Homepage

Free resources for programming, hacking & cyber security help

Welcome to Hacker Hours!

This is a community for young programmers all over the world to share experiences, cooperate and have fun. As a wiki, this site allows anyone to join and contribute content. All are welcome! Before you post anything, be sure to read about our licensing.

You may want to start by checking this list of our members’ projects.

If you’re still learning about programming, check our programming language articles, with advice and links. Or perhaps you’d rather read about our thoughts on Good or Bad programming style?

A returning member, or just curious by nature? There is a Resources page with more …resources.

Feeling lost? Check our latest articles.

  • FISMA Law vs. Home Email Server

    Working for a federal agency that has IT functions regulated by public law and running an email server from home to use for agency business…

  • APT vs. OODA Security Controls

    Advanced Persistent Threat (APT) is a kind of attack comes from a team with advanced skills, deep resources, and specific targets. They use advanced tools…

  • Simple Secure Configuration Management

    Configuration Management (CM) has some key controls and processes concentrated in the middle of the SDLC where configuration settings and the configuration baseline are recorded,…

  • Continuous Monitoring Misunderstood

    Network security monitoring includes intrusion detection, audit log correlation and analysis and other methods of detecting failures of our network protections. Continuous monitoring is not…

  • Wireless Restrictions

    AC-18 WIRELESS RESTRICTIONS (NIST SP 800-53) The organization: (i) establishes usage restrictions and implementation guidance for wireless technologies; and (ii) authorizes, monitors, controls wireless access…

  • Contingency Plan

    Policy Business Impact Assessment (BIA) The BIA is a critical piece of the CP that establishes requirements for the strategy and procedures in the rest…

  • Incident Response

    Federal agencies are required by law to report incidents to the US Computer Readiness Team (CERT) office in DHS and must have a formal incident…

  • Plan of Action and Milestones POAMs

    A POAM is a plan that describes specific measures to be taken to correct deficiencies found during a security control assessment. The POAM should identify:…

  • Rules of Behavior

    Any information security policy and Site Security Plan (SSP) should contain a section known as “Rules of Behavior” that establishes appropriate use and behavior of…

  • Policy and Procedure

    Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that…