Podcasts

News, analysis and commentary

Risky Business #379 -- Ashley Madison dump, Troy Hunt and The Grugq

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's podcast we check in with Troy Hunt from HaveIBeenPwned.com. Troy has done the responsible thing in adding the Ashley Madison dataset to his service -- you can only search for email addresses in the dump after you've verified that you control them. We'll talk to him about why he did that.

This week's show is brought to you by FireEye and FireEye senior systems engineer Ben Wilson stops by to have a chat about some neat tricks attackers and malware authors are getting up to with various scripts on Windows. WMI for persistence is a thing now, for example. It's a really interesting chat that one and it's coming up a bit later.

The Grugq is in the news chair this week, filling in for Adam Boileau.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and The Grugq on Twitter if that's your thing.

Show notes

Was the Ashley Madison Database Leaked? - Krebs on Security
http://krebsonsecurity.com/2015/08/was-the-ashley-madison-database-leaked/

Ashley Madison hack is not only real, it's worse than we thought | Ars Technica
http://arstechnica.com/security/2015/08/ashley-madison-hack-is-not-only-...

Microsoft issues emergency patch for critical IE bug under active exploit | Ars Technica
http://arstechnica.com/security/2015/08/microsoft-issues-emergency-patch...

Exclusive: Russian antivirus firm faked malware to harm rivals - Ex-employees | Reuters
http://www.reuters.com/article/2015/08/14/us-kaspersky-rivals-idUSKCN0QJ...

Crackdowns Haven't Stopped the Dark Web's $100M Yearly Drug Sales | WIRED
http://www.wired.com/2015/08/crackdowns-havent-stopped-dark-webs-100m-ye...

What We Know About the NSA and AT&T's Spying Pact | WIRED
http://www.wired.com/2015/08/know-nsa-atts-spying-pact/

Busting the Biggest Myth of CISA---That the Program Is Voluntary | WIRED
http://www.wired.com/2015/08/access-cisa-myth-of-voluntary-info-sharing/

Virginia Finally Drops America's 'Worst Voting Machines' | WIRED
http://www.wired.com/2015/08/virginia-finally-drops-americas-worst-votin...

How Not to Start an Encryption Company - Krebs on Security
http://krebsonsecurity.com/2015/08/how-not-to-start-an-encryption-company/

How BitTorrent could let lone DDoS attackers bring down big sites | Ars Technica
http://arstechnica.com/security/2015/08/how-bittorrent-could-let-lone-dd...

RPC Portmapper Reflective DDoS Attacks | Threatpost | The first stop for security news
https://threatpost.com/reflection-ddos-attacks-abusing-rpc-portmapper/11...

Android security on the ropes with one-two punch from researchers | Ars Technica
http://arstechnica.com/security/2015/08/android-security-on-the-ropes-wi...

Your BMW or Benz Could Also Be Vulnerable to That GM OnStar Hack | WIRED
http://www.wired.com/2015/08/bmw-benz-also-vulnerable-gm-onstar-hack/

My browser visited Weather.com and all I got was this lousy malware (Updated) | Ars Technica
http://arstechnica.com/security/2015/08/my-browser-visited-drudgereport-...

Luca Todesco OS X Zero Day Vulnerabilities | Threatpost | The first stop for security news
https://threatpost.com/inside-the-unpatched-os-x-vulnerabilities/114344

Bugged, Tracked, Hacked | 60 Minutes | 9Jumpin
http://www.9jumpin.com.au/show/60minutes/stories/2015/august/phone-hacking/

Troy Hunt: Here's how I'm going to handle the Ashley Madison data
http://www.troyhunt.com/2015/07/heres-how-im-going-to-handle-ashley.html

fireeye/flare-wmi \xb7 GitHub
https://github.com/fireeye/flare-wmi

https://www.insomniasec.com/downloads/publications/shellgame.pdf

Risky Business #379 -- Ashley Madison dump, Troy Hunt and The Grugq
0:00 / 41:40

An open letter to Risky Business Patreon supporters

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Hey to all you Patreon people!

First up, a big thanks to you for helping out the show. It's been really heartening to see so many of you value Risky Business enough to put your hands in your pockets and make a contribution.

The original idea behind the Patreon campaign was that if I hit the target I could take that money and throw it at an industrial unit here in Byron Bay and turn it into a proper studio. After 11.5 years working from home full time, I've been feeling a bit cooped up.

The plan was to buy one and use the Patreon contributions to help service the debt. I'd get an office to work in, and over time I'd be building some equity in some bricks and mortar which will come in handy if I'm lucky enough to get too old to work.

Well, we haven't hit the target (it was ambitious) and property prices have gone berserk here in Australia over the last 12 months. Also, commercial finance in this country is fraught. I wouldn't be able to get a loan for a commercial property anyway. (Not without a fully paid-off house as security.)

