<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>An Information Security Place</title>
	
	<link>http://infosecplace.com/blog</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Thu, 12 Nov 2009 12:51:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<media:copyright>Copyright Michael R. Farnum</media:copyright><media:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><itunes:owner><itunes:email>m1a1vet@infosecplace.com</itunes:email><itunes:name>Michael R. Farnum</itunes:name></itunes:owner><itunes:author>Michael R. Farnum</itunes:author><itunes:explicit>no</itunes:explicit><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><itunes:subtitle>Commentary on the state of information security.</itunes:subtitle><itunes:summary>Commentary on the state of information security.</itunes:summary><itunes:category text="Technology" /><creativeCommons:license>http://creativecommons.org/licenses/by-nd/2.0/</creativeCommons:license><image><url>http://www.feedburner.com/fb/images/pub/fb_pwrd.gif</url></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/AnInformationSecurityPlace" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>An Information Security Place Podcast – Episode 27</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/Dte9XZmgR4Y/</link>
		<comments>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 12:51:51 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Acer]]></category>
		<category><![CDATA[BBQ]]></category>
		<category><![CDATA[chief]]></category>
		<category><![CDATA[ChoicePoint]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Dell]]></category>
		<category><![CDATA[DigiQ]]></category>
		<category><![CDATA[FDIC]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Houston]]></category>
		<category><![CDATA[ikee]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NAISG]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[Netbook]]></category>
		<category><![CDATA[Nvidia]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1115</guid>
		<description><![CDATA[
Link to MP3

OK, Episode 27 is FINALLY here.  Sincere apologies to all of our listeners.  We really could not avoid the long break.  Work and family and everything else seriously pounded us this time.  ENJOY!
Show Notes:
InfoSec News Update -

FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – Link Here
Senator [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">OK, Episode 27 is FINALLY here.  Sincere apologies to all of our listeners.  We really could not avoid the long break.  Work and family and everything else seriously pounded us this time.  ENJOY!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong>InfoSec News Update -</strong></p>
<ul style="clear: both">
<li>FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – <a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=220900031">Link Here</a></li>
<li>Senator says the cybersecurity chief should be in DHS, not the White house – <a href="http://www.computerworld.com/s/article/9140307/Put_cybersecurity_chief_in_DHS_not_the_White_House_Senator_says?taxonomyId=82">Link Here</a></li>
<li>Major SSL Flaw Find Prompts Protocol Update – <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221600523">Link Here</a></li>
<li>Jailbroken iPhones more vulnerable to attack; ikee worm Rick Rolls iPhone users – <a href="http://www.computerworld.com/s/article/9140699/Hackers_pillage_jailbroken_iPhones?taxonomyId=82">Link Here</a></li>
<li>New FDIC Phishing Attack – <a href="http://www.fdic.gov/consumers/consumer/alerts/index.html">Link Here</a></li>
<li>MSFT trying to walk the annoyance / security fine line with toned down User Access Control (UAC) in Windows 7 – <a href="http://www.computerworld.com/s/article/9140323/Microsoft_neutered_UAC_in_Windows_7_says_researcher?taxonomyId=145">Link Here</a></li>
<li>Awesomely funny story about an IT engineer in Iraq annoying the troops with some bogus war driving – <a href="http://blogs.computerworld.com/15012/the_fobbit">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong> Highlights from Michael’s NAISG Chapter Meeting</p>
<p style="clear: both"><strong>Geek Toys – “Ideas to get your Geek for Christmas”</strong></p>
<ul style="clear: both">
<li>Still Need A Netbook? Try and <a href="http://www.officemax.com/technology/computers/netbook-computers/product-prod2550242">Acer</a> or a <a href="http://www.dell.com/home/netbooks">Dell</a></li>
<li>Playing with GPU Acceleration – <a href="http://www.newegg.com/Product/Product.aspx?Item=N82E16814125294&amp;cm_re=gtx_260-_-14-125-294-_-Product">The Nvidia GTX 260 is a great choice</a></li>
<li>Windows 7 – <a href="http://store.microsoft.com/Windows7/Compare">Pick your favorite version</a></li>
<li>Network Attached Storage – <a href="http://www.netgear.com/Products/Storage/ReadyNASDuo.aspx">2 Drive</a> / <a href="http://www.qnap.com/pro_detail_feature.asp?p_id=127">4 Drive</a> / <a href="http://www.qnap.com/pro_detail_feature.asp?p_id=109">8 Drive</a> Solutions</li>
<li>Make Perfect BBQ everytime – <a href="http://secure.thebbqguru.com/ProductCart/pc/viewPrd.asp?idcategory=49&amp;idproduct=235">DigiQ system from thebbqguru.com</a></li>
</ul>
<p style="clear: both"><strong>Music notes -</strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=6b2fccdd12aaeb7e3fd40fc37d5cda29">Nathan Lee – “Hold Me Down”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?pageNum_MusicList=1&amp;totalRows_MusicList=9&amp;BandHash=49cc3a9880475e71522596bdaa3dcb4d">Junk Yard Groove – “Its OK”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=53ed9999937c75761728272156dc002c">Great Luke SKI – “Parents Bought Me intellivision”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Dte9XZmgR4Y:jRCPPQuyOEc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Dte9XZmgR4Y:jRCPPQuyOEc:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Dte9XZmgR4Y:jRCPPQuyOEc:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3" length="58497152" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode27.mp3" fileSize="58497152" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 OK, Episode 27 is FINALLY here. Sincere apologies to all of our listeners. We really could not avoid the long break. Work and family and everything else seriously pounded us this time. ENJOY! Show Notes: InfoSec News Update - FTC Orders Choic</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 OK, Episode 27 is FINALLY here. Sincere apologies to all of our listeners. We really could not avoid the long break. Work and family and everything else seriously pounded us this time. ENJOY! Show Notes: InfoSec News Update - FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach – Link Here Senator [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/11/12/an-information-security-place-podcast-episode-27/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 26</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/-wBH4fdx8B4/</link>
		<comments>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 10:51:19 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[bad]]></category>
		<category><![CDATA[behavior]]></category>
		<category><![CDATA[grid]]></category>
		<category><![CDATA[Houston]]></category>
		<category><![CDATA[Marketing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NAISG]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[power]]></category>
		<category><![CDATA[Rsnake]]></category>
		<category><![CDATA[security consulting]]></category>
		<category><![CDATA[Star Trek]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[WAF]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1110</guid>
		<description><![CDATA[
�
Link to MP3

Episode 26 is here.  It almost didn&#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy!
