<description><![CDATA[[woocommerce_edit_address]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_edit_address]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/my-account/edit-address/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Account</title>
		<link>http://strategicsec.com/my-account/</link>
		<comments>http://strategicsec.com/my-account/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:50 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/my-account/</guid>
		<description><![CDATA[[woocommerce_my_account]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_my_account]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/my-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Checkout</title>
		<link>http://strategicsec.com/checkout/</link>
		<comments>http://strategicsec.com/checkout/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:49 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/checkout/</guid>
		<description><![CDATA[[woocommerce_checkout]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_checkout]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/checkout/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Track your order</title>
		<link>http://strategicsec.com/order-tracking/</link>
		<comments>http://strategicsec.com/order-tracking/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:49 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/order-tracking/</guid>
		<description><![CDATA[[woocommerce_order_tracking]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_order_tracking]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/order-tracking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cart</title>
		<link>http://strategicsec.com/cart/</link>
		<comments>http://strategicsec.com/cart/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:48 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/cart/</guid>
		<description><![CDATA[[woocommerce_cart]]]></description>
				<content:encoded><![CDATA[<p>[woocommerce_cart]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/cart/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shop</title>
		<link>http://strategicsec.com/shop/</link>
		<comments>http://strategicsec.com/shop/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 11:07:46 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/shop/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/shop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calendar</title>
		<link>http://strategicsec.com/calendar/</link>
		<comments>http://strategicsec.com/calendar/#comments</comments>
		<pubDate>Wed, 20 Feb 2013 05:19:04 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/calendar/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/calendar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentesting Without Metasploit</title>
		<link>http://strategicsec.com/2013/02/18/pentesting-without-metasploit/</link>
		<comments>http://strategicsec.com/2013/02/18/pentesting-without-metasploit/#comments</comments>
		<pubDate>Mon, 18 Feb 2013 08:15:15 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55307</guid>
		<description><![CDATA[Pentesting WITHOUT Metasploit I really think you are going to like this one! I really think this is the kind of class that pentesters, and security professionals are REALLY going    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/02/18/pentesting-without-metasploit/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><strong>Pentesting WITHOUT Metasploit</strong></p>
<p>I really think you are going to like this one!</p>
<p>I really think this is the kind of class that pentesters, and security professionals are REALLY going to enjoy.</p>
<p>There are a lot of situations that can arise on a pentest where Metasploit just won&#8217;t work and you&#8217;ll have to perform the task by hand &#8211; this is often the case in high security environments because many of the defensive tools look specifically for Metasploit. <strong>-</strong></p>
<p>&nbsp;</p>
<p><strong>- Hands-on -</strong></p>
<p>So what exactly do I mean by “Hands-on” – this video is a good example of the kinds of things you’ll be learning.</p>
<p>&nbsp;</p>
<p><a href="https://www.youtube.com/watch?v=wZ-b8qe7M8I" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.youtube.com/watch?v=wZ-b8qe7M8I']);">https://www.youtube.com/watch?v=wZ-b8qe7M8I</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Course Outline</strong></p>
<p>&nbsp;</p>
<ul>
<li>Week 1: Scanning (5 and 7 March)</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Week 2: Exploitation (12 and 14 March)</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Week 3: Post-Exploitation (19 and 21 March)</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Week 4: Tricky Stuff (26 and 28 March)</li>
</ul>
<p>&nbsp;</p>
<p><strong>Specifics I’ll Be Covering</strong></p>
<ul>
<li><strong>         </strong>Scripting
<ul>
<li>   Bash</li>
<li>   Batch</li>
<li>   VBScript</li>
<li>   Powershell</li>
<li>   Python</li>
</ul>
</li>
<li>         Using public exploit code
<ul>
<li>   Compiling Code on Windows and *nix</li>
<li>   Fixing broken exploit code</li>
<li>   Changing shellcode in exploits</li>
</ul>
</li>
<li>         Bypassing Anti-Virus</li>
<li>         Post-Exploitation</li>
</ul>
<p><strong> </strong></p>
<p><strong>Class Schedule</strong></p>
<p>Tuesday and Thursday evenings from 7pm EST to 9:00pm EST via webinar.</p>
<p>&nbsp;</p>
<p><strong>Network Access</strong></p>
<p>Students will have 24/7 network access from 1 March 2013 to 31 March 2013.</p>
<p><strong>Class Cost</strong></p>
<p><a title="Click Here To Signup For $200USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesting%20Without%20Metasploit&amp;item_number=PWOM&amp;amount=200%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesting%20Without%20Metasploit&amp;item_number=PWOM&amp;amount=200%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">This class has a cost $200 USD. Click HERE to signup.</a></p>
<p><a title="Click Here To Signup For $200USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesting%20Without%20Metasploit&amp;item_number=PWOM&amp;amount=200%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentesting%20Without%20Metasploit&amp;item_number=PWOM&amp;amount=200%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img class="alignnone size-full wp-image-55347" alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a><br />
Joe</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/02/18/pentesting-without-metasploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web App Pententester Night School</title>
		<link>http://strategicsec.com/2013/02/17/web-app-pententester-night-school/</link>
		<comments>http://strategicsec.com/2013/02/17/web-app-pententester-night-school/#comments</comments>
		<pubDate>Sun, 17 Feb 2013 22:38:59 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55303</guid>
		<description><![CDATA[New Web App Workshop and Other Things Alright, it’s been a whirlwind week teaching a classroom-based class in Maryland, 2 online classes, and of course the other recent drama. I’m    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/02/17/web-app-pententester-night-school/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><strong>New Web App Workshop and Other Things</strong></p>
<p>Alright, it’s been a whirlwind week teaching a classroom-based class in Maryland, 2 online classes, and of course the other recent drama. I’m working on a few new things right now that I think you might be interested in.</p>
<p>&nbsp;</p>
<p><strong>Hands-on Web Application Security</strong></p>
<p>So what exactly do I mean by “Hands-on” – <a href="https://www.youtube.com/watch?v=qBVThFwdYTc" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.youtube.com/watch?v=qBVThFwdYTc']);">this video is a good example of the kinds of things you’ll be learning.</a></p>
<p>&nbsp;</p>
<p><strong>Course Outline</strong></p>
<p>Week 1: Simple ASP/ MSSQL Web App (4 and 6 March)</p>
<p>Week 2: PHP/MySQL Web App (11 and 13 March)</p>
<p>Week 3: JSP/Oracle Web App (18 and 20 March)</p>
<p>Week 4: Tricky Stuff (25 and 27 March)</p>
<p>&nbsp;</p>
<p><strong>Specifics I’ll Be Covering</strong></p>
<ul>
<li>         SQL Injection</li>
<li>         Cross-Site Scripting</li>
<li>         Web Shells</li>
<li>         Filter Evasion</li>
<li>         SQL Injection to a command-shell</li>
<li>         XSS to a command-shell</li>
<li>         WAF Bypass</li>
</ul>
<p><strong> </strong></p>
<p><strong>Class Schedule</strong></p>
<p>Monday and Wednesday evenings from 7pm EST to 9:00pm EST via webinar.</p>
<p>&nbsp;</p>
<p><strong>Network Access</strong></p>
<p>Students will have 24/7 network access from 1 March 2013 to 31 March 2013.</p>
<p>&nbsp;</p>
<p><strong>Class Cost</strong></p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School&amp;item_number=WAPNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School&amp;item_number=WAPNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">This class has a cost $100 USD. Click HERE to signup.</a></p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School&amp;item_number=WAPNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Web%20App%20Pentester%20Night%20School&amp;item_number=WAPNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><img class="alignnone size-full wp-image-55347" alt="paypal" src="http://strategicsec.com/wp-content/uploads/2013/02/paypal.gif" width="150" height="52" /></a></p>
<p>New Stuff…I’m working on another course so later today I’ll be releasing the info on that as well!</p>
<p>&nbsp;</p>
<p>Joe</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/02/17/web-app-pententester-night-school/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Final Statement On This Issue</title>
		<link>http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/</link>
		<comments>http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/#comments</comments>
		<pubDate>Tue, 12 Feb 2013 04:44:58 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55300</guid>
		<description><![CDATA[I didn’t want to do this, I tried not to let it get to this point, but I’m done – and as much as I care about keeping my personal    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I didn’t want to do this, I tried not to let it get to this point, but I’m done – and as much as I care about keeping my personal issues to myself this is the straw that broke the camel’s back for me.</p>
<p>I’m putting this dirty laundry out 1 time, and one time only. I absolutely will not speak on this subject ever again after this post. In my last blog post I responded to this Plagarism accusation from Saumil Shah. I emailed every single student in the class, made them aware of the situation – apologized, and offered refunds to anyone that felt slighted in any way. For the nearly 180 students that are taking courses with me this month I’ve given 12 refunds and I’ll happily give a refund to any other student that requests it.</p>
<p>After that I tried to go on about my business, but this is getting to the point of sheer stupidity.</p>
<p>Saumil, for 2 years even though very mention of your name made my skin crawl I still praised you publicly, recommended you publicly (YES, EVEN IN THE COURSEWARE YOU SAY I STOLE FROM YOU  – said that I learned this from you and I’d recommend that people take your classes).</p>
<p>Let’s get down to brass tacks here…</p>
<p>The truth is that Saumil and I have a financial dispute over a class that he taught with my company and a partner training company that I often work with nearly two years ago. The class wasn’t selling well so I lowered the price (literally cut the price in half) to get some sales. The company that hosted the training paid Saumil $9,000 when the class only grossed a little over 20K. Saumil wanted me to pay him 17,000. In total I paid him 15K when my cut was only 6K. So basically I lost 11K on the class and Saumil still wants the remaining 2K. And no there was no contract between us – it was a gentlemen’s agreement done without even a handshake.</p>
<p>When I was in the class I was so appreciative of him helping me learn the subject that I offered to rewrite my notes from his class, update the attack scripts and port them to python for him which was something he said he wanted to do in the future, and fully document lab manuals with step-by-step walkthroughs for each lab.  I told him that he could have ALL of this for free and I would be happy to do it as it would help me learn the material better. I honestly had planned to work on future classes with him where he would teach the exploit development and I would teach the network/web attacks. I was excited about the potential and he was too.</p>
<p>When it came time to settle up I paid him more money than I took in for the class (more than double what I took in &#8211; $6,000 was all I made and he wanted $17,000 – nearly triple what I made).  I was already in financial peril at the time because 3 customers had not paid for their penetration tests, and 1 customer had not paid me for a class so I was owed nearly $100,000 dollars. I was drowning financially so I paid him late, but even with paying him late I was still giving him money when I didn’t have it to give.</p>
<p>I got evicted from my home and even then I was still trying to pay Saumil for a class that I lost money on, a few months later I taught a class in Norway at HackCON  and had my point of contact for the event give Saumil all of the money from the event when I had no home to live in.</p>
<p>At this point I was in deep financial peril at the time and felt like Saumil was being an asshole to me. What kind of human I kept thinking to myself would be this way to me when I was homeless.</p>
<p>At this point I now fully hated his guts – nothing would satisfy me more than punching him in the mouth in front of god and country. I only had a few thousand dollars left to pay at this point, and the only reason that I was going to pay it was because I didn’t want him to go to security conferences and tell people in the IT Security community that I didn’t pay my bills. I figured it would destroy my ability to speak at conferences, run classes, and basically ruin me.</p>
<p>At that point Saumil’s business partner Hiren Shah began calling our mutual acquaintances, and my contractors asking each of that what my financial situation was. How much money I had made on recent penetration tests, courses, had they been paid from me recently, and more.</p>
<p>This put me through the roof!!!!!!!!!</p>
<p>Here I am taking money out my family’s mouth, still don’t have a place to live, and struggling to pay Saumil just so I can keep my private life out of the security industry and now here we go. Too late for that.</p>
<p>At this point I didn’t care anymore, I was so angry with him for being such a cowardly bitch that I couldn’t stand it. I swore that the next time I see him there was gonna be some furniture moving. Yes ChrisJohnRiley THIS IS THE NEW BLACK I was 2 seconds away from whooping  Saumil’s ass. I was ready to put my foot so far up his ass that his breath would smell like shoe polish!</p>
<p>I told him explicitly (yes that means I dropped a lot of F-Bombs) how I felt, and that I’m not paying him the remaining money because he and Hiren are both some bitches.  After that – all of these notes I rewrote, scripts I ported from perl to python, lab manuals that I wrote – for him as a gift to show my appreciation that he mentions in his blog post, and yes his precious virtual machines – I used them in classes, webinars, and workshops I taught. I did it to spite him. I was pissed at him – immature I realize – but at least it’s the truth. I might as well try to make my money back after all of this mess.</p>
<p>Saumil and anybody else for that matter – you can write whatever you want about me. You can put me on what ever page you want, talk about me on twitter, but at the end of the day Saumil can have a hot steamy cup of FUCK YOU! At this point I flat out don’t care how many people you tell, how many people talk about this on twitter. I hope that every single human being on this earth learns how much of a whining wimpy little bitch you are, and knows that I can’t stand you and I would rather eat hot shit before I’d even acknowledge that you are a fucking human being let alone speak to you.</p>
<p>No I’m not paying you, and I sincerely feel bad for every single incident of a people loosing respect for me with regard to this issue, I know that I will never do it again because there is no HUMAN being that would ever be the way that he was to me, but I refuse to continue to talk to people like you are a good person when I know you are not.</p>
<p>So Saumil, and Hiren – I just want you to know what I think of you personally, and professionally.</p>
<p>From the bottom of my heart…</p>
<p>FUCK YOU!</p>
<p>Joe</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Addressing An Issue</title>
		<link>http://strategicsec.com/2013/02/08/addressing-an-issue/</link>
		<comments>http://strategicsec.com/2013/02/08/addressing-an-issue/#comments</comments>
		<pubDate>Fri, 08 Feb 2013 22:25:41 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55296</guid>
		<description><![CDATA[Hello everyone, I want to address an issue. Saumil Shah, of Exploit Labs has made a post on his blog that I feel I need to address: http://blog.exploitlab.net/2013/02/defending-our-work.html &#160; Summary:    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/02/08/addressing-an-issue/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Hello everyone, I want to address an issue. Saumil Shah, of Exploit Labs has made a post on his blog that I feel I need to address:</p>
<p><a href="http://blog.exploitlab.net/2013/02/defending-our-work.html" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://blog.exploitlab.net/2013/02/defending-our-work.html']);">http://blog.exploitlab.net/2013/02/defending-our-work.html</a></p>
<p>&nbsp;</p>
<p><strong>Summary:</strong></p>
<p>I used the virtual machines from the class that I was in 2 years ago. I did it out of convenience. The virtual machines are built with software that is freely available on the Internet. There is no intellectual property of his that was stolen.</p>
<p>Saumil and I have had disagreements in the past and quite frankly the differences between us have still not been resolved. We are civil, but that is about the end of it. I emailed Saumil yesterday and let him know the following:</p>
<p>Even though we are not on good terms I apologize for using his virtual machines and will create new ones for my upcoming classes.</p>
<ol>
<li>Even though we have personal issues I recommended him in my webinars and in this very course as a good person to learn from.</li>
<li>The screenshot of debugger commands that he references in his blog post was never given out to students. And honestly – it’s just commands not intellectual property. It’s the same as handing out a GDB cheatsheet for reference.</li>
</ol>
<p><strong>To both Saumil and the entire IT Security community</strong></p>
<p>I apologize for misrepresenting the courseware. I looked at it as all of the software on the virtual machines that he gives away is freely available on the internet and it was helping me get the courseware done quickly by providing a working set of attack target virtual machines. It was never intended to be considered giving away his courseware. I will correct this immediately and I will have new virtual machines for my future classes.</p>
<p>&nbsp;</p>
<p>I sent a formal apology for Peter Van Eeckhoutte (<a href="https://twitter.com/corelanc0d3r" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://twitter.com/corelanc0d3r']);">https://twitter.com/corelanc0d3r</a>), someone I truly respect for his technical ability and his friendship because someone contacted asking if this blog post was  about him. I can assure you that Peter has the utmost of integrity, honor, and professionalism. He has absolutely nothing to do with all of this.</p>
<p>If any student of mine in this course or anything other course I’m currently teaching would like a refund – feel free to ask. My integrity is important to me, and any student or client of mine that feels that my integrity is not at the proper level I will gladly refund their money.</p>
<p>Joe</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/02/08/addressing-an-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentester Night School</title>
		<link>http://strategicsec.com/2013/01/14/pentester-night-school/</link>
		<comments>http://strategicsec.com/2013/01/14/pentester-night-school/#comments</comments>
		<pubDate>Mon, 14 Jan 2013 14:17:38 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55289</guid>
		<description><![CDATA[Ok, this time I’m doing a night class for a client, and this client has allowed me to make the class public. The primary focus of the class is ‘goal    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/01/14/pentester-night-school/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Ok, this time I’m doing a night class for a client, and this client has allowed me to make the class public. The primary focus of the class is ‘goal oriented pentesting’, or emulating Advanced Persistent Threat so there will be a lot of focus on Bypassing Anti-Virus, and POST EXPLOITATION (with and without Metasploit).</p>
<p>The network environment is going to be highly fluid, really volatile. Each day the network topology will be changing slightly.</p>
