Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #317 -- Cryptocalypse news plus Dave DeWalt interview

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature guest is the man with the Midas touch -- former McAfee president and current FireEye CEO Dave DeWalt. This is the guy who sold McAfee to Intel for $7.8 billion dollars, so I chat to him about a whole bunch of topics, from his thoughts on how Intel has handled that deal, through to Snowden, to the security business overall. It's a great chat with one of the most interesting executives in this whole industry.

Also this week we chat with Marcus Ranum who's in the sponsor chair on behalf of Tenable Network Security. He's along this week to look back on his very popular 2005 blog post "The six dumbest ideas in computer security". Are they still dumb? Unsurprisingly they are, but the landscape has shifted a bit. That's a great chat and it's coming up later.

Adam Boileau joins the program to discuss the Heartbleed bug and some other infosec news from the last week.

Show notes are here.

Risky Business #317 -- Cryptocalypse news plus Dave DeWalt interview
0:00 / 0:00

Risky Business #316 -- Data breach suits could have legs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're taking a look at the Target/Trustwave suit. A couple of banks were suing Target and its alleged security auditor Trustwave over the massive credit card data breach last year. That suit has been withdrawn, possibly temporarily, and another has been filed on behalf of some other banks. We speak with former New York assistant DA and infosec law specialist Dave Stampley about these types of suits. Do they have legs?

This week we welcome a new sponsor -- Rapid7.

Rapid7 is launching an interesting campaign right now to try to fix the Computer Fraud and Abuse Act (CFAA) in America. They say it's stifling research. Rapid7's global security strategist Trey Ford joins the show to fill us in on that.

As news regulars Adam Boileau and The Grugq are both in Singapore for Syscan and probably nursing cripping hangovers, this week we're joined by a special guest in the news chair, Christopher Hoff. Hoff is the Vice President of Strategy for Juniper Networks' security business unit, but you may know him as Beaker on Twitter.

Show notes

Microsoft to Fix Word Zero Day with Final XP Patch | Threatpost | The first stop for security news
http://threatpost.com/microsoft-to-fix-word-zero-day-with-final-xp-patch...

Barrett Brown Signs Plea Deal in Case Involving Stratfor Hack | Threat Level | WIRED
http://www.wired.com/2014/04/barrett-brown-plea-agreement/

Alleged Silk Road Founder's Lawyer Moves to Dismiss Charges Against His Client | Threat Level | WIRED
http://www.wired.com/2014/04/threatlevel_0401_silkroad_motion/

Will Target's Lawsuit Finally Expose the Failings of Security Audits? | Threat Level | WIRED
http://www.wired.com/2014/03/trustwave-target-audit/

Information Security | Compliance | Trustwave
https://www.trustwave.com/Trustwave-Announcement/

http://www.smh.com.au/it-pro/security-it/default-password-leaves-tens-of... is not available
http://www.smh.com.au/it-pro/security-it/default-password-leaves-tens-of...

Cyber Tool Estimates Incident Response Cost for Businesses | Threatpost | The first stop for security news
http://threatpost.com/tool-estimates-incident-response-cost-for-business...

FTC Settles With Fandango, Credit Karma Over SSL Issues in Mobile Apps | Threatpost | The first stop for security news
http://threatpost.com/ftc-settles-with-fandango-credit-karma-over-ssl-is...

Amazon Web Services Combing Third Parties for Credentials | Threatpost | The first stop for security news
http://threatpost.com/amazon-web-services-combing-third-parties-for-expo...

Yahoo Encrypts Data Center Communication Links | Threatpost | The first stop for security news
http://threatpost.com/yahoo-encrypts-data-center-links-boosts-other-serv...

April Fools' Day prank: parents sent SMS saying school closed
http://www.smh.com.au/technology/technology-news/april-fools-day-prank-p...

DVR Infected with Bitcoin Mining Malware | Threatpost | The first stop for security news
http://threatpost.com/dvr-infected-with-bitcoin-mining-malware/105167

Extended Random: The PHANTOM NSA-RSA backdoor that never was \u2022 The Register
http://www.theregister.co.uk/2014/04/02/extended_random_nsa_rsa_bsafe/

Researcher Identifies Potential Security Issues in Tesla S | Threatpost | The first stop for security news
http://threatpost.com/researcher-identifies-potential-security-issues-wi...