Show Notes:
InfoSec News Update – 

Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>
<p> </p>
<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Episode 26 is here.  It almost didn&#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy!</p>
<p style="clear: both"><strong>Show Notes:</strong></p>
<p style="clear: both"><strong><span style="text-decoration: underline;">InfoSec News Update – </span></strong></p>
<ul style="clear: both">
<li>Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in Houston, TX. – <a href="http://houston.naisg.org">Houston Chapter Website</a> / <a href="http://chair-houston@naisg.org">Email Link</a><span style="text-decoration: underline;"><br />
</span></li>
<li>Power Grid Takedown – a HowTO – <a href="http://www.theregister.co.uk/2009/09/16/power_grid_weakness/">Link Here</a></li>
<li>Court Ruling – Disloyal Computing is Not Illegal – <a href="http://www.wired.com/threatlevel/2009/09/disloyalcomputing/">Link Here</a></li>
<li>New OWASP Sponsored Web App Firewall – <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=220100630">Link Here</a></li>
<li>MS Gets into the AV Game … Again…with latest release – <a href="http://blogs.pcmag.com/securitywatch/2009/09/microsoft_security_essentials.php">Link 1</a> / <a href="http://news.techworld.com/security/3202965/rivals-mock-microsoft-security-essentials-download/?olo=rss">Link 2</a></li>
<li>Trojans getting Smarter – <a href="http://www.h-online.com/security/Trojan-hides-in-Windows-recovery--/news/114322">Link Here</a><span style="text-decoration: underline;"><br />
</span></li>
<li>PCI DSS Update Could Include Virtualization Security – <a href=" http://www.darkreading.com/database_security/security/government/showArticle.jhtml?articleID=220200260">Link Here</a></li>
</ul>
<p style="clear: both"><strong><span style="text-decoration: underline;">Discussion Topic -</span></strong></p>
<p style="clear: both">Encouraging Bad Behavior via marketing (Identity Guard Commercials)</p>
<p style="clear: both"> </p>
<p style="clear: both"><strong><span style="text-decoration: underline;">Consultants Corner -</span></strong> Predicting what Security Consulting will be like in the future – <a href="http://ha.ckers.org/blog/20090918/what-star-trek-predicts-about-the-future-of-information-security/">Link Here</a><span style="text-decoration: underline;"><br />
</span></p>
<p style="clear: both"><strong><span style="text-decoration: underline;">Music notes – </span></strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=4a9250fbcd40a316a120f27af824054f">SwampdaWamp – “Lady”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=a84d881ac3a1f7dddc55cddfd9719126">Building Rome – “Dr. Doctor”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=5d22a6793650e9303f9b611f67e7d294">The Summer Set – “Chelsea”</a><span style="text-decoration: underline;"><br />
</span></li>
</ul>
<p> Vet</p></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=-wBH4fdx8B4:SuPhrK6VhVU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=-wBH4fdx8B4:SuPhrK6VhVU:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=-wBH4fdx8B4:SuPhrK6VhVU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3" length="60579968" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode26.mp3" fileSize="60579968" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> � Link to MP3 Episode 26 is here.  It almost didn&amp;#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy! Show Notes: InfoSec News Update – Michael’</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> � Link to MP3 Episode 26 is here.  It almost didn&amp;#8217;t happen since I was playing remote helpdesk dude for a relative from my hotel room in Dallas right before the recording, but we got it worked out.  Enjoy! Show Notes: InfoSec News Update – Michael’s New NAISG Group are having their first meeting on Nov 2, 2009 in [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/10/01/an-information-security-place-podcast-episode-26/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 25</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/CsCA1FTSkfQ/</link>
		<comments>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 02:00:01 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[GhostExodus]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Wesley McGrew]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1107</guid>
		<description><![CDATA[
Link to MP3
Episode 25 is here.  Today&#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3">Link to MP3</a></p>
<p>Episode 25 is here.  Today&#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He also operates <a href="http://mcgrewsecurity.com/">mcgrewsecurity.com</a> , where he blogs about information security topics.</p>
<p>Wesley caught a script-kiddie back in June trying to do some pretty weak SCADA hacking at a Dallas-area hospital.  He and I talked about the incident and also discussed some of Wesley&#8217;s future plan (not much since he couldn&#8217;t divulge a lot &#8211; oooo, mysterious!).  So enjoy the show.  Links to the blog posts from Wesley&#8217;s script kiddie adventure are below.</p>
<p><a href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/">http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/">http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/">http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/</a></p>
<p><a href="http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/">http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/</a></p>
<p>Vet</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=CsCA1FTSkfQ:_tVu0pB1_oA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=CsCA1FTSkfQ:_tVu0pB1_oA:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=CsCA1FTSkfQ:_tVu0pB1_oA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3" length="50219912" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode25.mp3" fileSize="50219912" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Episode 25 is here.  Today&amp;#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Episode 25 is here.  Today&amp;#8217;s podcast is different than our usual.  Instead of having Jim, Dan, and me spout off and pontificate, I am interviewing Wesley McGrew from McGrew Security.  Wesley is a security researcher at Mississippi State University&amp;#8217;s Critical Infrastructure Protection Center, where he works to find vulnerabilities in SCADA software.  He [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/09/15/an-information-security-place-podcast-episode-25/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 24</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/6m1KWVIIxVc/</link>
		<comments>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 14:09:49 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Card skimming]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Credit Unions]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ipod Touch]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Sears]]></category>
		<category><![CDATA[SkyJack]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[TKIP broken]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web app firewalls]]></category>
		<category><![CDATA[Web app scanners]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WLAN]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1102</guid>
		<description><![CDATA[
Link to MP3

Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver!