<p>&nbsp;</p>
<p><strong>Class Outline</strong></p>
<p>Week 1:  Scanning &amp; Exploitation                                                   (1-9 Feb)</p>
<ul>
<li>Dealing with Load Balancers, IPS, and WAF</li>
<li>Web Attacks</li>
<li>Client-Side Exploitation</li>
</ul>
<p>Week 2:  BypassingAV                                                                   (10-16 Feb)</p>
<ul>
<li>File Splitting</li>
<li>Packing</li>
<li>Encoding</li>
<li>Shellcode Injection</li>
</ul>
<p>Week 3: Post Exploitation                                                            (17-23 Feb)</p>
<ul>
<li>Getting Files On/Off System</li>
<li>Download and Execute</li>
<li>Creating Listeners/Backdoor Services</li>
<li>Different Kinds of Reverse Shells</li>
<li>Automating Tasks</li>
<li>Privilege Escalation</li>
<li>Lateral Movement</li>
<li>Pass The Hash</li>
<li>Host Enumeration</li>
<li>Host Data Mining</li>
<li>Active Directory Enumeration</li>
</ul>
<p>Week 4: Your Pentest                                                                    (24-28 Feb)</p>
<p>&nbsp;</p>
<p><strong>Class Schedule</strong></p>
<p>Monday and Wednesday evenings from 7pm EST to 9:30pm EST via webinar.</p>
<p>&nbsp;</p>
<p><strong>Network Access</strong></p>
<p>Students will have 24/7 network access from 1 Feb 2013 to 28 Feb 2013.</p>
<p>&nbsp;</p>
<p><strong>Class Cost</strong></p>
<p><a title="Click Here To Signup For $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School&amp;item_number=PNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%20Night%20School&amp;item_number=PNS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">This class has a cost $100 USD. Click HERE to signup.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/01/14/pentester-night-school/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Development Workshop</title>
		<link>http://strategicsec.com/2013/01/12/exploit-development-workshop/</link>
		<comments>http://strategicsec.com/2013/01/12/exploit-development-workshop/#comments</comments>
		<pubDate>Sat, 12 Jan 2013 09:25:35 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55284</guid>
		<description><![CDATA[This workshop is for newbies to the world of exploit development. It takes participants from &#8220;n00b&#8221; to &#8220;31337&#8243; &#8211; ok just kidding not quite “31337”, but it will help you    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2013/01/12/exploit-development-workshop/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>This workshop is for newbies to the world of exploit development. It takes participants from &#8220;n00b&#8221; to &#8220;31337&#8243; &#8211; ok just kidding not quite “31337”, but it will help you get comfortable with the subject because you are given the time to actually absorb the material.</p>
<p>Each Saturday in the month of February (2<sup>nd</sup>, 9<sup>th</sup>, 16<sup>th</sup>, and 23<sup>rd</sup>) from noon to 4pm EST Joe McCray will host a webinar.</p>
<p>Here are some of the topics to look forward to:</p>
<p>Course Outline:</p>
<ul>
<li>Feb 2<sup>nd</sup> &#8211; Stack Overflows (in both Linux and Windows)</li>
<li>Feb 9<sup>th</sup> &#8211; Abusing Structured Exception Handlers on Windows</li>
<li>Feb 16<sup>th</sup> – Heap Spray</li>
<li>Feb 23<sup>rd</sup> &#8211; ROP Exploits</li>
</ul>
<p>Each week Joe will host the 4 hour webinar where he will walk through the previous week’s homework exercises, cover the material for the current week, take questions from the students, and provide homework for the upcoming week. The homework that is handed out each week is designed so students can work on and reinforce each week’s lesson.</p>
<p><a title="Workshop Cost is $100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Workshop&amp;item_number=EDWS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Exploit%20Development%20Workshop&amp;item_number=EDWS&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);" target="_blank">The cost for this workshop is $100USD – click HERE to register.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2013/01/12/exploit-development-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your First CTF</title>
		<link>http://strategicsec.com/2012/10/04/your-first-ctf/</link>
		<comments>http://strategicsec.com/2012/10/04/your-first-ctf/#comments</comments>
		<pubDate>Thu, 04 Oct 2012 04:35:26 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[TrainingServices]]></category>
		<category><![CDATA[exploit development]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[reverse engineering]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55281</guid>
		<description><![CDATA[I&#8217;ve been getting a lot of people asking me about CTFs lately. I usually point people toward a few resources and tell them that CTFs are fun, but a lot    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2012/10/04/your-first-ctf/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ve been getting a lot of people asking me about CTFs lately. I usually point people toward a few resources and tell them that CTFs are fun, but a lot of work. I used to run <a href="http://web.archive.org/web/20030207053639/http:/www.rootwars.org/games/games.html" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','']);">RootWars.Org</a>, so I hosted a lot of hacking competitions back in the day. I was asked to host a CTF a few times and I kept going back and forth about it because they are just so much frigging work I would shy away from it.</p>
<p>The best thing about CTFs is also the worst thing about them &#8211; and that is that they can be all over the place. There are so many ways you can run one ranging from simple wargame servers, to network based exploitation games, to exploit development and reverse engineering challenges. After having several conversations about CTFs over the last month or so I found myself admitting over and over again that participating in CTFs was a HUGE factor in my skill development. It was how I learned Linux, it was how I learned packet analysis and intrusion detection &#8211; and to be honest &#8211; it was fun! I loved participating in CTFs, and I loved running them back then too because I learned so much. I can be honest and use the quote that rookie Frank Hackett says &#8220;The truth is&#8230;I just got a case of the lazies&#8217; so I was reluctant to do it.</p>
<p>I have a lot of newbies I work with now &#8211; I call them the <a href="http://security-rookies.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://security-rookies.com/']);">Security Rookies</a>. A lot of them are interested in being involved in a CTF.</p>
<p><strong><em>Sigh&#8230;Man what the hell&#8230;.who needs sleep? Let&#8217;z do da damn thang!</em></strong></p>
<p>I decided to setup a CTF for newbies &#8211; I&#8217;m calling it <strong>&#8216;Your First CTF&#8217;</strong>, it&#8217;s a CTF that starts with a month of training you up for the CTF and then finally participating in it. There will be tons of challenges ranging from simple Windows/Linux security tasks, to host-based exploitation (both with and without Metasploit), some malware analysis, some reverse engineering tasks, and some exploit development.</p>
<p>From October 22nd &#8211; November 11th I&#8217;ll provide you with access to the Strategic Sec lab network that will be full of challenges with explanations and step-by-step walkthroughs for each challenge. On the 22nd of October and each Saturday between October 22nd &#8211; November 11th I will release a video walk-through with me detailing how to solve each challenge and how it or something like it can be a &#8216;<strong><em>gotcha</em></strong>&#8216; in a CTF.</p>
<p>The actual CTF will be hosted from November 19th &#8211; 25th. It&#8217;ll be a team based CTF, and I&#8217;ll use the month that the training is being held to break people up into teams. We&#8217;ll allow participants to pick their own teams, and unpicked participants will be grouped into individual teams.</p>
<p>The cost of the event is $50 for the training, $50 to participate in the CTF, or $75 to do both.</p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Training&amp;item_number=CTFT&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Training&amp;item_number=CTFT&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">You can click here to purchase the $50 training for the CTF.</a></p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Participant%20Slot&amp;item_number=CTFPS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Participant%20Slot&amp;item_number=CTFPS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">You can click here to purchase your participant slot in the CTF for $50.</a></p>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Training%20and%20Participant%20Slot&amp;item_number=CTFTPS&amp;amount=75%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=CTF%20Training%20and%20Participant%20Slot&amp;item_number=CTFTPS&amp;amount=75%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">You  can click here to purchase the training and the CTF participant slot for $75.</a></p>
<p>Other relevant info:</p>
<ul>
<li>You should receive a confirmation of your purchase within 1 business day of purchase. Be sure to check your spam folder for this confirmation email. If you do not receive the email by the 2nd day please email me at joe&lt;at&gt;strategicsec.com with your Paypal confirmation number.</li>
</ul>
<ul>
<li>On the 22nd of October you will receive your network login information via email. Be sure to check your spam folder for this email as well, and if you don&#8217;t receive it please email me at joe&lt;at&gt;strategicsec.com with your Paypal confirmation number.</li>
</ul>
<ul>
<li>Each member of the winning team will be given a FREE Strategic Security class of their choice.</li>
</ul>
<ul>
<li>I&#8217;ll be providing more info to participants as they register&#8230;.right now &#8211; it&#8217;s time to get to work building the CTF network.</li>
</ul>
<p>&nbsp;</p>
<p>If you are interested in running your own CTF &#8211; these are some good documents that cover what CTFs are all about:</p>
<p><a href="https://www.calpolyswift.org/wp-content/uploads/2011/11/ctf_presen.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.calpolyswift.org/wp-content/uploads/2011/11/ctf_presen.pdf']);">https://www.calpolyswift.org/wp-content/uploads/2011/11/ctf_presen.pdf</a></p>
<p><a href="http://6dev.net/talk/pses-2012/pses_ctf_debriefings_en.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://6dev.net/talk/pses-2012/pses_ctf_debriefings_en.pdf']);" class="broken_link">http://6dev.net/talk/pses-2012/pses_ctf_debriefings_en.pdf</a></p>
<p><a href="http://cisr.nps.edu/events/downloads/WECS6/wecs6_ch04.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://cisr.nps.edu/events/downloads/WECS6/wecs6_ch04.pdf']);">http://cisr.nps.edu/events/downloads/WECS6/wecs6_ch04.pdf</a></p>
<p><a href="http://openctf.com/dox/oCTF6_whitepaper.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://openctf.com/dox/oCTF6_whitepaper.pdf']);" class="broken_link">http://openctf.com/dox/oCTF6_whitepaper.pdf</a></p>
<p>&nbsp;</p>
<p>This was the first CTF I ever participated in (this is a really good write-up):</p>
<p><a href="http://www.nxnw.org/~steve/papers/discex3_autonomix_defcon.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.nxnw.org/~steve/papers/discex3_autonomix_defcon.pdf']);">http://www.nxnw.org/~steve/papers/discex3_autonomix_defcon.pdf</a></p>
<p>&nbsp;</p>
<p>This is a really good write-up detailing how to run a CTF, network topology, vulnerable services/apps, and more importantly and setup a scoring system for it:</p>
<p><a href="http://theccgroup.org/carolinacon/ctf/presentation/HowTo0wnCaptureTheFlag.pdf" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://theccgroup.org/carolinacon/ctf/presentation/HowTo0wnCaptureTheFlag.pdf']);">http://theccgroup.org/carolinacon/ctf/presentation/HowTo0wnCaptureTheFlag.pdf</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2012/10/04/your-first-ctf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Development For Mere Mortals</title>
		<link>http://strategicsec.com/2012/08/16/exploit-development-for-mere-mortals/</link>
		<comments>http://strategicsec.com/2012/08/16/exploit-development-for-mere-mortals/#comments</comments>
		<pubDate>Thu, 16 Aug 2012 04:38:36 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Exploit Structured Exception Handlers]]></category>
		<category><![CDATA[Exploiting Stack Overflows]]></category>
		<category><![CDATA[Heap Sprays]]></category>
		<category><![CDATA[ROP Exploits]]></category>
		<category><![CDATA[Stack Pivots]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55277</guid>
		<description><![CDATA[I&#8217;m going to be hosting a FREE online workshop on exploit development called &#8220;Exploit Development For Mere Mortals&#8221; on September 13th, 2012 from 1-3pm EST.  The workshop is designed for    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2012/08/16/exploit-development-for-mere-mortals/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m going to be hosting a<strong> FREE</strong> online workshop on exploit development called &#8220;<em><a href="https://www3.gotomeeting.com/register/576658462" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www3.gotomeeting.com/register/576658462']);">Exploit Development For Mere Mortals&#8221; on September 13th, 2012 from 1-3pm EST</a></em>.  The workshop is designed for people that have an interest in exploit development and need to be pointed in the right direction to get started. No this is not some exploit development ninja workshop &#8211; you won&#8217;t be selling 0-days after attending.</p>
<p>However, you will learn everything you need to get up and running. I&#8217;ll be answering a lot of common beginner questions and showing how basic exploitation works.</p>
<p><strong>Common Questions I&#8217;ll be addressing:</strong></p>
<ul>
<li>What programming languages you need to know?</li>
<li>What are the best ways to learn these languages?</li>
<li>What tools do you need?</li>
<li>Which tools should you start with first?</li>
<li>What references you use to get started and more importantly what to avoid?</li>
</ul>
<p><strong> </strong></p>
<p><strong>Exploit Techniques I&#8217;ll be covering:</strong></p>
<ul>
<li>Exploiting Stack Overflows</li>
<li>Exploiting Structured Exception Handlers</li>
<li>Heap Sprays</li>
<li>ROP Exploits and Stack Pivots</li>
</ul>
<p><strong>Space is limited.</strong><br />
Reserve your Webinar seat now at:<br />
<a href="https://www3.gotomeeting.com/register/576658462" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www3.gotomeeting.com/register/576658462']);">https://www3.gotomeeting.com/register/576658462</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2012/08/16/exploit-development-for-mere-mortals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Analysis Workshop</title>
		<link>http://strategicsec.com/2012/08/09/malware-analysis-workshop/</link>
		<comments>http://strategicsec.com/2012/08/09/malware-analysis-workshop/#comments</comments>
		<pubDate>Thu, 09 Aug 2012 14:42:49 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Online]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analyzing malicious PDFs]]></category>
		<category><![CDATA[Analyzing network traffic pcaps]]></category>
		<category><![CDATA[Dealing with javascript obfuscation]]></category>
		<category><![CDATA[Dealing with packers]]></category>
		<category><![CDATA[Memory analysis]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55272</guid>
		<description><![CDATA[I&#8217;m doing a Malware Analysis workshop on Aug 25th from noon to 4pm EST for a customer and the customer has given me permission to make the workshop public. &#160;    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2012/08/09/malware-analysis-workshop/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m doing a Malware Analysis workshop on Aug 25th from noon to 4pm EST for a customer and the customer has given me permission to make the workshop public.</p>
<p>&nbsp;</p>
<p>I&#8217;ll be covering:</p>
<ul>
<li>Analyzing network traffic pcaps</li>
<li>Memory analysis</li>
<li>Analyzing malicious PDFs</li>
<li>Dealing with packers</li>
<li>Dealing with javascript obfuscation</li>
</ul>
<p>Like the every workshop I do this one is also designed to be a lab style of class.</p>
<p>Students will be given a VMware image with the malware all of the analysis tools preloaded to download and use for the workshop.</p>
<p>Along with the VMware image students will be given a lab manual that walks them through the various analysis steps.</p>
<p>The workshop will be LIVE via GotoWebinar again, and I will be walking the students through the various labs, and answering student questions.</p>
<p>Basic Info:</p>
<ul>
<li>The workshop will be held on Saturday the 25th of August, 2012 from 12 noon EST to 4 pm EST at a cost of <a title="Malware Analysis Workshop $50USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Workshop&amp;item_number=MAWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Workshop&amp;item_number=MAWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$50 USD</a></li>
<li>The VM and lab manual will be made available for download on the 20th of August at noon EST</li>
<li>The VM will also contain several samples of live malware so students can practice on other malware samples.</li>
<li>You should receive a confirmation email within 4 hours of registering for the workshop (be sure to check your spam folder)</li>
<li>Workshop attendees will get a 10% discount on the <a title="Advanced Malware Analysis" href="http://www.trainace.com/courses/advancedmalwareanalysis/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.trainace.com/courses/advancedmalwareanalysis/']);">Advanced Malware Analysis course</a> taught by Joe McCray</li>
</ul>
<p>Click <a title="Click Here To Register For This Workshop" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Workshop&amp;item_number=MAWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Malware%20Analysis%20Workshop&amp;item_number=MAWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><span style="color: #ff0000;"><strong>HERE</strong></span></a> to register for this workshop.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2012/08/09/malware-analysis-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategic Security Advanced Pentesting Lab Network</title>
		<link>http://strategicsec.com/strategic-security-advanced-pentesting-lab-network/</link>
		<comments>http://strategicsec.com/strategic-security-advanced-pentesting-lab-network/#comments</comments>
		<pubDate>Fri, 03 Aug 2012 02:16:13 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55264</guid>
		<description><![CDATA[The goal of the Strategic Security Advanced Pentesting Lab Network is to provide penetration testers with access to a lab network that is comprised of modern OSs and new security    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-advanced-pentesting-lab-network/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The goal of the Strategic Security Advanced Pentesting Lab Network is to provide penetration testers with access to a lab network that is comprised of modern OSs and new security products.</p>
<p>&nbsp;</p>
<p><strong>The Network</strong></p>
<p>The entire network is comprised of all 64-Bit Windows and Linux hosts.</p>
<ul>
<li>Hardened Hosts joined to a hardened domain
<ul>
<li>64-Bit Windows 7 hosts joined to a Server 2008 R2 Active Directory Domain with all security GPOs applied</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Hardened Servers
<ul>
<li>64-Bit Linux hosts running mod_security, suPHP, suhosin, greensql, and several other security mechanisms</li>
<li>64-Bit Server 2008 R2 running AppLocker, BitLocker, Auditing Services, IPSec, WAFs</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Other Types of Servers
<ul>
<li>HPC Server 2008</li>
<li>TMG</li>
<li>NPS/NAP</li>
<li>RODC</li>
<li>IAS</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Security Products
<ul>
<li>HIPS</li>
<li>AV</li>
<li>Snort</li>
<li>AlienVault</li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<p><strong>The Rules</strong></p>
<ul>
<li>Users will have administrative access to the workstations (but not the servers).</li>
<li>Admin access to the servers must be requested via email</li>
<li>User contributed binaries and tools can not be submitted to VirusTotal or similar sites without permission from the creator</li>
<li>Security mechanism bypass techniques can not be submitted vendors, or written about with out permission from the creator</li>
<li>Lab users can request that VMs with certain security mechanisms be added to the network. Strategic Security lab techs will make a best effort to fulfill these types of requests.</li>
<li>The group&#8217;s centralized meeting and discussion place is a LinkedIn group called &#8220;Advanced Penetration Testers: Pentesting High Security Environments&#8221; &#8211; http://www.linkedin.com/groups?gid=3270572&amp;trk=hb_side_g</li>
<li>Submitted VMs must be in VMWare ESX format with updated VMWare tools installed. Dropbox is the preferred VM transfer mechanism</li>
<li>Articles must be emailed to joe@strategicsec.com before the 1st of each month</li>
</ul>
<p>&nbsp;</p>
<p><strong>The Vetting</strong></p>
<ul>
