SecuraBit
SecuraBit Before It Bytes!
SecuraBit Episode 47: Double Dutch! Listen in as we interview 1Password and NetWitness! Dave Teare - Co-Founder of 1Password Agile Web Solutions' 1 Password http://agilewebsolutions.com/products/1Password Q's What was the motivation to create 1Password? There are two key chain types that are used. Why the switch to the other one? When will we be able to sync across the iphone cord? (Edge/3G) 8.02.11 BGA type Are there plans to port 1Password to Win/Lin platforms? 1password Anywhere? Is there a way to import from other password managers? CSV format what is the difference between the 1password pro and the touch pro? http://help.agile.ws/1Password_touch/pro_vs_standard.html What is the diffrence between 1Password and 1Password Pro? Who actually maintains the twitter account? Find out more at http://get1password.com NetWitness - Eddie Schwartz http://www.netwitness.com/ Q's How long have you been with NetWitness? http://download.netwitness.com/ http://download.netwitness.com/download.php?src=DIRECT Google Earth integration - Very Cool!! What OS will the free or paid version work on and will it work from within a VM? What does netwitness do at the layer 7 level? Join us in IRC at irc.freenode.net #securabit Hosts: Anthony Gartner – @anthonygartner Christopher Mills – @thechrisam Jason Mueller - @securabit_jay Andrew Borel – @andrew_secbit Guests: Dave Teare - 1Password Eddie Schwartz - Netwitness
Direct download: SecuraBit_EP47.mp3
Category:podcasts -- posted at: 4:32pm EDT

SecuraNibble Episode 03 - Security Hour on IMP

SecuraNibble Episode 03 - Security Hour on IMP

This SecuraNibble is released out of band is an extra episode outside our normal releases.  This SecuraNibble is the recording of the conversation that happened on The International Mac Podcast held during their 12 Cubed event held on December 12, 2009.  The conversation was a general security round table held between our own Anthony Gartner, and panel of 4 other security pod-casters.  The panel of pod-casters include Bart Busschots of the International Mac Podcast, George Starcher of Typical Mac User Podcast, and the one and only Paul Asadoorian of PaulDotCom.com fame.

This SecuraNibble is not an extremely in depth and geeky conversation but one that covers a lot of general information and it applies to all operating systems not just the mac.

Direct download: SecuraNibble_EP03.mp3
Category:podcasts -- posted at: 10:46am EDT

SecuraBit Episode 46 – Making a Faster and Safer Web with Billy Hoffman

SecuraBit Episode 46 – Making a Faster and Safer Web with Billy Hoffman

Details of the Academy Pro Deal
New affiliation with the Academy Pro
Old podcasts at http://www.theacademypro.com/podcasts.php

Help people have a better user experience on the web.

Zoompf
-Billy's new company

Common Mistakes on Low Performing Websites

What is the best CMS to use.

How the report on Zoompf is being run currently.

New cameras and metadata
http://en.wikipedia.org/wiki/Exchangeable_image_file_format
-how much does the extra metadata take up in a file?

AT&T service and coverage

The origin of the name Zoompf

Link farms and domain squating

ICANN

IPV6

ShmooCon

Upcoming Events

http://www.google.com/calendar/ical/pe2ikdbe6b841od6e26ato0asc%40group.calendar.google.com/public/basic.ics

http://www.security-twits.com/

Join us in IRC at irc.freenode.net #securabit

Hosts:
Anthony Gartner – @anthonygartner
Chris Gerling  – @chrisgerling
Christopher Mills – @thechrisam
Jason Mueller - @securabit_jay
Andrew Borel – @andrew_secbit

Guest:
Billy Hoffman - @zoompf - http://zoompf.com/blog/

Direct download: SecuraBit_EP46.mp3
Category:podcasts -- posted at: 6:13pm EDT

SecuraBit Episode 45 – More on DOJOCON

SecuraBit Episode 45 – More on DOJOCON

Marcus J Carey discusses MetaSponse tool to be released in mid-December. This uses the MetaSploit Framework for Incident Response.

Metasploit Framework 3.3  Released!
http://blog.metasploit.com/2009/11/metasploit-framework-33-released.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+metasploit%2Fblog+%28Metasploit+Blog%29

Join us in IRC at irc.freenode.net #securabit

Hosts:
Anthony Gartner – @anthonygartner
Chris Gerling  – @chrisgerling
Christopher Mills – @thechrisam
Jason Mueller - @securabit_jay
Andrew Borel – @andrew_secbit

Guest:
Marcus Carey – @marcusjcarey

Links:

DojoCon - http://www.dojocon.org/
Hackers for Charity - http://www.hackersforcharity.org/
hak5 - http://www.hak5.org/

