
OK, holy crap. We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin’ and churned out almost an hour of content (I use that term loosely). So enjoy the show!
Show Notes:
InfoSec News Update –
- Iran Shutters Google’s Gmail Service, offering own email for citizens – Link here
- Security Scoreboard – Link here
- Brian Kreb’s has blog post used by scammers - Link here and Sophos article link here
- The Death of Product Reviews (Mike Rothman at Securosis) - Link here
- TSA agent arrested for molestation - Link here
We won’t get intot he details here because this guy is sick, but I had to point out this line from the TSA blog about the issue:
“TSA holds the highest standards for our workforce and this individual’s actions do not reflect on the more than 50,000 men and women who work every day to keep the traveling public safe.”
- Hacker threat forces DoH to close appraisal site (Political Activist?) - Link here
Discussion Topic – Smaller, more intimate security conferences (Security B-Sides, Schmoocon, etc)

Link to MP3
OK, this was just a stupid, crazy, and fun episode. We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule. But we powered through it, and Jim got to spend a lot of time on post-production.
I think you are going to enjoy this randomness…
Show Notes:
InfoSec News Update and Geek Toys Update –
- T-Mobile Employee causes largest data theft in the UK – Link Here
- Government Security Woes
Story 1 – 5 TSA workers put on leave over online posting – Link here
Story 2 – The Party Crashing Scandal – Link Here
Story 3 – Felon working for DHS for 2 years – Link Here
- Nessus 4.2 is released – Link Here
- Rapid7 and Metasploit Community Projects – Link 1 / Link 2
- ProxMark3 now shipping completed RFID read/write/clone kits – Link here
- Moxie launched cloud-based WPA password Cracking – Link Here
- Cure for Eye Strain – Gunnar Glasses – Link Here
Discussion Topic -
Changes to OWASP standard for 2010 –
Link Here
Consultants Corner - Picking your tools wisely… 2009/2010 update
Music Notes –

Link to MP3
Episode 25 is here. Today’s podcast is different than our usual. Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security. Wesley is a security researcher at Mississippi State University’s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software. He also operates mcgrewsecurity.com , where he blogs about information security topics.
Wesley caught a script-kiddie back in June trying to do some pretty weak SCADA hacking at a Dallas-area hospital. He and I talked about the incident and also discussed some of Wesley’s future plan (not much since he couldn’t divulge a lot – oooo, mysterious!). So enjoy the show. Links to the blog posts from Wesley’s script kiddie adventure are below.
http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/
http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/
http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/
http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/
Vet

Link to MP3
We’re back with episode 23. Jim is back (you can decide if that is good news or bad news), and Dan Kuykendall is joining us again (calls himself the guest that won’t leave the couch). Thanks for listening…
Show notes:
InfoSec News Update -
- Big Thank You to all our Clients and the folks that stopped by thebBooth and our party at BlackHat!
- UK ID card Hacked/Cloned in 12 Minutes – Link Here
- “Mega breaches” use preventable attacks – Link Here
- Hackers target outsourced app development – Link Here
- National Retail Federation still struggling with PCI – Link Here
- Reset Password problems, and reusing passwords in general:
- “FILE UNDER DUH” – Study warns of cyberwarfare during military conflicts – Link Here
Discusstion Topic - Web Security On Cell Phones – Link Here
Geek Toyz –
Music Notes:

Link to MP3
Episode 22 is here. Jim was not available to join me this time (been traveling and real busy), so Dan Kuykendall from NT Objectives was kind enough to fill in as co-host for today. We had some good discussion, and a show that I thought would be a little shorter ended up being pretty long. But it is good stuff. Here are the show notes:
InfoSec News Update -
- Vulnerable web servers on webcams, NAS, etc – Link Here
- Obama’s cybersecurity Czar quits – Link Here
People familiar with the matter said Ms. Hathaway has been “spinning her wheels” in the White House, where the president’s economic advisers sought to marginalize her
politically.
In February, the White House tapped Ms. Hathaway, a senior intelligence official who had launched President George W. Bush’s cybersecurity initiative, to lead a 60-day
cybersecurity policy review. Ms. Hathaway completed her review in April, but the White House spent another 60 days debating the wording of her report and how to structure the
White House cyber post. National Economic Adviser Larry Summers argued forcefully that his team should have a say in the work of the new cyber official.
- SSL Under attack this year at BlackHat/Defcon. These attacks don’t attack the math, they attack the (mis)usage of the clients and cert authorities
New Tricks For Defeating SSL In Practice (sslstrip) -Link Here
Researcher Exposes Flaws In Certificate Authority Web Applications – Link Here
- Defcon goon “Priest” is everywhere – Links Here and Here
Discussion Topic - The ol’ security guidelines / best practices discussion
Consultants Corner – Varied BlackHat / Defcon points -
- SSL issues
- Unmasking You talk by Joshua “Jabra” Abraham and Robert “RSnake” Hansen
- Dan’s general Opinions about web security talks – he was underwhelmed
Music Notes:
Link to MP3
Here is Episode 17. Sorry for the delay in getting it out. Last week was extremely rough for Jim and I, but we are back at full strength now. Well, maybe 85% strength anyway.
In this show Jim and I relate the latest news as always, then we have some discussion about layoffs and how that is causing a lot of orphaned hardware and software. Then we discuss some challenges for the consultant in walking the mind field of politics at client companies.
Also, we had some listener feedback from Geir. He was busting on us a bit about our saying you need to patch your stuff when we were talking about 0day. Thanks for keeping us straight Geir. If you want to send feedback, you can send it to podcast-at-infosecplace.com.
Here are the show notes:
InfoSec News Update:
- Follow up – Another Payment Processor Has Been Hacked – Visa says JUST KIDDING! – Link Here – This Just In – A new timeline of the Unnamed Processor – Link Here
- Gartner – Nearly 8 Percent of U.S. Adults Lost Money To Financial Fraud in ‘08 – Link Here
- Federal cybersecurity director quits, complains of NSA role – Link Here
- Health Records Show Up in Yard – Link Here
- Study: Antivirus Software Catches About Half Of Malware – Link Here
- MS Finally killing off AutoRun – Link Here
- Marine One data leak – Link Here
- The Return of L0phtCrack!! – Link Here
- WarVox Released – Link Here
- Theives Steal the Show at Cebit – Link Here
- Checklist for complying with PCI security standard – Link Here / Link To Checklist
Discussion - Orphaned hardware and Software – Link Here
Consultant’s Corner - Dealing with political landscapes at your client’s company
Music Notes:
Vet

Link to MP3
Here is episode 15. There was a lot to cover in this episode. Jim and I were in discussion mode, so be prepared to sit down for a while longer than normal this time. Jim and I were also in a joking mood and consequently cracked ourselves up on this episode, so enjoy the laughter and comedy at a fellow human’s expense.
BTW, I am a milestone guy, and any time a “0″ or a “5″ is at the end of the episode number, I think it is cool. So 15 is a cool number to me. On to the show notes.
Show notes:
InfoSec News Update: whole lot of crap!
- FAA Security Breach Exposes 45K Employees
- AV makers Hacked – BitDefender and Kaspersky, More: Full Info on hackers Blog
- Electronics Firm Faces FTC Lawsuit Following Multiple Hacks – “The complaint alleges that until at least December 2007, Compgeeks (geeks.com) routinely stored this sensitive information in unencrypted text on its corporate computer network, among other security failures. The complaint also charges that the respondents did not adequately assess whether its Web application and network were vulnerable to commonly known or reasonably foreseeable attacks, such as SQL injection.”
- Identity thieves beat Obama to stimulus package punch
- Obama’s new CyberSec Chief Named
- Federal Workers Warned Of Potential Data Compromise At SRA
- Jailed SF network admin files $3M claim – Looks like the S.F. Mayor has some l33t admin skills because “Childs, formerly a network administrator with the city’s Telecommunications and Information Services (DTIS), had argued that the department’s staff was incompetent and that the mayor was the only person qualified to handle the passwords.”
- Heartland Breach Follow up – 157 institutions claiming issues – includes Bermuda, Canada, and Guam
- War cloning, the “new hacker sport”
- The latest MS Patches – One is for MS SQL, and there is exploit code out there
Discussion: File Under DUH! Unauthorized Web Use On The Rise
Consultants Corner: How does “Compliant” equal Owned?
Music Notes:

Link to MP3
MERRY CHRISTMAS and welcome to Episode 12! I have been sick all week, and it hit me hard yesterday and today. So Jim and Kirk saved the day and recorded the podcast without me. I am a little bummed that I was not on the last podcast of the year, but you would not have wanted to listen to me sounding all nasally.
So thanks to Jim and Kirk. Here are the…
Show Notes:
InfoSec News Update:
Discussion - Using Local resources for Social Engineering
Geek Toys – Last Minute Geek Gift Ideas
Consultant’s Corner - 2008 Year in Review – the Consultant’s Perspective
Music Notes:

Link to MP3
Show Notes:
Segment 1: InfoSec News Update (Michael gets to do a little talkin’ here – and he promptly screws it up):
- New Security Awareness video on YouTube – kinda cheesey, but a pretty good production
- Digittrade HD Encryption Broken- “in our test, unscrewing the housing took longer than cracking its encryption mechanism.”
- Lenovo’s new Facial recognition software defeated by printed photo
- Massachusetts new law – 201 CRM 17.00 – “Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing such personal information” – a civil penalty of $5,000 may be awarded for each violation of 93H. In addition, under the portion of 93H concerning data disposal, businesses can be subject to a fine of up to $50,000 for each instance of improper disposal. Requires – Regular Monitoring, Documenting responsive actions taken during breach, and reasonable monitors of systems.
- File Under DUH! – Symantec Discovers Cybercrime makes money – estimates value around $1.7Bil
- Really simple PCI FAQ that you should be aware of
- Apple and the AntiVirus Debate – In a written statement sent to security news site Securityfocus.com, Apple explained their decision to pull the document: “We have removed the KnowledgeBase article because it was old and inaccurate,” Apple said in a statement sent to SecurityFocus. “The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box. However, since no system can be 100 percent immune from every threat, running antivirus software may offer additional protection.”
Discussion: BLATANT FUD – Patching at the Enterprise level – Securina “virtually every Windows PC is at risk” – 98% of Windows computers are missing patches – 46% were missing more than 11 patches
Segment 2: Geek Toys and Consultants Corner
- Geek Toys – Kensington Portable Power outlet – AS SEEN ON REGIS AND KELLY!!!!
- Consultants Corner – Helping client dealing with a breach (specifically as how it relates to compliance issues)
Music Notes: NEW – CHECK OUT THE LINKS TO THE BANDS ON PODSHOW.COM
Vet

Link to MP3
Show Notes:
Episode 10! We are in double digits! W00T! Thanks to Jim for all the hard work on getting these podcasts produced, for picking the music, for doing most of the talking, for… errr, what do I do around here anyway??
Segment 1: InfoSec News Update and some discussion about pinko commies
Segment 2:
- Geek Toys – Jim has pretty much given up on trying to please Kirk because he is talking about non-security related toys AGAIN – a review of the Popcorn Hour A-110
- Consultants Corner- Staying diligent during holidays
- Further ranting – Jim says “LEAVE ME ALONE – I AM BUSY” to Q4 invitations to speak at conferences
Music Notes:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Naked Gun – “A.D.D.”
- Segway 2 – Kickstart – “Bouncey”

Link to MP3
Show notes:
Just Jim and I today talking about news and adding some ranting (as usual).
Segment 1: InfoSec News Update and various ranting
Segment 2:
- Geek Toys – BlueAnt SuperTooth 3 Review
- Consultants Corner – Importance of Physical Security
- We bid you a fond farewell
Music Notes:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Naked Gun – “A.D.D.”
- Zinger – JunkTones – “Welcome To the USA”
- Segway 2 – Kickstart – “Bouncey”
Vet

Link to MP3
Show Notes:
Kirk Greene, a coworker of Jim and me, joins us today, and general hilarity ensues. Thanks for being brave enough to come on the show Kirk!
Segment 1: InfoSec News Update
Segment 2:
- Geek Toys – 8 Gig laptops and how Apple sucks (Jim said it!) – and Kirk reminds Jim that this is an Infosec podcast AGAIN.
- Consultants Corner – Kirk opens up the PA DSS discussion, and we talk about some possible ramifications to the POS (“point of sale” for clarification) industry
- We say goodbye, but not before we turn this whole podcast into a political debate (not really) since the next podcast will be AFTER the election (the most important one in history according to everyone that said that about the last election)
Music Notes:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Jimmie Bratcher – “Bad Religion”
- Segway 2 – Kickstart – “Theme Song”
Hey everybody. Here’s podcast episode 7. There’s some great stuff in here, and some great interviews. Enjoy!
BTW, iTunes is downloading episode 6 for episode 7 for some friggin’ reason. I will look into it, but I have to finish a proposal tonight. Sheesh.

