Sinopsis
SecuraBit Before It Bytes!
Episodios
-
SecuraByte Episode 05 Happiness, Fail Whale beaches Itself!!!
07/01/2009 Duración: 39minNews at 11. Well really we started recording about 8 PM on Monday January 5th. In this SecuraByte episode, Securabit had its largest conference call yet. Securabit was joined by the guys from both SecurityJustice.com and SMBMinute.com, as well as Melissa on Twitter AKA @Geekgrrl. We discussed the security vulnerability discovered with twitter.com's tech support. This is a service many of us use and enjoy. Please have a listen in while we discuss amongst ourselves. Don’t forget to give us a feedback on Itunes so we can bump the old shows off the list. Thanks again for all the donations for the Tip Jar. Hosts: Rob Fuller - Mubix, room362.com @mubix Anthony Gartner - AnthonyGartner.com @AnthonyGartner Chris Gerling - Hak5Chris, Chrisgerling.com @Hak5chris Chris Mills - ChrisAM @packetsense Jason Mueller - SecurabitJay Special Guests: Melissa (@geekgrrl), Tim Krabec (@tkrabec) of the SMBMinute.com, Tom (@agent0x0) securityjustice.com, and Dave (@Securi-D) securityjustice.com Important links for the show
-
Securabit Episode 17 for xmass Santa gave us an Nmap book to give away!!!
22/12/2008 Duración: 44minThis is a unique episode for SecuraBit, we are teaming up with the Security Justice Podcast to do a double header show. SecuraBit recorded their show from 8-9 PST, then handed off the reins to Security Justice to finish out the night. In doing so we had a combine set of prizes. To win the prize required that you listen and get the correct answer to a trivia question given on SecuraBit. You also had to listen to the Security Justice Podcast to and know the answer to their question as well. SecuraBit even manged to start on time as well as hand off on time. It was a very different type of show due to trying to condense everything in to a single hour. (Good thing we didn't have any real content, Just kidding) SecuraBit opened the show but because Jay needed to switch some things out we actually went to a break faster than normal. When we returned from the break we did indeed have Jay on the line. We started to go into the new Microsoft Zero Day, and Jay informed us that he had been out of the loop fo
-
Securabit Episode 16 How many F-Bombs are required for $40
10/12/2008 Duración: 52minIn this episode we talk about Chris Gerling attending the SANS Cyber Defense Initiative 2008 in Washing DC. He will be taking the Security 508 Computer Forensics, Investigation, and Response course. If you are at the conference please make sure you look for Chris. He also plans to take the new GPEN test while there. We might be bringing the sock monkey to Shmoocon and have him do some interviews. We also spoke about how few businesses are actually checking a persons signature or id for credit cards. Most businesses are simply not checking the cards like they should be. Chris is beginning to wonder if they will card his fiancee between now and when they get married. After the break we came back and mentioned that we were not going going to drop the Fbomb for 40 bucks as was hinted at in the chat room. Went into the issue of dns forwarding being done on CheckFree.com The article was actually from The Washington Post by Brian Krebs. Anthony put a shout out to Ed Smiley for sending both Mubix and Antho
-
Securabit EP 15 Will the real Joel Esler please step forward!
01/12/2008 Duración: 52minSorry for the delay in getting this episode out this time. Anthony got stuck with doing some actual work and then we all got hit by the holidays. We do hope you enjoy the show this week. Mubix attended the CSI Conference and no not CSI on TV, the CSI Anual conference. The topic he found intriguing is Security and Responsibility. If something happens how and to what extent as security professionals are we responsible and accountable. This is a topic he brought up on twitter as well and got a lot of replies back. Some agreeing and some not, Feel free to weigh in on this one. Some of the references that were brought up in response to this topic were Sandboxie, castlecops, and Web of Trust. After the break we went into a discussion on DD Images and using live view on them, but since that was a fail, Chris used QEMU. You can even go get some test images at ProjectHoneypot.org and convert them using a tool dd2vmdk . The conversation went into WPA is not Busted. We referenced Steven Gibson's explantio
-
Securabit Episode 14 We remind you to not get SWACKED!!!
