Main

May 29, 2008

PaulDotCom Security Weekly - Episode 109 - May 22, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

Gone Fishin'

No, not permanently! We're just taking the week off.

It has been a hack of a week since we recorded Episode 109 (to be released later today)! There have been additions to family, remembrances of those lost, and time with loved ones. Needless to say this week has been about family.

We haven't forgotten about you all, our extended family of faithful podcast listeners and blog readers. We'll be back on track with a fantastic show next week.

Thanks for all of your continued support.

- Larry & Paul

May 23, 2008

PaulDotCom Security Weekly - Episode 108 Part II - May 15, 2008

Live from the PaulDotCom studios, Larry via Skype, and JJ comes on the show to talk about FreeBSD security, open-source tools for scheduling Nessus scans, Debian not-so-randomness, and more!...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 22, 2008

Recording and Stream Notice - Episode 109

The live stream should be active about 6:45 PM EDT, Thursday, May 22nd. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

psw-simpsons.jpg

- Larry & Paul

May 12, 2008

PaulDotCom Security Weekly - Episode 107 - May 9, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 09, 2008

Recording & Stream Notice - Episode 107

The live stream should be active about 6:45 PM EDT, Friday, May 9th. We should begin recording the live show at about 7:00 PM EDT. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

pdcskin.jpg

- Larry & Paul

May 07, 2008

Late-Breaking Computer Attack Vectors - April 2008

The media for the April 2008 Late-Breaking Computer Attack Vectors webcast is ready to be released:

LBCAV April 2008 - Audio

LBCAV April 2008 - Slides

This is a 45 minute presentation on the latest happenings in computer security, vulnerabilities, and methods in use by attackers. I've also included several recommendations for defensive measures, so enjoy! If you want to listen live this webcast is done on the last Wednesday of every month at 2:00PM EST.

I hope to create a podcast feed for the audio sometime in the near future as well.

Mission-impossible1.jpg

PaulDotCom

May 06, 2008

PaulDotCom TV: The Making Of The Shmooball Cannon

Larry did a fantastic job with the Shmooball Cannon, it was featured on Make Magazine and Hack A Day. It was such a huge success that we produced a video detailing how it was made, including several takes of Paul getting shot:


This video will also be added to our video feed and our YouTube channel:

Video Feeds:


YouTube: PaulDotCom YouTube Channel.

Look for more videos to come!

PaulDotCom

May 05, 2008

PaulDotCom Security Weekly - Episode 106 - May 1, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

May 01, 2008

Recording & Stream Notice - Episode 106

The live stream should be active about 6:15-6:30 PM EDT, Thursday, May 1st. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

pdcskin.jpg

- Larry & Paul

April 30, 2008

Network Security Podcast - Episode 103 Appearance

All:

It was my pleasure to make and appearance on the Network Security Podcast with Martin McKeay and Rich Mogull. We had some interesting conversations about SQL Injection, how we got started in computer security, thoughts on the CISSP certification, PCI and its usefullness, and general security banter.

You can download the Network Security Podcast episode 103 here.

Enjoy!

PaulDotCom

April 29, 2008

April Late-Breaking Computer Attack Vectors Webcast

All:

The April Late-Breaking Computer Attack Vectors webcast this month will be held on:

Wednesday, April 30, 2008 2:00 pm EDT (GMT -04:00, New York)

Register Here For This Webcast

This month we I will discuss some of the latest attacks, including hacking kiosks, attacking your desk, and darkets for defense. Hope to see you there...

PaulDotCom

April 28, 2008

Appearing On Network Security Podcast

At 9:00PM EST tonight I will be chatting with Rich & Martin from the Network Security Podcast. Should be fun, we will bat around PCI, SQL injection, and hopefully a few other topics of interest.

You can see and hear it all on our live Ustream channel here.

