Thursday, April 28, 2011

Guest Post: Brandon Tansey "SOURCE Boston & Mentors"


Today, our guest blogger is Brandon Tansey. He is a networking student and is active in the Boston Information Security community. Here is Brandon's post with his thoughts after attending SOURCE Boston.

I'm one of the folks that was lucky enough to make it out to SOURCE Boston this year, and I'm incredibly glad I did. There was a great selection of talks as well as hallway conversations, but there were a few sessions and conversations that stood out to me. The InfoSecMentors Panel and the following social were definitely among them.

The panel was primarily geared towards the mentors, however I found it quite interesting to listen to as a mentee. I feel that working with a mentor shouldn't be a one way street; the mentor should definitely be getting something out the relationship as well! Sitting in on the panel definitely gave me some insights to how mentors (at least the ones on the panel) view working with a mentee and the concerns they had. The panelists often had some differing opinions, however for the most part I didn't hear anything too unexpected. There was one answer that they all shared which shocked me, however: unresponsive mentees. The panelists were three people who are highly regarded when it comes to what they do professionally. There was Chris Gates(@carnal0wnage, Pentester at Rapid7), Andy Ellis(@csoandy, CSO at Akamai), and Allison Miller (@selenakyle, formerly a fraud specialist at Paypal). I was incredibly surprised to hear that even these three were having trouble with mentees not putting in the time. I found this to be a good problem as far as problems go, however. The fact that the program has mentors interested in more active mentees is great!

To backtrack for just a moment, my name is Brandon Tansey(@BrandonTansey) and I'm a sophomore Networking major at the Wentworth Institute of Technology in Boston. I'm enjoying my time at school and it has given me a desire to explore the InfoSec field beyond what the major offers. It's because of this that I began following quite a few of the SecurityFocus mailing lists early fall semester. I came across an email with the subject of "University Plan" on the PenTest list, and that was where my incredible mentor/mentee experience began.

As I was reading the discussion I saw something familiar. One of the people giving advice happened to have been describing the time he spent at Wentworth! I decided to email this mysterious Dan Crowley (@dan_crowley) and ask him a few questions about the school and the security field. After all, who could be better to ask than someone who started exactly where I was and happened to be exactly where I wanted to go? I found out that the answer to that is no one. The first time we spoke, I got the impression that he was even more excited about the hacklab setup my roommate and I have than we were. Within a week Dan started speaking (and would continue to do so weekly) at a club I help run on campus for technology enthusiasts. We'd also head back to my apartment afterwards with a few other classmates who really had an interest in exploring security.

Dan is, of course, incredibly talented when it comes to the technical side of things. What stood out to me, however, was the passion he had for both what he did and helping others learn what he knew. This passion is what immediately came to mind when Marisa Fagan(@dewzi) of the InfoSecMentors Project asked me if there was anything that I had from my work with Dan that I could share. Our discussion covered quite a few topics and some practical tips (which I'll get to in later), but I think the main point I was trying to make was how important that passion is.

I was certainly excited about security by the time I came across Dan (It definitely takes some level of interest to read through all of those SecurityFocus threads!). The passion I have now is on an entirely different order of magnitude, however. I'm also miles ahead of where I was in a technical regard, however I undoubtedly feel the biggest gain I've had has been in my interest of the subject. Without that I never would have done everything I've done on my own. I never would have been able to read the billions (give or take a few) of pages of security texts. I feel it's like the old "give a man a fish" proverb. A mentor can suggest a few vulnerabilities to look for or tools to use and call it a day, or they can help nurture the desire of the mentee to explore for themselves and keep learning between mentoring sessions. One of these will do much more for a mentee when he/she parts ways with the mentor, and I feel that's a large part of what the relationship is about: putting the mentee in a better position to help him or herself grow.

You can find Brandon Tansey on his new blog at The Wormhole, on his Twitter feed, or on LinkedIn.

Tuesday, April 19, 2011

InfoSecMentors at SOURCE Boston

We've been looking forward to April in Boston ever since last year when SOURCE Boston hosted a wonderful mentoring workshop. This week, Wim, Jimmy, and I will be attending the conference and hosting a mentoring workshop of our own! On Wednesday evening, there will be an interactive panel where we invite security professionals interested in the process of mentoring to come and learn about tricks and activities they can do with their mentee. Our panel of experienced mentors will be available to answer any type of questions. We also hope to brainstorm with our audience for new ideas for mentorship activities, like Open Source projects, CCDC, public speaking, and more.