10/11/2008 Duración: 54minIn this episode we have a special guest Adrian from Irongeek.com. We conversed about the going's on at phreaknic. Adrian presented down there and this is where he ended up meeting Bruce and Heidi Potter from the Shmoocon Group. The discussion covered a little more on the MS08-067 issues, Sans Training, and CEH. This is the first episode where we experimented and used stickam.com to allow the listeners to see just how messed up we really are. After the break, Adrian spoke about how one of the guys from binrev.com turned him on to a book for review called Googling Security: How Much Does Google Know About You? written by Greg Conti. Anthony ended up going into some of new virus / trojan infections. These were on the lines of antivirus 2009 and others of the type. Consensus was that a good cleaner tool was called Rougefix (recommendatin from the IRC channel by Tim Krabek). Adrian recommended a song by Tom Smith about Technical Suport for Dad. We went into a little more information on the New York Scho
-
Securabit Episode 13 B00 (Happy Ha110w33n)
30/10/2008 Duración: 46minIn the Halloween Episode 13 where we neglected to mention Halloween, the guys talk about a wide range of topics on the show. The topics we covered included Australia joining the Great Firewall of China, The FBI's Dark Market Takedown, National Cyber Security Awareness Month, CERT Training, spaghetti sauce, and phreaknic 12 (where Chris was going to go but was not able to at the last minute) The East Coast is represented up and down with Chris G traveling to New York. We even had a ghostly apparition that sounded a lot like Jason Mueller. Hosts: Chris Mills - ChrisAM Chris Gerling - Hak5Chris Anthony Gartner - AnthonyGartner.com Jason Mueller - Important links for the show and documents used: http://www.techcrunch.com/2007/12/30/australia-joins-china-in-censoring-the-internet/ http://www.fbi.gov/page2/oct08/darkmarket_102008.html http://www.sickurity.com/ http://www.us-cert.gov/press_room/cyber_security_awareness_month.html https://www.vte.cert.org/vteweb/ http://www.acm.org/ http://www.schneie
-
SecuraByte Episode 4
25/10/2008 Duración: 25minThis evening we had a podcast about the new Zero Day Exploit. This exploit covers all versions of windows from 2000 and above. Securabit brought in Tim Krabec from the smbminute.com podcast. This covers the article from Microsoft MS08-067. Hosts: Chris Mills - ChrisAM Chris Gerling - Hak5Chris Anthony Gartner - AnthonyGartner.com Guests: Tim Krabec (Cray Beck) Important links for the show and documents used: http://docs.google.com/Presentation?id=dghttrwg_26c47c5xcx http://blogs.technet.com/msrc/archive/2008/10/23/ms08-067-released.aspx http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx http://milw0rm.com/exploits/6824 http://blogs.technet.com/swi/ SecuraByte Episode 4Beer Tim's beer Optimator Spaten Munich
-
SecuraBit Episode 12
13/10/2008 Duración: 56minSecurabit Episode 12 Anthony Gartner Chris Mills Chris Gerling Chris G rides the Failbus with his FIOS connection IT Jobs: No "Widespread Worry"?: http://blogs.cioinsight.com/biztech30/content/it_careers/it_jobs_no_widespread_worry_2.html Air Force Cyber Command: http://blog.wired.com/defense/2008/08/air-force-suspe.html Cracking one billion passwords per second with NVIDIA video card - http://www.net-security.org/secworld.php?id=6616 BREAK Chris G talks about running VM's in Vista Ultimate 64 bit The guys discuss home networking Soekris Box: http://www.soekris.com/ Netgate m1n1wall firewall 3E 2D3 http://www.netgate.com/product_info.php?products_id=312 AIG Executives Blow $440,000 After Getting Bailout: http://www.foxbusiness.com/story/markets/industries/finance/aig-executives-blow--getting-bailout/ Password Management Systems: Password Safe - http://passwordsafe.sourceforge.net/ KeePass - http://keepass.info/ Password Gorilla - http://www.fpx.de/fp/Softwar
-
SecuraBit Episode 11
29/09/2008 Duración: 01h04minThis week Anthony Gartner & Rob Fuller discuss the latest computer security news. Special guests are Vyrus and CP from the dc949.org group. Episode 11 Discussions covered the following topics: Skynet, Advanced Dork, Google Site Indexer, These tools work worked on by CP and Vyrus and the dc949 group and are written as open source. Rob brought up a Firefox add on called Barrier Spoke of how we can use google alerts to help us in our daily tasks to track where our information is being sent out to. Discussion ensued about Scroogle.org not to be confused with scoogle.com and how you can do secure searching though the site and that the site purges logs with in 48 hours. A mention of Cisco was brought up and we also spoke of a visualized version for the Cisco Mips processors and the specific virtualized version of the Cisco 7200 Routers. BlackBerry Encryption keys may be in the hands of the Indian Government as part of the deal with Rim.