Link to MP3
Show notes:
Segment 1 – InfoSec News Update
Interview Segment:
Geek Toys: Jasager on the FON Router – Watch Episodes 403 and 405 of Hak5 or hop over to DigiNinja’s Jasager page
Consultants Corner: Discussion on doing some due diligence on checking vendor claims. Open discussion on the recent Evil Bits Darkreading blog post
Music Notes:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Jimmie Bratcher – “Bad Religion”
- Segway 2 – The Erotics – “Walk All Over You”
- Segway 3 – Megaphone – “Not Your Enemy”
- Segway 4 – Kickstart – “Theme Song”
Vet
Here’s episode #6. Jim was in a hotel room in California, so forgive any degradation in quality and the shorter-than-usual length. Just another risk when you are a world-traveling consultant like Mr. Broome.
As usual, we welcome feedback of any kind (we reserve the right to delete profanity). Please let us know how you like / dislike the show.
Also, I know the feed is broken via feedburner. Not sure what is going on there. I am looking into it. For now you can download the podcast via the link below.
OK, here are the show notes:
InfoSec News Update:
- Rsnake and Grossman’s talk on clickjacking pulled due to lack of feed back by some vendors and a request from Adobe to pull the OWASP USA talk until they issue a patch.
- Apple and Cisco Release Patches
- Followup – VMware Fusion 2.x not all that good!!!
- Palin hack – We don’t give a crap anymore!
Discussion on Remote access and employee termination – Open discussion on the recent articles
and whitepapers:
Segment 2:
And the wonderful music picks from Jim:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Climax – “OnTheEdge”
- Segway 2 – Climax – “Eternity”
Link to MP3
OK folks. Here’s the long awaited episode 5 of the the podcast. Sorry for the delay in getting this one out. Hurricane Ike put a big damper on our plans since I was without electricity for a few days. Internet has been spotty as well, but it held up for Jim and I to record last night.
Link to MP3
Show notes:
- Geek Toys – Personal Raid Devices – aka Drobo Review
- Consultants Corner – Dealing with clients that are bound by compliancy requirements.
Music:
- Intro/Outro – Digital Breaks – “Therapy”
- Segway 1 – Climax – “OnTheEdge”
- Segway 2 – Climax – “Eternity”
Vet
Episode 4 is here folks. We had a couple of times of weirdness happen, so forgive some of the bumps and weird splices going along. Here are the things Jim and I had some discussions around:
- More privacy rights violations, this time through people doing dumb things are just being lazy – low tech hacks
- FEMA voicemail system hack leading to $12k of long distance calls – default password left on system!
- Hurricane Gustav led to a discussion about DR / BC
- PCI 1.2 and what it means for you (if you have to deal with that crap)
- Consultant’s Corner – I blab about how you have to be prepared, set expectations, be knowledgeable, and be FLEXIBLE (I wrote a post about this).
- Geek toys was not included this time, but it will be in the future.
Also wanted to give shout outs to Ross at http://www.secureputer.com and Jean-Christophe at http://www.phocean.net, two brand new security blogs out there, which we mentioned in the show.
Music notes:
- Intro was Digital Breaks with “Therapy”
- The first segway was Climax with “OnTheEdge”
- The second segway was Climax with “Eternity”
Link to MP3
Link to the podcast site
Vet
Here’s the latest installment of the podcast. Jim Broome talks about some of the BH / DC talks he was interested in and rubs in the fact that I didn’t get to go (he also rubs in the fact that he was in Hawaii last week – thanks Jim).
We get some closure on the Dan Kaminsky / DNS issue (well, it was closure for us anyway).
We talk a little about Alan Shimel’s adventures in pwnage. We are not giving any details about the issue, but we give the big guy a little sympathy and some major props for his renewed sense of security importance and writing about the whole thing so we can all see how the process doesn’t work.
Then Jim busts into his favorite two segments. One is the Geek Toy segment, where he talks about the SanDisk Sansa TakeTV device. Very cool stuff for the traveler. And the other segment is the Consultant’s Corner, where Jim gives some advice for writing up and presenting an executive outbrief for a project.
The rest of the podcast is just general bantering and virtually poking each other in the ribs. We had fun with this one. Leave some comments on what you think. We’ll discuss some of them in the next podcast.
Music for this podcast is:
- Digital Breaks – “Therapy”
- Digital Droo – “Minor Things”
- Laika Cres – “Miles and Miles”
Vet
Here’s the second installment of the podcast. Joining me is my cohort and cohost, Jim Broome. Some of you may know Jim from his blog. Jim is definitely one of the more technical bloggers out there, serving up all kinds of geek toy and hacking fun. I hope to keep Jim around a long time since he has a whole lot of experience in the security field, and he is in no way shy to talk about it.
Also, Jim is doing most (if not all) of the mixing and production work on the podcast since he has a lot of cool toys and has experience in the broadcast industry. So thanks Jim!
Some show notes:
- Talk about the goals for the show
- News talk – all about BlackHat / Defcon (and how I am not going to be there – sheesh)
- Accuvant’s party
- Various and sundry talks that interest us
- Geek toys – ASUS EEEPC 1000H
- Consultant’s Corner – Rent the SUV… it’s cheaper!
Stick with us as we get all the bugs worked out. I hope to bring some new perspectives and liveliness to security podcasting.
Vet
I had some time last night while the kids were asleep to record a podcast. I have been wanting to get into it again, but I just haven’t dedicated the time to it. But I finally did it. I explain a bit of what I am planning for this podcast (product manufacturer interviews, etc.). Not sure yet what all I want to do, but I would like to put some time into it. We’ll see what happens.
Mostly I talk about the DNS flaw and the issues with disclosure that have been brought out again. It has been a while since those issues have been on the forefront, so it is interesting. Really it is me rambling, but that is what I do best.
An Information Security Place Podcast – Episode 1
Music is from .22 and Wendy Wall.
Vet