<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security for a day &#187; Study</title>
	<atom:link href="http://www.chris-mohan.com/category/study/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chris-mohan.com</link>
	<description>Securing Windows networks or giving it a go in Australia...</description>
	<lastBuildDate>Sat, 31 Dec 2011 12:54:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Off to be a CISM, a wonderful CISM of ISACA</title>
		<link>http://www.chris-mohan.com/2011/09/off-to-be-a-cism-a-wonder-cism-of-isaca/</link>
		<comments>http://www.chris-mohan.com/2011/09/off-to-be-a-cism-a-wonder-cism-of-isaca/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 07:06:16 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Exams]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=911</guid>
		<description><![CDATA[Okay, if you swap the words out of the song for the Wizards of Oz with the title of this post it sort of works. Thought I&#8217;d give taking ISACA&#8217;s Certified Information Security Manager (CISM) certification a go given the large amount of non-IT literate business people I&#8217;ve been dealing with needing careful hand holding when [...]]]></description>
			<content:encoded><![CDATA[<p>Okay, if you swap the words out of the song for the Wizards of Oz with the title of this post it sort of works.</p>
<p>Thought I&#8217;d give taking ISACA&#8217;s <a title="Certified Information Security Manager (CISM) certification" href="http://www.isaca.org/Certification/CISM-Certified-Information-Security-Manager/What-is-CISM/Pages/default.aspx" target="_blank">Certified Information Security Manager (CISM)</a> certification a go given the large amount of non-IT literate business people I&#8217;ve been dealing with needing careful hand holding when it comes to providing security to their operations. These people know their business operations inside and out until it&#8217;s connected to a computer and then it suddenly a black box of mystery.</p>
<p>As part of service to the business we (IT security folk) learn their language, terms and requirements but some business owners seem disinterested in even attempting the understanding the fundamentals of something that&#8217;s now critical to their business survival. Is it a simple fear of the unknown or the fear of being mocked for asking someone to explain something they have no understanding of ? Business-crippling IT stories are now filtering into the popular mainstream media, as a few examples:  <a title="IT admin cops to crippling ex-employer's network" href="http://www.theregister.co.uk/2011/08/17/it_admin_revenge/" target="_blank">administrators going mad</a> and faceless people attacking companies from the far side of the world, <a title="4800 Aussie sites evaporate after hack " href="http://www.smh.com.au/technology/security/4800-aussie-sites-evaporate-after-hack-20110621-1gd1h.html" target="_blank">deleting their web sites</a> and even the very IT security aware companies losing their <a title="GlobalSign stops secure certificates after hack claim" href="http://www.bbc.co.uk/news/technology-14819257" target="_blank">critical data</a>.</p>
<p>If it makes the business folk feel as if I&#8217;m approachable without me having an MBA, seems an easy step to take to help breach that gap.</p>
<p>I&#8217;m booked in for the 10 December 2011 exam in Sydney, so better get on with some study.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2011/09/off-to-be-a-cism-a-wonder-cism-of-isaca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful Web sites for Study</title>
		<link>http://www.chris-mohan.com/2010/12/useful-web-sites-for-study/</link>
		<comments>http://www.chris-mohan.com/2010/12/useful-web-sites-for-study/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 05:52:41 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Exams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=784</guid>
		<description><![CDATA[Oops, left this sitting in drafts rather than publish this last month. Some useful web sites I use to keep me up to date and  help out studying Security and all things SANS. The SANS Reading Room www.sans.org/reading_room/ The Honeypot Challenges www.honeynet.org/challenges The Ethical Hacker www.ethicalhacker.net Pauldotcom http://pauldotcom.com/wiki/index.php/Main_Page Darkreading room www.darkreading.com SANS forensic blog http://computer-forensics.sans.org/ [...]]]></description>
			<content:encoded><![CDATA[<p>Oops, left this sitting in drafts rather than publish this last month.</p>
<p>Some useful web sites I use to keep me up to date and  help out studying Security and all things SANS.</p>
<p>The SANS Reading Room <a href="http://www.sans.org/reading_room/">www.sans.org/reading_room/</a><br />
The Honeypot Challenges <a href="http://www.honeynet.org/challenges">www.honeynet.org/challenges</a><br />
The Ethical Hacker <a href="http://www.ethicalhacker.net">www.ethicalhacker.net</a><br />
Pauldotcom <a href="http://pauldotcom.com/wiki/index.php/Main_Page">http://pauldotcom.com/wiki/index.php/Main_Page</a></p>
<p>Darkreading room <a href="http://www.darkreading.com">www.darkreading.com</a><br />
SANS forensic blog <a href="http://computer-forensics.sans.org/">http://computer-forensics.sans.org/</a></p>
