Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #277 -- Vuln research trends with Mark Dowd

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is with Mark Dowd of Azimuth Security. Mark joins the show to fill us in on the latest trends in vulnerability research and exploit development. We recap CanSecWest's Pwn2Own competition and look at what 2013 has in store research-wise.

Risky.Biz is pleased to welcome a new sponsor to the lineup -- Solera Networks, makers of fine, big data security software.

These guys make packet capture-based security kit that I'm told is pretty impressive. And we've got an interesting chat in this week's sponsor interview with Solera's chief technology officer Joe Levy. We chat to him about some of the basics of big data security, as well as looking at how point solution providers are increasingly integrating their kit with established SIEM gear and log management consoles.

Insomnia Security's Adam Boileau joins us for a discussion of the week's news.

Show notes here.

Risky Business #277 -- Vuln research trends with Mark Dowd
0:00 / 57:07

Risky Business #276 -- Cold and flu edition

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is another shorter one! I've been sick so I just couldn't pull together a feature interview.

We've also got a chat with this week's sponsor guest Chris Gatford of the Australian security consulting firm HackLabs.

We chat to Chris about the whole Spamhaus DDoS disaster. How damaging is it when the world's media distracts business and government leaders with stuff like this? What *should* these leaders really be concerned with?

Show notes

You can find this week's show here.

DDoS Attack, Database Breach Take Down Two Bitcoin Services | threatpost

Adaptive Glass - Mobile Trends | Open Letter to Instawallet

Daily chart: A Bit expensive | The Economist

Justin Schuh - Google+ - What Blink means for Chrome Security The Chromium project\u2026

Vulnerability Patched in PostgreSQL Database Server | threatpost

PostgreSQL: 2013-04-04 Security Release FAQ

SEC Consult Vulnerability Alert: Critical Vulnerabilities In Sophos Web Protection Appliance - Dark Reading

iMessage denial of service 'prank' spams users rapidly with messages, crashes iOS Messages app - The Next Web

Anonymous hacks North Korea's Twitter and Flickr accounts | Security & Privacy - CNET News

Who Wrote the Flashback OS X Worm? - Krebs on Security

Huawei exec sees no growth in U.S. this year | Security & Privacy - CNET News

How the Spamhaus DDoS attack could have been prevented | Security & Privacy - CNET News

FTC Announces Winners of Death-to-Robocalls Challenge | Threat Level | Wired.com

DHS Warns of 'TDos' Extortion Attacks on Public Emergency Networks - Krebs on Security

Skype, Dropbox Patch Critical Facebook Authentication Bugs | threatpost

Using Customer Premise Equipment to Take Over the Internet | threatpost

Phishing Campaign Using Military, Illicit Attachments | threatpost

Has Anyone Seen a Missing Scroll Bar? Phony Flash Update Redirects to Malware | threatpost

Spammers Finding Favor with Google Translate | threatpost

Android malware again targets Tibetans - Applications - SC Magazine Australia - Secure Business Intelligence

Backdoor Uses Evernote as Command and Control Server | Security Intelligence Blog | Trend Micro

Government Fights for Use of Spy Tool That Spoofs Cell Towers | Threat Level | Wired.com

Secret Files Expose Offshore's Global Impact | International Consortium of Investigative Journalists

Aussie software ferrets out hidden money - Strategy - Business - News - iTnews.com.au

Hackers in Uganda: A Documentary by Jeremy Zerechak - Kickstarter

Penetration Testing & Web Application Security - HackLabs


The dream they have is really good. I guess they need to get the whole thing going. - Roger Stanton

Risky Business #276 -- Cold and flu edition
0:00 / 51:17

Risky Business #275 -- Patch Tuesday, Indicator Wednesday?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's show is brought to you by our longest term sponsor, Tenable Network Security, thanks guys. In this week's sponsor interview we chat with the CEO and co-founder of Tenable, industry stalwart Ron Gula. We're chatting to him about a funny idea -- that the release of indicators of compromise might become so regular that they'll have to be handled in regular info sec team workflow. So we'll have Patch Tuesday and "which IPs owned us" Wednesday.

