<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security for a day</title>
	<atom:link href="http://www.chris-mohan.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chris-mohan.com</link>
	<description>As every passing second brings a new perception to security</description>
	<lastBuildDate>Thu, 18 Apr 2013 13:38:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>WordPress Password Attacks for the last few days IP addresses</title>
		<link>http://www.chris-mohan.com/2013/04/wordpress-password-attacks-for-the-last-few-days-ip-addresses/</link>
		<comments>http://www.chris-mohan.com/2013/04/wordpress-password-attacks-for-the-last-few-days-ip-addresses/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 13:36:45 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Real world]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=1001</guid>
		<description><![CDATA[There&#8217;s been a number of news stories on mass password guessing attacks on WordPress sites &#8211; none of which is anything new or exciting. The possibility some of these attacks are being done by a large botnet has seemed to shaken &#8230; <a href="http://www.chris-mohan.com/2013/04/wordpress-password-attacks-for-the-last-few-days-ip-addresses/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>There&#8217;s been a number of news stories on mass password guessing attacks on WordPress sites &#8211; none of which is anything new or exciting. The possibility some of these attacks are being done by a large botnet has seemed to shaken some folks.</p>
<p><a href="http://blog.hostgator.com/2013/04/11/global-wordpress-brute-force-flood/">http://blog.hostgator.com/2013/04/11/global-wordpress-brute-force-flood/</a></p>
<p><a href="http://blog.sucuri.net/2013/04/mass-wordpress-brute-force-attacks-myth-or-reality.html">http://blog.sucuri.net/2013/04/mass-wordpress-brute-force-attacks-myth-or-reality.html</a></p>
<p><a href="http://krebsonsecurity.com/2013/04/brute-force-attacks-build-wordpress-botnet/">http://krebsonsecurity.com/2013/04/brute-force-attacks-build-wordpress-botnet/</a></p>
<p>Well, being the chummy, log sharing chap I am here&#8217;s a list of the naughty machines that have been trying to logging with the admin username on my lovely blog site.</p>
<p>My top security tip is rename the admin account to something less obvious: Elvis, pancake, tree, duh! or metalmicky would thwart this rather simplistic attack. A decent passphrase would be another fine option too&#8230;</p>
<p>Needless to say most of the attacking IP addresses are from the land of the free and the home of the weak password: The  United States of America.65 out of the 151 in the table below.</p>
<div id="attachment_1003" class="wp-caption aligncenter" style="width: 704px"><a href="http://www.chris-mohan.com/wp-content/uploads/2013/04/US-Attackers-this-week-18Apr2013.jpg"><img class="size-full wp-image-1003" alt="Thank you compromised US systems!" src="http://www.chris-mohan.com/wp-content/uploads/2013/04/US-Attackers-this-week-18Apr2013.jpg" width="694" height="368" /></a><p class="wp-caption-text">Thank you compromised US systems!</p></div>
<p>I found a niffy web site that allowed me to make this pretty visual map of the attackers location <a href="http://batchiplocator.webatu.com/">http://batchiplocator.webatu.com/</a></p>
<p>Shame they only allow 110 addresses to be entered for display on the geo-ip map, but it very handy for putting together a blog post like this.</p>
<p><a href="http://www.chris-mohan.com/wp-content/uploads/2013/04/Attackers-this-week-18Apr2013.jpg"><img class="aligncenter size-full wp-image-1002" alt="Attackers this week 18Apr2013" src="http://www.chris-mohan.com/wp-content/uploads/2013/04/Attackers-this-week-18Apr2013.jpg" width="914" height="485" /></a></p>
<p>Add the following naught password guessing IPs to block lists, see if these have hit your logs too or even report them to their abuse@ ISP emails. It&#8217;s up to you.</p>
<p>These IP addresses are from the 14th of April up to today (18th of April).</p>
<table width="271" border="0" cellspacing="0" cellpadding="0">
<colgroup>
<col width="118" />
<col width="153" /></colgroup>
<tbody>
<tr>
<td width="118" height="20">ip</td>
<td width="153">country</td>
</tr>
<tr>
<td height="20">193.180.115.113</td>
<td>Austria</td>
</tr>
<tr>
<td height="20">85.158.215.36</td>
<td>Belgium</td>
</tr>
<tr>
<td height="20">177.180.13.250</td>
<td>Brazil</td>
</tr>
<tr>
<td height="20">187.85.82.38</td>
<td>Brazil</td>
</tr>
<tr>
<td height="20">78.142.63.82</td>
<td>Bulgaria</td>
</tr>
<tr>
<td height="20">199.204.214.208</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">184.107.150.58</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">108.163.128.206</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">108.163.188.186</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">198.144.157.117</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">24.64.120.194</td>
<td>Canada</td>
</tr>
<tr>
<td height="20">190.98.219.99</td>
<td>Chile</td>