Afterwards, it's the InfoSecMentors Project One Year Anniversary! We're inviting everyone out for drinks/snacks and networking with the mentors and mentees of the project. Look for more information in your SOURCE Boston schedule brochure.

The InfoSecMentors Project is going to be very active this year! Be sure to follow us on Twitter, @infosecmentors, to get the latest on our plans for scholarships, publications, and the party at Brucon!

To hear us discuss all of this, and much more, (more than you could ever want!!) listen to my interview with the EuroTrash Security Podcast Episode 20.

-Marisa

Thursday, April 7, 2011

My SOURCE Boston Walkthrough

Let me introduce myself real quick, I'm Jimmy Vo and I've been a mentee in the InfoSec Mentors program for about 10 months now. I'm a recent Computer Science graduate and working my first year professionally as a systems analyst. I'm looking forward to going to my SOURCE Boston since it will be my first conference. I just wanted to do a walk through of some of the talks and workshops I'll be attending. If you see me, please say Hello.

Every single talk and session I’ve seen for this years SOURCE looks amazing. There were a few talks that popped out on the schedule. Of course, I wish I could attend every talk.

Bringing Sexy Back: Defensive Measures That Actually Work
Paul Asadoorian, Founder & CEO, PaulDotCom Enterprises
April 20, 11:00am-11:50am

This talk focuses on implementing defensive measures that can mitigate and/or slow down attackers using many technologies. These technologies include honeypots, scripts, and traps. This talk goes beyond traditional defensive measure that do not work anymore. I’m looking forward to this talk because I’m a big fan of the PaulDotCom podcast and Paul and the rest of his crew are as entertaining as they are knowledgeable when it comes to information security.

In the land of the blind, the squinter rules
Wim Remes, Ernst & Young (@wimremes)
April 20, 2:30pm-3:20pm

This talk focuses on security visualization, which a topic that my Mentor and I have talked a few times about. Visualization is an easily digestible way to present data to colleagues and executives. This talk by Wim will cover the basics of visualization and then elaborate on gathering information using Davix and Google Chart API.

Getting Stuff Done: How to work with the rest of the business
Andy Ellis, Senior Director of Information Security, Akamai
April 20, 4:00pm-4:50pm

This should be a very useful and interesting talk. In many organizations information security importance is not totally understood. Sometimes it’s very difficult for technical people to work with other business units and co-workers. It took me a while to figure out operational people don’t care for the technical background and jargon, they just want to know if the systems working. I’m hoping to learn some information on working more cohesively with other business units.

Selling Security Without Selling Your Soul
Aaron Cohen, Managing Partner, MAD Security (@aaronco)
April 20, 5:00-5:30pm

I’m very excited about this talk Aaron is giving. It’s evident that security is not widely and truly embraced as it should be. I’m personally very excited with this talk because I’m always trying to get management buy in and project sponsorship for security initiatives.

InfoSec Mentors Workshop
April 20, 5:30-8:30 in The Constitution

This workshop is to celebrate the 1 year anniversary of the InfoSec Mentors program/project. I hear there’s going to be good food and a lot of fun. I’m excited to talk to other mentors/mentees. I also look forward to sharing my experience at the workshop.

Between 5:30 and 6:30 there will be an InfoSec Mentors panel that will be discussing mentoring tips and tricks. The Panel will focus on making great mentors even greater. The panel will consist of many professionals, InfoSec veterans, and speakers to share their experience and knowledge to build mentors.

After the InfoSec Mentors Panel there will be a mixer at 6:30-8:00. During this time mentors and mentees will have time to meet and party! Also there’s an open bar and food, automatically a good time. I’m looking forward to talking to other mentors and mentees to see some other perspectives on the program.

Across the Desk: Different Perspectives on InfoSec Hiring and Interviewing
Lenny Zeltser, Security Consulting Director,Savvis & Faculty Member, SANS Institute (@lennyzeltser) & Lee Kushner, President, LJ Kushner & Associates (@ljkush)
April 21, 10:00-10:50am

I always look forward to the content on Lenny Zeltser and Lee Kushner’s blog. The talk focuses on very important perspectives from the candidate and the employer. There is further discussion on important aspects such as resumes, job descriptions, interview communications and compensation. This is an extremely relevant talk for me since I’m a mentee trying to get into the InfoSec field.

