Showing posts with label guest blog. Show all posts
Showing posts with label guest blog. Show all posts

Tuesday, May 3, 2011

Guest Post: Brandon Tansey "Practical Lessons"


Guest blogger Brandon Tansey is back this week to tell us about his experience as a mentee. He also has some suggestions for thing to do with your mentor, including setting up an at-home hacklab, and getting involved in the Security Community.

It's important to be clear that my last post isn't to say that practical lessons aren't great in a mentor/mentored relationship. My discussion with Marisa also included some thoughts I had on the practical aspects of working with a mentor. There were two main points I looked to get across: work with more than one mentee per mentor, and to focus on helping a mentee make the jump from methodology to practice.

As I mentioned, my experience with Dan began when he started giving presentations at the group on campus. After each meeting he would come back to my apartment and work more closely with people who were interested. The setup we have is great! We're fortunate enough to have a Poweredge 2650 humming away in our apartment. We use it to virtualize all sorts of targets and services (ex: PFSense) and to practice taking down some machines. We used a mix of standard virtualized desktops/servers and some premade target distributions (Damn Vulnerable Linux, Damn Vulnerable Webapp, Metasploitable, etc) to bang on. Our setup makes having people over to practice easy, but having a big, loud server isn't the only way to safely practice on live targets. A desktop virtualization program like VirtualBox can be just as good! Boot up a VM with Metasploitable (or whatever you'd like to attack) and you've already got your own mini-hacklab!

Some nights there were more people coming over than others, however there were two of us that made it week after week without fail. There was myself, and there was a junior networking major at Wentworth named Ian Abreu(@Ian_Abreu). Every week (and often in between) we'd meet up to work on something. Working as a trio was great; it allowed the dynamic to become less teacher/student like and more like a group of people working together. Everyone had something to bring to the group.

I understand that not all mentors are able to devote the amount of time that Dan did. The trio is even better in these situations. Having multiple mentees in a group allows for dialogue even when the mentor is busy between talks. The mentees can help each other grow both their passion and technical ability.

The other comment I had for Marisa was one that may have been more specific to my experiences, however I wouldn't be the least bit surprised to find that other students feel the same way. The comment I made was that it's incredibly handy for a mentor to help a mentee make the jump from methodology to practice.

Before meeting Dan I had done quite a bit of reading. I think the most well-known book I read was Hacking Exposed. The book was an incredible way to learn principles. I feel that the main issue I face, however, isn't the principles. I personally had a hard time starting the jump from reading to doing. I felt that I could describe quite a few techniques and how they worked, but if you asked me how to actually do them I'd be stumped. Technology in general moves quickly, however InfoSec seems to move especially fast. It's because of this that a lot of the reading material out there is far outdated by the time people get to reading it. If I was to redo the last year's mentoring experiences, that is probably the one thing I'd change. I think it would've been incredibly handy to slowly step through a particular methodology and really learn how each step translates from theoretical to practical.

There is one final tip that I feel is incredibly important to stress. Regardless of whether or not the pairing is local, getting mentees involved with the InfoSec community somehow is one of the best things you can do for them. Get them on twitter (or to start following the InfoSec crowd), get them on the mailing lists, if possible get them to local meetups and introduce them to people! The InfoSec community is a small one full of incredibly intelligent people. In my experience, many of these people are incredibly open (if not eager) to help people willing to take the time to learn. It is much easier to meet these people when you approach them with someone they already know! The best thing I personally got out of SOURCE was all of the incredible people I met, and I feel that was a direct result of volunteering for the conference which I did through the people I had already met at the local meetups!

Overall, I'm incredibly glad I was able to find a mentor to work with. I'm not Dan, however I feel that Ian and I were able to give him something through working with him as well. I'd personally consider the InfoSecMentors Project a success for simply putting together a few mentors and mentees. Fortunately they're only limited by the amount of people that express interest! I really do advise you give it a try. You'll be incredibly glad you did regardless of which side of the relationship you sign up for!


You can find Brandon Tansey on his new blog at The Wormhole, on his Twitter feed, or on LinkedIn.

Thursday, April 28, 2011

Guest Post: Brandon Tansey "SOURCE Boston & Mentors"


Today, our guest blogger is Brandon Tansey. He is a networking student and is active in the Boston Information Security community. Here is Brandon's post with his thoughts after attending SOURCE Boston.

I'm one of the folks that was lucky enough to make it out to SOURCE Boston this year, and I'm incredibly glad I did. There was a great selection of talks as well as hallway conversations, but there were a few sessions and conversations that stood out to me. The InfoSecMentors Panel and the following social were definitely among them.

The panel was primarily geared towards the mentors, however I found it quite interesting to listen to as a mentee. I feel that working with a mentor shouldn't be a one way street; the mentor should definitely be getting something out the relationship as well! Sitting in on the panel definitely gave me some insights to how mentors (at least the ones on the panel) view working with a mentee and the concerns they had. The panelists often had some differing opinions, however for the most part I didn't hear anything too unexpected. There was one answer that they all shared which shocked me, however: unresponsive mentees. The panelists were three people who are highly regarded when it comes to what they do professionally. There was Chris Gates(@carnal0wnage, Pentester at Rapid7), Andy Ellis(@csoandy, CSO at Akamai), and Allison Miller (@selenakyle, formerly a fraud specialist at Paypal). I was incredibly surprised to hear that even these three were having trouble with mentees not putting in the time. I found this to be a good problem as far as problems go, however. The fact that the program has mentors interested in more active mentees is great!

