The best style is the style you don't notice. – Somerset
Maugham
Sunday, August 19, 2012
Thursday, August 16, 2012
The Small Satisfactions of Writing by Aaron Michael Ritchey
Okay, I
love to complain. No, I’m really, really
good at complaining. Let me give you an
example. I go into a bookstore, and I
see all the books, and I know I’ll never be up on the bestseller’s list and
every book I write will eventually end up at the local Goodwill, heavily
discounted. Every minute I write I’m
wasting my time.
See, I can
complain. Give me perfection, and I will
find the blemish. Give me plain, old
vanilla life, and I will despair.
And yet,
more and more, I’m finding satisfaction in normal, everyday life and normal,
everyday writing. No, really. I’m tired of complaining. I’ve done enough. I’m going to practice gratitude and
satisfaction. Why not? It’s far more pleasant.
Writing
and finishing books is deeply satisfying, and yeah, chances are I won’t ever be
as popular as One Direction, the popular band.
While I probably won’t ever be a teen sensation, that doesn’t make what
I do less satisfying.
But I love
the idea of being a teen sensation. Have
you heard of Aaron Michael Ritchey? Of
course, he’s a teen sensation! Like
Stephenie Meyer.
The only
difference between me and Stephenie Meyer is scale. We both write. We both finish books. I just got published with a small press. She gets published with the big boys. She’s wildly popular and I write in
obscurity. But the act of writing is the
same for both of us.
And in
some ways, the more obscure I am, the more freedom I have. When I was unpublished, I could write
whatever I wanted and I wasn’t saddled with the marketing and work of
selling. Now, since I’m with a small
press, I don’t have the pressures that Stephenie Meyer has. Can you imagine trying to follow-up Twilight? Can you imagine continuing to write when huge
sections of the population think you are a crap?
I don’t
have all that. I write my books. I am satisfied, and yet, I yearn for more
because I’m human and humans love to yearn.
Yearn and burn, baby.
But the
secret to this whole thing? Love the day
you are in. Love the book you are
writing. Find satisfaction in the little
stuff. Because in the end, it will all
be over soon enough. For me. For Stephenie Meyer. For you.
Why
complain on this short trip to the grave?
Might as well be content on the trip.
About the
Writer: YA
Paranormal author Aaron Michael Ritchey has penned a dozen manuscripts in his
20 years as a writer. When he isn’t slapping around his muse, Aaron
cycles to look fabulous, works in medical technologies, and keeps his family in
silks and furs. His first novel, The Never Prayer, hit
the streets on
March 29, 2012.
Tuesday, August 14, 2012
Column: Turn Off That Editor! by Karen Albright Lin
I’ve got to get through it, that first attempt at getting my story down, living as my characters live, moving toward an inevitable yet unpredictable end. Those shitty first drafts, as Anne Lamott calls them in her brilliant book, Bird by Bird. All the workshops, all the books, all the talented and successful writers I know tell me to cage up the editor and whip through the sentences, to puke out the chapters, clean up the mess later. My brain, however, thinks more like an editor. I spit out a sentence, stop, fix that sentence, spit out more, notice that I didn’t backload a paragraph with the most powerful sentence, then the grammar checker is indicating I need to look at a word back where I wrote that clever reversal. Then there’s that pesky run-on sentence…I’m not talking about scrolling back a few pages to edit and refresh my memory, then moving forward into my next chapter. I’m talking about scrolling back each paragraph and, on a particularly critical day, scrolling back each sentence. Yes, I’m an obsessive editor. I’ve always written that way. In fourth grade I did it. Back then I wrote mostly poetry, a very tight and disciplined form. That didn’t help. Next I graduated to a twelve-year-old version of erotica--wish I’d kept some of those scenes to compare to my adult notes. But I digress. Doesn’t it go figure, I’ve reinforced the early analyzing habit by becoming a professional editor.