Show Notes:
InfoSec News Update – 

Credit Unions Under Attack – Link 1 / Link 2
Massive SQL Injection Attacks – Link 1 / Link2
Cisco [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3">Link to MP3</a></p>
<div class="post_content">
<p style="clear: both">Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver!</p>
<p style="clear: both">Show Notes:</p>
<p style="clear: both"><strong>InfoSec News Update – </strong></p>
<ul style="clear: both">
<li>Credit Unions Under Attack – <strong></strong><a href="http://threatpost.com/blogs/attackers-sending-malware-infected-cds-credit-unions-127 ">Link 1</a> / <a href="http://www.ncua.gov/news/press_releases/2009/MR09-0825a.htm">Link 2</a></li>
<li>Massive SQL Injection Attacks – <a href="http://www.scmagazineus.com/Mass-SQL-injection-attacks-still-scaling-up/article/147490/">Link 1</a> / <a href="http://www.securityfocus.com/brief/1001?ref=rss">Link2</a></li>
<li>Cisco Wireless LANS get “Skyjacked” – <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=219401274">Link 1</a> / <a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=18919">Link 2</a></li>
<li>Flaw in Sear’s Website Left Database Open To Attack – <a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=219500830&amp;cid=nl_DR_DAILY_T">Link Here</a></li>
<li>WPA/TKIP Can be Broken in 1 Minute – <a href="http://jwis2009.nsysu.edu.tw/location/paper/A%20Practical%20Message%20Falsification%20Attack%20on%20WPA.pdf">Link 1</a> / <a href="http://seclists.org/dailydave/2009/q3/0091.html">Link 2</a></li>
<li>100 Dirtiest Web Sites of Summer 2009 – <a href="http://www.mightyseek.com/web-application-security/dirtiest-web-sites-of-summer-2009">Link Here</a></li>
<li>No Thumbprint, No Check-Cashing, Bank Told Armless Man – <a href="http://www.foxnews.com/story/0,2933,545560,00.html">Link Here</a></li>
<li>PCI Council Releases recommendation for Preventing Card Skimming – <a href="http://www.darkreading.com/security/government/showArticle.jhtml;jsessionid=MR0HE1VGH0KNXQE1GHRSKHWATMY32JVN?articleID=219401468">Link 1</a> / <a href="https://www.pcisecuritystandards.org/education/info_sup.shtml">Link 2</a></li>
<li>Federal Certification Program for “Cyber Professionals” / Bill would give President emergency control of the Internet – <a href="http://news.cnet.com/8301-13578_3-10320096-38.html">Link Here</a></li>
</ul>
<p style="clear: both"><strong>Discussion Topic -</strong> Web App Scanners And Web App Firewalls According to Gartner</p>
<p>- <a href="http://blogs.gartner.com/neil_macdonald/2009/08/25/are-web-application-security-testing-tools-a-waste-of-time-and-money/">Link 1</a> / <a href="http://blogs.gartner.com/neil_macdonald/2009/08/19/security-no-brainer-9-application-vulnerability-scanners-should-communicate-with-application-firewalls/">Link 2</a></p>
<p><strong>Consultant’s Corner – </strong>Updating Tools and Techniques</p>
<p style="clear: both"><strong>Music Notes:</strong></p>
<ul style="clear: both">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=855fce1cfc0ead0f552963ba3bff22a5">Dave Stanley Band – “Lights Out”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1f9df891c1c8f91eaf5023d111ac0975">No Mans Hero -”Now That Its Over”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d87754a0ef419277dbdf2bbb6b2e284d">ByTheWayside- “DoYouEverNotice”</a></li>
</ul>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=6m1KWVIIxVc:RAKFb3PWry0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=6m1KWVIIxVc:RAKFb3PWry0:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=6m1KWVIIxVc:RAKFb3PWry0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3" length="90349696" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode24.mp3" fileSize="90349696" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver! Show Notes: InfoSec News Update – Credit Unions Under Attack – Link 1 / Link 2 M</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Hello all you happy people!  Episode 24 is here.  I was out sick, so Jim and Dan put it together. Jim is adamant about sticking to a schedule. Dang slave driver! Show Notes: InfoSec News Update – Credit Unions Under Attack – Link 1 / Link 2 Massive SQL Injection Attacks – Link 1 / Link2 Cisco [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/09/03/an-information-security-place-podcast-episode-24/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 23</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/ZIW2Ilc-TTU/</link>
		<comments>http://infosecplace.com/blog/2009/08/20/an-information-security-place-podcast-episode-23/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 15:31:00 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Geforce GTX 295s]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Hannaford]]></category>
		<category><![CDATA[Heartland]]></category>
		<category><![CDATA[mega breaches]]></category>
		<category><![CDATA[National Retail Federation]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SheevaPlug PC]]></category>
		<category><![CDATA[UK ID card Hacked]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1097</guid>
		<description><![CDATA[
Link to MP3
We&#8217;re back with episode 23.  Jim is back (you can decide if that is good news or bad news), and Dan Kuykendall is joining us again (calls himself the guest that won&#8217;t leave the couch).  Thanks for listening&#8230;
Show notes:
InfoSec News Update -

Big Thank You to all our Clients and the folks that stopped [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode23.mp3">Link to MP3</a></p>
<p>We&#8217;re back with episode 23.  Jim is back (you can decide if that is good news or bad news), and Dan Kuykendall is joining us again (calls himself the guest that won&#8217;t leave the couch).  Thanks for listening&#8230;</p>
<p>Show notes:</p>
<p><strong>InfoSec News Update -</strong></p>
<ul>
<li>Big Thank You to all our Clients and the folks that stopped by thebBooth and our party at BlackHat!</li>
<li>UK ID card Hacked/Cloned in 12 Minutes – <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=32633">Link Here</a></li>
<li>“Mega breaches” use preventable attacks – <a href="http://darkreading.com/database_security/security/attacks/showArticle.jhtml%3Bjsessionid%3D4TMOSGG3V3WI3QE1GHPCKH4ATMY32JVN?articleID=219400495">Link Here</a></li>
<li>Hackers target outsourced app development – <a href="http://securityreason.com/it_news/1/0x10b">Link Here</a></li>
<li>National Retail Federation still struggling with PCI – <a href="http://www.darkreading.com/database_security/security/government/showArticle.jhtml?articleID=219200246">Link Here</a></li>
<li>Reset Password problems, and reusing passwords in general:
<ul>
<li>Wordpress Password hack – <a href="http://seclists.org/fulldisclosure/2009/Aug/0113.html also on http://www.securitypronews.com/insiderreports/insider/spn-49-20090812WordPressPasswordProblemCropsUp.html">Link Here</a> / <a href="http://www.cgisecurity.com/2009/08/wordpress-admin-password-reset-vulnerability.html">Link2</a></li>
<li>The Twitter hack – <a href="http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/">Link Here</a></li>
</ul>
</li>
<li>“FILE UNDER DUH” – Study warns of cyberwarfare during military conflicts – <a href="Study warns of cyberwarfare during military conflicts - http://edition.cnn.com/2009/US/08/17/cyber.warfare/">Link Here</a></li>
</ul>
<p><strong>Discusstion Topic -</strong> Web Security On Cell Phones – <a href="http://www.mightyseek.com/web-application-security/web-security-on-cell-phones">Link Here</a></p>
<p><strong>Geek Toyz – </strong></p>
<ul>
<li><a href="http://www.marvell.com/products/embedded_processors/developer/kirkwood/sheevaplug.jsp">SheevaPlug PC</a></li>
<li>Dual <a href=" http://www.nvidia.com/object/product_geforce_gtx_295_us.html">Geforce GTX 295s</a> for the Win!!
