<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

<channel>
	<title>An Information Security Place</title>
	<atom:link href="http://infosecplace.com/blog/feed/podcast/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Wed, 23 Jun 2010 11:19:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<itunes:subtitle>Commentary on the State of Information Security</itunes:subtitle>
	<itunes:author>Michael R. Farnum</itunes:author>
	<itunes:category text="Technology" />
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
	</itunes:category>
	<itunes:keywords>Information, Security, Technology, Computers, Farnum, Broome</itunes:keywords>
	<itunes:explicit>no</itunes:explicit>
	<itunes:owner>
		<itunes:name>Michael R. Farnum</itunes:name>
		<itunes:email>m1a1vet@infosecplace.com</itunes:email>
	</itunes:owner>
			<item>
		<title>An Information Security Place Podcast &#8211; Episode 37</title>
		<link>http://infosecplace.com/blog/2010/06/23/an-information-security-place-podcast-episode-37/</link>
		<comments>http://infosecplace.com/blog/2010/06/23/an-information-security-place-podcast-episode-37/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 11:19:44 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[firmware hack]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[POET]]></category>
		<category><![CDATA[Rsnake]]></category>
		<category><![CDATA[sexting]]></category>
		<category><![CDATA[Supreme Court]]></category>
		<category><![CDATA[web application firewall]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1168</guid>
		<description><![CDATA[
All three of us are on this time.  Some good talk about disclosure and web app firewalls, and Google, and some other stuff.  Enjoy!
Show Notes:
InfoSec News Update -

Web App Firewall Discussion Continues – Link 1 / Link 2 / Link 3 / Link 4
Good Ole’ Firmware Hack – Link Here
Small and MidSize Businesses [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p style="clear: both;">All three of us are on this time.  Some good talk about disclosure and web app firewalls, and Google, and some other stuff.  Enjoy!</p>
<p style="clear: both;"><strong>Show Notes:</strong></p>
<p style="clear: both;"><strong>InfoSec News Update -</strong></p>
<ul style="clear: both;">
<li>Web App Firewall Discussion Continues – <a href="http://jeremiahgrossman.blogspot.com/2010/06/anti-waf-software-security-only.html">Link 1</a> / <a href="http://ha.ckers.org/blog/20100618/modsecurity-handbook/">Link 2</a> / <a href="http://www.net-security.org/secworld.php?id=9457">Link 3</a> / <a href="http://www.cgisecurity.com/2010/06/why-publishing-exploit-code-is-generally-a-bad-idea-if-youre-paid-to-protect.html">Link 4</a></li>
<li>Good Ole’ Firmware Hack – <a href="http://www.h-online.com/security/news/item/Kobil-smartcard-reader-hacked-1014651.html">Link Here</a></li>
<li>Small and MidSize Businesses are Getting Serious About Security – <a href="http://www.darkreading.com/securityservices/security/management/showArticle.jhtml?articleID=225700890">Link Here</a></li>
<li>Looking for the Next Generation of Security Folks -<a href="http://www.usatoday.com/money/industries/technology/2010-06-21-cybersecurity21_ST_N.htm">Link Here</a></li>
<li>“POET” Released – <a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=225700219">Link Here</a></li>
<li>Fingerprinting the Bad Guys – <a href="http://www.darkreading.com/database_security/security/intrusion-prevention/showArticle.jhtml?articleID=225700716">Link Here</a></li>
<li>Careful Where You Sext! – <a href="http://www.csmonitor.com/USA/Justice/2010/0617/Supreme-Court-backs-police-department-that-read-employee-s-texts">Link Here</a></li>
<li>Encouraging Everyone to Participate in the Survey -<a href="http://chuvakin.blogspot.com/2010/06/ultimate-security-survey-is-on.html">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Discussion Topic #1 – </strong>Google Is Watching Your Wifi, But do You Really Care?</p>
<p style="clear: both;"><strong>Discussion Topic #2 -</strong> Ye’ Old “Disclosure” Debate…Again?!? <a href="http://ha.ckers.org/blog/20100610/windows-help-centre-vuln/">Link 1</a> / <a href="http://www.cgisecurity.com/2010/06/why-publishing-exploit-code-is-generally-a-bad-idea-if-youre-paid-to-protect.html">Link 2</a></p>
<p style="clear: both;"><strong>Music Notes – </strong></p>
<ul style="clear: both;">
<li><strong>Intro / Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></strong></li>
<li><strong>Segway #1 – </strong><a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=3&amp;totalRows_MusicList=16&amp;BandHash=a84d881ac3a1f7dddc55cddfd9719126"><strong>Building Rome – “Bored”</strong></a></li>
<li><strong>Segway #2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=7&amp;BandHash=4dc3e9f44e4ce8bcbbc83d56575f1300">This is Fiction – “Breathe”</a></strong></li>
<li><strong>Segway #3 – </strong><a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=9f82d2117026d7ba7595c8161d91ec17"><strong>Patent Pending – “Los Angeles”</strong></a></li>
</ul>
<p style="clear: both;"><strong></strong><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode37.mp3">Link to MP3</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/06/23/an-information-security-place-podcast-episode-37/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode37.mp3" length="79245440" type="audio/mpeg" />
	<itunes:summary>

All three of us are on this time.  Some good talk about disclosure and web app firewalls, and Google, and some other stuff.  Enjoy!
Show Notes:
InfoSec News Update -

Web App Firewall Discussion Continues – Link 1 / Link 2 / Link 3 / Link 4
Good Ole’ Firmware Hack – Link Here
Small and MidSize Businesses are Getting Serious About Security – Link Here
Looking for the Next Generation of Security Folks -Link Here
“POET” Released – Link Here
Fingerprinting the Bad Guys – Link Here
Careful Where You Sext! – Link Here
Encouraging Everyone to Participate in the Survey -Link Here

Discussion Topic #1 – Google Is Watching Your Wifi, But do You Really Care?
Discussion Topic #2 - Ye’ Old “Disclosure” Debate…Again?!? Link 1 / Link 2
Music Notes – 