Google DNS Intercepted in Turkey | Threatpost | The first stop for security news
http://threatpost.com/google-dns-intercepted-in-turkey/105136

DOJ Pushes to Expand Hacking Abilities Against Cyber-Criminals - Law Blog - WSJ
http://blogs.wsj.com/law/2014/03/27/doj-pushes-to-expand-hacking-abiliti...

Watch out, journalists: Hackers are after you - CNET
http://www.cnet.com/news/watch-out-journalists-hackers-are-after-you-goo...

Facebook Bug Bounty Submissions Dramatically Increase | Threatpost | The first stop for security news
http://threatpost.com/facebook-bug-bounty-submissions-dramatically-incre...

Android Botnet Targets Middle East Banks - Krebs on Security
http://krebsonsecurity.com/2014/04/android-botnet-targets-middle-east-ba...

Home Routers at Core of DNS-Based DDoS Amplification Attacks | Threatpost | The first stop for security news
http://threatpost.com/dns-based-amplification-attacks-key-on-home-router...

Patch Available for Schneider Electric Serial Modbus Driver | Threatpost | The first stop for security news
http://threatpost.com/critical-vulnerabilities-patched-in-schneider-elec...

Cisco Patches Denial-of-Service Vulnerabilities in IOS | Threatpost | The first stop for security news
http://threatpost.com/cisco-patches-denial-of-service-vulnerabilities-in...

Researchers Divulge 30 Oracle Java Cloud Service Bugs | Threatpost | The first stop for security news
http://threatpost.com/researchers-divulge-30-oracle-java-cloud-service-b...

Apple Fixes More Than 25 Flaws in Safari | Threatpost | The first stop for security news
http://threatpost.com/apple-fixes-more-than-25-flaws-in-safari/105197

GOLDEN THREAD - Passenger featuring Matt Corby - YouTube
https://www.youtube.com/watch?v=Ms0A7pXPySc&feature=kp

KamberLaw | New York & California | Defending your legal rights in a digital world
http://www.kamberlaw.com/

IT Security Data & Analytics, Risk Management, Compliance | Rapid7
http://www.rapid7.com/

Risky Business #316 -- Data breach suits could have legs
0:00 / 0:00

Risky Business #315 -- Nmap's Fyodor talks FD relaunch

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is with nmap creator Gordon Lyon, who's probably better known by his handle: Fyodor.

Last week we brought you the news that the Full Disclosure mailing list was shuttered following legal threats from someone describing themselves as a security researcher. Fyodor runs the seclists.org mailing list archive and he's decided to bring FD back from the dead. I got him on the line and asked him why.

This week's show is brought to you by Bridgepoint -- a Queensland-based company that does all sorts of stuff -- systems integration, pen testing and PCI. With the G20 coming up we chat with the company's principal security consultant Michael Trott about the preparations underway. When the world shines its spotlight on Brisbane in November boy oh boy, everyone with a gripe is going to be trying to deface pretty much every website with the word "Queensland" on it. That's coming up soon.

Adam Boileau, as always, joins us to discuss the week's security news headlines.

Show notes are here.

Risky Business #315 -- Nmap's Fyodor talks FD relaunch
0:00 / 0:00

Risky Business #314 -- FD closure foreshadows cyberpocalypse

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're taking a look at some absolutely awesome research by Azimuth Security's Tarjei Mandt on the pseudo random number generators used by iOS 6 and 7. Tarjei has figured out a way to blow away iOS's memory mitigations with some very cool tricks.

This week's show is sponsored by Tenable Network Security, and this week we're joined by Carlos Perez, Tenable's Director of Reverse Engineering in the sponsor slot. He heard last week's interview all about using PowerShell as a post exploitation tool, and as it turns out, he's one of the leading experts out there on using PowerShell to do sneaky stuff. So he'll be along to pretty much pick up where we left off last week. More PowerShell! That's this week's sponsor interview.

Adam Boileau, as usual, joins us for the week's news headlines.

Show notes are here.

