<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/training_courses_and_services</link>
 <description></description>
 <language>en</language>
<item>
 <title>VoIP Security Training</title>
 <link>http://website.isecpartners.com/voip_security_training</link>
 <description> &lt;p&gt;Target: Network Engineers, Security Architects&lt;/p&gt;
&lt;p&gt;Length: 2 days&lt;/p&gt;
&lt;p&gt;Focus: VoIP Attacks&lt;/p&gt;
&lt;p&gt;Format: Lab &amp;amp; Lecture&lt;/p&gt;
&lt;p&gt;Content:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Writing unit tests to for defects&lt;/li&gt;
&lt;li&gt;Eavesdropping on third party calls via RTP&lt;/li&gt;
&lt;li&gt;SIP Attacks&lt;/li&gt;
&lt;li&gt;H.323 Attacks&lt;/li&gt;
&lt;li&gt;H.225 Registration&lt;/li&gt;
&lt;li&gt;Replay Attacks&lt;/li&gt;
&lt;li&gt;Spoofing (Endpoints, Gatekeepers, Border Controllers)&lt;/li&gt;
&lt;li&gt;Denial of Service (SIP and H.323)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Protocol Analysis:&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;SIP&lt;/li&gt;
&lt;li&gt;H.323&lt;/li&gt;
&lt;li&gt;RTP&lt;/li&gt;
&lt;li&gt;MGCP&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Device Analysis:&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Gatekeepers&lt;/li&gt;
&lt;li&gt;Media Gateways&lt;/li&gt;
&lt;li&gt;Border Controllers&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;VoIP Trends&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;GoogleTalk, Skype, MSN Live Messenger, Yahoo Messenger, Vontage&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about our training courses or onsite delivery options, contact &lt;a href=&quot;mailto:training@isecpartners.com&quot;&gt;training@isecpartners.com&lt;/a&gt;.&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:54:09 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">66 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Improving Software Security through Life Cycle Changes</title>
 <link>http://website.isecpartners.com/improving_software_security_through_life_cycle_changes</link>
 <description> &lt;p&gt;Target: Software development teams with responsibility for create secure applications.&lt;/p&gt;
&lt;p&gt;Length: 4 days&lt;/p&gt;
&lt;p&gt;Format: Lecture and Workshop&lt;/p&gt;
&lt;p&gt;Focus: Software development lifecycle of products.&lt;/p&gt;
&lt;p&gt;Content:  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The Agile software development lifecycle · Defining Security Requirements&lt;/li&gt;
&lt;li&gt;User Stories&lt;/li&gt;
&lt;li&gt;Threat modeling&lt;/li&gt;
&lt;li&gt;Negative QA testing&lt;/li&gt;
&lt;li&gt;Test Driven Design&lt;/li&gt;
&lt;li&gt;Security defects impact on your product&lt;/li&gt;
&lt;li&gt;Writing unit tests to for security defects&lt;/li&gt;
&lt;li&gt;Balancing security defects, regular defects and features&lt;/li&gt;
&lt;li&gt;Integrating the Agile lifecycle into your environment&lt;/li&gt;
&lt;li&gt;Continuous Improvement&lt;/li&gt;
&lt;li&gt;Security and Agile Engineering Practices&lt;/li&gt;
&lt;li&gt;Security and Agile Management Practices&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:41:48 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">64 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Web Application Security QA Testing</title>
 <link>http://website.isecpartners.com/web_application_security_qa_testing</link>
 <description> &lt;p&gt;Target: Developers and QA Professionals&lt;br /&gt;
Length: 2 Days&lt;br /&gt;
Focus: Security testing of web applications&lt;/p&gt;
&lt;p&gt;Format: Lab &amp;amp; Lecture&lt;/p&gt;
&lt;p&gt;Content: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cookies&lt;/li&gt;
&lt;li&gt;Cross-Site Scripting&lt;/li&gt;
&lt;li&gt;Hostile linking attacks&lt;/li&gt;
&lt;li&gt;Forms&lt;/li&gt;
&lt;li&gt;Hidden fields and business logic&lt;/li&gt;
&lt;li&gt;Links&lt;/li&gt;
&lt;li&gt;Page Redirection&lt;/li&gt;
&lt;li&gt;Phishing&lt;/li&gt;
&lt;li&gt;SQL Injection&lt;/li&gt;
&lt;li&gt;Error messages&lt;/li&gt;
&lt;li&gt;Concurrency&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:22:37 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">63 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Application Security Best Practices</title>