Cheers,

PaulDotCom

PaulDotCom Security Weekly - Episode 105 - April 25, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 25, 2008

Recording & Stream Notice - Episode 105

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Friday April 25th. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

mrtpdc.jpg

- Larry & Paul

April 22, 2008

Scamming Social Networks

Social networks have become a very popular usage of so-called "Web 2.0" technology. Web sites, such as Facebook and LinkedIn, have begun to move towards targeting working professionals, in addition to the traditional younger college and/or high school crowd. Myself, and others, have been doing extensive research into the security (and insecurity) present in social networking web sites. You may now be wondering, "Just how have you been doing your research?". Well, we decided to register ourselves on several social networking web sites to see just how they work, and just how ourselves and others could break them and abuse the security present in these web sites. What we've found has been very interesting, and useful for providing the community with information about the risks, and tips to protect themselves:

The “Evil Twin” attack was an experiment we performed, and turned out to be wildly successful. We registered a Facebook account as someone else, using an email address we controlled, pictures we downloaded from the Internet, and information we gathered from various publicly available sources. Our attack was very successful, several people believed that the person we faked was real and started to add them as a friend. The best defense here is to register yourself on social networking web sites to prevent others from doing so. We did a segment about this which you can read about and listen to here.

If you use social networking sites regularly you might say, “only people in my network can see my information or my pictures”. This may be true, however XSS vulnerabilities have exposed that information. For example, millions of pictures marked “private” on the popular social network site MySpace, and subsequently Facebook, were suddenly public due to a vulnerability. Once something is “public” on the Internet, there is no going back, its archived in cyberspace forever. Even without vulnerabilities there are groups on sites such as Facebook, and to a certain extent LinkedIn, that automatically allow others in your group to see your profile. For example, I was placed in the group “Providence, RI”, a group anyone can join, and now thousands of people can see my profile. You should always treat information on the Internet as public, whether marked "private" or not.

Recently there has been an unknown exploit of Facebook that is hijacking people’s Facebook accounts and putting up grotesque images, a social network “Rick Roll” attack with a bizarre twist. Reportedly there was a vulnerability in Facebook that allowed this to happen. However, recently I got the following email:

facebookemail.jpg

Looking at the link highlighted in red closely you see that it does not go to Facebook at all, but to some other site, which looks exactly like the Facebook login page, but really is an attacker collecting your username and password. Why would someone launch a phishing attack against Facebook? I'm still not certain why this information is so valuable that it is being targeted by attackers? If nothing else it proves that social networking sites are not only more popular, but represent an area that potentially could be profitable for attackers - as soon as I figure out how, I will let you know :).

Social networks are all about sharing information, however they’re a great way to distribute attacks. Attackers are not looking to use social networks to distribute links to a trusted audience, not just for fun, but profit! Use extreme caution when using social networks and try to think how attackers could use this information and technology against you.

There is no spoon...

Recently I taught a 2-day hacking course titled "Cutting-Edge Hacking Techniques", writen by Ed Skoudis, and offered by The SANS Institute. The students learned a lot, and as always when I teach, so did I. I summarized my thoughts and experiences on a guest blog posting I wrote for my friends over at GNUCITIZEN:

Read the full posting here.

Enjoy!

Cheers,
Paul

April 14, 2008

PaulDotCom Security Weekly - Episode 104 - April 11, 2008

Live from the PaulDotCom studios with special guest Wesley McGrew talking about memory analysis tools.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 12, 2008

PaulDotCom Security Weekly - Episode 103 Part II - April 3, 2008

Live from the PaulDotCom studios with special guest Kevin "The Hacker Princess" Johnson! In the second part of this episode we wrap up the discussion on web app testing and cover the stories for the week.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 11, 2008

Recording & Stream Notice - Episode 104

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Friday April 11th. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

make-the-switch.jpg

- Larry & Paul

April 06, 2008

PaulDotCom Security Weekly - Episode 103 Part I - April 3, 2008

Live from the PaulDotCom studios with special guest Kevin "The Hacker Princess" Johnson!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

April 03, 2008

Recording & Stream Notice - Episode 103

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:15-6:30 PM EDT, Thursday April 3rd. We should begin recording the live show at about 6:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

make-the-switch.jpg

- Larry & Paul

March 28, 2008

My Latest Presentations

All:

Recently I've done some webcasts on various security topics in a few different venues (webcasts and the like). I've had several requests for the presentation media, so I've updated our presentations section with the following:

I really enjoy doing the monthly threat summary and try to include as many "bleeding edge" threats as I can. Most I pull from my hundreds of security news feeds, and some I pull from my twisted imagination. The webcast had over 200 people listening live, so we are very pleased with the level of interest and thank all those who have attended. If you enjoyed the webcast please share it with all of your friends.