Risky Business #314 -- FD closure foreshadows cyberpocalypse
0:00 / 0:00

Risky Business #313 -- Why you should know PowerShell

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we have a look at PowerShell, the Microsoft sorta scripting language admin thingy. As it turns out, PowerShell can be an attacker's best friend when it comes to lateral movement through a network. We'll chat with Kieran Jacobson about that in this week's feature interview. He did a cracker presentation at CrikeyCon where he demo'd owning a domain controller and dumping all its creds with something like five lines of PowerShell. I mean, there are caveats there, but wow... the demotime was food for thought.

This week's show is sponsored by HackLabs. HackLabs head honcho Chris Gatford joins the program in this week's sponsor interview to have a yarn about the upcoming great XP switch of 2014. Ditching XP in your environment shouldn't be a supreme challenge, but what about specialist devices? Like the heart monitor that you can't patch but needs to be networked so you can know Mr. Jones in 14F is about to have a heart attack? Yeah, that'd be one of those intractable problems. Yay.

Show notes

Study Shows 'Metadata is Highly Sensitive' | Threatpost | The first stop for security news
http://threatpost.com/study-shows-phone-metadata-is-highly-sensitive/104767

HTTPS Traffic Attacks Leak Sensitive Personal Details | Threatpost | The first stop for security news
http://threatpost.com/new-attacks-on-https-traffic-reveal-plenty-about-y...

NSA Has Been Hijacking the Botnets of Other Hackers | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/03/nsa-botnet/

NSA Denies Impersonating Facebook to Exploit Targets | Threatpost | The first stop for security news
http://threatpost.com/nsa-denies-impersonating-facebook-to-exploit-targe...

Charitable Prelude to Pwn2Own Not Without Its Critics | Threatpost | The first stop for security news
http://threatpost.com/charitable-prelude-to-pwn2own-not-without-its-crit...

Vupen Cashes in Four Times at Pwn2Own 2014 | Threatpost | The first stop for security news
http://threatpost.com/vupen-cashes-in-four-times-at-pwn2own/104754

Weak Early Random PRNG Threatens iOS 7 Kernel Mitigations | Threatpost | The first stop for security news
http://threatpost.com/weak-random-number-generator-threatens-ios-7-kerne...

Researcher Eric Filiol Withdraws CanSecWest Presentation | Threatpost | The first stop for security news
http://threatpost.com/cansecwest-presenter-self-censors-risky-critical-i...

162,000 WordPress Sites Used in DDoS Attack | Threatpost | The first stop for security news
http://threatpost.com/162000-wordpress-sites-used-in-ddos-attack/104745

NTP Amplification DDoS Attacks Increasing | Threatpost | The first stop for security news
http://threatpost.com/ntp-amplified-ddos-attacks-on-the-rise/104741

Experian Lapse Allowed ID Theft Service Access to 200 Million Consumer Records - Krebs on Security
http://krebsonsecurity.com/2014/03/experian-lapse-allowed-id-theft-servi...

Energy Watering Hole Attack Used LightsOut Exploit Kit | Threatpost | The first stop for security news
http://threatpost.com/energy-watering-hole-attack-used-lightsout-exploit...

Malware Analysis: The Final Frontier: LightsOut EK: "By the way... How much is the fish!?"
http://malwageddon.blogspot.com.au/2013/09/unknown-ek-by-way-how-much-is...

MelbourneIT stores domain passwords in cleartext - Security - Technology - News - iTnews.com.au
http://www.itnews.com.au/News/374095,melbourneit-stores-domain-passwords...

How Target detected hack but failed to act -- Bloomberg | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57620289-83/how-target-detected-hack-bu...

Backdoor in Samsung Galaxy Devices Could Give Attackers Access | Threatpost | The first stop for security news
http://threatpost.com/backdoor-in-samsung-galaxy-devices-could-give-atta...

Google Fixes Four High-Risk Flaws in Chrome Before Pwn2Own | Threatpost | The first stop for security news
http://threatpost.com/google-fixes-four-high-risk-flaws-in-chrome-before...

Microsoft Resolves IE Zero Day with Patch Tuesday Release | Threatpost | The first stop for security news
http://threatpost.com/microsoft-closes-ie-zero-day-ships-final-xp-patch-...