So I'm switching my plans up and it looks like the most realistic thing I can do is to eventually build a backyard office designed for sound production. (Carpeted walls, right shape etc.)

I've got enough room for something small in the backyard (Maybe 2.5m x 3m), and while I don't absolutely need it right now, I'm going to eventually.

So the plan that I had with the money raised via the Patreon campaign has changed. The unit idea is out, but the backyard studio is in. The thing is, I have no idea when I'll be able to do that. It's a hell of a thing to organise and I'm pretty busy renovating my house at the moment. And there's still the possibility that I'll just say "You know what? I like that patch of lawn just the way it is". I doubt it, but it's a consideration.

Patreon pledges are up to about $1100 a month from around 200 patrons, so an average of about $5 a month each, which works out to $1.35 per patron per podcast. I could pay down a small garden studio in a few years at this rate, purely with listener contributions. That's pretty awesome.

But again, I'm not sure when I'll pull the trigger on that.

So that's my mini rant in the interests of transparency. I don't want to wind up like Bronwyn Bishop in some sort of misappropriation scandal, so I'm letting you all know that the original idea isn't going to happen. I'm pretty sure most of you are happy to just support the podcast and you don't really care where the money goes, but it's important to be open I think. If you don't want to support the show in this way anymore I respect it, but it's helping and I appreciate it.

Many thanks to all of you,

Pat

Risky Business #378 -- Mary Ann Davidson vs Krebs and Dowd

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with Mark Dowd and Brian Krebs about Oracle CSO Mary Ann Davidson's somewhat odd blog post from earlier this week. In the post she laid into security researchers for violating Oracle's EULA when reverse engineering their products. The post got pulled, much drama, we sift through the ashes of that. Plus we chat to Brian about the daring $46.7m online heist against Ubiquiti Networks.

This week's show is brought to you by BugCrowd. But in this week's sponsor interview we're not chatting with a BugCrowd representative, we're speaking to one of its customers instead. Paul Moreno from Pinterest drops by to talk about his experience in operating a bug bounty through an outsourced provider.

Adam Boileau, as always, joins the show to discuss the week's news headlines.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Doubts cast on Islamic State's so-called leak of US .mil, .gov passwords \u2022 The Register
http://www.theregister.co.uk/2015/08/12/islamic_panic/

Attackers are hijacking critical networking gear from Cisco, company warns | Ars Technica
http://arstechnica.com/security/2015/08/attackers-are-hijacking-critical...

Why Not Insider Trade on Every Company? - Bloomberg View
http://www.bloombergview.com/articles/2015-08-11/why-not-insider-trade-o...

Sen. Warren Worried About Banks' New Encrypted Messaging Platform | Threatpost | The first stop for security news
https://threatpost.com/sen-warren-worried-about-banks-new-encrypted-mess...

Russia hacks Pentagon computers: NBC, citing sources
http://www.cnbc.com/2015/08/06/russia-hacks-pentagon-computers-nbc-citin...

Manipulating Microsoft WSUS to Own Enterprises | Threatpost | The first stop for security news
https://threatpost.com/manipulating-wsus-to-own-enterprises/114168

Imploding Barrels and Other Highlights From Hackfest DefCon | WIRED
http://www.wired.com/2015/08/highlights-from-defcon-2015/

Hackers Cut a Corvette's Brakes Via a Common Car Gadget | WIRED
http://www.wired.com/2015/08/hackers-cut-corvettes-brakes-via-common-car...

Internet-Connected Gas Pumps Are a Lure for Hackers | WIRED
http://www.wired.com/2015/08/internet-connected-gas-pumps-lure-hackers/

Researchers Hacked a Model S, But Tesla's Already Released a Patch | WIRED
http://www.wired.com/2015/08/researchers-hacked-model-s-teslas-already/

Meet RollJam, the $30 device that jimmies car and garage doors | Ars Technica
http://arstechnica.com/security/2015/08/meet-rolljam-the-30-device-that-...

Researchers reveal electronic car lock hack after 2-year injunction by Volkswagen | Ars Technica
http://arstechnica.com/security/2015/08/researchers-reveal-electronic-ca...

"Funtenna" software hack turns a laser printer into a covert radio | Ars Technica
http://arstechnica.com/security/2015/08/funtenna-software-hack-turns-a-l...

Hack of telematics device lets attackers mess with car's brakes | Ars Technica
http://arstechnica.com/cars/2015/08/hack-of-telematics-device-lets-attac...

The Windows 10 Security Settings You Need to Know | WIRED
http://www.wired.com/2015/08/windows-10-security-settings-need-know/

Lenovo used Windows anti-theft feature to install persistent crapware | Ars Technica
http://arstechnica.com/information-technology/2015/08/lenovo-used-window...