Intro / Outro – Digital Breaks – “Therapy”
Segway #1 – Building Rome – “Bored”
Segway #2 – This is Fiction – “Breathe”
Segway #3 – Patent Pending – “Los Angeles”

Link to MP3
</itunes:summary>
<itunes:subtitle>
All three of us are on this time.  Some good talk about disclosure and web app firewalls, and Google, and some other stuff.  Enjoy!
Show Notes:
InfoSec News Update -

Web App Firewall Discussion Continues – Link 1 / Link 2 / Link 3 / Link 4
Good [...]</itunes:subtitle>
<itunes:author>Jim Broome, Dan Kuykendall, and Michael Farnum</itunes:author>
<itunes:keywords>web application firewall, Google, wireless, data, rsnake, firmware hack, POET, sexting, wifi, Supreme Court</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 36</title>
		<link>http://infosecplace.com/blog/2010/06/02/an-information-security-place-podcast-episode-36/</link>
		<comments>http://infosecplace.com/blog/2010/06/02/an-information-security-place-podcast-episode-36/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 03:33:57 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Denver]]></category>
		<category><![CDATA[denvergov]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[IE8]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SMS Rootkit]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1163</guid>
		<description><![CDATA[

So do we suck or what? Sorry that its taken so long for us to get another episode out… things have been crazy busy for all of us.
Anyway for this episode, Dan and Jim found themselves with 30 minutes or so of spare time, not much of a script, and working mics (Michael was working [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<div class="post_content">
<p style="clear: both;">So do we suck or what? Sorry that its taken so long for us to get another episode out… things have been crazy busy for all of us.</p>
<p style="clear: both;">Anyway for this episode, Dan and Jim found themselves with 30 minutes or so of spare time, not much of a script, and working mics (Michael was working on a couple of proposals and an RFP that is due in two days); so they sat down and simply recorded an unscripted show of rambling about things that are going on for the moment.</p>
<p style="clear: both;"><strong>Info Sec News Moments:</strong></p>
<ul style="clear: both;">
<li>Kudos to MS’ IE 8 Add Campaign – <a href="http://www.microsoft.com/australia/technet/ie8milk/">Link Here</a></li>
<li>Jim’s 4.5 Seconds of fame – DenverGov website Hack – <a href="http://www.9news.com/video/default.aspx?bctid=87993474001">Link Here</a></li>
<li>Android and the SMS Rootkit Hack – <a href="https://www.defcon.org/html/defcon-18/dc-18-speakers.html#Percoco1">Link Here</a></li>
<li>Google Ditching Windows due to Security Concerns – <a href="http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html">Link Here</a></li>
<li>Denver OWASP – SnowFroc Con – <a href="http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Music Notes:</strong> <strong><br />
</strong></p>
<ul style="clear: both;">
<li><strong>Intro / Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></strong></li>
</ul>
<p style="clear: both;"><strong></strong><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode36.mp3">Link to MP3</a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/06/02/an-information-security-place-podcast-episode-36/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode36.mp3" length="35567744" type="audio/mpeg" />
	<itunes:summary>


So do we suck or what? Sorry that its taken so long for us to get another episode out… things have been crazy busy for all of us.
Anyway for this episode, Dan and Jim found themselves with 30 minutes or so of spare time, not much of a script, and working mics (Michael was working on a couple of proposals and an RFP that is due in two days); so they sat down and simply recorded an unscripted show of rambling about things that are going on for the moment.
Info Sec News Moments:

Kudos to MS’ IE 8 Add Campaign – Link Here
Jim’s 4.5 Seconds of fame – DenverGov website Hack – Link Here
Android and the SMS Rootkit Hack – Link Here
Google Ditching Windows due to Security Concerns – Link Here
Denver OWASP – SnowFroc Con – Link Here

Music Notes: 


Intro / Outro – Digital Breaks – “Therapy”

Link to MP3

</itunes:summary>
<itunes:subtitle>

So do we suck or what? Sorry that its taken so long for us to get another episode out… things have been crazy busy for all of us.
Anyway for this episode, Dan and Jim found themselves with 30 minutes or so of spare time, not much of a script, [...]</itunes:subtitle>
<itunes:author>Jim Broome and Dan Kuykendall</itunes:author>
<itunes:keywords>Microsoft, IE8, Denver, interview, denvergov, website, hacked, Android, SMS Rootkit, Google, Windows, security, OWASP</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 35</title>
		<link>http://infosecplace.com/blog/2010/05/03/an-information-security-place-podcast-episode-35/</link>
		<comments>http://infosecplace.com/blog/2010/05/03/an-information-security-place-podcast-episode-35/#comments</comments>
		<pubDate>Mon, 03 May 2010 14:00:03 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[enterpirse]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1160</guid>
		<description><![CDATA[
Episode 35 is here.  The format is different today.  Instead of you listening to Dan, Jim, and me yap about news and pontificate about security topics, you are going to hear a talk I gave at the Texas Technology Summit in early April 2010.  The talk title and synopsis are below, along [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p>Episode 35 is here.  The format is different today.  Instead of you listening to Dan, Jim, and me yap about news and pontificate about security topics, you are going to hear a talk I gave at the <a href="http://texas.technologysummit.net/" target="_blank">Texas Technology Summit</a> in early April 2010.  The talk title and synopsis are below, along with a link to the slide deck.</p>
<p><strong>Title: </strong>Breaking Down the Enterprise Security Assessment</p>
<p><strong>Synopsis:</strong> Many enterprise security assessments look at too few  attack vectors  or do not dig far enough into the attack vectors once a  vulnerability  has been discovered.   Come join a discussion on the  breakdown of a  security assessment, explore the essential attack vectors, and  debate  the depth to which the assessment should go.</p>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode35.mp3">Link to MP3</a></p>
<p><a href="http://www.infosecplace.com/blog/Podcasts/assessmentpreso.pptx">Link to slides</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/05/03/an-information-security-place-podcast-episode-35/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode35.mp3" length="64952448" type="audio/mpeg" />
	<itunes:summary>