Some tell me not to worry over it. I’m still prolific, having written almost a dozen screenplays, three novels, a literary cookbook, newspaper and magazine articles, and short stories (some of them erotica--hopefully different than my grade-school imaginings). I wrote all that while raising two boys. Sure, pat myself on the back, but get on with the writing, and slap that hand that continues to go back, go back, go back. As if I just can’t do my book justice without making every sentence perfect as I go. What's up with that?!
To make matters worse, I write my shitty first drafts long hand, scrawling my additions and corrections all over the yellow pad – yellow to boost creativity. Unfortunately, yellow also nourishes my editing fixation. To make matters doubly frustrating, I have the worst handwriting known to the literate world. So my crazy first drafts are often indecipherable. Even to me. I have only my sisters to turn to when I’m puzzled to the point of pop-eyed madness, for they know me so well that they often step in to save my shitty first draft by interpreting my Gs that look like Ss and my Rs that look like Is and my ups and downs and arrows and my bubbles with sentences that are absolutely necessary to the line above or below or up the side and let’s not forget the middle phrase in the run-on sentence near the bottom of the page. This is no exaggeration. It’s a joke between us.
But when I’m working away solo at a restaurant over lunch, it’s not a joke. Sometimes I wish I could ask my waitress just what it was I wrote half a page up. Ten minutes ago. But then they’d think I wouldn’t be able to read the menu and so would bring me the picture menu. If they had one. OK, now my train of thought has drifted from editing to first drafts to penmanship. I think I need to go back and consider giving this blog entry a work out. Yes, the above photo is of a typical shitty rough draft page of mine, taken by my sister Storm Petrel. Is there a 12-step program for this obnoxious inclination?
It’s no use for me to seek advice on what I can do to improve my penmanship; teachers have been trying to help me there since my early erotica days. But I do ask, dear blog visitor, if you have any hints about how I can turn off my editor.
(Originally posted at the Sisters of the Quill blog on February 17, 2011)
Monday, August 13, 2012
August Write Brain: Blogging with Brandon and Bryan
When: Tuesday, August 21,
2012 – 6:30-8:30 p.m.
Where:
Community Room -
Colorado Springs Fire Station 16, 4980 Farthing Drive, Colorado Springs, CO
80906
(Note: The
fire station is set back from the main road, behind Oak Meadows Park.)
Please RSVP:
Note that an RSVP does NOT commit you
to attending, but helps us plan to have enough refreshments and materials on
hand.
Send
RSVP now.
As writers,
Bryan Pedas and Brandon Meyers understand that any author—aspiring or
published—needs to promote themselves, and they firmly believe that
blogging and getting involved in the blogging community is one of the best
tools an author can use for self-promotion. Over the course of the past two
years, they have learned a great deal about the ins and outs of the process and
would like to share the tips that have helped them find success in the
blogosphere.
Specific topics that will be covered are:
• Why it’s important to blog
• Where to blog (for computer gurus and
those who struggle with computers, alike)
• How to find your niche
• How to consistently come up with topics
to blog about
• How to reach out to other bloggers inside
and outside of your blogging community
• Blogger etiquette
• The general dos and don’ts of blogging
Brandon and
Bryan are a pair of fraternal, mostly unrelated twins. Bryan is from just
outside of Denver, Colorado and has never left because of a fear of the
unknown. And Brandon was once from Denver, Colorado but moved to Chicago,
Illinois to pursue his lifelong dream of dodging urban gunfire.
Both brothers
are writers, and between the two they've completed 46 short stories (40 from
Brandon, 1 from Bryan, 5 collaborative) and seven novels, a good half of which
are readable. They co-author the moderately popular blog/web-comic A Beer for the Shower. When they aren't
penning collaborative novels together, you can find them throttling their
livers at the local bar, posting politically incorrect web-comics, or indulging
in one of life's greatest victories: a beer in the shower (separately, we
assure you--get your mind out of the gutter).
Read Bryan and Brandon’s blog, www.abeerfortheshower.com.
Sunday, August 12, 2012
Quote
You know, it's hard work to write a book. I can't tell
you how many times I really get going on an idea, then my quill breaks. Or I
spill ink all over my writing tunic. – Ellen DeGeneres, The Funny Thing Is...