<ul>
<li>GPU Acceleration for Cracking Galore -
<ul>
<li><a href="http://project-rainbowcrack.com/ ">Rainbowcrack</a></li>
<li><a href="http://code.google.com/p/pyrit/">Pyrit</a></li>
<li><a href="http://www.cryptohaze.com/bruteforcers.php">CUDA MultiForcer</a></li>
<li><a href="http://www.elcomsoft.com/">ElcomSoft</a></li>
</ul>
</li>
</ul>
</li>
<li><a href="http://www.t-mobile.com/shop/phones/Cell-Phone-Detail.aspx?cell-phone=MyTouch-3G-Black">G2 / MyTouch Review from Dan</a></li>
<li>Hitting up your local Surplus Dealer</li>
<li>How To Quite down high end gear – <a href="http://www.newegg.com/Product/Product.aspx?Item=N82E16811999704">PCI slot fan</a> / <a href=" http://www.newegg.com/Product/Product.aspx?Item=N82E16835104004">4MM Fans</a></li>
<li><a href="http://www.cnn.cn/shop/">Good Source for parts and tools</a></li>
</ul>
<p><strong>Music Notes:</strong></p>
<ul class="noindent">
<li>Intro/Outro – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – “Therapy”</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=1089a8c084a1d803912e89f8b9cc6051">Megaphone – “Write it Down”</a></li>
<li>Segway 2 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=9f82d2117026d7ba7595c8161d91ec17">Patent Pending – “Los Angeles”</a></li>
<li>Segway 3 – <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=e418a4c6cb933be8c7abc95c51dec765">Devo Spice – “Platform Wars”</a></li>
</ul>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=ZIW2Ilc-TTU:SQbMaM4EzJo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=ZIW2Ilc-TTU:SQbMaM4EzJo:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=ZIW2Ilc-TTU:SQbMaM4EzJo:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/08/20/an-information-security-place-podcast-episode-23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode23.mp3" length="80464000" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode23.mp3" fileSize="80464000" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 We&amp;#8217;re back with episode 23.  Jim is back (you can decide if that is good news or bad news), and Dan Kuykendall is joining us again (calls himself the guest that won&amp;#8217;t leave the couch).  Thanks for listening&amp;#8230; Show notes: Info</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 We&amp;#8217;re back with episode 23.  Jim is back (you can decide if that is good news or bad news), and Dan Kuykendall is joining us again (calls himself the guest that won&amp;#8217;t leave the couch).  Thanks for listening&amp;#8230; Show notes: InfoSec News Update - Big Thank You to all our Clients and the folks that stopped [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/08/20/an-information-security-place-podcast-episode-23/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 22</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/Wa7dLHpnIZU/</link>
		<comments>http://infosecplace.com/blog/2009/08/08/an-information-security-place-podcast-episode-22/#comments</comments>
		<pubDate>Sat, 08 Aug 2009 21:33:03 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Czar]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[Goon]]></category>
		<category><![CDATA[guidelines]]></category>
		<category><![CDATA[Hathaway]]></category>
		<category><![CDATA[Joshua "Jabra" Abraham]]></category>
		<category><![CDATA[Marlinspike]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Priest]]></category>
		<category><![CDATA[quits]]></category>
		<category><![CDATA[Robert "RSnake" Hansen]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[vulnerable]]></category>
		<category><![CDATA[web server]]></category>
		<category><![CDATA[webcams]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1088</guid>
		<description><![CDATA[
Link to MP3
Episode 22 is here.  Jim was not available to join me this time (been traveling and real busy), so Dan Kuykendall from NT Objectives was kind enough to fill in as co-host for today.  We had some good discussion, and a show that I thought would be a little shorter ended [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode22.mp3">Link to MP3</a></p>
<p>Episode 22 is here.  Jim was not available to join me this time (been traveling and real busy), so Dan Kuykendall from NT Objectives was kind enough to fill in as co-host for today.  We had some good discussion, and a show that I thought would be a little shorter ended up being pretty long.  But it is good stuff.  Here are the show notes:</p>
<p><strong>InfoSec News Update -</strong></p>
<ul>
<li>Vulnerable web servers on webcams, NAS, etc – <a href="http://www.theregister.co.uk/2009/07/16/buggy_web_interface_peril/">Link Here</a></li>
<li>Obama&#8217;s cybersecurity Czar quits &#8211; <a href="http://online.wsj.com/article/SB124932480886002237.html">Link Here</a></li>
</ul>
<blockquote><p>People familiar with the matter said Ms. Hathaway has been &#8220;spinning her wheels&#8221; in the White House, where the president&#8217;s economic advisers sought to marginalize her</p>
<p>politically.</p>
<p>In February, the White House tapped Ms. Hathaway, a senior intelligence official who had launched President George W. Bush&#8217;s cybersecurity initiative, to lead a 60-day</p>
<p>cybersecurity policy review. Ms. Hathaway completed her review in April, but the White House spent another 60 days debating the wording of her report and how to structure the</p>
<p>White House cyber post. National Economic Adviser Larry Summers argued forcefully that his team should have a say in the work of the new cyber official.</p></blockquote>
<ul>
<li>SSL Under attack this year at BlackHat/Defcon. These attacks don&#8217;t attack the math, they attack the (mis)usage of the clients and cert authorities</li>
</ul>
<p>New Tricks For Defeating SSL In Practice (sslstrip) -<a href="http://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf" target="_blank">Link Here</a></p>
<p>Researcher Exposes Flaws In Certificate Authority Web Applications &#8211; <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=218900378" target="_blank">Link Here</a></p>
<ul>
<li>Defcon goon &#8220;Priest&#8221; is everywhere &#8211; Links <a href="http://www.computerworld.com/s/article/9136182/Korean_journalists_booted_from_Defcon?taxonomyId=17">Here</a> and <a href="http://www.computerworld.com/s/article/9136179/Fake_ATM_doesn_t_last_long_at_hacker_meet">Here</a></li>
</ul>
<p><strong>Discussion Topic -</strong> The ol&#8217; security guidelines / best practices discussion</p>