Episode 35 is here.  The format is different today.  Instead of you listening to Dan, Jim, and me yap about news and pontificate about security topics, you are going to hear a talk I gave at the Texas Technology Summit in early April 2010.  The talk title and synopsis are below, along with a link to the slide deck.
Title: Breaking Down the Enterprise Security Assessment
Synopsis: Many enterprise security assessments look at too few  attack vectors  or do not dig far enough into the attack vectors once a  vulnerability  has been discovered.   Come join a discussion on the  breakdown of a  security assessment, explore the essential attack vectors, and  debate  the depth to which the assessment should go.
Link to MP3
Link to slides
</itunes:summary>
<itunes:subtitle>
Episode 35 is here.  The format is different today.  Instead of you listening to Dan, Jim, and me yap about news and pontificate about security topics, you are going to hear a talk I gave at the Texas Technology Summit in early April 2010.  The [...]</itunes:subtitle>
<itunes:author>Michael Farnum</itunes:author>
<itunes:keywords>assessment, enterprise, security</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 34</title>
		<link>http://infosecplace.com/blog/2010/04/16/an-information-security-place-podcast-episode-34/</link>
		<comments>http://infosecplace.com/blog/2010/04/16/an-information-security-place-podcast-episode-34/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 12:43:07 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1153</guid>
		<description><![CDATA[

We are really sorry for the long delay, but all three of our schedules have been packed for the last 2 months. But I&#8217;m sure you don&#8217;t want to hear any excuses, so without further hesitation… Here’s Episode 34.
Show Notes:
Kudos to Tommy Perniciaro for article at SC Magazine &#8211; Link Here
InfoSec News Update – 

Physical [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<div class="post_content">
<p style="clear: both;">We are really sorry for the long delay, but all three of our schedules have been packed for the last 2 months. But I&#8217;m sure you don&#8217;t want to hear any excuses, so without further hesitation… Here’s Episode 34.</p>
<p style="clear: both;"><strong>Show Notes:</strong></p>
<p style="clear: both;">Kudos to Tommy Perniciaro for article at SC Magazine &#8211; <a href="http://www.scmagazineus.com/mpls-the-forgotten-enterprise-technology/article/166353/">Link Here</a></p>
<p style="clear: both;"><strong>InfoSec News Update – </strong></p>
<ul style="clear: both;">
<li>Physical Security on Mac sucks – <a href="http://the?appleblog.?com/2008/0?6/22/reset?-os-x-pass?word-witho?ut-an-os-x?-cd/">Link Here</a></li>
<li>What Drives Corporate Security Spending? – <a href="http://www.rsa.com/products/DLP/ar/10844_5415_The_Value_of_Corporate_Secrets.pdf">Link Here</a></li>
<li>Crazy Patch Week – <a href="http://www.scmagazineus.com/oracle-issues-critical-patch-update-for-47-flaws/article/167945/">Link 1</a> / <a href="http://www.scmagazineus.com/microsoft-patches-25-flaws-with-11-patches-five-critical/article/167907/">Link 2</a></li>
<li>Federal Court Uphold Border Searches for Laptops – <a href="http://www.computerworld.com/s/article/9175403/Federal_court_upholds_border_search_of_laptop_in_Texas?taxonomyId=84&amp;pageNumber=2">Link Here</a></li>
<li>Are Bank Breaches Still Trending High in 2010 -<a href="http://www.bankinfosecurity.com/articles.phpart_id=2321">Link Here</a></li>
<li>So Easy, Even a Celebretard Can Do It! – <a href="http://www.theregister.co.uk/2010/04/06/richie_twitter_hacking_prank/">Link Here</a></li>
<li>Perceptions Of Security Vary Widely Between IT Management, Security Staff – <a href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=224400277">Link Here</a></li>
<li>Slow Death of XSS Vulns – <a href="http://blog.c22.cc/2010/03/16/alertxss-the-slow-death-of-xss/">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Discussion Topic #1 – </strong>Integration of Web Vuln Scanners with IPS/WAFs</p>
<p style="clear: both;"><strong>Discussion Topic #2 -</strong> Update your End user Awareness Training and stop blaming your users!</p>
<p style="clear: both;"><a href="http://research.microsoft.com/en-us/um/people/cormac/papers/2009/SoLongAndNoThanks.pdf">Link 1</a> / <a href="http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=224000172 http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=224000172 http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=224000172">Link 2</a> / <a href="http://www.darkreading.com/vulnerability_management/security/antivirus/showArticle.jhtml?articleID=223600014">Link 3</a></p>
<p style="clear: both;"><strong>Music Notes:</strong></p>
<ul style="clear: both;">
<li>Intro / Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=e1e44eea52f67e1e4df5bcd64528b21a">The Mannish Boys – “Too Tired”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=f63c11fedf84a6d486197f2e755e3810">Slide Show Baby – “Long, Long Road”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1089a8c084a1d803912e89f8b9cc6051">Megaphone – “Making Sense”</a></li>
</ul>
</div>
<p><strong><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode34.mp3">Link to MP3</a><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/04/16/an-information-security-place-podcast-episode-34/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode34.mp3" length="91279488" type="audio/mpeg" />
	<itunes:summary>


We are really sorry for the long delay, but all three of our schedules have been packed for the last 2 months. But I’m sure you don’t want to hear any excuses, so without further hesitation… Here’s Episode 34.
Show Notes:
Kudos to Tommy Perniciaro for article at SC Magazine – Link Here
InfoSec News Update – 

Physical Security on Mac sucks – Link Here
What Drives Corporate Security Spending? – Link Here
Crazy Patch Week – Link 1 / Link 2
Federal Court Uphold Border Searches for Laptops – Link Here
Are Bank Breaches Still Trending High in 2010 -Link Here
So Easy, Even a Celebretard Can Do It! – Link Here
Perceptions Of Security Vary Widely Between IT Management, Security Staff – Link Here
Slow Death of XSS Vulns – Link Here

Discussion Topic #1 – Integration of Web Vuln Scanners with IPS/WAFs
Discussion Topic #2 - Update your End user Awareness Training and stop blaming your users!
Link 1 / Link 2 / Link 3
Music Notes:

Intro / Outro – Digital Breaks – “Therapy”
Segway 1 – The Mannish Boys – “Too Tired”
Segway 2 – Slide Show Baby – “Long, Long Road”
Segway 3 – Megaphone – “Making Sense”


Link to MP3

</itunes:summary>
<itunes:subtitle>

We are really sorry for the long delay, but all three of our schedules have been packed for the last 2 months. But I’m sure you don’t want to hear any excuses, so without further hesitation… Here’s Episode 34.
Show Notes:
Kudos to Tommy [...]</itunes:subtitle>
<itunes:author>Jim Broome, Michael Farnum, Dan Kuykendall</itunes:author>
<itunes:keywords>Tommy Perniciaro, Physical Security, Macintosh, Apple, RSA, Security, Spending, patching, Federal, judge, laptop, search, Twitter, Ponemon, awareness, training, Cormac Herley</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 33</title>
		<link>http://infosecplace.com/blog/2010/03/12/an-information-security-place-podcast-episode-33/</link>
		<comments>http://infosecplace.com/blog/2010/03/12/an-information-security-place-podcast-episode-33/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 21:34:19 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1151</guid>
		<description><![CDATA[
Yes, the logo is weird this time.  If you can&#8217;t tell what it is, maybe this will help.  For the first time ever (and probably the only time since I don&#8217;t get to Atlanta much), An Information Security Place Podcast has joined forces with the  Southern Fried Security Podcast to create a joint episode.  Can [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head-SFS-ISPP.JPG"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head-SFS-ISPP.JPG" alt="" width="159" height="165" /></a></p>

<p>Yes, the logo is weird this time.  If you can&#8217;t tell what it is, maybe this will help.  For the first time ever (and probably the only time since I don&#8217;t get to Atlanta much), An Information Security Place Podcast has joined forces with the  Southern Fried Security Podcast to create a joint episode.  Can you see it now??  Yes, that is the logo for An Information Security Place Podcast placed over Colonel Sander&#8217;s face (he is the patron saint for the SFS podcast).  Yea,  I thought it was actually kinda freaky, too.  but what else do I have to do with my time??</p>
<p>So we joined forces for a couple of reasons:</p>
<ol>
<li>Because I was in Atlanta to speak about security assessments at the local <a href="http://atlanta.naisg.org">NAISG</a> chapter.</li>
<li>I begged Martin to let me post it up as episode 33 over here since Dan, Jim and I haven&#8217;t had a chance to record yet, and this makes it all better!</li>
</ol>
<p>So we stayed in the same room where the event was held and got irradiated by a myriad of computer and sound equipment while recording the podcast.  I had to wear someone&#8217;s headset, and now I have some kind of weird rash and some minor swelling around my ears.  And to make it even more fun, Mike Rothman sat across from us the whole time and heckled us.  What a night.</p>
<p>Actually, I had an awesome time.  Very good times with very good friends.  Thanks to the whole Atlanta NAISG crew and the SFS podcast crew (Andy Willingham, Martin Fisher, and Steve Ragan) for inviting me in with typical southern hospitality (even though Steve is a Yankee).</p>
<p>As to show notes, I am lazy.  I am only going to have one note (below) because it is the one news item that I brought along and the <strong>ONLY</strong> one that Andy didn&#8217;t include in his notes (in fairness, I never sent him the link).  Here&#8217;s a<a href="http://www.southernfriedsecurity.com/the-episodes/episode-9---live-recording-with-michael-farnum"> link to the SFS podcast site</a> with the rest of the notes.   (Hey, Andy did the hard work &#8211; why duplicate efforts??)</p>
<ul>
<li>Caleb Sima says that developers shouldn&#8217;t learn anything about security &#8211; <a href="http://itknowledgeexchange.techtarget.com/security-bytes/static-source-code-analysis-turned-on-its-head/">Link here</a></li>
</ul>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode33.mp3">Link to MP3</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/03/12/an-information-security-place-podcast-episode-33/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode33.mp3" length="55027480" type="audio/mpeg" />
	<itunes:summary>

Yes, the logo is weird this time.  If you can’t tell what it is, maybe this will help.  For the first time ever (and probably the only time since I don’t get to Atlanta much), An Information Security Place Podcast has joined forces with the  Southern Fried Security Podcast to create a joint episode.  Can you see it now??  Yes, that is the logo for An Information Security Place Podcast placed over Colonel Sander’s face (he is the patron saint for the SFS podcast).  Yea,  I thought it was actually kinda freaky, too.  but what else do I have to do with my time??
So we joined forces for a couple of reasons:

Because I was in Atlanta to speak about security assessments at the local NAISG chapter.
I begged Martin to let me post it up as episode 33 over here since Dan, Jim and I haven’t had a chance to record yet, and this makes it all better!

So we stayed in the same room where the event was held and got irradiated by a myriad of computer and sound equipment while recording the podcast.  I had to wear someone’s headset, and now I have some kind of weird rash and some minor swelling around my ears.  And to make it even more fun, Mike Rothman sat across from us the whole time and heckled us.  What a night.
Actually, I had an awesome time.  Very good times with very good friends.  Thanks to the whole Atlanta NAISG crew and the SFS podcast crew (Andy Willingham, Martin Fisher, and Steve Ragan) for inviting me in with typical southern hospitality (even though Steve is a Yankee).
As to show notes, I am lazy.  I am only going to have one note (below) because it is the one news item that I brought along and the ONLY one that Andy didn’t include in his notes (in fairness, I never sent him the link).  Here’s a link to the SFS podcast site with the rest of the notes.   (Hey, Andy did the hard work – why duplicate efforts??)

