WELCOME

Capella has been designated a National Center of Academic Excellence in Information Assurance Education (CAEIAE) by the National Security Agency and the U.S. Department of Homeland Security. Capella’s information security curriculum meets the NSA Committee on National Security Systems standards 4011, 4013, 4014.

This center provides access to resources, tools, and the latest information regarding information assurance as a way to enhance understanding in this field of study.

CNSS Certification

The NSA’s Information Assurance Courseware Evaluation (IACE) Review Committee has validated that Capella’s information security curriculum meets the Committee on National Security Systems (CNSS) National Standards 4011, 4013, (and 4014 coming). Learn what this means to a Capella learner.

ARCHIVES

Microsoft SMB fail 2.0

From Rodney Visser | September 15th, 2009

Recently, another Windows os vulnerability has surfaced pointed at ports 139 and 445. It was initially released as a denial of service attack, but could also allow system level remote code execution. The strange thing about this particular exploit for me, is that this issue was fixed on Windows 7 build 7130, but as of today there is still no fix for Vista or Server 2008.

In the time it is taking them to address this issue there is already working exploit code in the ever popular MetaSploit framework and as an added bonus it has the ability to do reverse HTTP tunneling on port 80. This means that you could hit an exploited system and the firewall will literally mean nothing.

 

Tags: ,

 

Invisible Firewalls?

From Rodney Visser | August 18th, 2009

 When adding a traditional hardware based firewall to a network, major network based surgery is needed a majority of the time.  The potential for configuration problems with both internal clients and the router/proxy are increased.  There is also overhead that goes into processing each packet or session for the firewall, making it difficult to come to an informed decision. 

When looking though the eyes of an attacker, only minimal investigation and enumeration is needed to identify a device that is acting as a firewall. Its rule-set or “protection” features can be realized. READ ON

Tags: , , , ,

 

Categories

RESOURCES

NEWS FEEDS

META

CAPELLA CONNECTION

Capella University offers several degree programs which specialize in the information assurance and security field. Visit one of the links below for more information.

To learn more about Capella, please visit http://www.capella.edu or call 1.888.CAPELLA, option 2, to speak to an enrollment counselor.

Capella University