<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Free IT Security Training</title>
	<atom:link href="http://www.freeitsecuritytraining.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.freeitsecuritytraining.com</link>
	<description>Community-supported free training resource</description>
	<pubDate>Mon, 14 Jul 2008 14:09:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>OpenFISMA.org</title>
		<link>http://www.freeitsecuritytraining.com/2008/07/14/openfismaorg/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/07/14/openfismaorg/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 14:09:00 +0000</pubDate>
		<dc:creator>jliford</dc:creator>
		
		<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=35</guid>
		<description><![CDATA[
The OpenFISMA project is an open source application designed to reduce the complexity and automate the regulatory requirements of the Federal Information Security Management Act (FISMA) and the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). While many security managers are eager to demonstrate their best practices for incident response, patch management, [...]]]></description>
			<content:encoded><![CDATA[<div style="-moz-initial;">
<p>The <strong>OpenFISMA</strong> project is an <a class="external text" title="http://en.wikipedia.org/wiki/Open_source_software" rel="nofollow" href="http://en.wikipedia.org/wiki/Open_source_software">open source</a> application designed to reduce the complexity and automate the regulatory requirements of the <a class="external text" title="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002" rel="nofollow" href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002">Federal Information Security Management Act (FISMA)</a> and the National Institute of Standards and Technology (NIST) <a class="external text" title="http://csrc.nist.gov/groups/SMA/fisma/framework.html" rel="nofollow" href="http://csrc.nist.gov/groups/SMA/fisma/framework.html">Risk Management Framework (RMF)</a>. While many security managers are eager to demonstrate their best practices for incident response, patch management, and configuration management, they are overwhelmed with the reporting and documentation requirements of FISMA. You can <a class="external text" title="https://sourceforge.net/project/showfiles.php?group_id=208522" rel="nofollow" href="https://sourceforge.net/project/showfiles.php?group_id=208522">download</a> our released software right away or peruse the current <a title="Documentation" href="http://www.openfisma.org/mw/index.php?title=Documentation">documentation</a>.</p>
<p>OpenFISMA is built on the Zend Framework which is an open source, object oriented, web application framework with a flexible architecture. ZF is often referred to as a &#8216;component library&#8217; because it has many loosely coupled components that you can use more or less independently. However, Zend Framework also provides a core <a class="external text" title="http://en.wikipedia.org/wiki/Model-view-controller" rel="nofollow" href="http://en.wikipedia.org/wiki/Model-view-controller">model-view-controller</a> (MVC) implementation that you can use to provide basic &#8216;best practices&#8217; structure to web applications.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/07/14/openfismaorg/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Templora Provides a Tutorial on Basic PHP Script Security</title>
		<link>http://www.freeitsecuritytraining.com/2008/06/07/templora-provides-a-tutorial-on-basic-php-script-security/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/06/07/templora-provides-a-tutorial-on-basic-php-script-security/#comments</comments>
		<pubDate>Sat, 07 Jun 2008 20:52:53 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=34</guid>
		<description><![CDATA[Templora provides a tutorial on &#8220;Basic PHP Script Security.&#8221;
http://templora.com/content/14
Topics covered include:
SQL Injection
XSS Attacks
CSRF Attacks
PHP variable insertion
Input Validation
]]></description>
			<content:encoded><![CDATA[<p>Templora provides a tutorial on &#8220;Basic PHP Script Security.&#8221;</p>
<p><a href="http://templora.com/content/14">http://templora.com/content/14</a></p>
<p>Topics covered include:<br />
SQL Injection<br />
XSS Attacks<br />
CSRF Attacks<br />
PHP variable insertion<br />
Input Validation</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/06/07/templora-provides-a-tutorial-on-basic-php-script-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Several Computer Forensics Training Resources</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/30/several-computer-forensics-training-resources/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/30/several-computer-forensics-training-resources/#comments</comments>
		<pubDate>Fri, 30 May 2008 19:39:26 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=33</guid>
		<description><![CDATA[Dan Dickerman from the IRS Criminal Investigation, Electronic Crimes Program, provided several presentations on computer forensics topics:
Advanced Data Carving
Advanced Data Carving: New Directions in Data Carving Techniques
Using VMWare in Digital Forensic Investigations
RAID Rebuilding
Unfortunately, these slides don&#8217;t include Dan&#8217;s narration, but they&#8217;re detailed enough that you can get a good understanding of each topic on your [...]]]></description>
			<content:encoded><![CDATA[<p>Dan Dickerman from the IRS Criminal Investigation, Electronic Crimes Program, provided several presentations on computer forensics topics:</p>
<p><span style="text-decoration: underline;"><span style="color: #0000ff;"><a href="http://sandbox.dfrws.org/2006/dickerman/Dickerman%20DFRWS%202006%20Challenge%20Final%20Submission.pdf">Advanced Data Carving</a></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #0000ff;"><a href="http://www.techsec.com/TF-2006-PDF/TF-2006-DanDickerman-Advanced%20Data%20Carving.pdf">Advanced Data Carving: New Directions in Data Carving Techniques</a></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #800080;"><a href="http://www.cthtcia.org/documents/2007%20Connecticut%20Chapter%20HTCIA%20VMWare%20Presentation.ppt">Using VMWare in Digital Forensic Investigations</a></span></span></p>
<p><a href="http://www.techsec.com/pdf/Wednesday/RAID%20Rebuilding%20-%20Dickerman.pdf">RAID Rebuilding</a></p>
<p>Unfortunately, these slides don&#8217;t include Dan&#8217;s narration, but they&#8217;re detailed enough that you can get a good understanding of each topic on your own.  Any remaining questions are a simple task for <a href="http://www.google.com">Google</a>.</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/30/several-computer-forensics-training-resources/feed/</wfw:commentRss>
		</item>
		<item>
		<title>CERT.org offers the First Responders Guide to Computer Forensics: Advanced Topics</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/30/certorg-offers-the-first-responders-guide-to-computer-forensics-advanced-topics/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/30/certorg-offers-the-first-responders-guide-to-computer-forensics-advanced-topics/#comments</comments>
		<pubDate>Fri, 30 May 2008 19:13:15 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Papers]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=32</guid>
		<description><![CDATA[CERT.org offers an advanced guide to computer forensics: 