Darkhotel APT Latest to Use Hacking Team Zero Day | Threatpost | The first stop for security news
https://threatpost.com/darkhotel-apt-latest-to-use-hacking-team-zero-day...

0-day attack on Firefox users stole password and key data: Patch now! | Ars Technica
http://arstechnica.com/security/2015/08/0-day-attack-on-firefox-users-st...

Attackers actively exploit Windows bug that uses USB sticks to infect PCs | Ars Technica
http://arstechnica.com/security/2015/08/attackers-actively-exploit-windo...

Microsoft Patches USB-Related Flaw Used in Targeted Attacks | Threatpost | The first stop for security news
https://threatpost.com/microsoft-patches-usb-related-flaw-used-in-target...

August 2015 Microsoft Patch Tuesday Security Bulletins | Threatpost | The first stop for security news
https://threatpost.com/microsoft-patches-critical-vulnerabilities-in-new...

Severe weaknesses in Android handsets could leak user fingerprints | Ars Technica
http://arstechnica.com/security/2015/08/severe-weaknesses-in-android-han...

Android 'Serialization' Vulnerability Affects 55 Percent of Devices | Threatpost | The first stop for security news
https://threatpost.com/patched-android-serialization-vulnerability-affec...

Huge Flash Update Patches More Than 30 Vulnerabilities | Threatpost | The first stop for security news
https://threatpost.com/huge-flash-update-patches-more-than-30-vulnerabil...

Oracle security chief to customers: Stop checking our code for vulnerabilities [Updated] | Ars Technica
http://arstechnica.com/information-technology/2015/08/oracle-security-ch...

Tech Firm Ubiquiti Suffers $46M Cyberheist - Krebs on Security
http://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberh...

History | DAN WARNER
http://danwarner.com.au/history/

Risky Business #378 -- Mary Ann Davidson vs Krebs and Dowd
0:00 / 63:17

Risky Business #377 -- Wassenaar back to drawing board, latest from BlackHat

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we discuss the BIS decision to ditch its car-a-zay plans for Wassenaar regulation, the latest car hacking news and more.

We also check in with Trey Ford in this week's feature slot. Trey was the General Manager of the BlackHat conference, these days he works at Rapid7, and he joins us to talk about the vibe in Vegas at this year's conference.

This week's show is brought to you by RSA Security! Big thanks to RSA for making this week's show possible. RSA's very own Chris Thomas will be joining us in this week's sponsor interview to talk about the role industry should be playing in education. RSA is helping a few universities set up "learning SOCs", but where to from there?

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Government Takes Second Look at US Wassenaar Rules | Threatpost | The first stop for security news
https://threatpost.com/unusual-re-do-of-us-wassenaar-rules-applauded/114096

Chrysler and Harman Hit With a Class Action Complaint After Jeep Hack | WIRED
http://www.wired.com/2015/08/chrysler-harman-hit-class-action-complaint-...

Patch Your OnStar iOS App to Avoid Getting Your Car Hacked | WIRED
http://www.wired.com/2015/07/patch-gm-onstar-ios-app-avoid-wireless-car-...

This Gadget Hacks GM Cars to Locate, Unlock, and Start Them (UPDATED) | WIRED
http://www.wired.com/2015/07/gadget-hacks-gm-cars-locate-unlock-start/

Hackers Could Heist Semis by Exploiting This Satellite Flaw | WIRED
http://www.wired.com/2015/07/hackers-heist-semis-exploiting-satellite-flaw/

Hackers Can Seize Control of Electric Skateboards and Toss Riders | WIRED
http://www.wired.com/2015/08/hackers-can-seize-control-of-electric-skate...

DRAM "Bitflipping" exploit for attacking PCs: Just add JavaScript | Ars Technica
http://arstechnica.com/security/2015/08/dram-bitflipping-exploit-for-att...

"Thunderstrike 2" rootkit uses Thunderbolt accessories to infect Mac firmware [Updated] | Ars Technica
http://arstechnica.com/apple/2015/08/thunderstrike-2-rootkit-uses-thunde...

0-day bug in fully patched OS X comes under active exploit to bypass password protection | Ars Technica
http://arstechnica.com/security/2015/08/0-day-bug-in-fully-patched-os-x-...

Inside the $100M 'Business Club' Crime Gang - Krebs on Security
http://krebsonsecurity.com/2015/08/inside-the-100m-business-club-crime-g...

Chinese VPN Service as Attack Platform? - Krebs on Security
http://krebsonsecurity.com/2015/08/chinese-vpn-service-as-attack-platform/

Newly discovered Chinese hacking group hacked 100+ websites to use as "watering holes" | Ars Technica
http://arstechnica.com/security/2015/08/newly-discovered-chinese-hacking...

China-Tied Hackers That Hit U.S. Said to Breach United Airlines - Bloomberg Business
http://www.bloomberg.com/news/articles/2015-07-29/china-tied-hackers-tha...