Thanks for listening!

PaulDotCom

March 23, 2008

Press Release: PaulDotCom and Haxorthematrix Blogs Merge

As we move forward building PaulDotCom Enterprises we will be working to consolidate some of our other efforts under one umbrelss. As such Larry and myself have agreed that the Haxorthematrix blog will be moved to PaulDotCom. The domain will redirect to this site and Larry will begin posting all his fantastic content to pauldotcom (So if you really like the content, you can click the donate button on the left :).

Some of the latest postings from Haxorthematrix will be moved over to pauldotcom, so look for some good stuff coming soon!

Happy Easter to all those who celebrate it!


pdcbanner2.jpg

haxorthematrix.jpg

Cheers,

PaulDotCom

March 22, 2008

Shmooball Launcher Teaser Trailier

All:

Coming soon, we'll be showing you how the 2008 Shmooball launcher goes together and operates. We even get to fire it a few times. Here's a tease of how we made out.

This video has also been added to our video feed and our YouTube channel

Video Feeds:

YouTube: PaulDotCom YouTube Channel.

Look for more videos to come!

- Larry aka haxorthematrix

March 21, 2008

PaulDotCom Security Weekly - Episode 102 - March 20, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

March Late-Breaking Computer Attack Vectors Webcast

All:

The March Late-Breaking Computer Attack Vectors webcast this month will be held on:

Wednesday, March 26, 2008 2:00 pm EDT (GMT -04:00, New York)

Register Here For This Webcast

This month we are sponsored by Mu Security, makers of a security analyzer series of products (aka automated fuzzing). Very cool devices! I will discuss some of the latest attacks, including RFID, attacking SIM cards, and more! Hope to see you there...

PaulDotCom

March 19, 2008

PaulDotCom Security Weekly - Episode 101 - March 13, 2008

Live from the PaulDotCom studios...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

Recording & Stream Notice - Episode 102

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 6:30-6:45 PM EDT, Thursday March 20th. We should begin recording the live show at about 6:45 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

l33t_odo_sm.jpg

- Larry & Paul

March 14, 2008

PaulDotCom Security Weekly - Special Edition - Interview with GNUCITIZEN Part II - March 7th, 2008

Live from the PaulDotCom Security Weekly Studio, the fine folks from GNUCITIZEN (Petko D. Petkov and Adrian P.) join us for discussion on more of their projects including MDNS and others. Part two of two.

There is s slight, barely audible echo in a few places as an artifact from Skype! We apologize!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

March 11, 2008

Recording & Stream Notice - Episode 101

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 5:45-6:00 PM EST, Thursday March 13th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

larryeatswrt-sm.jpg

- Larry & Paul

March 10, 2008

PaulDotCom Security Weekly - Special Edition - Interview with GNUCITIZEN Part I - March 7th, 2008

Live from the PaulDotCom Security Weekly Studio, the fine folks from GNUCITIZEN (Petko D. Petkov and Adrian P.) join us for discussion on how they got started, and who they are all about and delve into some of their projects in this episode. Part one of two.

There is s slight, barely audible echo in a few places as an artifact from Skype! We apologize!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

March 09, 2008

PaulDotCom TV - Video Feed Update

The PaulDotCom TV video feed lives on! I just know that everyone was dying to have the latest videos from PaulDotCom available on your iPods and iPhones, so I've updated the feed with the latest four spectacular videos from the PaulDotCom crew. They include:

  • Make the Switch: Danny - Larry and I were talking one day last week about the number of listeners that have given us much of the same feedback. They all stated something along the lines of, "I used to listen to Security Now!, but now I listen to PaulDotCom Security Weekly". So, on the last podcast we asked real listeners to record their own switch commercials (audio only). I've added a bit of flavor (thanks to iMovie) and created this video of our first submission (Thanks Danny!).
  • Set Your Router On Fire! SANS SEC 535 - We have created a promotion video for the SANS course I authored called "SEC535 - Network Security Projects Using Hacked Wireless Routers". Sign up for this course today!
  • The Destruction Files - Paul & Larry have some fun busting up some old computer equipment. Sun monitor, take 2, network sniffer, and a Cisco switch all fall victim to Paul's new sledge...
  • Where's Twitchy? - So many of you have written to ask us the age old question, "Where's Twitchy?". This video provides you with the answer...