<li>Initial vetting will be done by Joe McCray (ensuring the user is either a security consultant, security researcher, or security enthusiast).</li>
<li>After 3 &#8211; 6 month a board of directors will be established to vet new members, and manage the day to day issues associated with the lab network</li>
</ul>
<p><strong> </strong></p>
<p><strong>The Cost</strong></p>
<ul>
<li>The lab network access cost is <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=782TC5LD6MMVC" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=782TC5LD6MMVC']);">$100 per dollars per month</a> for unrestricted access.</li>
<li>The lab network access cost is $50 per dollars per month for unrestricted access if you contribute 1 virtual machine configured with a security product.</li>
<li>The lab network access cost is $50 per dollars per month for unrestricted access if you contribute an article that provides a step-by-step walkthrough for bypassing a security mechanism that is in the lab network. The screenshots for this document must be taken using the lab network hosts.</li>
<li>The lab network access will be free if you donate 2 or more VMs with security products configured, or 2 or more articles detailing how to bypass a security mechanism that is in the lab network, or at least one of each.</li>
<li>You must sign up for the <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=782TC5LD6MMVC" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=782TC5LD6MMVC']);">$100 per dollars per month</a> access and when you donate either an article or a VM with a security product you won&#8217;t be charged for the upcoming month.</li>
</ul>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-advanced-pentesting-lab-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking In Paradise Giveaway</title>
		<link>http://strategicsec.com/2012/07/05/hacking-in-paradise-giveaway/</link>
		<comments>http://strategicsec.com/2012/07/05/hacking-in-paradise-giveaway/#comments</comments>
		<pubDate>Thu, 05 Jul 2012 06:25:51 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://strategicsec.com/?p=55228</guid>
		<description><![CDATA[Strategic Security is giving away three (3) free seats to Hacking In Paradise &#8211; The Bahamas 2012. If you complete all of the activities, you will receive 2 additional bonus    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/2012/07/05/hacking-in-paradise-giveaway/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Strategic Security is giving away three (3) free seats to <a title="Hacking In Paradise - The Bahamas 2012" href="strategicsec.com/services/training-services/classroom/hacking-in-paradise/">Hacking In Paradise &#8211; The Bahamas 2012</a>.<br />
If you complete all of the activities, you will receive 2 additional bonus points on<br />
top of what you already accumulated (<strong>you can do as many activities as you want everyday</strong> &#8211; good luck).</p>
<p>After you complete your tasks, send an email to joe(at)strategicsec(dot)com with<br />
publicly viewable links to the completed activities.</p>
<p>Here are the entry activities:</p>
<p>- Tweet about this giveaway (3 points)<br />
- Follow @j0emccray on twitter (1 point)<br />
- Follow @strategicsec on twitter (1 point)<br />
- Friend j0emccray on facebook [facebook.com/j0emccray] (1 point)<br />
- Add gplus.to/j0emccray to one of your circles on Google+ (1 point)<br />
- Like this page on facebook (1 point)<br />
- +1 this Hacking in Paradise page on Google+ (1 point)<br />
- Blog about this class (3 points)<br />
- Google+ post about this class (3 points)<br />
-<br />
<a id="rc-2b3ea70" class="rafl" href="http://www.rafflecopter.com/rafl/display/2b3ea70/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.rafflecopter.com/rafl/display/2b3ea70/']);" rel="nofollow">a Rafflecopter giveaway</a><br />
<script type="text/javascript" src="//d12vno17mo87cx.cloudfront.net/embed/rafl/cptr.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/2012/07/05/hacking-in-paradise-giveaway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking In Paradise- Includes Airfare, Hotel, and Training</title>
		<link>http://strategicsec.com/services/training-services/classroom/hacking-in-paradise/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/hacking-in-paradise/#comments</comments>
		<pubDate>Thu, 05 Jul 2012 05:21:41 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=55179</guid>
		<description><![CDATA[This is NOT your normal IT Security training session, this is NOT a boring death by powerpoint hacking class, this is NOT a 50 million old tools hacking history lesson    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/hacking-in-paradise/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<h3>This is <span style="color: #ff0000;"><b>NOT</b></span> your normal IT Security training session, this is <span style="color: #ff0000;"><b>NOT</b></span> a boring death by powerpoint hacking class, this is <span style="color: #ff0000;"><b>NOT</b></span> a 50 million old tools hacking history lesson style of workshop.</h3>
<h3><span style="color: #000000;">THIS IS A SECURITY TRAINING EXPERIENCE COMBINED WITH A 3-DAY BAHAMAS VACATION &#8211; THE ONLY COST TO YOU IS YOUR MEALS!</span></h3>
<p>&nbsp;</p>
<h3><b>Event Dates and Times</b></h3>
<p><span style="color: #ff0000;">September 6th</span>  &#8211; Arrival and hotel check-in</p>
<p><span style="color: #ff0000;">September 7-8th</span> &#8211; do your choice of fun activities on Saturday the 7th, relax and enjoy the entire day Sunday for yourself.</p>
<p>There are tons of things you can from absolutely nothing at all to jet skiing, kayaking, swimming with dolphins, jeep safaris and so much more.</p>
<p><span style="color: #ff0000;">September 9 – 11, 2013</span></p>
<p>After your built-in 3day vacation in the Bahamas you can settle in to the training will be held from 8:30am to 4:30pm each day. The class will be broken down into 50 minute sessions, 10 minute breaks, and 1 hour for lunch each day.</p>
<p>&nbsp;</p>
<h3><b>Event Location</b></h3>
<p>British Colonial Hilton Nassau hotel<br />
One Bay Street, Nassau, N-7148, Bahamas TEL: 1-242-322-3301</p>
<p><a href="http://www.bchiltonnassauhotel.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.bchiltonnassauhotel.com/']);">http://www.bchiltonnassauhotel.com/</a></p>
<p><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton9.png" ><img class="alignnone size-thumbnail wp-image-55190" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton9-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton5.png" ><img class="alignnone size-thumbnail wp-image-55189" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton5-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton8.png" ><img class="alignnone size-thumbnail wp-image-55188" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton8-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton71.png" ><img class="alignnone size-thumbnail wp-image-55187" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton71-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton6.png" ><img class="alignnone size-thumbnail wp-image-55186" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton6-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton3.png" ><img class="alignnone size-thumbnail wp-image-55184" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton3-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton4.png" ><img class="alignnone size-thumbnail wp-image-55183" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton4-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton2.png" ><img class="alignnone size-thumbnail wp-image-55182" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton2-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton.png" ><img class="alignnone size-thumbnail wp-image-55181" alt="Hilton Nassau Hotel" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton-150x150.png" width="150" height="150" /></a></p>
<p>&nbsp;</p>
<h3></h3>
<h3><strong>Accommodations</strong></h3>
<p><a href="http://strategicsec.com/wp-content/uploads/2012/07/Hilton-Nassau-Accomodations.jpg" ><img class="alignnone size-thumbnail wp-image-55413" alt="Hilton-Nassau-Accomodations" src="http://strategicsec.com/wp-content/uploads/2012/07/Hilton-Nassau-Accomodations-150x150.jpg" width="150" height="150" /></a> <a href="http://strategicsec.com/wp-content/uploads/2012/07/hilton-nassau-accomodations-5-300x200.jpg" ><img class="alignnone size-thumbnail wp-image-55416" alt="hilton-nassau-accomodations-5-300x200" src="http://strategicsec.com/wp-content/uploads/2012/07/hilton-nassau-accomodations-5-300x200-150x150.jpg" width="150" height="150" /></a></p>
<p><em>&#8220;Taken from the hotel website&#8221;</em></p>
<div>
<p>Your spacious guest room will offer you beautiful views of the harbor or city and many amenities. Each of our accommodations features an array of special touches and luxuries to ensure the ultimate experience during your stay.</p>
</div>
<div>
<h3>In-Room Amenities include:</h3>
<ul>
<li>Air conditioning</li>
<li>Alarm radio</li>
<li>Clock radio with MP3</li>
<li>Ergonomic desk chair</li>
<li>Hilton Serenity bed</li>
<li>Non-smoking</li>
<li>Separate bathtub and shower</li>
<li>Signature bedding</li>
<li>32-inch LCD HDTV</li>
<li>Cable TV</li>
<li>Bathroom amenities</li>
<li>Coffee maker</li>
<li>Hairdryer</li>
<li>Wireless high-speed Internet access</li>
<li>Iron &amp; ironing board</li>
<li>Mini refrigerator</li>
<li>Telephone with voicemail</li>
<li>Telephone with dataport</li>
<li>Automatic door closer</li>
<li>Double locking doors</li>
</ul>
</div>
<p>&nbsp;</p>
<h3><b>Activities</b></h3>
<p><a href="http://strategicsec.com/wp-content/uploads/2012/07/jetski1.png" ><img class="alignnone size-thumbnail wp-image-55191" alt="jetski1" src="http://strategicsec.com/wp-content/uploads/2012/07/jetski1-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Kayak2.png" ><img class="alignnone size-thumbnail wp-image-55192" alt="Kayak2" src="http://strategicsec.com/wp-content/uploads/2012/07/Kayak2-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/Kayak1.png" ><img class="alignnone size-thumbnail wp-image-55193" alt="Kayak1" src="http://strategicsec.com/wp-content/uploads/2012/07/Kayak1-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/dolfinswim.png" ><img class="alignnone size-thumbnail wp-image-55194" alt="dolfinswim" src="http://strategicsec.com/wp-content/uploads/2012/07/dolfinswim-150x150.png" width="150" height="150" /></a><a href="http://strategicsec.com/wp-content/uploads/2012/07/jeepsafari.png" ><img class="alignnone size-thumbnail wp-image-55195" alt="jeepsafari" src="http://strategicsec.com/wp-content/uploads/2012/07/jeepsafari-150x150.png" width="150" height="150" /></a></p>
<p>It&#8217;s time to have a real vacation &#8211; I&#8217;m talking fun in the sun. There are tons of things you can from absolutely nothing at all to jet skiing, kayaking, swimming with dolphins, jeep safaris and so much more.</p>
<p>We’re making sure that you have plenty of time for activities – you’ll arrive on Friday the 6<sup>th</sup> of September and you’ll have the entire weekend before the training starts to relax or to have some SERIOUS FUN. <strong>Your package deal will <span style="color: #ff0000;">include</span> your choice of jet-skiing, clear bottom kayaking, swimming with dolphins, or a Jeep safari.</strong></p>
<p>&nbsp;</p>
<p>Get there on Friday the 6th of September, do your choice of fun activities on Saturday the 7th, relax and enjoy the entire day Sunday for yourself and do the training from Monday to Wednesday &#8211; fly home on Thursday.</p>
<p>&nbsp;</p>
<h3><strong>Companion Airfare:</strong></h3>
<p>Ok &#8211; let&#8217;s be real. There is no way your wife/girlfriend/husband/boyfriend or (significant other) is going to let you go to this without them. Yes, we can do that. Just contact Joe McCray for a quote.</p>
<p>&nbsp;</p>
<h3><b>Workshop choices:</b></h3>
<p>&nbsp;</p>
<p><strong>Workshop 1:   Metasploit  (Great for beginners and intermediate students) &#8211; taught by <a href="https://twitter.com/georgiaweidman" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://twitter.com/georgiaweidman']);" target="_blank">@georgiaweidman</a></strong></p>
<p>or</p>
<p><strong>Workshop 2:  Cyberwar (Great for  intermediates and advanced students)- taught by <a href="https://twitter.com/j0emccray" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://twitter.com/j0emccray']);" target="_blank">@j0emccray</a></strong></p>
<p>&nbsp;</p>
<p>These workshops run in parallel.  Workshop 1 is designed for IT and IT Security Professionals that want more exposure to network and application penetration testing. Workshop 2 is designed for IT Security Professionals and Penetration Testers that want to take their skills to the next level.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h3><b>Metasploit Short Description</b></h3>
<p>The class will begin with the basics of using the Metasploit Framework and then continue on following the Open Source Security Testing Methodology Manual (OSSTMM) to exploit vulnerable systems in a lab network. Quickly moving on from the basic concepts the class will move into advanced topics such as writing your own Metasploit modules and creating sophisticated client side attacks with Metasploit and the Social Engineering Toolkit. This class is ideal for beginning pentesters looking to pick up many skills and become comfortable using the common tools of the trade.</p>
<p>Students will be introduced to finding and exploiting vulnerabilities in both Windows and Linux-based systems, attacking web applications with Metasploit and additional pentesting tools such as Maltego, Nmap, and Nikto will also be covered.</p>
<p>&nbsp;</p>
<h3><b>CyberWar Short Description</b></h3>
<p>This course picks up where the wildly successful &#8220;Advanced Penetration Tester: Pentesting High Security Environments&#8221; left off. Taking Intrusion Detection System (IDS) evasion, and Anti-virus bypass to the next level.  There are a few things to note that will be different from the &#8220;Advanced Penetration Tester: Pentesting High Security Environments&#8221; and from any other hacking course for that matter:</p>
<ol start="1">
<li>Per student request there will be NO Windows 2000, no Windows XP, or Vista in the course. Only Windows 7, Windows 8, and Server 2008 RC2, and new Linux distributions as the targets for students to go after.</li>
</ol>
<ol start="1">
<li>Students attack a network of fully patched, and hardened Windows 7, Server 2008 RC2 hosts. Each target computer will be running a Host-Based Intrusion Detection System (HIDS), updated Anti-Virus, and a logging agent that reports to a Security Information and Event Management (SIEM) solution.</li>
</ol>
<ol start="1">
<li>There will also be a Network Intrusion Detection System (NIDS), a web content filtering proxy, and a stateful inspection firewall as well.</li>
</ol>
<ol start="1">
<li>The classroom will have 4 projectors running to show in real time the events triggered by the HIDS, NIDS, Proxy, and the logs so the student can learn exactly what attacks and defenses really work in today&#8217;s high security environment.</li>
</ol>
<p>&nbsp;</p>
<p><b>Download The Complete Hacking In Paradise Package Description Document By Clicking <a title="Download The Course Syllabus and Package Description" href="http://strategicsec.com/Hacking-In-Paradise-2013.pdf"  target="_blank">HERE</a></b></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h2><span style="color: #ff0000;"><b>All Inclusive Pricing (Training, Airfare, Lodging)</b></span></h2>
<h3>US Based All-Inclusive Packages (Meaning you are traveling from the US):</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $3,500USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20&amp;item_number=HIPMetasploit&amp;amount=3500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20&amp;item_number=HIPMetasploit&amp;amount=3500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the Metasploit All-Inclusive Package</a></li>
</ul>
</li>
<li>CyberWar, Flight, Hotel, and Activities                           $3,500USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20European%20Package&amp;item_number=HIPCyberWar&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20European%20Package&amp;item_number=HIPCyberWar&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the CyberWar All-Inclusive Package</a></li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<h3>Europe Based All-Inclusive Packages (Meaning you are traveling from Europe):</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $4,500USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20European%20Travel%20Package&amp;item_number=HIPMetasploitEuro&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20European%20Travel%20Package&amp;item_number=HIPMetasploitEuro&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the Metasploit All-Inclusive Package</a></li>
</ul>
</li>
<li>CyberWar, Flight, Hotel, and Activities                           $4,500USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20European%20Travel%20Package&amp;item_number=HIPCyberWarEuro&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20European%20Travel%20Package&amp;item_number=HIPCyberWarEuro&amp;amount=4500%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the CyberWar All-Inclusive Package</a></li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<h3>Asia/Austrailia/Africa Based All-Inclusive Packages (Meaning you are traveling from Asia/Austrailia/Africa):</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $5,000USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20Asian%20Travel%20Package&amp;item_number=HIPMetasploitAsia&amp;amount=5000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=georgia%40grmn00bs%2ecom&amp;item_name=Hacking%20In%20Paradise%20Metasploit%20Asian%20Travel%20Package&amp;item_number=HIPMetasploitAsia&amp;amount=5000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the Metasploit All-Inclusive Package</a></li>
</ul>
</li>
<li>CyberWar, Flight, Hotel, and Activities                           $5,000USD
<ul>
<li><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20Asian%20Package&amp;item_number=HIPCyberWarAsia&amp;amount=5000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacking%20In%20Paradise%20CyberWar%20Asian%20Package&amp;item_number=HIPCyberWarAsia&amp;amount=5000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Click here to purchase the CyberWar All-Inclusive Package</a></li>
</ul>
</li>
</ul>
<p>&nbsp;</p>
<h3><span style="color: #ff0000;"><b>Prices listed above are valid if purchased before May 31<sup>st</sup>, 2013</b></span></h3>
<p>&nbsp;</p>
<h3>All-Inclusive Packages (Prices below if purchased between 31 May and 31 July, 2013):</h3>
<h3>US Based All-Inclusive Packages:</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $4,500USD</li>
<li>CyberWar, Flight, Hotel, and Activities                           $4,500USD</li>
</ul>
<p>&nbsp;</p>
<h3>Europe Based All-Inclusive Packages:</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $5,500USD</li>
<li>CyberWar, Flight, Hotel, and Activities                           $5,500USD</li>
</ul>
<p>&nbsp;</p>
<h3>Asia/Austrailia/Africa Based All-Inclusive Packages:</h3>
<ul>
<li>Metasploit, Flight, Hotel, and Activities                          $6,000USD</li>
<li>CyberWar, Flight, Hotel, and Activities                           $6,000USD</li>
</ul>
<p><b> </b></p>
<p><b>NOTE:</b></p>
<p>If you are interested in purchasing the training without travel and lodging please contact Joe McCray directly.</p>
<p align="center"><b> </b></p>
<p align="center"><b>About The Metasploit Instructor: Georgia Weidman</b></p>
<p> <a href="http://strategicsec.com/wp-content/uploads/2012/07/georgia.jpg" ><img class="size-thumbnail wp-image-55374 aligncenter" alt="georgia" src="http://strategicsec.com/wp-content/uploads/2012/07/georgia-150x150.jpg" width="150" height="150" /></a></p>
<p>Georgia Weidman is a penetration tester, security researcher, and trainer. She holds a Master of Science degree in computer science, secure software engineering, and information security as well as holding CISSP, CEH, NIST 4011, and OSCP certifications. Her work in the field of smartphone exploitation has been featured in print and on television internationally. She has presented her research at top conferences around the world including Shmoocon, Blackhat, Hacker Halted, and Bsides. Georgia has delivered highly technical security training for conferences, schools, and corporate clients to excellent reviews. Building on her experience, Georgia founded Bulb Security LLC (http://www.bulbsecurity.com), a security consulting firm specializing in security assessments/penetration testing, security training, and research/development. She was awarded a DARPA Cyber Fast Track grant to continue her work in mobile device security, culminating in the release of the Smartphone Pentest Framework (SPF).</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p align="center"> <b>About The CyberWar Instructor: Joe McCray</b></p>
<p> <a href="http://strategicsec.com/wp-content/uploads/2012/07/me.png" ><img class="size-thumbnail wp-image-55196 aligncenter" alt="Joe McCray" src="http://strategicsec.com/wp-content/uploads/2012/07/me-129x150.png" width="129" height="150" /></a></p>