<p>Metasploit unleased <a href="http://www.offensive-security.com/metasploit-unleashed/Metasploit_Unleashed_Information_Security_Training">www.offensive-security.com/metasploit-unleashed/Metasploit_Unleashed_Information_Security_Training</a><br />
Internet Storm Center <a href="http://isc.sans.edu/index.html">http://isc.sans.edu/index.html</a><br />
Security Tube <a href="http://www.securitytube.net">www.securitytube.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/12/useful-web-sites-for-study/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Additional GSE study material</title>
		<link>http://www.chris-mohan.com/2010/10/additional-gse-study-material/</link>
		<comments>http://www.chris-mohan.com/2010/10/additional-gse-study-material/#comments</comments>
		<pubDate>Sat, 09 Oct 2010 12:47:26 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[GSE]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/2010/10/additional-gse-study-material/</guid>
		<description><![CDATA[Here&#8217;s a list of some of the additional material I used to on top of the SANS courseware. I used these as a jump off point to understand some more in-depth points Books: Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide by Laura Chappell Extrusion Detection by Richard Bejtlich A Practical Guide [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a list of some of the additional material I used to on top of the SANS courseware. I used these as a jump off point to understand some more in-depth points
</p>
<p>Books:
</p>
<p><span style="font-family:Verdana; font-size:9pt">Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide by Laura Chappell<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">Extrusion Detection by Richard Bejtlich<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">A Practical Guide to Fedora and Red Hat Enterprise Linux – Fifth Edition by Mark G. Sobell<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">Unix and Linux System Administration Handbook – Forth Edition by Evi Nemeth,<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">Attack Detection and Response with iptables, psad, and fwsnort by Michael Rash,<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">NMap Scanning by Gordon &#8220;Fyodor&#8221; Lyon<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">The Hacking Exposed series<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">Counter Hack reloaded by <span style="color:black">Ed Skoudis</span><br />
		</span></p>
<p><span style="font-family:Verdana; font-size:9pt">The Hacker&#8217;s Challenge series<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">SQL Injection Attacks and defense by Justin Clarke<br />
</span></p>
<p><span style="font-family:Verdana; font-size:9pt">Sherlock Homes by Sir Arthur Conan Doyle<br />
</span></p>
<p><a href="http://hakin9.org/"><span style="font-family:Verdana; font-size:9pt">Hackin9 magazines</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/10/additional-gse-study-material/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Preparing for the GSE multiple choice written exam</title>
		<link>http://www.chris-mohan.com/2010/10/preparing-for-the-gse-multiple-choice-written-exam/</link>
		<comments>http://www.chris-mohan.com/2010/10/preparing-for-the-gse-multiple-choice-written-exam/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 08:42:49 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Exams]]></category>
		<category><![CDATA[GSE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=717</guid>
		<description><![CDATA[My approach to the multiple choice exam, was to treat it like any normal 500 level SANS exam. My target – life-, work- and proctor-willing, is to take the exam on Saturday the 20th March 2010; which is exactly 42 days from now. As we all know 42 is the mean of Life or is that [...]]]></description>
			<content:encoded><![CDATA[<p>My approach to the multiple choice exam, was to treat it like any normal 500 level SANS exam.</p>
<p>My target – life-, work- and proctor-willing, is to take the exam on Saturday the 20<sup>th</sup> March 2010; which is exactly 42 days from now. As we all know 42 is the mean of Life or is that just a spooky coincidence?</p>
<p>I’m going to use an individual index system of each of the 3 courseware (401, 503 and 504). I have a brand new, lined A4 wire bound note book in which I’m handwriting the index of each book.</p>
<p>My goal is to have the 503 books indexed in seven days, then 504 indexed in seven days followed by the monstrous 401 fully indexed in ten days.</p>
<p>The rationale behind this is</p>
<p>1)      To make me read each page of each book and work out if that page should be indexed</p>
<p>2)      To make me read and think about each topic on the page</p>
<p>3)      For me to make side notes on tools, topics or subjects that are unclear</p>
<p>4)      I want to retain and use the knowledge for the practical exam</p>
<p>5)      I like using pen and paper</p>
<p>To make sure I don’t become just book smart, I plan to also run through the practical questions and exercises throughout the courseware books.</p>