Video Feeds:

All of these videos are also available on our PaulDotCom YouTube Site. Look for more videos to come!

PaulDotCom

March 07, 2008

Recording and Stream Notice - GNUCITIZEN

NOTE: Our streaming method has changed as of episode 100, and is reflected in the links below.

The live stream should be active about 5:45-6:00 PM EST, Friday March 7th. We should begin recording the live show at about 6:15 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

March 03, 2008

Rhode Island Linux Installfest

All:

In collabortation with SNENUG (The Southern New England Network Users Group), OSHEAN, and PaulDotCom, we are proud to bring you a good 'ole fashion Linux installfest! Got an old PC hanging around? Bring it by! Got a dusty old ipod or wireless router? Come get help with installing Linux, a free operating system that is fun to learn and hack with.

Members of PaulDotCom (Larry and Myself), in addition to some other Linux "gurus" will be at OSHEAN for a full day on Saturday April 5, 2008 to assist people installing Linux.

For more information and to register for this event click here.

I hope to see you all there (however seating is limited so be certain to register at the link above).

Cheers,

Paul

PaulDotCom's Penetration Testing Dojo: Core IMPACT Style

This is going to be another neat webcast in collaboration with SANS and Core Security. Below is the description and sign-up information:

"When beginning a security process at a consortium of non-profits, senior network security engineer, Paul Asadoorian of Pauldotcom began looking for a penetration testing tool that did network, web application and social engineering tests. The tool he purchased is low on manpower use, mostly self-maintaining and reliably proves the existence of network vulnerabilities. Please attend this webcast to find out why Paul selected CORE IMPACT and learn how it can help you safely perform network, web application and end-user penetration testing."

When: Tuesday, March 18 at 1:00 PM EDT (1700 UTC/GMT)
Where: Sign-up here
Who: Allen Paller & Paul Asadoorian

This webcast will give listeners some insight into why I have used Core IMPACT in many different organizations, its benefits, and some of the more creative uses for the product.

Sign-up Today!

PaulDotCom

PaulDotCom Security Weekly - Episode 100 Part II - February 28, 2008

Live from the PaulDotCom Security Weekly Studio for Episode 100! Special guest appearnces from listeners across the world, Black Dragon offers listeners a special treat, and Paul & Larry profess their love for each other...

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

PaulDotCom Security Weekly - Episode 100 Part I - February 28, 2008

Live from the PaulDotCom Security Weekly Studio for Episode 100! Special guest appearnces from Ed Skoudis, Ron Gula, the British Royal Family, and Bob's true identity revealed!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 28, 2008

Recording and Stream Notice - The Big 100!

NOTE: Our streaming method has changed as of episode, and is reflected in the links below.

The 100th episode of PaulDotCom Security Weekly, W00t! There will be much rejoicing, the Skype lines will be open, we have multiple audio clips to play, and this just in, Bob's true identity revealed!

The live stream should be active about 6:30-7:00 PM EST, Thursday February 28th. We should begin recording the live show at about 7:00 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

Don't forget, this is a call in type event! We will have Skype active (id "pauldotcom"), or call in to 401-626-4636!

We using Ustream.tv for this and future episodes (now with video!). We understand the importance of this monumental event, and we will be attempting to make both audio streams available for this episode.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

February 22, 2008

Late Breaking Computer Attack Vectors - Registration Information

This is the first webcast in a monthly webcast series that we are putting on, so bear with us while we work out all of the logistics. I wanted to share the direct registration link:

Late Breaking Computer Attack Vectors - Feb 27 2:00PM EST

I am very excited about this new opportunity and hope you are able to listen in!

Cheers,

PaulDotCom

February 21, 2008

Announcing A New Monthly Webcast: "Late-Breaking Computer Attack Vectors"

PaulDotCom has teamed up with White Hat World to bring you a monthly 30-40 minute webcast titled "Late-Breacking Computer Attack Vectors". I will be hosting the technical discussions where I will b covering the trends happening in security for that month and defensive strategies. Details below:

When: February 27th 2:00PM EST (They will all occur on the last Wednesday of each month at 2:00PM EST,with the exception of November 25, 2008 and December 23, 2008)

Who: Hosted by Paul Asadoorian from PaulDotCom Security Weekly

What Is It? This lively session will discuss recent and anticipated computer and network attack vectors, highlighting the current trends in information security and hacking. Understand some of the most powerful tools and methods in the bad guys' arsenal today, most importantly how to defend your network against them. For each attack vector, we will look at practical, real-world solutions for stemming the tide and keeping your network a safer place.