</tr>
<tr>
<td height="20">210.14.78.21</td>
<td>China</td>
</tr>
<tr>
<td height="20">223.87.0.177</td>
<td>China</td>
</tr>
<tr>
<td height="20">111.13.87.150</td>
<td>China</td>
</tr>
<tr>
<td height="20">218.203.105.26</td>
<td>China</td>
</tr>
<tr>
<td height="20">61.234.146.186</td>
<td>China</td>
</tr>
<tr>
<td height="20">61.175.223.134</td>
<td>China</td>
</tr>
<tr>
<td height="20">211.167.112.14</td>
<td>China</td>
</tr>
<tr>
<td height="20">14.17.29.112</td>
<td>China</td>
</tr>
<tr>
<td height="20">41.222.196.37</td>
<td>Congo, The Democratic Republic of the</td>
</tr>
<tr>
<td height="20">185.15.196.72</td>
<td>Europe</td>
</tr>
<tr>
<td height="20">94.23.234.227</td>
<td>France</td>
</tr>
<tr>
<td height="20">188.165.202.45</td>
<td>France</td>
</tr>
<tr>
<td height="20">5.135.158.104</td>
<td>France</td>
</tr>
<tr>
<td height="20">109.1.137.192</td>
<td>France</td>
</tr>
<tr>
<td height="20">81.252.211.149</td>
<td>France</td>
</tr>
<tr>
<td height="20">194.231.138.35</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">194.116.187.25</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">83.243.57.33</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">87.253.162.6</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">188.40.166.133</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">31.22.104.28</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">85.10.195.141</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">176.9.78.117</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">85.214.27.40</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">46.165.198.100</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">85.25.73.37</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">188.40.69.202</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">78.46.34.77</td>
<td>Germany</td>
</tr>
<tr>
<td height="20">180.188.194.54</td>
<td>Hong Kong</td>
</tr>
<tr>
<td height="20">124.244.59.238</td>
<td>Hong Kong</td>
</tr>
<tr>
<td height="20">94.199.51.8</td>
<td>Hungary</td>
</tr>
<tr>
<td height="20">210.210.178.20</td>
<td>Indonesia</td>
</tr>
<tr>
<td height="20">115.124.72.62</td>
<td>Indonesia</td>
</tr>
<tr>
<td height="20">118.99.79.123</td>
<td>Indonesia</td>
</tr>
<tr>
<td height="20">42.62.176.150</td>
<td>Indonesia</td>
</tr>
<tr>
<td height="20">180.244.193.110</td>
<td>Indonesia</td>
</tr>
<tr>
<td height="20">77.237.73.3</td>
<td>Iran, Islamic Republic of</td>
</tr>
<tr>
<td height="20">85.119.183.223</td>
<td>Italy</td>
</tr>
<tr>
<td height="20">202.232.236.66</td>
<td>Japan</td>
</tr>
<tr>
<td height="20">210.188.201.41</td>
<td>Japan</td>
</tr>
<tr>
<td height="20">115.187.79.147</td>
<td>Japan</td>
</tr>
<tr>
<td height="20">202.214.8.82</td>
<td>Japan</td>
</tr>
<tr>
<td height="20">2.135.238.162</td>
<td>Kazakhstan</td>
</tr>
<tr>
<td height="20">176.123.0.114</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">176.123.0.105</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">91.214.200.45</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">176.123.0.237</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">176.123.0.231</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">176.123.0.94</td>
<td>Moldova, Republic of</td>
</tr>
<tr>
<td height="20">77.235.47.247</td>
<td>Netherlands</td>
</tr>
<tr>
<td height="20">194.247.30.126</td>
<td>Netherlands</td>
</tr>
<tr>
<td height="20">80.95.160.178</td>
<td>Netherlands</td>
</tr>
<tr>
<td height="20">146.0.79.23</td>
<td>Netherlands</td>
</tr>
<tr>
<td height="20">89.44.200.154</td>
<td>Romania</td>
</tr>
<tr>
<td height="20">92.114.86.81</td>
<td>Romania</td>
</tr>
<tr>
<td height="20">93.187.140.18</td>
<td>Romania</td>
</tr>
<tr>
<td height="20">89.38.207.234</td>
<td>Romania</td>
</tr>
<tr>
<td height="20">80.86.105.174</td>
<td>Romania</td>
</tr>
<tr>
<td height="20">80.78.247.92</td>
<td>Russian Federation</td>
</tr>
<tr>
<td height="20">178.208.91.196</td>
<td>Russian Federation</td>
</tr>
<tr>
<td height="20">151.248.123.211</td>
<td>Russian Federation</td>
</tr>
<tr>
<td height="20">212.49.116.20</td>
<td>Russian Federation</td>
</tr>
<tr>
<td height="20">119.31.233.40</td>
<td>Singapore</td>
</tr>
<tr>
<td height="20">80.35.80.139</td>
<td>Spain</td>
</tr>
<tr>
<td height="20">80.28.254.179</td>
<td>Spain</td>
</tr>
<tr>
<td height="20">61.19.248.138</td>
<td>Thailand</td>
</tr>
<tr>
<td height="20">95.173.186.104</td>
<td>Turkey</td>
</tr>
<tr>
<td height="20">31.210.86.205</td>
<td>Turkey</td>
</tr>
<tr>
<td height="20">37.247.99.82</td>
<td>Turkey</td>
</tr>
<tr>
<td height="20">94.138.206.66</td>
<td>Turkey</td>
</tr>
<tr>
<td height="20">37.57.25.225</td>
<td>Ukraine</td>
</tr>
<tr>
<td height="20">31.202.217.135</td>
<td>Ukraine</td>
</tr>
<tr>
<td height="20">95.154.234.101</td>
<td>United Kingdom</td>
</tr>
<tr>
<td height="20">80.68.95.137</td>
<td>United Kingdom</td>
</tr>
<tr>
<td height="20">216.224.169.123</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.154.36.210</td>
<td>United States</td>
</tr>
<tr>