<p>Joe McCray is an Air Force Veteran and has been in security for over 10 years. Joe has been involved in over 150 very high level pentesting assessments and has some major hacking accomplishments that he can share with his classes. His extensive experience and deep knowledge, mixed with his comedic style has lead Joe to be one of the most highly sought after speaking experts in the industry. Joe makes speaking appearances and gives seminars at major events in the security community such as Black Hat, DefCon, BruCon, Hacker Halted and more. Joe is the recipient of the 2009 EC-Council Instructor Circle of Excellence Award and the 2010 EC-Council Instructor of the Year Award. Joe is the founder and CEO of <a href="http://strategicsec.com" >http://strategicsec.com</a> an IT Security consulting firm that provides in-depth technical security assessments of your network, web application, and regulatory compliance gap analysis.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><b>Who To Contact For More Information</b></p>
<p>&nbsp;</p>
<p>You can contact Joe McCray at:</p>
<p>&nbsp;</p>
<p>Toll Free:                     1-866-892-2132</p>
<p>Email:                          <a href="mailto:joe@strategicsec.com">joe@strategicsec.com</a></p>
<p>LinkedIn:                    <a href="http://www.linkedin.com/in/joemccray" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.linkedin.com/in/joemccray']);">http://www.linkedin.com/in/joemccray</a></p>
<p>Twitter:                       <a href="http://twitter.com/j0emccray" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://twitter.com/j0emccray']);">http://twitter.com/j0emccray</a></p>
<p>Website:                      <a href="http://strategicsec.com" >http://strategicsec.com</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/hacking-in-paradise/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Advanced Pentester&#8217;s Weekend Workshop</title>
		<link>http://strategicsec.com/services/training-services/online/advanced-pentesters-workshop/</link>
		<comments>http://strategicsec.com/services/training-services/online/advanced-pentesters-workshop/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 05:50:32 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=33442</guid>
		<description><![CDATA[Yup, I&#8217;m doing another one. This time we are going to cover bypassing AV/HIPS (specifically Symantec AV &#38; EndPoint Protection) in addition to everything else. What I&#8217;ll be doing this    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/advanced-pentesters-workshop/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Yup, I&#8217;m doing another one. This time we are going to cover bypassing AV/HIPS (specifically Symantec AV &amp; EndPoint Protection) in addition to everything else.</p>
<p>What I&#8217;ll be doing this time is basically focusing on Pentester Headaches:</p>
<ul>
<li>Intrusion Prevention Systems</li>
<li>Web Application Firewalls</li>
<li>Anti-Virus</li>
</ul>
<p>I&#8217;ll also cover ways to implement penetration tester tactics such as:</p>
<ul>
<li>Lateral movement</li>
<li>Data-Driven Testing</li>
<li>Persistence</li>
</ul>
<p>Specific tools and techniques I&#8217;ll be covering will be:</p>
<ul>
<li>Nmap Scripting Engine</li>
<li>Windows Credential Editor and Mimikatz</li>
<li>New Pass-The-Hash functionality in Firefox</li>
</ul>
<p>Like the last workshop this one is also designed to be an attack lab style of class.</p>
<p>Students will be given a VMware image with all of the attack tools preloaded to download, and VPN credentials to log into the Strategic Security lab network.</p>
<p><span style="color: #ff6600;">NOTE:</span> This is NOT the same network as the last workshop (different network network, different targets).</p>
<p>Like the previous workshop&#8217;s target network there will be vulnerable hosts running Windows 2000, XP, Vista, Windows 7, Server 2003, Server 2008, and various flavors of Linux. There is also a snort IDS, and an AlienVault SEIM in the network as well so students can look to see which of their attacks are being detected.</p>
<p>The workshop will be LIVE via GotoWebinar again, and I will be walking the students through the various attacks, and answering student questions.</p>
<p>Students will be given a lab manual that walks them through the various attacks.</p>
<p>The workshop will be held on Saturday the 11th of August, 2012 from 12 noon EST to 4 pm EST at a cost of <a title="Advanced Pentester's Workshop $50USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Pentester%27s%20Workshop&amp;item_number=APTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Pentester%27s%20Workshop&amp;item_number=APTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$50 USD</a></p>
<p>The students will be allowed to maintain their VPN access until the end of the month of August.</p>
<p>A few things to note that will be different from the last workshop:</p>
<ul>
<li>The attack VM will be made available for students to download within 4 hours of workshop purchase</li>
<li>The VPN credentials, IRC channel info, and lab manual for the target network made available to the students on Monday the 6th of August at noon EST via email or within 4 hours of workshop purchase if you purchased after the 6th</li>
<li>From 6pm &#8211; 9pm EST on the 10th of August Strategic Security rookies will be in an IRC channel assisting people with connecting to the Strategic Security Lab network.</li>
<li>From 9am &#8211; noon EST on the 11th of August Strategic Security rookies will be in an IRC channel assisting people with connecting to the Strategic Security Lab network.</li>
</ul>
<p>Click <a title="Register for this workshop" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Pentester%27s%20Workshop&amp;item_number=APTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Pentester%27s%20Workshop&amp;item_number=APTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);"><span style="color: #ff0000;"><strong>HERE</strong></span></a> to register for this workshop.</p>
<p>Well that&#8217;s about it &#8211; hope to you in the workshop.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/advanced-pentesters-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker&#8217;s Breakfast (3-Hour Workshops in MD and VA)</title>
		<link>http://strategicsec.com/services/training-services/classroom/hackers-breakfast-3-hour-workshops-in-md-and-va/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/hackers-breakfast-3-hour-workshops-in-md-and-va/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 09:41:34 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=28692</guid>
		<description><![CDATA[Hackers Breakfast is a 3 hour training seminar where we cover new, cutting edge, little known yet highly effective skill sets that are imperative for an emerging IT security expert.    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/hackers-breakfast-3-hour-workshops-in-md-and-va/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Hackers Breakfast is a 3 hour training seminar where we cover new, cutting edge, little known yet highly effective skill sets that are imperative for an emerging IT security expert. These seminars take place at ACE&#8217;s Ashburn, VA and Greenbelt, MD locations throughout the year. The events are limited to 18 attendees. At the seminar we will serve coffee and breakfast and we will cover a unique security topic through live demonstration while you get hands-on experience with that topic on a PC in our classroom.</p>
<p>Schedule:<br />
1) Ashburn, VA February 23, 2012 8:30am &#8211; 11:30am<br />
Topic: Web Application Security<br />
Joe McCray will be covering both manual and automated vulnerability testing of Web Applications. This workshop will focus on vulnerabilities like SQL Injection, Cross-Site Scripting, and LFI/RFI vulnerabilities. You’ll also learn how to test applications built on .NET, J2EE and other frameworks. This workshop will be 90% hands-on.</p>
<p>Cost:  <a title="$100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacker%27s%20Breakfast%20in%20Ashburn,%20VA&amp;item_number=HBASH&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacker%27s%20Breakfast%20in%20Ashburn,%20VA&amp;item_number=HBASH&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$100</a></p>
<p>Address:</p>
<p>45195 Research Pl, Suite 120<br />
Ashburn, VA 20147</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>2) Greenbelt, MD March 7, 2012 8:30am &#8211; 11:30am<br />
Network Vulnerability Testing<br />
Joe will be covering both manual and automated vulnerability testing of networked hosts running all of the major platforms XP/Vista/Win7 and Server 2003/2008 – as well as popular Linux platforms. You’ll learn the newest methods for attacking these types of hosts and dealing with defensive technologies such as Anti-Virus, IDS, IPS, etc. This workshop will be 90% hands-on.</p>
<p>Cost:  <a title="$100USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacker%27s%20Breakfast%20in%20Greenbelt,%20MD&amp;item_number=HBGB&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Hacker%27s%20Breakfast%20in%20Greenbelt,%20MD&amp;item_number=HBGB&amp;amount=100%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$100</a></p>
<p>Address:</p>
<p>7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/hackers-breakfast-3-hour-workshops-in-md-and-va/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentester&#8217;s Workshop</title>
		<link>http://strategicsec.com/services/training-services/online/pentesters-workshop/</link>
		<comments>http://strategicsec.com/services/training-services/online/pentesters-workshop/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 20:58:02 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=22393</guid>
		<description><![CDATA[We&#8217;ve been doing a lot of work on the lab network so we decided to do another Pentester&#8217;s Workshop. I think you&#8217;ll really like it &#8211; it&#8217;s 50 bucks just    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/pentesters-workshop/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>We&#8217;ve been doing a lot of work on the lab network so we decided to do another Pentester&#8217;s Workshop. I think you&#8217;ll really like it &#8211; it&#8217;s 50 bucks just like last time.</p>
<p><a title="Pentester's Workshop $50USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%27s%20Workshop&amp;item_number=PTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%27s%20Workshop&amp;item_number=PTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">Pentester&#8217;s Workshop</a></p>
<p>This is a HOW/WHY class. We&#8217;ll be covering the common penetration testing related subjects such as:</p>
<ul>
<li>Scanning</li>
<li>Enumeration</li>
<li>Exploitation</li>
<li>Post-Exploitation</li>
<li>Web Application Testing</li>
</ul>
<p>This workshop is designed to be an attack lab style of class.</p>
<p>Students will be given a VMware image with all of the attack tools preloaded to download, and VPN credentials to log into the Strategic Security lab network.</p>
<p>The target network will contain vulnerable hosts running Windows 2000, XP, Vista, Windows 7, Server 2003, Server 2008, and various flavors of Linux. There is also a snort IDS in the network as well so students can look to see which of their attacks are being detected.</p>
<p>The workshop will be LIVE via GotoWebinar, and I will be walking the students through the various attacks, and answering student questions.</p>
<p>Students will be given a lab manual that walks them through the various attacks.</p>
<p>The workshop will be held on Saturday the 14th of April, 2012 from 4 pm &#8211; 6pm EST at a cost of <a title="Pentester's Workshop $50USD" href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%27s%20Workshop&amp;item_number=PTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Pentester%27s%20Workshop&amp;item_number=PTWS&amp;amount=50%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$50 USD</a></p>
<p>The students will be allowed to maintain their VPN access until midnight April 30th of April, 2012.</p>
<p>A few things to note that will be different from the first workshop:</p>
<ul>
<li>The attack VM will be made available for students to download on Wednesday the 9th of April</li>
<li>The VPN credentials, IRC channel info, and lab manual for the target network made available to the students on Friday the 13th of April at noon EST via email</li>
<li>From 6pm – 9pm EST on the 13th of April Strategic Security rookies will be in an IRC channel assisting people with connecting to the Strategic Security Lab network.</li>
<li>From noon EST to 4pm on the 14th of April Strategic Security rookies will be in an IRC channel assisting people with connecting to the Strategic Security Lab network</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/pentesters-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Python For Security Professionals</title>
		<link>http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 09:23:13 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=19095</guid>
		<description><![CDATA[This class is for security professionals that have very little programming experience. If you&#8217;ve ever struggled in a programming class because you wanted the instructor to put programming concepts in    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>This class is for security professionals that have very little programming experience.</p>
<p>If you&#8217;ve ever struggled in a programming class because you wanted the instructor to put programming concepts in plain and simple english &#8211; this class is for you.</p>
<p>If you&#8217;ve ever tried to learn programming from a book thought the book spent too much time on math, and writing absolutely programs like a CD collection database &#8211; this class is for you.</p>
<p>If you&#8217;ve ever wanted a programming course to be about stuff you could actually use at work &#8211; this class is for you.</p>
<p>This is a functional programming course focused on programming concepts that can be used to accomplish common security tasks such as log parsing, password cracking, port scanning, vulnerability testing, web application security testing, malware analysis, and exploit development. There won&#8217;t be a bunch of math, no CD collection databases, and no useless programming mumbo jumbo.</p>
<p>Each day the students will learn a few basic programming concepts, and then use some sample code (skeleton scripts) to perform security tasks. The students will keep the skeleton<br />
scripts so that when they get back to work they&#8217;ll have something that they can use a crib sheet to do other security tasks.</p>
<p><strong>Day 1:     Programming Concepts, Parsing Files, Logs, and PCAPs</strong></p>
<ul>
<li>    Python Basics</li>
<li>    Text File Parsing</li>
<li>    Log Parsing</li>
<li>    PCAP Parsing</li>
</ul>
<p><strong>Day 2:    System Administration and Password Cracking</strong></p>
<ul>
<li>    Windows and *nix Administration</li>
<li>    Password Cracking</li>
<li>    Netcat-like Functionality</li>
<li>    Port-Scanning</li>
</ul>
<p><strong>Day 3:    Network and Web Application Vulnerability Testing</strong></p>
<ul>
<li>    Vulnerable Service Identification</li>
<li>    SQL Injection</li>
<li>    XSS</li>
<li>    RFI/LFI</li>
</ul>
<p><strong>Day 4:    Forensics and Malware Analysis</strong></p>
<ul>
<li>    Memory Analysis</li>
<li>    Identifying/Classifying Malware</li>
<li>    HexEditing/Dissabling Malware</li>
</ul>
<p><strong>Day 5:    Reverse Engineering, Fuzzing and Exploit-Dev</strong></p>
<ul>
<li>    Debugging</li>
<li>    Protocol Fuzzing</li>
<li>    File Format Fuzzing</li>
<li>    Exploiting Software</li>
</ul>
<p><strong>Course Instructor:</strong><br />
The course instructor is security consultant and trainer Joe McCray. Joe McCray has over 10 years of experience in the security industry with a diverse background that includes network and web application penetration testing, incident response, and forensics in the both DoD community and the private sector. Joe is also a frequent trainer/presenter at security conferences such as Black Hat, Def Con, ToorCon, BruCON, LayerOne, TechnoSecurity, and TechnoForensics.</p>
<p><strong>General Course Info:</strong><br />
Course dates are 13th – 17th Febrary 2012. The course will be comprised of 5 days of 50 minute sessions with 5-10 minute breaks, and an hour for lunch.</p>
<p><strong>Pre-requisites:</strong><br />
Students must be familiar with IT Security best practices, and have a good understanding of TCP/IP and common web technologies.</p>
<ul>
<li>Basic Windows administration for both servers and workstations</li>
<li>Basic Linux/*NIX system administration skill</li>
<li>Basic command-line proficiency on both Windows and *NIX systems</li>
</ul>
<p><strong>Training Location:</strong><br />
Academy of Computer Education<br />
7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770<br />
Phone: (301) 220-2802<br />
Toll-Free: (877) 564-TRAIN</p>
<p><a title="TrainACE" href="http://www.trainace.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.trainace.com/']);">http://www.trainace.com/</a></p>
<p><strong>Pricing:</strong> <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals&amp;item_number=PFSP&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Python%20For%20Security%20Professionals&amp;item_number=PFSP&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$2,000</a></p>
<p>All software and necessary equipment is provided.</p>
<p>Need a hotel for the week of your class?</p>
<p>For a discounted hotel rate please contact us. ACE has pre-negotiated a discounted stay for Python For Security Professionals students in the Greenbelt Hilton Garden Inn.<br />
The Hotel is located approximately 200 yards from the school.</p>
<p>All Inclusive Python For Security Professionals Class Pricing:</p>
<p>If you are flying in from out of town for the Python For Security Professionals training class, we have an all-inclusive bootcamp style package which includes your flight, hotel, and breakfast each day for <a href=" https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=PFSP%20With%20Hotel&amp;item_number=PFSPWH&amp;amount=3000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" >$3,000</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Network Security Architecture Class</title>
		<link>http://strategicsec.com/services/training-services/classroom/advanced-network-security-architecture-class/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/advanced-network-security-architecture-class/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 00:12:47 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=13467</guid>
		<description><![CDATA[The Advanced Network Security Architecture (ANSA): Attacking/Defending Complex Networks course is a five-day intensive that focuses attacking and defending highly secured environments such as 3-letter agencies, DoD, financial organizations, federal    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/advanced-network-security-architecture-class/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The Advanced Network Security Architecture (ANSA): Attacking/Defending Complex Networks course is a five-day intensive that focuses attacking and defending highly secured environments such as 3-letter agencies, DoD, financial organizations, federal organizations, and large companies.</p>
<p>Like every course that Joe McCray teaches &#8211; this is NOT your normal Hacking course. You won’t be attacking unpatched Windows 2000 Servers, and you won’t be learning a bunch of outdated tools like most Hacking courses. The over-arching focus of the is Secure Network Architecture and design principles.</p>
<p>Each day you will be tasked with attacking and defending an increasingly complex network. On the first day you&#8217;ll start with both attacking and defending an environment with basic firewalling, and simple network segmentation.  On the second day you&#8217;ll add VLANs, and network based IDS. On the third and fourth days you&#8217;ll add content filtering web proxies, reverse proxies, host&#8211;based IDS, WAFs, NAC, and a SIEM solution. Finally, on the fifth day will be an attack and defense based capture the flag event that incorporates all of the security solutions in place with multiple projectors in the room so each security system will be projected on the wall like a SOC environment.</p>
<p>The attack portion of the course starts with attacking heavily protected environments from the outside and dealing with things like Load Balancing, Deep Packet Inspection, and Network-Based IDS/IPS. Next is attacking web applications and dealing with common application security measures in PHP/ASP.NET, and Web Application Firewalls.</p>
<p>Then the course moves on to attacking from the LAN, dealing with NAC solutions, locked down workstations/GPOs, and Host-Based IDS/IPS. Then finally the last section of the course covers gaining control of Active Directory.</p>
<p>In ANSA, just like the advanced penetration testing courses that Joe McCray teaches you will be learning how to attack new operating systems such as Windows Vista, Windows 7, Windows Server 2008, and the latest Linux servers. All of these servers will be patched, and hardened. Both Network and Host-based Intrusion Detection/Preventions systems (IDS/IPS) will be in place as well.</p>
<p>Like all of the advanced courses that Joe McCray teaches the learning curve is high, but the rewards are astronomical. Attacking/Defending Complex Networks is NOT a death by powerpoint course. Over 90% of class is hands-on labs.</p>