So You Got That SIEM. Now What Do You Do?
Anton Chuvakin, Principal, Security Warrior Consulting (@anton_chuvakin)
April 22 - 11:10am-12pm

This talk by Dr. Anton Chuvakin helps navigate the challenges of deploying SIEM. Dr. Chuvakin shares some best practices and insight on how to achieve SIEM success. I’m interested in this talk because I’ve recently have been following Dr. Chuvakin’s blog which covers topics such as log management and SIEM. I’ll also be working with SIEM solutions in the near future.

Wednesday, March 16, 2011

The InfoSecMentors Project Essay Contest

The InfoSecMentors Project is giving away one ticket to Notacon 8 by having an essay contest. Each entrant should write an essay of less than 400 words about the following topic:

"Pretending I am your supervisor, write me an email requesting leave to attend a conference. Include reasons why attending conferences are valuable to the organization, and what you hope to learn from this hypothetical conference."

Submissions will be judged by an independent professional manager who makes decisions like this one. The submission that is most convincing and appropriate for a professional situation wins!

Email submissions to marisa@infosecmentors.com. Anyone can enter. The ticket will be available at will call. Contest ends April 8th 2:00pm ET. Winner announced April 9th.

Notacon is April 14-17 in Cleveland, OH. http://www.notacon.org

Tuesday, December 28, 2010

Guest Interview: Hadi El-Khoury and Jimmy Vo "Mentor & Mentee Q&A"


Today, our guest bloggers are Hadi El-Khoury and Jimmy Vo. Hadi and Jimmy are participants in the InfoSecMentors Project as mentor and mentee, respectively. This pair has been kind enough to keep us posted on their progress in the mentorship via updates on Twitter, and they have sent us the interview below where they both weigh in on several questions relating to mentoring in Information Security.

1. How long have you been in the program?

Jimmy: Hadi had indicated that we’ve been in the InfoSec mentor program for about 6 months. Time flies when you’re having fun.

Hadi: Indeed, mentoring Jimmy has been so enjoyable since he's keen on pushing forward in real life the new ideas and concepts we've been discussing.

2. What are your backgrounds?

Jimmy: I am a recent college graduate from Richard Stockton College of New Jersey with my B.S in Computer Science/Information Systems, specializing in an Information Systems concentration. The Information systems concentration was more business orientated, which I found helpful already. I’ve worked part time help desk positions during my undergrad studies. I’ve started my first full time position as an IT Systems Analyst for a small business. I’ve always gravitated towards information security and had an interest in hacking. Most of my undergrad research was centered on information security. I’m currently attending Boston University for my M.S in Computer Information Systems – Security Concentration.

Hadi: I hold a post-graduate degree in Network and Information Systems Security from the French Ecole Nationale Supérieure des Télécommunications. Prior to that, I graduated from the Beirut School of Engineering ESIB with a specialization in telecommunications. I am currently a Security Consulting Manager. For the last ten years, I've been dealing with information security and business continuity subjects on technical, organizational and business levels in line with ISMS (Information Security Management System) implementation while taking advantage of quality and business process management aspects for large financial institutions and critical private operators across Europe and the MENA region.

3. What were the main logistical challenges?

Jimmy: Hadi resides in Paris, France so there is a six hour time difference. Despite the time difference we meet weekly via Skype. We usually chat for about an hour to an hour and a half about various topics which I’ll go into detail later.

Hadi: Indeed, since it's often past midnight Paris time when Jimmy and I meet through Skype, I have to keep a Coke can by my side to regain some energy after a long day at work.

4. What were the covered topics? (Hard Skills)

Jimmy: One of my main focuses is business continuity planning. We developed a plan to create a business continuity plan which involved business process modeling, dealing with vendors in regards to SLA, coming up with metrics, determining risks, and various other BCP related topics.

We also discussed ways to improve an IT infrastructure, such as concepts like ITIL and other ISO standards. We also discussed various information security topics which deal with metrics, creating security awareness, OS hardening, integrating security into BCP, web application firewalls and securing the SDLC.