Thursday, August 9, 2012
Things to Remember When Writing Post-Apocalyptic by Shannon Lawrence
You've envisioned a world where some large-scale event has
wiped out hordes of humanity. Your characters are alive in your head,
probably struggling to survive. You can see the blighted landscape all
around you. What do you need to do now?
There are a few things that must be part of your
post-apocalyptic story, or you have no story. Let's take a peek.
1. An
apocalyptic event.
That's right, you can't have a post-apocalyptic world without something that
got them there. What will yours be? Viral, bacterial, natural,
man-made, space-related or nuclear? These are all options, and there are
probably plenty more. Did the swine flu get out of hand? Was it helped
by humanity or just one of those things that happens in nature? Did the
Earth tilt too far off its axis? Did nuclear Hell flame rain down upon
the continents? There must be a reason the people in your story are stuck
in this particular landscape.
![]() |
| Four Horsemen of Apocalypse, by Viktor Vasnetsov. Painted in 1887; Viktor Vasnetsov [Public domain], via Wikimedia Commons |
2. A
time frame. Are they living through the
event or has it already happened? Is it fresh or decades down the
line? You have to know when it happened and what stage humanity is in to
really tell your story. If it happened decades ago, the landscape is
going to be significantly different than if it just happened yesterday.
Quality of life will also probably be very different. If they've been
coping for decades, they probably aren't struggling to find food or water
sources as much as if it just happened and everything is tainted or
burning. If it's a new problem, there will be mostly individuals and
small groups, whereas a length of time may mean there are established
towns/cities.
![]() |
| Stalingrad after the battle; [Public domain], via Wikimedia Commons |
3. A
fully realized landscape.
World building is important in any story, but you need to build this
post-apocalyptic world so that people see your vision of what it looks
like. They must know what your characters' reality looks like. Are
there fires raging? Or is everything underwater? Are there bodies
everywhere? Or has nature reclaimed what once was solely hers? Let
us know what it is your characters are looking at. Make sure it makes
sense for passage of time and the particular event that occurred.
4.
Strong characters. We need to
believe that these people can make it (or not, as the case may be). It
must be a real struggle. We have to care whether they can survive, one
way or another. Maybe we hate this guy so much that we question why he
survived, when better people died. Maybe we love this character and
desperately want to see her rebuild her life. Whichever characters you
have, we must believe in them, and they must have a mission, of sorts.
Does Evil Guy want to take over what remains of the world? Find natural
resources to survive? Or just be left alone? Does Lovely Heroine have
a child to fend for? Is she just trying to find a home she can call her
own? What drives them? What are they trying to accomplish?
This is important in every single kind of story you may write, but don't get so
intent on your world building that you forget your characters.
5. A
purpose. All right, we get it.
The world has ended. The apocalypse has found us.
Whoopty-doo. What is so important about this world that you just have to
tell the story? What are we going to take away from this? I'm not
talking about a moral (necessarily), but just a life story that means something
to us when we read it. A violent post-apocalyptic world, where survivors
are constantly under siege, does us no good if we don't come out of the story
feeling something. Perhaps you want us to know that humanity will always
find a way to thrive. Or that love will always pull someone
through. Whatever it is, make it part of your story.
![]() |
| The aftermath of Hurricane Camille. Ruins of Texaco gas station with Rambler automobile, Biloxi, Mississippi, 17 August 1969 |
There are many elements that are important in a story, but
these are just a few of the top ones to keep in mind when writing a
post-apocalyptic tale. Now that those stories are becoming more popular,
it's important to keep them high quality. Want to read a story that takes
something familiar and turns it on its head, all the while showing us the
strength of humanity and the power of good versus evil? Read Stephen
King's The Stand. Watch Book of Eli for another viewpoint.