<p>Students that are Network/System Administrators with three or more years experience working in environments such as financial institutions, DoD networks, or similar high security environments will benefit greatly from this course.</p>
<p>&nbsp;</p>
<p><strong>Course Instructor</strong><br />
The course instructor is security consultant and trainer Joe McCray. Joe McCray has over 10 years of experience in the security industry with a diverse background that includes network and web application penetration testing, incident response, and forensics in the both DoD community and the private sector. Joe is also a frequent trainer/presenter at security conferences such as Black Hat, Def Con, ToorCon, BruCON, LayerOne, TechnoSecurity, and TechnoForensics.</p>
<p><strong>General Course Info</strong></p>
<p>Course dates are 9th – 13th January 2012. The course will be comprised of 5 days of 50 minute sessions with 5-10 minute breaks, and an hour for lunch.</p>
<p>Pre-requisites:<br />
Students must be familiar with IT Security best practices, and have a good understanding of TCP/IP and common web technologies.<br />
* Basic Windows administration for both servers and workstations<br />
* Basic Linux/*NIX system administration skill<br />
* Basic command-line proficiency on both Windows and *NIX systems</p>
<p>Students should be familiar with the following web technologies and languages:<br />
* HTML<br />
* Javascript<br />
* ASP<br />
* PHP<br />
* SQL</p>
<p>Students should also be familiar with Metasploit, and VMWare.</p>
<p><strong>Training Location</strong><br />
Academy of Computer Education<br />
7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770<br />
Phone: (301) 220-2802<br />
Toll-Free: (877) 564-TRAIN</p>
<p><a href="http://www.trainace.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.trainace.com/']);">http://www.trainace.com/</a></p>
<p>Pricing: <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Network%20Security%20Architecture&amp;item_number=ANSA&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Network%20Security%20Architecture&amp;item_number=ANSA&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$2,000</a></p>
<p>All software and necessary equipment is provided.</p>
<p><strong>Need a hotel for the week of your class?</strong></p>
<p>For a discounted hotel rate please contact us. ACE has pre-negotiated a discounted stay for ANSA students in the Greenbelt Hilton Garden Inn.<br />
The Hotel is located approximately 200 yards from the school.</p>
<p><strong>All Inclusive ANSA Class Pricing:</strong></p>
<p>If you are flying in from out of town for the ANSA training class, we have an all-inclusive bootcamp style package which includes your flight, hotel, and breakfast each day for <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=ANSA%20With%20Hotel&amp;item_number=ANSA&amp;amount=3000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=ANSA%20With%20Hotel&amp;item_number=ANSA&amp;amount=3000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$3,000</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/advanced-network-security-architecture-class/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quick Look &#8211; Web App</title>
		<link>http://strategicsec.com/services/assessment-services/web-application-assessment/quick-look-web-app/</link>
		<comments>http://strategicsec.com/services/assessment-services/web-application-assessment/quick-look-web-app/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 05:40:19 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/?page_id=3923</guid>
		<description><![CDATA[Do you just want someone to take a quick look at your company website? We get a lot of requests from people that just want us to take a look    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/assessment-services/web-application-assessment/quick-look-web-app/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Do you just want someone to take a quick look at your company website?</p>
<p>We get a lot of requests from people that just want us to take a look quick look at their company website. Not as deep as a full on web application security assessment, but not just as trivial as a scan with a vulnerability scanner either.</p>
<p>We&#8217;ve created a service to address this need. Basically it&#8217;s web app vulnerability scan with a few different types of automated scanners and security tools, and eight (8) hours of manual testing by one of our application security consultants.</p>
<p>This will let you know if you are on the right track as far as security is concerned, or if you actually need to allocate more resources to securing your website. The cost of the service is trivial, we start the next business day after purchase, and give you the report on 3rd business day.</p>
<p>So if you:</p>
<ul>
<li>Have an audit coming up and are concerned about the security of a particular server</li>
<li>Recently deployed a server and are curious if the right security measures are in place</li>
<li>Need to be able to answer questions about the security of a server for an upcoming meeting</li>
<li>Want to verify that your IT, or IT security team is taking the right precautions when they deploy a server</li>
</ul>
<p>If you fall into any of these categories listed above than this service offering is for you. The cost is <a title="$1,500 USD" href=" https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;amp;item_name=Quick%20Look%20Web%20App%20Assessment&amp;item_number=QLWA&amp;amount=1500&amp;no_shipping=0&amp;no_note=1&amp;amp;currency_code=USD&amp;lc=US&amp;bn=PP%%202dBuyNowBF&amp;charset=UTF%2d8" >$1,500USD</a>. It doesn&#8217;t cost you an arm and a leg, it&#8217;s quick, no fuss, and most importantly there&#8217;s no bait and switch upsell crap.</p>
<p>It&#8217;s simple &#8211; you need someone to take a quick look at your website security and let you know either:</p>
<p>a) Yes, it looks good. Keep on doing what you are doing</p>
<p>b) No, found a few security issues so you need to spend some time on this and look at it more closely</p>
<p>It&#8217;s 2 minutes to purchase, 1 day for a quick synopsis, and 3 business days for the full report.</p>
<p>How to get started:</p>
<p>1. <a title="Click here to purchase the Quick Look: Web App service" href=" https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;amp;item_name=Quick%20Look%20Web%20App%20Assessment&amp;item_number=QLWA&amp;amount=1500&amp;no_shipping=0&amp;no_note=1&amp;amp;currency_code=USD&amp;lc=US&amp;bn=PP%%202dBuyNowBF&amp;charset=UTF%2d8" >Click here to purchase the Quick Look: Web App service</a></p>
<p>2. We will email you an Statement of Work (SOW) for the project, and the project will begin on the next business day after we received the signed SOW.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/assessment-services/web-application-assessment/quick-look-web-app/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Malware Analysis</title>
		<link>http://strategicsec.com/services/training-services/classroom/advanced-malware-analysis/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/advanced-malware-analysis/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 20:15:13 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/</guid>
		<description><![CDATA[What has become accepted as &#8220;reverse engineering training&#8221; is really just malware analysis that simply consists of &#8220;run-time analysis&#8221;. What this means is that you put the malware on a    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/advanced-malware-analysis/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>What has become accepted as &#8220;reverse engineering training&#8221; is really just malware analysis that simply consists of &#8220;run-time analysis&#8221;. What this means is that you put the malware on a virtual machine and run a packet sniffer (like Wireshark), a registry monitor (like regshot), a file monitor (like filemon) and then a process monitor (like process explorer).</p>
<p>These common &#8220;reverse engineering&#8221; courses have you run malware and answer the questions:</p>
<p>1. Where is it connecting to?<br />
2. Does it modify the registry?</p>
<p>3. Does it modify the file system?<br />
4. Does it modify any running processes or start any new ones?<br />
You don&#8217;t need a class to teach you these things.</p>
<p>The goal of the AMA training class is to provide a methodical hands-on approach to reverse-engineering by covering both behavioral and code analysis aspects of the analytical process.</p>
<p>The course begins by looking into PE headers and how toÂ  handle DLL interactions. Then it moves on to the fundamentals of x86 architecture assembly. Next you learn to examine malicious code in order to understand the program&#8217;s key components and execution flow. You then learn to identify common malware characteristics by looking at Windows API use patterns, and will examine excerpts from bots, rootkits, key loggers, and downloaders. From there you move on to standard and custom packers and other tools and techniques for bypassing anti-virus, and then on to malware with anti-debugging/anti-analysis capabilities. Then the class is concluded with obfuscated browser scripts.</p>
<p>You can purchase this course by clicking <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis%20Course%203%20Oct%202011%20in%20Maryland%20From%20SS&amp;item_number=APT&amp;amount=2000&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%25%202dBu" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis%20Course%203%20Oct%202011%20in%20Maryland%20From%20SS&amp;item_number=APT&amp;amount=2000&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%25%202dBu']);">here</a>.</p>
<p>Day 1: Basic Forensics</p>
<ul>
<li>Analyzing a hard drive image</li>
<li>Recovering deleted files</li>
<li>Decrypting encrypted files</li>
</ul>
<p>Day2: Bypassing Anti-Virus</p>
<ul>
<li>Using Hex Editors to bypass AV</li>
<li>Using packers to bypass AV</li>
<li>Using debuggers/disassemblers to bypass AV</li>
</ul>
<p>Day3: Network/Browser Forensics</p>
<ul>
<li>Advanced pcap analysis</li>
<li>De-obfuscating malicious javascript</li>
</ul>
<p>Day4: Memory Analysis</p>
<ul>
<li>Memory analysis</li>
<li>Malicious pdf file analysis</li>
<li>DLL injection</li>
</ul>
<p>Day5: Reverse Engineering</p>
<ul>
<li>Binary modification/patching techniques</li>
<li>Anti-Debugging/Anti-Analysis techniques</li>
<li>Exploit development</li>
</ul>
<p><strong>Course Instructor</strong><br />
The course instructor is security consultant and trainer Joe McCray. Joe McCray has 10 years of experience in the security industry with a diverse background that includes network and web application penetration testing, incident response, and forensics in the both DoD community and the private sector. Joe is also a frequent trainer/presenter at security conferences such as Black Hat, Def Con, ToorCon, BruCON, LayerOne, TechnoSecurity, and TechnoForensics.</p>
<p><strong>General Course Info</strong></p>
<p>Course dates are October 3rd &#8211; 7th. The course will be comprised of 5 days of 50 minute sessions with 5-10 minute breaks, and an hour for lunch.</p>
<p>Pre-requisites:<br />
Students must be familiar with IT Security best practices, and have a good understanding of TCP/IP and common web technologies.</p>
<p>* Basic Windows administration for both servers and workstations</p>
<p>* Basic Linux/*NIX system administration skill</p>
<p>* Basic command-line proficiency on both Windows and *NIX systems</p>
<p>Students should be familiar with the following web technologies and languages:<br />
* HTTP<br />
* HTML<br />
* Javascript<br />
* ASP<br />
* PHP<br />
* SQL</p>
<p><strong>Training Location</strong><br />
Academy of Computer Education<br />
7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770<br />
Phone: (301) 220-2802<br />
Toll-Free: (877) 564-TRAIN<br />
<a href="http://www.trainace.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.trainace.com/']);">http://www.trainace.com/</a></p>
<p>Pricing <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis&amp;item_number=AMA&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis&amp;item_number=AMA&amp;amount=2000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$2,000</a></p>
<p>All software and necessary equipment is provided.</p>
<p>Need a hotel for the week of your class?</p>
<p>For a discounted hotel rate please contact us. ACE has pre-negotiated a<br />
discounted stay for AMA students in the Greenbelt Hilton Garden Inn.<br />
The Hotel is located approximately 200 yards from the school.</p>
<p>All Inclusive AMA Class Pricing:</p>
<p>If you are flying in from out of town for the AMA training class, we<br />
have an all-inclusive bootcamp style package which includes your flight,<br />
hotel, and breakfast each day for <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis%20All%20Inclusive&amp;item_number=AMAAE&amp;amount=3000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=joe%40strategicsec%2ecom&amp;item_name=Advanced%20Malware%20Analysis%20All%20Inclusive&amp;item_number=AMAAE&amp;amount=3000%2e00&amp;no_shipping=0&amp;no_note=1&amp;currency_code=USD&amp;lc=US&amp;bn=PP%2dBuyNowBF&amp;charset=UTF%2d8']);">$3,000</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/advanced-malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Capability-Based Security Assessment: Emulating Advanced Persistent Threat</title>
		<link>http://strategicsec.com/capabilitybased-security-assessment-emulating-advanced-persistent-threat/</link>
		<comments>http://strategicsec.com/capabilitybased-security-assessment-emulating-advanced-persistent-threat/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 03:08:23 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/</guid>
		<description><![CDATA[If an organization has an information assurance program that is fairly mature then it&#8217;s time to shift focus from identifying and patching security vulnerabilities to the ability to detecting and    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/capabilitybased-security-assessment-emulating-advanced-persistent-threat/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>If an organization has an information assurance program that is  fairly mature then it&#8217;s time to shift focus from identifying and  patching security vulnerabilities to the ability to detecting and  responding to highly skilled hackers attempting to steal intellectual  property, trade secrets, insider information, customer data, and money.</p>
<p>This  type of assessment differs from traditional security assessments in  that the organization is rated by the level of attacker sophistication  it is able to detect and respond to. These types of security assessments  have a lot of value if your Information Assurance program IS mature  because they help organizations determine how effectively they have  utilized their IT Security budget.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/capabilitybased-security-assessment-emulating-advanced-persistent-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking In Hawaii (2 2-Day Pentesting Workshops)</title>
		<link>http://strategicsec.com/services/training-services/classroom/hacking-hawaii-2-2day-pentesting-workshops/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/hacking-hawaii-2-2day-pentesting-workshops/#comments</comments>
		<pubDate>Sun, 05 Jun 2011 02:10:05 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/</guid>
		<description><![CDATA[Workshop 1: Description Crash Course In Pentesting This workshop will cover some of the newer aspects of penetration testing such as Open Source Intelligence Gathering with Maltego and other Open    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/hacking-hawaii-2-2day-pentesting-workshops/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<h1>Workshop 1: Description</h1>
<h2>Crash Course In Pentesting</h2>
<p>This workshop will cover some of the newer aspects of penetration testing such as Open Source Intelligence Gathering with Maltego and other Open Source tools.</p>
<p>Basic Network Scanning, Enumeration, Exploitation (remote and client-side), and Post-Exploitation relying heavily on the features included in the Metasploit Framework will also be covered.</p>
<p>Basic Web Application penetration testing will be covered as well with focus on practical exploitation of sql injection, and cross-site scripting (XSS).</p>
<p>&nbsp;</p>
<p><strong>Workshop 1 Outline</strong></p>
<p><strong>Day 1:</strong></p>
<ul>
<li>Penetration Testing Fundamentals</li>
<li>Scope of Modern Pentests</li>
<li>Compliance Testing (PCI, HIPAA, ISO 27000)</li>
<li>Blackbox vs. Whitebox</li>
<li>Full Scope</li>
<li>The Down &amp; Dirty</li>
<li>Open Source Intelligence (OSINT)</li>
<li>Maltego, and other tools</li>
<li>Scanning</li>
<li>Stealth Scanning Techniques</li>
<li>Scanning from the outside</li>
<li>Scanning from the inside</li>
<li>Enumeration</li>
<li>Host/Network Enumeration</li>
<li>Vulnerability Testing</li>
<li>Using Nessus</li>
<li>Correlating Scan results to public exploits</li>
<li>Owning Boxes for Fun and Profit</li>
<li>Exploitation</li>
<li>Remote Exploits</li>
<li>Post-Exploitation (Old School)</li>
<li>Setting up a workshop</li>
<li>Metasploit (MSF)</li>
<li>MSF Basics</li>
</ul>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Day 2:</strong></p>
<p>&nbsp;</p>
<ul>
<li>Transitioning from Network to Web App Penetration Testing</li>
<li>Similarities &amp; Differences</li>
<li>What Makes up a Web Application Assessment</li>
<li>Web Application Security Threat Classification</li>
<li>OWASP Testing Guide</li>
<li>Injection Vulnerabilities</li>
<li>SQL Injection</li>
<li>Error-based</li>
<li>Platform Specifics</li>
<li>SQL Server (2000/2005)</li>
<li>Abuse of Trust Vulnerabilites</li>
<li>Cross-Site Scripting</li>
</ul>
<h1></h1>
<h1></h1>
<h1>Workshop 2: Description</h1>
<h2>CyberWar: Emulating Advanced Persistent Threat in Pentests</h2>
<p>This workshop will focus on hacker tactics and techniques commonly referred to as Advanced Persistent Threat (APT). Some examples of APT have been the high profile intrusions in companies such as Google, Sony, Lockheed Martin, CitiBank, and too many others to list here. The key thing to note is that all of these companies have robust IT Security programs with patch management, configuration management, network monitoring systems, and intrusion detection systems.</p>
<p>This workshop will focus on attacking and defending highly secured environments<br />
such as 3-letter agencies, DoD, financial organizations, federal organizations, and large companies.</p>
<p>Emphasis throughout the entire workshop will be placed on being as stealthy as possible, and dealing with popular defensive technologies such as:</p>
<ul>
<li>Network Intrusion Detection/Prevention Systems</li>
<li>Host-Based Intrusion Detection/Prevention Systems</li>
<li>Web Application Firewalls</li>
<li>Anti-Virus</li>
<li>Content-Filtering Proxies</li>
<li>Locked Down (Hardened)Workstations</li>
</ul>
<p>Students that are Network/System Administrators with three or more years experience working in environments such as financial institutions, DoD networks, or similar high security environments will benefit greatly from this course.<br />
It is however primarily designed for Network/Web Application Penetration testers that are looking for the little tips and tricks that will help them better attack high security environments.</p>
<p><strong>Workshop 2 Outline</strong></p>
<p><strong>Day 3:</strong></p>
<ul>
<li>Attacking interesting stuff (Oracle &amp; JBoss)</li>
<li>Web App to a command shell (SQL Injection, XSS)</li>
<li>Bypassing Security mechanisms (magic quotes, and ASP.NET Request Validate)</li>
<li>Filter/IDS/Web Application Firewall Evasion (Client-Side Filtering, Alphanumeric Filtering, IDS Signature Evasion, Dealing with Web Application Firewalls)</li>
</ul>
<p>&nbsp;</p>
<p><strong>Day 4:</strong></p>
<p>&nbsp;</p>
<ul>
<li>Bypassing a locked down desktop</li>
<li>Attacking Windows 7</li>
<li>Advanced Network Vulnerability Scanning: Nmap Scripting Engine (NSE), Metasploit Auxiliary Modules</li>
<li>Advanced Network Enumeration: Net Commands, Data-Mining Active Directory</li>
<li>Advanced Post-Exploitation: Pivoting, Persistence</li>
<li>Finding all of a company&#8217;s intellectual property and stealing it</li>
</ul>
<p><strong>Student Requirements:</strong></p>
<p>Each student must bring his own laptop with no less than 2GB of RAM, with a DVD drive, and be running Windows XP/Vista/7 or a recent Linux distribution such as:</p>
<ul>
<li>Fedora</li>
<li>RHEL</li>
<li>Gentoo</li>
<li>Ubuntu</li>
</ul>
<p>Software packages that should be installed prior to attending the workshop are:</p>
<ul>
<li>Metasploit: www.metasploit.com</li>
<li>Nessus: http://nessus.org/download/ (with home feed and all plugins loaded)</li>
<li>Nmap: nmap.org/download.html</li>
<li>VMPlayer: www.vmware.com/products/player/</li>
</ul>
<ul>
<li>Current version of Firefox and the following add-ons:</li>
</ul>
<ul>
<li>Passive Recon:</li>
<li>ShowIP:</li>
<li>ServerSpy:</li>
<li>Tamper Data:</li>
<li>Live HTTP Headers:</li>
<li>AccessMe:</li>
<li>XSSMe:</li>
<li>SQL Inject Me:</li>
<li>Firebug:</li>
</ul>
<h1 style="text-align: left;"></h1>
<h1 style="text-align: left;"></h1>
<h1 style="text-align: left;">Training Dates and Times</h1>