Hadi: I am always stressing the importance of bridging the gap between the various disciplines governing IT, HR, business process modeling, information security, business continuity, risk analysis, to name of few.... Information security and business continuity are transversal by essence and should be dealt with as such.

5. What skills categories were covered? (Soft Skills)

Jimmy: A great amount of emphasis is focused on developing soft skills that are essential to my success. We discussed effective communication with other business units. Hadi discussed the importance of working across different “silos” in order to assist in my organization’s success. There was discussion on persuasion and negotiation techniques. We talked of project management techniques to prevent project failures. Our mentorship was more than being technically able; it was about being approachable and tightly integrating technical initiatives within an organization.

Hadi: The best "geek" in the world will remain unnoticed if he doesn't possess a minimum of soft skills, namely the ones just mentioned by Jimmy. When it comes to information security and business continuity, organizations are so reluctant to change their approach that the battle won't be won unless a significant load of soft skills is invested. To support this, I share the following quote from Wall Street Journal Deputy Managing Editor Alan Murray as he was discussing some of the lessons new managers can learn from his new book, "The Wall Street Journal Essential Guide to Management." It reads: "Even best-managed companies aren't protected from this destructive clash between whirlwind change & corporate inertia". IMHO, corporate inertia will exclusively be defeated by soft skills.

6. What was the used approach? (use cases, transversality, feedback, ...)

Jimmy: From my perspective, Hadi has coached me rather than taught me. We didn’t spend our Skype sessions on going over step by step of configuring an intrusion detection system. Our discussions are at a higher level, which worked very effectively for me. I can just read a manual or Google a tutorial on deploying an IDS. In the contrary, I can’t read a manual on convincing management on the requirement of an IDS. Sometimes Hadi will assign me “assignments” which we go over during the following meeting. We also discuss interesting InfoSec related articles and try to apply them.

Hadi: In addition, I'll just mention the mindset changing "Security by Analogy" approach. Readers can find an excellent example at the ISECOM website here: http://isecom.securenetltd.com/jack.1.0.en.pdf. I personally love the Electrician example, since it constitutes IMHO the very basic foundation of Information Security and Business Continuity.

7. What were the quick wins? (ROI, ...)

Jimmy: One of the quickest wins was learning how to deal with salary negotiations. This was a skill that wasn’t taught in college. In the end, I was able to negotiate for more benefits. I was able to implement some initiatives for my organization with the help of Hadi. I see the wins every day at my workplace because of the knowledge and coaching I’m receiving.

Hadi: Every Skype session with Jimmy is a quick win by itself since his motivation remains constant and his open mindset is ready to bust a new corporate silo. Jimmy is trying hard to tackle things properly each day despite corporate inertia. These are valuable assets for any wannabe Infosec practitioner.

8. What are the induced projects?

Jimmy: My experiences beginning my professional career and discussions Hadi had motivated me to start a blog called Above Technical (.com). There are many technical blogs that focus on the mechanics of technology and/or information security. These skills are very important but the soft skills to communicate with others in an organization are even more important. The blog is focused on what I learn and the tips I’ve gathered in hopes to post some useful content for others.

Hadi: Besides naturally contributing to Jimmy's new blog, I'm evaluating the feasibility of a larger scale mentoring program that takes advantage of the InfoSecMentors experience along with online news aggregators like the http://coaching.sekimia.com one.

9. What's new on your bookshelves?

Jimmy: The newest book I’m reading is Yes! 50 Scientifically Proven ways to Be Persuasive by Noah J. Goldstein, Steve J. Martin, and Robert B. Cialdini. It’s a book Hadi had recommended for me.

Hadi: Jimmy introduced me to the Toastmasters International website. I'm looking forward to delving into their leadership concepts.

You can find Hadi El-Khoury on LinkedIn and Twitter.
You can find Jimmy Vo on Twitter and at his blog, AboveTechnical.com.

Monday, December 13, 2010

Guest Post: Michelle Klinger "Interview with a Mentee...Mentee T"

This is the continuation in a series of interviews with both mentees and mentors on their experience with InfoSec Mentors to date. Individuals have had to have been paired up for at least two months and I also chose to keep the participants anonymous as I thought I’d receive more honest answers, both praise and critique of the program. And with that I introduce an interview with a mentee.....Mentee T:

Q: What was your reasoning for engaging an infosec mentor that you were not able to do on your own?