There's also The Road, Mad Max, Water World (hey, I'm not saying these are all good), The Postman, Jericho and The Walking Dead
for movies/television shows. For books, this link should take you to a comprehensive list of classic
post-apocalyptic stories. Of course, The
Hunger Games and Forest of Hands and
Teeth should be on there. Also, I recently read Without Warning by John Birmingham, on a whim, and I enjoyed
it. It was more a political/government/military-type book that took on
what happened in those facets – so different than I'm used to for this genre,
but also quite good. I don't know how The
Marbury Lens and The Maze Runner
are qualified, but I'd consider both to be sort of post-apocalyptic. We
really aren't sure with The Maze Runner,
but we get a sense something big must have happened, and in The Marbury Lens, the alternative world
he visits via the lens seems quite post-apocalyptic. Both are excellent
books, though be aware that The Marbury
Lens can be graphic or disturbing, despite being Young Adult.
The short of it is, fully realize your story so we can be
drawn into it, feel for your characters, smell the fires, feel a sniffle coming
on as everyone dies of the Hulk of flu bugs. Watch some of these movies
or read some of the books (or both) and figure out what you like in them, so
you can duplicate that, in a sense.
About the Writer: Shannon Lawrence is a mom of two, a freelance
writer and aspiring novelist. She lives in Colorado Springs and is
inspired by the beauty of Pikes Peak and the Rockies. After years of
letting her writing fall by the wayside, she has recently thrown herself back
into it. Her main focus is fantasy and horror and she has just finished a
Young Adult Fantasy novel. She has also recently discovered a love of
photography and enjoys photographing the breathtaking Colorado scenery and
wildlife, as well as her children. She blogs about writing at
www.thewarriormuse.com.
Tuesday, August 7, 2012
What I’ve Learned on Twitter (in way more than 140 characters) by Cindi Madsen
Any writers out there looking to do more social media? Twitter’s a big
one now. I remember being a little hesitant to start an account. I mean, what
do you do on Twitter? Does everyone really want to know what I’m
eating/thinking/feeling? What I ended up finding was a world of people who like
to talk books and music, plus a lot of other random things, as much as I do.
For this post, I’m going to focus on what I learned about authors and readers.
1. People are different.
Yes, I knew this before. But people have a lot to say about characters
in the books they read, whether they love them or hate them. They fall for
different love interests. They connect with different heroes and heroines.
Sometimes personal experiences will affect how readers react. Sometimes they
pick up a book and hate it, then give it a chance a few weeks later and love
it. So what does this all mean? How does this knowledge help me?
Well, I’ve got a couple books coming out at the end of this year. When
people don’t love my characters the way I do, or my writing style, or the cover,
or the fact I use “the” all the time, I’m going to try not to take it so
personally. I’m not pretending it won’t hurt, but I think knowing that some
people will love it, some people will hate it, and some people will have
mediocre feelings about it, will keep things in perspective. I read an
excellent post from Beth Revis, who talked about how some people don’t like
chocolate, puppies, bacon, or Harry Potter. Great, bestselling books have thousands of 1-star reviews. Remember
that if (or most likely when) you get one. But...
2. Do NOT respond to negative reviews or bash
people who didn’t like your novel.
Trust me, you don’t want to do this. It’s unprofessional, and people
won’t want to read your book, so just don’t. You know how on “American Idol” or
“So You Think You Can Dance?” or whatever competition show you watch, there’s
one person who talks back to the judges and looks like an ass? Do you want to
be that ass? (Hint: No, no you don’t.) The publishing industry is a tight-knit
community. If you offend publishers or agents or authors or book bloggers, your
name will soon be mud and no one will be talking about your actual book. But
they will talk about you and how unprofessional you are.
3. People see your tweets.
Yes, that’s the point. But think about it when you post your 140
characters. Think it doesn’t matter? Tell that to the Greek athlete who posted
something racist on Twitter right before the Olympics. Guess what, she’s out of
the competition now, something she trained for her whole life, all because of one
tweet. Even if you delete it, a simple screen capture will be proof forever.
4. It’s called social media. Be social.
Find common interests with people. Respond to their comments. Interact—do
not just tell people to buy your book. It feels like spam and soon you’ll be
down followers. Before I knew what I was doing, I wasn’t interacting with
people and Twitter was dull. Once I found people to talk my favorite books
with, I finally saw what all the fuss was about. I know different groups, we
have different jokes, and I learn about their lives. That means that Twitter
now takes up some of my time, but since I’ve met so many cool people, I’m okay
with that. I reward myself after writing with some tweeting.