<p>Workshop 1:  Oct 17-18, 2011</p>
<p>Workshop 2:  Oct 19-20, 2011</p>
<p>The training will be held from 8:30am to 4:30pm each day. The class will be broken down into 50 minute sessions, 10 minute breaks, and 1 hour for lunch each day.</p>
<h1 style="text-align: left;"></h1>
<h1 style="text-align: left;">Training Costs With Payment Links</h1>
<p>Workshop 1: $1,000</p>
<p>http://tinyurl.com/HackingHawaii-W1</p>
<p>&nbsp;</p>
<p>Workshop 2: $1,500</p>
<p>http://tinyurl.com/HackingHawaii-W2</p>
<p>&nbsp;</p>
<p>Workshops 1 &amp; 2: $2,000</p>
<p>http://tinyurl.com/HackingHawaii-W1-2</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>College student, ISSA, ISACA, and Infragard member discounts</p>
<p>Workshop 1:  $800</p>
<p>http://tinyurl.com/HackingHawaii-W1WD</p>
<p>Workshop 2:  $1,200</p>
<p>http://tinyurl.com/HackingHawaii-W2WD</p>
<p>Workshops 1 &amp; 2: $1,600</p>
<p>http://tinyurl.com/HackingHawaii-W1-2WD</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h1 style="text-align: left;">Training Location</h1>
<p>The workshops will be held at Hawaii Imin International Conference Center in Honolulu, Hi.</p>
<p>The address is:</p>
<p>1777 East-West Road<br />
Honolulu, Hi 96822</p>
<h1></h1>
<h1></h1>
<h1>About The Course Sponsor SecureDNA</h1>
<p>Secure DNA is a company focused on improving the security of organizations globally.  This focus is exhibited in the commitment to the city and state where we are headquartered by being the primary organizer of Shakacon.  Shakacon is a security conference that brings global security experts and trainers to Hawaii in order to increase the security knowledge of our neighbors.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/hacking-hawaii-2-2day-pentesting-workshops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Development</title>
		<link>http://strategicsec.com/services/training-services/classroom/exploit-development/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/exploit-development/#comments</comments>
		<pubDate>Mon, 23 May 2011 03:32:57 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/</guid>
		<description><![CDATA[Exploit Dev Package Course Description Strategic Security has teamed up with Net-Square to provide the most comprehensive exploit development course package available to the public. Occasionally similar courses are offered    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/exploit-development/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<h1 style="text-align: left;">Exploit Dev Package Course Description</h1>
<p>Strategic Security has teamed up with Net-Square to provide the most comprehensive exploit development course package available to the public. Occasionally similar courses are offered privately to various three letter agencies and large financial institutions.</p>
<p>Exploit development is often considered the most difficult area of focus in the entire field of IT security. It requires both a broad range of skills and deep level of knowledge in Networking, Operating Systems, and Programming. Now you too can learn what has long been thought to be &#8220;Black Magic&#8221; by many from one of the top practitioners and trainers in the world.</p>
<p><strong>How is this course put together?</strong></p>
<p>The course is actually a 2 week package deal designed to both teach the fundamentals of modern exploit development and give the student ample guided practice time with the instructor to actually get proficient.</p>
<p><strong>Benefits:</strong></p>
<ul>
<li>Takes the student from relative beginner in exploit development to writing weaponized exploits against real world applications that run on both 32bit and 64bit architectures and utilize modern exploit mitigations such as DEP, ASLR.</li>
</ul>
<ul>
<li>Is lower priced than other similar courses, and offers much more labs and practice time. The student will learn how to do it instead of just learn about it as in other courses.</li>
</ul>
<ul>
<li>Course is taught by a skilled practitioner, and trainer that is well regarded in the IT Security community.</li>
</ul>
<ul>
<li>Focuses more writing exploits against applications using modern mitigations than other courses.</li>
</ul>
<ul>
<li>Doesn&#8217;t require the student to know Assembly prior to attending the course</li>
</ul>
<h1 style="text-align: left;">Full Course Description &amp; Syllabus</h1>
<p><a title="http://strategicsec.com/Exploit-Dev-Courses-Oct-2011.pdf" href="http://strategicsec.com/Exploit-Dev-Courses-Oct-2011.pdf" >http://strategicsec.com/Exploit-Dev-Courses-Oct-2011.pdf</a> &lt;&#8211; Old course. Will be updated soon.</p>
<h1 style="text-align: left;">Training Dates and Times</h1>
<p>Workshop 1:  Oct 29th &#8211; Nov 2nd, 2012</p>
<p>Workshop 2:  Nov 5th &#8211; Nov 9th, 2012</p>
<p>The training will be held from 8:30am to 4:30pm each day. The class will be broken down into 50 minute sessions, 10 minute breaks, and 1 hour for lunch each day.</p>
<h1 style="text-align: left;">Training Costs (with TinyURL payment links)</h1>
<p>Workshop 1:  $7,000</p>
<p><a title="http://tinyurl.com/SS-EDNAR" href="http://tinyurl.com/SS-EDNAR" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-EDNAR']);">http://tinyurl.com/SS-EDNAR</a></p>
<p>&nbsp;</p>
<p>Workshop 2:  $8,000</p>
<p><a title="http://tinyurl.com/SS-EDTP" href="http://tinyurl.com/SS-EDTP" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-EDTP']);">http://tinyurl.com/SS-EDTP</a></p>
<p>Workshops 1 &amp; 2  $12,500</p>
<p><a title="http://tinyurl.com/SS-EDNAR-TP" href="http://tinyurl.com/SS-EDNAR-TP" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-EDNAR-TP']);">http://tinyurl.com/SS-EDNAR-TP</a></p>
<p>Defense contractor, Active Duty Military, FBI, CIA, Secret Service, College student, ISSA, ISACA, former ACE student, and Infragard member discounts.</p>
<p>Workshop 1:  $5,000</p>
<p><a title="http://tinyurl.com/SS-EDNAR-D" href="http://tinyurl.com/SS-EDNAR-D" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-EDNAR-D']);">http://tinyurl.com/SS-EDNAR-D</a></p>
<p>&nbsp;</p>
<p>Workshop 2:  $6,000</p>
<p><a title="http://tinyurl.com/SS-D-EDTP" href="http://tinyurl.com/SS-D-EDTP" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-D-EDTP']);">http://tinyurl.com/SS-D-EDTP</a></p>
<p>&nbsp;</p>
<p>Workshops 1 &amp; 2  $8,500</p>
<p><a title="http://tinyurl.com/SS-EDNAR-TP-D" href="http://tinyurl.com/SS-EDNAR-TP-D" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://tinyurl.com/SS-EDNAR-TP-D']);">http://tinyurl.com/SS-EDNAR-TP-D</a></p>
<h1 style="text-align: left;"></h1>
<h1 style="text-align: left;">Training Location</h1>
<p>The workshops will be held at &#8220;The Academy of Computer Education&#8221; in Greenbelt, MD.</p>
<p>The address is:</p>
<p>7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770</p>
<h1 style="text-align: center;">About The Instructor</h1>
<p style="text-align: center;"><a href="http://strategicsec.com/wp-content/uploads/2011/05/saumil_photo.jpg" ><img class="size-medium wp-image-620 aligncenter" title="saumil_photo" src="http://strategicsec.com/wp-content/uploads/2011/05/saumil_photo-217x300.jpg" alt="" width="217" height="300" /></a></p>
<p>Saumil Shah is the founder and CEO of Net-Square, providing cutting edge information security services to clients around the globe. Saumil is an internationally recognized speaker and instructor, having regularly presented at conferences like Blackhat, RSA, CanSecWest, PacSec, EUSecWest, Hack.lu, Hack-in-the-box and others. He has authored two books titled &#8220;Web Hacking: Attacks and Defense&#8221; and &#8220;The Anti-Virus Book&#8221;. Before Net-Square, he worked with Foundstone Inc and Ernst &amp; Young in the US, and is currently a guest faculty at the Indian Institute of Management, Ahmedabad for their Management Development Programmes. Saumil graduated with an M.S. in Computer Science from Purdue University, USA and a B.E. in Computer Engineering from Gujarat University. He spends his leisure time traveling around the world and taking pictures.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/exploit-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So You Wanna Be A WebApp Pentester</title>
		<link>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-webapp-pentester/</link>
		<comments>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-webapp-pentester/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 01:17:59 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com</guid>
		<description><![CDATA[Web Application penetration testing will be covered with focus on practical exploitation of cross-site scripting (XSS), cross-site request forgery (CSRF), local/remote file includes, and SQL Injection. - Transitioning from Network    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-webapp-pentester/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Web Application penetration testing will be covered with focus on practical exploitation of cross-site scripting (XSS), cross-site request forgery (CSRF), local/remote file includes, and SQL Injection.</p>
<p>- Transitioning from Network to Web App Penetration Testing<br />
- Similarities &amp; Differences</p>
<p>- What Makes up a Web Application Assessment<br />
- Web Application Security Threat Classification<br />
- OWASP Testing Guide</p>
<p>- Injection Vulnerabilities<br />
- SQL Injection<br />
- Error-based<br />
- Union-based<br />
- True/False Blind<br />
- Time Based Blind</p>
<p>- Platform Specifics<br />
- SQL Server (2000/2005)<br />
- MySQL<br />
- Oracle</p>
<p>- Abuse of Trust Vulnerabilites<br />
- Cross-Site Scripting<br />
- Cross-Site Request Forgery</p>
<p>- File Handling/Redirection Vulnerabilities<br />
- Remote File Includes<br />
- Local File Includes<br />
- File Upload<br />
- Null Byte Injection</p>
<p>- Filter/IDS/Web Application Firewall Evasion<br />
- Client-Side Filtering<br />
- Alphanumeric Filtering<br />
- IDS Signature Evasion<br />
- Dealing with Web Application Firewalls</p>
<p>Joe&#8217;s Web Application Assessment Attack Methodology<br />
- Stepping Through A Web App<br />
- Automated Tools<br />
- Commercial Tools<br />
- Open Source Tools</p>
<p>- Manual Analysis<br />
- How to look at a Web App<br />
- Common Headaches<br />
- Tips &amp; Tricks</p>
<p>- Labs<br />
- HackMe Bank<br />
- MackMe Books<br />
- WebMaven<br />
- WebGoat</p>
<p>Popular Testing Guides &amp; Methodologies<br />
- Can You Use The Open Source Testing Methodology Manual (OSSTMM) for Web App Testing<br />
- Simplifying The OWASP Testing Guide into something managable</p>
<p>When and how to Threat Model<br />
- Popular Methodologies<br />
- Stride vs Dread</p>
<p>Web Application Security Reporting<br />
- Don&#8217;t just hand the scanner results to the customer</p>
<p>Course Prequisites<br />
Students should have some basic familiarity with the following web technologies and<br />
languages:</p>
<p>- HTTP<br />
- HTML<br />
- Javascript<br />
- ASP<br />
- PHP<br />
- SQL</p>
<p>How Is The Course Delivered &amp; What Do You Get<br />
All of the courseware will be delivered in PDF format</p>
<p>- 5 sets of powerpoint slides in PDF format<br />
- 1 document (103 page course document) in PDF format<br />
- 1 web app tools install walkthrough document<br />
- 4 lab documents</p>
<p>Basic tutorial documents (each ranging from 20 &#8211; 50 pages in length)<br />
- HTML<br />
- PHP<br />
- ASP<br />
- CSS<br />
- XML<br />
- SQL</p>
<p>All labs must be performed on your own machine (NOT IN THE STRATEGIC SECURITY LAB NETWORK).<br />
<!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-webapp-pentester/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So You Wanna Be A Pentester</title>
		<link>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-pentester/</link>
		<comments>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-pentester/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 00:43:29 +0000</pubDate>
		<dc:creator>joemccray</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com</guid>
		<description><![CDATA[Description This course will cover some of the newer aspects of penetration testing such as Open Source Intelligence Gathering with Maltego and other Open Source tools. Advanced Scanning, Enumeration, Exploitation    By <a class="link-thin" href="/author/joemccray">joemccray</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-pentester/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en--><strong>Description</strong><br />
This course will cover some of the newer aspects of penetration testing such as Open Source Intelligence Gathering with Maltego and other Open Source tools.</p>
<p>Advanced Scanning, Enumeration, Exploitation (remote and client-side), and Post-Exploitation relying heavily on the features included in the Metasploit Framework will also be covered.</p>
<p>Emphasis throughout the entire workshop will be placed on being as stealthy as possible, and dealing with popular defensive technologies such as:</p>
<p>• Network Intrusion Detection/Prevention Systems</p>
<p>• Host-Based Intrusion Detection/Prevention Systems</p>
<p>• Web Application Firewalls</p>
<p>• Anti-Virus</p>
<p>• Content-Filtering Proxies</p>
<p>Topics</p>
<p>Penetration Testing Fundamentals<br />
- Scope of Modern Pentests<br />
- Compliance Testing (PCI, HIPAA, ISO 27000)<br />
- Blackbox<br />
- Whitebox<br />
- Full Scope</p>
<p>The Down &amp; Dirty<br />
- Open Source Intelligence (OSINT)<br />
- Maltego, and other tools</p>
<p><!--:--> <a href="http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-pentester/#more-512"  class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/so-you-wanna-be-a-pentester/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Penetration Testing</title>
		<link>http://strategicsec.com/services/training-services/classroom/advanced-penetration-testing/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/advanced-penetration-testing/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 11:52:53 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://strategicsec.com/</guid>
		<description><![CDATA[Advanced Penetration Testing (APT): Pentesting High Security Environments course is a five-day intensive that focuses attacking and defending highly secured environments such as 3-letter agencies, DoD, financial organizations, federal organizations,    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/advanced-penetration-testing/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Advanced Penetration Testing (APT): Pentesting High Security Environments course is a five-day intensive that focuses attacking and defending highly secured environments such as 3-letter agencies, DoD, financial organizations, federal organizations, and large companies.</p>
<p>This is NOT your normal Ethical Hacking course. You won&#8217;t be attacking unpatched Windows 2000 Servers, and you won&#8217;t be learning a bunch of outdated tools like most Ethical Hacking courses.</p>
<p>In APT, you will be learning how to attack new operating systems such as Windows Vista, Windows 7, Windows Server 2008, and the latest Linux servers. All of these servers will be patched, and hardened. Both Network and Host-based Intrusion Detection/Preventions systems (IDS/IPS) will be in place as well.<br />
The learning curve is high, but the rewards are astronomical.</p>
<p>The course starts with attacking heavily protected environments from the outside and dealing with things like Load Balancing, Deep Packet Inspection, and Network-Based IDS/IPS. Next is attacking web applications and dealing with common application security measures in PHP/ASP.NET, and Web Application<br />
Firewalls.</p>
<p>Then the course moves on to attacking from the LAN, dealing with NAC solutions, locked down workstations/GPOs, and Host-Based IDS/IPS. Then finally the last section of the course covers gaining control of Active Directory.</p>
<p>Pentesting High Security Environments is NOT a death by powerpoint course. Over 80% of class is hands-on hacking labs.</p>
<p>Students that are Network/System Administrators with three or more years experience working in environments such as financial institutions, DoD networks, or similar high security environments will benefit greatly from this course.<br />
It is however primarily designed for Network/Web Application Penetration testers that are looking for the little tips</p>
<p>and tricks that will help them better attack high security environments.</p>
<p>APT Course Syllabus</p>
<p>Stealth Scanning<br />
1. Bypassing IDS/IPS</p>
<p>Attacking From the Web<br />
1. XSS to command-shell<br />
2. SQL Injection to command-shell<br />
Oracle<br />
3. File Handling to command-shell<br />
File Upload to command-shell<br />
command-shell</p>
<p>Client-Side Pentesting<br />
1. Bypassing Antivirus<br />
Packing Binaries<br />
Modifying Binaries with OllyDBG<br />
Custom Trojans<br />
2. Email Collection &amp; Web Server Setup<br />
3. Pivoting into the LAN</p>
<p>MS-SQL</p>
<p>MySQL</p>
<p>RFI to command-shell</p>
<p>LFI to</p>
<p>Writing</p>
<p>Attacking From the LAN<br />
1. Bypassing Port Security<br />
2. Bypassing NAC Solutions</p>
<p>Breaking out of Restricted Environments<br />
1. Citrix in Kiosk Mode<br />
2. Restricted Desktops<br />
3. Group Policy Object Restricted Applications</p>
<p>Bypassing Network-Based IDS/IPS<br />
1. Enumerating the network<br />
2. Defeating IDS/IPS Signatures</p>
<p>Privilege Escalation</p>
<p>1. Privilege Escalation in Windows XP<br />
2. Privilege Escalation in Windows Vista\Windows 7</p>
<p>Post-Exploitation<br />
1. Remote Command Execution<br />
2. Automating Tasks<br />
3. Enabling RDP/VNC<br />
4. Persistence</p>
<p>Course Instructor<br />
The course instructor is security consultant and trainer Joe McCray. Joe McCray has 10 years of experience in the security industry with a diverse background that includes network and web application penetration testing, incident response, and forensics in the both DoD community and the private sector. Joe is also a frequent<br />
trainer/presenter at security conferences such as Black Hat, Def Con, ToorCon, BruCON, LayerOne, TechnoSecurity, and TechnoForensics.</p>
<p>General Course Info</p>
<p>Course dates are 13th &#8211; 17th December 2010. The course will be comprised of 5 days of 50 minute sessions with 5-10 minute breaks, and an hour for lunch.</p>
<p>Pre-requisites:<br />
Students must be familiar with IT Security best practices, and have a good understanding of TCP/IP and common web technologies.<br />
* Basic Windows administration for both servers and workstations<br />
* Basic Linux/*NIX system administration skill<br />
* Basic command-line proficiency on both Windows and *NIX systems</p>
<p>Students should be familiar with the following web technologies and languages:<br />
* HTML<br />
* Javascript<br />
* ASP<br />
* PHP<br />
* SQL</p>
<p>Students should also be familiar with Metasploit, and VMWare.</p>
<p>* HTTP</p>
<p>Training Location<br />
Academy of Computer Education<br />
7833 Walker Drive, Suite 520C<br />
Greenbelt, Maryland 20770<br />
Phone: (301) 220-2802<br />
Toll-Free: (877) 564-TRAIN</p>
<p><a href="http://www.trainace.com/" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://www.trainace.com/']);">http://www.trainace.com/</a></p>
<p>Pricing $2,500</p>
<p>All software and necessary equipment is provided.</p>
<p>Need a hotel for the week of your class?</p>
<p>For a discounted hotel rate please contact us. ACE has pre-negotiated a discounted stay for APT students in the Greenbelt Hilton Garden Inn.<br />
The Hotel is located approximately 200 yards from the school.</p>
<p>All Inclusive APT Class Pricing:</p>
<p>If you are flying in from out of town for the APT training class, we have an all-inclusive bootcamp style package which includes your flight, hotel, and breakfast each day for $3,500<!--:--><!--:es-->
</p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/advanced-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Terms of Use</title>
		<link>http://strategicsec.com/terms-of-use/</link>
		<comments>http://strategicsec.com/terms-of-use/#comments</comments>
		<pubDate>Mon, 22 Nov 2010 16:31:50 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://204.244.123.113/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/terms-of-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy</title>
		<link>http://strategicsec.com/page-privacy/</link>
		<comments>http://strategicsec.com/page-privacy/#comments</comments>
		<pubDate>Mon, 22 Nov 2010 16:31:05 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://204.244.123.113/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/page-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Case Study 3</title>
		<link>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-3/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-3/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 12:40:30 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Troubled CIO Strategic Security&#8217;s client had recently failed a compliance audit and the newly appointed CIO faced a task list from his CEO that was a mile long with less    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-3/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en--><strong>Troubled CIO</strong></p>
<p>Strategic Security&#8217;s client had recently failed a compliance audit and the newly appointed CIO faced a task list from his CEO that was a mile long with less then one month to complete.</p>
<p>The tasks included:</p>