<td height="20">67.205.24.238</td>
<td>United States</td>
</tr>
<tr>
<td height="20">96.127.139.170</td>
<td>United States</td>
</tr>
<tr>
<td height="20">74.208.66.177</td>
<td>United States</td>
</tr>
<tr>
<td height="20">65.254.40.154</td>
<td>United States</td>
</tr>
<tr>
<td height="20">70.32.112.125</td>
<td>United States</td>
</tr>
<tr>
<td height="20">64.202.240.136</td>
<td>United States</td>
</tr>
<tr>
<td height="20">209.51.142.178</td>
<td>United States</td>
</tr>
<tr>
<td height="20">199.195.143.121</td>
<td>United States</td>
</tr>
<tr>
<td height="20">24.234.3.189</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.105.235.28</td>
<td>United States</td>
</tr>
<tr>
<td height="20">66.36.228.123</td>
<td>United States</td>
</tr>
<tr>
<td height="20">207.58.185.126</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.154.115.10</td>
<td>United States</td>
</tr>
<tr>
<td height="20">69.163.164.44</td>
<td>United States</td>
</tr>
<tr>
<td height="20">199.180.252.22</td>
<td>United States</td>
</tr>
<tr>
<td height="20">66.55.144.244</td>
<td>United States</td>
</tr>
<tr>
<td height="20">173.245.6.132</td>
<td>United States</td>
</tr>
<tr>
<td height="20">65.254.168.168</td>
<td>United States</td>
</tr>
<tr>
<td height="20">67.215.243.250</td>
<td>United States</td>
</tr>
<tr>
<td height="20">216.224.175.71</td>
<td>United States</td>
</tr>
<tr>
<td height="20">72.29.68.51</td>
<td>United States</td>
</tr>
<tr>
<td height="20">74.207.224.242</td>
<td>United States</td>
</tr>
<tr>
<td height="20">69.174.254.88</td>
<td>United States</td>
</tr>
<tr>
<td height="20">74.117.61.88</td>
<td>United States</td>
</tr>
<tr>
<td height="20">174.127.117.77</td>
<td>United States</td>
</tr>
<tr>
<td height="20">72.32.68.101</td>
<td>United States</td>
</tr>
<tr>
<td height="20">69.195.198.111</td>
<td>United States</td>
</tr>
<tr>
<td height="20">198.1.127.222</td>
<td>United States</td>
</tr>
<tr>
<td height="20">208.113.170.83</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.103</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.174</td>
<td>United States</td>
</tr>
<tr>
<td height="20">207.58.139.238</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.208</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.84</td>
<td>United States</td>
</tr>
<tr>
<td height="20">216.172.147.251</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.164</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.75</td>
<td>United States</td>
</tr>
<tr>
<td height="20">50.22.236.98</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.12</td>
<td>United States</td>
</tr>
<tr>
<td height="20">50.117.80.66</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.58</td>
<td>United States</td>
</tr>
<tr>
<td height="20">216.172.147.234</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.168.112.26</td>
<td>United States</td>
</tr>
<tr>
<td height="20">199.223.214.154</td>
<td>United States</td>
</tr>
<tr>
<td height="20">8.29.131.248</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.168.109.23</td>
<td>United States</td>
</tr>
<tr>
<td height="20">23.27.237.205</td>
<td>United States</td>
</tr>
<tr>
<td height="20">208.116.36.230</td>
<td>United States</td>
</tr>
<tr>
<td height="20">198.98.113.47</td>
<td>United States</td>
</tr>
<tr>
<td height="20">65.60.19.242</td>
<td>United States</td>
</tr>
<tr>
<td height="20">72.167.13.19</td>
<td>United States</td>
</tr>
<tr>
<td height="20">50.117.80.168</td>
<td>United States</td>
</tr>
<tr>
<td height="20">216.172.147.57</td>
<td>United States</td>
</tr>
<tr>
<td height="20">198.144.116.91</td>
<td>United States</td>
</tr>
<tr>
<td height="20">184.168.114.10</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.9</td>
<td>United States</td>
</tr>
<tr>
<td height="20">208.115.125.60</td>
<td>United States</td>
</tr>
<tr>
<td height="20">204.93.60.207</td>
<td>United States</td>
</tr>
<tr>
<td height="20">23.27.238.51</td>
<td>United States</td>
</tr>
<tr>
<td height="20">198.144.116.100</td>
<td>United States</td>
</tr>
<tr>
<td height="20">50.117.80.38</td>
<td>United States</td>
</tr>
<tr>
<td height="20">50.31.98.92</td>
<td>United States</td>
</tr>
<tr>
<td height="20">209.73.151.229</td>
<td>United States</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2013/04/wordpress-password-attacks-for-the-last-few-days-ip-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My, my! Bye-bye 2012</title>
		<link>http://www.chris-mohan.com/2012/12/my-my-bye-bye-2012/</link>
		<comments>http://www.chris-mohan.com/2012/12/my-my-bye-bye-2012/#comments</comments>
		<pubDate>Mon, 31 Dec 2012 04:47:57 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Real world]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=993</guid>
		<description><![CDATA[The end of the old year rapidly approaching, and the birth of a new one is nigh! That&#8217;s all for this year folks. Let&#8217;s see if I can&#8217;t come up with something a bit more interesting or relevent in 2013.]]></description>