-
SecuraBit Episode 10
19/09/2008 Duración: 49min(Apologies in advance for the short term 'wiki' look of these show notes, the public wiki will be up soon!) On this Episode of Securabit: Chris Gerling - Hak5chris Chris Mills - ChrisAM Anthony Gartner - AnthonyGartner Jason Mueller - SecuraBit_Jay Guest Chris Wilson Episode 10 - A milestone! We are all still alive even though the CERN Particle Collider has been started up. OpenSource Projects, Software, Patches Obama Sex Video Spam New SecuraBit VPS! (We have since cancelled and will be moving to something else soon) Linode with CentOS. However, no SELinux available For CentOS help go to: #CentOS on irc.freenode.net Tips for configuring the new server: Disable root login on ssh Good passwords Lock down ports The Securabit guys started using the CentOS distribution because of its interconnections with Snort See this site for details on how to configure Snort on CentOS In non-security related news: Steve Jobs Apple Special Event "Let's Rock" Apple did update QuicktTime and Bonjour: http://
-
SecuraByte Episode 3
10/09/2008 Duración: 46minLast night we did a spontaneous hour long interview with the guys from HacDC, a Hackerspaces group.Hosts:Rob Fuller - Mubix Chris Mills - ChrisAM Chris Gerling - Hak5Chris Guests:Nick Farr - Treasurer HacDC Mitch Altman - http://en.wikipedia.org/wiki/Mitch_Altman - NoiseBridge San FranciscoBryceHacDC and Hackerspaces.What is a Hackerspace?: Physical space where hackers make things, inperson place to do things rather in addition to online. People canwork on their own projects and collaborate with others.Mitch has been working on Brain machines.Tips on how to start a hackerspace:- Visit a hackerspace- Document on Hackerspace design patterns (PDF).- Go to Visit: Hackerspaces.org and email questions about getting started to info@hacdc.org- Last Hope Talk: Building Hacker Spaces Everywhere: Your Excuses are Invalid - Nick Farr and Friends (MP3).If I am not a member, can I go: Yes!Some hackerspaces mentioned:NY ResistorC-base (Berlin Germany)The Hacktory (Philadelphia)Mitch working on SF Space, NoiseBridgeNoiseB
-
SecuraBit Episode 9
04/09/2008 Duración: 01h02minOn this episode of SecuraBit: Multiboot Security DVD Mubix posted an awesome link on his blog to a Multiboot Security DVD that allows you to choose which common security distros, all on one medium! OS Choices: Backtrack 3 Damn Small Linux 4.2.5 GeeXBoX 1.1 (not geekbox ) Damn Vulnerable Linux (Strychnine) 1.4 Knoppix 5.1.1 MPentoo 2006.1 Ophcrack 1.2.2 (with 720 mb tables) Puppy Linux 3.01 Byzantine OS i586-20040404 Make a bootable FAT32 USB stick using Unetbootin Some distros the Securabit guys would like to see added: Helix Intelguardians Samurai RedHat/Fedora OpenSSH Compromises As noted on the Securabit website, a Fedora and Red Hat Enterprise Linux servers were compromised. The ComputerWorld Blog - Linux Security Idiots article explains how the servers were compromised -Stolen SSH keys are used to gain access to the system -After that, rootkit "phalanx2" is installed and steals more SSH keys -Ob
-
SecuraBit Episode 8
15/08/2008 Duración: 45minOn this Episode of SecuraBit Jason Mueller Chris Gerling Anthony Gartner Back from three week hiatus. Defcon and BlackHat Defcon Parties: Core Impact Party EthicalHacker.net party Cisco Party Isight Party I-hacked Party StillSecure Freakshow Party ChicagoCon: Boot Camps: Oct 27 - 31 Conference: Oct 31 - Nov 1: http://www.chicagocon.com/ Defcon Badges Ran out of Badges on first day: http://search.twitter.com/search?q=Defcon+badges+out TV-B-Gone built into the badges: http://www.hackaday.com/2008/08/05/defcon-16-badge-details-released/ Servo hacks the badges - LINK? Podcasters Meetup - http://www.podcastersmeetup.com/ and http://securabit.com/2008/08/13/dc16-recap/ Documentary: Hackers are People Too: http://www.hackersarepeopletoo.com/ BREAK More from Podcasters meetup: Maltego - Maltego is an open source intelligence and forensics application - http://www.paterva.com/maltego/ Iphone Met
-
SecuraBit Episode 7
27/07/2008 Duración: 55minOn this episode of SecuraBit, we talk to Chris Eng and Chris Wysopal from Veracode about SOURCE Boston, as well as Jennifer Leggio about Twitter and more: SOURCE Boston identi.ca and OpenID Facebug Bug leaks birthday data ActiveworxA little more on the DNS fiasco (see past show links on DNS issues).Failbus I'm going to be installing wiki software and recruiting some folks to help us do proper full show notes for each episode. We're also looking for people to help out with the forums, IRC, and research for technical segments. If you can contribute in any way we'll make sure you get recognized. Direct link to show here. Remember to hit up the T-Shirt and Sticker page. Soon I will remove the T-Shirt donate link as I will be shipping the box of T-Shirts to Jay to take with him to Defcon. Hit us up on the forums, or at irc.freenode.net #securabit. Thanks for listening!