Caleb Sima says that developers shouldn’t learn anything about security – Link here

Link to MP3
</itunes:summary>
<itunes:subtitle>
Yes, the logo is weird this time.  If you can’t tell what it is, maybe this will help.  For the first time ever (and probably the only time since I don’t get to Atlanta much), An Information Security Place Podcast has joined forces with the [...]</itunes:subtitle>
<itunes:author>Martin Fisher, Andy Willingham, Steve Ragan, Michael Farnum</itunes:author>
<itunes:keywords>Southern Fried Security Podcast, Caleb Sima</itunes:keywords>
<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 32</title>
		<link>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/</link>
		<comments>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 13:24:35 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[arrested]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[Chuvakin]]></category>
		<category><![CDATA[dictatorship]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Schmoocon]]></category>
		<category><![CDATA[Scorecard]]></category>
		<category><![CDATA[Security B-Sides]]></category>
		<category><![CDATA[security conference]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1136</guid>
		<description><![CDATA[
OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show!
Show Notes:
InfoSec News Update –

Iran Shutters Google&#8217;s Gmail Service, offering own email for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p>OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin&#8217; and churned out almost an hour of content (I use that term loosely).  So enjoy the show!</p>
<p><strong>Show Notes:</strong></p>
<p><strong>InfoSec News Update –</strong></p>
<ul>
<li>Iran Shutters Google&#8217;s Gmail Service, offering own email for citizens &#8211; <a href="http://darkreading.com/security/app-security/showArticle.jhtml?articleID=222900064" target="_blank">Link here</a></li>
<li>Security Scoreboard &#8211; <a href="http://chuvakin.blogspot.com/2010/02/security-scoreboard-out.html" target="_blank">Link here</a></li>
<li>Brian Kreb&#8217;s has blog post used by scammers - <a href="http://www.krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/" target="_blank">Link here</a> and Sophos article <a href="http://www.sophos.com/blogs/sophoslabs/?p=8654" target="_blank">link here</a></li>
<li>The Death of Product Reviews (Mike Rothman at Securosis) - <a href="http://securosis.com/blog/death-of-product-reviews" target="_blank">Link here</a></li>
<li>TSA agent arrested for molestation - <a href="http://www.tsa.gov/blog/2010/02/orlando-officer-arrested.html" target="_blank">Link here</a></li>
</ul>
<div id="_mcePaste">
<div id="_mcePaste">We won&#8217;t get intot he details here because this guy is sick, but I had to point out this line from the TSA blog about the issue:</div>
<div id="_mcePaste">&#8220;TSA holds the highest standards for our workforce and this individual&#8217;s actions do not reflect on the more than 50,000 men and women who work every day to keep the traveling public safe.&#8221;</div>
</div>
<div>
<ul>
<li>Hacker threat forces DoH to close appraisal site (Political Activist?) - <a href="http://www.healthcarerepublic.com/news/982894/Hacker-threat-forces-DoH-close-appraisal-site/" target="_blank">Link here</a></li>
</ul>
</div>
<div><strong>Discussion Topic &#8211; </strong>Smaller, more intimate security conferences (Security B-Sides, Schmoocon, etc)</div>
<div>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=3d4e22af2d41713462855383c927ef43" target="_blank">Guitar Slingers &#8211; &#8220;Johnny Dangerously&#8221;</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=280202729dad1ad3a780a4d20afbe39b" target="_blank">Matthew Ebel &#8211; &#8220;Trees&#8221;</a></li>
</ul>
<p></strong><strong><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode32.mp3">Link to MP3</a><br />
</strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/02/18/an-information-security-place-podcast-episode-32/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" length="91490432" type="audio/mpeg" />
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode32.mp3" length="63906508" type="audio/mpeg" />
	<itunes:summary>

OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin’ and churned out almost an hour of content (I use that term loosely).  So enjoy the show!
Show Notes:
InfoSec News Update –

Iran Shutters Google’s Gmail Service, offering own email for citizens – Link here
Security Scoreboard – Link here
Brian Kreb’s has blog post used by scammers - Link here and Sophos article link here
The Death of Product Reviews (Mike Rothman at Securosis) - Link here
TSA agent arrested for molestation - Link here


We won’t get intot he details here because this guy is sick, but I had to point out this line from the TSA blog about the issue:
“TSA holds the highest standards for our workforce and this individual’s actions do not reflect on the more than 50,000 men and women who work every day to keep the traveling public safe.”



Hacker threat forces DoH to close appraisal site (Political Activist?) - Link here


Discussion Topic – Smaller, more intimate security conferences (Security B-Sides, Schmoocon, etc)

 
 
 
 
 
 
 
 
 
 


Intro/Outro – Digital Breaks – “Therapy”
Segway 1 – Guitar Slingers – “Johnny Dangerously”
Segway 2 – Matthew Ebel – “Trees”

Link to MP3


</itunes:summary>
<itunes:subtitle>
OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin’ and churned out almost an hour of content (I use that term loosely).  So enjoy the show!
Show [...]</itunes:subtitle>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 31</title>
		<link>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/</link>
		<comments>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 12:58:46 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1134</guid>
		<description><![CDATA[

Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek speak.  You will definitely learn  from stuff from this [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<div class="post_content">
<p style="clear: both;">Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek speak.  You will definitely learn  from stuff from this episode (as opposed to the drivel you get from most of our episodes).  Very good stuff.</p>
<p>BTW, the format of the posts are changing just a bit.  While the podcast player will stay where it usually is at the top of the post, the link to the file will now be below the posts.  This is changing because when iTunes picks up the text from the feed, it throws the &#8220;Link to MP3&#8243; text at the top, and it looks weird when looking at the show description in iTunes.  Just a minor change really, but just wanted to point it out here in case that is where you grab the file.  OK, now on to the show!</p>
<p style="clear: both;"><strong>Show Notes:</strong></p>
<p style="clear: both;"><strong>InfoSec News Update – </strong></p>
<ul style="clear: both;">
<li>Hacker Cracks 49 House Sites and Insults Obama – <a href="http://www.msnbc.msn.com/id/35125467/ns/technology_and_science-security/?GT1=43001">Link Here</a></li>
<li>17 Year Old Vulnerability – <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx">Link Here</a></li>
<li>77K Risk Data Loss in Alaska – <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=222600500">Link Here</a></li>
<li>SEC Workers Surfing Pr0n – <a href="http://www.foxnews.com/politics/2010/02/02/sec-workers-investigated-porn-surfing/">Link Here</a> / <a href="http://www.break.com/index/worker-looks-at-nude-pics-during-news-report.html">BREAK.COM VIDEO Link</a></li>
<li>If your password is 123456, just make it HACKME – <a href="http://www.nytimes.com/2010/01/21/technology/21password.html?em">Link Here</a></li>
<li>ID Thieves Successfully Targeting Wealth Victims – <a href="http://www.darkreading.com/securityservices/security/privacy/showArticle.jhtml?articleID=222600185">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Discussion Topic #1 – </strong>Laptops on Hostile Networks – <a href="http://www.networkworld.com/news/2010/020310-black-hat-wi-fi-attackers.html?hpg1=bn">Link Here</a></p>
<p style="clear: both;">
<p style="clear: both;"><strong>Discussion Topic #2 -</strong> DK’s Web App Security Minute… and then some <img class="wp-smiley" src="http://www.jimsblog.org/blog/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
<ul style="clear: both;">
<li>Remote File Include Attacks – <a href="http://ha.ckers.org/blog/20100129/large-list-of-rfis-1000/">Link Here</a> / <a href="http://www.ntobjectives.com/research-anatomy-of-rfi-attack"><strong>DK’s Info Page</strong></a></li>
<li>Larry Suto’s New Web App Scanner Review Report -<strong> </strong><a href="http://ha.ckers.org/blog/20100203/accuracy-and-time-costs-of-web-application-security-scanner-report/">Link Here</a></li>
</ul>
<p style="clear: both;"><strong>Music Notes:</strong></p>
<p style="clear: both;"><strong> </strong></p>
<p style="clear: both;"><strong> </strong></p>
<p><strong> </strong></p>
<p><strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=6b2fccdd12aaeb7e3fd40fc37d5cda29">Nathan Lee – “Hold Me Down”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=3&amp;totalRows_MusicList=16&amp;BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Bored”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=53ed9999937c75761728272156dc002c">Devo Spice – “I’m Not Your Personal IT Guy”</a></li>
</ul>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3">Link to MP3</a></p>
<p></strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/02/05/an-information-security-place-podcast-episode-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode31.mp3" length="91490432" type="audio/mpeg" />
	<itunes:summary>


Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek speak.  You will definitely learn  from stuff from this episode (as opposed to the drivel you get from most of our episodes).  Very good stuff.
BTW, the format of the posts are changing just a bit.  While the podcast player will stay where it usually is at the top of the post, the link to the file will now be below the posts.  This is changing because when iTunes picks up the text from the feed, it throws the “Link to MP3″ text at the top, and it looks weird when looking at the show description in iTunes.  Just a minor change really, but just wanted to point it out here in case that is where you grab the file.  OK, now on to the show!
Show Notes:
InfoSec News Update – 

Hacker Cracks 49 House Sites and Insults Obama – Link Here
17 Year Old Vulnerability – Link Here
77K Risk Data Loss in Alaska – Link Here
SEC Workers Surfing Pr0n – Link Here / BREAK.COM VIDEO Link
If your password is 123456, just make it HACKME – Link Here
ID Thieves Successfully Targeting Wealth Victims – Link Here

Discussion Topic #1 – Laptops on Hostile Networks – Link Here

Discussion Topic #2 - DK’s Web App Security Minute… and then some 

Remote File Include Attacks – Link Here / DK’s Info Page
Larry Suto’s New Web App Scanner Review Report - Link Here

Music Notes:
 
 
 


Intro/Outro – Digital Breaks – “Therapy”
Segway 1 – Nathan Lee – “Hold Me Down”
Segway 2 – Building Rome – “Bored”
Segway 3 – Devo Spice – “I’m Not Your Personal IT Guy”

Link to MP3


</itunes:summary>
<itunes:subtitle>

Everyone was here for this episode (meaning Dan, Jim, and Michael), and it was pretty much on schedule this time.  We do the normal cutting up, then talk about news and start discussing stuff.  Then Dan puts the hurt down on some developer geek [...]</itunes:subtitle>
<itunes:author>Dan Kuykendall, Jim Broome, and Michael Farnum</itunes:author>
<itunes:duration>1:15</itunes:duration>
<itunes:keywords>Obama, hacked, websites, RFI, rsnake, remote file include, Larry Suto, Mike Kershaw passwords, laptops, hostile network, wireless, cache poisoning,  SEC, pr0n,  Alaska, ID theft, 77000,  House of Representatives, Web App Scanners, NTO Spider</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 30</title>
		<link>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/</link>
		<comments>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 02:02:00 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Las Vegas]]></category>
		<category><![CDATA[Mike Tuchen]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[Roger Hegland]]></category>
		<category><![CDATA[TruArx]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1126</guid>
		<description><![CDATA[
Link to MP3


The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode30.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both;">
<p style="clear: both;">The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at our (Michael and Jim) employer’s annual company meeting.  Jim is a miracle worker, but even he could not make it completely fluid!</p>
<p style="clear: both;">Also, because of scheduling, Dan did not get to join us.  But Jim and I were fortunate enough to be joined by coworker and wireless uber-beast, Mr. Tyler Theys.  I think you will enjoy this episode, even with all the weirdness!</p>
<p style="clear: both;">Show Notes:</p>
<p style="clear: both;"><strong>Info Sec News Update -</strong></p>
<ul style="clear: both;">
<li>Jim, Michael, and Tyler talk about all the Google Hacking – <strong><a href="http://www.computerworlduk.com/community/blogs/index.cfm?entryid=2741&amp;blogid=24">Link Here</a></strong></li>
</ul>
<p style="clear: both;"><strong>Interview #1 -</strong>Michael with Roger Hegland of <a href="http://www.truarx.com/"><strong>TruARX</strong></a></p>
<p style="clear: both;"><strong>Interview #2 -</strong> Jim with Mike Tuchen of <a href="http://www.rapid7.com/"><strong>Rapid7</strong></a></p>
<p style="clear: both;"><strong><em>“Added Bonus to Our Listeners”</em></strong></p>
<p><em>Going to RSA? Join Rapid7 on March 3<sup>rd</sup> for a party at Ruby Skye. Get on the VIP list for the evening everyone else will be talking about at RSA 2010: </em><em><span style="text-decoration: underline;"><strong><a href="http://www.rapid7.com/forms/rsarsvp.jsp">www.rapid7.com/forms/rsarsvp.jsp</a></strong><br />
</span></em></p>
<p style="clear: both;"><strong>Discussion Topic -</strong> PCI in the Gaming Industry</p>
<p style="clear: both;"><strong>Music Notes – </strong></p>
<ul style="clear: both;">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Dr. Doctor”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1089a8c084a1d803912e89f8b9cc6051">Megaphone – “Write it Down”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=7&amp;BandHash=4dc3e9f44e4ce8bcbbc83d56575f1300">This is Fiction – “Breathe”</a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2010/01/25/an-information-security-place-podcast-episode-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" length="86507648" type="audio/mpeg" />
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode30.mp3" length="86642816" type="audio/mpeg" />
	<itunes:summary>