				<content:encoded><![CDATA[<p>The end of the old year rapidly approaching, and the birth of a new one is nigh!</p>
<p>That&#8217;s all for this year folks. Let&#8217;s see if I can&#8217;t come up with something a bit more interesting or relevent in 2013.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/12/my-my-bye-bye-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A sad farewell to TMG as it gets the chop</title>
		<link>http://www.chris-mohan.com/2012/09/a-sad-farewell-to-tmg-as-it-get-the-chop/</link>
		<comments>http://www.chris-mohan.com/2012/09/a-sad-farewell-to-tmg-as-it-get-the-chop/#comments</comments>
		<pubDate>Thu, 13 Sep 2012 05:30:06 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=988</guid>
		<description><![CDATA[Microsoft have announced that the Forefront Threat Management Gateway 2010 (TMG) product is being discontinued. A few of us have suspected this might be the case but TMG death knell is printed here  Like any product, it had it flaws, but it &#8230; <a href="http://www.chris-mohan.com/2012/09/a-sad-farewell-to-tmg-as-it-get-the-chop/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Microsoft have announced that the Forefront Threat Management Gateway 2010 (TMG) product is being discontinued. A few of us have suspected this might be the case but TMG death knell is printed <a title="TMG no more!" href="http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx" target="_blank">here </a></p>
<p>Like any product, it had it flaws, but it was a plucky little proxy firewall that had some sweet moves; finally beaten by the owner throwing in the towel.</p>
<p>Somewhat bizarrely TMG will be supported until 2015 then kept on minimal life support until 2020. Why is this bizarre? Security threats change daily, so having an unpatched and with no means to keep it reacting to changes in technology (hello? IPV6 anyone?) it&#8217;ll be a liability to the security team.</p>
<p>Ms will either have to bring out a replacement product or it&#8217;s time to find another edge security product that works well with Microsoft products and protocols before the end of the year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/09/a-sad-farewell-to-tmg-as-it-get-the-chop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP training in Brisbane 2013 &#8211; SANS MGT414 Mentor Session with Ashley Deuble</title>
		<link>http://www.chris-mohan.com/2012/09/cissp-training-in-brisbane-2013-sans-mgt414-mentor-session-with-ashley-deuble/</link>
		<comments>http://www.chris-mohan.com/2012/09/cissp-training-in-brisbane-2013-sans-mgt414-mentor-session-with-ashley-deuble/#comments</comments>
		<pubDate>Wed, 12 Sep 2012 12:45:54 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS Mentoring]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=981</guid>
		<description><![CDATA[For the first time SANS® +S™ Training Program for the CISSP® Certification Exam is being run as a mentor class in Brisbane. Starting on the Wednesday 6th of February, 2013, Ashley Deuble, CISSP, CISM, CISA &#38; GSE #47, is leading the remarkably indepth and &#8230; <a href="http://www.chris-mohan.com/2012/09/cissp-training-in-brisbane-2013-sans-mgt414-mentor-session-with-ashley-deuble/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>For the first time SANS® +S™ Training Program for the CISSP® Certification Exam is being run as a mentor class in Brisbane.</p>
<p>Starting on the Wednesday 6th of February, 2013, Ashley Deuble, CISSP, CISM, CISA &amp; GSE #47, is leading the remarkably indepth and comprehensive SANS training to help you master ISC2&#8242;s material and pass the CISSP exam.</p>
<p>Ashley brings his wealth of personal  and industry experience to guide you through the courseware to make the dense subject matter clear, understandable and relatable so you&#8217;re ready to tackle the CISSP exam with a real knowledge of the CISSP domains.</p>
<p>Download <a href="http://www.chris-mohan.com/wp-content/uploads/2012/09/Ashley-Deuble-MGT414-Flyer.pdf">Ashley Deuble MGT414 Flyer</a> or sign up <a title="Ashley Deuble's CISSP Mentor Class" href="http://www.sans.org/mentor/class/30062" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/09/cissp-training-in-brisbane-2013-sans-mgt414-mentor-session-with-ashley-deuble/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Time to find a new hosting provider</title>
		<link>http://www.chris-mohan.com/2012/06/time-to-find-a-new-hosting-provider/</link>
		<comments>http://www.chris-mohan.com/2012/06/time-to-find-a-new-hosting-provider/#comments</comments>
		<pubDate>Sun, 03 Jun 2012 14:39:54 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Real world]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=976</guid>
		<description><![CDATA[More very soon. Not happy.]]></description>
				<content:encoded><![CDATA[<p>More very soon.</p>
<p>Not happy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/06/time-to-find-a-new-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mentoring SANS Hacker Guard: Security Baseline Training for IT Administrators and Operations with Continuing Education in Sydney August 2012</title>
