<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Chris Gerling</title>
	<atom:link href="http://www.chrisgerling.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chrisgerling.com</link>
	<description>Musings of a Security Guru</description>
	<lastBuildDate>Fri, 29 Jan 2010 06:06:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>And back..</title>
		<link>http://www.chrisgerling.com/2010/01/29/and-back/</link>
		<comments>http://www.chrisgerling.com/2010/01/29/and-back/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:06:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=228</guid>
		<description><![CDATA[Yeah sorry about that.  I just sort of left the site go while I was having issues getting it migrated to a VPS.
It shouldn&#8217;t be going down again anytime soon.
]]></description>
			<content:encoded><![CDATA[<p>Yeah sorry about that.  I just sort of left the site go while I was having issues getting it migrated to a VPS.</p>
<p>It shouldn&#8217;t be going down again anytime soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2010/01/29/and-back/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My trip to Portland, OR for the e-fense Helix E103 course</title>
		<link>http://www.chrisgerling.com/2009/04/17/my-trip-to-portland-or-for-the-e-fense-helix-e103-course/</link>
		<comments>http://www.chrisgerling.com/2009/04/17/my-trip-to-portland-or-for-the-e-fense-helix-e103-course/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 21:25:36 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[gcfa]]></category>
		<category><![CDATA[helix]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[mcmenamins]]></category>
		<category><![CDATA[papa haydn]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=225</guid>
		<description><![CDATA[Yeah I haven&#8217;t blogged in a bit.. haha.  I&#8217;ll get around to some updates this weekend.
I just got up after sleeping a good bit of the day.  I had to red-eye it and fly all night to get home last night.
If you didn&#8217;t know, I was up in Portland, OR this week for e-fense&#8217;s E103 [...]]]></description>
			<content:encoded><![CDATA[<p>Yeah I haven&#8217;t blogged in a bit.. haha.  I&#8217;ll get around to some updates this weekend.</p>
<p>I just got up after sleeping a good bit of the day.  I had to red-eye it and fly all night to get home last night.</p>
<p>If you didn&#8217;t know, I was up in Portland, OR this week for e-fense&#8217;s <a href="http://www.e-fense.com/training/">E103 Live Forensics &amp; Incident Response</a> course.  I had a hell of a time actually getting there, it seemed the travel gods just wanted me to suffer, so after an unexpected overnight stay in Dallas on Monday, I made it into the class at 2pm pacific on Tuesday.  I didn&#8217;t miss much, and the fact that I had recently attended the SANS GCFA course made this more of a refresher course with the bonus of getting some goodies.</p>
<p>I was a bit skeptical before about Helix going commercial, but I see who the target audience was with the move, and honestly it looks like the stuff that will be in Pro (due out in May) is worth the subscription cost.  If I recall correctly, dc3dd is the default imaging tool when utilizing the Windows Live Acquisition part of the CD.</p>
<p>Eric Smith was a great facilitator, and the learning environment was great.  I loved the classroom they had setup, there were very few glitches, and the workstations were configured correctly, so diving right into some hands on was very very easy.</p>
<p>Portland is a pretty cool place.  I lucked out and @Jerod on twitter showed me around town Tuesday night.  McMenamins had great beer, and Papa Haydn&#8217;s had the best cake I have ever eaten.</p>
<p>Now to get some more sleep. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/04/17/my-trip-to-portland-or-for-the-e-fense-helix-e103-course/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A blog to blog and stuff.</title>
		<link>http://www.chrisgerling.com/2009/03/16/a-blog-to-blog-and-stuff/</link>
		<comments>http://www.chrisgerling.com/2009/03/16/a-blog-to-blog-and-stuff/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 02:23:38 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[blogs]]></category>
		<category><![CDATA[hackerspace]]></category>
		<category><![CDATA[hackrva]]></category>
		<category><![CDATA[helix]]></category>
		<category><![CDATA[incident_response]]></category>
		<category><![CDATA[SecuraBit]]></category>
		<category><![CDATA[sumolinux]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/2009/03/16/a-blog-to-blog-and-stuff/</guid>
		<description><![CDATA[I never did do my full Shmoo writeup.  Let&#8217;s just say you had to be there, and what happens at hacker cons tends to stay there.  