IE Zero Day Exploits Increase Just Before Patch | Threatpost | The first stop for security news
http://threatpost.com/hackers-milk-ie-zero-day-before-patch/104713

Apple iOS 7.1 Fixes More Than 20 Code-Execution Flaws | Threatpost | The first stop for security news
http://threatpost.com/apple-ios-7-1-fixes-more-than-20-code-execution-fl...

Risky Business #313 -- Why you should know PowerShell
0:00 / 0:00

Risky Business #312 -- RSA special edition

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

It's a solid week for BitCoin news. The (maybe) outing of the elusive Satoshi Nakamoto, the MtGox mystery, dead exchanges and even, unfortunately, a suicide of a former BitCoin exchange CEO in Singapore.

But there's been plenty of other news! Apple's gotofail bug, GnuTLS issues, more NTP amplification attacks, and of course YahooWebcamGate. You can find links to the news items discussed in this week's show here.

There's also a stack of interviews in this week's podcast, including a bunch recorded in San Francisco last week. The run sheet looks like this:

\t- The Grugq discussing the news headlines of the last two weeks
\t- Marcus Ranum on the RSA trade floor discourse
\t- RSA CEO Art Coviello on the NSA controversy
\t- ACLU principal technologist Chris Soghoian
\t- RSA Chief Architect Robert Griffin
\t- Jack Daniel of Tenable Network Security (sponsor interview) on the "Threat Intelligence" buzzword craze

Risky Business #312 -- RSA special edition
0:00 / 0:00

Risky Business #311 -- Does NameCoin have legs?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week we chat with a local consultant, Mark Brand of Datacom TSS, about the general topic of authentication. We've seen some interesting cases of things going wrong with auth on consumer sources lately. The @n Twitter username hijacking, the Matt Honan disaster of 2012.

Now Google's run off and bought SlickLogin, a novel approach to mobile app auth. Will that get us anywhere? And what about NameCoin -- a BitCoin protocol-derived peer-to-peer authentication scheme? I'd never heard of it, but the concept is fascinating. Mark pops by to fill us in.

This week's show is brought to you by Senetas. In this week's sponsor interview we're chatting with Senetas CTO Julian Fay about some work they've been doing on their Ethernet products. As it turns out, variable frame sizes can give up too much info to an attacker, so they've worked on some neat new tech that basically forces their stuff to send fixed length frames and make sure everything stays random.

Adam Boileau pops by as usual to chat about the week's security news. Show notes, including links, are here.

Risky Business #311 -- Does NameCoin have legs?
0:00 / 0:00

Risky Business #310 -- Export exploits? Wassenaar says no

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with COSEINC's Thomas Lim about the Wassenaar Arrangement. It's basically a worldwide framework that restricts the sale of munitions and dual use technologies, and it has exploits in its sites.

COSEINC is a security research company that engages in exploit development, and Lim thinks extending regulations to exploit sales is pointless.

This week's show is brought to you by BugCrowd, a company that was founded in Australia but is now based in San Francisco thanks to VC investment.

Bugcrowd runs outsourced bug bounties, and its founder and CEO Casey Ellis joins the show in this week's sponsor interview to talk about the latest goings on in the burgeoning bug bounty industry!

Show notes

Top U.S. Spy Claims 'Terrorists Are Going to School' on Snowden Leaks | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/clapper-snowden-fallout/

Hacked X-Rays Could Slip Guns Past Airport Security | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/tsa-airport-scanners/

Sophisticated Spy Tool 'The Mask' Rages Undetected for 7 Years | Threat Level | Wired.com
http://www.wired.com/threatlevel/2014/02/mask/

Public servant Peter Nash allegedly ran drug ring from Wacol prison | The Courier-Mail
http://www.couriermail.com.au/news/queensland/public-servant-peter-nash-...

400 Gbps NTP Amplification DDoS Attack Alarmingly Simple | Threatpost | The first stop for security news
http://threatpost.com/400-gbps-ntp-amplification-attack-alarmingly-simpl...