It's a really interesting chat and it's after the news. It's a short week this week because of Easter, plus I'm in Melbourne taking care of a few things, so there's no feature interview this week.

Show notes

Spamhaus DDoS Attacks Triple Size of Attacks on US Banks | threatpost

That Internet War Apocalypse Is a Lie

South Korean cyberattack may not have come from China | Security & Privacy - CNET News

Spear Phishing Cause of South Korean Cyber Attack | threatpost

Legal Experts: Stuxnet Attack on Iran Was Illegal 'Act of Force' | Threat Level | Wired.com

Top Chinese university linked to alleged military cybercrime unit | Security & Privacy - CNET News

Don't Just Hate CISPA - Fix It | Wired Opinion | Wired.com

Draft US cyber bill seeks 10 years jail for passwords 'traffickers' - Applications - SC Magazine Australia - Secure Business Intelligence

Outdated Java weak spots are widespread, Websense says | Security & Privacy - CNET News

Apple ID security issue fixed, password page back online | Security & Privacy - CNET News

Apple Sets May 1 End Date for Apps that Want UDIDs | threatpost

Missouri Court Rules Against $440,000 Cyberheist Victim - Krebs on Security

Attackers Shifting to Delivering Unknown Malware Via FTP and Web Pages | threatpost

Privacy 101: Skype Leaks Your Location - Krebs on Security

Researchers Uncover Targeted Attack Campaign Using Android Malware | threatpost

Anonymized Phone Location Data Not So Anonymous, Researchers Find | Threat Level | Wired.com

ICS Vulnerabilities Surface as Monitoring Systems Integrate with Digital Backends | threatpost

Sensitive Enterprise Data Exposed in Amazon S3 Public Buckets | threatpost

83,000 Kiwis exposed in email blunder - Messaging - SC Magazine Australia - Secure Business Intelligence

Google Fixes 11 Flaws in Chrome | threatpost

Egyptian navy captures divers trying to cut undersea internet cables \u2022 The Register

We have Microsoft Tuesday, so how long until we have Indicator Wednesday? | Tenable Network Security

SW&theE | The Simon Wright Band


Of course, the internet apocalypse is a lie. I guess we can be so sure about that one. - James Cullem

Risky Business #275 -- Patch Tuesday, Indicator Wednesday?
0:00 / 43:30

Risky Business #274 -- Is "active defence" legal?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we chat with Jennifer Granick, the Head of Civil Liberties at Stanford University's Centre for Internet and Society. Jennifer has extensive experience with cyberlaw -- she has acted for clients as diverse as Aaron Swartz and HBGary! She's done it all! And she joins the show to talk about a few things -- is active defence ever legal? And what the hell is going on with the Computer Abuse and Fraud Act over there in the USA?

This week's show is brought to you by Senetas, makers of fine, fine crypto hardware. If you need some crypto in your second layer, I'd suggest you get in touch with these guys. Awesome gear and as you'll hear in this week's sponsor interview with Senetas co-founder and CTO Julian Fay, these guys really know their stuff.

Julian joins the show a bit later on to talk about what happens when his customers ask them to roll with custom algos because some of them don't trust those published crypto techniques.

Show notes

You can find this week's episode here.