Russian hacker targets CommSec, E*TRADE retail accounts
http://www.theage.com.au/business/markets/russian-hacker-targets-commsec...

New attack on Tor can deanonymize hidden services with surprising accuracy | Ars Technica
http://arstechnica.com/security/2015/07/new-attack-on-tor-can-deanonymiz...

Bound to happen: BIND bug exploits now in the wild \u2022 The Register
http://www.theregister.co.uk/2015/08/04/bind_bug_exploits_now_in_the_wild/

Windows 10 Upgrade Spam Carries CTB-Locker Ransomware | Threatpost | The first stop for security news
https://threatpost.com/windows-10-upgrade-spam-carries-ctb-locker-ransom...

drspringfield / cabletables - Bitbucket
https://bitbucket.org/drspringfield/cabletables

John McAfee cuffed by Tennessee cops, faces drug-driving, gun rap \u2022 The Register
http://www.theregister.co.uk/2015/08/05/tennessee_cops_stops_john_mcafee...

McAfee tells El Reg: 'My shootout with the police was highly exaggerated' \u2022 The Register
http://www.theregister.co.uk/2015/08/05/john_mcafee_says_police_shootout...

Office Lip Dub - Everything's Under Control by Peregrine - YouTube
https://www.youtube.com/watch?v=o8DQKieBPNU

Risky Business #377 -- Wassenaar back to drawing board, latest from BlackHat
0:00 / 55:45

Risky Business #376 -- Sniper rifles, bank safes and Android all pwned

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week we're checking in with Josh Drake of Zimperium. With exploitation of Stagefright via Josh's sweet, sweet exploit you'd think the mother of all worms is coming. Well, probably not. Later versions of Android are tricky to exploit, and the diversity of hardware in earlier versions means coming up with one exploit to rule them all isn't really feasible. We'll drill down into that with Josh in a little while.

This week's show is brought to you by Tenable Network Security. Tenable's very own Jack Daniel will be along in this week's sponsor interview to add a bit of context to recent car hacking news. Jack was a mechanic in a previous life. I myself worked for Bosch as an engineer designing automotive electronics in the 90s. So we put our old man pants on and talk about how we arrived in a world where 1.4 million Chrysler owners are patching their vehicles against security flaws using a mailed out USB stick.

Adam Boileau, as usual, joins the show to discuss the week's news headlines.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Hackers Can Disable a Sniper Rifle-Or Change Its Target | WIRED
http://www.wired.com/2015/07/hackers-can-disable-sniper-rifleor-change-t...

Brinks' Super-Secure Smart Safes: Not So Secure | WIRED
http://www.wired.com/2015/07/brinks-super-secure-smart-safes-not-secure/

Researchers Hack Air-Gapped Computer With Simple Cell Phone | WIRED
http://www.wired.com/2015/07/researchers-hack-air-gapped-computer-simple...

US Census Bureau IT systems hacked, data leaked by Anonymous \u2022 The Register
http://www.theregister.co.uk/2015/07/23/us_census_bureau_hacked/

NSA: We'll move your metadata into /dev/null when you stop suing us \u2022 The Register
http://www.theregister.co.uk/2015/07/27/nsa_phone_metadata_latest/

White House Says No Thanks to Snowden Pardon Petition | Threatpost | The first stop for security news
https://threatpost.com/white-house-says-no-thanks-to-snowden-pardon-peti...

New Chrome Extension Helps Combat Keyboard Biometrics | Threatpost | The first stop for security news
https://threatpost.com/new-chrome-extension-helps-combat-keyboard-biomet...

Researchers claim they've developed a better, faster Tor | Ars Technica
http://arstechnica.com/information-technology/2015/07/researchers-claim-...

A public marketplace for hackers-what could possibly go wrong? | Ars Technica
http://arstechnica.com/security/2015/07/a-public-marketplace-for-hackers...

Pakistan bans BlackBerry messaging, e-mail for "security reasons" | Ars Technica
http://arstechnica.com/security/2015/07/pakistan-bans-blackberry-messagi...

What amateurs can learn from security pros about staying safe online | Ars Technica
http://arstechnica.com/security/2015/07/what-amateurs-can-learn-from-sec...

Yahoo Touts Success of Bug Bounty Program | Threatpost | The first stop for security news
https://threatpost.com/yahoo-touts-success-of-bug-bounty-program/114019

Malvertising campaign hits 10 MEELLION users in 10 days \u2022 The Register
http://www.theregister.co.uk/2015/07/29/malvertising_affects_10_million/

Click-Fraud Malware Spreading via JavaScript Attachments | Threatpost | The first stop for security news
https://threatpost.com/click-fraud-malware-spreading-via-javascript-atta...