<p>I been pretty active with hands on training from studying and passing SANS <a title="SANS 501" href="http://www.sans.org/security-training/advanced-security-essentials-enterprise-defender-1102-mid" target="_blank">Advanced Security Essentials – Enterprise Defender</a> (SEC501) and Offensive Security’s <a href="http://www.offensive-security.com/penetration-testing-backtrack-online-training.php">Pentesting with Backtrack</a>, but intend to use some of the following sites to keep sharp:</p>
<p>Pauldotcom’s links to challenges, tools and a variety of other madness <a href="http://www.pauldotcom.com/wiki/index.php/Main_Page">http://www.pauldotcom.com/wiki/index.php/Main_Page</a> and not to mention actually listening to the podcast</p>
<p>The web site of the three Spanish GSE <a href="http://www.radajo.com/">http://www.radajo.com/</a> they set a huge benchmark to reach</p>
<p>The internet storm centre for what’s going down in the real world <a href="http://isc.sans.org/">http://isc.sans.org/</a></p>
<p>The ethical hacker forums can post up some interesting links to other challenges <a href="http://www.ethicalhacker.net/">http://www.ethicalhacker.net/</a></p>
<p>Ed Skoudis and friends various devious, mind-twisting and nefarious challenges <a href="http://www.counterhack.net/Counter_Hack/Challenges.html">http://www.counterhack.net/Counter_Hack/Challenges.html</a></p>
<p>Mr Skoudis and friends again with command line kung fu in all shapes and flavours  <a href="http://blog.commandlinekungfu.com/">http://blog.commandlinekungfu.com/</a></p>
<p>Laura Chappell is always fantastic for packets and wireshark <a href="http://laurachappell.blogspot.com/">http://laurachappell.blogspot.com/</a></p>
<p>Richard Bejtlich still pops up some great snort and packet stuff despite being a boss now <img src='http://www.chris-mohan.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  <em><a href="http://taosecurity.blogspot.com/" target="_blank">http://taosecurity.blogspot.com</a></em></p>
<p><em>The SANS reading room for a brilliant reading resource and new ideas </em><a href="http://www.sans.org/reading_room/">http://www.sans.org/reading_room/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/10/preparing-for-the-gse-multiple-choice-written-exam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Indexing and how can it help me for the open book exams?</title>
		<link>http://www.chris-mohan.com/2010/10/what-is-indexing-and-how-can-it-help-me-for-the-open-book-exams/</link>
		<comments>http://www.chris-mohan.com/2010/10/what-is-indexing-and-how-can-it-help-me-for-the-open-book-exams/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 08:32:58 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[GSE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=719</guid>
		<description><![CDATA[Quick word on indexing for SANS exams. SANS exams are open book, this means you can refer to the books at any point during the exam. In fact you can refer to any paper notes during the exam, only electronic notes are disallowed. Time is the enemy in open book exams, as spending too much [...]]]></description>
			<content:encoded><![CDATA[<p>Quick word on indexing for SANS exams.</p>
<p>SANS exams are open book, this means you can refer to the books at any point during the exam. In fact you can refer to any paper notes during the exam, only electronic notes are disallowed. Time is the enemy in open book exams, as spending too much time flipping pages or jumping between books looking for an answer slows you down horribly, eating away at the precious seconds.</p>
<p>The way I use indexing is to jog my memory and note tools, processes, concepts and the like next to the page number it appears on.</p>
<p>I only have page entries when I need to recall something on that page. This saves time when during an exam as I can to jump straight to a reference.</p>
<p>Using a lined book I put down the page number, the title of the page and some key words or details. These details may be a formula, port numbers someone&#8217;s name or command line syntax.</p>
<p>At the top of each page I have the course and book number as a title.</p>
<p>As an example</p>
<p>503 Day 2</p>
<p>P99 TCPdump commands -F \location (tcpdump filter expression in a file) -s 0capture full packet -X display in hex&amp; ascii</p>
<p>P130 filter for weird stuff in IP source and dest fieldsIP[12:4] != 127.0.01 and IP[16:4] != 10.10.10.10</p>
<p>Post-it tags can also be very help to mark out section full of tables as another form of reference for quick jump to sections.</p>
<p>As an side, my tutor for 503 was <a title="The legend that is Mike Poor" href="http://www.sans.org/security-training/instructors.php#Poor" target="_blank">Mike Poor</a>. As I read through the 503 pages making notes, I have him on the iPod. This unfortunately means I unconsciously use him as a narrator for my study notes. Even some of his jokes have started to appear in the notes&#8230;. I think I may know some of his stories better than him now <img src='http://www.chris-mohan.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/10/what-is-indexing-and-how-can-it-help-me-for-the-open-book-exams/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why use old tools in the GSE?</title>
		<link>http://www.chris-mohan.com/2010/10/why-use-old-tools-in-the-gse/</link>