South Korea: Chinese address source of attack

South Korea traces cyberattack to IP address in China | Security & Privacy - CNET News

Theories Abound on Wiper Malware Attack Against South Korea | threatpost

Twitter / LukeCleary: @W7VOA http://t.co/EGMq34ssk6

CCD COE - The Tallinn Manual

NATO cyberwar directive declares hackers military targets - RT USA

What 420,000 insecure devices reveal about Web security | Security & Privacy - CNET News

Internet Census 2012

Decade-old espionage malware found targeting government computers | Ars Technica

CIA $600 Million Deal For Amazon's Cloud - Business Insider

Firm faces scrutiny over hacked ABC website

Experts Tell Congress Serious Deterrence Needed to Impede Foreign Cyber Attacks | threatpost

AT&T Hacker 'Weev' Sentenced to 3.5 Years in Prison | Threat Level | Wired.com

Keys denies giving Tribune log-in credentials to Anonymous | Security & Privacy - CNET News

Cautious Optimism over Google DNSSEC Deployment | threatpost

Java Code, Details Released for Potential Sandbox Bypass Issue | threatpost

Vulnerabilities Continue to Weigh Down Samsung Android Phones | threatpost


Cisco switches to weaker hashing scheme, passwords cracked wide open | Ars Technica

Apple adds two-step verification option for Apple IDs | Security & Privacy - CNET News

Crown casino made no formal complaint to police after $32 million scam | News.com.au

Crown casino hi-tech scam nets $32 million | News.com.au

'Chameleon Botnet' takes $6-million-a-month in ad money | Security & Privacy - CNET News

Security reporter hit by 'swatting' attack | Security & Privacy - CNET News

Jennifer Granick | Center for Internet and Society

Senetas grants master distribution status to SafeNet - SafeNet, Senetas, distribution deals - ARN

Ash Grunwald - Longtime - YouTube


The source of attack will be very good. They need to get the whole thing very good. - James Cullem

Risky Business #274 -- Is "active defence" legal?
0:00 / 67:30

Risky Business #273 -- The birth of the online Pinkertons?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week's feature interview we're chatting to industry legend and In-Q-Tel CSO Dan Geer about the idea of offence as defence. If someone's attacking you do you have the moral right to attack them back? Dan actually thinks you do.

This week's show is brought to you by Adobe.

Adobe's head of product security and privacy Brad Arkin pops along to have a bit of a chat about the busy few months they've been having at Adobe dealing with some interesting bugs.

Show notes

Intelligence chief offers dire warning on cyberattacks | Security & Privacy - CNET News

Spy Chief Says Little Danger of Cyber 'Pearl Harbor' in Next Two Years | Threat Level | Wired.com

RBA Chinese hack attack not an online security threat | Crikey

Twitter OAuth API Keys Leaked | threatpost

Spy Agencies to Get Access to U.S. Bank Transactions Database | Threat Level | Wired.com

Secret Courtroom Audio Gives WikiLeaker Bradley Manning a Voice | Threat Level | Wired.com

Retailer Sues Visa Over $13 Million 'Fine' for Being Hacked | Threat Level | Wired.com

LinkedIn Data Breach Lawsuit Dismissed | threatpost

Doctors 'used fake fingers' to clock in for colleagues at ER | Security & Privacy - CNET News

Google rolls out initiative to help hacked sites | Security & Privacy - CNET News

FBI investigating how sensitive celebrity data landed on Web | Security & Privacy - CNET News

White House demands China cease alleged hacking activity | Security & Privacy - CNET News

China claims it's willing to talk to U.S. about cybersecurity | Security & Privacy - CNET News

How Skype monitors and censors its Chinese users | Security & Privacy - CNET News

Many Watering Holes, Targets In Hacks That Netted Facebook, Twitter and Apple | The Security Ledger

Colin Powell's Facebook page defaced | Security & Privacy - CNET News

Researchers highlight potential security risk to iOS users | Security & Privacy - CNET News

Apple marketing chief jabs Android security on Twitter | Security & Privacy - CNET News

Apple Finally Fixes App Store Vulnerabilities | threatpost

Researchers win $100,000 for Chrome hack that leaves Windows vulnerable | Security & Privacy - CNET News

Microsoft patches against evil maid attack - Applications - SC Magazine Australia - Secure Business Intelligence

Adobe Fixes Four Critical Flaws in Flash | threatpost

'Herp Derp EFTPOS' update goes public - Security - Technology - News - iTnews.com.au

Hijacked webcam footage paraded online - Applications - SC Magazine Australia - Secure Business Intelligence