To backtrack for just a moment, my name is Brandon Tansey(@BrandonTansey) and I'm a sophomore Networking major at the Wentworth Institute of Technology in Boston. I'm enjoying my time at school and it has given me a desire to explore the InfoSec field beyond what the major offers. It's because of this that I began following quite a few of the SecurityFocus mailing lists early fall semester. I came across an email with the subject of "University Plan" on the PenTest list, and that was where my incredible mentor/mentee experience began.

As I was reading the discussion I saw something familiar. One of the people giving advice happened to have been describing the time he spent at Wentworth! I decided to email this mysterious Dan Crowley (@dan_crowley) and ask him a few questions about the school and the security field. After all, who could be better to ask than someone who started exactly where I was and happened to be exactly where I wanted to go? I found out that the answer to that is no one. The first time we spoke, I got the impression that he was even more excited about the hacklab setup my roommate and I have than we were. Within a week Dan started speaking (and would continue to do so weekly) at a club I help run on campus for technology enthusiasts. We'd also head back to my apartment afterwards with a few other classmates who really had an interest in exploring security.

Dan is, of course, incredibly talented when it comes to the technical side of things. What stood out to me, however, was the passion he had for both what he did and helping others learn what he knew. This passion is what immediately came to mind when Marisa Fagan(@dewzi) of the InfoSecMentors Project asked me if there was anything that I had from my work with Dan that I could share. Our discussion covered quite a few topics and some practical tips (which I'll get to in later), but I think the main point I was trying to make was how important that passion is.

I was certainly excited about security by the time I came across Dan (It definitely takes some level of interest to read through all of those SecurityFocus threads!). The passion I have now is on an entirely different order of magnitude, however. I'm also miles ahead of where I was in a technical regard, however I undoubtedly feel the biggest gain I've had has been in my interest of the subject. Without that I never would have done everything I've done on my own. I never would have been able to read the billions (give or take a few) of pages of security texts. I feel it's like the old "give a man a fish" proverb. A mentor can suggest a few vulnerabilities to look for or tools to use and call it a day, or they can help nurture the desire of the mentee to explore for themselves and keep learning between mentoring sessions. One of these will do much more for a mentee when he/she parts ways with the mentor, and I feel that's a large part of what the relationship is about: putting the mentee in a better position to help him or herself grow.

You can find Brandon Tansey on his new blog at The Wormhole, on his Twitter feed, or on LinkedIn.

Friday, June 4, 2010

Guest Blog: Michelle Klinger "And when exactly am I supposed to find time for that?"


Today, our guest blogger is Michelle Klinger. Michelle has spent the last 5 years as a security assessor for Fortune 500 companies. She has joined the InfoSec Mentors program as a way to increase her technical skills and gain a better understanding of the industry.

As I begin to pursue my information security career in earnest I have come to the conclusion that in order to truly succeed in this industry, it requires an inordinate amount of time and energy be devoted to the trade. Now I know what you are saying... DUH! I suppose to be successful in any career one must devote endless amounts of time. I obviously recognize that hard work is required to succeed but I am more curious about the info sec community specifically and how you deal with these pressures.

I use Twitter specifically to connect, interact, and network with the info sec community, and I’ve been lucky enough to make some good friends with what Andrew Hay calls “D List” security professionals. But as I read my tweet stream I am struck by all of the activities these D list, successful, security professionals engage in: giving talks; blogs (both writing and reading); attending conferences; “real job”; side projects; reading security articles; podcasts (both recording and listening to); and attending local security meet-ups. When do you sleep?! I want to know what the secret is for being able to maintain this level of devotion. Does one need to be single? Is it absolutely necessary to have an understanding spouse? Or have you just resigned yourself to the fact that people are going to be disappointed and pissed off that you never have time for them?

Now I’ve committed to taking this seriously to learn as much as I can….I’ve subscribed to various podcasts & blogs; I’ve participated on a few Bsides panels at BSidesSF and even gave my own talk at BSidesBos, wrote my first blog, attended several conferences, co-planning BSidesDFW (shameless plug), and even signed up for InfoSecMentors. And so as I begin to come to the realization that there are not enough hours in the day, I turn to the experts for advice on what I should expect or watch out for? At the very least send me that dohicky thing that is able to make time stand still...


In addition to finding the balance between the daily grind and the extracurriculars, you can find Michelle Klinger working on her latest side project, Security B-Sides DFW.

This B-Sides is an unconference event held in Dallas-Fort Worth on Saturday, November 6, 2010. The committee is still looking for sponsors, and the Call For Speakers is still open.

To show support, tweet "#BSidesDFW November 6, 2010: Don't Mess with Security! http://bit.ly/BSidesDFW"
Michelle Klinger