First Responders Guide to Computer Forensics: Advanced Topics
They cover log file analysis, Microsoft Log Parser, running processes, automated process collection, and many other topics.

 
]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000000;">CERT.org offers an advanced guide to computer forensics:<span style="color: #000000;"> </p>
<p></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #800080;"><a href="http://www.cert.org/archive/pdf/05hb003.pdf">First Responders Guide to Computer Forensics: Advanced Topics</a></span></span></p>
<p>They cover log file analysis, Microsoft Log Parser, running processes, automated process collection, and many other topics.</p>
<p><a href="http://www.cert.org/archive/pdf/05hb003.pdf"></a></p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/30/certorg-offers-the-first-responders-guide-to-computer-forensics-advanced-topics/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A Guide to Basic Computer Forensics by Microsoft</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/30/a-guide-to-basic-computer-forensics-by-microsoft/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/30/a-guide-to-basic-computer-forensics-by-microsoft/#comments</comments>
		<pubDate>Fri, 30 May 2008 18:59:07 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Papers]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=31</guid>
		<description><![CDATA[Microsoft provides A Guide to Basic Computer Forensics for free.
This article also mentions:
The Fundamental Computer Investigation Guide for Windows
The Malware Removal Starter Kit
 
]]></description>
			<content:encoded><![CDATA[<p>Microsoft provides <a href="http://technet.microsoft.com/en-us/magazine/cc137738.aspx">A Guide to Basic Computer Forensics</a> for free.</p>
<p>This article also mentions:<br />
<a href="http://go.microsoft.com/fwlink/?LinkId=80344">The Fundamental Computer Investigation Guide for Windows</a><br />
<a href="http://go.microsoft.com/fwlink/?LinkId=93103">The Malware Removal Starter Kit</a></p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/30/a-guide-to-basic-computer-forensics-by-microsoft/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Submit Training Requests</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/11/submit-training-requests/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/11/submit-training-requests/#comments</comments>
		<pubDate>Sun, 11 May 2008 15:03:25 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=30</guid>
		<description><![CDATA[If you have a request for specific types of training, please feel free to send me an email.  I&#8217;ll try to find it for you.
-Scott (scott@freeitsecuritytraining.com)
]]></description>
			<content:encoded><![CDATA[<p>If you have a request for specific types of training, please feel free to send me an email.  I&#8217;ll try to find it for you.<br />
-Scott (scott@freeitsecuritytraining.com)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/11/submit-training-requests/feed/</wfw:commentRss>
		</item>
		<item>
		<title>We Have a LinkedIn Group!</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/06/free-it-security-training-linkedin-group/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/06/free-it-security-training-linkedin-group/#comments</comments>
		<pubDate>Tue, 06 May 2008 19:32:47 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=29</guid>
		<description><![CDATA[If you have an account on LinkedIn, you can join the FreeITSecurityTraining LinkedIn group.
Thanks for all your support!
-Scott (scott@freeitsecuritytraining.com)
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="float: right;" src="http://www.freeitsecuritytraining.com/content/FreeITSecurityTraining.jpg" alt="FreeITSecurityTraining.com" width="100" height="50" />If you have an account on LinkedIn, you can join the <a href="http://www.linkedin.com/e/gis/99845/15985C0764A1" target="_blank">FreeITSecurityTraining LinkedIn group</a>.</p>
<p>Thanks for all your support!</p>
<p>-Scott (<a href="mailto:scott@freeitsecuritytraining.com">scott@freeitsecuritytraining.com</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/06/free-it-security-training-linkedin-group/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Academy Provides Free IT Security Training Videos</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/05/the-academy-provides-free-it-security-training-videos/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/05/the-academy-provides-free-it-security-training-videos/#comments</comments>
		<pubDate>Tue, 06 May 2008 03:36:22 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=28</guid>
		<description><![CDATA[I just stumbled upon a great video training resource: The Academy
They have a nice collection of security videos including:
IronPort (Anti-Spam)
Sophos (Anti-Virus)
AccessData (Forensics)
Nessus, Nmap, Netcat, Metasploit, Cain &#38; Abel (Vulnerability Assessment / Penetration Testing)