Link to MP3


The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and there with vendors as well as each other while we were at our (Michael and Jim) employer’s annual company meeting.  Jim is a miracle worker, but even he could not make it completely fluid!
Also, because of scheduling, Dan did not get to join us.  But Jim and I were fortunate enough to be joined by coworker and wireless uber-beast, Mr. Tyler Theys.  I think you will enjoy this episode, even with all the weirdness!
Show Notes:
Info Sec News Update -

Jim, Michael, and Tyler talk about all the Google Hacking – Link Here

Interview #1 -Michael with Roger Hegland of TruARX
Interview #2 - Jim with Mike Tuchen of Rapid7
“Added Bonus to Our Listeners”
Going to RSA? Join Rapid7 on March 3rd for a party at Ruby Skye. Get on the VIP list for the evening everyone else will be talking about at RSA 2010: www.rapid7.com/forms/rsarsvp.jsp

Discussion Topic - PCI in the Gaming Industry
Music Notes – 

Intro/Outro – Digital Breaks – “Therapy”
Segway 1 – Building Rome – “Dr. Doctor”
Segway 2 – Megaphone – “Write it Down”
Segway 3 – This is Fiction – “Breathe”


</itunes:summary>
<itunes:subtitle>
Link to MP3


The first podcast of the new year is here, and it is a nice round number!  That is sweet!  So please forgive any weirdness in the way this episode sounds.  It was put together over a couple of weeks doing interviews here and [...]</itunes:subtitle>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 29</title>
		<link>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/</link>
		<comments>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 14:48:46 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[2010. Adobe]]></category>
		<category><![CDATA[buggy]]></category>
		<category><![CDATA[COFEE]]></category>
		<category><![CDATA[Cybersecurity coordinator]]></category>
		<category><![CDATA[DECAF]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[drones]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Howard Schmidt]]></category>
		<category><![CDATA[Merry Christmas]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1123</guid>
		<description><![CDATA[
Link to MP3

Merry Christmas to all our listeners!  It&#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!!  So sit [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Merry Christmas to all our listeners!  It&#8217;s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!!  So sit back with your eggnog next to the Yule log fire under the stockings and enjoy!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p><strong>InfoSec News Update – </strong></p>
<ul style="clear: both">
<li>Howard Schmidt new White House cybersecurity coordinator – <a href="http://www.computerworld.com/s/article/9142579/Schmidt_tapped_as_White_House_cybersecurity_coordinator">Link Here</a></li>
<li>deCOFEEnating Windows – <a href="http://www.h-online.com/security/news/item/New-tool-deCOFEEnates-Windows-systems-885688.html">Link Here</a></li>
<li>Twitter DNS hack came from authorized credentials – <a href="http://voices.washingtonpost.com/securityfix/2009/12/twittercom_hijacked_by_iranian.html">Link Here</a></li>
<li>Social Networks searches could be a hackers dream… <a href="http://www.usatoday.com/tech/news/2009-12-14-searchsecurity14_ST_N.htm">Link 1</a> / <a href="http://www.paterva.com/web4/index.php/maltego">Link 2</a></li>
<li>FireFox and Adobe named “Most Buggy” – <a href="http://news.cnet.com/8301-27080_3-10417785-245.html">Link Here</a> / <a href="http://www.bit9.com/news-events/press-release-details.php?id=140">Bit9 Link</a></li>
<li>Insurgents Hack US Drones – <a href="http://online.wsj.com/article/SB126102247889095011.html?mod=wsj_share_twitter">Link Here</a> / <a href="http://www.skygrabber.com/en/index.php">Software Link</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong></p>
<p style="clear: both">2009 Year in Review and Looking Forward Predictions to 2010 –</p>
<p style="clear: both"><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=222003008">Link 1</a> / <a href="http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29 http://securityblog.verizonbusiness.com/2009/12/15/2010-security-predictions/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29">Link 2</a> / <a href="http://www.greebo.net/2009/12/18/web-app-sec-predictions-for-2010/">Link 3</a></p>
<p style="clear: both"><strong>Music Notes -</strong></p>
<p style="clear: both">
<ul style="clear: both">
<li>Intro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=94354662c286953389e4b053406665ba">TheHipCola – “SleighRide”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=082e5aa3474a24d58c17e9f91c210311">Winzenried – “Have Yourself A Merry Little Christmas”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=7d112cb6e6d69c810497671ae56fb618">OutSpoken – “Punk Rock Bells”</a></li>
<li>Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=94354662c286953389e4b053406665ba">TheHipCola – “Winter WonderLand”</a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/12/23/an-information-security-place-podcast-episode-29/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode29.mp3" length="86507648" type="audio/mpeg" />
	<itunes:summary>

Link to MP3

Merry Christmas to all our listeners!  It’s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was actually recorded on time !!!!  So sit back with your eggnog next to the Yule log fire under the stockings and enjoy!
Show Notes:
InfoSec News Update – 

Howard Schmidt new White House cybersecurity coordinator – Link Here
deCOFEEnating Windows – Link Here
Twitter DNS hack came from authorized credentials – Link Here
Social Networks searches could be a hackers dream… Link 1 / Link 2
FireFox and Adobe named “Most Buggy” – Link Here / Bit9 Link
Insurgents Hack US Drones – Link Here / Software Link

