Charl Van Der Walt

SensePost partners with Paterva to offer improved security intelligence

We’ve been big fans of Maltego and the team at Paterva for a very long time now, and we frequently use this powerful tool for all kinds of fun and interesting stuff, like Using Maltego to explore threat & vulnerability data; Snoopy: A distributed tracking and profiling framework, ‘Scraping’ time servers; Using Maltego to Data Mine Twitter; and even an analyse on the Use of Social Media by ISIS. We go way back with Andrew and Roelof, who was in fact a founder of SensePost, so today we’re super excited to be able to announce a new, strengthened partnership with them under which we have been accredited as an Approved Maltego Solutions Provider. Basically this means the that with Paterva’s help we plan to use the powerful Maltego toolset to become better at our job – that is to provide information and information systems to our customer with which they can make sound security decisions. Here’s the official news:

A new owner for a new chapter

We’re pleased to announce our acquisition today by SecureData Europe. SecureData (www.secdata.com) is a complete independent security services provider based in the UK and was also previously part of the SecureData Holdings group before being acquired by management in November 2012. The strategic acquisition complements SecureData’s vision for enabling an end-to-end, proactive approach to security for global customers by assessing risk, detecting threats in real-time, protecting valuable assets and responding to security issues when they occur.

Honey, I’m home!! – Hacking Z-Wave & other Black Hat news

You’ve probably never thought of this, but the home automation market in the US was worth approximately $3.2 billion in 2010 and is expected to exceed $5.5 billion in 2016. Under the hood, the Zigbee and Z-wave wireless communication protocols are the most common used RF technology in home automation systems. Zigbee is based on an open specification (IEEE 802.15.4) and has been the subject of several academic and practical security researches. Z-wave is a proprietary wireless protocol that works in the Industrial, Scientific and Medical radio band (ISM). It transmits on the 868.42 MHz (Europe) and 908.42MHz (United States) frequencies designed for low-bandwidth data communications in embedded devices such as security sensors, alarms and home automation control panels.

Black Hat Vegas 2013 – Course Summaries

We have an updated breakdown of our BlackHat courses here With the ‘early registration’ discount period coming to an end on May 31, I wanted to provide an overview of what courses we’re offering and how those courses fit together. Please be sure to take advantage of these discounted prices whilst they’re still available. This summary will help you decide which course is best for you… 1. “Cadet” is our intro course. It provides the theoretical and practical base required to get the most of our other courses. Don’t let the introduction title put you off, this course sets the stage for the rest of the course, and indeed fills in many blanks people might have when performing offensive security assessments. We only offer it on the weekend (27th & 28th) but its really popular so we’ve opened a 2nd classroom. Plenty of space available, so sign up!

Charity Drive – Antarctica Expedition

\ Like many businesses we at SensePost are aware of how fortunate we are and and of the many around us who struggle to make ends meet day to day. We have a heart for our community and regularly supported charities and causes that touch us. In South Africa its not hard to find causes to support, but one that’s particularly close to my heart is the Little Lambs Christian Daycare in a township in Cape Town called ‘Imizamo Yethu‘ (The People Have Gathered).

SensePost People News

We’re extremely proud to announce today the promotion of a number of key people here at SensePost. Shane Kemp, Daniel Cuthbert and Dominic White will be promoted to Global Sales Manager, Chief Operations Officer and Chief Technology Officer respectivley and will join SensePost’s senior leadership structures, effective 01 October 2012. The three new c-levels, along with a number of other emergent leaders, will be commencing a training and development program spanning a number of months as they gradually assume their new responsibilities.

Black Hat Training Classes Update

Hey All, We’re about locked and loaded down here in ZA – ready to tackle the looooong journey to Vegas for Black Hat. If you’re headed to Black Hat but haven’t yet booked training there’s still time, so I thought I’d push out a brief update on what’s still available from our stable of courses. As many of our courses have sold out we opened second classrooms and as a result have plenty of space to accommodate late comers!

CREST South Africa? Let’s talk…

First, some background on CREST in the form of blatant plagiarism… CREST – The Council for Registered Ethical Security Testers – exists to serve the needs of a global information security marketplace that increasingly requires the services of a regulated and professional security testing capability. They provide globally recognised, up to date certifications for organisations and individuals providing penetration testing services. For organisations, CREST provides a provable validation of security testing methodologies and practices, aiding with client engagement and procurement processes, and proving that your company is committed to providing testing services to the highest standard.

ITWeb Security Summit 2012

This year, for the fourth time, myself and some others here at SensePost have worked together with the team from ITWeb in the planning of their annual Security Summit. A commercial conference is always (I suspect) a delicate balance between the different drivers from business, technology and ‘industry’, but this year’s event is definitely our best effort thus far. ITWeb has more than ever acknowledged the centrality of good, objective content and has worked closely with us as the Technical Committee and their various sponsors to strike the optimal balance. I don’t think we have it 100% right yet, and there are some improvements and initiatives that will unfortunately only manifest at next year’s event, but this year’s program (here and here) is nevertheless first class and comparable with almost anything else I’ve seen.

Pentesting in the spotlight – a view

As 44Con 2012 starts to gain momentum (we’ll be there again this time around) I was perusing some of the talks from last year’s event… It was a great event with some great presentations, including (if I may say) our own Ian deVilliers’ *Security Application Proxy Pwnage*. Another presentation that caught my attention was Haroon Meer’s *Penetration Testing considered harmful today*. In this presentation Haroon outlines concerns he has with Penetration Testing and suggests some changes that could be made to the way we test in order to improve the results we get. As you may know a core part of SensePost’s business, and my career for almost 13 years, has been security testing, and so I followed this talk quite closely. The raises some interesting ideas and I felt I’d like to comment on some of the points he was making.