-
SecuraByte Episode 2
26/07/2008 Duración: 20minLast night we decided to discuss a little more on the DNS vulnerability issue that's been the hot topic everywhere in terms of detection and defense. Thanks to guest Chris Wilson for his invaluable insight into the snort signature we were provided by alexkirk in #snort on irc.freenode.net. We also discussed detection of encrypted traffic on a network, and some of the implications of it. Direct link to the mp3 is here. Apologies for Chris Wilson's audio, his speakers were on unbeknown-st to us, and I cleaned it up as best I could. :) Also, the stickers are finally in! Get your T-Shirts and stickers here!
-
SecuraByte Episode 1: DNS Haiku
22/07/2008 Duración: 36minToday we introduce a new portion of the show: Securabytes. Securabytes are unannounced episodes, they could be last minute interviews or just more beer induced security speak. So, without further ado, here is the first Securabyte from the Securabit Podcast. "Introducing haiku-DNS: [laughing corruption collapsing kittens gallop nectars forgiving] = usa.gov" - Chris Wesley McGrew of McGrew Security, Martin McKeay of the Network Security Blog / Podcast, and some guy name Joel joined me (Rob Fuller) last night to discuss the DNS vulnerability leakage that happened about quitting time yesterday (7/21). We discuss the leak, how the vulnerability works, mitigating, and the potential it has on mass scales. Every one of the gentlemen that joined us, and we here at Securabit urge you to patch as soon as possible. If you need further information, please check the following links: Direct link to this episode: http://media.libsyn.com/media/securabit/securabytep01.mp3 Check to see if you are vulnerable: http://www.doxpara.
-
SecuraBit Episode 6
17/07/2008 Duración: 58minOn this episode of SecuraBit Chris, Jay, and the crew discuss: Major DNS vulnerability patched!Check your DNS vulnerability status here!BackTrack 3: Hard Drive?More BT3 goodness! (Courtesy of pure_hate)Andy's Trip to Spain!Various other things, and if you haven't noticed by now.. bloopers! We also want to announce that our T-Shirts have arrived, which you can get here! Stickers will be available very soon! As always, hit up the forums and start talking security with other professionals, pop into our irc at irc.freenode.net #securabit (cloaks coming soon!), and send any feedback to feedback@securabit.com or through the contact page on the site here! Thanks for listening!
-
SecuraBit Episode 5
29/06/2008 Duración: 01h12minOn this episode of SecuraBit:Anthony, Chris, Christopher, Jay, and special guest Rob (mubix) discuss:Signature based anti-virus dead?Rubbermaid Botmaster SentencedBackTrack3 Final released!Using Google Earth to crash neighboring poolsCrazed Bovine TraversalDistributed Honeypot ProjectThe iTunes link on the front page here works again!!! Check out the forums, and our IRC at irc.freenode.net #securabit. Any feedback is welcomed either through the contact form, or at feedback@securabit.com, or on the forums. Thanks for listening!!
-
SecuraBit Episode 4
17/06/2008 Duración: 01h24minOn this episode of SecuraBit, Chris, Jay, Anthony, Andy, and Chris Mills discuss: * Integrity of Fax Signatures. * Metasploit hacked? Layer 2 VLAN fun. * Clever Museum Theft. * Ironkey-like USB Flash Drive: DiskGO GUARDIAN. * Virus that encrypts your data. * Safari Carpet Bombing, and more!Make sure to hit up our forums, and IRC at irc.freenode.net channel #securabitSend all feedback to feedback@securabit.com or use the contact page on the site. We apologize for the delay! Thanks for listening!
-
SecuraBit Episode 3
02/06/2008 Duración: 01h01minOn this episode of SecuraBit, Chris, Jay, Anthony, Andy, and Chris Mills discuss: TJ Maxx employee fired for disclosing vulnerability.Atari CEO says TPM chips will end all game piracy.How to sell security.Hackthissite.org call for developers.Large companies paying employees to read internal email.Comcast loses control of its domain name.Various geek talk. Going MP3 only on this episode. Thanks for listening! Direct DL: SecuraBit Episode 3 MP3