Discussion Topic -
2009 Year in Review and Looking Forward Predictions to 2010 –
Link 1 / Link 2 / Link 3
Music Notes -


Intro – TheHipCola – “SleighRide”
Segway 1 – Winzenried – “Have Yourself A Merry Little Christmas”
Segway 2 – OutSpoken – “Punk Rock Bells”
Outro – TheHipCola – “Winter WonderLand”


</itunes:summary>
<itunes:subtitle>
Link to MP3

Merry Christmas to all our listeners!  It’s that time of the year again where we sit down and make a fun podcast and recap the year and look forward to next year. Heck there was even a Christmas Miracle on this episode… it was [...]</itunes:subtitle>
<itunes:author>Michael Farnum, Jim Broome, and Dan Kuykendall</itunes:author>
<itunes:keywords>Merry Christmas, Cybersecurity coordinator, Howard Schmidt, COFEE, DECAF, Firefox, buggy, drones, 2009, 2010. Adobe, Twitter, DNS</itunes:keywords>
	</item>
		<item>
		<title>An Information Security Place Podcast &#8211; Episode 28</title>
		<link>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/</link>
		<comments>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 13:49:11 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[felon]]></category>
		<category><![CDATA[Gunnar]]></category>
		<category><![CDATA[Marlinspike]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Moxie]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ProxMark3]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[Salahis]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1119</guid>
		<description><![CDATA[
Link to MP3
OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production.
I think [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>
<p><br />
<a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode28.mp3">Link to MP3</a></p>
<p style="clear: both">OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production.</p>
<p style="clear: both">I think you are going to enjoy this randomness&#8230;</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong>InfoSec News Update and Geek Toys Update – </strong></p>
<ul style="clear: both">
<li>T-Mobile Employee causes largest data theft in the UK – <a href="http://www.darkreading.com/database_security/security/privacy/showArticle.jhtml?articleID=221900209">Link Here</a></li>
<li>Government Security Woes<br />
Story 1 – 5 TSA workers put on leave over online posting – <a href="http://www.msnbc.msn.com/id/34346213/ns/travel-news/?gt1=43001">Link here</a><br />
Story 2 – The Party Crashing Scandal – <a href="http://www.foxnews.com/politics/2009/11/30/rep-white-house-crashers-says-couple-interested-media-interviews/">Link Here</a><br />
Story 3 – Felon working for DHS for 2 years – <a href="http://www.theregister.co.uk/2009/12/10/dhs_fugitive/">Link Here</a></li>
<li>Nessus 4.2 is released – <a href="http://www.tenablesecurity.com">Link Here</a></li>
<li>Rapid7 and Metasploit Community Projects – <a href="http://www.metasploit.com/framework/">Link 1</a> / <a href="http://www.rapid7.com/nexposecommunitydownload.jsp">Link 2</a></li>
<li>ProxMark3 now shipping completed RFID read/write/clone kits – <a href="http://www.proxmark3.com/">Link here</a></li>
<li>Moxie launched cloud-based WPA password Cracking – <a href="http://blogs.zdnet.com/BTL/?p=28224 ">Link Here</a></li>
<li>Cure for Eye Strain – Gunnar Glasses – <a href="http://www.gunnars.com/gunnar_indoor_collection.php">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong></p>
<p style="clear: both">Changes to OWASP standard for 2010 –</p>
<p style="clear: both"><a href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf">Link Here</a></p>
<p style="clear: both"><strong>Consultants Corner -</strong> Picking your tools wisely… 2009/2010 update</p>
<p style="clear: both"><strong>Music Notes – </strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=7&amp;BandHash=4dc3e9f44e4ce8bcbbc83d56575f1300">This is Fiction – “Breathe”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=9f82d2117026d7ba7595c8161d91ec17">Patent Pending – “Los Angeles”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=2&amp;totalRows_MusicList=331&amp;BandHash=53ed9999937c75761728272156dc002c">The FUMP – “”All You Can Tweet”</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/12/11/an-information-security-place-podcast-episode-28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode28.mp3" length="73980032" type="audio/mpeg" />
	<itunes:summary>

Link to MP3
OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we powered through it, and Jim got to spend a lot of time on post-production.
I think you are going to enjoy this randomness…
Show Notes:
InfoSec News Update and Geek Toys Update – 

T-Mobile Employee causes largest data theft in the UK – Link Here
Government Security Woes
Story 1 – 5 TSA workers put on leave over online posting – Link here
Story 2 – The Party Crashing Scandal – Link Here
Story 3 – Felon working for DHS for 2 years – Link Here
Nessus 4.2 is released – Link Here
Rapid7 and Metasploit Community Projects – Link 1 / Link 2
ProxMark3 now shipping completed RFID read/write/clone kits – Link here
Moxie launched cloud-based WPA password Cracking – Link Here
Cure for Eye Strain – Gunnar Glasses – Link Here

Discussion Topic -
Changes to OWASP standard for 2010 –
Link Here
Consultants Corner - Picking your tools wisely… 2009/2010 update
Music Notes – 

Intro/Outro – Digital Breaks – “Therapy”
Segway 1 – This is Fiction – “Breathe”
Segway 2 – Patent Pending – “Los Angeles”
Segway 3 – The FUMP – “”All You Can Tweet”

</itunes:summary>
<itunes:subtitle>
Link to MP3
OK, this was just a stupid, crazy, and fun episode.  We had technical hiccups, a roving co-host that likes to text another cohost during recording, plus this episode is late getting recorded because of end-of-year schedule.  But we [...]</itunes:subtitle>
<itunes:author>Michael Farnum, Jim Broome, and Dan Kuykendall</itunes:author>
<itunes:keywords>OWASP, Moxie, Marlinspike, Rapid7, ProxMark3, Metasploit, Nessus, WPA, cracking, Gunnar, Salahis, TSA, DHS, felon</itunes:keywords>
<itunes:explicit>yes</itunes:explicit>
	</item>
	</channel>
</rss>