Indian Govt pays bounty for botnet probe - Networks - SC Magazine Australia - Secure Business Intelligence

DOWNLOAD: Kenneth Bager - Fragment Seven (Les Fleurs) (Jesse Rose remix) - RCRD LBL


Those cyber attacks are imminent. I guess we all should be aware of that one. - Kris Krohn

Risky Business #273 -- The birth of the online Pinkertons?
0:00 / 59:13

Risky Business #272 -- Jon Callas talks Silent Circle

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we chat to PGP Corporation co-founder Jon Callas. Jon's been in the security business for a long time and he's bringing us up to speed on his latest venture, Silent Circle.

This week's show is brought to you by the Australian security consulting and penetration testing firm HackLabs. And we've got a really interesting sponsor interview with HackLabs head honcho Chris Gatford about how many, many organisations simply don't do any foot-printing... and it means they miss so much! Come on people, it's a two-day job!

Adam Boileau, as usual, joins us for this week's news segment.

Show notes

Episode 272 can be found here.

The Java Zero-Day Procession Continues | threatpost

New Java 0-Day Attack Echoes Bit9 Breach - Krebs on Security

Oracle issues emergency Java update to patch vulnerabilities | Security & Privacy - CNET News

Prompted by Oracle Rejection, Researcher Finds Five New Java Sandbox Vulnerabilities | threatpost

More Java-based malware plagues the cross-platform runtime | Security & Privacy - CNET News

Jailed hacker allowed into IT class, hacks prison computers | Security & Privacy - CNET News

Groundbreaking Cyber Fast Track Research Program Ending | threatpost

Google Says the FBI Is Secretly Spying on Some of Its Customers | Threat Level | Wired.com

Attorney General: Aaron Swartz Case Was a 'Good Use of Prosecutorial Discretion' | Threat Level | Wired.com

White House, FCC Chairman Support Legalizing Unlocking of Mobile Phones | Threat Level | Wired.com

Mobile Malcoders Pay to (Google) Play - Krebs on Security

APT1-Themed Spear Phishing Campaign Linked to China | threatpost

Google Patches 10 Chrome Flaws Ahead of Pwn2Own, Pwnium | threatpost

Time Stamp Bug in Sudo Could Have Allowed Code Entry | threatpost

MiniDuke Espionage Campaign Began About a Year Earlier Than First Thought | threatpost

Apple Begins to Blacklist Old Versions of Flash for Safari | threatpost

Evernote Compromised, But Says No User Data Affected | threatpost

Locked-down BlackBerry offers classified, personal use | Security & Privacy - CNET News

CloudFlare security service goes down after router failure | Security & Privacy - CNET News

The most secure Android phone in the world (maybe) | Security & Privacy - CNET News

Sudden death of U.S. engineer in Singapore linked to cyber espionage? | Security & Privacy - CNET News

Dropbox users getting spammed, might be from earlier hack | Security & Privacy - CNET News

Anonymous leaks alleged data on BofA execs, surveillance | Security & Privacy - CNET News

Dell builds sinkhole data-sharing platform - Applications - SC Magazine Australia - Secure Business Intelligence

CommBank builds security fault tree after RSA breach - Networks - SC Magazine Australia - Secure Business Intelligence

Use decoy and deception to mess with hackers - Applications - SC Magazine Australia - Secure Business Intelligence

Hackers focus energy on solar sector - Networks - SC Magazine Australia - Secure Business Intelligence

silent circle - Google Search

Here's this week's sponsor: Buy their stuff!!!

Penetration Testing & Web Application Security - HackLabs


The zero day attack is really good. I guess they are aware of what they have. - Kris Krohn

Risky Business #272 -- Jon Callas talks Silent Circle
0:00 / 61:25

Risky Business #271 -- All your funnycats R belong 2 APT1

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're chatting with Mandiant's Managing Director of Threat Intelligence, Dan McWhorter, about that company's report into Chinese cyber espionage activity.