<p><strong>Consultants Corner &#8211; </strong>Varied BlackHat / Defcon points -</p>
<ul>
<li>SSL issues</li>
<li>Unmasking You talk by Joshua &#8220;Jabra&#8221; Abraham and Robert &#8220;RSnake&#8221; Hansen</li>
<li>Dan&#8217;s general Opinions about web security talks &#8211; he was underwhelmed</li>
</ul>
<p><strong>Music Notes:</strong></p>
<ul class="noindent">
<li>Intro/Outro – <a href="http://music.mevio.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks – &#8220;Therapy&#8221;</a></li>
<li>Segway 1 – <a href="http://www.musicalley.com/music/producers/producerLibrary/artistdetails.php?BandHash=d0d4478a203c3adf0cd6be6256ca1f90">AllofaSudden &#8211; &#8220;disAppear&#8221;</a></li>
<li>Segway 2 &#8211; <a href="http://www.musicalley.com/music/producers/producerLibrary/artistdetails.php?BandHash=5a9814ca558b170779bf1224a5cc1d4c">Battery Life &#8211; &#8220;Double Wide&#8221;</a></li>
<li>Segway 3 &#8211; <a href="http://www.musicalley.com/music/listeners/artistdetails.php?BandHash=383e382f200a7113d4be436672b20ec7">Rocket Propelled Geeks &#8211; &#8220;Sarlac&#8221;</a></li>
</ul>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Wa7dLHpnIZU:coB9slDgCQQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Wa7dLHpnIZU:coB9slDgCQQ:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Wa7dLHpnIZU:coB9slDgCQQ:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/08/08/an-information-security-place-podcast-episode-22/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode22.mp3" length="101947124" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode22.mp3" fileSize="101947124" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Episode 22 is here. Jim was not available to join me this time (been traveling and real busy), so Dan Kuykendall from NT Objectives was kind enough to fill in as co-host for today. We had some good discussion, and a show that I thought would </itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Episode 22 is here. Jim was not available to join me this time (been traveling and real busy), so Dan Kuykendall from NT Objectives was kind enough to fill in as co-host for today. We had some good discussion, and a show that I thought would be a little shorter ended [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/08/08/an-information-security-place-podcast-episode-22/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 21</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/R0TR_87Ywbg/</link>
		<comments>http://infosecplace.com/blog/2009/07/09/an-information-security-place-podcast-episode-21/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 11:50:12 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[algorithm]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[auditor]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Cyberattacks]]></category>
		<category><![CDATA[Exobox]]></category>
		<category><![CDATA[Federal Government]]></category>
		<category><![CDATA[Goldman Sachs]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[MI6]]></category>
		<category><![CDATA[month]]></category>
		<category><![CDATA[North Korea]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Shackleford]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[Social security numbers]]></category>
		<category><![CDATA[South Korea]]></category>
		<category><![CDATA[speedos]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[US Government]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1078</guid>
		<description><![CDATA[
Link to MP3
Episode 21 is up and going.  Looks like Jim and I are back on a regular cycle again.  Hopefully it stays that way!  Here are the show notes:
InfoSec News Update - 

Goldman Sachs looses its secret sauce online &#8211; Link Here
Fed gets and F on Physical Security &#8211; Link Here
North [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode21.mp3">Link to MP3</a></p>
<p>Episode 21 is up and going.  Looks like Jim and I are back on a regular cycle again.  Hopefully it stays that way!  Here are the show notes:</p>
<p><strong>InfoSec News Update -</strong> </p>
<ul>
<li>Goldman Sachs looses its secret sauce online &#8211; <a href="http://www.bloomberg.com/apps/news?pid=20601087&#038;sid=ajIMch.ErnD4">Link Here</a></li>
<li>Fed gets and F on Physical Security &#8211; <a href="http://www.cnn.com/2009/POLITICS/07/07/federal.buildings.security/index.html">Link Here</a></li>
<li>North Korea Blamed in Cyber Attacks over July 4th &#8211; <a href="http://www.telegraph.co.uk/news/worldnews/asia/southkorea/5778176/North-Korea-blamed-for-cyber-attack-on-South-Korea.html">Link Here</a></li>
<li>Juniper Pulls ATM hacking preso from BH &#8211; <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1360597,00.html?track=sy160">Link Here</a></li>
<li>Month of Twitter Bugs &#8211; <a href="http://darkreading.com/security/app-security/showArticle.jhtml?articleID=218400029">Link Here</a></li>
<li>10 Things Your Auditor Isn&#8217;t Telling Your &#8211; <a href=" http://daveshackleford.com/?p=211">Link Here</a></li>
<li>New head of MI6 wears Speedos on Facebook &#8211; <a href="http://www.guardian.co.uk/politics/2009/jul/05/mi6-facebook-sawers-wife-miliband">Link Here</a></li>
<li>Algorithm for Predicting and guessing SSNs &#8211; <a href="http://arstechnica.com/tech-policy/news/2009/07/social-insecurity-numbers-open-to-hacking.ars">Link Here</a></li>
<li>Iphone SMS Vulnerability &#8211; <a href="http://www.scmagazineus.com/iPhone-hacker-reveals-SMS-vulnerabity/article/139479">Link Here</a></li>
<li>Study &#8211; Oracle Users struggle with patch management &#8211; <a href="http://ioug.itconvergence.com/pls/apex/f?p=201:1:136152952018385">Link Here</a></li>
</ul>
<p><strong>Discussion Topic -</strong> Cloud Computing &#8211; is it a security nightmare waiting to happen? &#8211; <a href="http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=218102139">Link Here</a></p>
<p><strong>Consultants Corner -</strong> Developing an offering before going public!</p>
<p><strong>Music Notes:</strong></p>
<ul class="noindent">
<li>Intro/Outro &#8211; <a href="http://music.mevio.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks &#8211; &quot;Therapy&quot;</a></li>
<li>Segway 1 &#8211; <a href="http://music.mevio.com/music/listeners/artistdetails.php?BandHash=2606003972e352ea2a35e3b97d3a7a5d">Eric Kauschen &#8211; &quot;Speed of Light&quot;</a></li>
