Risky Business Podcast
June 02, 2011
Risky Business #196 -- Mark Dowd on infosec software bugs
Presented by
CEO and Publisher
Technology Editor
On this week's show we're taking a look at the issue of failkit. Why is it that the very software designed to keep our networks secure is full of bugs?
A pen tester buddy of mine recently found an 0day XSS in a single sign on product... on ITS FRONT PAGE. Another friend found an auth bypass in a two-factor authentication management console. ON ITS FRONT PAGE.
It's impossible to find AV engines that don't come preloaded with a zillion format string vulnerabilities, and as you'll hear in this week's news, even Cisco's VPN solution is a nice way to actually own organisations. WTF.
Bug hunter extraordinaire, Azimuth Security's Mark Dowd, joins us after the news to chat about that. We'll also have a quick chat with Josh Corman, an analyst with 451 group in the USA and co-founder of the Rugged Software initiative.
Adam Boileau, as always, stops by for a check of the week's news headlines.