		<comments>http://www.chris-mohan.com/2010/10/why-use-old-tools-in-the-gse/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 08:28:47 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[GSE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=721</guid>
		<description><![CDATA[A great question was posted to one of the SANS’ lists on the practical requirements I felt it was worth while publishing as it covers and answers a question I though about but never asked. The Question: I&#8217;ve just had a quick look at the site you link to and would be interested to know [...]]]></description>
			<content:encoded><![CDATA[<p>A great question was posted to one of the SANS’ lists on the <a href="http://www.giac.org/certifications/gse.php">practical requirements</a></p>
<p>I felt it was worth while publishing as it covers and answers a question I though about but never asked.</p>
<p>The Question:</p>
<p>I&#8217;ve just had a quick look at the site you link to and would be interested to know why this was chosen as the attack platform:</p>
<p>&lt;quote&gt;</p>
<p>* Backtrack version 4</p>
<p>* Fedora Core 12</p>
<p>* Windows  Server</p>
<p>To ensure a level playing field for all candidates, you will not be permitted to use any pre-installed favourite tools that you may have on your laptop. To complete the exercises you must exclusively use the tools and virtual machines provided by GIAC. Failure to comply will result in dismissal from the examination.</p>
<p>&lt;/quote&gt;</p>
<p>What does this prove, that you are a pen-tester from 4 years ago (BT1 released May 26, 2006)?</p>
<p>Surely if this exam is meant to show that you have current skills then it should allow you to use current tools.</p>
<p>A great response came back from Mark Baggett, one of the most recently minted GSE.</p>
<p>Mark’s response:</p>
<p>I think of it more like &#8220;Hey McGuyver, here is your paperclip and bubble gum, now dodge this.&#8221;</p>
<p>I found the old tools added VMWare compatibility complications to the test.</p>
<p>Having newer tools would have been nice. (or not deviating from the system requirements, no matter how smart I thought I was)  That said, the compatibility problems I experienced added to the &#8220;pressure cooker&#8221; which I think is part of it.  Also, I don&#8217;t think that being able to attack ms08-067 requires a different skill set than ms04-011.  Certainly pen-testing has changed a bit since then, but the GSE covers 504 <strong>not 560</strong>.  All aspects of pen-testing are not part of this.  A very solid understanding of the fundamentals of an attack are required.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/10/why-use-old-tools-in-the-gse/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The GSE Practical Exam 2010</title>
		<link>http://www.chris-mohan.com/2010/09/the-gse-practical-exam-2010/</link>
		<comments>http://www.chris-mohan.com/2010/09/the-gse-practical-exam-2010/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 08:44:44 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Exams]]></category>
		<category><![CDATA[GSE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/2010/09/the-gse-practical-exam-2010/</guid>
		<description><![CDATA[Months of waiting, debating about what might occur, what they may ask, what would be required and the occasional bits of study all came to a head on Saturday the 19th of September 2010, in Caesar&#8217;s Palace, Las Vegas, Nevada in the United States of America. I got there two days before, in a vague [...]]]></description>
			<content:encoded><![CDATA[<p>Months of waiting, debating about what might occur, what they may ask, what would be required and the occasional bits of study all came to a head on Saturday the 19<sup>th</sup> of September 2010, in Caesar&#8217;s Palace, Las Vegas, Nevada in the United States of America.</p>
<p>I got there two days before, in a vague attempt to shake off any jet lag effects and to get into the Vegas flow. Nice idea, but the execution failed abysmally. It may have been due to the excited anticipation, nerves or the simple desire to get on with it, take the damnable thing and have done with it. Meeting up with two other GSE candidates, who&#8217;d also arrived early, only proved how much the three of us had no idea what was really going to happen over the two days. Many of my personal thoughts stretched from the ridiculous that it would just be the practice examples from the three courses in the books, to some mix of the Bourne movies, involving being hunted, tortured and escaping all while having to set up Snort alerts and using Netcat to defeat the bad guys.</p>
<p>The only thing I really knew was that it was two days for testing taken from the SANS courses of 401, 503 and 504 and that the ring leader of this circus, Jeff Pike, was a man of mystery. Mr Pike cruelly tantalised us with brief emails, each of which gave a tiny hint on what was going to happen at the exam. My over-active imagination pictured Jeff as a classic Bond evil mastermind villain, sitting in his high-backed leather chair, cackling &#8211; in an evil mastermind way &#8211; flipping switches labeled Doom, Pain, Mayhem and Café-latte Decaf with a twist of hazelnut and lemon. I&#8217;d imagine him ordering his minions to stop feeding the sharks, set the booby traps and prepare for the would-be GSEs.</p>
