<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chrisbrenton.org &#187; 3-err</title>
	<atom:link href="http://www.chrisbrenton.org/category/infocon-level/3-err/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chrisbrenton.org</link>
	<description>Your source for invisible security bug spray</description>
	<lastBuildDate>Mon, 22 Aug 2011 01:04:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Are Virtualized Systems More Or Less Secure?</title>
		<link>http://www.chrisbrenton.org/2010/05/are-virtualized-systems-more-or-less-secure/</link>
		<comments>http://www.chrisbrenton.org/2010/05/are-virtualized-systems-more-or-less-secure/#comments</comments>
		<pubDate>Tue, 18 May 2010 20:53:20 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[General Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=815</guid>
		<description><![CDATA[I’ve had the above question asked enough times that I felt it worthy of a blog post. While a few years back the answer may have been “less secure”, today the answer is “both”. I know, sounds like Chris being non-committal, but that answer really does most accurately describe the current state of the technology. [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/05/are-virtualized-systems-more-or-less-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC – Part 4</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 20:05:52 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=811</guid>
		<description><![CDATA[In my last post we installed Logwatch as well as OSSEC. It is now time to get Logwatch and OSSEC playing together in the same sandbox. In this post I’ll discuss how to get Logwatch to summarize the information being generated by OSSEC. Deployment Options We have two paths we can follow to set this [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC – Part 3</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 20:46:00 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=807</guid>
		<description><![CDATA[In my last two posts I discussed Logwatch and OSSEC, as well as how they can be leverage to augment your security posture. In this installment I’ll discuss how to install both of these tools. Installing Logwatch Logwatch is pretty easy to install. In fact, it is installed by default on many Linux distributions so [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC – Part 2</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 16:45:07 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=803</guid>
		<description><![CDATA[In my last post I described how Logwatch could be used to simplify the log review process. In this post we’ll look at OSSEC and what it brings to the table. What Is OSSEC? OSSEC, short for “Open Source SECurity”, is a host based intrusion detection system (HIDS). In other words, it is designed to [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 19:39:13 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=797</guid>
		<description><![CDATA[I recently had a student ask me a question regarding the integration of Logwatch with OSSEC. I felt like this was a complex and yet cool enough idea that it warranted a series of posts to cover it in full. So over the next few days I’ll talk about each of these tools, how to [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Day 2 Keynote</title>
		<link>http://www.chrisbrenton.org/2010/01/day-2-keynote/</link>
		<comments>http://www.chrisbrenton.org/2010/01/day-2-keynote/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 14:30:01 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[General Security]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=792</guid>
		<description><![CDATA[Thanks to all who came out to the Encryption/DLP summit. Here are the slides from my keynote on day 2. encryption-dlp-keynote]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/01/day-2-keynote/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICMPv6 Challenge &#8211; Answers</title>
		<link>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-answers/</link>
		<comments>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-answers/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 11:52:03 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Packet Decoding]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=746</guid>
		<description><![CDATA[The challenge was: “Write a tcpdump/windump filter that will capture ICMPv6 Multicast Listener packets.” I have an extensive write up on what makes the answer so complex. If you know IPv6 and just want the answer, skip to the end. First, Some Background Steinar made some comments to the previous posts and was 100% on [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-answers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICMPv6 Challenge &#8211; Hints</title>
		<link>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-hints/</link>
		<comments>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-hints/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 05:36:04 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Packet Decoding]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=732</guid>
		<description><![CDATA[OK, here&#8217;s a hint to point you in the right direction. The challenge was: &#8220;Write a tcpdump/windump filter that will capture ICMPv6 Multicast Listener packets.&#8221; Sounds easy, right? With a little help from Google you&#8217;ll find that the &#8220;type&#8221; for Multicast listener is 130, and the ICMPv6 type field is the first byte in the [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/12/icmpv6-challenge-hints/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>ICMPv6 Challenge</title>
		<link>http://www.chrisbrenton.org/2009/12/icmpv6-challenge/</link>
		<comments>http://www.chrisbrenton.org/2009/12/icmpv6-challenge/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 01:07:40 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Packet Decoding]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=726</guid>
		<description><![CDATA[Building on the IPv6 challenge from last time, I have a new one for you: Write a tcpdump/windump filter which will capture ICMPv6 Multicast Listener packets. That&#8217;s it! Pretty easy, right?]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/12/icmpv6-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekend Challenge &#8211; Answers</title>
		<link>http://www.chrisbrenton.org/2009/12/weekend-challenge-answers/</link>
		<comments>http://www.chrisbrenton.org/2009/12/weekend-challenge-answers/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 17:01:20 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Packet Decoding]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=722</guid>
		<description><![CDATA[Well its now Thursday so I figured its time to post the answers to last weekend&#8217;s challenge. First, why should you even care about IPv6 if you have not started deploying it? I felt much the same way till I found IPv6 being used as a covert communication channel within a client&#8217;s network. The data [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/12/weekend-challenge-answers/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