		<link>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-guard-security-baseline-training-for-it-administrators-and-operations-with-continuing-education-in-sydney-august-2012/</link>
		<comments>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-guard-security-baseline-training-for-it-administrators-and-operations-with-continuing-education-in-sydney-august-2012/#comments</comments>
		<pubDate>Tue, 08 May 2012 12:41:05 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[SANS Mentoring]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=962</guid>
		<description><![CDATA[System administrators get a rough deal. They are expected to do their jobs and keep up with the non-stop changes in security, which has a massive impact on their workload. The media routinely preaches that updated patching, antivirus and the &#8230; <a href="http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-guard-security-baseline-training-for-it-administrators-and-operations-with-continuing-education-in-sydney-august-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p style="background: white;"><span style="color: black; font-family: Helvetica; font-size: 11pt;">System administrators get a rough deal. They are expected to do their jobs and keep up with the non-stop changes in security, which has a massive impact on their workload. The media routinely preaches that updated patching, antivirus and the latest and greatest security device will keep them and their companies&#8217; safe. That just isn&#8217;t true.<br />
</span></p>
<p style="background: white;"><span style="color: black; font-family: Helvetica; font-size: 11pt;">This course brings real world security awareness to you, the Sysadmin, on what to look for if your network is under attack or has been hacked. It helps explain how the bad guys get in and how to block them. This isn&#8217;t a course telling you to do all the basic stuff &#8211; patching, installing anti-virus software, running hardening guides and so on &#8211; you&#8217;ve being doing as part of your job for years and it&#8217;s nothing new.<br />
</span></p>
<p style="background: white;"><a href="https://www.sans.org/mentor/class/sec464-sydney-aug-2012-mohan"><span style="font-family: Helvetica; font-size: 11pt;">Hacker Guard: Security Baseline Training for IT Administrators and Operations with Continuing Education</span></a><span style="color: black; font-family: Helvetica; font-size: 11pt;"> may sound like a mouthful, but it&#8217;s practical, sensible topics and can be used in your job. This is all common sense material that the various OS vendor training courses never tells you about that actually make it easier for you to make your network more secure. Now you&#8217;ll be able to hold a solid conversation with the security team and understand what their after and how you can help provide it without making your life a misery.<br />
</span></p>
<p style="text-align: center; background: white;">
<p style="text-align: center; background: white;"><span style="color: black; font-family: Helvetica; font-size: 18pt;"><strong>Why SANS Mentor Training?<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica;"><span style="font-size: 11pt;">This is why I think the SANS Mentor classes are a terrific training option. If you live in the Sydney area and are interested in attending SANS classes, please do <a href="mailto:chris@chris-mohan.com?subject=Mentoring%20504%20in%20Sydney"><span style="color: #1982d1;">contact me</span></a> to get more details!</span><span style="color: black; font-size: 18pt;"><strong><br />
</strong></span></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Pace:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">The material is covered over a four week period which provides lots of time for you to read on your own time and come back to the mentor meetings with questions and get answers. This helps to digest the massive amount of material in smaller, manageable doses. We study 2 or 3 modules each week and that material can be applied immediately on the job.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Cost:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">The cost is significantly reduced. the cost is lower than any other form of SANS training making it very accessible to those who are budget constrained – which these days is many of us. There is an automatic 25% price reduction from the cost of courses delivered at the conferences. There is no travel or accommodations, so that massive saving in costs. And finally, I can generally offer an additional discount if you <a href="mailto:chris@chris-mohan.com?subject=Mentoring%20504%20in%20Sydney"><span style="color: #1982d1;">contact me</span></a> prior to registration.