Registration: Please visit http://www.whitehatworld.com for more information.

We are very excited about this opportunity and I also hope to release these as a podcast as well.

PaulDotCom

February 20, 2008

Episode 99 Problems

All:

If you are experiencing problems with episode 99, please delete the podcast from iTunes and re-add it. It seems that Libsyn and iTunes got stuck indexing only the first 9 seconds of the podcast. I think this is because I ran out of space on my Libsyn account, which I have since upgraded. Please contact us if you hasve any problems.

Thank You,

PaulDotCom

February 18, 2008

PaulDotCom Security Weekly - Episode 99 - February 16, 2008

Paul is live from the PaulDotCom Security Weekly Studio, and Larry is live from Shmoocon! Get the latest information from the hottest security conference this year!

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 14, 2008

Shmoocon and Recording notice.

Just as a reminder Larry will be at Shmoocon this weekend in chilly Washington DC. Don't forget to check our the podcasters meet up Friday night. It is our understang that we'll be doing a video cast, and streaming live courtesy of the geeks at Hak.5. Stay tuned for more details as they unfold.

Larry has a limited supply of some shwag, but plenty of stickers!

Additionally, the PaulDotCom crew will be recording an episode on Saturday Feb, 16 at about 6:30 PM.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

February 11, 2008

SEC535 - "Set Your Router On Fire" Video

All:

We have created a promotion video for the SANS course I authored called "SEC535 - Network Security Projects Using Hacked Wireless Routers":

Sign up for this course today:

SANS Orlando (Comes with your very own copy of Linksys WRT54G Ultimate Hacking by Paul Asadoorian and Larry Pesce!

If you are interested in this course and cannot attend the Orlando conference please contact me (paul /at/ pauldotcom.com) for more information.

PaulDotCom

PaulDotCom Mailing List

All:

Larry and myself have many conversations about how to best communicate with our listeners, send/receive feedback, and generally what our presence on the Internet should be. We've created a mailing list with the following intentions:

  • General Questions/Feedback - Please do still send email to psw /at/ pauldotcom.com, however Larry and I are sometimes busy and do not get a chance to respond to all emails. This mailing list can serve as a place to post questions, feedback, or general comments and the hope is that if Larry or myself can't respond, someone else will.
  • Announcements - Yes, we have a blog, podcast, and multiple RSS feeds. However, some just prefer to have a mailing list that keeps them current. We intend to use the list to announce episodes, locations where we are recording live, contests, and everything related to PaulDotCom!
  • Technical Discussion - We hope that the discussions on the mailing list will be as technical and informative as the podcast and to a certain extent the IRC channel. Our goal is to keep everyone educated and allow you to learn about computer security and hacking, and hopefully the mailing list helps you do that

So come join now!

PaulDotCom

February 08, 2008

PaulDotCom Security Weekly - Episode 98 Part II - January 31, 2008

Live from the PaulDotCom Security Weekly Studio with our very own "reverse engineering specialist", the baby maker from Canada himself, Justin Seitz!

In part II of this episode we first have an awesome discussion about how broken the information security industry is right now and offer some advice on how to fix it, then cover the stories for the week.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

February 03, 2008

./PaulDotCom &

Just a quick notice to all listeners that we will not be recording the week of February 4, 2008. Our short little hiatus will be just that, short. We are releasing episode 98 in two parts as it was a two hour show, full of glorious security karma. Also filling the the gaps is my keynote presentation on hacking embedded devices which is always a treat.

Looking ahead we are planning a special 100th episode where we hope to have participation from many of our dedicated and wonderful listeners and collaborators on the show. We may take a week off in order to prepare for this show as I believe that 100 episodes is quite a landmark achievement for PaulDotCom Security Weekly. Still to this day I am astonished at what we have created. Don't worry we have plenty of new, exciting, entertaining, and informative inititives up our sleeves so stay tuned! Along with a new web site in the works there may be some special annoucements regarding PaulDotCom as we move forward to reach out to new audiences and continue to grow.