HVAC Vendor: Data Connection to Target was Billing System | Threatpost | The first stop for security news
http://threatpost.com/hvac-integrators-billing-connection-led-to-target-...

faziomechanical.com/Target-Breach-Statement.pdf
http://faziomechanical.com/Target-Breach-Statement.pdf

Websites of Las Vegas Sands casinos hacked, including Venetian, Palazzo on Las Vegas Strip | Star Tribune
http://www.startribune.com/lifestyle/244922181.html

Errata Security: That NBC story 100% fraudulent
http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudulent.html#.Uv...

Detecting Car Hacks | Threatpost | The first stop for security news
http://threatpost.com/detecting-car-hacks/104190

illmatics.com/car_hacking.pdf
http://illmatics.com/car_hacking.pdf

CoinThief Bitcoin Trojan Found on Popular Download Sites | Threatpost | The first stop for security news
http://threatpost.com/cointhief-bitcoin-trojan-found-on-popular-download...

Bitcoin Foundation, Mt. Gox spar over purported bug | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57618646-83/bitcoin-foundation-mt-gox-s...

Florida Targets High-Dollar Bitcoin Exchangers - Krebs on Security
http://krebsonsecurity.com/2014/02/florida-targets-high-dollar-bitcoin-e...

LinkedIn Intro Service to Shut Down March 7 | Threatpost | The first stop for security news
http://threatpost.com/controversial-linkedin-intro-service-to-shut-down/...

Snapchat hack spams users with smoothie photos | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57618782-83/snapchat-hack-spams-users-w...

Facebook Fixes CSRF Vulnerability in Instagram | Threatpost | The first stop for security news
http://threatpost.com/facebook-fixes-instagram-csrf-vulnerability-to-kee...

Five OAuth Bugs Lead to Github Hack | Threatpost | The first stop for security news
http://threatpost.com/five-oauth-bugs-lead-to-github-hack/104178

Adobe Patches Shockwave, Fixes Two Vulnerabilities | Threatpost | The first stop for security news
http://threatpost.com/adobe-patches-critical-vulnerabilities-in-shockwav...

February 2014 Microsoft Patch Tuesday Security Bulletins | Threatpost | The first stop for security news
http://threatpost.com/microsoft-adds-critical-ie-patches-under-the-wire/...

New IE Zero-Day Found in Watering Hole Attack | FireEye Blog
http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/new-ie-zero...

Operation SnowMan: DeputyDog Actor Compromises US Veterans of Foreign Wars Website | FireEye Blog
http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-depu...

Changes to Export Control Arrangement Apply to Computer Exploits and More | Center for Internet and Society
https://cyberlaw.stanford.edu/publications/changes-export-control-arrang...

Bugcrowd | Managed bug bounty programs, better security testing
https://bugcrowd.com/mobile-application-security

Pumped Up Kicks by Hailey-Marie on SoundCloud - Hear the world's sounds
https://soundcloud.com/hailey-marie-mcfadden/pumped-up-kicks

Risky Business #310 -- Export exploits? Wassenaar says no
0:00 / 0:00

Risky Business #309 -- All your clipboards R belong 2 OJ

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

We're back after a nice long rest, and boy oh boy did a lot of stuff happen during the break. Adam Boileau joins the show to discuss the choicest selection of news items to emerge over the last six weeks.

In this week's feature slot we chat to OJ Reeves about his work in upgrading Meterpreter, the Metasploit payload. There are some cool new features on the way, he'll clue us in on those.

This week's show is brought to you by Tenable Network Security.

Tenable's very own Marcus Ranum will be joining us to have a chat about security metrics in this week's sponsor interview, stick around for that.

Show notes for this week's episode are here.

Patrick Gray on Twitter.
Adam Boileau on Twitter.

Risky Business #309 -- All your clipboards R belong 2 OJ
0:00 / 0:00

Risky Business #308 -- 2013 in review

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This is the final Risky Business podcast for 2013. The show will resume its weekly schedule in February 2014.

Oh, and there are still three sponsor slots left between now and July. If you're interested, drop us a line with the contact form...

This week's show looks back over the key events and trends of 2013; how media focus shifted from focussing on China's cyber-espionage to the scandalous revelations of the Snowden leaks.

We also take a quick look at the Silk Road bust, say goodbye to some friends and check in with Insomnia Security's Brett Moore in this week's sponsor interview.

Risky Business #308 -- 2013 in review
0:00 / 0:00