Mandiant dropped the report last week and it's caused quite a stir, even eliciting a response from the Whitehouse and Chinese officials.

That's an interesting conversation and it's after the news.

This week's show is brought to you by Tenable Network Security, makers of fine vulnerability scanning and SIEM software. Tenable's product manager and all-round nice guy Jack Daniel will be along in this week's sponsor interview to discuss some other aspects of this APT1 issue.

Like, for example, how the attackers were using executable trojans embedded in zip files and still managed to own half the Western world's intellectual property. That's this week's sponsor interview -- an interesting blend of hilarious and depressing.

Show notes

Bradley Manning Takes "Full Responsibility" for Giving WikiLeaks Huge Government Data Trove | Threat Level | Wired.com

The Incredible Rise and Fall of a Hacker Who Found the Secrets of the Next Xbox and PlayStation-And Maybe More

Sentencing of LulzSec double agent postponed | Security & Privacy - CNET News

Stuxnet Missing Link Found, Resolves Some Mysteries Around the Cyberweapon | Threat Level | Wired.com

EXCLUSIVE: Hacked ABC website likely breached by crooks in 2011 | Risky Business

MiniDuke Espionage Malware Hits Governments in Europe Using Adobe Exploits | threatpost

Adobe Patches Two Critical Flash Player Vulnerabilities | threatpost

Chrome 25 Fixes Nine High-Risk Vulnerabilities | threatpost

Latest Kelihos Botnet Shut Down Live at RSA Conference 2013 | threatpost

RSA Conference 2013: Experts Say It's Time to Prepare for a 'Post-Crypto' World | threatpost

Two More Java Zero Days Found by Polish Research Team | threatpost

Microsoft Azure Cloud Storage Suffers Major Outage Over Expired SSL Certificate | threatpost

Feds Used Aaron Swartz's Political Manifesto Against Him | Threat Level | Wired.com

Facebook Patches OAuth Authentication Vulnerability | threatpost

China blames U.S. for most cyberattacks against military Web sites | Security & Privacy - CNET News

Add Microsoft to list of hacked companies | Security & Privacy - CNET News

ATO passwords stored in clear text - Web/client - SC Magazine Australia - Secure Business Intelligence

Mandiant Intelligence Center Report | Mandiant\xae

Tenable Network Security

Das EFX - Straight Out The Sewer - YouTube

Patrick Gray on ABC television, discussing ABC breach


Xbox and Playstation has its secret? Wow, this is a conspiracy theory in one way or another. - Mission Maids

Risky Business #271 -- All your funnycats R belong 2 APT1
0:00 / 66:41

Risky Business #270 -- Red teaming your law firm for fun and profit

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we're taking a look at the issue of secondary targeting. These days it's borderline likely that attackers who want information on your company's upcoming mergers and acquisition activity won't even bother attacking you to get the intel. They'll go for your law firm instead... or your accountants... or another partner.

CERT Australia Executive Manager Dr. Carolyn Patterson joins the show to talk about that.

This week's show is brought to you by Senetas, makers of fine, layer 2 encryption hardware boxens! If you're planning a greenfields development, please, please, please go visit the Senetas website. They're a publicly listed company and they make really good gear. This week's sponsor interview is with Senetas co-founder and CTO Julian Fay, who as you'll discover, really knows what he's talking about.

This week we chat to Julian about the various certification schemes out there -- FIPS, Common Criteria and CAPS. We talk about some of the problems with these schemes, and also about some of the changes that are being made to them. Certification is changing, big time, so make sure you listen to that one.

Risky Business #270 -- Red teaming your law firm for fun and profit
0:00 / 61:05

Risky Business #269 -- Dave Aitel on the end of clientsides

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week's show we have a chat with industry stalwart Dave Aitel of Immunity Inc.

Dave joins us to chat about a few things -- like what it will be like when clientside memory corruption exploits become as rare as server side corruption exploits are now. How will that change the security discipline? We also have a chat about El Jefe and sneaky ways of handling command and control.