<li>Segway 2 &#8211; <a href="http://music.mevio.com/music/listeners/artistdetails.php?BandHash=25860ca362c17aeb878b31194877590e">The WaterMarks &#8211; &quot;Shut Down&quot;</a></li>
<li>Segway 3 &#8211; <a href="http://music.mevio.com/music/listeners/artistdetails.php?BandHash=1089a8c084a1d803912e89f8b9cc6051">Megaphone &#8211; &quot;Not your enemy&quot;</a></li>
</ul>
<p>Vet</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=R0TR_87Ywbg:UzmI7MO9Tuo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=R0TR_87Ywbg:UzmI7MO9Tuo:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=R0TR_87Ywbg:UzmI7MO9Tuo:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/07/09/an-information-security-place-podcast-episode-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode21.mp3" length="73382016" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode21.mp3" fileSize="73382016" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 Episode 21 is up and going. Looks like Jim and I are back on a regular cycle again. Hopefully it stays that way! Here are the show notes: InfoSec News Update - Goldman Sachs looses its secret sauce online &amp;#8211; Link Here Fed gets and F on P</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 Episode 21 is up and going. Looks like Jim and I are back on a regular cycle again. Hopefully it stays that way! Here are the show notes: InfoSec News Update - Goldman Sachs looses its secret sauce online &amp;#8211; Link Here Fed gets and F on Physical Security &amp;#8211; Link Here North [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/07/09/an-information-security-place-podcast-episode-21/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 20</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/p9EWGUl76NY/</link>
		<comments>http://infosecplace.com/blog/2009/06/19/an-information-security-place-podcast-episode-20/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 13:28:31 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[assessor]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[auditor sued]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[Eastern Europe]]></category>
		<category><![CDATA[Exobox]]></category>
		<category><![CDATA[IOSCAT]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Keykeriki]]></category>
		<category><![CDATA[L0phtCrack]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[T-Mobile]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1076</guid>
		<description><![CDATA[
Link to MP3
The long-awaited episode 20 is finally here.  Sorry for the crazy long wait!
InfoSec News Update &#8211; 

Data Breach Suit Targets Auditor &#8211; Link Here
Exobox data leak detection coming out &#8211; Link Here
&#34;CloudBurst&#34; allows attackers to break VM guest OS and attack Host &#8211; Link Here
Obama creates the office of Cyber Czar &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode20.mp3">Link to MP3</a></p>
<p>The long-awaited episode 20 is finally here.  Sorry for the crazy long wait!</p>
<p><strong>InfoSec News Update &#8211; </strong></p>
<ul>
<li>Data Breach Suit Targets Auditor &#8211; <a href="http://www.wired.com/threatlev%E2%80%8Bel/2009/06%E2%80%8B/auditor_s%E2%80%8Bued/">Link Here</a></li>
<li>Exobox data leak detection coming out &#8211; <a href="http://www.exobox.com/">Link Here</a></li>
<li>&quot;CloudBurst&quot; allows attackers to break VM guest OS and attack Host &#8211; <a href="http://www.darkreading.com/sec%E2%80%8Burityservi%E2%80%8Bces/securi%E2%80%8Bty/app-sec%E2%80%8Burity/show%E2%80%8BArticle.jh%E2%80%8Btml;jsessi%E2%80%8Bonid=31JOR%E2%80%8B5ROZ5HLOQS%E2%80%8BNDLOSKH0CJ%E2%80%8BUNN2JVN?ar%E2%80%8BticleID=21%E2%80%8B7701908">Link Here</a></li>
<li>Obama creates the office of Cyber Czar &#8211; <a href="http://www.whitehouse.gov/the_%E2%80%8Bpress_offi%E2%80%8Bce/Remarks%E2%80%8B-by-the-Pr%E2%80%8Besident-on%E2%80%8B-Securing-%E2%80%8BOur-Nation%E2%80%8Bs-Cyber-In%E2%80%8Bfrastructu%E2%80%8Bre/">Link Here</a></li>
<li>Twitter and Iran &#8211; <a href="http://www.foxnews.com/story/0%E2%80%8B,2933,5270%E2%80%8B68,00.html">Link Here</a></li>
<li>IOSCAT talk from SANS &#8211; <a href="www.sans.org/reading_room/whitepapers/tools/rss/ioscat_a_port_of_netcats_tcp_functions_to_cisco_ios_33109">Link Here</a></li>
<li>Tmobile Breached&#8230;.Maybe? &#8211; <a href="http://seclists.org/fulldisclosure/2009/Jun/0062.html#start">Link 1</a> / <a href="http://www.pcworld.com/businesscenter/article/166384/is_the_tmobile_breach_the_beginning_of_the_end.html">Link 2</a></li>
<li>Wireless Keyboard sniffing just got alot easier &#8211; <a href="http://www.remote-exploit.org/Keykeriki.html">Link Here</a></li>
<li>LC6 is Officially Released &#8211; <a href="http://www.l0phtcrack.com/index.html">Link Here</a></li>
<li>Trojan Attack on ATMs &#8211; <a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml;jsessionid=31JOR5ROZ5HLOQSNDLOSKH0CJUNN2JVN?articleID=217701880<br />
">Link Here</a></li>
<li>Patch Your Blackberry Servers &#8211; <a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&#038;docType=kc&#038;externalId=KB18327">Link Here</a></li>
</ul>
<p><strong>Discussion Topic</strong> -Whats the difference between an Auditor and a Assessor?</p>
<p><strong>Consultant&#8217;s Corner </strong>- To Scope or Not to Scope</p>
<p><strong>Music Notes:</strong></p>
<ul class="noindent">
<li>Intro/Outro &#8211; <a href=" http://music.podshow.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks &#8211; &quot;Therapy&quot;</a></li>
<li>Segway 1 &#8211; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=1e3f680c4828ffbca012129500fbc834">PawnShop Diamonds &#8211; &quot;High Road Low Down&quot;</a></li>
<li>Segway 2 &#8211; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=3b103156bd6087d2fee6a2e281167011">Woodfish &#8211; &quot;Melody&quot;</a></li>
<li>Segway 3 &#8211; <a href='"Shut Down" - http://music.podshow.com/music/listeners/artistdetails.php?BandHash=25860ca362c17aeb878b31194877590e'>The WaterMarks &#8211; &quot;Shut Down&quot;</a></li>