The world’s changed. We now have to be out there, creating our
platform, doing blog interviews, and trying to make a name for ourselves. But
it’s also a great opportunity to connect with people you’d never otherwise
meet. So jump in and have some fun.
And good luck squeezing everything you want to say into 140 characters
or less.
About the Writer: Cindi Madsen sits at her computer every
chance she gets, plotting, revising, and falling in love with her characters.
Sometimes this makes her a crazy person. Without it, she’d be even crazier. She
has way too many shoes, but can always find a reason to buy a new pretty pair,
especially if they’re sparkly, colorful, or super tall. She lives in Colorado
with her husband and three children. Look for her YA novels, All the Broken Pieces with Entangled
Publishing, and Demons of the Sun
with Crescent Moon Press, to be released Fall 2012. More information can be
found on her website: cindimadsen.blogspot.com.
Sunday, August 5, 2012
Friday, August 3, 2012
Column: Writing Boot Camps by Deb McLeod
With so
many writing classes and groups out there, writing doesn’t have to be a lonely
journey. Online classes, in-person classes, MFA programs, critique groups, writers
book clubs, Meetups, conferences: You can find a group or a class to fit any
writing need you might have. You can create your own writing boot camp.
I teach
classes, but I also take them. I read craft books, too. These practices keep me
thinking about the process and challenge me to try new ways to reach writing
goals for myself and my clients.
Over the
course of my coaching career, through the classes I’ve taken and the books I’ve
read, I’ve developed a Boot Camp Process I use with my clients and in my own
work.
The stages
aren’t always clearly delineated and they vary in length from project to
project or person to person. But all
processes can be broken into smaller steps, and writing is a process.
The
breakdown I use for myself and my clients to define the process, is this:
1. Gathering
2. Shaping
3. Editing
4. Publishing
5. Marketing
Gathering
In the
gathering stage I’m researching and playing with ideas. I’m collecting
freewrites and material that may or may not make it into the project. I’m
getting to know what it is I want to say. Here is where I’m looking for classes
and methods that let me play. Sometimes it helps to take a poetry class when
I’m writing a novel. Or to read fiction that isn’t at all like the story I’m
working on. Whatever I do, I step away
from my editing mind and open myself to any possibility. In this stage I do
a lot of freewriting. I avoid any class or group that is going to engage my
editor or the writing rules.
Shaping
The
shaping stage for me is the most rewarding and the most challenging. Here is
where distance becomes important. I peel the story away from myself so I can
see what it is I’m trying to say. Once I begin to see the themes I find it
easier to find the proper structure.
It is in
this stage that many people will turn to critique groups. I don’t advocate critique groups until the editing stage. (See my
blog: Testing Your Voice: Are You Ready for Critique). When you’re in the shaping stage your voice is still
vulnerable to groupthink. So, instead of critique groups, I look for classes
that approach structure. The three-act structure, the journey structure or
specific genre classes will do. Writer’s book clubs are good here, too.
The
gathering and shaping stage overlap for most people. While I’m outlining,
looking at arcs and moving material around during the shaping stage, I’m still
producing and keeping as much playful energy around the project as I can.
Editing
My editing
stage is divided into two segments: combing and editing. Combing is where I go
through the manuscript and smooth out the transitions, check the dialogue,
tighten and polish as much as I can. If
I were going to attend a critique group, here is where I would feel safe
bringing my manuscript to a group. It’s their job to find fault and this is
where it’s appropriate.
Instead of
using a critique group, I send my work to a small number of writing friends whose
work I admire and who are great readers. They read the manuscript individually.
I may or may not edit the work based on their suggestions, but once I receive
their feedback, I comb through the whole manuscript again.
I have not
begun my indie publishing journey yet, but when I do I know I will submit my
work to a professional editor at this point. Even though I’m a professional
editor myself, when it’s my work, there are continuity issues I might not see.
