ZaCon II Call For Papers

Posted on May 28, 2010

Date : 9 October 2010.
Location : University of Joburg. Joburg.
Cost : The goal is to hit breakeven on the costs,  so an entry fee (if charged) will be low.

Many other conferences exist to cater either to the strictly Academic or Professional individual. We want a simple community based forum  that is completely  free of  corporate affiliation (or shilling). The intention behind this  is that the passion for the field or of sharing knowledge should  be  the primary motivation  of attending or speaking at this conference.

We aim to fulfill these objectives:
* Provide a platform for publication of infosec research
* Showcase free locally-developed infosec tools
* Support  the interaction of industry, academia and  the interested public
* Encourage discussion on infosec / hackery / sec-related-geekery at large
* Build the ZA infosec community
* Provide a platform to up-n-coming talent

Closing date for submissions is 20 August 2010.

Contacts
* Site: http://zacon.org.za
* Abstracts: abstracts AT zacon org za
* Organisers: people AT zacon org za
* IRC: #zacon on irc.atrum.org

ITWeb Security Summit 2010

Posted on May 19, 2010

I was up in Johannesburg last week to attend and co-present at the IT Web Security Summit 2010. The conference had some really good speakers (Joe Grand, Moxie Marlinspike, FX, Charlie Miller, and others) covering a wide variety of most interesting topics.

You can read some articles about the conference, the speakers and the presentations at the link above. Alex Kayle did a brief email based Q&A ahead of the presentation and wrote up the following article. It gives some idea of what the presentation is all about.

I was co-presenting with a colleague, David Volschenk on the implementation of Security and control frameworks. We took two hypothetical companies (combined from various client experiences) and compared the processes and experiences to contrast what worked and what didn’t across the organisations, while looking at the key drivers (of which King 3 is now a significant one). This was woven around Dickens’ “A tale of two cities” to bring a bit of a different angle into what otherwise could have been quite a dry topic. Take a look at the King 3 responsibilities on the Board of Directors if you haven’t already. They are quite onerous compared to King 2 (which pretty much ignored IT governance). The King 3 report is available for download on the Institute of Directors (IOD) website.

Our presentation on the day went down reasonably well to quite a full venue. Thanks to all those who attended, hope you enjoyed what we had to say.

The presentation has been uploaded for all those who may wish to check it out.

It’s a new beginning

Posted on April 24, 2010

It took a cold (well for Durban) miserable autumnish first day of the long weekend to finally get motivated to get this site back up and running again. After going through the process of changing ISPs a few times in short succession I finally have a new home (thanks Gridhost.co.za) and things are back up and running again.

The content from the old site is backed up on my old PC (which now won’t boot – duh) so it is time to start afresh. When I eventually get around to recovering the data from the old PC I will bring anything useful across.

The most accessed part of the old site was the Oracle default passwords list, linked from Pete Finnigan’s security site (www.petefinnigan.com) so I have uploaded it. You can grab it on  :   Oracle password list

Now to find a theme I like (that is usable from mobile devices and blackberry).

%d bloggers like this: