Podcasts

News, analysis and commentary

Risky Business #251 -- Thunderbolt strikes Mac EFI

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we're getting an update on some research we looked at last year. Loukas of Assurance.com.au in Melbourne had been playing around with some "evil maid" EFI hacks on Macs, but he's done some more work on them and presented his findings at BlackHat in July.

He joins the show to discuss his latest EFI work. See this week's show notes for links to his slide deck and paper, as well as links to this week's news.

This week's show is brought to you by Adobe!

Adobe's head of product security Brad Arkin joins us to give us some development tips for smaller coding teams. He also discusses his involvement with the RSA conference -- he'll be helping to select some talks.

Risky Business #251 -- Thunderbolt strikes Mac EFI
0:00 / 0:00

Risky Business #250 -- Hack it like it's 1999

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Recurity Labs' Felix "FX" Lindner and Greg Kopf in the feature segment.

These guys recently shredded some Huawei equipment. They owned it hard and turned it into a DEFCON talk [pdf]. They'll be along a bit later on to tell us why hacking away at Huawei kit made them feel nostalgic.

This week's show is brought to you by the fine folks at Australian pentesting firm HackLabs, so I hope you'll keep them in mind next time you're firing off those RFPs!

HackLabs founder and main man Chris Gatford joins us in this week's sponsor slot to discuss the extremely clever social engineering attack against accounts belonging to technology journalist Mat Honan. he got owned pretty hard. No clientsides, no exploits, no bruteforcing. Just a few phone calls.

Show notes

http://phenoelit.org/stuff/Huawei_DEFCON_XX.pdf

THIS WEEK'S NEWS ITEMS:

Stratfor emails reveal secret, widespread TrapWire surveillance system - RT
http://rt.com/usa/news/stratfor-trapwire-abraxas-wikileaks-313/

Is TrapWire surveillance really spying on Americans? - Technolog on NBCNews.com
http://www.technolog.msnbc.msn.com/technology/technolog/trapwire-surveil...

New Gauss Malware, Descended From Flame and Stuxnet, Found On Thousands of PCs in Middle East | threatpost
http://threatpost.com/en_us/blogs/new-gauss-malware-descended-flame-and-...

Amazon addresses security exploit after journalist hack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57488759-83/amazon-addresses-security-e...

Apple responds to journalist's iCloud hack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57487873-83/apple-responds-to-journalis...

One way to make passwords obsolete -- just keep typing | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57492355-83/one-way-to-make-passwords-o...

DOJ Won't Ask Supreme Court to Review Hacking Case | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/computer-fraud-supreme-court/

Goldman Sachs Programmer Back in Court on New Charges | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/sergey-aleynikov-new-charges/

FTC Dings Google $22.5M in Safari Cookie Flap | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/ftc-google-cookie/

Microsoft Releases Attack Surface Analyzer Tool | threatpost
http://threatpost.com/en_us/blogs/microsoft-releases-attack-surface-anal...

#684121 - libotr2: Buffer overflows in libotr - Debian Bug report logs
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684121

Anonymous targets ASIO, government websites | ZDNet
http://www.zdnet.com/au/anonymous-targets-asio-government-websites-70000...

Oracle Warns Users About Privilege Escalation Bug in Database Server | threatpost
http://threatpost.com/en_us/blogs/oracle-warns-users-about-privilege-esc...

,

The secret is already out there. You don't need to become so sensitive about that one. - James Cullem

Risky Business #250 -- Hack it like it's 1999
0:00 / 0:00

Risky Business #249 -- Did the BlueHat prize experiment succeed?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Microsoft's Katie Moussouris about the company's BlueHat prize. How successful was the prize, and did it get Microsoft value for money in terms of quality entries?

Katie took some time out from her maternity leave to join the show.

This week's show is brought to you by Tenable Network Security.

In this week's sponsor interview with Tenable founder and CEO Ron Gula we get a bit philosophical. Has it become culturally acceptable in the business world to get owned?

If LinkedIn and Sony can have such a bad time, are major incidents therefore seen as routine?

Follow Patrick Gray on Twitter.

Show notes

Get the podcast here.

Expert: Huawei routers are riddled with vulnerabilities | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57482813-83/expert-huawei-routers-are-r...

Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate
https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/

Full Disclosure: nvidia linux binary driver priv escalation exploit
http://seclists.org/fulldisclosure/2012/Aug/4

Firm Sees More DDoS Attacks Aimed at Telecom Systems | threatpost
http://threatpost.com/en_us/blogs/firm-sees-more-ddos-attacks-aimed-tele...

Republicans block vote on cybersecurity bill | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57485404-83/republicans-block-vote-on-c...

Vasillis Pappas Wins $200,000 Microsoft Blue Hat Prize | threatpost
http://threatpost.com/en_us/blogs/vasillis-pappas-wins-200000-microsoft-...

In First Black Hat Talk, Apple Reveals Little New About iOS Security | threatpost
http://threatpost.com/en_us/blogs/first-black-hat-talk-apple-reveals-lit...

Facebook aims 'bug bounty' at in-house network | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57480383-83/facebook-aims-bug-bounty-at...

More information on Security Advisory 2737111 - Security Research & Defense - Site Home - TechNet Blogs
http://blogs.technet.com/b/srd/archive/2012/07/24/more-information-on-se...

Anonymous in a tizzy over logo trademark | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57484468-83/anonymous-in-a-tizzy-over-l...

Does Cybercrime Really Cost $1 Trillion? | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/08/cybercrime-trillion/all/

Illinois Outlaws Employer Requests for Facebook Passwords | threatpost
http://threatpost.com/en_us/blogs/illinois-outlaws-employer-requests-fac...

Anonymous dumps hacked AAPT data - Hackers - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/310159,anonymous-dumps-hacked-aapt-dat...

OAuth 2.0 and the Road to Hell \xab hueniverse
http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell/

FX's Huawei slides:
http://phenoelit.org/stuff/Huawei_DEFCON_XX.pdf

,

A VERY ENTERTAINING SITE!
vacation rental koh samui

,

They surely are riddled with uncertainties. It will become a little bit better if you ask me. - Reputation Advocate

Risky Business #249 -- Did the BlueHat prize experiment succeed?
0:00 / 0:00

Risky Business #248 -- Being Big Brother on a budget

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

I've been busy preparing my debate speech for tomorrow's Splendour in the Grass music festival, so this week's show is a shorter one than usual; there's no feature interview.

But we've got a fascinating sponsor interview with SensePost's Glenn Wilkinson coming up. He's a lead security analyst with SensePost in its London office. He and his colleague Daniel Cuthbert are doing a talk and tool release at 44con in September called Terrorism, Tracking, Privacy and Human Interactions.

They set about writing some really creepy Big Brother-style tools for doing massive surveillance by dropping a few wireless access points around London. And you know what? As it turns out it's really easy to be really creepy!

Show notes

Australia, Canada 'primary spy targets'
http://www.theage.com.au/opinion/political-news/australia-canada-primary...

Nearly 5 Million People Have Government Security Clearances | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/security-clearances-increasing/

AAPT hacked by Anonymous - Security - Technology - News - CRN Australia
http://www.crn.com.au/News/309915,aapt-hacked-by-anonymous.aspx

Anonymous hackers cripple Aussie government websites | Information, Gadgets, Mobile Phones News & Reviews | News.com.au
http://www.news.com.au/technology/anonymous-hackers-cripples-aussie-gove...

Par:AnoIA | Meanwhile in Australia
http://par-anoia.net/queensland/

Watching the crooks: Researcher monitors cyber-espionage ring | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57479682-83/watching-the-crooks-researc...

Microsoft implements BlueHat prize tech | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57479407-83/microsoft-implements-blueha...

Charlie Miller Takes on NFC, Charlie Miller Wins | threatpost
http://threatpost.com/en_us/blogs/charlie-miller-takes-nfc-charlie-mille...

Reverse-Engineered Irises Look So Real, They Fool Eye-Scanners | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/reverse-engineering-iris-scans/

Siemens Patches Stuxnet-Like SCADA Bugs | threatpost
http://threatpost.com/en_us/blogs/siemens-patches-stuxnet-scada-bugs-072...

Grum Botnet Briefly Revived, Now Dead Again | threatpost
http://threatpost.com/en_us/blogs/grum-botnet-briefly-revived-now-dead-a...

Black Hat: Phishing E-Mail Scare A False Alarm | threatpost
http://threatpost.com/en_us/blogs/black-hat-phishing-e-mail-scare-false-...

Termineter Security Framework for Smart Meters Released | threatpost
http://threatpost.com/en_us/blogs/termineter-security-framework-smart-me...

This Xbox HDMI cable has 'anti-virus protection' | ZDNet
http://www.zdnet.com/this-xbox-hdmi-cable-has-anti-virus-protection-7000...

Skype makes chats and user data more available to police - The Washington Post
http://www.washingtonpost.com/business/economy/skype-makes-chats-and-use...

McKinnon extradition decision date set for mid-October | ZDNet
http://www.zdnet.com/mckinnon-extradition-decision-date-set-for-mid-octo...

Power Pwn: This DARPA-funded power strip will hack your network | ZDNet
http://www.zdnet.com/power-pwn-this-darpa-funded-power-strip-will-hack-y...

Eight million passwords stolen from gaming site - Crypto - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/309627,eight-million-passwords-stolen-...

,

And why is Canada a target of spies? I don't quite see what is with Canada that makes them so. - Feed the Children Reviews

,

Following on from the uses of smart-phone wifi detection comes the interesting idea from GM - identify pedestrians before you see them in low-visibility situations.

http://mobile.slashdot.org/story/12/07/29/1412252/gm-working-on-wi-fi-di...

Great show - high point of weeks technical listening

Risky Business #248 -- Being Big Brother on a budget
0:00 / 0:00

Risky Business #247 -- Could a quantum leap spell the end of crypto?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show the NSA's former Technical Director of Information Assurance, Brian Snow, joins the program to warn us that recent advancements in quantum computing could invalidate all of our cryptographic systems within 15 years.

So we'd better get cracking on finding alternatives!

This week's show is brought to you by the security team at Adobe! Big thanks to them. And Adobe's head of security and privacy Brad Arkin will be along later in the show to discuss Adobe's planned deprecation of Flash on mobile devices. As of September 2013 the whole lot goes dark permanently, so how DO you manage that sort of support withdrawal?

That's this week's sponsor interview.

Show notes

Password Leaks Continue: Billabong, NVIDIA Accounts Compromised | threatpost
http://threatpost.com/en_us/blogs/password-leaks-continue-billabong-nvid...

Hacker Claims Compromise of IT Recruiter | threatpost
http://threatpost.com/en_us/blogs/hacker-claims-compromise-wall-street-i...

Yahoo gives all clear after hack attack | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57472023-83/yahoo-gives-all-clear-after...

Microsoft: Fake Skype For Android App Linked To SMS Scams | threatpost
http://threatpost.com/en_us/blogs/microsoft-fake-skype-android-app-linke...

Google Hardens Chrome To Block Malicious Extensions | threatpost
http://threatpost.com/en_us/blogs/google-hardens-chrome-block-malicious-...

Former Pentagon Analyst Warns China Has Back Doors To Global Telcos | threatpost
http://threatpost.com/en_us/blogs/former-pentagon-analyst-warns-china-ha...

FBI Investigating Major Chinese Firm for Selling Spy Gear to Iran | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/fbi-zte/

Senators introduce amended cybersecurity measure | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57476215-83/senators-introduce-amended-...

Skype squashes bug that sends messages to random contacts | ZDNet
http://www.zdnet.com/skype-squashes-bug-that-sends-messages-to-random-co...

Symantec antivirus software update crashes some PCs | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57472624-83/symantec-antivirus-software...

Oracle won't patch zero-day hole in Database | ZDNet
http://www.zdnet.com/oracle-wont-patch-zero-day-hole-in-database-7000001...

Nike hacker steals over $80,000 | ZDNet
http://www.zdnet.com/nike-hacker-steals-over-80000-7000001177/

Officials attack Grum: World's third largest botnet (18% of spam) | ZDNet
http://www.zdnet.com/officials-attack-grum-worlds-third-largest-botnet-1...

Security flaw found in Amazon's Kindle Touch | ZDNet
http://www.zdnet.com/security-flaw-found-in-amazons-kindle-touch-7000001...

Apple iOS in-app purchases hacked; everything is free (video) | ZDNet
http://www.zdnet.com/apple-ios-in-app-purchases-hacked-everything-is-fre...

Charlie Miller: 'Difficult to write exploits' for Android 4.1 | ZDNet
http://www.zdnet.com/charlie-miller-difficult-to-write-exploits-for-andr...

Assad's sexist email jokes leaked | Herald Sun
http://www.heraldsun.com.au/news/breaking-news/assads-sexist-email-jokes...

[Event] Information Security Awareness Tour 2012 - Registration Open and Call for Speakers/Sponsors | in2securITy
http://www.in2security.org.nz/?q=node/153

,

The recruiter is going to be hunted. He messed up with the wrong people. - Feed the Children Reviews

Risky Business #247 -- Could a quantum leap spell the end of crypto?
0:00 / 0:00

Risky Business #246 -- Here lies password authentication. RIP.

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's edition of the show we catch up with Mark Dowd of Azimuth security for a bit of a chat about Apple's upcoming iOS 6 operating system and its security features. We also wind up chatting about Apple's approach to OS security in general and the whole signed code appstore thing, it's fun stuff!

This week's show is brought to you by Tenable Network Security -- the most long term and loyal supporter of this podcast.

Tenable founder and CEO Ron Gula joins us later on in the show to chat about the media hype surrounding DNSChanger and Flame, as well as talking about some really, really rudimentary approaches to picking up stuff your AV may have missed. That's this week's sponsor interview.

In this week's news segment, Insomnia Security's Adam Boileau joins the program to discuss the following stories:

Govt defends need to snoop on online and phone records | Information, Gadgets, Mobile Phones News & Reviews | News.com.au
http://www.news.com.au/technology/govt-defends-need-to-keep-internet-dat...

1.3M Cellphone Snooping Requests Yearly? It's Time for Privacy and Transparency Laws | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/mobile-data-transparency/

AusCERT loses passwords to Govt service - Web/client - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/307954,auscert-loses-passwords-to-govt...

Gone in 3 Minutes: Keyless BMWs a Boon to Hacker Thieves | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/keyless-bmw-gone/

Android forum site hacked; data swiped on 1 million users | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57471297-83/android-forum-site-hacked-d...

Top domains and passwords compromised by Yahoo breach | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57471299-83/top-domains-and-passwords-c...

Formspring disables user passwords in security breach | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57469944-83/formspring-disables-user-pa...

Apple Receives NFC Patent, But Takes It Slow with Mobile Payments | threatpost
http://threatpost.com/en_us/blogs/apple-receives-nfc-patent-taking-it-sl...

Anonymous Group Says It Gave Syrian E-mails to WikiLeaks | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/anonymous-syrian-emails/

WikiLeaks Wins Icelandic Court Battle Against Visa for Blocking Donations | Threat Level | Wired.com
http://www.wired.com/threatlevel/2012/07/wikileaks-visa-blockade/

Instagram Patches "Friendship Vulnerability" Privacy Hole | threatpost
http://threatpost.com/en_us/blogs/instagram-patches-friendship-vulnerabi...

Google Adds Full Flash Sandbox to Chrome 21 | threatpost
http://threatpost.com/en_us/blogs/google-adds-full-flash-sandbox-chrome-...

Google Patches Three High-Priority Flaws in Chrome 20 | threatpost
http://threatpost.com/en_us/blogs/google-patches-three-high-priority-fla...

Microsoft Revokes Trust in 28 of Its Own Certificates | threatpost
http://threatpost.com/en_us/blogs/microsoft-revokes-trust-28-its-own-cer...

NSA Chief Says Today's Cyber Attacks Amount to 'Greatest Transfer of Wealth in History' | threatpost
http://threatpost.com/en_us/blogs/nsa-chief-says-todays-cyber-attacks-am...

Deep Packet Inspection Firm Cyberoam Issues Fix Following Private Key Leak | threatpost
http://threatpost.com/en_us/blogs/deep-packet-inspection-firm-cyberoam-i...

Hackers can break into your Cisco TelePresence sessions | ZDNet
http://www.zdnet.com/hackers-can-break-into-your-cisco-telepresence-sess...

Data-breach laws are coming: OAIC assistant | ZDNet
http://www.zdnet.com/data-breach-laws-are-coming-oaic-assistant-7000000761/

Stratfor Class Action Settlement Email
http://cryptome.org/2012/07/sterling-stratfor-email.htm

Risky Business #246 -- Here lies password authentication. RIP.
0:00 / 0:00

Risky Business #245 -- Drop boxes for the win

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's podcast we're chatting with Jonathan Cran of Pwnie Express.

Pwnie Express makes dropboxes that were designed to be used by pentesters. Funnily enough people have actually found all sorts of non-illicit uses for them.

In this week's sponsor interview we chat with HackLabs' penetration tester Jody Melbourne to ask if there's a future for hacktivists after SQLi bugs are a thing of the past.

In this week's news segment with Adam Boileau we discuss the following items:

'DNSChanger' Malware Could Strand Thousands When Domains Go Dark on
Monday | Threat Level | Wired.com

http://www.wired.com/threatlevel/2012/07/dns-changer-going-dark/

Report: Wireless Hacking Suspected In Air Raid Siren Miscues |
threatpost

http://threatpost.com/en_us/blogs/report-wireless-hacking-suspected-air-raid-siren-miscues-070512

Cisco Pulls Back on Routers' 'Supplemental Privacy Policy' |
threatpost

http://threatpost.com/en_us/blogs/cisco-pulls-back-routers-supplemental-privacy-policy-070312

There is No Reason to Take a Picture of Your Debit Card ...Ever |
threatpost

http://threatpost.com/en_us/blogs/there-no-reason-take-picture-your-debit-card-ever-070312