I know my grammar leaves much to be desired. And, everyone makes typos.
Publishing
Once my
manuscript is complete, I move into the publishing stage. In the past, this was
where I attended conferences and made pitches. I sent out letters to agents,
etc. With indie publishing, here is where I will design my cover and upload my
project. I’m starting to see lots of classes that cover this material and all
have great suggestions and ideas for this rapidly evolving industry.
Marketing
Finally, I
begin the long cycle of marketing (which will be the subject of another blog).
But at the
same time, I’m beginning the gathering stage for a new project.
If you
break down your projects into stages, you might avoid that sense of overwhelm
that sometimes happens when you’re tackling a large project. You’ll also be
more aware of what you need to help you through to the next stage.
For more
information on Writing Boot Camps or Coaching, please see www.debmcleod or www.thewritingschool.org.
About the Writer: Deb
McLeod, is a writer, creative writing coach, co-founder
and executive director of The
Writing School. She has both an MFA and a BA in creative writing. She has
been teaching and coaching for over ten years. Deb has published short fiction
in anthologies and journals. She has written articles and creative nonfiction.
Deb has been a professional blogger, tech writer, graphic artist and Internet
marketing specialist.
Wednesday, August 1, 2012
From the Editor: Check Your Ego at the Door
A few days ago, I was perusing writing craft books at an
online retail site, looking for one that would suit my present needs. I clicked on a few that looked promising, read the descriptions, and then,
reluctantly, checked out ratings and reviews given by readers.
I say “reluctantly” because among the thoughtful and useful
comments lurk occasional venomous tirades whose only purpose appears to be inflating
the egos of those writing them. Such postings are usually attached to the one
or two low ratings given to books that otherwise rank highly in readers’
opinions. While I recognize these attacks for what they are, I simply detest
subjecting myself to someone else’s negativity.
One of the titles I looked at fell squarely into this
category: mostly positive 4- and 5-star reviews with a solitary one-star
review. And sure enough, the person behind the one-star felt the need to
declare that the author, a long-published journalist with many credits to his
name, “lacks writing skill.” Curious, I dug a little deeper and discovered this
“reviewer” had nothing positive to say about any of the three writing books
he/she has “reviewed.”
These kind of commentaries really do nothing except make the person who’s writing them look bad. Even if the writer has a valid gripe against an author, or the publishing industry at large, hiding behind a fake name to spew hateful comments destroys any credibility the argument might have.
These kind of commentaries really do nothing except make the person who’s writing them look bad. Even if the writer has a valid gripe against an author, or the publishing industry at large, hiding behind a fake name to spew hateful comments destroys any credibility the argument might have.
Writing is hard work. Successful writers
diligently work at their craft, write as much and as often as they can, and
never give up. Instead of tearing someone else down, they build themselves up
by continuing to learn, grow, and try. They are professional in their dealings
with others.
Keep writing, keep learning, keep growing. Have a goal, and
keep it firmly in your sights. Use criticism as an opportunity to re-evaluate
and improve your work. When you get a rejection, understand that your book may not fit a particular
market, might need more work, and that agent tastes can
be subjective. Be polite and professional toward your fellow writers.
And don’t be that writer who is memorable for the wrong reasons.
Robin Widmar
Managing Editor, Writing
from the Peak
Monday, July 30, 2012
JT Evans on Computer Security for Writers (Part 3) by DeAnna Knippling
Editor’s
Note: This is the third in a
three-part series. You can read Part 1 here and Part 2 here.
JT Evans, as well as being a writer, is
a computer security expert who started programming at the age of seven and has
been a Certified Ethical Hacker since 2009. During his June Write Brain talk,
he covered three main topics: how writers should take care of their computers,
computer security basics for writers, and what the bad guys are doing with
computers.
What
the Bad Guys Are Doing with Computers
The bad guys are violating one of three
principles of computer security when they go after someone’s computer:
Confidentiality. For example, sending your personal information without authorization.
Integrity. For example, changing test scores or introducing a virus onto your system.
Accessibility. For example, taking down a website or server.
These are known as the CIA triad of
computer security.