Group that hacked Anthem shared weaponized 0-days with rival attackers | Ars Technica
http://arstechnica.com/security/2015/07/group-that-hacked-anthem-shared-...

Apple Patches Remote 'Invoice Vulnerability' in iTunes, App Store | Threatpost | The first stop for security news
https://threatpost.com/apple-patches-remote-invoice-vulnerability-in-itu...

Xen reports new guest-host escape, this time through CD-ROMs \u2022 The Register
http://www.theregister.co.uk/2015/07/28/xen_reports_new_guesthost_escape...

PHP File Manager Riddled With Vulnerabilities, Including Backdoor | Threatpost | The first stop for security news
https://threatpost.com/php-file-manager-riddled-with-vulnerabilities-inc...

New vulnerability can put Android phones into permanent vegetative state | Ars Technica
http://arstechnica.com/security/2015/07/new-vulnerability-can-put-androi...

WordPress Patches Critical XSS Vulnerability in All Builds | Threatpost | The first stop for security news
https://threatpost.com/wordpress-patches-critical-xss-vulnerability-in-a...

Valve patches security hole that enabled takeover of Steam accounts | Ars Technica
http://arstechnica.com/gaming/2015/07/valve-patches-security-hole-that-e...

Critical Remotely Exploitable Bug Haunts BIND | Threatpost | The first stop for security news
https://threatpost.com/critical-remotely-exploitable-bug-haunts-bind/114008

950 million Android phones can be hijacked by malicious text messages | Ars Technica
http://arstechnica.com/security/2015/07/950-million-android-phones-can-b...

La Polic\xeda by labjacd | Free Listening on SoundCloud
https://soundcloud.com/labjacd/la-policia

Risky Business #376 -- Sniper rifles, bank safes and Android all pwned
0:00 / 67:44

Serious Business #4 -- Reclaim Australia, Donald Trump and Ashley Madison

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

This is the podcast I do for shiggles with Australian comedian, radio and TV personality Dan Ilic.

This week we're talking about the nationalist, anti-Islam rallies held across Australia over the last week or so. We also chat about Donald Trump being a douche and Barack Obama's new lease of life as a lame duck president. Oh, and we also talk about the Ashley Madison hack because, hey, who isn't...

Serious Business #4 -- Reclaim Australia, Donald Trump and Ashley Madison
0:00 / 24:33

Risky Business #375 -- Ashley Madison, Jeep hacks drive news agenda

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we're chatting with Dave Jorm, our resident North Korea watcher. Some of you might remember Dave, he was on the show a couple of years ago talking about his OSINT satellite data analysis of North Korea and more recently he popped by to talk about software defined networking security.

Well, some recent analysis of North Korea's official Red Star OS has found it has a nasty habit -- it watermarks media files that users open with a unique ID. This will of course help the North Korean regime to track down the smugglers of digital media, whether that's activist material or South Korean soaps, which are most definitely verboten in the hermit kingdom.

This week's show is brought to you by Intralinks -- these guys do secure document exchange and storage. Intralinks very own Todd Partridge drops by to talk about how their customers are actually customising these types of document services.

Adam Boileau, as usual, joins the show to discuss the week's news headlines.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Online Cheating Site AshleyMadison Hacked - Krebs on Security
http://krebsonsecurity.com/2015/07/online-cheating-site-ashleymadison-ha...

Hackers Remotely Kill a Jeep on the Highway-With Me in It | WIRED
http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

Patch Your Chrysler Now Against a Wireless Hacking Attack | WIRED
http://www.wired.com/2015/07/patch-chrysler-vehicle-now-wireless-hacking...

Senate Bill Seeks Standards For Cars' Defenses From Hackers | WIRED
http://www.wired.com/2015/07/senate-bill-seeks-standards-cars-defenses-h...

Google Calls Proposed U.S. Wassenaar Rules 'Not Feasible' | Threatpost | The first stop for security news
https://threatpost.com/google-calls-proposed-u-s-wassenaar-rules-not-fea...

Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In
http://blog.trendmicro.com/trendlabs-security-intelligence/hacking-team-...

SSD Advisory - Trend Micro Threat Intelligence Manager Multiple Vulnerabilities Remote Code Execution | SecuriTeam Blogs
https://blogs.securiteam.com/index.php/archives/2502

Hacking Team apparently violated EU rules in sale of spyware to Russian agency | Ars Technica
http://arstechnica.com/tech-policy/2015/07/hacking-teams-surveillance-so...

Hacking Team Says It Always Sold 'Strictly Within the Law' | Threatpost | The first stop for security news
https://threatpost.com/hacking-team-claims-it-always-sold-strictly-withi...

Netragard Shutters Controversial Exploit Acquisition Program | Threatpost | The first stop for security news
https://threatpost.com/netragard-shutters-controversial-exploit-acquisit...