New Version of Sykipot Trojan Linked To Targeted Attacks On Aerospace
Industry | threatpost

http://threatpost.com/en_us/blogs/new-version-sykipot-trojan-linked-targeted-attacks-aerospace-industry-070312

Mac OS X, Windows Backdoors Used in New APT Attacks | threatposthttp://threatpost.com/en_us/blogs/mac-os-x-windows-backdoors-used-new-apt-attacks-062912

Microsoft Names Two Alleged Zeus Botnet Operators | threatpost
http://threatpost.com/en_us/blogs/microsoft-names-two-alleged-zeus-botnet-operators-070312

Appeals Court Calls Bank's Security "Commercially Unreasonable" |
threatpost

http://threatpost.com/en_us/blogs/appeals-court-calls-bank-s-security-commercially-unreasonable-070512

Senator Seeks to Strengthen SEC-Required Cybercrime Reporting | threatpost
http://threatpost.com/en_us/blogs/senator-seeks-strengthen-sec-required-cybercrime-reporting-070212

Adobe: No Flash Player For Future Android Versions | threatpost
http://threatpost.com/en_us/blogs/adobe-no-flash-player-future-android-versions-062912

Iran state TV: The BBC hacked us | ZDNet
http://www.zdnet.com/iran-state-tv-the-bbc-hacked-us-7000000334/

WikiLeaks starts publishing millions of 'Syria Files' emails | ZDNet
http://www.zdnet.com/wikileaks-starts-publishing-millions-of-syria-files-emails-7000000316/

Want cheaper insurance? Brush up on your IT security | ZDNet
http://www.zdnet.com/want-cheaper-insurance-brush-up-on-your-it-security-7000000251/

NBN Co: Huawei FOI could harm national security | ZDNet
http://www.zdnet.com/nbn-co-huawei-foi-could-harm-national-security-7000000106/

Risky Business #245 -- Drop boxes for the win
0:00 / 0:00

Risky Business #244 -- Padding oracle attacks on crypto tokens: How bad?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

There's a lot of really interesting news this week. Adam Boileau is back on deck at the top of the show to discuss shitty security at the Ecuadorian embassy in London, the new tool DroidSheep, DARPA's (DERPA? Lol.) attempts at securing the architectural mess that is Android, dudes going to prison, other dudes getting away with stuff and much, much more!

In this week's feature interview we chat with Matthew D Greene, Assistant Research Professor at Johns Hopkins University's Information Security Institute. We're talking to him about some recently unveiled attacks against hardware tokens that enable attackers to extract key material that's supposed to be protected. Oops!

Matthew blogged about it here, and the paper we discuss is here [pdf].

This week's show is brought to you by our good friends at SensePost! Sensepost founder and director Charl Van Der Walt will be along in this week's sponsor interview to discuss what he's learned from teaching BlackHat courses for 10 years.

Risky Business #244 -- Padding oracle attacks on crypto tokens: How bad?
0:00 / 0:00

Risky Business #243 -- Quickly! To Ecuador!

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's news segment we cover Julian Assange's attempt at martyrdom in style, claims of a Twitter outage, the cracking of 923-bit pairing-based encryption in Japan, the blackmailing of an American firm by hackers, Face.com's tragic fail, The Washington Post's stunning (not) revelation that Flame was the work of the US and Israel, AutoCAD worms, bug bounties and more!

Insomnia Security's Mark Piper tackles all that at the top of the show. He's filling in for Adam Boileau.

Also in this week's show we're chatting with Adobe's director of product security and privacy Brad Arkin. We're talking to him all about an opinion piece Bruce Schneier wrote for Forbes about twisted incentives in the vulnerability market. It's interesting stuff.

That's this week's sponsor interview.

There's no feature interview this week and possibly no podcast next week. Family stuff.

Risky Business #243 -- Quickly! To Ecuador!
0:00 / 0:00

Risky Business #242 -- Massive recon with HD Moore

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat with Rapid7's H D Moore about massive recon in both the IPv4 and IPv6 worlds. He's been busy basically banner grabbing the entire Internet and he's found some really, really weird stuff out there. There are some very interesting nuggets in that interview. Check it out.

This week's show is brought to you by Tenable Network Security so in this week's sponsor interview we're chatting with Tenable's CSO Marcus Ranum about why the hell people are still using fast hashing algorithms for password storage. We also talk about a couple of novel approaches to authenticating high-value clients in the finance world.

Normally we'd start off with the week's news segment with Adam Boileau, but he's off in Estonia at the moment, so filling in for him this week is his colleague at Insomnia Security, Mark "Pipes" Piper.

Risky Business #242 -- Massive recon with HD Moore
0:00 / 0:00