« October 2007 | Main | December 2007 »

November 26, 2007

Recording and Stream Notice - Episode 90

The live stream should be active about 6:30 PM EDT, Thursday November 29th. We should begin recording the live show at about 4:30 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

PaulDotCom Security Weekly - Episode 89 - November 23, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 21, 2007

Recording and Stream Notice - Episode 89

Note: Updated times!

The live stream should be active about 7:30 - 8:00 PM EDT, Friday November 23rd. We should begin recording the live show at about 8:30 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

November 17, 2007

PaulDotCom Security Weekly - Episode 88 - November 15, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 15, 2007

Recording and Stream Notice - Episode 88

The live stream should be active about 6:30 PM EDT, Thursday November 8th. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://hydrogen.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

November 13, 2007

INSECURE Magazine Issue 14 - Attacking Consumer Embedded Devices

Recently I had the opportunity (privilege actually) of writing an article for INSECURE Magazine which appeared in issue 14 and is titled "Attacking Consumer Embedded Devices". It covers reasons why you would want to attack embedded devices, the goals of exploitation, example vulnerabilities and exploits, discovering vulnerabilities, and finally defense.

In researching and writing this article I had some thoughts that I will share (for those still reading this posting and not INSECURE magazine issue 14 :). First, its somewhat sad that the security industry as a whole is heavily focused on vulnerabilities and exploits, instead of attacks methodologies and protection of information. I think that far too many vendors, and the community as a whole, puts too much time and effort into what ultimately boils down to software bugs/vulnerabilities. I know this is true because so many times I go into the first meeting with a customer to discuss a security assessment and they automatically think that I should just be scanning the network for vulnerabilities. When in reality their organization, and most importantly their information, may be at risk due to other insufficient security measures such as poor physical security, end-users that will click on anything, and weak passwords. None of those problems can be solved by the latest and greatest intrusion prevention system, firewall, or vulnerability scanner. The best example that I can give is in the form of a question, if you can entice users to click a link and install software, why do you need a vulnerability to be present? This idea was underscored in "Tactical Exploitation" by HD Moore and Valsmith. I believe this is some of the most signifigant research/presentation to come out of the latest onslaught of conferences, including Blackhat, Defcon, and Toorcon.

So go check out this months INSECURE mag, and remember that software vulnerabilities are but a small part of the problem we must face as security professionals.

PaulDotCom

November 09, 2007

PaulDotCom Security Weekly - Episode 87 - November 8, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova

November 08, 2007

Recording and Stream Notice - Episode 87

The live stream should be active about 6:30 PM EST, Thursday November 8th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can. Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom. When active, the live stream can be found at: http://hydrogen.oshean.org:8000 Please join us, and thanks for listening! - Larry

November 02, 2007

PaulDotCom Security Weekly - Episode 86 - November 1, 2007

Live from the PaulDotCom Security Weekly Studio...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds: add to my PodNova