  7. Studying for the CEH and looking for some free study questions? If you haven’t seen the Skillset exam prep engine, it’s definitely worth checking out. Skillset offers thousands of free practice questions for the CEH exam and a wide array of other IT certs. The questions for the CEH are categorized by the specific skillsets required for the exam, so you know where you are strong and where you need to study more. Examples include cryptography, penetration testing, social engineering and more. Skillset gives you ultimate control over your studies and can drill on any single, or multiple skills, by creating custom tests via the test builder. Questions are further sub divided into difficulty level: beginner, intermediate and expert. While you practice, Skillset uses a fairly accurate algorithm to determine when you are actually ready to sit for the exam. How would you like to not guess, but KNOW that you are ready to sit for an exam in advance? Best of all, it’s all free. Not freemium, not almost free, not free now but pay later, but free. Check out the CEH practice questions here: CEH Exam and CEH Practice Questions - Skillset --------------- CEH Practice Exam: Thousands of Test Questions - InfoSec Institute
  19. Ever since October 2013, when the FBI took down the online black market and drug bazaar known as the Silk Road, privacy activists and security experts have traded conspiracy theories about how the U.S. government managed to discover the geographic location of the Silk Road Web servers. Those systems were supposed to be obscured behind the anonymity service Tor, but as court documents released Friday explain, that wasn’t entirely true: Turns out, the login page for the Silk Road employed an anti-abuse CAPTCHA service that pulled content from the open Internet, thus leaking the site’s true location. Tor helps users disguise their identity by bouncing their traffic between different Tor servers, and by encrypting that traffic at every hop along the way. The Silk Road, like many sites that host illicit activity, relied on a feature of Tor known as “hidden services.” This feature allows anyone to offer a Web server without revealing the true Internet address to the site’s users. That is, if you do it correctly, which involves making sure you aren’t mixing content from the regular open Internet into the fabric of a site protected by Tor. But according to federal investigators, Ross W. Ulbricht — a.k.a. the “Dread Pirate Roberts” and the 30-year-old arrested last year and charged with running the Silk Road — made this exact mistake. As explained in the Tor how-to, in order for the Internet address of a computer to be fully hidden on Tor, the applications running on the computer must be properly configured for that purpose. Otherwise, the computer’s true Internet address may “leak” through the traffic sent from the computer. And this is how the feds say they located the Silk Road servers: For many Tor fans and advocates, The Dread Pirate Roberts’ goof will no doubt be labeled a noob mistake — and perhaps it was. But as I’ve said time and again, staying anonymous online is hard work, even for those of us who are relatively experienced at it. It’s so difficult, in fact, that even hardened cybercrooks eventually slip up in important and often fateful ways (that is, if someone or something was around at the time to keep a record of it). A copy of the government’s declaration on how it located the Silk Road servers is here (PDF). A hat tip to Nicholas Weaver for the heads up about this filing.
  20. Now that we have the C10K concurrent connection problem licked, how do we level up and support 10 million concurrent connections? Impossible you say. Nope, systems right now are delivering 10 million concurrent connections using techniques that are as radical as they may be unfamiliar. To learn how it’s done we turn to Robert Graham, CEO of Errata Security, and his absolutely fantastic talk at Shmoocon 2013 called C10M Defending The Internet At Scale. Robert has a brilliant way of framing the problem that I’ve never heard of before. He starts with a little bit of history, relating how Unix wasn’t originally designed to be a general server OS, it was designed to be a control system for a telephone network. It was the telephone network that actually transported the data so there was a clean separation between the control plane and the data plane. The problem is we now use Unix servers as part of the data plane, which we shouldn’t do at all. If we were designing a kernel for handling one application per server we would design it very differently than for a multi-user kernel. Which is why he says the key is to understand: => The Secret to 10 Million Concurrent Connections -The Kernel is the Problem, Not the*Solution - High Scalability -