NoVA Hackers - http://groups.google.com/group/novahackers

dojosec @ USTREAM http://www.ustream.tv/dojosec
White Wolf Security - http://www.whitewolfsecurity.com/
ShmooCon 2010 - http://www.shmoocon.org/
Netwars Competition - http://www.sans.org/netwars/
International Spy Museum - http://www.spymuseum.org/
Cyber Forensics: Digital CSI - http://spymuseum.org/programs/calendar_pages/2009/q4/2009_12_01_prog.php
http://hashtags.org/tag/roachesmustdie

Direct download: SecuraBit_EP45.mp3
Category:podcasts -- posted at: 12:53pm EDT

SecuraBit Episode 44 - Dennis Hurst and Movember! SecuraBit Episode 44 – Guest Interview: Dennis Hurst, Senior Application Security Architect at HP Software & Solutions and a founding member of the Cloud Security Alliance Discussion of security and Agile development. Scaling agile requires feedback mechanisms and strong visibility http://h71028.www7.hp.com/enterprise/us/en/messaging/feature-software-scale-agile.html HP Application Security Center http://www.hp.com/go/stophackers Cloud Security Alliance http://cloudsecurityalliance.org Movember: Chris Gerling and Andrew Borel represent SecuraBit! http://us.movember.com/mospace/99916 (Chris) http://us.movember.com/mospace/361416/ (Andrew) Join us in IRC at irc.freenode.net #securabit Hosts: Anthony Gartner – @anthonygartner Chris Gerling – @chrisgerling Christopher Mills – @thechrisam Andrew Borel – @andrew_secbit Guest: Dennis Hurst Links: Movember - http://us.movember.com/ Donate to Security Podcasters Alliance - https://www.movember.com/us/donate/your-details/team_id/997 Security podcasters get hairy for charity - http://www.securecomputing.net.au/News/159403,security-podcasters-get-hairy-for-charity.aspx
Direct download: SecuraBit_EP44.mp3
Category:podcasts -- posted at: 3:47pm EDT

SecuraBit Episode 43 – The Academy Pro

SecuraBit Episode 43 – The Academy Pro

Guest Interview: Peter Giannoulis of The Academy Pro

Metasploit Rising

http://blog.metasploit.com/2009/10/metasploit-rising.html

WordPress 2.8.5: Hardening Release
http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/

Blubrry PowerPress Podcasting Plugin for WordPress
http://www.blubrry.com/powerpress/

Time Warner Cable Exposes 65,000 Customer Routers to Remote Hacks http://www.wired.com/threatlevel/2009/10/time-warner-cable/

Google Voice voicemails appearing in public search results
http://www.engadget.com/2009/10/19/google-voice-voicemails-appearing-in-public-search-results/

TweetDeck
http://www.tweetdeck.com/beta/

Porn, CSS History Hacking, User Recon and Blackmail
http://ha.ckers.org/blog/20091021/porn-css-history-hacking-user-recon-and-blackmail/

Windows 7
http://www.microsoft.com/windows/

Magic Mouse
http://www.apple.com/magicmouse/

Quick Shell Script to Extract Contents
http://pinowudi.blogspot.com/2009/10/quick-shell-script-to-extract-contents.html

Join us in IRC at irc.freenode.net #securabit

Hosts:
Anthony Gartner – @anthonygartner
Chris Gerling  – @chrisgerling
Christopher Mills – @thechrisam
Andrew Borel – @andrew_secbit

Guest:
Peter Giannoulis

Links:
The Academy Pro - http://www.theacademypro.com/
The Academy Home - http://www.theacademyhome.com/

Don't forget to listen to the end of the show for the guest appearances by both Kermit the Frog and Sean Connery

Direct download: SecuraBit_EP43.mp3
Category:podcasts -- posted at: 10:21am EDT

SecuraBit Episode 42 - Phreaking Sweet Con in TN.
SecuraBit Episode 42 – Phreaking Sweet Con in TN.
Phreaknic 13 – October 30 – November 1 2009
Phreaknic Curse
CCTV throughout hotel, great + for attending the con
Ware Chair Toss
Firing a jet engine in the parking lot.
Four Tracks
1 Cumberland (Main ballroom)
2 9th Floor (Vendor Area)
3 Cafe Area (Gaming)
4 Contest Area
Size of conferences
ShmooCon
Running Conferences
#RoachesMustDie from ShmooCon 2009 via Security Justice
Microsoft Security Essentials - http://www.microsoft.com/security_essentials/
New iTunes Store - http://www.apple.com/itunes/
Metasploit hiring in Austin, TX
New version of Pocket God for the iPhone
Hacker Consortium - http://hackerconsortium.com/

Join us in IRC at irc.freenode.net #securabit
Hosts:
Anthony Gartner – @anthonygartner
Chris Gerling  – @chrisgerling
Christopher Mills – @thechrisam
Andrew Borel – @andrew_secbit
Guest:
SkyDog
Links:
Direct download: Securabit_EP42.mp3
Category:podcasts -- posted at: 12:09pm EDT

SecuraBit Episode 41 - Speaking of Cons, and forensics...
SecuraBit Episode 41 - Speaking of Cons, and forensics...
Part 1: Marcus Carey
Dojocon - http://www.dojocon.org/ - @dojocon
November 6 & 7, 2009
Capitol College Maryland