GIAC Systems and Network Auditor (GSNA)
]]></description>
			<content:encoded><![CDATA[<p>I just stumbled upon a great video training resource: <a href="http://www.theacademy.ca/" target="_blank">The Academy</a></p>
<p>They have a nice collection of security videos including:<img class="alignright" style="float: right;" src="http://www.freeitsecuritytraining.com/content/TheAcademy.png" alt="The Academy" width="100" height="50" /><br />
IronPort (Anti-Spam)<br />
Sophos (Anti-Virus)<br />
AccessData (Forensics)<br />
Nessus, Nmap, Netcat, Metasploit, Cain &amp; Abel (Vulnerability Assessment / Penetration Testing)<br />
GIAC Systems and Network Auditor (GSNA)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/05/the-academy-provides-free-it-security-training-videos/feed/</wfw:commentRss>
		</item>
		<item>
		<title>CramSession Offers CISSP Study Tips and More</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/04/cramsession-offers-cissp-study-tips-and-more/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/04/cramsession-offers-cissp-study-tips-and-more/#comments</comments>
		<pubDate>Mon, 05 May 2008 01:38:50 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Test Info]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=27</guid>
		<description><![CDATA[CramSession offers CISSP study tips, what you need to know when you&#8217;re going to take the exam, and information about the CISSP exam itself.
*Update*
CramSession also  offers a free CISSP exam study guide courtesy of PrepLogic.
You have two options to receive it:
1) Download the study guide directly
or
2) Sign up for a free CramSession account (or [...]]]></description>
			<content:encoded><![CDATA[<p>CramSession offers <a href="http://www.cramsession.com/articles/files/certified-information-sys-9222003-1219.asp" target="_blank">CISSP study tips</a>, <a href="http://www.cramsession.com/articles/files/certified-information-sys-9222003-1216.asp" target="_blank">what you need to know</a> when you&#8217;re going to take the exam, and information about the <a href="http://www.cramsession.com/certifications/isc2/cissp.asp" target="_blank">CISSP exam</a> itself.</p>
<p>*Update*</p>
<p>CramSession also  offers a free CISSP exam study guide courtesy of PrepLogic.</p>
<p>You have two options to receive it:</p>
<p>1) <a href="https://www.cramsession.com/commerce/dmd/default.aspx?lk=1575-FDEHBCFA-1352-A8998912" target="_blank">Download the study guide directly<br />
</a>or<a href="https://www.cramsession.com/commerce/dmd/default.aspx?lk=1575-FDEHBCFA-1352-A8998912" target="_blank"><br />
</a>2) Sign up for a free CramSession account (or use <a href="http://www.bugmenot.com/view/cramsession.com" target="_blank">BugMeNot</a> to avoid the compulsory registration) and <a href="http://www.cramsession.com/certifications/studyguides/free_studyguides.asp?product_ID=1575" target="_blank">download the CISSP training</a> after clicking &#8216;not interested&#8217; to all their sponsor sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/04/cramsession-offers-cissp-study-tips-and-more/feed/</wfw:commentRss>
		</item>
		<item>
		<title>milw0rm Offers Free Security Videos and Papers</title>
		<link>http://www.freeitsecuritytraining.com/2008/05/01/milw0rm-offers-free-security-videos-and-papers/</link>
		<comments>http://www.freeitsecuritytraining.com/2008/05/01/milw0rm-offers-free-security-videos-and-papers/#comments</comments>
		<pubDate>Fri, 02 May 2008 02:41:54 +0000</pubDate>
		<dc:creator>scott</dc:creator>
		
		<category><![CDATA[Papers]]></category>

		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.freeitsecuritytraining.com/?p=26</guid>
		<description><![CDATA[milw0rm.com hosts many security-related videos and papers for free:
[Papers]
Lateral SQL Injection: A New Class of Vulnerability in Oracle
Security Implications of Windows Access Tokens
802.11 Attacks
[Videos]
Packet sniffing with Ettercap (arp spoofing basics)
Anonymous Voice Vlan Hack
How to Make Files Undetected by AVs
Howto using aircrack-ptw WEP cracking tool
Advanced Mysql Injection in Joomla
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.milw0rm.com/" target="_blank">milw0rm.com</a> hosts many security-related videos and papers for free:</p>
<p><a href="http://www.milw0rm.com/papers/" target="_blank">[Papers]</a><br />
Lateral SQL Injection: A New Class of Vulnerability in Oracle<br />
Security Implications of Windows Access Tokens<br />
802.11 Attacks</p>
<p><a href="http://www.milw0rm.com/video/" target="_blank">[Videos]</a><br />
Packet sniffing with Ettercap (arp spoofing basics)<br />
Anonymous Voice Vlan Hack<br />
How to Make Files Undetected by AVs<br />
Howto using aircrack-ptw WEP cracking tool<br />
Advanced Mysql Injection in Joomla</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freeitsecuritytraining.com/2008/05/01/milw0rm-offers-free-security-videos-and-papers/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