I passed my GCFA the other week, barely.  Worst I have ever done on a GIAC exam so far, but really was my own fault for [...]]]></description>
			<content:encoded><![CDATA[<p>I never did do my full Shmoo writeup.  Let&#8217;s just say you had to be there, and what happens at hacker cons tends to stay there. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I passed my GCFA the other week, barely.  Worst I have ever done on a GIAC exam so far, but really was my own fault for not tabbing my books out or doing much in the way of studying.</p>
<p>Hackerspace planning is in full swing.  If you&#8217;re local to the Richmond area hit up hackrva.org (currently redirects to hacrva but that&#8217;ll be getting fixed soon) and help us plan <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .  We&#8217;re looking for help in getting organized as a nonprofit and all the things that go along with that.</p>
<p>SecuraBit is rolling along nicely.  We had G Mark Hardy on last week who is always a pleasure to talk to.  I learn so much everytime I run into him.  We&#8217;re having Jayson Street on this week, and the guests just keep coming courtesy of Bart Hopper, who does so much for us in that area.</p>
<p>SUMO Linux will be releasing a beta for the future 2.0 release soon, so we can all get testing and providing feedback in order to make ourselves a bonified Helix replacement and perhaps do a little expansion in the process.</p>
<p>It&#8217;s about time to hit the hay and help the fiancee&#8217; make the bed.  Till next time!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/03/16/a-blog-to-blog-and-stuff/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shmoocon V Quickie Wrap-up</title>
		<link>http://www.chrisgerling.com/2009/02/08/shmoocon-v-quickie-wrap-up/</link>
		<comments>http://www.chrisgerling.com/2009/02/08/shmoocon-v-quickie-wrap-up/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 01:05:44 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[SecuraBit]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[shortpost]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/2009/02/08/shmoocon-v-quickie-wrap-up/</guid>
		<description><![CDATA[We got home about an hour ago, and I must say that was the best Shmoocon I have attended since starting at Shmoocon 3.
I&#8217;ll post a full account of the event later on tonight or tomorrow, but I just want to say that I met some awesome people and I hope everyone had a great [...]]]></description>
			<content:encoded><![CDATA[<p>We got home about an hour ago, and I must say that was the best Shmoocon I have attended since starting at Shmoocon 3.</p>
<p>I&#8217;ll post a full account of the event later on tonight or tomorrow, but I just want to say that I met some awesome people and I hope everyone had a great time partying with us.</p>
<p>See you next year!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/02/08/shmoocon-v-quickie-wrap-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hak5 Episode 425</title>
		<link>http://www.chrisgerling.com/2009/02/04/hak5-episode-425/</link>
		<comments>http://www.chrisgerling.com/2009/02/04/hak5-episode-425/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 19:20:22 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Hak5]]></category>
		<category><![CDATA[Hak5ShowNotes]]></category>
		<category><![CDATA[shownotes]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=215</guid>
		<description><![CDATA[Hey guys, thanks for watching!  I pretty much detailed everything out in the show notes, but if there are any other questions feel free to contact me!
]]></description>
			<content:encoded><![CDATA[<p>Hey guys, thanks for watching!  I pretty much detailed everything out in the show notes, but if there are any other questions feel free to contact me!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/02/04/hak5-episode-425/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2009</title>
		<link>http://www.chrisgerling.com/2009/01/31/january-2009/</link>
		<comments>http://www.chrisgerling.com/2009/01/31/january-2009/#comments</comments>
		<pubDate>Sun, 01 Feb 2009 04:44:56 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ces]]></category>
		<category><![CDATA[Hak5]]></category>
		<category><![CDATA[plague]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=213</guid>
		<description><![CDATA[~16 minutes left in January.