What methods can the bad guys use?
Denial of Service (DOS) or Distributed Denial of
Service (DDOS) attack. This kind of
attack blocks user access of a computer, website, or network. The DOS too
advantage of a particular vulnerability in the Windows 95/ME/XP operating
systems that let a bad guy crash your computer (a division by zero error was
involved). DOS vulnerabilities are mostly closed now. DDOS attacks are a
technique using botnets to send so many requests to a webpage or server that
the server is unable to provide access all the requests--effectively taking
down the webpage or server for a time.
Weak password vulnerabilities. A computer program can guess a lot of passwords
using dictionary files, very quickly. Because a lot of people have easily
guessed passwords (from things like “password” to their spouse’s name), a lot
of people are vulnerable to this kind of attack. Here are some password tips:
Use at least eight characters.
Use a mix of lowercase, uppercase, and symbols whenever possible.
Don’t depend on replacing letters with numbers (as in p@ssw0rd), because those types of replacements are in the programs’ dictionaries now, too.
Don’t use an easily guessed word or code as a password (password, 123456, qwerty, letmein, etc).
Use a phrase that you can easily remember (like a book title) to build a password, using the initial letters of each word in the phrase (e.g., TQBFJOTLD for “The quick brown fox jumps over the lazy dog”).
Don’t use the same password everywhere; in some cases, if a computer or website is hacked, then all the passwords on it are vulnerable (as in the recent LinkedIn hacking). You don’t want your password at your bank to be hacked just because someone hacked into a social networking site, do you?
A good way to store passwords is to have one really good password that you don’t use anywhere else that you save for a GPG-encrypted text file that stores all your other passwords (including user names and websites).
Buffer overflows. When you’re inputting data into a field, if the field is, say, 10
characters long for a phone number, and if the field isn’t protected from someone
typing in too many characters, then the extra information (after the first ten
characters, in our example) can be used to reprogram the software. In the past,
this was the most common way to attack a system; now, with more protection
being developed, it’s moving to #2 after...
SQL injection. Structured Query Language (SQL) is the programming language used in
relational databases. It’s like a buffer overflow in that you type extra
information to force the database to do something it wasn’t supposed to do, but
the techniques are specific to SQL databases.
Social engineering. This is using clever tricks to get people to give you information. If
someone ever asks you for personal
information, and you didn’t initiate the request by asking for something first,
it’s probably social engineering (for example, phishing emails or even fake
antivirus software).
Cross Site Scripting (XSS). This takes over your browser by injecting code into
a website, then letting the website do naughty things to your browser. This can
be used to create a browser-based botnet.
Cross Site Request Forgery (CSRF). This uses HTML to trick your browser into turning one
action into doing a different action instead. For example, if you clicked
anywhere on an Amazon page, a bad guy might use CSRF to force the click to work
on the “Buy now with 1-Click” button instead.
Lack of encryption. An unsecured wireless network can be used to do many things, include
monitoring every action on your desktop. You should use a Virtual Private
Network (VPN) if you have one, if you’re on unsecured wifi, and use Secure
Socket Layer (SSL) (that is, a site that starts with https:// rather than http://)
when possible. Also, when you’re choosing the encryption for your wireless
network, use WPA, rather than the WEP or WEP2 options, which are easily broken.
Network/Host scanning. There are a wealth of tools available that will scan
for vulnerabilities. These are used by both the bad guys and the good guys: the
bad guys to try to break into systems; the good guys to make sure it won’t be
easy to break in. Some examples are nmap, Nessus/OpenVAS, Metasploit, and
kismet.
If you need more information, you can
go to JT’s website, jtevans.net.
If you’d like a copy of his handouts,
click here.
About the Writer:
DeAnna Knippling is a freelance writer, editor, and formatter married to
a Network Administrator, and she was still embarrassed about some of her
personal security practices after hearing JT's talk. Check out her
personal blog at www.DeAnnaKnippling.com
or her small press at www.WonderlandPress.com.
Sunday, July 29, 2012
Subscribe to:
Posts (Atom)