A: To be honest, it was the experience really. I was looking for a way to broaden my horizons, and talk to all the people I could. I'm relatively new to the community, and one of the most important things that I've found, as well as the most rewarding, is just to talk to people. When I heard about the starting of the project, I was one of the first to pitch it to others.

Q: Prior to being matched, had you known of your mentor either personally or through social media forums? Were you hoping for someone “well known” in the social infosec social circle?

A: I was definitely aware of my mentor, and I think my mentor and I had mentioned each other on twitter once or twice, but had never actually conversed. Was I hoping for someone well known? I had no preference, really. One of the most important things about a project like this is coming into it with an open mind. Particularly as a mentee, you're really after someone who is well, smarter than you. So you have to throw out a lot of your preconceived notions and just go with the flow. (Also, wow, that was incredibly hippie-ish.)

Q: Was gender a concern when envisioning who you’d be paired with?

A: Not in the slightest. There are a lot of infosec chicks who are significantly smarter than me, and a lot of dudes who are as well. Like I said above, it was really about making the connections and conversations.

Q: Has your mentor suggested or encouraged you to engage in social media (i.e. Facebook, Twitter, and LinkedIn)?

A: I'm actually more active on social media than my mentor. Mentor did make a point to remind me to be careful what I say out there, but that wasn't much of a stretch more than what I already do. It's an often forgotten art, the act of not spewing every little thought on to the interwebs. Actually, if you watch my stream really closely, you'll see me tweet something, then within a minute or two, delete it after some thought.

Q: Was your pairing public via social media (i.e. Facebook, Twitter, LinkedIn) either by you or your mentor? What was the reasoning behind the decision?

A: It was actually kind of a game to see if people could figure it out. Even about 6 months or so later, once we had pretty well, if not officially ended the mentor/mentee relationship, that some folks were still trying to catch hints. But we never officially made it public. Just never felt the need, I suppose. Now, though, I wonder if that might have put some necessary pressure on the relationship.

Q: Did the initial meeting/conversation meet expectations? What did that initial communication entail?

A: The initial conversation actually threw up some red flags for me. Our initial introduction was through email (we didn't meet in person until BH/DC), and I went ahead and took the lead, since every conversation should be a two way street, by sending a few questions in my mentor’s direction. Just a few things like how mentor got 1st infosec start, what some of my mentor’s day to day duties and such are, and a few other questions just to get to know my mentor better. And while my mentor acknowledged that emails were received, I didn't receive a full response to those questions for about 2 weeks.

Understandably, that's a little rough on the start of what's supposed to be a back and forth relationship, just by definition of a mentor/mentee relationship. I understand being busy, I was in the process of writing and preparing a talk myself, but this definitely started us off on a rocky footing.

Q: Have you made any major changes or decisions based on advice or direction from your mentor?

A: Well, I'd like to say I have, since I received such advice as "Stay in school." "Don't let your ego get ahead of you." But I don't know that those are really personally specific, so I guess the answer is no.

Q: Were you given any “homework” or assignments to complete and did you actually do them? Did you see value in the tasks assigned?

A: In an odd turning of the tables, I was actually the one issuing homework. I was looking for feedback on my talks, and my topics, so I assigned my mentor to watch the recordings. However, I don't think that was ever done, so I suppose there wasn't much value from the assignment if it never got done.

Q: Do you feel the mentor you were paired up with was an accurate match?

A: That's a hard, hard question to answer. I think we had some similarities to be sure, and since I still don't have much of a direction in mind, just getting to know someone new was kind of rewarding. However, I am still definitely disappointed, thinking about what could have come out of it. Even meeting in person never lit much of a fire. This is an organic thing, it has to be nurtured and grown, which requires effort on both sides of the table. If that never happened, nothing ever grew, and then I don't know that we could call the match accurate. The important thing, though, is that I learned something from this, even if I'm not totally sure what I'm it is quite yet.

Q: If you could re-do any aspect of your interaction with your mentor to date, what would it be and why?

A: That's a loaded question, particularly after my comments above. Is there stuff that I would change? Hell yes. I'd love to have gotten to know my mentor a little better. I wish we could have shared a bit more than the IM conversations and a few hours of surface chat at BH/DC. I was in an area where I was trying to make some decisions and more than a line or two would have been greatly appreciated.