Researcher angry after finding his code in Hacking Team malware | Ars Technica
http://arstechnica.com/security/2015/07/researcher-takes-umbrage-after-f...

Obama administration decides not to blame China publicly for OPM hack | Ars Technica
http://arstechnica.com/tech-policy/2015/07/obama-administration-decides-...

Four men reportedly arrested in connection to JPMorgan Chase hack | Ars Technica
http://arstechnica.com/tech-policy/2015/07/4-men-reportedly-arrested-in-...

UK man accused of hacking spree on US government is arrested (again) | Ars Technica
http://arstechnica.com/security/2015/07/uk-man-accused-of-hacking-spree-...

Experian Hit With Class Action Over ID Theft Service - Krebs on Security
http://krebsonsecurity.com/2015/07/experian-hit-with-class-action-over-i...

Hacking Team's evil Android app had code to bypass Google Play screening | Ars Technica
http://arstechnica.com/security/2015/07/hackingteams-evil-android-app-ha...

Dozens of phone apps with 300M downloads vulnerable to password cracking | Ars Technica
http://arstechnica.com/security/2015/07/dozens-of-phone-apps-with-300m-d...

New Campaign Targeting Japanese with Hacking Team Zero Day | Threatpost | The first stop for security news
https://threatpost.com/new-campaign-targeting-japanese-with-hackingteam-...

Free Tool Looks for HackingTeam Malware | Threatpost | The first stop for security news
https://threatpost.com/free-tool-looks-for-hackingteam-malware/113850

OpenDNS BGP Stream Twitter Feed | Threatpost | The first stop for security news
https://threatpost.com/bgp-security-alerts-coming-to-twitter/113843

Bug in widely used OpenSSH opens servers to password cracking | Ars Technica
http://arstechnica.com/security/2015/07/bug-in-widely-used-openssh-opens...

Google Patches 43 Bugs in Chrome | Threatpost | The first stop for security news
https://threatpost.com/google-patches-43-bugs-in-chrome/113892

Bug in latest version of OS X gives attackers unfettered root privileges | Ars Technica
http://arstechnica.com/security/2015/07/bug-in-latest-version-of-os-x-gi...

Microsoft Issues Critical, Out-of-Band Patch for All Versions of Windows | Threatpost | The first stop for security news
https://threatpost.com/microsoft-issues-critical-out-of-band-patch-for-a...

RedStar OS Watermarking - Insinuator
http://www.insinuator.net/2015/07/redstar-os-watermarking/

Secure Collaboration + Content Management | Intralinks
https://www.intralinks.com/

Risky Business #375 -- Ashley Madison, Jeep hacks drive news agenda
0:00 / 57:22

Risky Business #374 -- Anti-Flash sentiment sweeps the globe

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we'll be checking in with Richard Forno on the fallout from the OPM breach. Richard has been kicking around in DC infosec circles for a long time now and he let's us know what the mood is like inside the beltway.

In this week's sponsor interview we chat with Chris Gatford of HackLabs! HackLabs is an Australia-based pentesting and consulting firm and we're speaking to Chris about the changing nature of security consultancies.

Adam Boileau, as usual, joins the show to discuss the week's news, which has been dominated by calls for the axing of the Flash plugin and the continued fallout from the Hacking Team breach.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Flash. Must. Die. | WIRED
http://www.wired.com/2015/07/adobe-flash-player-die/

Microsoft nixes A-V updates for XP, exposes 180 MEEELLION luddites \u2022 The Register
http://www.theregister.co.uk/2015/07/15/xp_antimalware_support_axed/

Ubuntu PC maker System76 abandons Flash, says it's too dangerous | Ars Technica
http://arstechnica.com/information-technology/2015/07/ubuntu-pc-maker-sy...

Firefox blacklists Flash player due to unpatched 0-day vulnerabilities | Ars Technica
http://arstechnica.com/security/2015/07/firefox-blacklists-flash-player-...

Adobe: We REALLY are taking Flash security seriously - honest \u2022 The Register
http://www.theregister.co.uk/2015/07/14/adobe_response_to_security_holes/

Once again, Adobe releases emergency Flash patch for Hacking Team 0-days | Ars Technica
http://arstechnica.com/security/2015/07/once-again-adobe-releases-emerge...

Hacking Team's Flash 0-day: Potent enough to infect actual Chrome user | Ars Technica
http://arstechnica.com/security/2015/07/hacking-teams-flash-0day-potent-...

Hacking Team Used Spammer Tricks to Resurrect Spy Network - Krebs on Security
http://krebsonsecurity.com/2015/07/hacking-team-used-spammer-tricks-to-r...

Hacking Team spyware rootkit: Even a new HARD DRIVE wouldn't get rid of it \u2022 The Register
http://www.theregister.co.uk/2015/07/14/hacking_team_stealth_rootkit/

How a Russian hacker made $45,000 selling a 0-day Flash exploit to Hacking Team | Ars Technica
http://arstechnica.com/security/2015/07/how-a-russian-hacker-made-45000-...