 <link>http://website.isecpartners.com/application_security_best_practices</link>
 <description> &lt;p&gt;Target: Developers QA &amp;amp; Application Security Professionals&lt;br /&gt;
Length: 2 Days&lt;br /&gt;
Focus: Application Weaknesses, Development Flaws, and Remediation Strategies&lt;/p&gt;
&lt;p&gt;Format: Lab &amp;amp; Lecture&lt;/p&gt;
&lt;p&gt;Content: &lt;/p&gt;
&lt;p&gt;Application Attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Execution of the following attacks on web interfaces&lt;/li&gt;
&lt;li&gt;Cross-site scripting&lt;/li&gt;
&lt;li&gt;Code Injection&lt;/li&gt;
&lt;li&gt;Session Hijacking&lt;/li&gt;
&lt;li&gt;Enumeration of network and device settings&lt;/li&gt;
&lt;li&gt;Enumeration of web server type, either Apache or propriety, and CLI management methods&lt;/li&gt;
&lt;li&gt;Denial of Service attacks&lt;/li&gt;
&lt;li&gt;Responsible disclosure doctrines and practices&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Binary Analysis&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Binary analysis with hex editor and an introduction to forensics tools&lt;/li&gt;
&lt;li&gt;Binary examination, disassembly, and modification&lt;/li&gt;
&lt;li&gt;Run-time debugging and reverse engineering&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:20:05 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">62 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Penetration Testing &amp; Binary Analysis</title>
 <link>http://website.isecpartners.com/penetration_testing_binary_analysis</link>
 <description> &lt;p&gt;Target: Network and Application Security Professionals&lt;br /&gt;
Length: 1, 2 and 3 Day courses&lt;br /&gt;
Focus: Application and Network Penetration Testing&lt;/p&gt;
&lt;p&gt;Format: Lab &amp;amp; Lecture&lt;/p&gt;
&lt;p&gt;Content:&lt;/p&gt;
&lt;p&gt;Authentication Attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;NTLM Attacks&lt;/li&gt;
&lt;li&gt;Kerberos downgrade attacks&lt;/li&gt;
&lt;li&gt;SSL Man-in-the-Middle Attack&lt;/li&gt;
&lt;li&gt;Force SSL browsing with expire/un-trusted certificates&lt;/li&gt;
&lt;li&gt;Deletion/corruption of the audit log&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Application Attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Execution of the following attacks on web interfaces&lt;/li&gt;
&lt;li&gt;Cross-site scripting&lt;/li&gt;
&lt;li&gt;Code Injection&lt;/li&gt;
&lt;li&gt;Session Hijacking&lt;/li&gt;
&lt;li&gt;Enumeration of network and device settings&lt;/li&gt;
&lt;li&gt;Enumeration of web server type, either Apache or propriety, and CLI management methods&lt;/li&gt;
&lt;li&gt;Denial of Service attacks&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Network Attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Layer 2 ARP Attacks&lt;/li&gt;
&lt;li&gt;Session Hijacking&lt;/li&gt;
&lt;li&gt;Subverting Firewalls and Routing ACLs&lt;/li&gt;
&lt;li&gt;Identification Spoofing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Host Attacks&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows 2003/2000 Attacks&lt;/li&gt;
&lt;li&gt;IIS 5.0 Security&lt;/li&gt;
&lt;li&gt;Linux (various flavors) Attack&lt;/li&gt;
&lt;li&gt;Apache Security&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 01:15:16 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">61 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Defend the Flag (DTF)</title>
 <link>http://website.isecpartners.com/defend_the_flag_dtf</link>
 <description> &lt;p&gt;Target: Network and Operations Security Professionals&lt;br /&gt;
Length: 2 Days&lt;br /&gt;
Focus: Windows network and host attack, hardening and defense&lt;/p&gt;
&lt;p&gt;Format: Lecture, Lab and Competition&lt;/p&gt;
&lt;p&gt;Content:&lt;/p&gt;