</ul>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=p9EWGUl76NY:nCM4RSSpAz8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=p9EWGUl76NY:nCM4RSSpAz8:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=p9EWGUl76NY:nCM4RSSpAz8:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/06/19/an-information-security-place-podcast-episode-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode20.mp3" length="46254208" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode20.mp3" fileSize="46254208" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 The long-awaited episode 20 is finally here. Sorry for the crazy long wait! InfoSec News Update &amp;#8211; Data Breach Suit Targets Auditor &amp;#8211; Link Here Exobox data leak detection coming out &amp;#8211; Link Here &amp;#34;CloudBurst&amp;#34; allows att</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 The long-awaited episode 20 is finally here. Sorry for the crazy long wait! InfoSec News Update &amp;#8211; Data Breach Suit Targets Auditor &amp;#8211; Link Here Exobox data leak detection coming out &amp;#8211; Link Here &amp;#34;CloudBurst&amp;#34; allows attackers to break VM guest OS and attack Host &amp;#8211; Link Here Obama creates the office of Cyber Czar &amp;#8211; [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/06/19/an-information-security-place-podcast-episode-20/</feedburner:origLink></item>
		<item>
		<title>An Information Security Place Podcast – Episode 19</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/Tl53azsrYmU/</link>
		<comments>http://infosecplace.com/blog/2009/05/18/an-information-security-place-podcast-episode-19/#comments</comments>
		<pubDate>Mon, 18 May 2009 13:14:44 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[Acer]]></category>
		<category><![CDATA[acrobat]]></category>
		<category><![CDATA[admin account]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[federal regulations]]></category>
		<category><![CDATA[firewall swapping]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[power]]></category>
		<category><![CDATA[prescription]]></category>
		<category><![CDATA[QNAP TS-809]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerabilities. Virginia]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/?p=1071</guid>
		<description><![CDATA[
Link to MP3
So, we officially have our first lost episode.  I recorded episode 18 a while back with Michael Santarcangelo, but we had some crazy technical problems.  When I tried to get everything edited together to make it work, I started having some major problems.  Without getting into all the details, the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg"><img class="alignnone size-medium wp-image-21" title="head" src="http://infosecplacepodcast.com/wp-content/uploads/2008/09/head.jpg" alt="" width="159" height="131" /></a></p>

<p><a href="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode19.mp3">Link to MP3</a></p>
<p>So, we officially have our first lost episode.  I recorded episode 18 a while back with Michael Santarcangelo, but we had some crazy technical problems.  When I tried to get everything edited together to make it work, I started having some major problems.  Without getting into all the details, the recording was not salvageable.  Sorry to Michael for this since I know he took his valuable time to record with me.</p>
<p>So know we have episode 19.  I guess we could have just said this one was episode 18 and went on, but we are honest people over here at An Information Security Place Podcast.  And as far as episode 19 goes, Jim and I have been balls-to-the-wall busy lately, and I have had a crazy schedule for over a month.  Jim got a break in his schedule (probably more like forced a break) and coerced Kirk Greene to help him out in my place.  And then Jim had some technical problems as well and ended up recording the last 15 minutes by himself (or Kirk pissed him off &#8211; not sure which).  Yes, it has been a crazy time for us.  But we are back, and hopefully we will get back on a regular schedule.</p>
<p>Now, here are the show notes for episode 19:</p>
<p><strong>InfoSec News Update &#8211; </strong></p>
<ul>
<li>Warm Fuzzy Story &#8211; Many Users say they’d sell company info for the right price! &#8211; <a href="http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml;jsessionid=DSDDEK13Y1QTSQSNDLOSKHSCJUNN2JVN?articleID=217100330">Link Here</a></li>
<li>Another Twitter Admin Account Compromised &#8211; <a href="http://www.sophos.com/blogs/gc/g/2009/05/01/twitter-security-breach-exposes-accounts-hackers/">Link Here</a></li>
<li>New Tools Emerge To Ease Enterprise Fear Of Firewall Swapping &#8211; <a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=217201016">Link Here</a></li>
<li>Acrobat with Yet Another 0-day &#8211; <a href="http://blogs.adobe.com/psirt/">Link Here</a></li>
<li>Feb Bank Worker charged with Data Theft &#8211; <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml;jsessionid=DSDDEK13Y1QTSQSNDLOSKHSCJUNN2JVN?articleID=217200487">Link Here</a></li>
<li>More Federal Reg ‘a’ Coming for Power companies &#8211; <a href="http://www.eweek.com/c/a/Security/Lawmakers-Move-to-Secure-Electric-Grid-281213/">Link Here</a></li>
<li>Thats gonna leave a mark! &#8211; Multiple Vulns found on Mcaffee’s website &#8211; <a href="http://nemesis.te-home.net/News/20090501_Multiple_Bugs_on_Mcafee_Websites_.html">Link Here</a></li>
<li>Hacker’s demand: $10M for Virginia prescriptions database &#8211; <a href="http://hamptonroads.com/2009/05/hackers-demand-10m-virginia-prescriptions-database">Link Here</a></li>
<li>Economy Note &#8211; Security Suffers Cuts but fares better than most &#8211; <a href=" http://www.virtualpressoffice.com/detail.do?contentId=100815&amp;showId=1215381716906">Link Here</a></li>
</ul>
<p><strong>Geek Toys -</strong></p>
<ul>
<li>Interceptor &#8211; <a href="http://www.hak5.org/episodes/episode-505">Hak5 Episode</a> &#8211; <a href="http://www.digininja.org/interceptor/ ">DigiNinja’s Page</a></li>
<li><a href="http://www.acer.com/aspireone">Acer Aspire One 10.1 Netbook</a></li>
<li>Wifi Card of Choice &#8211; <a href=" http://www.data-alliance.net/servlet/the-90/802.11g-USB-802.11b-802.11n/Detail">Alfa Network AWUS036H</a></li>
<li>Need a second NIC on a laptop? &#8211; <a href="store.apple.com/us/product/MB442Z/ ">Apple USB Ethernet is rather inexpensive and works with Windows / Linux / and OSX (duh).</a> / <a href="http://dl.getdropbox.com/u/23528/Software/Apple%20USB%20Ethernet%20Adapter%20Drivers.zip">Windows Driver</a></li>
<li>NAS From Heaven &#8211; <a href="http://www.qnap.com/pro_detail_feature.asp?p_id=109">QNAP TS-809</a></li>
</ul>
<p><strong>Consultants Corner -</strong> DIY Security Testing Lab</p>
<p><strong>Music Notes:</strong></p>
<ul class="noindent">