Hacking Team's snoopware 'spied on anti-communist activists in Vietnam' \u2022 The Register
http://www.theregister.co.uk/2015/07/13/hacking_team_vietnam_apt/

Hacking Team touts new spyware suite, calls leaks now "obsolete" | Ars Technica
http://arstechnica.com/security/2015/07/hacking-team-remains-defiant-tou...

Critical OpenSSL bug allows attackers to impersonate any trusted server | Ars Technica
http://arstechnica.com/security/2015/07/critical-openssl-bug-allows-atta...

Dozens Nabbed in Takedown of Cybercrime Forum Darkode | WIRED
http://www.wired.com/2015/07/dozens-nabbed-takedown-cybercrime-forum-dar...

As Predicted, OPM Director Resigns in Wake of Epic Hack | WIRED
http://www.wired.com/2015/07/predicted-opm-director-katherine-archuleta-...

New Bill Would Grant Lifetime Credit Monitoring to OPM Victims | Threatpost | The first stop for security news
https://threatpost.com/new-bill-would-grant-lifetime-credit-monitoring-t...

A $200 privacy device has been killed, and no one knows why | Ars Technica
http://arstechnica.com/security/2015/07/a-200-privacy-device-has-been-ki...

ProxyGambit - anonymize net over GSM or PTP link
http://samy.pl/proxygambit/

Sixty-five THOUSAND Range Rovers recalled over DOOR software glitch \u2022 The Register
http://www.theregister.co.uk/2015/07/14/range_rover_recall/

Hackers sell 79,267 Cloudminr accounts for ONE Bitcoin \u2022 The Register
http://www.theregister.co.uk/2015/07/14/cloudminr_hack_80000_bitcoin_min...

DEA agent slugged a MEELLION dollars for Silk Road snipe \u2022 The Register
http://www.theregister.co.uk/2015/07/13/silkroad_dea_agent_outofpocket_b...

Papa don't breach: Wannabe singer jailed for hacking Madonna \u2022 The Register
http://www.theregister.co.uk/2015/07/10/madonna_hacker_sentencing/

Wow, another NSA leak: Network security code appears on GitHub \u2022 The Register
http://www.theregister.co.uk/2015/07/09/nsa_network_security_code_leaks_...

New RC4 Attack Dramatically Reduces Plaintext Recovery Time | Threatpost | The first stop for security news
https://threatpost.com/new-rc4-attack-dramatically-reduces-plaintext-rec...

Oracle Patches Java Zero Day | Threatpost | The first stop for security news
https://threatpost.com/oracle-patches-java-zero-day/113792

New PHP Releases Fix BACRONYM MySQL Flaw | Threatpost | The first stop for security news
https://threatpost.com/new-php-releases-fix-bacronym-mysql-flaw/113740

Firefox 39 Out With Patches for Four Critical Vulnerabilities | Threatpost | The first stop for security news
https://threatpost.com/firefox-39-out-with-patches-for-four-critical-vul...

MS kills critical IE 11 bug after exploit was shopped to Hacking Team | Ars Technica
http://arstechnica.com/security/2015/07/ms-kills-critical-ie-11-bug-afte...

Microsoft Security Bulletin MS15-058 - Important
https://technet.microsoft.com/en-us/library/security/MS15-058

Microsoft Security Bulletin MS15-068 - Critical
https://technet.microsoft.com/en-us/library/security/ms15-068.aspx

Microsoft Security Bulletin MS15-067 - Critical
https://technet.microsoft.com/en-us/library/security/ms15-067.aspx

Job search | Employment and jobs | Queensland Government
https://smartjobs.qld.gov.au/jobtools/jncustomsearch.viewFullSingle?in_o...

[ - infowarrior.org - ]
http://infowarrior.org/about.html

Penetration Testing & Web Application Security - HackLabs
http://www.hacklabs.com/

Screaming Headless Torsos (Live in New York -- Knitting Factory 1996) - YouTube
https://www.youtube.com/watch?v=FAKhafsFslE

Screaming Headless Torsos - 2 Bruce Wayne featuring Jimmy Valentine - YouTube
https://www.youtube.com/watch?v=Pzdd2mUiDF0

Risky Business #374 -- Anti-Flash sentiment sweeps the globe
0:00 / 55:38

Risky Business #373 -- Hacking Team gets owned. Quite a lot.

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

Obviously the Hacking Team breach is the big story of the week and we'll be jumping right into that.

It's a jam packed podcast this week -- we check in with Dave Aitel of Immunity to talk about the impending Wassenaar Arrangement disaster about to hit America. We're also joined by Claudio Guarnieri.