As always, thank you for listening...

PaulDotCom

PaulDotCom Security Weekly - Episode 98 Part I - January 31, 2008

Live from the PaulDotCom Security Weekly Studio with our very own "reverse engineering specialist", the baby maker from Canada himself, Justin Seitz!

In part I of this episode we cover two technical segments, one by Justin on DLL injection, and one by PaulDotCom on hacking mDNS/Bonjour/Zeroconf.

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds: add to my PodNova

January 31, 2008

Recording and Stream Notice - Episode 98

NOTE: Our Streaming server has changed as of episode 94, and is reflected in the link below.

The live stream should be active about 7:00-7:30 PM EST, Thursday January 31st. We should begin recording the live show at about 7:30 PM EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream can be found at:

http://radio.oshean.org:8000

Please join us, and thanks for listening!

- Larry & Paul

January 29, 2008

PaulDotCom Switch Commercial - Danny

Larry and I were talking one day last week about the number of listeners that have given us much of the same feedback. They all stated something along the lines of, "I used to listen to Security Now!, but now I listen to PaulDotCom Security Weekly". So, on the last podcast we asked real listeners to record their own switch commercials (audio only). I've added a bit of flavor (thanks to iMovie) and created a YouTube video of our first submission (Thanks Danny!):

Enjoy! And keep those submissions coming as we reward with fabulous prizes!

PaulDotCom

January 28, 2008

Where's My iPhone? - A Lesson In Incident Response

Introduction

Security incidents come in many forms, from attackers breaking into computers, unauthorized attempts to sniff wireless networks and collect information, and stolen laptops or phones. This example is the latter, a stolen smartphone. What follows is the incident response procedure that I followed once I found out my phone had been stolen. Its not a comfortable feeling to know that someone else has control over a device containing your information. However, you must remain calm and follow some sort of incident response procedure. Sometimes this is not as easy as it sounds (as you will see below). Once the incident is over the most important thing you must do is learn from it. Hopefully you can learn from my experience.

Some Days Are Better Than Others

This all started with one of the things I enjoy most in this world, and thats sushi (In fact Josh just pointed out that I was the one who introduced him to sushi, and now he has an entire site named after this fabulous food!). I was going out to eat with my family and was talking on my iPhone on the way. I pulled into a spot in the parking lot, got out of the car and went into the restaurant where I draped my long trenchcoat over the chair on the table behind me. After feasting on some sushi ("slammin' salmon" roll was awesome) we paid the bill and I all of a sudden realized I did not have my phone. I searched my pockets, no iPhone. I thought, "well, I must have left it in my coat". I searched my coat, no iPhone. I searched around the table and the table behind us where my coat had been, no iPhone. I then thought, "well, it must be in the car". I searched the car, making everyone get out all while I cursed aloud, and no iPhone. I went back into the restaurant and searched the tables again, no iPhone. The conclusion, someone had stolen my iPhone when I either dropped it getting our of the car or when it fell out of my coat pocket.

Incident Response 101: Don't Panic

So I called my wife in a panic, explaining to her how someone else now has possession of my phone, which not only contained countless pictures of our last vacation and family (mostly pictures of the dog), but also had access to ALL of my email accounts. I was on my way to a family members house to get a flashlight to do a more thorough search of the car, as I was still in disbelief that someone stole my phone. Human instinct is a funny thing, even though I have training in computer incident response (even worked a few cases of data theft) I was still in great disbelief that someone would actually steal my phone. Another search through the car, guess what no iPhone. My only saving grace was that I left my home phone number with the restaurant in case the phone magically appeared. On my way home I still thought there would be a chance that they found my phone and called the house to tell me. I got home, no phone call and still no iPhone.

When you can't prevent or detect, react

I picked up my wife's phone as soon as I got home and dialed 611, the number for direct access to AT&T customer service. I waded my way through the options and discovered that I could report the other phone line, and associated phone, lost or stolen right through the menu, after of course being prompted for the billing zip code. Thats right, the only authentication you need to cancel the other line is the billing zip code. This means you can use anyone's AT&T phone to disconnect the other line on that account, and all you need is access to that phone and the billing zip code (most people put their address on the phone in case its lost, how ironic). If you are a smart phone thief, you can disable the other line when you steal a phone.