<p>Anyway, away from ramblings of my deluded mind, Saturday morning 8am arrived. Caesars Palace&#8217;s huge Italian styled hallways of its conference centre and archway entrance to the exam room, did nothing to detract from the imagined Herculean tasks ahead.</p>
<p>The architect of my fears over the last few months, Jeff Pike was sitting at the head of the room, bathed in the glow of reflected laptop screens arrayed around him. Looking up, he saw me entering the room in a natty, and very fashionable, grey linen suit, hair flowing heroically with forced, nonchalant bring-it-on grin slapped on my face. In a freakish fast motion he was up and striding towards me.</p>
<p>Cue dramatic, sweeping music and fade to black.</p>
<h2 style="text-align: center;">The GSE Practical Exam</h2>
<p>I&#8217;m not going to comment on what the exam contained over the two days. The GSE practical exam subject matter is laid out on the web site, so take your cues from there.</p>
<p>Nine people took the exam; a very mixed bunch of skills, experiences and job roles. I knew each of them from traded emails, sneaky peaks at LinkedIn profiles, blogs, postings and some from the books they had written. I took a small comfort that the group, as a whole, seemed pretty nervous.</p>
<p>I will say that the GSE exam is split in to four, four hour sessions over the two days and it&#8217;s about using the skills and knowledge learnt in the three SANS course to deal with real world scenarios in a compressed time frame. It&#8217;s not just a &#8220;do you know it and how to do it&#8221;, but &#8220;can you do it&#8221; in the time allocated. Jeff or a proctor (Charles, in the case) is in the room at all times and there to answer any question on the exam or help with any odd problems that pop up. There is no group presentation objective any more, which was a bit disappointing, so the entire GSE exam is a solo effort.</p>
<p>You need to have a laptop that runs VMWare images, has over 2GB of RAM and you have full admin rights over. It shouldn&#8217;t, much to my embarrassment, be massively locked down and specially harden. That caused one or two problems, which I really didn&#8217;t need during the exam as you will be connected to a segmented network at some point. Basically bring a basic patched OS that just simply works on, is pretty much set to all defaults and you could happily format once you&#8217;ve finished the exam – should you want to.</p>
<p>You can bring in up to a suit case worth of written material and have access to the internet from a couple of isolated laptops to refer to at any point during the exam. It&#8217;s pretty fitting to have access to notes and the web as it&#8217;s only very rare cases I&#8217;ve been locked in a room without some form of reference. I had every cheat sheet under the sun, a copy of security Fedora 12 and my Don&#8217;t Panic –a guide to the GSE. This is a booklet I&#8217;d created when recording all the crazy tests, examples, exercises, trivia, trials and tribulations from the testing I&#8217;d put myself through over the last few months.</p>
<p>Once I broke through the initial nerves, I really started to enjoy the exam. Some parts I flew through and other parts I want to throw the laptop through the wall. Some parts completely stumped me and others left me grinning like a Cheshire cat, but I worked through each and double checked what I could. After the first day ended, we were all wired and still energized. I chatted with a couple of the guys on way back to the hotel on how they approach the objectives on the way, just to understand what approach they had taken. Around 2am, I snapped awake and realised I&#8217;d cocked up a response. Sleep didn&#8217;t come easy after that.</p>
<p>I want to say the second day was calmer, as we knew the level of testing to be expected. There was definitely a buzz of excitement and anticipation going in to the exam, as we&#8217;d discussed a number of guesses what was going to be tested on. Again, a day of highs and lows, with parts I felt I sail through on the Sea of Easy and those that sank me on the rough Seas of What the Heck and the fatal jagged rocks of WTF. Jeff Frisk, Director of GIAC, sent in a trolley full of cold beers and dips in the last hour of the second day&#8217;s exam. I couldn&#8217;t work out if it was some weird form of mental torture, in order to apply a final piece of pressure in that precious hour.</p>
<p>After time was called and exam was ended, the mixed look of relief, frustration, reflection, puzzlement, excitement and sheer pleasure just to be finally done was on the group&#8217;s faces. We all took a long drink, shook hands, rolled out eyes at the questions and answer given. A group of SANS instructors, Jeff Frisk, and current GSE magically appeared to offer their congratulations for taking the exam and making it to the end -and steal a beer or two. Jeff Pike had one final joke to spring on us. The results of the GSE would not be reviled until after 30 days once we&#8217;d completed the exam. With the large number of people taking the exam they need to triple check our answers with multiple reviewers and confirm if we passed enough questions successfully. Each of the sections is marked separately, as they demonstrate different knowledge and skills. I guess you need to reach a base score in each section to hit the pass mark of the GSE, as it&#8217;s a pass or fail exam with no scoring revealed. I&#8217;m not sure if that&#8217;s a good or bad thing, but it&#8217;s just the way of the world.</p>