However, I don't want my story to be a discouragement. More a...disclaimer, I think. As you go into your mentorship/menteeship, be aware this is definitely a relationship. It has to be a two way street, or this isn't going to work. Take a look at your time commitments before joining the program. This whole post could have been avoided early on, if my mentor had waited until a period where mentor had a little more time on his hands. And not even a whole lot, but enough to answer an email every few days. Just something to think about…..


Looking for other mentors/mentees...If you'd like to be interviewed, please contact me at securityindepth at gmail dot com

Monday, November 22, 2010

Guest Post: Michelle Klinger "Interview with a Mentee...Mentee Y"

As previously mentioned, this is the continuation in a series of interviews with both mentees and mentors on their experience with InfoSec Mentors to date. Individuals have had to have been paired up for at least two months and I also chose to keep the participants anonymous as I thought I’d receive more honest answers, both praise and critique of the program. And with that I introduce an interview with a mentee.....Mentee Y:

Q: What was your reasoning for engaging an infosec mentor that you were not able to do on your own?

A: I'd been working to transition into the pen-testing field but without direct experience it was difficult to get past initial interviews. I sought a mentor to help me identify the areas I was lacking and suggest how I could fill the gaps in my experience.

Q: Have you’ve ever had a mentor before? Was it organically developed or had you been a part of other mentor programs?

A: I've had mentors off and on throughout my life. In every case they were organically developed and made a huge contribution to my success at the time.

Q: Prior to being matched, had you known of your mentor either personally or through social media forums? Where you hoping for someone “well known” in the social infosec social circle? Why or why not?

A: Yes, I'd seen my mentor present at Shmoo earlier this year so I knew of them already. The fact that he is well known only helped me to more quickly understand how he could contribute and help me towards my goals. The "well known" factor wasn't a requirement for me though. As long as the mentor had the experience to understand what I was looking for and help me down that path, that's all that mattered to me.

Q: Was gender a concern when envisioning who you’d be paired with? Why or why not?

A: No, gender was of no concern to me. I've met plenty of highly experienced people in this field and their gender had little or nothing to do with that success. As long as we could communicate and work together that's all I cared about.

Q: Has your mentor suggested or encouraged you to engage in social media (i.e. Facebook, Twitter, and LinkedIn)? Have you? Why or why not? If you have, has aided in your original goals?

A: I was already engaged in most of the social media options when I was matched so no, he didn't suggest any of those. Of all the social media I use, Twitter has been the most valuable for keeping pace with what's happening as it's communicated by the infosec industry.

Q: Was your pairing public via social media (i.e. Facebook, Twitter, LinkedIn) either by you or your mentor? What was the reasoning behind the decision?

A: Yes, I know I tweeted about it immediately although I waited to say who my mentor was until after we'd exchanged an email or two.

Q: Did the initial meeting/conversation meet expectations? What did that initial communication entail?

A: It wasn't what I expected but that wasn't a bad thing either. I learned that my mentor and I shared many similar experiences which helped me to understand that my goals were reasonable. Basically, "If he could do it, then I had a shot too".

Q: Have you made any major changes or decisions based on advice or direction from your mentor?

A: Absolutely. His experience gave me an alternative path to consider for my job search. Ultimately this is what led me to my current new job that I've had for about a month now. It's not a pen-testing role like I'd been targeting but it turns out I'm probably 10x better at being an analyst than I would have been a pen tester. Plus, the company I'm with now has lots of opportunities internally when I'm ready to move into other areas, including pen testing.

Q: Were you given any “homework” or assignments to complete and did you actually do them? What are a few examples of assignments given? Did you see value in the tasks assigned?

A: He definitely gave me recommendations for web app lab configurations. It wasn't homework though and unfortunately I've never taken the time to set up the suggested lab systems. I do see value in this and when I do reach this point I know my mentor will still be there to help with any questions that may come up.

Q: Do you feel the mentor you were paired up with was an accurate match? Why or why not?

A: Yes, my mentor was an accurate match based on the information I provided in my questionnaire. The end result was a path I hadn't considered taking and was different from what I thought I was looking for but a win is a win.

In the end, the InfoSec Mentor experience was less what I was looking for, and more of what I needed. If you're open minded enough to see this and respect it for what it is, then it's a priceless lesson and an invaluable experience.

If you’d like to be interviewed, please contact me at securityindepth at gmail dot com