<p style="padding-left: 30px;">Develop a security awareness training program</p>
<p style="padding-left: 30px;">Develop a secure coding training program for the development team</p>
<p style="padding-left: 30px;">Develop a disaster recovery plan</p>
<p><em><strong>So What????</strong></em></p>
<p style="text-align: justify;">Strategic Security Consultants worked with the entire IT staff (CIO, network admins, system admins, developers, techs, help desk) and HR to develop a full blown Information Assurance Program that far exceeded the initial regulatory compliance concerns.</p>
<p style="text-align: justify;">Now the client&#8217;s IT security budget was aligned with its business goals.</p>
<p style="text-align: justify;">A business continuity plan had been developed.Â  The plan included a business impact assessment, a risk assessment and a disaster recovery plan.Â  Each plan was created in a modular fashion so that the planÂ could be quickly updated.</p>
<p style="text-align: justify;">Old policies and procedures were rewritten; and new ones were developed where applicable. All documents were created in a modular fashion so they could be quickly updated.</p>
<p style="text-align: justify;">A change control board was developed and new processes were put in place to allow the new information assurance program to develop, grow and change as needed.</p>
<p>Of course, they passed their next compliance audit!<!--:--><!--:es--></p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Case Study 2</title>
		<link>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-2/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-2/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 10:01:22 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Major Investment Bank hired Strategic Security for a Web Application Security Assessment The bank had created a portfolio management application that was intended to have several thousand customers accessing it    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-2/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><span style="color: #000000;"><!--:en--></span></p>
<h3 style="text-align: justify;"><span style="color: #000000;">Major Investment Bank hired Strategic Security for a Web Application<strong> Security Assessment</strong></span></h3>
<p style="text-align: justify;"><span style="color: #000000;">The bank had created a portfolio management application that was intended to have several thousand customers accessing it daily. The Strategic Security consultants identified several critical security flaws that could have cost the bank millions of dollars in losses.</span></p>
<p style="text-align: justify;"><em><strong><span style="color: #000000;">So What????</span></strong></em></p>
<p style="text-align: justify;"><span style="color: #000000;">Strategic Security Consultants showed the client how to secure the application source code.</span></p>
<p style="text-align: justify;"><span style="color: #000000;">The client had already wanted to integrate security into their software development lifecycle (SDLC) but really didn&#8217;t know where to start.</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Strategic Security Consultants showed the development team how to fix the flaws in the application.</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Strategic Security Consultants also provided a 4-day secure coding course for the developers and a 1 day building security into your SDLC course for the developers, security group and senior management.</span></p>
<p style="text-align: justify;"><span style="color: #000000;">With Strategic Security&#8217;s help the bank developed a comprehensive Software Security Framework (SSF) that included internal secure development training, automated and manual security testing, secure code metrics which resulted in 41% decrease in security vulnerabilities per 1,000 lines of code written.<!--:--><!--:es--></span></p>
<p><span style="color: #000000;"><!--:--></span></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Case Study 1</title>
		<link>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-1/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-1/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 09:32:11 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Major Hospital hired Strategic Security for a Network Security Assessment The hospital&#8217;s primary concerns were HIPAA compliance and the overall state of IT security. Strategic Security consultants gained access to    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-1/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><!--:en--><strong>Major Hospital hired Strategic Security for a Network Security </strong><strong>Assessment</strong></p>
<p style="text-align: justify;">The hospital&#8217;s primary concerns were HIPAA compliance and the overall state of IT security.</p>
<p style="text-align: justify;">Strategic Security consultants gained access to the their:</p>
<p style="text-align: justify; padding-left: 30px;">Medication tracking &amp; dispensing applications<br />
Patient Medical Records<br />
Administrative control over entire IT infrastructure</p>
<p style="text-align: justify;"><em><strong>So What????</strong></em></p>
<p style="text-align: justify;">Strategic Security Consultants showed the client how to secure the infrastructure at no additional cost:</p>
<p style="text-align: justify;">The client had been trying to request budget for a $60,000 security system.</p>
<p style="text-align: justify;">Strategic Security Consultants showed the client how to gain the same level of security using technology that was already in place.</p>
<p style="text-align: justify;">Strategic Security Consultants provided training to the IT staff to better implement security practices and policies that were already in place.</p>
<p style="text-align: justify;">The hospital used the training they received from Strategic Security to develop and integrate security metrics into their information assurance program allowing them to cut security spending by 21% over the course of the next year while actually increasing security effectiveness.<!--:--><!--:es--></p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sitemap</title>
		<link>http://strategicsec.com/sitemap/</link>
		<comments>http://strategicsec.com/sitemap/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 11:13:41 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/sitemap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategic Consulting</title>
		<link>http://strategicsec.com/services/strategic-consulting/</link>
		<comments>http://strategicsec.com/services/strategic-consulting/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:25:34 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[When your company&#8217;s security needsÂ extend beyond a typical security assessment,Â Strategic Security offers customized Strategic Consulting solutions. Some examples of Strategic Security Consulting Packages are: Capability-Based Security Assessment Security Assessment Ride    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/strategic-consulting/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->When your company&#8217;s security needsÂ extend beyond a typical security assessment,Â Strategic Security offers customized Strategic Consulting solutions.</p>
<p>Some examples of Strategic Security Consulting Packages are:</p>
<ul>
<li>Capability-Based Security Assessment</li>
<li>Security Assessment Ride Along</li>
<li>Incident Response/Forensic Analysis &amp; Security Assessment</li>
<li>Compliance Assistance</li>
</ul>
<p><a title="Capability Based Assessment" href="http://strategicsec.com/capabilitybased-security-assessment-emulating-advanced-persistent-threat/"  target="_self"><strong>Capability-Based Security Assessment (Emulating Advanced Persistent Threat)</strong></a></p>
<p>This type of assessment differs from traditional security assessments in that the organization is rated by the level of attacker sophistication it is able to detect and respond to. These types of security assessments have a lot of value if your Information Assurance program IS mature because they help organizations determine how effectively they have utilized their IT Security budget. Please use the <a title="Contact Us" href="http://strategicsec.com/contact-us"  target="_self">contact-us</a> to request more information about this service.</p>
<p><a title="Security Assessment Ride Along" href="http://strategicsec.com/2010/11/23/get-help-hacking-your-company/"  target="_self" class="broken_link"><strong>Security Assessment Ride Along</strong></a></p>
<p>This type of security assessment is a value added combination of training and the actual assessment. <a href="http://twitter.com/j0emccray" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','http://twitter.com/j0emccray']);" target="_blank">Joe McCray</a> will teach you or your IT staff network or web application penetration  testing in your environment. No more sending your people away for  training and only being able to send one or two people, no more sitting  in a classroom, and no wondering if what youÂ’re learning works in your  environment. Now your organization can build this competency, and  develop this skill-set in house.</p>
<p>This offering is a modular solution allowing the customer to choose  both the scope of the security assessment being performed, and the scope  of the training for the company employees. The customer can choose  between a Network Security Assessment, a Web Application Security  Assessment, a Wireless Security Assessment, or any combination of them.  Please use the <a title="Contact Us" href="http://strategicsec.com/contact-us/"  target="_self">contact-us</a> to request more information about this service.</p>
<p><strong>Incident Response/Forensic Analysis/Training &amp; Security Assessment</strong></p>
<p>Get immediate crisis response. Strategic SecurityÂ’s Emergency Incident Response Team investigates, assesses, and contains security breaches. Strategic SecurityÂ’s Forensic Investigation Team hunts down digital data and provides the investigative expertise and tools to answer your data breach questions. Strategic Security will also provide training to help you and your team understand the techniques to identify, respond to, and recover from both insider and outsider attacks in this in-depth computer forensics course. Please use the <a title="Contact Us" href="http://strategicsec.com/contact-us"  target="_self">contact-us</a> to request more information about this service.</p>
<p><strong>Compliance Assistance</strong></p>
<p>Strategic Security can assist you with regulatory compliance gap analysis (ex: PCI, HIPAA, ISO 27000, etc). Please use the <a title="Contact Us" href="http://strategicsec.com/contact-us"  target="_self">contact-us</a> to request more information about this service.</p>
<p><!--:--><!--:es--></p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/strategic-consulting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conferences</title>
		<link>http://strategicsec.com/services/training-services/conferences/</link>
		<comments>http://strategicsec.com/services/training-services/conferences/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:25:00 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security offers training at several security conferences around the world.]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Strategic Security offers training at several security conferences around the world.<!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/conferences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Classroom</title>
		<link>http://strategicsec.com/services/training-services/classroom/</link>
		<comments>http://strategicsec.com/services/training-services/classroom/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:24:12 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security provides courses for beginners or people trying to get into the field. We also offer advanced courses for security professionals. &#160; Advanced Network Security Architecture (9 Jan 2012)    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/classroom/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Strategic Security provides courses for beginners or people trying to get into the field. We also offer advanced courses for security professionals.</p>
<p>&nbsp;</p>
<p><a title="Advanced Network Security Architecture (9 Jan 2012) in Maryland" href="http://strategicsec.com/services/training-services/classroom/advanced-network-security-architecture-class/" >Advanced Network Security Architecture (9 Jan 2012) in Maryland</a></p>
<p><a title="Advanced Malware Analysis" href="http://strategicsec.com/services/training-services/classroom/advanced-malware-analysis/" >Advanced Malware Analysis (Feb 2012) in Maryland</a></p>
<p><a title="Hacking In Hawaii" href="http://strategicsec.com/services/training-services/classroom/hacking-hawaii-2-2day-pentesting-workshops"  target="_blank">Hacking in Hawaii (Oct 17 &#8211; 20)</a></p>
<p><a title="Exploit Dev" href="http://strategicsec.com/services/training-services/classroom/exploit-development/"  target="_blank">2 Exploit Development Classes (Oct 31 &#8211; 4 Nov &amp; 7 &#8211; 11 Nov) in Maryland</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/classroom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On-Site</title>
		<link>http://strategicsec.com/services/training-services/on-site/</link>
		<comments>http://strategicsec.com/services/training-services/on-site/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:23:32 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Many organizations, agencies, and groups have chosen to host Strategic Security courses at their own facilities. On-Site training provides a substantial cost savings, time benefits, and a safe environment to    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/on-site/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Many organizations, agencies, and groups have chosen to host Strategic Security courses at their own facilities. On-Site training provides a substantial cost savings, time benefits, and a safe environment to discuss sensitive or proprietary issues along with having the training customized to your organization&#8217;s specific needs as well.<!--:--><!--:es-->
</p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/on-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Training</title>
		<link>http://strategicsec.com/services/training-services/online/</link>
		<comments>http://strategicsec.com/services/training-services/online/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:22:55 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security provides courses for beginners or people trying to get into the field as well as advanced courses for security professionals trying to advance their career. All of the    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/online/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Strategic Security provides courses for beginners or people trying to get into the field as well as advanced courses for security professionals trying to advance their career.</p>
<p><strong>All of the online classes come in 3 basic packages:</strong></p>
<p><strong>Level 1:</strong> Courseware, Labs, forums, videos $100<br />
<strong>Level 2:</strong> Live Online (Nights/Weekends) $500<br />
<strong>Level 3:</strong> Live Online (5-Day weekdays) $1500</p>
<h3>Pentesting</h3>
<p><strong>We have 2 major categories of Pentesting classes (Network and Web App).</strong></p>
<p><a href="http://strategicsec.com/services/training-services/online/network-pentester-night-school/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Network Pentester Night School</span></a>  <a href="http://strategicsec.com/services/training-services/online/web-app-pentester-night-school/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Web App Pentester Night School</span></a></p>
<p>&nbsp;</p>
<h3>Defensive</h3>
<p><strong>We have 2 major categories of Defensive classes (Malware Analysis and IDS Signature Writing).</strong></p>
<p><a href="http://strategicsec.com/services/training-services/online/malware-analysis/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Malware Analysis</span></a>  <a href="http://strategicsec.com/services/training-services/online/ids-signature-writing/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">IDS Signature Writing</span></a></p>
<p>&nbsp;</p>
<h3>Scripting</h3>
<p><strong>We have 2 major categories of Scripting classes (Python and Powershell).</strong></p>
<p><a href="http://strategicsec.com/services/training-services/online/python/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Python</span></a>  <a href="http://strategicsec.com/services/training-services/online/powershell/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Powershell</span></a></p>
<p>&nbsp;</p>
<h3>Advanced</h3>
<p><strong>We have 2 major categories of advanced classes (CyberWar and Exploit Development).</strong></p>
<p><a href="http://strategicsec.com/services/training-services/online/cyberwar/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">CyberWar</span></a>  <a href="http://strategicsec.com/services/training-services/online/exploit-development/"  class="su-button su-button-style-1 su-button-class" style="background-color:#1E82A9;border:1px solid #186887;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;" target="_blank"><span style="color:#e9f3f6;padding:8px 19px;font-size:16px;height:16px;line-height:16px;border-top:1px solid #bcdae5;border-radius:5px;text-shadow:-1px -1px 0 #186887;-moz-border-radius:5px;-moz-text-shadow:-1px -1px 0 #186887;-webkit-border-radius:5px;-webkit-text-shadow:-1px -1px 0 #186887;">Exploit Development</span></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Check out the calendar below to see what online courses we have available.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Training Services</title>
		<link>http://strategicsec.com/services/training-services/</link>
		<comments>http://strategicsec.com/services/training-services/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:22:16 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security offers a comprehensive network and application security training curriculum designed to meet the needs of individuals, departments and organizations desiring to develop highly skilled security professionals. Strategic Security    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/training-services/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en-->Strategic Security offers a comprehensive network and application security training curriculum designed to meet the needs of individuals, departments and organizations desiring to develop highly skilled security professionals.</p>
<p>Strategic Security offers online, on-site and class-room led instruction all over the world.</p>
<p>Contact Joe McCray at joe[at]strategicsec[dot]com for pricing.<!--:--><!--:es--></p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/training-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Application Assessment</title>
		<link>http://strategicsec.com/services/assessment-services/mobile-app-assessment/</link>
		<comments>http://strategicsec.com/services/assessment-services/mobile-app-assessment/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:20:58 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Increasing numbers of mobile devices are being used in business, but the measures organizations take to secure the data stored on and accessed by these devices are often inadequate. In    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/assessment-services/mobile-app-assessment/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Increasing numbers of mobile devices are being used in business, but the measures organizations take to secure the data stored on and accessed by these devices are often inadequate. In the same manner as a network attack, or a web application attack an experienced or motivated attacker can take advantage of vulnerabilities and mis-configurations in a mobile application. This can lead to  unauthorized access to the device, privilege escalation, or worse your business critical data.</p>
<p>In a Mobile Security Assessment, Strategic Security conducts an extensive review of your mobile application from the perspective of a malicious hacker and finds the security holes before they can be exploited by hackers.</p>
<p>The Strategic Security difference evaluates business risk aligned with IT security risks and develops a comprehensive action plan.</p>
<p>Having a Mobile Security Assessment performed will allow you to:</p>
<p><strong>Reduce Your Security Costs:</strong></p>
<ul>
<li>Align costs with business risk</li>
<li>Decrease operating expenses and overhead</li>
</ul>
<p><strong>Focus on Your Business Objectives:</strong></p>
<ul>
<li>Measure security risk level and tolerance</li>
<li>Free internal IT staff for other priorities</li>
</ul>
<p><a title="Contact Joe McCray" href="https://strategicsec.com/contact-us"  target="_self" class="broken_link">Contact Joe McCray</a> for a sample Mobile Security Assessment report.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/assessment-services/mobile-app-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Application Security Assessment</title>