Part 2: Scott Moulton

blackberry stuff:
bitpim

Hosts:
Chris Gerling  – @chrisgerling
Jason Mueller – @securabit_jay
Andrew Borel – @andrew_secbit
Anthony Gartner –  AnthonyGartner.com - @anthonygartner
Guest:
Marcus Carey - http://www.dojocon.org/ - @dojocon
Links:
Dojocon - http://www.dojocon.org/ - @dojocon
Direct download: SecuraBit_EP41.mp3
Category:podcasts -- posted at: 10:12am EDT

SecuraBit Episode 40 - Paul WHO????
SecuraBit Episode 40 - Paul "Pauldotcom" Asadoorian
Renaud script to go from Nmap to Nessus
Interview with Paul Asadoorian (PaulDotCom/Tenable/Nessus)
Intro Questions:
  • Who are you, and what are you doing on THIS podcast?
  • Tell us about the PaulDotCom podcast (I’ve talked to SecuraBit listeners who have never heard of PDC)
  • How long have you been using Nessus?
  • When did you start working for Tenable?
  • What is your role at Tenable?
Nessus Questions:
  • What’s new in this version of Nessus?
  • Are changes driven primarily by Tenable, or the community?
  • What does Nessus use for a scanning engine?
  • How does Nessus interact and work with Nmap?
  • Explain Nessus licensing and what an individual vs a corp is entitled to.
  • How much is a license?
  • Cost of proffesional feed = $1200.00/year
  • Home feed no longer a delay, no SCADA plugins
  • How does Nessus differ from OpenVAS?
  • Can you use the OpenVAS repo with Nessus?
  • Talk about the extensibility of Nessus. (Scripting, etc)
  • How does Nessus work with OVAL definitions? How does this help for FDCC compliance?
  • Does tenable have any dedicated appliances for enterprise scanning and monitoring based on nessus?
Implementation and Operation questions (How Paul Does Things):
  • Do you place scanning servers on each segment of the network, or do you scan through zone-to-zone firewalls? Why?
  • Is there a practical limit to the number of deices that can be scanned by one scanning server? Or is it just a time tradeoff?
  • How often do you scan (and re-scan) a network?
  • How do you handle the results (and avoid dropping a 300 page Nessus report on the server guys and saying FIX IT)
  • Are results parse-able and able to be fed into compliance and risk management tools?
Other Questions:
  • When is the next PaulDotCom episode?
  • What are the topics/guests?
  • What is your favorite beer?
Hosts:
Anthony Gartner – AnthonyGartner.com @anthonygartner
Christopher Mills – @thechrisam
Andrew Borel – @andrew_secbit
Ed Smiley - @edsmiley
Guest:
Paul Asadoorian - @pauldotcom - http://www.pauldotcom.com
Links:
Tenable Network Security Blog and Podcast - http://blog.tenablesecurity.com/
Direct download: SecuraBit_EP40.mp3
Category:podcasts -- posted at: 10:11pm EDT

SecuraBit Episode 39 - Stealing candy from little kids everywhere!!!

SecuraBit Episode 39 – Stealing candy from little kids everywhere!!!

Jay brought up that some government web sites will be switching to an http://openid.org authentication

What Does DHS Know About You? - http://philosecurity.org/2009/09/07/what-does-dhs-know-about-you
How to request your travel records - http://www.hasbrouck.org/blog/archives/001607.html

TwiGUARD - http://twiguard.com/index.html
TweetDeck - http://tweetdeck.com/beta/

MS IIS FTPD DoS ZER0DAY - http://www.milw0rm.com/exploits/9587

Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D. - http://www.milw0rm.com/exploits/9594

Poison Ivy Remote Administration Tool - http://www.poisonivy-rat.com/

FRHACK: Pentesting Live DVD - http://pentestit.com/2009/09/09/frhack-pentesting-livedvd/

Upcoming Events:
SANSFIRE 2009 - http://www.sans.org/sansfire09/
Baltimore, MD - June 13 - 22, 2009

Phreaknic 13 - http://www.phreaknic.info/pn13/Site_2/Welcome.html
October 30 - November 1 2009

SANS Cyber Defense Initiative - http://www.sans.org/cyber-defense-initiative-2009
Washington, DC - December 11 - 18, 2009

ToorCon - http://www.toorcon.org/
San Diego Convention Center -  October 23rd-25th, 2009

Join us in IRC at irc.freenode.net #securabit

Hosts:
Anthony Gartner – http://www.anthonygartner.com – @anthonygartner
Chris Gerling – http://www.chrisgerling.com – @hak5chris
Christopher Mills – http://www.packetsense.net – @thechrisam
Andrew Borel – @andrew_secbit
Jason Mueller – @securabit_jay

Direct download: SecuraBit_EP39.mp3
Category:podcasts -- posted at: 7:18pm EDT