<h2 style="text-align: center;">Should You Attempt the GSE?</h2>
<p>If you have the <a href="http://www.giac.org/certifications/gse.php">exam skills</a> and <a href="http://www.giac.org/certifications/gse.php">qualification requirements</a>, then it&#8217;s simple. <a href="https://www.sans.org/registration/register.php?conferenceid=1251&amp;assessment_only=3092"><strong>Book the exam</strong><br />
<strong>now</strong></a>. The exam is hard but fair, very real world based and uses from the knowledge and skills of the three courses. No annoyingly vague or trivia based knowledge questions appeared, but you <strong>have</strong> to be good under pressure and able to work to deadlines.</p>
<p>If you can respond to an event or incident, analysis the information and present your findings clearly while working to a strict time line, you should take the GSE. The test and objectives flowed well and was in a very logical format, but allowed for personal styles to work in their own fashion to present their answers. If you are a well-rounded security professional, being comfortable with completing the exercises in any of the three SANS courses and smart enough to read into the hints on the GSE requirements, plus be able to clearly communicate findings on to paper, take the GSE.</p>
<p>To me the GSE qualification is about challenging myself to prove I &#8216;m able to stand shoulder to shoulder with my peers; a virtual marathon or mountain to climb, if you will. Finishing or the view from the top is amazing, but the determination, effort and sheer grit to attempt such a goal in the first place is worth of admiration and a nod respect for trying to improve yourself from your peers. I&#8217;ve been lucky enough to sit in classes with skilled classmates, talked to brilliant people in hallways and worked with amazing fellow workplace facilitators who could easily be in the next round of GSE candidates if they want to be. All it takes is making the financial and mental commitment to sign up. It is a good chunk of money and time, but doesn&#8217;t anything worth achieving have a price?</p>
<h2 style="text-align: center;">More Suggestions on GSE preparation</h2>
<p>My top tip is not to attempt the exam with jet lag. At one point I thought the room went green and at several stages I swear objects started moving by themselves. Really.</p>
<ol>
<li><strong>Find someone to study with and bounce questions off</strong>. This really helps as you get to look at differing ideas and directions. I occasionally get stuck in one particular direction and mindset which means I fail to grasp the meaning, question or objective without spending a lot more time the really necessary.</li>
<li><strong>Mentor or teach others</strong>. The SANS mentor program is a heck of a way to get a better understanding the SANS material and help others to learn security, it also makes you read related subjects and topics. Even if you don&#8217;t lead any SANS training, do security talks at local user group meetings, help a friend or colleague pass and exam or even just explain to your parents how to stay safe online. Create a couple of security awareness programs at work, one for the technical and one of the non-technical staff.</li>
<li><strong>Read good quality blogs and books</strong>. When researching GSE objectives and topics, I spent quite a bit of time searching the web for decent examples. I&#8217;m sure no-one is amazed to read that there&#8217;s a huge amount of poorly written, ill-informed and just plain wrong pieces out there.</li>
<li><strong>Watch good webcasts or recorded sessions</strong>. I&#8217;m quite slow sometimes and watching someone perform the steps in front of me, with the ability to stop pause and rewind, means I can grasp the information a lot faster.</li>
<li><strong>Ask others</strong>. There are some wonderful people out there that actually answer questions, even when it&#8217;s a complete stranger. I had some responses from book authors, security royalty, and well informed normal security guys and girls, none of which knew anything about me but freely and very generously spend time answering questions or correcting misperceptions.</li>
<li><strong>Review Jeff Pike&#8217;s presentation on GSE: facts, rumours and myths -</strong> Sadly, this didn&#8217;t get recorded so all the abuse he gave me will remain in that Vegas room <img src='http://www.chris-mohan.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  The slides from that day are <a title="GSE facts, rumours and myths ppt" href="http://www.giac.org/certifications/GSE_20101103.pdf" target="_blank">here</a> and worth a look.</li>
</ol>
<h2 style="text-align: center;">Final Thoughts</h2>