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Networking:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Don&#8217;t overlook this one. When you are in the two-day conference courses, you definitely get a change to meet others, talk about your experiences and issues in the field, and maybe even keep in touch via email. But when meeting for 10 weekly classes with your peers in the same community, that networking experience is enhanced significantly. You have the chance to really get to know the others in the class by the shared experiences, work through the material and bounce ideas of each other; that&#8217;s a great benefit to being part of a local Mentor class.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Size:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Class sizes are typically small – much smaller than what you would find at a SANS conference, which means we can focus more closely on those areas which are difficult for the group<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Material:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">You get all the same material as you would from the conference course, including the same books, CDs, and even audio files of the full 2-day course lectures.<br />
</span></p>
<p style="background: white;">
<p><span style="color: #373737;"><span style="font-family: Helvetica; font-size: 11pt;">Feel free to e-mail me with any questions, or visit the course website here:<br />
</span>https://www.sans.org/mentor/class/sec464-sydney-aug-2012-mohan</span></p>
<p>&nbsp;</p>
<p style="background: white;">
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">A great guy and friend <a href="http://www.voipsec.eu/" target="_blank"><span style="color: #1982d1;">Wouter</span></a>, managed to get a room in Sydney&#8217;s CBD to hold the training. It&#8217;s easy to get to and has parking nearby.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Mentor training location details<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Dates: Tuesday, August 7, 2012 – Tuesday, August 28, 2012<br />
Meeting Time: 6:00 PM – 8:00 PM<br />
Where:<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Level 33<br />
Ernst &amp; Young Centre<br />
680 George Street<br />
Sydney, Australia 2000<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-guard-security-baseline-training-for-it-administrators-and-operations-with-continuing-education-in-sydney-august-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mentoring SANS Hacker Techniques, Exploits &amp; Incident Handling in Sydney July 2012</title>
		<link>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-techniques-exploits-incident-handling-in-sydney-july-2012/</link>
		<comments>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-techniques-exploits-incident-handling-in-sydney-july-2012/#comments</comments>
		<pubDate>Tue, 08 May 2012 12:03:24 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[SANS Mentoring]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=956</guid>
		<description><![CDATA[I was again offered the opportunity to lead mentoring for SANS Hacker Techniques, Exploits &#38; Incident Handling (SEC-504), here in Sydney, and I leapt at the chance! I love this course and it helped me reach a deeper understanding on &#8230; <a href="http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-techniques-exploits-incident-handling-in-sydney-july-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">I was again offered the opportunity to lead mentoring for <a href="https://www.sans.org/mentor/class/sec504-sydney-jul-2012-mohan">SANS Hacker Techniques, Exploits &amp; Incident Handling</a> (SEC-504), here in Sydney, and I leapt at the chance!<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">I love this course and it helped me reach a deeper understanding on a number of aspects of my role as the IT security person charged with incident response. It provided that real world, hands-on practical skills you need to do this job.<br />
</span></p>
<p style="text-align: center; background: white;"><span style="color: black; font-family: Helvetica; font-size: 18pt;"><strong>Why SANS Mentor Training?<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica;"><span style="font-size: 11pt;">This is why I think the SANS Mentor classes are a terrific training option. If you live in the Sydney area and are interested in attending SANS classes, please do <a href="mailto:chris@chris-mohan.com?subject=Mentoring%20504%20in%20Sydney"><span style="color: #1982d1;">contact me</span></a> to get more details!</span><span style="color: black; font-size: 18pt;"><strong><br />