It&#8217;s amazing how fast the first month of a new year goes by.  Those older than me probably recognize this better, but it&#8217;s definitely becoming more noticible as I get older.  One minute you&#8217;re toasting some champagne with your friends and the next, well&#8230; you&#8217;re on the fast track to the [...]]]></description>
			<content:encoded><![CDATA[<p>~16 minutes left in January.</p>
<p>It&#8217;s amazing how fast the first month of a new year goes by.  Those older than me probably recognize this better, but it&#8217;s definitely becoming more noticible as I get older.  One minute you&#8217;re toasting some champagne with your friends and the next, well&#8230; you&#8217;re on the fast track to the next year. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>In any event, this month was pretty interesting.  We started the new year off near Baltimore with friends, and then I went out to Vegas to cover CES with Hak5.  I got the plague while I was there, and unfortunately didn&#8217;t get to do any partying with all the awesome people I met out there.</p>
<p>After recovering from the plague and spending a couple of weekends just enjoying Richmond, I went back down to the HakHouse last night and recorded a segment on USB device tracking, which I owe a great deal of thanks to Harlan Carvey for both his book, and his help in my understanding of the windows registry. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>February&#8217;s looking to be a very interesting month.  Shmoocon this coming Friday, and my birthday 6 days later.  Valentine&#8217;s Day, and then a pretty busy rest of the month.  Looking forward to seeing everyone at Shmoocon and hopefully seeing some new faces.</p>
<p>Peace</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/01/31/january-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecuraBit, CES, Hak5, Life</title>
		<link>http://www.chrisgerling.com/2009/01/05/securabit-ces-hak5-life/</link>
		<comments>http://www.chrisgerling.com/2009/01/05/securabit-ces-hak5-life/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 23:49:51 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Hak5]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[ces]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[gtd]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[SecuraBit]]></category>
		<category><![CDATA[securabyte]]></category>
		<category><![CDATA[show]]></category>
		<category><![CDATA[stuff]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/2009/01/05/securabit-ces-hak5-life/</guid>
		<description><![CDATA[I love my crazy titles.  
Now that I have been out of the Navy 3 months, I have learned precisely how bad my time management skills really are.  It&#8217;s a funny thing really, but something I now know about and aim to fix, though not this week, here&#8217;s the lineup from now till [...]]]></description>
			<content:encoded><![CDATA[<p>I love my crazy titles. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Now that I have been out of the Navy 3 months, I have learned precisely how bad my time management skills really are.  It&#8217;s a funny thing really, but something I now know about and aim to fix, though not this week, here&#8217;s the lineup from now till the end of the month:</p>
<p>- Tonight at 9:30pm EST I will be doing a quick SecuraByte with Rob Fuller (aka mubix), Tom Eston (aka agent0&#215;0 from Security Justice) and geekgrrl (whose name I have just learned is Melissa), and perhaps some others.</p>
<p>- Wednesday is a normal SecuraBit show, with another one likely coming next Wed as well to make up for the holidays.</p>
<p>- Thurs-Sun is CES, which is going to be a very crazy fun time.</p>
<p>- I&#8217;m taking my GCFA exam hopefully a week from Saturday if we can crash at our friends&#8217; place in Norfolk.</p>
<p>- More Hak5 segments, though my next one likely won&#8217;t be filmed until one of the last 2 weekends of the month due to the schedule.</p>
<p>I&#8217;m definitely going to be looking at some time management books, and perhaps trying some of the GTD (Getting Things Done) type stuff.  I waste a lot of my time and although I am firmly a hedonistic creature, there is a point where some goals and tracking them are good for more than work related things.</p>
<p>I want to thank everyone who reads this blog, as seldom as I do update. <img src='http://www.chrisgerling.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2009/01/05/securabit-ces-hak5-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forensics</title>
		<link>http://www.chrisgerling.com/2008/12/18/forensics/</link>
		<comments>http://www.chrisgerling.com/2008/12/18/forensics/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 13:39:53 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[sans]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/2008/12/18/forensics/</guid>
		<description><![CDATA[Just a quick post regarding forensics.
I&#8217;ve gotten some IM&#8217;s and feedback asking for some good links/blogs dedicated to computer forensics.  If you head over to http://forensics.sans.org you&#8217;ll find a wealth of information and many links to forensics blogs/sites.  You can thank Rob Lee of SANS for it.
]]></description>
			<content:encoded><![CDATA[<p>Just a quick post regarding forensics.</p>
<p>I&#8217;ve gotten some IM&#8217;s and feedback asking for some good links/blogs dedicated to computer forensics.  If you head over to http://forensics.sans.org you&#8217;ll find a wealth of information and many links to forensics blogs/sites.  You can thank Rob Lee of SANS for it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2008/12/18/forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hak5 Episode 413</title>
		<link>http://www.chrisgerling.com/2008/12/01/hak5-episode-413/</link>
		<comments>http://www.chrisgerling.com/2008/12/01/hak5-episode-413/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 20:35:06 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Hak5]]></category>
		<category><![CDATA[Hak5ShowNotes]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[helix]]></category>
		<category><![CDATA[live view]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=207</guid>
		<description><![CDATA[Hey guys,
Darren was nice enough to include the full notes I sent to him in the actual posting on Rev3, but here&#8217;s a copy in case you wander over this way.