&lt;p&gt;iSEC Partners has partnered with Microsoft to deliver this unique, hands-on training exercise in network attack and defense on the Windows platform.  Day one begins with a half-day tutorial on attacking Windows systems utilizing state of the art attack tools,  (previous DTF delivery partners for this portion of the course have included Immunity and Core) followed by another half day of materials and labs developed and delivered by iSEC’s industry-leading experts on Windows platform security.  On day two, the students will form teams to compete against each other, exercising skills learned in both attack and defense.  While the class is applicable to all recent versions of the Windows operating system, Defending Windows focuses on Windows XP and Windows 2003 which are currently the most deployed Windows versions.&lt;/p&gt;
&lt;p&gt;“Defending Windows” material includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Preparing for an attack
&lt;ul&gt;
&lt;li&gt;Discussion of hardening principles and methodologies
&lt;li&gt;System classification techniques
&lt;li&gt;Hardening network protocols, system services, DCOM
&lt;li&gt;Security-relevant registry settings
&lt;li&gt;User rights assignments
&lt;li&gt;Audit and event logs
&lt;li&gt;Account and password policies
&lt;li&gt;Group Policy Settings
&lt;li&gt;Basic forensic methodologies to assist in detecting/responding to attacks&lt;/ul&gt;
&lt;li&gt;During the attack
&lt;ul&gt;
&lt;li&gt;How to find out that a system is under attack or has been compromised
&lt;li&gt;How to stop the attack &lt;/ul&gt;
&lt;li&gt;After the attack
&lt;ul&gt;
&lt;li&gt;Basic forensics
&lt;li&gt;How to prevent recurrence&lt;/ul&gt;
&lt;/ul&gt;
&lt;p&gt;Due to the unique nature of this course, it will only be offered at select international security conferences.  Please register to participate directly with the hosting venue.&lt;/p&gt;
&lt;h2&gt;Past events:&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-dc-08/train-bh-dc-08-msisim.html&quot;&gt; Black Hat DC Training 2008&lt;/a&gt;&lt;br /&gt;
District of Columbia, USA&lt;br /&gt;
Feb 18-19, 2008&lt;/p&gt;
&lt;h2&gt;Upcoming events include:&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;http://cansecwest.com/dojodtf.html&quot;&gt; CanSecWest Vancouver 2008&lt;/a&gt;&lt;br /&gt;
Vancouver, British Columbia, Canada&lt;br /&gt;
March 24-25, 2008&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.syscan.org/hk/indexhk.html&quot;&gt;SyScan ’08 Hong Kong&lt;/a&gt;&lt;br /&gt;
Hong Kong, China&lt;br /&gt;
May 27-28, 2008&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://conference.auscert.org.au/conf2008/&quot;&gt;AusCERT 2008&lt;/a&gt;&lt;br /&gt;
Gold Coast, Australia&lt;br /&gt;
May 18-23, 2008&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.syscan.org/sg/indexsg.html&quot;&gt;SyScan ’08 Singapore&lt;/a&gt;&lt;br /&gt;
Singapore&lt;br /&gt;
July 1-2, 2008&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-index.html&quot;&gt;Black Hat USA Training 2008&lt;/a&gt;&lt;br /&gt;
Las Vegas, Nevada, USA&lt;br /&gt;
August 2-5, 2008&lt;/p&gt;
&lt;p&gt;More dates coming soon, or contact &lt;a href= &quot;mailto:info@isecpartners.com&quot;&gt;info@isecpartners.com&lt;/a&gt; for additional details.&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Thu, 28 Feb 2008 17:16:03 -0800</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">316 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Windows Vista Security for Developers</title>
 <link>http://website.isecpartners.com/windows_vista_security_for_developers</link>
 <description> &lt;p&gt;Target: Security reviewers and developers already familiar with Windows security features and looking to understand how Vista changes the Windows security model and can be leveraged to improve application and enterprise security.&lt;/p&gt;
&lt;p&gt;Length: 4 hours&lt;/p&gt;
&lt;p&gt;Format: Lecture &lt;/p&gt;
&lt;p&gt;Focus: This is a technical introduction to several of the important security changes introduced in Microsoft Windows &lt;/p&gt;
&lt;p&gt;Content:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User Account Control (UAC)&lt;/li&gt;
&lt;li&gt;Protected Mode Internet Explorer&lt;/li&gt;
&lt;li&gt;Service Hardening&lt;/li&gt;
&lt;li&gt;Odds and Ends&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Mon, 05 Feb 2007 10:57:15 -0800</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">174 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