		<link>http://strategicsec.com/services/assessment-services/web-application-assessment/</link>
		<comments>http://strategicsec.com/services/assessment-services/web-application-assessment/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:19:57 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[As more organizations utilize the Internet for business and commercial transactions, attackers are focusing on web applications to penetrate corporate security controls. Historically, developers have focused on functionality over security.     By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/assessment-services/web-application-assessment/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><!--:en-->As more organizations utilize the Internet for business and commercial transactions, attackers are focusing on web applications to penetrate corporate security controls. Historically, developers have focused on functionality over security.  The result of a lack of security integration into the software development lifecycle has created unlimited venues for attackers to launch exploits, compromise systems and steal critical information.</p>
<p style="text-align: justify;">In a Web Application Security Assessment, a Strategic Security consultant looks at a web site from the perspective of a malicious hacker and finds the security holes before they can be exploited by hackers or disgruntled employees.</p>
<p>Just like a Network Assessment, having a Web Application Security Assessment performed will allow you to:</p>
<p style="padding-left: 30px;"><strong>Reduce Your Security Costs:</strong></p>
<ul>
<li>Align costs with business risk</li>
<li>Decrease operating expenses and overhead</li>
</ul>
<p style="padding-left: 30px;"><strong>Focus on Your Business Objectives:</strong></p>
<ul>
<li>Measure security risk level and tolerance</li>
<li>Free internal IT staff for other priorities</li>
</ul>
<p>&nbsp;</p>
<p>Strategic Security offers 3 different Web Application Security Assessments:</p>
<p>1. <a title="Quick Look: Web App" href="http//strategicsec.com/services/assessment-services/web-application-assessment/quick-look-web-app/" >Quick Look</a> &#8211; A two (2) day assessment that lets you know if you are on the right track with your website security</p>
<p>2. Standard &#8211; A five (5) day assessment that is very thorough and can be used to show compliance with industry best practices,</p>
<p>3. Custom &#8211; This can be anything from an assessment that includes source code review, to web services, custom protocols and whole lot more.<br title="Contact Joe McCray" /><!--:--><!--:es--></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/assessment-services/web-application-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Security Assessment</title>
		<link>http://strategicsec.com/services/assessment-services/network-assessment/</link>
		<comments>http://strategicsec.com/services/assessment-services/network-assessment/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:18:52 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Gartner estimates that, although fewer than 10% of the attacks on the Internet are targeted against a single company, the financial impact to an individual business of a single successful    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/assessment-services/network-assessment/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Gartner estimates that, although fewer than 10% of the attacks on the Internet are targeted against a single company, the financial impact to an individual business of a single successful targeted attack will be 50 to 100 times greater than the impact of a successful worm or virus event.</p>
<p>An experienced or motivated attacker can take advantage of system vulnerabilities and mis-configurations to gain unauthorized access to the system or other detailed information that can lead to privilege escalation on a critical target. A Network Security Assessment emulates the same process that an attacker would follow to exploit multiple security weaknesses that individually are not critical, but in the aggregate allow an attacker to compromise business-critical data.</p>
<p>In a Network Security Assessment, Strategic Security conducts an extensive review of your network from the perspective of a malicious hacker and finds the security holes before they can be exploited by hackers or disgruntled employees.</p>
<p>The Strategic Security difference evaluates business risk aligned with IT security risks and develops a comprehensive action plan.</p>
<p>Having a Network Security Assessment performed will allow you to:</p>
<p style="padding-left: 30px;"><strong>Reduce Your Security Costs:</strong></p>
<ul>
<li>Align costs with business risk</li>
<li>Decrease operating expenses and overhead</li>
</ul>
<p style="padding-left: 30px;"><strong>Focus on Your Business Objectives:</strong></p>
<ul>
<li>Measure security risk level and tolerance</li>
<li>Free internal IT staff for other priorities</li>
</ul>
<p><a title="Contact Joe McCray" href="/contact-us" target="_self">Contact Joe McCray</a> for a sample Network Security Assessment report.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/assessment-services/network-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Assessment Services</title>
		<link>http://strategicsec.com/services/assessment-services/</link>
		<comments>http://strategicsec.com/services/assessment-services/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:17:27 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[What is a Network Security Assessment? A Network Security Assessment emulates the same process that an attacker would follow to exploit multiple security weaknesses which individually are not critical but    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/assessment-services/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><strong>What is a Network Security Assessment?</strong></p>
<p>A <a href="http://strategicsec.com/services/assessment-services/network-assessment"  target="_self">Network Security Assessment</a> emulates the same process that an attacker would follow to exploit multiple security weaknesses which individually are not critical but in aggregate allow an attacker to compromise business-critical data.</p>
<p>An experienced or motivated attacker can take advantage of system vulnerabilities and mis-configurations to gain unauthorized access.Â  This access may be exploitedÂ to attain further detailed information which may be used to escalate privileges on a critical target and potentially compromise additional systems.</p>
<p><strong>How Does A Network Security Assessment Differ From A Web Application Security Assessment?</strong></p>
<p>As more organizations utilize the Internet for business and commercial transactions, attackers are targeting web applications in order to penetrate corporate security controls.Â  Historically, developers have focused on functionality over security. This lack of attention towards integrating security into the development process presents an entirely new venue for attackers to launch exploits and compromise systems.</p>
<p>In a <a href="http://strategicsec.com/services/assessment-services/web-application-assessment"  target="_self">Web Application Security Assessment</a>, Strategic Security inspectsÂ a web site from the perspective of a malicious hacker and identifies the security weaknesses so that remediations can be made to circumventÂ exploitation by hackers or disgruntled employees.</p>
<p><strong><br />
</strong></p>
<p><strong>What is a Mobile Application Security Assessment?</strong></p>
<p>Increasing numbers of mobile devices are being used in business, but   the measures organizations take to secure the data stored on and   accessed by these devices are often inadequate. In the same manner as a   network attack, or a web application attack an experienced or motivated   attacker can take advantage of vulnerabilities and mis-configurations  in  a mobile application.</p>
<p>In a <a title="Mobile Application Security Assessment" href="http://strategicsec.com/services/assessment-services/mobile-app-assessment/"  target="_self">Mobile Security Assessment</a>, Strategic Security conducts an   extensive review of your mobile application from the perspective of a   malicious hacker and finds the security holes before they can be   exploited by hackers.</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/assessment-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Testimonials</title>
		<link>http://strategicsec.com/strategic-security-difference-2/testimonials/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/testimonials/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 22:16:50 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[“Joe is a dynamic and experienced professional who goes the extra mile to get the job done. He brings a strong skill set and unwavering dedication to his engagements. He    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/testimonials/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p style="text-align: left;"><!--:en-->“Joe is a dynamic and experienced professional who goes the extra mile to get the job done. He brings a strong skill set and unwavering dedication to his engagements. He can be counted upon to provide excellent results. I would not hesitate to hire Joe again.”<br />
<em>Director of Information Security</em><br />
Multi-Billion Dollar Investment Bank</p>
<p>&#8220;I love how Joe translates Geekenese to English. He really has a unique ability to make business sense out of complex technological problems.&#8221;<br />
<em>Network Manager</em><br />
Major Law Firm</p>
<p>&#8220;Not only did Joe identify our security issues, he showed us how to improve our security posture and save money doing it! Joe is a wizard with security budgets.&#8221;<br />
<em>IT Director</em><br />
Major Las Vegas Hotel &amp; Casino<!--:--><!--:es--></p>
<p>&#8220;This guy Joe McCray is by far the most amazing security guy I&#8217;ve ever met.<br />
In one week he revamped and streamlined our whole IT Security program and saved us a ton of money. He just makes it look too easy!&#8221;<br />
<em>IT Security Manager</em><br />
Large Retail Chain</p>
<p>&#8220;We hired a big four firm last year, and this year we hired Strategic Security.<br />
The difference was amazing. They did nearly triple the work in half the time at nearly half the cost! We changed our policy of switching IT Security companies each year because of Joe McCray.&#8221;<br />
<em>IT Directory</em><br />
Financial Services Firm</p>
<p>&#8220;Joe&#8217;s team was great. They gave us training that really helped our team get up to speed with secure software development.&#8221;<br />
<em>Lead Developer</em><br />
Software Development Company</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/testimonials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Case Studies</title>
		<link>http://strategicsec.com/strategic-security-difference-2/case-studies/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/case-studies/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 20:15:56 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[We are problem solvers, and security assessment services are just part of the tool set we use to diagnose problems. Take a look at a few of our case studies    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/case-studies/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>We are problem solvers, and security assessment services are just part of the tool set we use to diagnose problems. Take a look at a few of our case studies to get an idea of how we work with clients.</p>
<p><a href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-1"  target="_self">Case Study 1</a></p>
<p><a href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-2"  target="_self">Case Study 2</a></p>
<p><a href="http://strategicsec.com/strategic-security-difference-2/case-studies/case-study-3"  target="_self">Case Study 3</a></p>
<p><!--:--></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/case-studies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome to Strategic Security</title>
		<link>http://strategicsec.com/welcome-to-strategic-security-inc/</link>
		<comments>http://strategicsec.com/welcome-to-strategic-security-inc/#comments</comments>
		<pubDate>Tue, 16 Nov 2010 09:57:24 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/?p=226</guid>
		<description><![CDATA[Strategic Security is an Information Technology (IT) Security consulting firm that provides in-depth technical security assessments of your networks or web applications, regulatory compliance gap analysis (ex: PCI, HIPAA, ISO    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/welcome-to-strategic-security-inc/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p><!--:en--><img class="alignleft front-post-img" title="Strategic Security, Inc. - Front Page - Post Image" alt="Strategic Security, Inc. - Front Page - Post Image" src="http://wp-theme-dev.it-gnoth.de/wp-content/themes/strategicsecurity/images/people_standing.png" width="341" height="231" /></p>
<p>Strategic Security is an Information Technology (IT) Security consulting firm that provides in-depth technical security assessments of your networks or web applications, regulatory compliance gap analysis (ex: PCI, HIPAA, ISO 27000, etc), guidance on integrating security into your software development life cycle, building an enterprise security program, and much more.</p>
<p>Although these services are offered by most security consulting firms, implementing and maintaining an effective information security management practices involves more than just security testing and compliance. Today’s organizations must first identify how they use information to meet their strategic business goals and then determine the best ways to protect their information assets throughout the information security life cycle.</p>
<p>Strategic Security’s highly skilled practitioners employ tremendous skill in the areas of penetration testing and compliance auditing, but the real skill – the real value Strategic Security brings to the table is the ability to understand our client’s business vision, mission, goals and strategic business objectives. By assessing our client’s enterprise security posture, we can effectively ensure that critical security areas are aligned with organizational business objectives taking into account associated business risks and reducing operating expenses. We welcome you to browse the website. Please read the <a title="case studies" href="../strategic-security-difference-2/case-studies/" target="_self">case studies</a>, <a title="testimonials" href="../strategic-security-difference-2/testimonials/" target="_self">testimonials</a>, and feel free to <a title="contact us" href="http://strategicsec.com/about-us/contact-us/" >contact us</a> for more information including references, work samples. More importantly, if your organization is interested in learning more about  how Strategic Security can help achieve your business goals while ensuring that your company’s security is aligned with them, <a title="contact us" href="http://strategicsec.com/about-us/contact-us/" >contact us</a> today.<!--:--><!--:es--></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/welcome-to-strategic-security-inc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About Us</title>
		<link>http://strategicsec.com/about-us/</link>
		<comments>http://strategicsec.com/about-us/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 18:33:30 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[[end_tabset]]]></description>
				<content:encoded><![CDATA[<p>[end_tabset]</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/about-us/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Resources</title>
		<link>http://strategicsec.com/resources/</link>
		<comments>http://strategicsec.com/resources/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 18:33:14 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security Advanced Pentesting Lab Network Data Collector]]></description>
				<content:encoded><![CDATA[<ul>
<li><a title="Strategic Security Advanced Pentesting Lab Network" href="http://strategicsec.com/strategic-security-advanced-pentesting-lab-network/" >Strategic Security Advanced Pentesting Lab Network</a></li>
<li>Data Collector</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blog</title>
		<link>http://strategicsec.com/blog/</link>
		<comments>http://strategicsec.com/blog/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 18:32:56 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Videos</title>
		<link>http://strategicsec.com/videos/</link>
		<comments>http://strategicsec.com/videos/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 18:32:39 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[<p style="text-align: center;"><iframe src="http://www.youtube.com/embed/qBVThFwdYTc" height="315" width="600" allowfullscreen="" frameborder="0"></iframe></p>
<p></br></br></p>
<p style="text-align: center;"><iframe src="http://www.youtube.com/embed/rdyQoUNeXSg" height="315" width="600" allowfullscreen="" frameborder="0"></iframe></p>
<p></br></br></p>
<p style="text-align: center;"><iframe src="http://www.youtube.com/embed/wZ-b8qe7M8I" height="315" width="600" allowfullscreen="" frameborder="0"></iframe></p>
<p></br></br></p>
<p style="text-align: center;"><iframe src="http://www.youtube.com/embed/lujbS0lPGUw" height="315" width="600" allowfullscreen="" frameborder="0"></iframe></p>
<p></br></br></p>
<p style="text-align: center;"><iframe src="http://www.youtube.com/embed/_HDVwxjtKnw" height="315" width="600" allowfullscreen="" frameborder="0"></iframe></p>
<p></br></br></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/videos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategic Security Difference</title>
		<link>http://strategicsec.com/strategic-security-difference-2/</link>
		<comments>http://strategicsec.com/strategic-security-difference-2/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 20:31:36 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/</guid>
		<description><![CDATA[Strategic Security helps clients solve security challenges facing their environments through Strategic Consulting, technology consulting, education or a combination of all three. Our Professional Services team balances the benefits of    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/strategic-security-difference-2/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>Strategic Security helps clients solve security challenges facing their environments through Strategic Consulting, technology consulting, education or a combination of all three.</p>
<p style="text-align: justify;">Our Professional Services team balances the benefits of strategic consulting with a tactical, hands-on approach to technology consulting and security training to help customers mitigate and manage the digital security risks inherent in doing business today.</p>
<p>See what our customers are saying about us:</p>
<p><a href="http://strategicsec.com/strategic-security-difference-2/case-studies"  target="_self">Case Studies</a></p>
<p><a href="http://strategicsec.com/strategic-security-difference-2/testimonials"  target="_self">Testimonials</a></p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/strategic-security-difference-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Services</title>
		<link>http://strategicsec.com/services/</link>
		<comments>http://strategicsec.com/services/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 22:23:56 +0000</pubDate>
		<dc:creator>webdeveloper</dc:creator>
		
		<guid isPermaLink="false">http://wp-theme-dev.it-gnoth.de/about/</guid>
		<description><![CDATA[The complexity of modern enterprises and the increased inter-connectivity among organizations create widespread opportunities for theft, fraud, and other forms of exploitation by offenders both outside and inside an organization.    By <a class="link-thin" href="/author/webdeveloper">webdeveloper</a> <a class="link-thin" href="http://strategicsec.com/services/"> [More ...]</a>]]></description>
				<content:encoded><![CDATA[<p>The complexity of modern enterprises and the increased inter-connectivity among organizations create widespread opportunities for theft, fraud, and other forms of exploitation by offenders both outside and inside an organization. Attackers, both internal and external, are scanning your network looking for vulnerabilities to exploit. Even if your network is protected by firewalls, anti-virus software and intrusion-detection systems, your IT assets are still at risk of being attacked by network security threats that can enter through undetected or uncorrected vulnerabilities.</p>
<p>Strategic Security provides in-depth technical security assessments of your network, web application, and regulatory compliance gap analysis. We also provide guidance on integrating security into your software development life-cycle, developing an enterprise information assurance program, and much more…</p>
<p>Strategic Security helps organizations identify how they use information to meet their strategic business goals; then determine the best ways to protect their information assets throughout the information security life-cycle.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://strategicsec.com/services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