If you&#8217;re ever in a position where you have to perform forensic imaging duties on a machine, this segment may be useful to you!  The [...]]]></description>
			<content:encoded><![CDATA[<p>Hey guys,</p>
<p>Darren was nice enough to include the full notes I sent to him in the actual posting on Rev3, but here&#8217;s a copy in case you wander over this way.<br />
If you&#8217;re ever in a position where you have to perform forensic imaging duties on a machine, this segment may be useful to you!  The overall goal is to be able to load a forensic .dd image into an environment where you can interact at the user level with it, and perform some initial analysis that may help to paint the overall picture of what happened later on.</p>
<p>Requirements:  A <a title="Helix" href="http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.e-fense.com%2Fhelix%2F&amp;ei=Bko0SdyBDZCm8ASg_cXaCg&amp;usg=AFQjCNGgeGTKTdslU1bw4C9h9lqU308BPw&amp;sig2=S4gDbjMFJN3zag_0h9MiOg">Helix live CD</a> (any of their versions should work, but I recommend 2.0)<br />
Any machine that has an OS which is compatible with VMware<br />
Either a removable drive, or enough free space on a network share in order to push the .dd image out to it.<br />
<a href="http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fliveview.sourceforge.net%2F&amp;ei=REo0SfjBNofcerCS3O4P&amp;usg=AFQjCNGF-gsmXiBjnzSQY5PrOpA2-Qeynw&amp;sig2=r4iwldHmD-0jPMPEEoDyEQ"> Live View</a><br />
Having <a href="http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.vmware.com%2F&amp;ei=I0o0SYzdO6Ce8wTN5unZCg&amp;usg=AFQjCNEvFvErvZHvRukT7j2poj0tjTt3qQ&amp;sig2=Euu343U1UP0CE9UpiO23JQ">VMware</a> Workstation is a plus, but if not, Live View will automatically download and install VMware Server and the DiskMount utility for you, if you so choose.</p>
<p>Helix is a forensic Live CD with loads of tools.  We&#8217;re focused on just the image acquisition part today.  For the most part, the default options are fine, just specify where you are outputting the .dd image to and you&#8217;re on your way!</p>
<p>Install Live View and make sure you either let it install the necessary components, or already have VMware installed ahead of time.  It tends to not like the absolute newest version of VMware Server, so ideally use the older one that it suggests.  Open the .dd image with Live View, and either Start it directly or Generate the config files.  Should you encounter problems with Starting it directly, use the generate config files option and then manually open the .vmx/.vmdk file from within VMware itself.  Don&#8217;t forget to check the settings on the new VM and make sure the operating system is set correctly, the program does not always autodetect it.</p>
<p>In layman&#8217;s terms, this takes the forensic image and converts it to a virtual machine format, so you can interact with it as if you were the user.  It does not write anything to the .dd image at all, but obviously I suggest using this with a COPY of the original .dd image you make of the suspect machine.</p>
<p>Have fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2008/12/01/hak5-episode-413/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digsby</title>
		<link>http://www.chrisgerling.com/2008/11/11/digsby-2/</link>
		<comments>http://www.chrisgerling.com/2008/11/11/digsby-2/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 14:38:01 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[contact]]></category>
		<category><![CDATA[digsby]]></category>
		<category><![CDATA[widget]]></category>

		<guid isPermaLink="false">http://www.chrisgerling.com/?p=205</guid>
		<description><![CDATA[If you happen to IM me on the digsby widget on this site, and I don&#8217;t respond, make sure you use the contact page or email feedback at hak5 dot org.
Thanks!
]]></description>
			<content:encoded><![CDATA[<p>If you happen to IM me on the digsby widget on this site, and I don&#8217;t respond, make sure you use the contact page or email feedback at hak5 dot org.</p>
<p>Thanks!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrisgerling.com/2008/11/11/digsby-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.396 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-03-06 01:25:09 -->