Claudio has spent years tracking Hacking Team's malware to the darkest regions of the planet. For a long time he's been claiming Hacking Team were up to no good, now we know he was right. We get him on to the show for a well-earned gloat.

This week's show is brought to you by Xipiter! Do you want to learn how to exploit and reverse engineer IoT, mobile and embedded devices? Xipiter is teaching their SexViaHex and ARM Exploitation classes in September in the Hague. Both their Blackhat classes have sold out four years in a row, and they are indeed sold out this year. Go to SexViaHex.com to book your spot.

Adam Boileau, as usual, joins us to discuss the week's security news.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Show notes

Hacking Team Breach Shows a Global Spying Firm Run Amok | WIRED
http://www.wired.com/2015/07/hacking-team-breach-shows-global-spying-fir...

Despite Hacking Team's poor opsec, CEO came from early days of PGP | Ars Technica
http://arstechnica.com/security/2015/07/despite-hacking-teams-poor-opsec...

Hacking Team responds to data breach, issues public threats and denials | CSO Online
http://www.csoonline.com/article/2944333/data-breach/hacking-team-respon...

Days after Hacking Team breach, nobody fired, no customers lost | Ars Technica
http://arstechnica.com/security/2015/07/days-after-hacking-team-breach-n...

Hacking Team Flash Zero Day Weaponized in Exploit Kits | Threatpost | The first stop for security news
https://threatpost.com/hacking-team-flash-zero-day-weaponized-in-exploit...

Hacking Team Couldn't Hack Your iPhone | Threatpost | The first stop for security news
https://threatpost.com/hacking-team-couldnt-hack-your-iphone/113636

Dutch MEP whacks Hacking Team over embargo-busting \u2022 The Register
http://www.theregister.co.uk/2015/07/08/dutch_mep_whacks_hacking_team_ov...

Latest News
http://www.hackingteam.it/index.php/about-us

Student claims Wassenaar Arrangement prevents him from publishing dissertation | Ars Technica
http://arstechnica.com/security/2015/07/student-claims-wassenaar-agreeme...

Berlin pours bucket of flat beer on Patriot missile hack report \u2022 The Register
http://www.theregister.co.uk/2015/07/08/german_hackers_hijack_missiles/

Meet the hackers who break into Microsoft and Apple to steal insider info | Ars Technica
http://arstechnica.com/security/2015/07/meet-the-hackers-who-break-into-...

Finnish Decision is Win for Internet Trolls - Krebs on Security
http://krebsonsecurity.com/2015/07/finnish-decision-is-win-for-internet-...

Ford's 400,000-car recall could be the tip of an auto security iceberg \u2022 The Register
http://www.theregister.co.uk/2015/07/08/ford_car_software_recall_analysis/

Kali Linux 2.0 to launch at DEFCON 23 \u2022 The Register
http://www.theregister.co.uk/2015/07/08/kali_20/

Heart of Darkness: Mass of clone scam sites appear \u2022 The Register
http://www.theregister.co.uk/2015/07/07/dark_web_cloned_site_scam_resurg...

SyncStop / USB Condom - Charge Your Mobile Phone Safely
http://syncstop.com/

Software Exploitation via Hardware exploitation training (LITE) - SexViaHex
http://www.sexviahex.com/

Xipiter - Home
http://www.xipiter.com/

Colin Hay - Beautiful World - YouTube
https://www.youtube.com/watch?v=xe3RqgnXaT4

Risky Business #373 -- Hacking Team gets owned. Quite a lot.
0:00 / 75:38

Risky Business #372 -- Airbus pilot talks plane hacking

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is a bit left of field With all the talk about plane hacking flying around over the last couple of months (zing) I thought it might be an idea to talk to an actual airliner pilot. So this week we're joined by an Australian Airbus pilot. He works for an Asian airline but he was in Australia recently and I caught up with him to ask him for his thoughts on the topic.

As you'll hear, there's a bit more to an Airbus than it just being a flying computer. It's more like a flying computer warehouse with multiple redundant systems. Our anonymous pilot says stopping a hacker on a plane might be as simple as just killing power to the cabin with the flick of a switch -- BUT, he says there are no procedures or training around troubleshooting for malicious attackers and in such a heavily process-oriented environment that could cause problems.

This week's show is brought to you by our friends at Tenable Network Security, big thanks to them! Tenable's very own Marcus Ranum will be along in this week's sponsor interview to talk about detection concepts. He pulls on his grumpy pants and doles out some stone-cold old school advice for people out there building networks. That's a fun one.

Adam Boileau, as usual, joins us to discuss the week's security news.

Links to everything can be found in this week's show notes.

Links to everything are in this week's show notes.

Don't forget you can now support the Risky Business page via our Patreon campaign.

Oh, and do add Patrick and Adam on Twitter if that's your thing.

Risky Business #372 -- Airbus pilot talks plane hacking
0:00 / 63:17