<li>Intro/Outro &#8211; <a href=" http://music.podshow.com/music/listeners/artistdetails.php?BandHash=d65dc8af297fd7a4cc57554b2a826a8e">Digital Breaks &#8211; &#8220;Therapy&#8221;</a></li>
<li>Segway 1 &#8211; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=855fce1cfc0ead0f552963ba3bff22a5 ">Dave Stanley Band &#8211; &#8220;Lights Out&#8221; </a></li>
<li>Segway 2 &#8211; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=5848a0485a0f4eff28c22288a2396a57">John Taglieri &#8211; &#8221; Make A Mistake With Me&#8221;</a></li>
<li>Segway 3 &#8211; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=605ec36a6b5e1c91d4ce9e349ca4c444">Junior &#8211; &#8220;What Was I Thinking?&#8221;</a></li>
</ul>
<p>Vet</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Tl53azsrYmU:HGvoFfZF4ow:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=Tl53azsrYmU:HGvoFfZF4ow:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=Tl53azsrYmU:HGvoFfZF4ow:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/05/18/an-information-security-place-podcast-episode-19/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode19.mp3" length="42784896" type="audio/mpeg" />
		<media:content url="http://www.infosecplace.com/blog/Podcasts/AnInformationSecurityPlacePodcast-Episode19.mp3" fileSize="42784896" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Link to MP3 So, we officially have our first lost episode. I recorded episode 18 a while back with Michael Santarcangelo, but we had some crazy technical problems. When I tried to get everything edited together to make it work, I started having some majo</itunes:subtitle><itunes:author>Michael R. Farnum</itunes:author><itunes:summary> Link to MP3 So, we officially have our first lost episode. I recorded episode 18 a while back with Michael Santarcangelo, but we had some crazy technical problems. When I tried to get everything edited together to make it work, I started having some major problems. Without getting into all the details, the [...]</itunes:summary><itunes:keywords>security,Michael,R,Farnum,podcast,blog,information,security,infosec</itunes:keywords><feedburner:origLink>http://infosecplace.com/blog/2009/05/18/an-information-security-place-podcast-episode-19/</feedburner:origLink></item>
		<item>
		<title>Some advice when writing security assessment RFP’s</title>
		<link>http://feedproxy.google.com/~r/AnInformationSecurityPlace/~3/a2x3Wxw6Gks/</link>
		<comments>http://infosecplace.com/blog/2009/05/15/some-advice-when-writing-security-assessment-rfps/#comments</comments>
		<pubDate>Sat, 16 May 2009 01:57:06 +0000</pubDate>
		<dc:creator>m1a1vet@infosecplace.com (Michael R. Farnum)</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/2009/05/15/some-advice-when-writing-security-assessment-rfps/</guid>
		<description><![CDATA[I have been answering quite a few security assessment RFP’s lately, most specifically geared towards penetration testing of the external and internal environment (you guessed it – PCI).&#160; And what I have noticed is that the writers of the RFP typically do not include enough detail in the RFP for the organizations attempting to answer [...]]]></description>
			<content:encoded><![CDATA[<p>I have been answering quite a few security assessment RFP’s lately, most specifically geared towards penetration testing of the external and internal environment (you guessed it – PCI).&#160; And what I have noticed is that the writers of the RFP typically do not include enough detail in the RFP for the organizations attempting to answer to give a solid response.&#160; Basically, if you need a good answer to your RFP, you have to give me enough to scope the amount of time it is going to take me to get it done.&#160; </p>
<ol>
<li>If you have 200 external IPs and you want to have those scanned for vulnerabilities, and then you want to have those vulnerabilities used for penetration testing, I have to know that in order to scope. </li>
<li>If you have some applications on those servers, I need to know if I will have credentials or if this is going to be totally black-box testing.&#160; I also need to have SOME idea of how many apps I am going to run up against. </li>
<li>If you want me to scan your internal network for vulnerabilities, I have to know how many machines I am going to be scanning. </li>
<li>Etc, etc, etc </li>
</ol>
<p>If you would provide this quantity type of information up front, I would not have to write up a bunch of questions and send them to you.&#160; You would not have to take the time to answer these questions (and probably send them to me 2 days before the responses are due).&#160; It really is simple: if I don’t have this information, I have to guess, and you are going to get an inaccurate response (of course, you might be looking for a completely black-box test where I am blind to any information – the effectiveness and efficiency of that is for another blog post on another day).</p>
<p>Of course, many people will tell you that RFP’s are often written in such a way to discourage responses because the company writing the RFP already has a partner in mind, and that partner probably already has the answers to any questions.&#160; The RFP writer is simply going through the motions because of company policy.&#160; I get that.</p>
<p>But if you are writing an honest RFP, one that is simply inspired by a need and is seeking multiple responses from which the best is chosen, then <strong>please</strong> include the information needed in the RFP itself so things can proceed smoothly.&#160; Thank you for your consideration.</p>
<p>Vet </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:5lVTG1FW49M"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=5lVTG1FW49M" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=a2x3Wxw6Gks:fH3ZIasAUBU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?i=a2x3Wxw6Gks:fH3ZIasAUBU:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?a=a2x3Wxw6Gks:fH3ZIasAUBU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/AnInformationSecurityPlace?d=63t7Ie-LG7Y" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2009/05/15/some-advice-when-writing-security-assessment-rfps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecplace.com/blog/2009/05/15/some-advice-when-writing-security-assessment-rfps/</feedburner:origLink></item>
	<copyright>Copyright Michael R. Farnum</copyright><media:credit role="author">Michael R. Farnum</media:credit><media:rating>nonadult</media:rating></channel>
</rss>