This week's show is brought to you by NCC Group, the global information security firm. NCC Group's Asia Pacific General Manager and BeEF project creator Wade Alcorn joins us in this week's sponsor slot to chat about recent Ruby on Rails bugs. It's been patched three times in the last month! But how much of a problem is that for you?

Is Ruby on Rails being used for serious business? Should it be?

You can find Patrick on Twitter here and Adam here.

Show notes

Security Firm Bit9 Hacked, Used to Spread Malware - Krebs on Security

Microsoft Report Examines Socio-Economic Relationships to Malware Infections | threatpost

Cybersecurity Executive Order Short on Action, Long on Voluntary Initiatives | threatpost

White House Must Respond to Petition Seeking Swartz Prosecutor's Firing | Threat Level | Wired.com

DHS Watchdog OKs 'Suspicionless' Seizure of Electronic Devices Along Border | Threat Level | Wired.com

Malware Intelligence Lab from FireEye - Research & Analysis of Zero-Day & Advanced Targeted Threats:In Turn, It's PDF Time

Emergency Adobe Flash Player Patches Fix Pair of Zero Days | threatpost

Microsoft's next Patch Tuesday to fix 57 security bugs | Security & Privacy - CNET News

Hackers can easily breach Emergency Alert Systems | Security & Privacy - CNET News

Ransomware cybercrime ring dismantled in Europe | Security & Privacy - CNET News

Old OS X malware used in increased attacks against Uyghur groups | Security & Privacy - CNET News

Anonymous fails to shut down live streams of Obama address | Security & Privacy - CNET News

Gmail of journalists in Myanmar said to be hacked | Security & Privacy - CNET News

Audacious Hack Exposes Bush Family Pix, E-Mail | The Smoking Gun

Telecom NZ says 22,500 Xtra email accounts hacked - Networks - SC Magazine Australia - Secure Business Intelligence

Yahoo! Pushing Java Version Released in 2008 - Krebs on Security

Mega security bugs detailed - Web/client - SC Magazine Australia - Secure Business Intelligence

Australian Tax System Breached By Criminals

CERT Australia rebuffs ex-staff criticism - Networks - SC Magazine Australia - Secure Business Intelligence

Theoretical Lucky Thirteen TLS Attacks Could Turn Practical | threatpost

VMware Fixes Privilege Escalation Vulnerability | threatpost

Ballot-stuffing bot hits News Ltd polls - Web/client - SC Magazine Australia - Secure Business Intelligence

The Ubermotive Guide to Media Influence |

Media Watch: News gets gamed (11/02/2013)

Anonymous intends to block Webcasts of State of the Union | Security & Privacy - CNET News

IMMUNITY : Knowing You're Secure

IMMUNITY : Knowing You're Secure

JaFFer Music, Lyrics, Songs, and Videos

BeEF - The Browser Exploitation Framework Project

Information Security, Escrow & Other Solutions - NCC Group


This week's show should not be missed. i am definite for the real thing that we will learn on this show. looking forward to it. - Flemings Ultimate Garage

Risky Business #269 -- Dave Aitel on the end of clientsides
0:00 / 56:46

Risky Business #268 -- Outsource your bug bounty program?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

This week's feature interview is with Casey Ellis of BugCrowd.com -- a new business that runs outsourced bug bounty programs. It's a great idea and it's one that I personally think will really take off over the next couple of years.

This week's show is brought to you by our good friends at Adobe.

Adobe's director of product security and privacy Brad Arkin will be along a bit later on with an update on the phantom 0day issue the company experienced last year, as well as filling us in on some efforts designed to combat spearphishing attacks that use dodgy Flash objects embedded in Office files. It's more interesting than it sounds!

Adam Boileau is back in the news seat for a chat about recent headlines. You can find links to all the articles we discussed here.

Risky Business #268 -- Outsource your bug bounty program?
0:00 / 66:58