</strong></span></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Pace:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">The material is covered over a 10 week period which provides lots of time for you to read on your own time and come back to the mentor meetings with questions and get answers. This helps to digest the massive amount of material in smaller, manageable doses. We study 2 or 3 modules each week and that material can be applied immediately on the job.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Cost:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">The cost is significantly reduced. the cost is lower than any other form of SANS training making it very accessible to those who are budget constrained – which these days is many of us. There is an automatic 25% price reduction from the cost of courses delivered at the conferences. There is no travel or accommodations, so that massive saving in costs. And finally, I can generally offer an additional discount if you <a href="mailto:chris@chris-mohan.com?subject=Mentoring%20504%20in%20Sydney"><span style="color: #1982d1;">contact me</span></a> prior to registration.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Networking:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Don&#8217;t overlook this one. When you are in the 6-day conference courses, you definitely get a change to meet others, talk about your experiences and issues in the field, and maybe even keep in touch via email. But when meeting for 10 weekly classes with your peers in the same community, that networking experience is enhanced significantly. You have the chance to really get to know the others in the class by the shared experiences, work through the material and bounce ideas of each other; that&#8217;s a great benefit to being part of a local Mentor class.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Size:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Class sizes are typically small – much smaller than what you would find at a SANS conference, which means we can focus more closely on those areas which are difficult for the group<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Material:<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">You get all the same material as you would from the conference course, including the same books, CDs, and even audio files of the full 6-day course lectures.<br />
</span></p>
<p style="background: white;">
<p><span style="color: #373737;"><span style="font-family: Helvetica; font-size: 11pt;">Feel free to e-mail me with any questions, or visit the course website here:<br />
</span>https://www.sans.org/mentor/class/sec504-sydney-jul-2012-mohan</span></p>
<p style="background: white;">
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">A great guy and friend <a href="http://www.voipsec.eu/" target="_blank"><span style="color: #1982d1;">Wouter</span></a>, managed to get a room in Sydney&#8217;s CBD to hold the training. It&#8217;s easy to get to and has parking nearby.<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 7pt;"><strong>Mentor training location details<br />
</strong></span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Dates: Thursday, July 12, 2012 – Thursday, September 13, 2012<br />
Meeting Time: 6:00 PM – 8:00 PM<br />
Where:<br />
</span></p>
<p style="background: white;"><span style="color: #373737; font-family: Helvetica; font-size: 11pt;">Level 33<br />
Ernst &amp; Young Centre<br />
680 George Street<br />
Sydney, Australia 2000</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/05/mentoring-sans-hacker-techniques-exploits-incident-handling-in-sydney-july-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outlook Tweaks</title>
		<link>http://www.chris-mohan.com/2012/04/outlook-tweaks/</link>
		<comments>http://www.chris-mohan.com/2012/04/outlook-tweaks/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 11:12:17 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=947</guid>
		<description><![CDATA[I continually forget these Outlook settings to make reading lovely HTML emails just that little bit safer. Then I also like to be able to read the message headers on those odd emails In Outlook 2010 File &#8211; Quick Access &#8230; <a href="http://www.chris-mohan.com/2012/04/outlook-tweaks/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>I continually forget these Outlook settings to make reading lovely HTML emails just that little bit safer. Then I also like to be able to read the message headers on those odd emails In Outlook 2010 File &#8211; Quick Access Toolbar add in Message Header from the all option drop down tab.</p>
<p>Taken from <a href="http://support.microsoft.com/kb/831607">http://support.microsoft.com/kb/831607</a></p>
<p>To turn on the <strong>Read all standard mail in plain text </strong>option in Outlook 2003, follow these steps:</p>
<ol>
<li>Start Outlook 2003.</li>
<li>On the <strong>Tools</strong> menu, click <strong>Options</strong>.</li>
<li>On the <strong>Preferences</strong> tab, in the <strong>E-mail</strong> area, click <strong>E-mail Options</strong>.</li>
<li>In the <strong>Message handling</strong> area, click to select the <strong>Read all standard mail in plain text</strong> check box.<br />
<strong>Note</strong> By default, the <strong>Read all standard mail in plain text</strong> option is turned off.</li>
</ol>
<p>To turn on the <strong>Read all standard mail in plain   text</strong>option in Outlook 2007, follow these steps:</p>
<ol>
<li>Start Outlook 2007.</li>
<li>On the <strong>Tools</strong> menu, click <strong>Trust Center</strong>, and then click <strong>E-mail Security</strong>.</li>