<p>Whether I pass or fail the GSE, it&#8217;s been an amazing experience. I&#8217;ve learnt diverse materials and skills, much more than my current job role requires, even in areas I simply have no current requirement for. As I&#8217;ve mentioned before, we have a couple of *Nix systems out of thousands of Windows systems, but none of what I&#8217;ve studied, practiced and now learnt will go to waste. The other GSE candidates are normal, very smart and motivated people who are true security professionals. I&#8217;m proud and humbled to have attempted the same exam as them. I still have a have a long way to go before I&#8217;d ever <em>think</em> of calling myself a security expert, but I now know I can cope, handle and deal with real security incidents in a professional manner under pressure and others watchful eyes. The GSE would be a seal of approve and validation from <a href="http://www.giac.org/overview/statement.php">GIAC</a> that I can do this and an excellent affirmation of the teaching skills and abilities of my SANS instructors.</p>
<h3>Do I think I&#8217;ve passed?</h3>
<p>I&#8217;ll tell you in thirty days.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/09/the-gse-practical-exam-2010/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>GSE – Last week before the off</title>
		<link>http://www.chris-mohan.com/2010/09/gse-%e2%80%93-last-week-before-the-off/</link>
		<comments>http://www.chris-mohan.com/2010/09/gse-%e2%80%93-last-week-before-the-off/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 13:10:14 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[GSE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/2010/09/gse-%e2%80%93-last-week-before-the-off/</guid>
		<description><![CDATA[Now in the week of the GSE exam, how did that happen so quickly? I know of another six people take are taking the GSE in Las Vegas, so the biggest group of GSE candidates, to date, all in one room and hungry for the SANS platinum qualification. Well, except for me &#8211; I&#8217;m really [...]]]></description>
			<content:encoded><![CDATA[<p>Now in the week of the GSE exam, how did that happen so quickly?
</p>
<p>I know of another six people take are taking the GSE in Las Vegas, so the biggest group of GSE candidates, to date, all in one room and hungry for the SANS platinum qualification.
</p>
<p>Well, except for me &#8211; I&#8217;m really there for the sandwiches and to take in a Tom Jones show. These months of prep have all been a cover for that. Apparently, it&#8217;s not unusual….
</p>
<p>I&#8217;ve talked to a couple the GSE candidates about the exam and we got a similar theory on how the exam is going to play out. The current GSE&#8217;s have given away nothing other than &#8220;know your stuff&#8221; I think that&#8217;s a Zen mindset you reach, either than or they want everyone else to go through the same pain are them.
</p>
<p>I&#8217;m sitting here running through some exercises on getting <a href="http://www.gnupg.org/documentation/">GPG</a> to do securing stuff and watching <a href="http://www.imdb.com/title/tt0082198/">Conan the Barbarian</a> The only reason I&#8217;m doing this is a) GPG and me have don&#8217;t get on as well as I like and b)<a href="http://ericjhuber.blogspot.com/"> Eric Huber</a> put the thought in to my overly crammed and easily confused head via a supportive Conan-esk tweet.
</p>
<p>Thankfully the web is full of quick start guides on GPG <a href="http://www.madboa.com/geek/gpg-quickstart/">using this one</a>. I&#8217;ve set up my BT4 and Fedora 12 machines to pass files over in a secured manner while evil BT3 machine is capturing the traffic and trying to steal the &#8216;top secret&#8217; information of top Conan quotes.
</p>
<p>Oddly enough, going over this has made me flash back to the SANS 560 course and it all started making sense. Or it could be the fact Conan has just punched out a camel. That sometime happens in Canberra too.
</p>
<p>I&#8217;ll just run through a few more exercises to lock in the basic principles again and update my notes. The lovely folk at Fedora have straight forward steps to <a href="http://fedoraproject.org/wiki/DocsProject/UsingGpg/CreatingKeys">protect GPG keys</a>, so that the next thing I&#8217;ll be playing with. At no point will I attempt any strange posturing with make believe swords during the typing of gpg commands. Crom!
</p>
<p>
 </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/09/gse-%e2%80%93-last-week-before-the-off/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Blundering on the CLI</title>
		<link>http://www.chris-mohan.com/2010/08/blundering-on-the-cli/</link>
		<comments>http://www.chris-mohan.com/2010/08/blundering-on-the-cli/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 13:19:49 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/2010/08/blundering-on-the-cli/</guid>
		<description><![CDATA[Much to my own amusement, I&#8217;m still crashing around Linux like the proverbial bull in a china shop. One of the odd things about working in an OS that you hardly ever use is there&#8217;s no &#8220;where is everything and how do I use it&#8221; button. Google brings up fifty ways to do the same [...]]]></description>
			<content:encoded><![CDATA[<p>Much to my own amusement, I&#8217;m still crashing around Linux like the proverbial bull in a china shop.