My iPhone had access to all of my email via passwords stored on the phone itself. My first step was to change all of my email passwords immediately. Once that was done I also changed the pin number to my voicemail. There was nothing sensitive in my email lately (i.e. a password emailed from a credit card or bank account), but I wanted to be certain that no one used the phone to check my email. I checked the email logs on one of the email servers I controlled and it showed that no one had used it to access my email. I started feeling a little better. Calls to the phone were going directly to voicemail while the phone was missing, and my guess is that the thief turned the phone off and removed the SIM card, or the battery died. In either case I wanted to be certain there we no calls made from the phone, so we activated our account online with AT&T and checked the call logs, which showed calls to my voicemail (which was normal as my voicemail forwards to YouMail, which is a great service). Now I feel slightly better, and my wife, as always, puts things in perspective and points out that it was not my car or laptop that was stolen, and that no one was hurt (however, the thought of having the opportunity to defend my iPhone appealed to me, if ever so briefly).

I did call the police, who weren't much help and told me that I need to go back to the scene of the crime or come to the station to file a report. Since the damage was done, I did not follow through with a police report. However, had I not been in such disbelief, I would have most likely called the police on the spot.

Lessons Learned

I try to look at all incidents, especially ones that have financial impact, as a learning experience. What could I have done better? Also, what can I do better/different in the future to have a positive impact on the outcome? Below is a list that I hope we can all learn from:


  • Make it easy to change passwords and access your account - Have instructions on how/where you change your email/voicemail passwords so you can do it quickly. Also, have your online account setup and easy to access so you can check your statement and/or de-activate accounts online. This could be as easy as keeping a list of local bookmarks in your browser or in a text file.
  • Report your phone stolen immediately - There were reports online about stolen phones being used to rack up $20,000+ worth of charges. Its hard to overcome the disbelief that your phone has been stolen, however better safe than sorry. It is best to report your phone stolen ASAP.
  • Get insurance - Apple Care protection extends your warranty (Which I had), and is not insurance. Supposedly Apple offers some kind of insurance (according to the AT&T representative), but I am unable to find more information. Also, you may want to follow up with your home insurance provider to see if its covered ($400 may slide under your deductible though).
  • Use a keypad/passcode lock - I did not set the passcode on the iPhone. I know, I know...silly me. However, this passcode is easily bypassed thanks to a vulnerability described here. This has to do with the "Emergency Call" feature in the iPhone, which could be used to not only make a call even though the phone is locked (which is still the case in the latest firmware) but launch applications as well. The only other method available to get around the passcode is to restore the iPhone, which would wipe all the data off of it, but still give an attacker access to your cell service if it has not already been de-activated.
  • Don't store your email passwords on your phone - This is a hard one. On the one hand we tell everyone to use good, if not great, passwords. But, imagine trying to enter a 12 character passwords, mixing upper/lower case, letters, numbers, and symbols on your iPhone? To quote someone from the #pauldotcom IRC chat room, "Ugh.". If you do store passwords on your phone, make sure they are not used anywhere else.
  • Use security software on your phone - This is an interesting dilema, if you hack your iPhone it most likely prevents you from applying security updates from Apple (which fix things such as the passcode bypass). These updates will break all of the modifications made to your iPhone, including the hack to change providers. However, hacking your iPhone allows you to install 3rd party applications, such as iphonelockbox, which lets you encrypt your passwords and other information on your iPhone. Apple is supposed to make available the ability to install 3rd party applications on your iPhone sometime in February 2008, so this may be a wait and see situation.
  • Smart phone, careless user - I can't live without my phone. Aside from providing the ability to send and receive phone calls, I use my phone to store contact information, check my email, send/receive text messages, take pictures, listen to music, watch TV shows/Movies, and browse the web. I should have been more careful, just as with your laptop, never let your phone out of your sight. Always be mindful of where your phone is at all times. For me, I may chain it to my belt from now on!

Conclusion

I hope that you read the above and learned something about how to protect your information. I hope that you use this information to make changes to your security strategy, whether it be protecting your personal information, or your organization's secrets.

PaulDotCom


January 27, 2008

PaulDotCom Security Weekly - Episode 97 - January 24, 2008