<li>Under <strong>Read as Plain Text</strong>, click to select  the <strong>Read all standard mail in plain text</strong> check box.</li>
<li>To include messages that are signed with a digital signature, click to select the <strong>Read all digitally signed mail in plain text</strong> check box.</li>
</ol>
<p>When the <strong>Read all standard mail in plain text</strong>  option is turned on, you receive the following notification on the InfoBar at   the top of the e-mail message:</p>
<div>
<div>This message was converted to plain text.</div>
</div>
<p><strong>Note</strong> If you decide to view the plain text message in its original format, click the InfoBar, and then select <strong>Display as HTML</strong> or <strong>Display as Rich Text</strong>.<br />
To turn on the <strong>Read all standard mail in plain text</strong>option in Outlook 2010, follow these steps:</p>
<ol>
<li>Start Outlook 2010.</li>
<li>  Click the <strong>File</strong> tab in the Ribbon, and then click <strong>Options</strong> on the menu.</li>
<li>Click <strong>Trust Center</strong> on the <strong>Options</strong> menu.</li>
<li>Click the <strong>Trust Center Settings</strong> tab.</li>
<li>Click <strong>E-mail Security</strong>.</li>
<li>Under <strong>Read as Plain Text</strong>, click to select  the <strong>Read all standard mail in plain text</strong> check box.</li>
<li>To include messages that are signed with a digital signature, click to select the <strong>Read all digitally signed mail in plain text</strong> check box.</li>
</ol>
<p>When the <strong>Read all standard mail in plain text</strong>  option is turned on, you receive the following notification on the InfoBar at   the top of the e-mail message:</p>
<div>
<div>This message was converted to plain text.</div>
<div></div>
<div></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/04/outlook-tweaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS Canberra 2012</title>
		<link>http://www.chris-mohan.com/2012/03/sans-canberra-2012/</link>
		<comments>http://www.chris-mohan.com/2012/03/sans-canberra-2012/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 12:32:04 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[Study]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=939</guid>
		<description><![CDATA[In an attempt to plan some of my training/learning schedule I&#8217;m quietly excited about attending the SANS Canberra conference and taking the Forensics 610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques (GREM) with Hal Pomeranz. Spending a bit of quality &#8230; <a href="http://www.chris-mohan.com/2012/03/sans-canberra-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>In an attempt to plan some of my training/learning schedule I&#8217;m quietly excited about attending the SANS Canberra conference and taking the Forensics 610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques (GREM) with Hal Pomeranz.</p>
<p>Spending a bit of quality time working through the malware process will be interesting to see how my current processes stack up against the SANS format created by <a title="The one, the only Lenny Z!" href="http://zeltser.com/" target="_blank">Lenny Zelster</a></p>
<p><a title="SANS Canberra 2012" href="http://www.sans.org/canberra-2012/" target="_blank">SANS Canberra 2012</a> kicks off on the 2nd of July</p>
<p>&nbsp;</p>
<p>Hal&#8217;s a Unix guru, so I&#8217;ll make sure I bring a fake beard, white socks and sandals to avoid him noticing the &#8220;I heart Windows&#8221; tattoo across my forehead.</p>
<p>Note to self &#8211; when looking for humour image on the inter-tubes you should know better.</p>
<p>Now this is a tattoo</p>
<p><a href="http://www.chris-mohan.com/wp-content/uploads/2012/03/Windows-going-a-bit-too-far.jpg"><img class="aligncenter size-full wp-image-940" title="Windows going a bit too far" src="http://www.chris-mohan.com/wp-content/uploads/2012/03/Windows-going-a-bit-too-far.jpg" alt="" width="600" height="644" /></a>Source : http://news.bmezine.com/2007/07/26/best-windows-tattoo-ever/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/03/sans-canberra-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Well, that was unexpected</title>
		<link>http://www.chris-mohan.com/2012/03/well-that-was-unexpected/</link>
		<comments>http://www.chris-mohan.com/2012/03/well-that-was-unexpected/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 12:04:27 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Real world]]></category>
		<category><![CDATA[Stuff]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=935</guid>
		<description><![CDATA[Google informed me that this blog was re-directing to bad stuff. So took it off air and had a look for this evil. Hmmm.]]></description>
				<content:encoded><![CDATA[<p>Google informed me that this blog was re-directing to bad stuff. So took it off air and had a look for this evil.</p>
<p>Hmmm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2012/03/well-that-was-unexpected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