</p>
<p>One of the odd things about working in an OS that you hardly ever use is there&#8217;s no &#8220;where is everything and how do I use it&#8221; button. Google brings up fifty ways to do the same thing, yet the syntax doesn&#8217;t quite work. I&#8217;m pretty sure most of the learned *Nix folks would be shaking their heads at the blundering of a Windows Admin in their home turf.
</p>
<p>Thank goodness for the &#8220;revert to snapshot&#8221; button on in VMware workstation for when I download every piece of software for no real reason and stuff up a perfectly working environment.
</p>
<p>Let me give you an example.
</p>
<p>One of the objectives in the GSE is a simple netcat relay followed by lots of weird and twisted relays, then shove shell back to you with the lovely # prompt.
</p>
<p>Normally this is easy, jump on to the final box type in nc –l –p 80 –e /bin/sh. Not on Fedora, which doen&#8217;t like the -l and –p being run together. So nc –l 80 –e /bin/sh then?
</p>
<p>No – Fedora&#8217;s default installed out of the box netcat stops the evil <span style="color:black">shenanigans of the –e excution command. Oops, so you have to go and get then install another version of netcat, such as the original written by the Hobbit (make netcat, as along as long as there&#8217;s a complier on the box) which is on all Ed Skoudis&#8217; SANS course materials or pulled download socat or one its friends.<br />
</span></p>
<p><span style="color:black">Then using –e to shove a shell works tricks works fine.<br />
</span></p>
<p><span style="color:black">Okay, so different OS have different versions of applications, but surely we could keep command syntax similar? Apparently not.<br />
</span></p>
<p><span style="color:black">I decided to reach out for a bit of help and guidance, in the form of what books to read. The two I settled on were both recommendations by people in the know:<br />
</span></p>
<p><a href="http://www.amazon.com/Practical-Guide-Fedora-Enterprise-Linux/dp/0137060882">A Practical Guide to Fedora and Red Hat Enterprise Linux &#8211; Fifth Edition</a><span style="color:black"> by Mark G. Sobell.<br />
</span></p>
<p><span style="color:black">It&#8217;s all about Fedora 12, which is the subject of the current GSE Linux tests. Very solid and clear layout, comprehensively covering the features of Fedora and its syntax proving excellent examples<br />
</span></p>
<p><a href="http://www.amazon.com/UNIX-Linux-System-Administration-Handbook/dp/0131480057/">Unix and Linux System Administration Handbook &#8211; Forth Edition</a><span style="color:black"> by Evi Nemeth, Garth Snyder, Trent Hein and Ben Whaley.<br />
</span></p>
<p><span style="color:black">This one was recommended by <a href="https://twitter.com/hal_pomeranz">Hal_Pomeranz</a></span>,  who wrote the <a href="http://www.sans.org/security-training/securing-linux-unix-76-mid">SANS Linux 506 track</a>, after I hassled him on twitter. This one goes covers many flavours of Linux and Unix, but it&#8217;s a marvelous journey through a SysAdmin approach to using *nix, making it a surprisingly easy read.
</p>
<p>I don&#8217;t expect either book will make me a super admin over the next few weeks, but they go a great way to make me feel somewhat more at home and relaxed in Linux, rather than feeling like I just broken in to someone&#8217;s place and set fire to it.
</p>
<p>
 </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/08/blundering-on-the-cli/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>31 days to the GSE Exam</title>
		<link>http://www.chris-mohan.com/2010/08/31-days-to-the-gse-exam/</link>
		<comments>http://www.chris-mohan.com/2010/08/31-days-to-the-gse-exam/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 12:48:10 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[GSE]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=697</guid>
		<description><![CDATA[31 days to the GSE Exam and counting down. The 18th of September is D-Day and I have to make it through to some point in the evening of the 19th, surviving what ever the fiendish SANS team have to throw at me at Caesars Palace in Las Vegas. I still have a giant pile [...]]]></description>
			<content:encoded><![CDATA[<p>31 days to the GSE Exam and counting down.</p>
<p>The 18th of September is D-Day and I have to make it through to some point in the evening of the 19th, surviving what ever the fiendish SANS team have to throw at me at Caesars Palace in Las Vegas.</p>
<p>I still have a giant pile of books next to my bed read through and plenty of hands of exercises to drill tools, techniques and best practices in to what ever space I have left in my brain.</p>
<p>Just when the GSE exam ends, the main event of <a title="SANS Network Security 2010" href="http://www.sans.org/network-security-2010/" target="_blank">SANS Network Security 2010</a> kicks off on the 20th. 41 different SANS tracks are running, meaning a huge number of security professionals there to learn, understand and have a great time. Seems so unfair, so much to learn and so little time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/08/31-days-to-the-gse-exam/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

